Tag: control
-
Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data-Exfiltration Infrastructure
More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control, credential theft, staging, and chunked data exfiltration. The investigation shows why defenders should prioritize repeatable endpoint and network behavior over static domain-based detections. Observed executions originate from interactive zsh sessions and use curl to fetch payloads from…
-
When the AI Goes Rogue: Who Goes to Jail”, and Who Pays?
When autonomous AI agents hack without explicit human instructions, who is legally responsible? The answer may depend on intent, foreseeability, control and safeguards. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/when-the-ai-goes-rogue-who-goes-to-jail-and-who-pays/
-
What Cloud Security Actually Controls
First seen on scworld.com Jump to article: www.scworld.com/tech-explainer/what-cloud-security-actually-controls
-
Control Plane Gaps Create Invisible Cloud Risk
First seen on scworld.com Jump to article: www.scworld.com/risk-advisory/risk-advisory-control-plane-gaps-create-invisible-cloud-risk
-
Cloud Governance and Assurance: Evidencing Control Effectiveness Across Providers
First seen on scworld.com Jump to article: www.scworld.com/implementation-guides/cloud-governance-and-assurance-evidencing-control-effectiveness-across-providers
-
Fortinet Buys Virtue AI for Agent and Model Runtime Controls
Acquisition Adds Offensive and Defensive Testing for Agents and Models. Fortinet acquired Virtue AI’s technology to extend FortiAIGate with red- and blue-team testing, runtime controls and policy enforcement for AI agents, models, skills and MCP services as enterprises deploy more autonomous workflows. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/fortinet-buys-virtue-ai-for-agent-model-runtime-controls-a-32592
-
Hugging Face Breach Raises Big Questions About AI Security Controls
Adam Shostack, president of Shostack & Associates and an affiliate professor at the University of Washington, talks with the Dark Reading News Desk about why he was blown away by OpenAI’s revelations regarding the Hugging Face attack. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b
-
2,000 Hacked WordPress Sites Were Secretly Running a Global Crime Ring
A newly identified cybercrime operation dubbed StopAndProtect has been quietly running its entire criminal infrastructure through close to 2,000 hacked WordPress websites, according to new research from Check Point. Rather than relying on dedicated command-and-control servers, which are relatively easy for defenders to identify and take down, the group behind StopAndProtect compromised thousands of legitimate…
-
Your Controls Block Known Attacks. What About the Behavior?
Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security’s Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/your-controls-block-known-attacks-what-about-the-behavior/
-
NASA Ground Control Software Flaw Enables Unauthenticated Commands
Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nasa-ground-control-software-flaw/
-
FedRAMP 20x Modernization: Continuous Monitoring Audits
FedRAMP 20x represents a fundamental evolution in cloud authorization, replacing static annual assessments with dynamic, real-time continuous monitoring audits that demand integrated governance and automated evidence pipelines. This modernization requires organizations to embed NIST 800-53 controls into operational workflows rather than treating compliance as a periodic checkpoint. FedRAMP Continuous Monitoring Audits Under 20x Modernization In”¦…
-
10 Integrated Risk Management Strategies with Continuum GRC in 2026
Tags: business, ciso, compliance, control, cybersecurity, governance, grc, risk, risk-management, strategy, threatIn 2026, organizations face an increasingly complex threat landscape where siloed risk management approaches fail to address the interoperability demands of modern regulatory frameworks. Integrated Risk Management has emerged as the essential discipline for CISOs and compliance officers seeking to unify cybersecurity controls, audit processes, and business objectives under a single governance model. Continuum GRC”¦…
-
The Governance Gaps Holding Back Enterprise Agentic Networks
Enterprise AI is moving from individual assistants to interconnected networks of autonomous agents. That creates a new governance challenge: knowing which agent acted, why it acted, what permissions it had and who authorized it. Identity, runtime policy, delegation controls and auditability are quickly becoming foundational AI security requirements. First seen on securityboulevard.com Jump to article:…
-
Broken Access Control Is Still Winning: 2025 OWASP Data
Key Takeaways Broken access control remains the number one category in OWASP’s Top 10 2025 release, the fourth consecutive edition where it has held the top spot. Security misconfiguration jumped from fifth place to second, driven largely by cloud configuration complexity rather than code level bugs. OWASP’s own reported average incidence rate for broken access…The…
-
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Tags: control, credentials, cybersecurity, framework, hacker, infrastructure, microsoft, network, serviceCybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.”TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,” Ontinue said in a technical report shared with The Hacker News. “Tasking flows through SharePoint Online file First seen on thehackernews.com Jump to article:…
-
LLMs and Contextual Integrity
I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs”: Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However,…
-
Securing Model Context Protocol (MCP) tool integrations
Model Context Protocol, or MCP, is becoming a practical way to connect large language models to internal tools, data sources, and workflows. For security teams, that changes the control problem. A chat-only assistant can still leak information or be manipulated, but an MCP-enabled assistant can also trigger actions in business systems, query sensitive data, and……
-
Securing Model Context Protocol (MCP) tool integrations
Model Context Protocol, or MCP, is becoming a practical way to connect large language models to internal tools, data sources, and workflows. For security teams, that changes the control problem. A chat-only assistant can still leak information or be manipulated, but an MCP-enabled assistant can also trigger actions in business systems, query sensitive data, and……
-
Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, the toolkit combines abuse of accessibility, stealthy remote control, credential-stealing overlays, SMS interception, and device reconnaissance to enable direct account takeover and cryptocurrency…
-
From Demo to Production: Scaling Continuous Control Monitoring with ServiceNow and Atlassian
Enterprises answered the question: is my software actually working? about a decade ago. Not by hiring more people to read logs but by instrumenting the data plane once and letting anyone query it. Observability became infrastructure, and the people who used to read logs went and solved harder problems. GRC has never had that moment….The…
-
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s FortiGuard Labs disclosed Evooo1Bot in mid-August, a previously undocumented Linux botnet that’s been active since July 2026. The bot borrows Mirai’s DDoS engine but adds encrypted command-and-control communications, an SSH brute-force scanner, a…
-
C2Looper v2 Uses GitHub Repositories as Full CommandControl Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver tasks, receive results, maintain beacon records, and host payloads. ThreatLabz identified the malware in July 2026 and assesses, with low-to-medium confidence, that it is delivered through…

