Tag: control
-
Why embodied AI security extends beyond the robot
As AI moves into robots, autonomous vehicles and industrial systems, attackers are likely to target the credentials, cloud services and update channels that control them First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646180/Why-embodied-AI-security-extends-beyond-the-robot
-
Breach Roundup: Zelle Must Face NY Lawsuit Over Fraud
Also, Spain Fines 23andMe Over 2023 Data Breach. This week: Zelle can’t transfer out of a New York state lawsuit alleging poor controls over rampant fraud, a hack wiped Romania’s land registry, Spain fined 23andMe, Australia’s Origin Energy data breach and pirate World Cup streaming sites seized. Malware found hiding in Microsoft 365 calendars. First…
-
Top 10 Best Physical Security Penetration Testing Firms 2026
In an era dominated by cyber threats, the importance of physical security penetration testing often gets overshadowed. However, a robust security posture requires a holistic approach that addresses vulnerabilities in both the digital and physical realms. A determined attacker can bypass sophisticated cyber defenses simply by walking through an unlocked door, exploiting weak physical controls,…
-
Chaos ransomware deploys browser-based msaRAT to evade network detection
Cisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire command-and-control channel through the victim’s own Chrome or Edge browser. The malware…
-
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fedramp-rev5-is-ending-what-the-20x-transition-really-requires/
-
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge…
-
New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs
Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs. First seen on hackread.com Jump to article: hackread.com/new-trickbot-variant-dns-control-infected-windows-pcs/
-
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-browsers-to-route-c2-traffic/
-
New TrickBot Malware Variant Uses DNS Tunneling for CommandControl
A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift among financially motivated threat actors toward stealthier communication channels designed to evade network detection and security controls. However, the newly analyzed samples demonstrate a…
-
TrickBot variant uses DNS tunneling for command and control
First seen on scworld.com Jump to article: www.scworld.com/brief/trickbot-variant-uses-dns-tunneling-for-command-and-control
-
OpenAI Seeks Agent Trust After Hugging Face Breach
Security Leaders Say Governance and Runtime Controls Matter More Than Models. Artificial intelligence firm OpenAI encouraged corporations Wednesday to enfold more autonomous agents into their workflows – a message sounded just a day after the firm disclosed that one of its models was responsible for a breach at coding platform Hugging Face. First seen on…
-
Federal agencies broaden alert on Iran-linked OT attacks
The observed incidents include “malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays,” the advisory says. First seen on therecord.media Jump to article: therecord.media/federal-agencies-broaden-alert-on-iran-linked-ot-attacks
-
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as…
-
How enterprise GenAI can amplify ransomware risk, and how to contain it
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-enterprise-genai-can-amplify-ransomware-risk-and-how-to-contain-it/
-
New Ubuntu Desktop Vulnerability Turns Local Access Into Root Control
A vulnerability in snap-confine lets an unprivileged user gain root access on affected Ubuntu Desktop systems. Install the latest snapd update to fix the issue. First seen on hackread.com Jump to article: hackread.com/ubuntu-desktop-vulnerability-local-access-root-control/
-
HollowGraph malware uses Microsoft 365 calendar for command and control
First seen on scworld.com Jump to article: www.scworld.com/brief/hollowgraph-malware-uses-microsoft-365-calendar-for-command-and-control
-
How Zero Networks Targets AI Agents With Microsegmentation
CEO Says Process-Level Controls Offer Deeper Visibility Than Network-Only Policies. Zero Networks debuted AI-focused microsegmentation that discovers AI agents, maps communications and enforces least-privilege controls, while CEO Benny Lakunishok said containment and process-level visibility are vital to limiting AI-driven lateral movement across enterprise and OT environments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-zero-networks-targets-ai-agents-microsegmentation-a-32283
-
Windows Privilege Escalation: SeRestorePrivilege
Overview SeRestorePrivilege is a Windows special privilege that allows its holder to restore files and directories, effectively bypassing discretionary access controls on the file system. First seen on hackingarticles.in Jump to article: www.hackingarticles.in/windows-privilege-escalation-serestoreprivilege/
-
Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers
Hackers are increasingly abusing decentralized infrastructure and legitimate development frameworks to evade detection, with a newly observed campaign leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated عبر malicious websites, file-sharing platforms such as Google Drive, MEGA, GoFile, and Wormhole, and spoofed download portals designed to…
-
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == >>Public<< in the DeviceNetworkEvents table. As a result, traffic destined for public…
-
The air gap is a myth and other OT security truths
Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/benjamin-bachmann-bilfinger-ot-security/
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…
-
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/
-
Salt Security tackles AI governance challenge with 100 pre-built agentic security policies
Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments. The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance…
-
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience
Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.…
-
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things,…
-
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an “unprecedented” four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, First seen on thehackernews.com Jump…

