access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Google, OpenAI, Anthropic Plan Frontier AI Standards Body
Proposed Independent Group Would Set Common Benchmarks and Test Advanced AI Models. The three largest frontier AI labs, Google, OpenAI and Anthropic, are reportedly close to establishing a common standards organization that would act as a third-party entity to monitor AI models. The group would be called the Standards Authority for Frontier AI and could…
-
Google, OpenAI, Anthropic Plan Frontier AI Standards Body
Proposed Independent Group Would Set Common Benchmarks and Test Advanced AI Models. The three largest frontier AI labs, Google, OpenAI and Anthropic, are reportedly close to establishing a common standards organization that would act as a third-party entity to monitor AI models. The group would be called the Standards Authority for Frontier AI and could…
-
SectopRAT Returns, Hiding Inside a Legitimate Application
Tags: accessThe latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/sectoprat-returns-hiding-inside-legitimate-application also interesting: Nach Angriff auf Antragsportal: D-Trust informiert über neue Erkenntnisse Treasury Curtails Musk-led DOGE’s Government Access New Sophisticated Multi-Stage Malware Campaign…
-
‘Salesbleed’ Exploits Salesforce Agents to Enable Slack Phishing
Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing also interesting: Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer Prevention Tips Against Telecom Spying Attacks A new era of cyberthreats from sophisticated threat actors…
-
Island Gets $400M to Take Worker Security Into the Agent Era
Non-Human Identity and Transient Networks Extend Controls Beyond Human Workers. Island raised $400 million at a $6.4 billion valuation to extend its worker-centric security platform to AI agents, applying data, identity, network, endpoint and observability controls to non-human workers while funding growth toward profitability and a potential IPO. First seen on govinfosecurity.com Jump to article:…
-
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/ also interesting: New XCSSET Malware Targets macOS Users Through Infected Xcode Projects UNC5174 Deploys SNOWLIGHT Malware in Linux and macOS Attacks N. Korean Group BlueNoroff Uses…
-
Is Your Network Ready for Post-Quantum Cryptography?
Bigger Keys and Heavier Handshakes Will Test Routers, Firewalls and Apps. Updating enterprise networks for the post-quantum era will require more than simply swapping out one encryption algorithm for another. It could require enterprises to transform their hardware ecosystems to support the processing capacity, memory or protocol requirements. First seen on govinfosecurity.com Jump to article:…
-
AI Is Changing Cybersecurity Jobs, Not Erasing Them
SANS Institute’s Rob Lee on AI Transforming Cyber Jobs. AI is reshaping entry-level cybersecurity, but SANS Institute’s Rob Lee says the data doesn’t show junior jobs disappearing. Instead, he expects the starting point to move higher as AI accelerates technical work, raises skill expectations and creates new security roles. First seen on govinfosecurity.com Jump to…
-
AI Is Changing Cybersecurity Jobs, Not Erasing Them
SANS Institute’s Rob Lee on AI Transforming Cyber Jobs. AI is reshaping entry-level cybersecurity, but SANS Institute’s Rob Lee says the data doesn’t show junior jobs disappearing. Instead, he expects the starting point to move higher as AI accelerates technical work, raises skill expectations and creates new security roles. First seen on govinfosecurity.com Jump to…
-
CISA Promises OT Recovery Guidance Through CI-Fortify
Agency Tells Operators to Test Recovery Plans End-to-End for Real Life Conditions. The U.S. government and its Five Eyes partners will soon publish guidance for operational technology owners and operators on recovering from a cyberattack, the next part of their CI-Fortify initiative, officials said this week, delivering an update on the state of the program.…
-
CISA Promises OT Recovery Guidance Through CI-Fortify
Agency Tells Operators to Test Recovery Plans End-to-End for Real Life Conditions. The U.S. government and its Five Eyes partners will soon publish guidance for operational technology owners and operators on recovering from a cyberattack, the next part of their CI-Fortify initiative, officials said this week, delivering an update on the state of the program.…
-
CISA Promises OT Recovery Guidance Through CI-Fortify
Agency Tells Operators to Test Recovery Plans End-to-End for Real Life Conditions. The U.S. government and its Five Eyes partners will soon publish guidance for operational technology owners and operators on recovering from a cyberattack, the next part of their CI-Fortify initiative, officials said this week, delivering an update on the state of the program.…
-
Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison
Tags: ukraineRyuk member Karen Vardanyan was sentenced to 24 months in U.S. prison after extradition from Ukraine and ordered to pay $1.2M in restitution. Karen Vardanyan, a 35-year-old Armenian citizen who went by >>Maneeken<>Karl Lagerfeld<< online, was extradited from Ukraine and sentenced to 24 months in federal prison plus three years of supervised […] First seen…
-
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it. First seen on cyberscoop.com Jump to article: cyberscoop.com/biotech-critical-infrastructure-cybersecurity-legislation/ also interesting: CISA Defunds Threat-Sharing Hubs for States and Elections Cisco Firewall and VPN Zero Day Attacks: CVE-2025-20333 and CVE-2025-20362 Cybersecurity Snapshot: Refresh Your Akira…
-
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it. First seen on cyberscoop.com Jump to article: cyberscoop.com/biotech-critical-infrastructure-cybersecurity-legislation/ also interesting: CISA Defunds Threat-Sharing Hubs for States and Elections Cisco Firewall and VPN Zero Day Attacks: CVE-2025-20333 and CVE-2025-20362 Cybersecurity Snapshot: Refresh Your Akira…
-
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/ also interesting: Top 7 zero-day exploitation trends of 2024 New Docker Malware Strain Spotted Blocking Rivals on Exposed APIs Docker APIs Targeted FireTail Blog Top…
-
Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks
U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was necessary in light of the Salt Typhoon attacks which saw Chinese hackers breach nearly all of the major telecommunications giants in the U.S. First seen on therecord.media Jump to article: therecord.media/lawmakers-introduce-bill-for-voluntary-telecom-cyber-rules…
-
Breach Roundup: Thousands of AI Relays Hide China Users
Tags: ai, breach, china, cisa, cve, cybercrime, data, data-breach, flaw, google, jobs, north-korea, russia, scam, vpnAlso, CISA Ends Weekly CVE Bulletin After 22 Years, Check Point VPN Flaw Exploited. This week: AI relay servers connect to China, CISA ends weekly CVE bulletin, cybercriminal guilty pleas and sentences, drug dealers hijack Google Maps, Russian Burger King customers’ data leaked, North Korean fake job scams, SectopRAT, a Check Point VPN flaw and…
-
OpenAI Agent Breached Australian Medicare Statistics Portal
An OpenAI agent bypassed controls on Australia’s Medicare statistics portal, accessed non-public data and was not reported to officials for nearly 3 months. First seen on hackread.com Jump to article: hackread.com/openai-agent-breached-australian-medicare-portal/ also interesting: Cybersecurity Snapshot: F5 Breach Prompts Urgent U.S. Gov’t Warning, as OpenAI Details Disrupted ChatGPT Abuses Top 5 real-world AI security threats revealed…
-
Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges
Two executives at a data extraction and digital forensics company that sold several U.S. agencies its software were arrested for allegedly lying about the fact that its technology is made in Russia. First seen on therecord.media Jump to article: therecord.media/russia-forensics-technology-doj also interesting: Cybersecurity Snapshot: CISA Hands Down Cloud Security Directive, While Threat from North Korean…
-
AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS
MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days. MikroTik pushed out patches on September 3, 2026 for several RouterOS issues at once, calling it an important security update without saying what it actually fixed. That silence was deliberate, and it didn’t last…
-
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before.That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts…
-
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus’s own software to gain root access, the highest level of control over an Android phone.OnePlus told him the same flaws affect many…
-
SCOUTz Prospect Intelligence Platform Launches for MSPs with 30-Day Beta
Phoenix, Arizona, September 24th, 2026, CyberNewswire SCOUTz, a prospect intelligence platform built for managed service provider (MSP) security sales, is now available in open beta. The platform gives an MSP dated evidence about a prospect’s environment before the first meeting and keeps that evidence attached through delivery and reassessment. The open beta is available at…
-
SCOUTz Prospect Intelligence Platform Launches for MSPs with 30-Day Beta
Phoenix, Arizona, September 24th, 2026, CyberNewswire SCOUTz, a prospect intelligence platform built for managed service provider (MSP) security sales, is now available in open beta. The platform gives an MSP dated evidence about a prospect’s environment before the first meeting and keeps that evidence attached through delivery and reassessment. The open beta is available at…
-
SCOUTz Prospect Intelligence Platform Launches for MSPs with 30-Day Beta
Phoenix, Arizona, September 24th, 2026, CyberNewswire SCOUTz, a prospect intelligence platform built for managed service provider (MSP) security sales, is now available in open beta. The platform gives an MSP dated evidence about a prospect’s environment before the first meeting and keeps that evidence attached through delivery and reassessment. The open beta is available at…
-
Building AI Systems With ‘Least Capability’ Cuts Agent Risk
Akamai CTO Robert Blumofe on Reliability, Visibility and AI Security. AI systems that perform well in the lab can fail at scale, drive unexpected costs and expose new attack paths in production. Robert Blumofe, executive vice president and CTO at Akamai, says enterprises need stronger visibility, reliability engineering and a least capability model for AI…
-
AI Agents Need More Than Proofs of Concept
AWS’ Sivasubramanian Says Enterprises Need Focused AI Agent Investments. Enterprises risk getting trapped in AI proof-of-concept hell when they deploy agents without clear measures of success. AWS executive Swami Sivasubramanian explains how focused investments, shared infrastructure and human oversight can help move AI agents into production. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-agents-need-more-than-proofs-concept-a-32919 also…
-
Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation
Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox, an illicit platform used by cybercriminals to sell stolen personal information, illegal access to devices and other tools for carrying out fraud. First seen on therecord.media Jump to article: therecord.media/rydox-criminal-marketplace-operator-pleads-guilty also…
-
Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/ also interesting: Cybersecurity Snapshot: CISA Hands Down Cloud Security Directive, While Threat from North Korean IT…
-
Rogue OpenAI Agent Hacks Australian Medicare Site
Government Launches Task Force, Urges Agencies to Shore Up Public-Facing Systems. Australian officials have launched a task force and are urging government agencies to shore up cybersecurity of their public-facing websites and apps after the country’s prime minister revealed that a rogue OpenAI agent hacked into the nation’s public health Medicare website in June. First…
-
Rogue OpenAI Agent Hacks Australian Medicare Site
Government Launches Task Force, Urges Agencies to Shore Up Public-Facing Systems. Australian officials have launched a task force and are urging government agencies to shore up cybersecurity of their public-facing websites and apps after the country’s prime minister revealed that a rogue OpenAI agent hacked into the nation’s public health Medicare website in June. First…
-
‘Psychedelic Stealer” Legitime ukrainische Websites verbreiten Clickfix-Köder
Tags: unclassifiedVeranschaulichung der fünf Phasen des Angriffsablaufs des ‘Psychedelic Stealers”, Quelle: Arctic WolfArctic Wolf Labs veröffentlicht neue Forschungsergebnisse zu einer aktuellen Kampagne, bei der Angreifer kompromittierte legitime ukrainische Websites zur Verbreitung eines Clickfix-Köders nutzen. Ein Verwaltungspanel mit russischem Branding dient dazu, Befehle zu konfigurieren und Besucherinteraktionen zu erfassen. Das öffentlich zugängliche Panel offenbarte domänenspezifische Befehlskonfigurationen und…
-
‘Psychedelic Stealer” Legitime ukrainische Websites verbreiten Clickfix-Köder
Tags: unclassifiedVeranschaulichung der fünf Phasen des Angriffsablaufs des ‘Psychedelic Stealers”, Quelle: Arctic WolfArctic Wolf Labs veröffentlicht neue Forschungsergebnisse zu einer aktuellen Kampagne, bei der Angreifer kompromittierte legitime ukrainische Websites zur Verbreitung eines Clickfix-Köders nutzen. Ein Verwaltungspanel mit russischem Branding dient dazu, Befehle zu konfigurieren und Besucherinteraktionen zu erfassen. Das öffentlich zugängliche Panel offenbarte domänenspezifische Befehlskonfigurationen und…
-
Sicherheit für Microsoft-365 Coreview startet Intelligence-Labs
Der Spezialist für den Schutz und das Management von Microsoft-365-Tenants, Coreview, hilft mit seinen neuen Intelligence-Labs Sicherheitsexperten dabei, die Prozesse in ihren Microsoft-Tenants zu verstehen und bestehende sowie neu auftretende Sicherheitslücken zu schließen. Hierfür werden die Sicherheitsforscher unter der Leitung von Kasper Lindgaard technische Forschungsergebnisse und praktische Leitfäden zur Sicherheit von Microsoft-365 veröffentlichen. Die Einführung…
-
Trust and the enticing consultancy offer
In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the cyber industry must worry about. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/ also interesting: SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by…
-
New bill would create federal investigative body for AI-driven hacks
A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyberattacks carried out by AI agents, following recent hacks by models run at companies like Anthropic, OpenAI, Meta and others. The bill, introduced by Sen. Ed Markey, D-Mass., would attempt to establish a…
-
Cryptohack Roundup: US Sanctions BitBank
Also: South Korea Books 26 Polymarket Users for Alleged Illegal Gambling. This week, the United States sanctioned Iranian exchange BitBank, South Korea booked 26 Polymarket users and Polymarket faced $10 million fraud attempt. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cryptohack-roundup-us-sanctions-bitbank-a-32914 also interesting: Successful Military Attacks are Driving Nation States to Cyber Options Top 10…
-
ISMG Security Report: AI Doesn’t Wait for Patch Tuesday
AI Bug Discovery Forces Security Teams to Rethink Vulnerability Management. AI is getting scary good at finding software vulnerabilities. Anthropic says Claude Mythos previews uncovered more than 10,000 flaws in key software products. That’s great news, but somebody still has to triage them, figure out which ones attackers can actually exploit and, eventually, patch them.…
-
ISMG Security Report: AI Doesn’t Wait for Patch Tuesday
AI Bug Discovery Forces Security Teams to Rethink Vulnerability Management. AI is getting scary good at finding software vulnerabilities. Anthropic says Claude Mythos previews uncovered more than 10,000 flaws in key software products. That’s great news, but somebody still has to triage them, figure out which ones attackers can actually exploit and, eventually, patch them.…
-
ISMG Security Report: AI Doesn’t Wait for Patch Tuesday
AI Bug Discovery Forces Security Teams to Rethink Vulnerability Management. AI is getting scary good at finding software vulnerabilities. Anthropic says Claude Mythos previews uncovered more than 10,000 flaws in key software products. That’s great news, but somebody still has to triage them, figure out which ones attackers can actually exploit and, eventually, patch them.…
-
Microsoft Password Reset Portal Can Leak Account Verification Details
LevelBlue found Microsoft’s password reset portal can reveal valid accounts, recovery methods and likely administrator accounts without user authentication. First seen on hackread.com Jump to article: hackread.com/microsoft-password-reset-portal-leak-account-details/ also interesting: Privacy Roundup: Week 7 of Year 2025 The most notorious and damaging ransomware of all time Privacy Roundup: Week 12 of Year 2025 Top cybersecurity M&A…
-
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges
The Justice Department said two leaders of the company have been arrested and face conspiracy to commit wire fraud. First seen on cyberscoop.com Jump to article: cyberscoop.com/oxygen-forensics-ceo-arrested-russian-ownership-fraud/ also interesting: The most notorious and damaging ransomware of all time TDL001 – Cybersecurity Explained: Privacy, Threats, and the Future – Chester Wisniewski Russia used Cellebrite phone-hacking tool…
-
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The “third-party[.]com” domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.”third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,” Manifold Security’s Head of Research, Ax Sharma, said. “Unlike ‘example[.]com,’ third-party[.]com First seen on thehackernews.com…
-
3 Cyber Threats That Defined the Summer of 2026
This installment of the Reporters’ Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife’s ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/3-cyber-threats-defined-summer-2026 also interesting: 8 biggest cybersecurity threats manufacturers face 8 biggest cybersecurity threats…
-
The Hidden Security Risks of Devices You Forgot Were Connected
IoT and OT devices can create hidden security gaps. Learn how asset visibility helps organizations find forgotten devices and reduce network security risks now. First seen on hackread.com Jump to article: hackread.com/hidden-security-risks-connected-devices/ also interesting: U.S. House Homeland Security Appropriations Bill Seeks to Modernize Border Infrastructure Security with Proactive OT/IT Security Measures 7 obsolete security practices…
-
Kombination aus Software, Beratung und Moderation unterstützt Unternehmen bei normgerechtem Risikomanagement
Die Bassetti Group und die PSCR Consulting bündeln ihre Kompetenzen im deutschsprachigen Raum. Gemeinsam bieten Knowllence, ein Unternehmen der Bassetti Group, und PSCR Consulting ein integriertes Angebot für die Fehlermöglichkeits- und Einflussanalyse (FMEA), das Software, Moderation und Schulung miteinander verbindet. Ziel der Partnerschaft ist es, Unternehmen bei der Einführung und Durchführung normgerechter Risikoanalysen zu unterstützen.…
-
Künstliche Intelligenz als Kraftmultiplikator in der Cyberabwehr
Russische offensive Cyberoperationen sind seit 2014 ein zentraler Bestandteil der Aggression des Kremls gegen die Ukraine. Ukrainische Verteidiger stehen unter ständigem Druck zusätzlich zu den physischen Angriffen auf die Infrastruktur des Landes. Vor diesem Hintergrund ist es eine begrüßenswerte Entwicklung, dass OpenAI der Ukraine im Rahmen seines Daybreak-Programms nun KI-Tools zur Cyberabwehr ziviler Infrastruktur […]…
-
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-gang-uses-backup/ also interesting: Scattered Lapsus$ Hunters extortion site goes dark: What’s next? The cybercrime industry continues to challenge CISOs in 2026 Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure…
-
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-gang-uses-backup/ also interesting: Scattered Lapsus$ Hunters extortion site goes dark: What’s next? The cybercrime industry continues to challenge CISOs in 2026 Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure…

