access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/ also interesting: The 2024 cyberwar playbook: Tricks used by nation-state actors Agents, Robotics, and Auth…
-
AI Hallucinations Nearly Triggered a US-China Military Confrontation
An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle East was carrying components for a nuclear weapons program. The…
-
107 Jahre ungelöst: KI knackt deutschen Funkspruch aus dem Ersten Weltkrieg
Tags: aiEin Autor namens prinz will mit einem KI-Modell eine deutsche Militärchiffre von 1918 entschlüsselt haben, die bislang als unlösbar galt. First seen on golem.de Jump to article: www.golem.de/news/107-jahre-ungeloest-ki-knackt-deutschen-funkspruch-aus-dem-ersten-weltkrieg-2609-213252.html also interesting: 5 Actionable Steps to Prevent GenAI Data Leaks Without Fully Blocking AI Usage MSSP Market News: Prompt Brings GenAI Security to MSSPs Unpatched flaw in…
-
RNLI warns supporters their personal information may have been hacked
Data raid comes amid targeting of lifeboat charity by far-right agitators who object to migrant boat rescuesSupporters of the Royal National Lifeboat Institution (<a href=”https://www.theguardian.com/uk-news/rnli”>RNLI) have been warned that their personal information could have been stolen by hackers amid targeting of the charity by far-right agitators.In a letter accompanying the autumn copy of its Lifeboat…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot…
-
Researchers escape OpenAI Codex sandbox to run commands on host
Tags: openaiResearchers escaped OpenAI’s Codex sandbox two ways, one running commands on a developer’s machine from its most locked-down mode. OpenAI has patched both. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/researchers-escape-openai-codex-sandbox-to-run-commands-on-host/ also interesting: Apple Integrates OpenAI’s ChatGPT into Siri for iOS, iPadOS, and macOS Researchers warn devs of vulnerabilities in ChatGPT plugins OpenAI Killed Iranian…
-
An undercover Google analyst infiltrated a notorious supply-chain hacking gang
Google’s threat intelligence group said it had a mole inside TeamPCP’s inner circle. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/ also interesting: Cybersecurity Snapshot: Top Advice for Detecting and Preventing AI Attacks, and for Securing AI Systems An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang An Undercover Google Analyst Infiltrated a…
-
SIM-Swaps im Darknet schon ab 300 Dollar
Tags: dark-webLaut einer Analyse von NordStellar werden SIM-Swapping-Dienste im Darknet bereits ab 300 US-Dollar gehandelt, oft gebündelt mit gestohlenen Identitätsdaten. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/sim-swaps-darknet also interesting: Early Detection, Fewer Headaches: The Benefits of Dark Web Monitoring for CFOs Clop ransomware threatens 66 Cleo attack victims with data leak Police shuts down KidFlix…
-
KI-Kontroverse: Trump setzt trotz Warnungen vor Gefahren noch stärker auf KI
Tags: aiFührende Köpfe der KI-Branche verlangen eine Verlangsamung bei der KI-Entwicklung und warnen vor Kontrollverlust. Donald Trump ist das egal. First seen on golem.de Jump to article: www.golem.de/news/ki-kontroverse-trump-setzt-trotz-warnungen-vor-gefahren-noch-staerker-auf-ki-2609-213247.html also interesting: Researchers Urge Immediate Action on New EmailGPT Vulnerability Exposing Users to Data Breach Hands-on Review: Cynomi AI-powered vCISO Platform Hacker Attacking Bank Users With AI-powered Phishing…
-
(g+) Risk-Based Patching: Warum der CVSS-Wert allein in die Irre führt
Cisa hat CVSS als Maßstab für Patchfristen abgeschafft. Vier Fragen entscheiden jetzt. Worauf es dabei ankommt. First seen on golem.de Jump to article: www.golem.de/news/risk-based-patching-warum-der-cvss-wert-allein-in-die-irre-fuehrt-2609-213204.html also interesting: CISA warns of critical, high-risk flaws in ICS products from four vendors F5 BIG-IP Breach: 44 CVEs That Need Your Attention Now F5 Security Incident Advisory The nexus of…
-
Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far Someone impersonating a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/20/week-in-review-cisco-patches-exploited-email-gateway-0-day-revolut-breach/ also interesting: Top 7 zero-day exploitation trends of 2024 Your Network Is Showing Time to Go Stealth Top…
-
KI-Agenten brauchen eine Undo-Taste: Warum ‘Human in the Loop” allein nicht mehr reicht
Autonome KI-Agenten handeln schneller als Menschen eingreifen können. Warum granulare Recovery, Daten-Governance und Zero Trust jetzt entscheidend werden. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-agenten-brauchen-eine-undo-taste-warum-human-in-the-loop-allein-nicht-mehr-reicht/a46435/ also interesting: Beyond cryptocurrency: Blockchain 101 for CISOs and why it matters Beyond cryptocurrency: Blockchain 101 for CISOs and why it matters When AI nukes your database: The dark…
-
Horizon3 und CrowdStrike verbinden Pentest-Ergebnisse mit SIEM-Telemetrie
Horizon3 integriert NodeZero in CrowdStrike Falcon Next-Gen SIEM. Validierte Angriffspfade lassen sich so mit SOC-Telemetrie korrelieren und priorisieren. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/horizon3-und-crowdstrike-verbinden-pentest-ergebnisse-mit-siem-telemetrie/a46432/ also interesting: Top cybersecurity products showcased at RSA 2025 CSO Awards winners highlight security innovation and transformation Beyond silos: How DDI-AI integration is redefining cyber resilience The noisy tenants:…
-
Reαd carefully: how to spot and avoid a homoglyph attack
Scam emails are increasingly using psychological tricks, such as using near-identical URLs like miÑrosoft.comYou’ve read the email carefully and it looks legitimate. The link it asks you to click on has none of the usual red flags: there are no weird numbers or extra parts to the URL. You feel safe to proceed.But if you…
-
Staatliche Akteure, OT-Systeme und KI: Europas Cyberlage erreicht die nächste Reifestufe
Die aktuelle Bedrohungslage zeigt eine neue Qualität staatlich geprägter Cyberoperationen: Angreifer agieren leiser, strategischer und zunehmend automatisiert. Für IT-Entscheider zählt daher nicht mehr nur die Abwehr einzelner Angriffe, sondern die Fähigkeit, Expositionen frühzeitig zu erkennen, kritische OT- und Edge-Systeme sichtbar zu machen und Cyberresilienz als kontinuierlichen Managementprozess zu verankern. Die fünf wichtigsten Management-Impulse: Sichtbarkeit… First…
-
Security Affairs newsletter Round 595 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of Its Test Environment AI Helps Hackers Hijack OpenAI Staff Accounts Through…
-
100.000 Dollar gestrichen – Intel stoppt offenbar Bug-Bounty-Prämien
Tags: bug-bountyIntel hat sein bisheriges Bug-Bounty-Programm eventuell ausgesetzt. Das neue Meldeprogramm lockt Sicherheitsforscher nicht mehr mit Geld. First seen on computerbase.de Jump to article: www.computerbase.de/news/wirtschaft/100-000-dollar-gestrichen-intel-stoppt-moeglicherweise-bug-bounty-praemien.99474 also interesting: Google Launches $250,000 kvmCTF Bug Bounty Program for KVM Exploits Microsoft launches $4M bug bounty challenge to secure AI, cloud Researchers Breach Software Supply Chain and Secure $50K Bug…
-
Google’s Gemini is the latest AI model to hack other companies
Google said Gemini had “acted appropriately” by ending each hack immediately. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/19/googles-gemini-is-the-latest-ai-model-to-hack-other-companies/ also interesting: Lowe’s employees phished via Google ads and AI generated webpages 17 hottest IT security certs for higher pay today Privacy Roundup: Week 4 of Year 2025 KI-gestützte Angriffe machen deutschen Betrieben zu schaffen
-
Hackers Crack Flock Camera, Expose 1.6M Images in 21 Days
Hackers physically compromised a Flock camera and found an encryption key, 27,000 clips, and 1.6 million images generated in 21 days. The post Hackers Crack Flock Camera, Expose 1.6M Images in 21 Days appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-flock-camera-hack-1-6m-images/ also interesting: Privacy Roundup: Week 9 of Year 2025 Cybersecurity…
-
UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day
The UAE faced 640,000 cyberattacks in one day, its cyber chief says, highlighting risks from unpatched software, ransomware, and deepfakes. The post UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-uae-640000-cyberattacks-deepfakes-ransomware-emea/ also interesting: 8 biggest cybersecurity threats manufacturers face Cybercrime Inc.:…
-
Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook
Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data. The post Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-passkey-phishing-mfa-device-code/ also interesting: 8 Cyber Predictions for 2025: A CSO’s Perspective…
-
Viral AI actress’ hotline face-scans every caller, watches their mood
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her “Talking Tilly” video call service face-scans every caller for an 18+ age check, senses callers’ moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. First seen on bleepingcomputer.com Jump…
-
‘Nudify”-Apps: Was tun, wenn jemand ein gefälschtes Nacktbild von Ihnen erstellt?
Tags: unclassifiedGanz gleich, ob Sie selbst betrifft, Sie Eltern eines Opfers sind oder sich einfach nur Sorgen machen: Hier erfahren Sie, was Sie gegen gefälschte Nacktbilder tun können. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/privatsphare/nudify-apps-was-tun-wenn-jemand-ein-gefalschtes-nacktbild-von-ihnen-erstellt/ also interesting: Tipps von Faronics: So schützen sich kleine Firmen vor IT-Bedrohungen DigiCert to Revoke 83,000+ SSL Certificates Due to…
-
BragJack attacks hijack AI browser agents through malicious extensions
BragJack, a proof-of-concept attack from Forever Security’s Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/ also interesting: OAuth Identity Attack”Š”, “ŠAre your…
-
100.000 Dollar gestrichen – Intel stoppt möglicherweise Bug-Bounty-Prämien
Tags: bug-bountyIntel hat sein bisheriges Bug-Bounty-Programm eventuell ausgesetzt. Das neue Meldeprogramm lockt Sicherheitsforscher nicht mehr mit Geld. First seen on computerbase.de Jump to article: www.computerbase.de/news/wirtschaft/100-000-dollar-gestrichen-intel-stoppt-moeglicherweise-bug-bounty-praemien.99474 also interesting: Bug-Bounty-Programm trifft KI ein zweischneidiges Schwert Bug-Bounty-Programm trifft KI ein zweischneidiges Schwert Hardware Hackers Urge Vendor Engagement for Security Success Psychische Belastung – cURL stoppt Bug-Bounty-Programm wegen KI-generierten Falschmeldungen
-
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/ also interesting: Top 10 Cybersecurity Predictions for 2026 Cybersecurity Snapshot:…
-
100.000 Dollar gestrichen? – Intel stoppt möglicherweise Bug-Bounty-Prämien
Tags: bug-bountyIntel hat sein bisheriges Bug-Bounty-Programm eventuell ausgesetzt. Das neue Meldeprogramm lockt Sicherheitsforscher nicht mehr mit Geld. First seen on computerbase.de Jump to article: www.computerbase.de/news/wirtschaft/100-000-dollar-gestrichen-intel-stoppt-moeglicherweise-bug-bounty-praemien.99474 also interesting: Channel Brief: Tata Launches GenAI Aggregator, Apple Balks at Kaspersky Bug Bounty OpenAI Offers Up to $100,000 for Critical Infrastructure Vulnerability Reports OpenAI Bug Bounty Program Increases Top Reward…
-
100.000 Dollar gestrichen? – Intel stoppt möglicherweise Bug-Bounty-Prämien
Tags: bug-bountyIntel hat sein bisheriges Bug-Bounty-Programm eventuell ausgesetzt. Das neue Meldeprogramm lockt Sicherheitsforscher nicht mehr mit Geld. First seen on computerbase.de Jump to article: www.computerbase.de/news/wirtschaft/100-000-dollar-gestrichen-intel-stoppt-moeglicherweise-bug-bounty-praemien.99474 also interesting: Channel Brief: Tata Launches GenAI Aggregator, Apple Balks at Kaspersky Bug Bounty OpenAI Offers Up to $100,000 for Critical Infrastructure Vulnerability Reports OpenAI Bug Bounty Program Increases Top Reward…
-
100.000 Dollar gestrichen? – Intel stoppt möglicherweise Bug-Bounty-Prämien
Tags: bug-bountyIntel hat sein bisheriges Bug-Bounty-Programm eventuell ausgesetzt. Das neue Meldeprogramm lockt Sicherheitsforscher nicht mehr mit Geld. First seen on computerbase.de Jump to article: www.computerbase.de/news/wirtschaft/100-000-dollar-gestrichen-intel-stoppt-moeglicherweise-bug-bounty-praemien.99474 also interesting: Channel Brief: Tata Launches GenAI Aggregator, Apple Balks at Kaspersky Bug Bounty OpenAI Offers Up to $100,000 for Critical Infrastructure Vulnerability Reports OpenAI Bug Bounty Program Increases Top Reward…
-
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/ also interesting: FBI: Fake Ransomware Attack Claims Sent to US Executives via Snail Mail Alliances between…
-
Google Gemini also Broke Out of Its Test Environment
Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity test in May. The incident is the first publicly known case in which a Google…
-
Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon’s annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in First…
-
AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum
AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s…
-
Google Gemini AI Hacked 3 Real Companies After Cybersecurity Test Exposed It to Internet
Google has confirmed that its Gemini artificial intelligence model accidentally accessed protected systems belonging to three real companies during a cybersecurity evaluation. The incident stemmed from a configuration error that exposed the AI agent to the public internet. Google Gemini AI Hacked This situation highlights how autonomous AI systems can breach intended testing boundaries when…
-
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.”SolarWinds…
-
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic’s Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.The chain began with a bug in the software that runs OpenAI’s public help forum and moved through a weakness in…
-
Calling viral AI actress Tilly Norwood? Agree to a face scan first
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her “Talking Tilly” video call service face-scans every caller for an 18+ age check, senses callers’ moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. First seen on bleepingcomputer.com Jump…
-
KI-Sicherheit in Unternehmen: Warum Governance, Sichtbarkeit und Deepfake-Abwehr jetzt entscheidend sind
Deutsche Unternehmen fühlen sich beim Schutz ihrer KI-Systeme gut vorbereitet doch die Erkennung böswilligen oder unerwarteten KI-Verhaltens bleibt deutlich zurück. Der TrendAI-Report zeigt eine gefährliche Lücke zwischen Governance-Anspruch und operativer Sicherheitsrealität. Für Entscheider wird KI-Sicherheit damit zur Managementaufgabe: Sichtbarkeit, Testing, Deepfake-Abwehr und wirksame Eingriffsmechanismen müssen von Anfang an Teil jeder Enterprise-AI-Strategie sein. Management Summary… First…
-
Digitale Infrastruktur: Warum Rechenzentren mehr Resilienz gegen Cyberrisiken und Energieengpässe brauchen
Digitale Infrastrukturen werden zum Rückgrat von Wirtschaft, KI und vernetzten Geschäftsmodellen. Doch mit dem Wachstum von Rechenzentren steigen auch die systemischen Risiken: Cyberangriffe, Energieengpässe, Klimafolgen und Lieferkettenstörungen wirken immer häufiger zusammen. Die Studie von Economist Enterprise und FM zeigt, dass Unternehmen zwar in Resilienz investieren, aber komplexe Krisenszenarien noch zu selten ganzheitlich testen [1]. Management……
-
Forget the AI Slowdown”, the Vulnerability Explosion Is Already Happening
AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws. First seen on wired.com Jump to article: www.wired.com/story/kernel-panic-ai-vulnerability-explosion/ also interesting: MCP is fueling agentic AI, and introducing new security risks New K2 Think AI Model Falls to Jailbreak in…
-
Google bestätigt: KI-Modell Gemini knackt drei echte Firmen
Bei einem Sicherheitstest sollte Googles KI eigentlich nur fiktive Firmen angreifen. Stattdessen ist sie bei drei echten Unternehmen eingebrochen. First seen on golem.de Jump to article: www.golem.de/news/google-bestaetigt-ki-modell-gemini-knackt-drei-echte-firmen-2609-213241.html also interesting: Google’s AI Watermarks Will Identify Deepfakes More evidence your AI agents can be turned against you Google launches Gemini Agent Platform, eighth-generation TPUs Thales named a…
-
Google bestätigt: KI-Modell Gemini knackt drei echte Firmen
Bei einem Sicherheitstest sollte Googles KI eigentlich nur fiktive Firmen angreifen. Stattdessen ist sie bei drei echten Unternehmen eingebrochen. First seen on golem.de Jump to article: www.golem.de/news/google-bestaetigt-ki-modell-gemini-knackt-drei-echte-firmen-2609-213241.html also interesting: Google’s AI Watermarks Will Identify Deepfakes More evidence your AI agents can be turned against you Google launches Gemini Agent Platform, eighth-generation TPUs Thales named a…
-
Google bestätigt: KI-Modell Gemini knackt drei echte Firmen
Bei einem Sicherheitstest sollte Googles KI eigentlich nur fiktive Firmen angreifen. Stattdessen ist sie bei drei echten Unternehmen eingebrochen. First seen on golem.de Jump to article: www.golem.de/news/google-bestaetigt-ki-modell-gemini-knackt-drei-echte-firmen-2609-213241.html also interesting: Google Debuts Private AI Compute to Protect Data in Cloud AI 6 key takeaways from RSA Conference 2026 Securing RAG pipelines in enterprise SaaS ‘Cordyceps’: Mushrooming…
-
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Google’s Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also…
-
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.”Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote First seen on…
-
AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes
Researchers have identified a new Android banking Trojan called RatHat that utilizes artificial intelligence to automate device compromise and steal financial credentials, PINs, and one-time passcodes. Zimperium’s zLabs researchers analyzed this malware, which represents a significant evolution in Android threats. AI-Powered RatHat Android Trojan Unlike traditional malware that relies on fixed scripts, RatHat offers a…
-
North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto
North Korean threat actors, known as WaterPlum (also referred to as Contagious Interview), have infected at least 30,000 devices in over 100 countries by luring software developers and IT professionals into malicious job interviews. This campaign specifically targets web developers, freelancers, blockchain specialists, and cryptocurrency professionals. The attackers use persuasive recruitment messages that mimic legitimate…
-
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on TanStack, in which malicious versions of…
-
Sicherheitskontrolle am Flughafen: Deine Rechte beim Smartphone
Tags: unclassifiedDarf man mein Smartphone bei der Sicherheitskontrolle des Flughafens beschlagnahmen? Darf man mich dazu zwingen, es zu entsperren? First seen on tarnkappe.info Jump to article: tarnkappe.info/tutorials/sicherheitskontrolle-am-flughafen-deine-rechte-beim-smartphone-333590.html also interesting: McDonald’s IT systems outage impacts restaurants worldwide Get a Lifetime Subscription of FastestVPN for just $32 DeFi Development Corp. Buys 172,670 SOL, Hits $100M Treasury Gesetzentwurf zu…
-
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerabilities are listed below – CVE-2025-39682 (CVSS score: 9.8) – An improper check for unusual or exceptional conditions vulnerability in the TLS receive path First…

