Tag: control
-
MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network patterns to steal credentials, browser data, cloud access keys, SSH material, and sensitive user files. Earlier research by RST Cloud identified MacSync infrastructure and observed command-and-control replacement after public disclosure. Microsoft’s subsequent telemetry-led…
-
NCSC Urges Stronger Controls for Agentic AI Systems
NCSC urged sandboxing, oversight and tight access controls for autonomous AI agents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-stronger-controls-agentic-ai/
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
AWS limits AI agents’ data access, even when manipulated
AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/aws-ai-agents-access-controls/
-
Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE
Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code execution (RCE) flaw in the Splunk MCP Server app. The vulnerabilities encompass deserialization, access control, server-side request forgery (SSRF), denial-of-service, certificate validation, and information disclosure. Tracked as SVD-2026-0808 and published on August 19, 2026, the…
-
Aeternum Operators Use Polygon Smart Contracts to Rotate Malware C2 Domains Dynamically
Aeternum operators are abusing Polygon smart contracts as a decentralized dead-drop resolver, allowing malware to retrieve and rotate command-and-control (C2) domains without depending on conventional attacker-owned servers. The approach turns a public blockchain into resilient C2 infrastructure that is substantially harder to disrupt through domain seizures, hosting takedowns, or sinkholing. Rather than contacting a fixed…
-
Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level
Adelaide, Australia, August 19th, 2026, CyberNewswire Independent assessment provides Australian organisations with additional evidence when evaluating application control for sensitive, government, defence and critical infrastructure environments. Airlock Digital, a global provider of application control and allowlisting solutions, today announced that it has completed an independent Information Security Registered Assessors Program (IRAP) assessment at the PROTECTED…
-
Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level
Adelaide, Australia, August 19th, 2026, CyberNewswire Independent assessment provides Australian organisations with additional evidence when evaluating application control for sensitive, government, defence and critical infrastructure environments. Airlock Digital, a global provider of application control and allowlisting solutions, today announced that it has completed an independent Information Security Registered Assessors Program (IRAP) assessment at the PROTECTED…
-
SOC 2 + AI Controls: Strengthen Reports with Risk Audits
In 2026, organizations integrating artificial intelligence into core operations face a critical gap: traditional SOC 2 audits often overlook the unique risks introduced by AI systems, leaving reports incomplete and compliance efforts vulnerable to regulatory scrutiny. By expanding SOC 2 assessments with dedicated AI controls and integrated risk audits, firms can produce stronger, more defensible”¦…
-
NIST Frameworks and SOC 2 Reporting via Continuum GRC Services
As organizations navigate an increasingly complex regulatory environment in 2026, integrating NIST frameworks with SOC 2 reporting offers a strategic advantage that reduces audit fatigue while strengthening overall governance, risk, and compliance postures. Continuum GRC enables this interoperability through unified control mapping that aligns NIST SP 800-53, NIST SP 800-171 Rev 3, and CMMC 2.0″¦…
-
Blinde Flecken bei der Absicherung von KI-Rechenzentren
TrendAI veröffentlicht den Report ‘An Invisible Attack Surface: Thousands of Industrial Control Systems Exposed Near Data Centers”. Die Untersuchung zeigt: Während die Server von KI-Rechenzentren mit leistungsstarken Firewalls und Zero-Trust-Architekturen gesichert werden, bleibt eine andere Angriffsfläche oft unbeachtet die physische Gebäudetechnik, die Kühlung, Stromversorgung und Klimaregelung steuert. Forscher von TrendAI fanden 6.300 solcher Systeme, […]…
-
Why compliance does not guarantee cyber resilience
Cyber security has become one of the most audited and regulated areas of enterprise technology. Yet an organisation can satisfy every requirement on paper and still discover, during a real incident, that its systems, people or processes are not ready for the pressure that follows. Compliance can demonstrate that controls have been put in place;…
-
Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data-Exfiltration Infrastructure
More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control, credential theft, staging, and chunked data exfiltration. The investigation shows why defenders should prioritize repeatable endpoint and network behavior over static domain-based detections. Observed executions originate from interactive zsh sessions and use curl to fetch payloads from…
-
When the AI Goes Rogue: Who Goes to Jail”, and Who Pays?
When autonomous AI agents hack without explicit human instructions, who is legally responsible? The answer may depend on intent, foreseeability, control and safeguards. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/when-the-ai-goes-rogue-who-goes-to-jail-and-who-pays/

