Tag: attack
-
Suspected Iranian Campaign Disrupts Minnesota Water Systems
U.S. and Minnesota investigators believe Iranian hackers were likely responsible for a cyberattack on roughly 36 municipal water systems in Minnesota, The New York Times reported Thursday. Officials cautioned that the attribution remains a preliminary assessment and could change as investigators gather more evidence. The attacks occurred Monday and were focused on technology that municipalities..…
-
Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure. First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/minnesota-water-utility-attacks-expose-sector-cyber-risks
-
Why brand impersonation is becoming an initial access vector
Brand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites, including sites run by Harvard, Oxford, and DuckDuckGo. They used a fake Cloudflare page to trick visitors into running a ClickFix attack that installed malware. Researchers tracing…
-
AI Harnesses Burst With Potential Exploit Opps
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/ai-harnesses-potential-exploit-opps
-
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.The defining aspect of the attack is that bogus macOS software…
-
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/
-
Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents
Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and…
-
Authorities investigating a coordinated cyberattack against Minnesota water systems
The two-day attack comes days after federal officials warned of state-linked threat groups targeting a wider set of industrial devices. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/authorities-investigating-a-coordinated-cyberattack-against-minnesota-water/826427/
-
Thousands of Data Center Controllers Open to Takeover
A host of Internet-exposed remote hardware management processors are subject to offline password-cracking attacks, and adversaries have taken note. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
-
Flaw From 2002 Exposes Data Centers to Server Takeover
Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks, and adversaries have taken note. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover
-
Coca-Cola Confirms Data Theft as Fairlife Ransomware Attack Escalates
Coca-Cola has confirmed data was stolen in the ransomware attack on Fairlife after the Anubis gang published allegedly stolen files, escalating the incident. The post Coca-Cola Confirms Data Theft as Fairlife Ransomware Attack Escalates appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-coca-cola-confirms-data-theft-fairlife-ransomware/
-
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128.The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic’s released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on…
-
Microsoft launches agentic security platform designed to combat AI-based attacks
The rollout comes amid growing concerns about the ability of hackers to launch campaigns using autonomous methods.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-agentic-security-platform-ai-attacks/826365/
-
Is Your SSO Protected Against Modern Credential Attacks?
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/is-your-sso-protected-against-modern-credential-attacks/
-
Fake Claude Code Installer Delivers MacSync macOS Infostealer Through Google Ads
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting software vulnerabilities. The attack highlights a growing shift toward trust-based compromise, where attackers weaponize authentic platforms such as Google Ads and claude.ai…
-
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
-
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
-
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments. Despite being disrupted under Operation Olympus Blade, which led to the seizure of…
-
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,…
-
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/coca-cola-subsidiary-fairlife-data/
-
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR’s Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/ir-trends-q2-2026/
-
New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal…
-
Coca-Cola confirms hackers stole data in Fairlife ransomware attack
Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/coca-cola-fairlife-dairy-subsidiary-ransomware-attack/
-
Tengu Mirai Botnet Uses Watchdog Reboots and Binary Bricking to Resist Removal
Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence, evasion, and multi-functional attack capabilities. Unlike legacy Mirai variants, Tengu employs a hybrid C2 model that blends plaintext and encrypted communications. Initial registration and heartbeat messages are transmitted in cleartext, while…
-
Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks
A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) operations. Dysphoria’s evolution has been unusually aggressive, transitioning from early jackskid-derived variants to more sophisticated fbot-based implementations within weeks. Initial samples observed in March 2026…
-
GitHub and PyPI implement new security measures against supply-chain attacks
First seen on scworld.com Jump to article: www.scworld.com/brief/github-and-pypi-implement-new-security-measures-against-supply-chain-attacks
-
Steam forums used for ClickFix cryptominer attacks
Tags: attackFirst seen on scworld.com Jump to article: www.scworld.com/brief/steam-forums-used-for-clickfix-cryptominer-attacks
-
Phishing attacks on insurance companies evolve to real-time account hijacking
First seen on scworld.com Jump to article: www.scworld.com/brief/phishing-attacks-on-insurance-companies-evolve-to-real-time-account-hijacking
-
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
-
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/

