Tag: control
-
Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload
An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload inside a TAR archive disguised as a purchase order, ultimately loading a .NET assembly directly into memory. The activity was first observed…
-
Millions of Shark Robot Vacuums Vulnerable to Unpatched Remote Code Execution Flaw
Millions of internet-connected Shark robot vacuums may be vulnerable to a critical remote code execution (RCE) flaw that could allow attackers to control devices remotely, access onboard cameras, retrieve home maps, and potentially steal stored Wi-Fi credentials. An independent researcher disclosed this issue following a 90-day reporting period, and it arises from overly permissive AWS…
-
Millions of Shark Robot Vacuums Vulnerable to Unpatched Remote Code Execution Flaw
Millions of internet-connected Shark robot vacuums may be vulnerable to a critical remote code execution (RCE) flaw that could allow attackers to control devices remotely, access onboard cameras, retrieve home maps, and potentially steal stored Wi-Fi credentials. An independent researcher disclosed this issue following a 90-day reporting period, and it arises from overly permissive AWS…
-
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide
Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people’s Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext.A researcher publishing under the handle tokay0 put the…
-
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks – no login, no passwords, no permissions needed. First seen on grahamcluley.com Jump to article: grahamcluley.com/smashing-security-podcast-476/
-
Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign
Chinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A single HTTP header fingerprint on port 1111 led them to 13 Hong Kong-based servers and, on one of…
-
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
U.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure. The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and infrastructure to ransomware groups that have caused billions of dollars in losses to…
-
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments.”LabubaRAT creates a reusable foothold for hands-on activity,” Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. “Once deployed, it can profile the host, First seen on…
-
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments.”LabubaRAT creates a reusable foothold for hands-on activity,” Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. “Once deployed, it can profile the host, First seen on…
-
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries.Miggo’s security team, which discovered and reported the flaws, said one “leaks the broker’s confidential OAuth First seen on thehackernews.com…
-
US sanctions VPN, malware providers for enabling ransomware attacks
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-sanctions-vpn-malware-providers-linked-to-ransomware-gangs/
-
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors’ and other cybercriminals’ malicious activities, including ransomware attacks against Americans.The VPN, named First VPN Service (1VPNS), has been accused of offering its tools to ransomware groups, along with its 45-year-old Ukrainian First…
-
RabbitMQ Vulnerability Exposes OAuth Secrets to Attackers
A newly disclosed RabbitMQ vulnerability, tracked as CVE-2026-5721, has raised concerns among enterprise users after researchers revealed that the flaw could allow unauthenticated attackers to retrieve a broker’s confidential OAuth client secret. The successful exploitation could enable attackers to impersonate the broker, obtain administrator-level access, and potentially take control of the messaging infrastructure. First seen…
-
Fake Bank Apps Let Scammers Control Android Phones in Southeast Asia
RedHook malware uses fake banking and government apps to steal data and control Android phones, with attacks confirmed in Vietnam and Indonesia so far. The post Fake Bank Apps Let Scammers Control Android Phones in Southeast Asia appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-android-malware-apac-southeast-asia/
-
Hackers Can Exploit RabbitMQ OAuth Flaw to Access Every Message, Queue, and User
Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the open-source message broker used in an estimated 8% of all containers running today, that could allow attackers to seize full administrative control of a broker or silently map out sensitive queue data across shared tenants. Both flaws were discovered by Miggo Security’s autonomous research system,…
-
The quiet rise of digital identity: Convenience, control and the new social contract
Governments are rapidly expanding digital identity systems, promising greater convenience and faster access to services, but concerns around privacy, trust, surveillance and inclusion continue to grow First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645703/The-quiet-rise-of-digital-identity-Convenience-control-and-the-new-social-contract
-
AWS centralizes access, spending, and governance for Claude
Claude apps gateway for AWS is a self-hosted control plane that gives organizations a single point of control over access, costs, and policies for Claude Code and Claude … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/aws-claude-apps-gateway-governance/
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
New Helix Extortion Group Targets Enterprises With MFA Abuse and SharePoint Exfiltration
A previously unreported data extortion operation dubbed “Helix” that targets enterprises using identity-focused entry techniques and automated SharePoint exfiltration. The group’s playbook combines voice phishing (vishing), device-code phishing to capture session tokens and bypass Conditional Access controls, rapid MFA registration for persistence, and scripted enumeration and bulk download of SharePoint content all staged from shared…
-
Claude AI Prompt Injection Attack Turns Chatbot Into Stealthy C2 Agent to Achieve Remote Code Execution
Claude Desktop’s synced Personal Preferences feature can be exploited as a covert prompt-injection vector, transforming the AI assistant into a de facto command-and-control (C2) agent. This method allows for remote code execution on a compromised user workstation without the need for phishing emails or traditional malware delivery. In this attack chain, the initial access is…
-
GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer’s computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead.The affected tools are Amazon Q Developer, Anthropic’s Claude Code, Augment, Cursor, Google…
-
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution.The list of vulnerabilities is as follows – CVE-2026-50746 (CVSS score: 10.0) – An improper access control vulnerability in UniFi Connect Application that an…
-
Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan
A new intrusion campaign attributed to APT”‘C”‘20 (aka Fancy Bear, APT28) demonstrates the group’s continued refinement of stealthy, fileless techniques: weaponized Office documents that deploy a COM”‘hijacking DLL. Extract shellcode hidden via LSB steganography in a PNG, and use reflective loading to run an obfuscated C# remote”‘control Trojan that communicates through the legitimate cloud storage…
-
Claude Cowork turns your phone into a remote control for AI work
Anthropic started rolling out Claude Cowork, an AI agent that completes multi-step tasks, in beta for Max users on mobile and the web. They describe a goal, and Claude plans … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/claude-cowork-phone-mobile-web/
-
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network…
-
LONGLEASH Malware Adds Reverse Shell, Proxying, and Intermediate C2 Capabilities
A significant upgrade to malware maintained by the UAT-7810 actor: LONGLEASH, a successor to the previously reported SHORTLEASH implant, now sporting reverse-shell, multi-protocol proxying, and intermediate command-and-control (C2) forwarding capabilities. LONGLEASH retains SHORTLEASH’s ff-agent codebase but expands its operational scope. The implant, internally named “nz1.0,” splits into Base, Executor, and Core modules. The Base module…
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…
-
GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
A critical vulnerability known as >>GitLost<< has been discovered in GitHub's newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to exfiltrate sensitive data from private repositories. It demonstrates how AI-driven automation within development pipelines can be manipulated to bypass conventional access controls and leak confidential information across repository boundaries. GitLost Vulnerability…
-
EU Pushes for Domestic AI Momentum
Eurozone Banks Told to Strengthen Controls Amid AI Vulnerability Disclosure Wave. Europe is planning for improved capabilities to evaluate the cybersecurity implications of frontier artificial intelligence models – and will possibly mount a grand challenge for developing AI-powered cybersecurity systems – as part of a new strategy unveiled Tuesday. First seen on govinfosecurity.com Jump to…
-
AI Sovereignty Is a New Test for Enterprises
Enterprises are Rethinking Operational Risks to Gain Greater Control of AI Stacks. IBM reports that only 9% of executives fully understand their AI dependencies, while 71% say switching vendors would be difficult. AI sovereignty concerns reached a fevered pitch for tech leaders last month after Anthropic switched off two of its most capable artificial intelligence…

