Tag: communications
-
BlackCloak Expands Impersonation Protection to Executives’ Trusted Circles
BlackCloak is expanding its Impersonation Protection service with a “circle of trust” feature designed to help executives verify communications from the people closest to them. The company announced the capability ahead of Black Hat USA 2026 in Las Vegas. Impersonation Protection lets members authenticate phone calls, video meetings, emails, WhatsApp and Slack messages, texts, and..…
-
From Inspection to Authorization: Securing Networks for AI Agents
Tags: access, ai, api, business, ceo, cloud, communications, control, crowdstrike, cryptography, data, encryption, endpoint, finance, firewall, identity, infrastructure, login, network, office, risk, saas, service, usa, vpn<div cla An Industry Perspective By Rajiv Pimplaskar, CEO, Dispersive Holdings, Inc. Agentic AI changes the network security problem from inspection to authorization. As more traffic is generated by agents, models, and workloads operating at machine speed, the network has to make trust decisions continuously, evaluate policy in real time, revoke access automatically, and keep…
-
SharePoint Flaws Used to Hack Switzerland’s Federal IT Agency
Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue. Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that unknown attackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The FOITT said the unknown attackers…
-
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
The Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers got in. First seen on therecord.media Jump to article: therecord.media/swiss-bit-foitt-hacked-possibly-sharepoint-vulnerabilities
-
Police monitored phone data of BBC security editor Brian Rowan to identify confidential sources
Northern Ireland police monitored phone communications of former BBC security editor Brian Rowan after he wrote about a police and MI5 agent in Northern Ireland First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646575/Police-monitored-phone-data-of-BBC-security-editor-Brian-Rowan-to-identify-confidential-sources
-
UK court rejects Bahrain immunity claim in spyware case
The alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers, interception of communications conducted using the computers and use of the computers’ microphones and cameras to surveil the respondents,” according to the court opinion. First seen on therecord.media Jump to article: therecord.media/uk-court-rejects-bahrain-immunity-claim-spyware-case
-
Phantom Stealer Campaign Uses JavaScript and PowerShell to Steal Browser Credentials
Tags: business, communications, credentials, crypto, cyber, data, email, infection, malware, phishing, powershellA sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and cryptocurrency wallet information from victims. Documented by Seqrite, the campaign uses two distinct phishing themes that both lead to the same infection chain. One email impersonates UPS Forwarding Hub, referencing fake…
-
How Zero Networks Targets AI Agents With Microsegmentation
CEO Says Process-Level Controls Offer Deeper Visibility Than Network-Only Policies. Zero Networks debuted AI-focused microsegmentation that discovers AI agents, maps communications and enforces least-privilege controls, while CEO Benny Lakunishok said containment and process-level visibility are vital to limiting AI-driven lateral movement across enterprise and OT environments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-zero-networks-targets-ai-agents-microsegmentation-a-32283
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…
-
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hollowgraph-microsoft-calendars/
-
Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites
A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB. The malware, dubbed HOLLOWGRAPH, was detailed…
-
Officials once again warn defenders that Russian hackers are targeting network devices
State-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care. First seen on cyberscoop.com Jump to article: cyberscoop.com/russian-fsb-cisco-joint-cybersecurity-advisory/
-
Forescout recognised by NATO for cybersecurity capabilities across IT and OT environments
Forescout Technologies Inc. has been added to the NATO Information Assurance Product Catalogue (NIAPC), marking formal recognition that the company’s cybersecurity platform meets NATO’s information assurance requirements for deployment across mission-critical defence environments. Maintained by the NATO Communications and Information Agency (NCIA), the NIAPC serves as a trusted catalogue of cybersecurity technologies that have been…
-
Canadian spy agency reports hacking three criminal groups in 2025
A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada’s Communications Security Establishment. First seen on therecord.media Jump to article: therecord.media/canada-cse-2025-cyber-operations-ransomware-drugs-extremism
-
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that’s designed to gain surreptitious access to a victim’s email correspondence via the Google API.”In this campaign, the attackers focused their attention on corporate email communications hosted on Gmail, targeting access compromise via APIs,” Kaspersky said in a detailed report…
-
Cisco finally confirms attackers exploiting Unified CM flaw
Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-finally-confirms-attackers-exploiting-unified-cm-flaw/
-
FCC Bans Chinese-Produced Network Equipment Linked to Cyber and Espionage Risks
The U.S. Federal Communications Commission (FCC) has implemented comprehensive new restrictions banning the import and marketing of Chinese-produced telecommunications and surveillance equipment identified as posing significant cybersecurity and espionage risks. Announced on June 26, 2026, this updated regulation addresses a longstanding loophole that previously allowed companies on the FCC’s “Covered List” to continue selling older,…
-
Russian Water System Hack Attempted to Turn Canada Dry
Hackers Said They Gained Access to Pumps, Chlorine Dosing and Pressure Settings. Canada’s Communications Security Establishment, the Maple Leaf version of the U.S. National Security Agency, refreshed a warning to the country’s water sector, revealing for the first time that Russian hackers attacked operational technology systems at a Quebec municipality utility last year. First seen…
-
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
Tags: attack, cisa, cisco, communications, cybersecurity, exploit, flaw, infrastructure, update, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks/
-
CISA Adds Actively Exploited Cisco Unified CM Flaws to KEV Catalog
Tags: cisa, cisco, communications, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, risk, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Cisco Unified Communications Manager (Unified CM) to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting active exploitation risks in enterprise communication environments. The newly listed flaw, tracked as CVE-2026-20230, involves a server-side request forgery (SSRF) vulnerability in Cisco Unified CM and Unified…
-
Malicious hackers exploit Cisco zero-day for highest access level at communications service provider
Mandiant detailed the incident in a blog post Wednesday, but it’s unclear who was behind it or if they managed to get broad visibility into the victim’s internal traffic. First seen on cyberscoop.com Jump to article: cyberscoop.com/cisco-sd-wan-zero-day-exploit-communications-provider/
-
German rail services resume after wireless communications outage
Deutsche Bahn said a nationwide disruption of railway services was tied to a malfunction in its 2G-based GSM-R communications system. First seen on therecord.media Jump to article: therecord.media/deutsche-bahn-railroad-gsmr-outage
-
Cisco Unified CM Flaw CVE-2026-20230 Actively Exploited in the Wild
Attackers exploit Cisco Unified CM flaw (CVE-2026-20230) allowing unauth HTTP requests to trigger SSRF, write files, and gain root access Cisco Unified Communications Manager has a serious vulnerability, tracked as CVE-2026-20230 (CVSS score of 8.6), that attackers are already exploiting. The flaw, caused by improper validation of certain HTTP requests, allows a remote attacker without…
-
Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)
CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/24/cisco-unified-cm-flaw-exploited-to-drop-webshells-cve-2026-20230/
-
Cisco Unified Communications Manager Flaw Exposes Systems to SSRF Attacks and Root Access
Cisco has disclosed a critical server-side request forgery (SSRF) vulnerability affecting its Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). This vulnerability could enable unauthenticated remote attackers to write files to the underlying operating system and potentially escalate their privileges to root. Identified as CVE-2026-20230 and documented in…
-
One Railway Radio Outage Stopped Trains Across Germany and Nobody Knew Why
A nationwide GSM-R outage stopped trains across Germany, exposing how one aging communications system can still bring an entire rail network to a halt At 10:30 PM on Tuesday June 23, Deutsche Bahn told passengers something that had never happened before for technical reasons: all trains across Germany were being held at their stations. The…
-
Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, remote First seen…
-
Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
A high-severity SSRF vulnerability, tracked as CVE-2026-20230, in Cisco Unified Communications Manager Server is now being exploited in attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/
-
Europe Seeks to Advance 6G Security, Privacy
EU Projects Seek to Protect Fast New Network, Secure Information Sharing. The mobile communications technology known as 6G still hasn’t been standardized and its earliest commercial deployments are years away. But Europe is investing early in preparing for the next telecoms revolution – and the inevitable cybersecurity problems bundled into it. First seen on govinfosecurity.com…
-
State Digital Surveillance Puts Foreign Travelers and Businesses at Risk Across 31 Countries
A new state-surveillance assessment finds that foreign travelers and business staff face high or very high digital risk in 31 countries, where governments increasingly use telecom interception, spyware, AI-enabled monitoring, and data aggregation with little meaningful oversight. The concern is not just espionage in the classic sense; it is the routine conversion of travel, communications,…

