access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerabilities are listed below – CVE-2025-39682 (CVSS score: 9.8) – An improper check for unusual or exceptional conditions vulnerability in the TLS receive path First…
-
PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner
A sophisticated cryptomining campaign is employing multiple layers of obfuscation to conceal malicious PowerShell payloads and ultimately deploy an XMRig-based cryptocurrency miner. This obfuscation includes Windows Registry entries, DNS TXT records, PNG images, and WAV audio files. The infection was detected after repeated security alerts indicated suspicious PowerShell activity. The initial execution command launched PowerShell…
-
Flock Offers Employees Buyouts as Customers Flee
Tags: unclassifiedAs dozens of cities end contracts for its controversial license plate readers, Flock is rolling out a voluntary severance program, WIRED has learned. First seen on wired.com Jump to article: www.wired.com/story/flock-is-offering-voluntary-buyouts-to-employees/ also interesting: assassins-creed Peter Higgs, Father Of The God Particle, Dies At 94 Honeytokens [Security Zines] Facebook-Seite einer Tourismusinformation in Rheinland-Pfalz gehackt
-
Anthropic’s AI Plays Major Role in Building Next Models
Internal Study Finds AI Leads 26% of Work and Collaborates on Most of the Rest. Anthropic said Claude now leads 26% of surveyed model R&D, offering a rare measure of how frontier AI labs are using models to build their successors while monitoring automation, safety and agent misbehavior. First seen on govinfosecurity.com Jump to article:…
-
Cyber Defense Alone Can’t Keep Critical Services Running
States Must Map Dependencies and Engineer Safeguards for Water and Hospitals. State CIOs must decide which water systems, hospitals and other essential services need protection first. NASCIO data shows why states should rank infrastructure by consequence, test simultaneous failures and pair cyber defenses with engineering safeguards. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-defense-alone-cant-keep-critical-services-running-a-32871 also…
-
China Hackers Hit Latin American Governments With Backdoor
ESET Says FamousSparrow Shifted Nearly All Targeting to Latin America. A Chinese espionage group has deployed a previously undocumented backdoor against government entities in eight Latin American countries and territories, including Puerto Rico, in a campaign researchers say tracks with U.S. pressure on Chinese investments across the region. First seen on govinfosecurity.com Jump to article:…
-
Post-Mythos Security Rally Rewards Broad Cyber Platforms
6 Major Security Vendors Have Doubled in Value Since Anthropic Unveiled Mythos Six prominent cybersecurity vendors have doubled their valuations since Anthropic announced Claude Mythos in April, led by Okta’s 131% stock surge as investors bet that AI agents will drive demand for identity, data, network and integrated security platforms. First seen on govinfosecurity.com Jump…
-
Now AI Puts Financial Crime Within Anyone’s Reach
Eliminate Silos to Better Combat AI-Driven Crime, Says Global Payments’ Shola Akeju. Financial crime might be nothing new, but artificial intelligence is making it faster to execute and harder to detect by putting sophisticated tools within reach of almost anyone, said Shola Akeju, director of global financial crime program implementation at Global Payments First seen…
-
Brevo Supply-Chain Attack Infected Over 100,000 Websites
A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michelin. The company was first compromised on September 10, when attackers exploited a vulnerability in its…
-
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
The new program expands Vectra AI’s partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/vectra-ai-launches-ascent-new-era-ai-driven-attacks also interesting: Cybersecurity Snapshot: Tenable Report Spotlights Cloud Exposures, as Google Catches Pro-Russia Hackers Impersonating Feds AI-powered phishing…
-
ISMG Editors: Even Valid Email Addresses Can’t Be Trusted
Also: States Inherit America’s Cyber Burden, AI Agents Reshape the MSSP Market. In this week’s panel, four ISMG editors discuss an unusual breach at U.K. digital banking platform Revolut, the growing role of U.S. state governments in protecting local critical infrastructure and what a new cybersecurity acquisition tells us about the AI-powered SOC. First seen…
-
DARPA Seeks AI Tools to Transform Battlefield Medical Care
Competitions Focus on Surgical Robotics, Clinical Decision Support, Documentation. Traumatic injuries in combat environments can turn deadly if field surgeons aren’t near, or if medical care documentation for split-second clinical decisions goes unrecorded. DARPA is launching two competitions to harness AI, robotics and automation to tackle critical gaps in trauma care. First seen on govinfosecurity.com…
-
Early Scattered Spider member pleads guilty to cybercrime spree
Tags: cybercrimeAhmed Elbadawy pocketed massive proceeds from his crimes. Prosecutors are seeking the forfeiture of about $17.6 million in virtual currency, luxury vehicles, and a vast collection of jewelry and designer bags. First seen on cyberscoop.com Jump to article: cyberscoop.com/scattered-spider-member-guilty-ahmed-elbadawy/ also interesting: Hackers Launching AI-Powered Cyber Attacks to Steal Billions The dirty dozen: 12 worst ransomware groups…
-
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine.Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now…
-
EY Survey Finds Autonomous AI Implementation Outpaces Oversight
A new survey of senior AI execs shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ey-survey-autonomous-ai-implementation-outpaces-oversight also interesting: How JPMorgan Chase Scaled Secure Software Delivery Cymphony Raises $30M to Turn Access Data Into Remediation Defining What Counts…
-
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco’s Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues also interesting: Claude Mythos: Prepare for your board’s cybersecurity questions about the latest AI model from Anthropic Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS…
-
MFA Won’t Save You From OAuth Consent Abuse
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/mfa-oauth-consent-abuse also interesting: Ransomware attacks: The evolving extortion threat to US financial institutions Why can’t enterprises get a handle on the cloud misconfiguration problem? What is Security Posture Management and Why is…
-
InjectEave: Elektromagnetischer Angriff macht elektronische Geräte abhörbar
Tags: cyberattackInjectEave zeigt, wie elektromagnetische Angriffe Signale aus elektronischen Geräten aus der Ferne rekonstruieren können. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/injecteave-elektromagnetischer-angriff-333581.html also interesting: WazirX Faces Backlash Over Socialized Losses from $230M Cyberattack Cyberangriff auf Freizeitparks in Mexiko Intro to Deceptionology: Why Falling for Scams is Human Nature Royal Mail untersucht Datenleck
-
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum”, a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. First seen on therecord.media Jump to article: therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme also interesting: Top 10…
-
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell.…
-
US cyber agency endorses ‘decoy’ tactics
Official US guidance suggests organisations consider using cyber decoys to strengthen their detection and response capabilities. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650815/US-cyber-agency-endorses-decoy-tactics also interesting: 7 biggest cybersecurity stories of 2024 XwormRAT Hackers Leverage Code Injection for Sophisticated Malware Deployment Qilin Ransomware Uses TPwSav.sys Driver to Bypass EDR Security Measures Why domain-based attacks will…
-
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
Tags: networkThe feds are said to be investigating the compromise of the tankers’ networks, which in one case interfered with one of the tanker’s navigation and propulsion systems. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/18/fbi-coast-guard-boarded-hacked-oil-tankers-heading-towards-us-coast/ also interesting: US takes aim at healthcare cybersecurity with proposed HIPAA changes Barracuda Networks Unveils BarracudaONE to Simplify Cybersecurity for…
-
Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors
Exclusive: Official UK security assessment found Microsoft cloud platform storing files was at potential risk from hostile hackersVast troves of highly sensitive police data are lying on Microsoft cloud platforms which an official UK security assessment deemed to be vulnerable to “compromise” by foreign actors and the US government, a Guardian investigation can reveal.The files…
-
An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle. First seen on wired.com Jump to article: www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/ also interesting: An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang The 2024 cyberwar playbook: Tricks…
-
KI-Agenten im Unternehmenseinsatz Architektur, Sicherheit und Integration in bestehende IT-Landschaften
Tags: aiAutonome KI-Agenten verlassen zunehmend die Phase der Pilotprojekte und rücken in produktive Unternehmensumgebungen. Anders als klassische Chatbots planen sie mehrstufige Aufgaben, rufen Werkzeuge auf und interagieren mit Fachanwendungen. Für IT-Verantwortliche stellt sich damit die Frage, wie solche Systeme sicher in bestehende Netzwerke, Identitätsdienste und Datenflüsse eingebettet werden können, ohne bestehende Kontrollmechanismen zu unterlaufen. Architektur autonomer…
-
Weltweiter Anstieg von exponierten industriellen Steuerungssystemen
In seinem jährlichen State of the Internet Report analysiert Censys, Experte für Internet-Intelligence, Attack-Surface-Management und Threat-Hunting, weltweite Bedrohungen und Sicherheitslücken sowie die Entwicklung des öffentlichen Internets. Der Forschungsbericht 2026 erscheint am 6. Oktober und beschäftigt sich unter anderem mit der weltweiten Exposition von industriellen Steuerungssystemen (ICS). Der Bericht zeigt, wie sich die weltweite ICS-Angriffsfläche verändert.…
-
Cisco ISE Vulnerability With CVSS 10.0 Score Under Active Attack
Cisco has released a fix for a maximum-severity flaw in its Identity Services Engine (ISE) platform after confirming the bug was already being exploited by attackers. The vulnerability, tracked as CVE-2026-76460, carries a perfect CVSS score of 10.0 and was patched by Cisco on September 16, 2026. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cisco-ise-cve-2026-76460/…
-
The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown
This weekly roundup covers a stark small-business cyberattack report out of the UK, a hardware flaw exposing Nintendo Switch owners to nearby attackers, the largest known seizure of AI deepfake porn websites, a candid conversation on AI’s role in offensive security, new US legislation targeting elder fraud, and a fresh national threat-intelligence partnership in the…
-
Researchers use AI to find widespread software decoder flaw
The bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software repository. First seen on cyberscoop.com Jump to article: cyberscoop.com/hacktron-ai-heif-heist-vulnerability/ also interesting: Top 5 real-world AI security threats revealed in 2025 Anthropic’s DXT poses “critical RCE vulnerability” by running…
-
AI Governance Is Key”, But Don’t Let It Slow Down Cyber Defense: Optiv CISO
While businesses must make governance an essential part of their AI strategies, it’s also important to not allow policies and approval processes to prevent defenders from moving as quickly as today’s increasingly machine-speed attackers, according to Optiv security chief Rob Gregory. First seen on crn.com Jump to article: www.crn.com/news/security/2026/ai-governance-is-key-but-don-t-let-it-slow-down-cyber-defense-optiv-ciso also interesting: Cybersecurity Snapshot: NIST Aligns…
-
ALPSiX: Berliner Inter.link errichtet neuen Peeringknoten des DE-CIX in Südöstereich
Tags: containerDer neue Internetknoten ALPSiX in Klagenfurt-Villach setzt auf Edge-Container, um die Unabhängigkeit von Wien zu stärken und Daten direkt nach Norditalien, Bayern und auf den Balkan zu leiten. First seen on golem.de Jump to article: www.golem.de/news/alpsix-berliner-inter-link-errichtet-neuen-peeringknoten-des-de-cix-in-suedoestereich-2609-213224.html also interesting: Critical NVIDIA Container Toolkit flaw could allow access to the underlying host So können Cloud- und Container-Umgebungen…
-
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation…
-
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-to-steal-236-million-user-records/ also interesting: Top 7 zero-day exploitation trends of 2024 Privacy Roundup: Week 9 of Year 2025 Synack + Tenable: AI-Powered Partnership Translates…
-
Google Opens Google Home to Claude and Other AI Agents, Here’s What They Can Control
Google Home now lets Claude and other compatible AI agents inspect devices, review activity, and perform approved actions through Home MCP. The post Google Opens Google Home to Claude and Other AI Agents, Here’s What They Can Control appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-home-claude-ai-agents/ also interesting: How the generative…
-
An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle. First seen on wired.com Jump to article: www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/ also interesting: 8 Cyber Predictions for 2025: A CSO’s Perspective SentinelLabs uncovers China’s hidden cyber-espionage arsenal Cybersecurity…
-
Zero-Days, AI Agents, and Massive Data Leaks Define the Week
Weekly summary of Cybersecurity Insider newsletters First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/zero-days-ai-agents-and-massive-data-leaks-define-the-week/ also interesting: Wiz’s Security GraphDB vs. DeepTempo’s LogLM 9 things CISOs need know about the dark web Cybersecurity Snapshot: AI Will Take Center Stage in Cyber in 2026, Google Says, as MITRE Revamps ATTCK Framework The zero-day timeline just collapsed. Here’s…
-
FBI, Coast Guard boarded hacked oil tankers heading towards US coast
Tags: networkThe feds are said to be investigating the compromise of the tankers’ networks, which in one case interfered with one of the tanker’s navigation and propulsion systems. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/18/fbi-coast-guard-boarded-hacked-oil-tankers-heading-towards-us-coast/ also interesting: Strengthen Cyber Resilience: A Checklist for ITOps and SecOps Collaboration New Application-Layer Loop DoS Attack 300,000 Online Systems…
-
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide. First seen on cyberscoop.com Jump to article: cyberscoop.com/north-korea-waterplum-job-seeker-crypto-attacks/ also interesting: The most notorious and damaging ransomware of all time 7 biggest cybersecurity stories of 2024 North Korean fake IT workers up the ante in…
-
Settra ransomware variant deployed in recent attacks
Security researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/settra-ransomware-variant-recent-attacks/830787/ also interesting: Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer Prevention Tips Against Telecom Spying Attacks Old threats, new consequences: 90% of cyber claims stem from…
-
Swedish teenager jailed for attempted murder, rape and assault committed online, with victims in Germany and Australia
Eighteen-year-old known as Chai was active in networks notorious for their sadistic exploitation of young peopleA Swedish teenager known as Chai has been sentenced to more than 10 years in jail for attempted murder, rape and aggravated assault crimes committed via the internet, <a href=”https://www.theguardian.com/technology/ng-interactive/2026/jul/21/764-network-gamification-of-harm-the-com-cybercrime-ntwnfb”>including against a teenage girl in Australia.The district court found that…
-
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/ also interesting: Fast 1 Million Geschäfts- und Privat-PCs kompromittiert What the Arc Browser Story Reveals About the Future of Browser Security Smart GPUGate malware exploits…
-
Nations take action on North Korean IT workers after UN report
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study. First seen on therecord.media Jump to article: therecord.media/nations-take-action-on-north-korean-it-worker-schemes also interesting: North Korean Hackers Spoofing Journalist Emails to Spy on Policy Experts Five charged for cyber schemes…
-
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
The agency wants to help companies sort through the AI-fueled avalanche of bug reports. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-vulnerability-bulletins-sunset-prioritization/830779/ also interesting: Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer Prevention Tips Against Telecom Spying Attacks Exposure Management Beyond The Endpoint Cybersecurity Snapshot: Global Agencies Target Criminal “Bulletproof”…
-
Software Supply Chain Security – Wenn Open-Source-Pakete zur Hintertür werden
First seen on security-insider.de Jump to article: www.security-insider.de/operation-navy-ghost-backdoor-supply-chain-a-a7aef14bca7ea71dbb268aaf312f2b5f/ also interesting: Agentic AI promises a cybersecurity revolution, with asterisks Compromise of Notepad++ Equals Software Supply Chain Fallout Supply chain attack on Axios npm package: Scope, impact, and remediations EU’s Cyber Resiliency Act will put IT leaders to the test
-
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/settra-ransomware-retail/ also interesting: Change Healthcare Ransomware Attack: BlackCat Hackers Quickly Returned After FBI Bust Casio Discloses Data Leak Following Ransomware Attack Akira Ransomware Dominates January 2025 as the Most Active…
-
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.The firm said Anthropic has patched the flaw in Claude…
-
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
Tags: unclassifiedIn July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references…

