Tag: communications
-
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded First…
-
Cyber Op Targets South Korean Media & Automotive Sectors
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive
-
House Rejects Renewal of FISA 702 Surveillance Program
The House rejection of a short-term FISA Section 702 extension renews the debate over foreign intelligence, warrantless searches of Americans’ communications, privacy and cybersecurity governance. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/house-rejects-renewal-of-fisa-702-surveillance-program/
-
CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance urging service providers to deliver timely, accurate, and transparent communications during major information technology (IT) and operational technology (OT) outages. The document, titled ‘Communicating Under Pressure: Best Practices for Service Providers’, was developed with the Federal Bureau of Investigation (FBI) and international partners.…
-
CISA head says agency must change quickly to prevent the ‘worst that could happen’
CISA’s cybersecurity, infrastructure security and emergency communications divisions are among the priorities as the agency fills vacancies created at the beginning of the Trump administration, acting director Nick Andersen says. First seen on therecord.media Jump to article: therecord.media/cisa-hiring-nick-andersen-warning
-
A New AI Vulnerability Exposes the Security Gap That PQC Won’t Fix
In a previous article, we discussed why PQC compliance does not equal architectural resilience. In this post, we’ll explore why organizations must be prepared to protect identity, context, communications, and paths not merely ciphertext. What a New AI Vulnerability… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/a-new-ai-vulnerability-exposes-the-security-gap-that-pqc-wont-fix/
-
QA: Viasat Tests Satellite Resilience With AI as Cyber Expert Warns an Attack Could ‘Hurt an Entire Country’
Tags: ai, attack, communications, country, cyber, data-breach, network, resilience, russia, ukraine, vulnerabilityAn AI-assisted platform has been used to test whether Viasat’s satellite communications links can meet operational thresholds under interference and adversarial jamming. Announced this month, the work with Atalanta has renewed scrutiny of the vulnerabilities exposed by Russia’s 2022 attack on Viasat’s KA-SAT network, which disrupted communications across Ukraine and several European countries. Gil Baram,…
-
Daily OT Security News: September 3, 2026
Multinational joint guidance for service providers on IT and OT outage communications On September 2, 2026 the Canadian Centre for Cyber Security (Canada) joined CISA, ASD’s ACSC, NCSC”‘NZ, NCSC”‘UK and the FBI to publish joint guidance addressing IT and OT… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-3-2026/
-
SkySwitch launches native AI agent, bringing enterprise AI communications to every white-label partner
First seen on scworld.com Jump to article: www.scworld.com/news/skyswitch-launches-native-ai-agent-bringing-enterprise-ai-communications-to-every-white-label-partner
-
Leaked Russian Cyber-Operations Training Materials
This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security….The reporting also linked a 2024… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/leaked-russian-cyber-operations-training-materials/
-
Leaked Russian Cyber-Operations Training Materials
This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security….The reporting also linked a 2024… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/leaked-russian-cyber-operations-training-materials/
-
SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications
A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections. Raw-packet activation, DNS-based tasking support, VMware VMCI communications, named-pipe capabilities, and in-memory payload execution. No threat actor, victim, delivery chain, or live campaign has yet been attributed to the malware. SLEEPWALKER is an unsigned 64-bit Windows DLL…
-
Hackers Use Ethereum Smart Contracts to Keep New GoCaracal Malware Connected
Dark Caracal-linked operators are using Ethereum smart contracts as a resilient fallback mechanism for a newly identified Go-based malware framework called GoCaracal. Arctic Wolf Labs uncovered the framework while investigating a targeted intrusion in June 2026 against a communications organization in Venezuela. The company assesses, with medium confidence, that the activity is tied to Dark…
-
Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback
Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications. Dark Caracal is back with new malware and the same hunting grounds. Arctic Wolf Labs researchers link a June 2026 intrusion against a communications organisation in Venezuela to the Lebanon”‘linked espionage group, and says it deployed a…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
TP-Link Kasa Smart Home Flaw Lets Attackers Forge Control Messages and Take Control of Devices
TP-Link has revealed a critical vulnerability in Kasa smart home devices that could allow an attacker on the same local network to intercept, replay, or forge control messages, potentially manipulating affected products. This issue, tracked as CVE-2026-76784, arises from inadequate cryptographic protections in the protocol used for local communications among Kasa devices. TP-Link has assigned…
-
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control First seen…
-
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela.GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds browser data theft, keylogging, remote desktop control First seen…
-
Ransomware surges as criminals deploy AI tools
Research from NCC Group and a partnership between Axis Communications and Palo Alton underline how artificial intelligence is impacting customers First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366649752/Ransomware-surges-as-criminals-deploy-AI-tools
-
Three 10.0 security flaws fixed across Ubiquiti’s UniFi line
The communications product company disclosed 22 total Wednesday, all but one of which was rated “critical” at 9.0 or higher. First seen on cyberscoop.com Jump to article: cyberscoop.com/ubiquiti-unifi-critical-vulnerabilities-patched/
-
CISA orders feds to patch actively exploited TrueConf Server flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/
-
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: TrueConf Server is an on-premises video conferencing and unified communications platform developed by TrueConf. Organizations can deploy it on their…
-
Quantum-Safe Isn’t Cyber-Safe
Tags: access, ai, api, breach, communications, compliance, computer, computing, credentials, cryptography, cyber, data, defense, encryption, exploit, flaw, google, group, ml, openai, password, radius, risk, threat, update<div cla In the same week federal agencies began scoping migrations under the White House’s new Post-Quantum Cryptography Executive Order, a group of academic researchers published a paper that, on its face, had nothing to do with quantum computing at all. It described a flaw in how three of the most security-conscious engineering organizations on…
-
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai’s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a…

