Tag: control
-
FireTail State of AI Security 2026: Adoption Has Outpaced Control FireTail Blog
Tags: access, ai, control, credentials, data, group, intelligence, jobs, leak, risk, threat, tool, vulnerabilityAug 17, 2026 – Ayush Sethi – What your workforce’s AI prompts reveal in aggregate Most AI security controls judge one prompt at a time. We built Topics to read the layer above them, where a workforce’s prompts add up into a pattern that no single message shows.Someone in your legal team pastes a contract…
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
Water Water Everywhere Possible Iranian Attack to Water Infrastructure
In recent days, a multistate cyber campaign has reached the programmable controllers that run American water and wastewater systems, depriving operators of monitoring and control and, in some cases, contributing to loss of pressure and flooding. Beginning July 27, the FBI and Environmental Protection Agency said, utilities in at least seven states reported intrusions into..…
-
Copeland XWEB Pro Vulnerabilities Let Attackers Gain Root Access and Manipulate Refrigeration Systems
Security researchers have discovered 23 vulnerabilities in Copeland’s XWEB Pro commercial refrigeration controllers, with 21 rated as high severity. These vulnerabilities could allow unauthenticated attackers to gain root-level remote code execution and control connected cooling equipment. Claroty’s Team82 found that an attacker could exploit a combination of authentication flaws, predictable administrator credentials, and command-injection vulnerabilities…
-
Critical Rancher Flaw Lets Authenticated Users Gain Full Admin Access to All Managed Clusters
A critical privilege-escalation vulnerability in SUSE Rancher could allow a low-privilege, authenticated user to gain administrative control of the Rancher management plane and every downstream Kubernetes cluster it manages. This issue is tracked as CVE-2026-44945 and GHSA-v584-7w32-jwpq, affecting Rancher releases 2.11.0 through 2.11.15, 2.12.0 through 2.12.11, 2.13.0 through 2.13.7, and 2.14.0 through 2.14.1. Rancher has…
-
Ransomware gangs don’t need control system access to disrupt industrial production
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/11/industrial-ransomware-attacks-q2-2026/
-
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment.The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active…
-
New Abyssos RAT Hijacks Browser Sessions, Steals Credentials and Gives Attackers Remote VNC Access
Abyssos, a modular C++ remote-access trojan that combines credential theft, browser-session hijacking, file exfiltration and hidden VNC control in a single post-compromise framework. Technical analysis from ThreatLabz indicates that Abyssos is designed for hands-on intrusion activity rather than opportunistic, single-purpose theft. The most concerning feature is its hidden VNC capability. The HVNC_START command opens a…
-
Red Hat Kubernetes Flaw Allows Attackers to Escalate Privileges to Cluster-Admin
Red Hat has disclosed a privilege-escalation vulnerability in Red Hat Advanced Cluster Management for Kubernetes (ACM) that could allow a low-privileged user to gain full cluster-admin control of an affected hub cluster. This vulnerability is tracked as CVE-2026-10090 and affects the Application Subscription controller, specifically the multicluster-operators-subscription. It has a CVSS v3.1 score of 9.9…
-
Obsidian Secures $85M to Control AI Agents in SaaS Apps
CEO Hasan Imam Says AI Agents Are Already Modifying and Deleting Enterprise Data. Obsidian Security raised $85 million at a $1.1 billion valuation to expand real-time monitoring and enforcement as enterprises give autonomous AI agents access to sensitive data and the ability to modify or delete information inside SaaS and other third-party applications. First seen…
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
Shipping 1050× More Code? Watch This Webinar on Securing AI-Speed Development
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed.When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing…
-
“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls
Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ghostjacking-ai-gents-access/
-
OpenAI’s Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI has announced that it’s pausing some “internal activities” involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity.In response to the discovery, the AI upstart said it’s implementing security controls for higher-capability models and associated activities, such as isolated First seen…
-
71% of CISOs spend 10+ hours on board reports
Boards want evidence that security controls and architecture reduce business risk, expressed in terms of resilience, consequence, and decision relevance. Translating technical … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/ciso-board-communication-gap-report/
-
Continuous Control Monitoring vs Annual Testing – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/continuous-control-monitoring-vs-annual-testing-kovrr/
-
Secure SDLC principles explained for SaaS founders
Key takeaways Secure SDLC helps SaaS founders reduce breach risk, rework, and customer trust damage by building security into normal delivery. The most effective controls are simple and repeatable across planning, design, build, test, release, and maintenance. Small teams can make real progress with clear ownership, peer review, automated checks, and a basic release checklist….…
-
Detecting Cobalt Strike beacons with JA3 and JARM fingerprinting
Cobalt Strike remains a common post-compromise tool in intrusion sets because it gives an operator a flexible command-and-control channel, tasking framework, and a way to blend into normal network traffic. For defenders, the challenge is not just spotting malware on an endpoint. It is identifying the beaconing pattern that sits behind the traffic, especially when……
-
Someone Changed the Password on a Water Utility’s PLC
More than 30 Minnesota water systems lost control of their equipment in a single weekend, and the campaign has since reached at least a dozen states. The connections attackers used were not carelessness. They were put there by people trying to keep water flowing. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/someone-changed-the-password-on-a-water-utilitys-plc/
-
18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Root and Escape Containers
SCTPhantom, tracked as CVE-2026-64564, is a high-severity Linux kernel use-after-free vulnerability in the Stream Control Transmission Protocol (SCTP) Dynamic Address Reconfiguration implementation. Researchers at Tencent Zhuque Lab’s Corvus AI project reported that a local attacker could leverage the flaw to escalate privileges to root and, in certain configurations, to escape from containers to the host.…
-
Mapping One Control Set to Multiple Frameworks – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/mapping-one-control-set-to-multiple-frameworks-kovrr/
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
ThreatLabz 2026 Report: Frontier AI and Enterprise Readiness
Tags: access, ai, attack, authentication, breach, cisa, ciso, control, credentials, cyberattack, data, data-breach, endpoint, exploit, flaw, governance, identity, Internet, kev, login, malicious, privacy, radius, resilience, strategy, switch, threat, update, vpn, vulnerability, zero-trustThe BreachIt was 9:14 AM when the CISO’s VPN connection momentarily dropped, something that normally wouldn’t cause any concern. What he couldn’t see was that attackers had already exploited a pre-authentication flaw in the VPN appliance itself, gaining access before any login ever occurred. From there, they extracted stored credentials, forged an identity as his…
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
15 AI Security Lessons From Black Hat and Ai4 2026
Black Hat and Ai4 2026 highlighted gaps in AI agent security, identity controls, software supply chains, monitoring, and incident response. The post 15 AI Security Lessons From Black Hat and Ai4 2026 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-black-hat-ai4-2026-ai-security-takeaways/
-
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email.”The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic, First seen on thehackernews.com…
-
Deemed Export, Deemed Impossible: The Government Discovers That AI Has No Border
Anthropic’s reported AI model shutdown highlights how U.S. export controls could collide with frontier AI, cybersecurity, identity management and global cloud access. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/deemed-export-deemed-impossible-the-government-discovers-that-ai-has-no-border/
-
Contrast Security Launches CVE Shield for Runtime Exploit Protection
Contrast Security has launched CVE Shield, a runtime control that detects, monitors and blocks exploitation of known vulnerabilities in production applications and APIs while teams work on permanent fixes. Announced July 29 ahead of Black Hat USA 2026, CVE Shield operates inside running applications and uses a microsandbox for each supported CVE. Contrast said the..…
-
Check Point Puts AI Traffic Controls Into Its Existing Firewalls
Check Point has launched an AI Network Firewall that brings visibility and enforcement for AI applications, agents and Model Context Protocol traffic into the physical and virtual firewalls organizations already operate. Introduced July 30 ahead of Black Hat USA 2026, the product is delivered through Check Point’s AI Defense Plane and firewall software release R82.20……

