Tag: control
-
RemControl Banking Trojan Gives Attackers Remote Control of Android Devices
The newly-discovered trojan abuses the Android Accessibility Service to gain control over victim devices and collect sensitive banking credentials First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/banking-trojan-remote-control/
-
Sudo Vulnerability Lets Attackers Bypass Time-Based Authorization Controls
A recently disclosed high-severity vulnerability in Sudo could allow local, unprivileged Linux users to manipulate time-based authorization restrictions in sudoers policies. Tracked as CVE-2026-96512, this vulnerability arises from how Sudo handles the attacker-controlled TZ environment variable when evaluating NOTBEFORE and NOTAFTER constraints. Red Hat is monitoring this flaw under Bug 2539327, which is currently categorized…
-
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
Tags: adobe, api, attack, cisa, control, cve, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.The vulnerabilities are listed below – CVE-2026-5430 (CVS score: 9.8) – A path traversal vulnerability in WSO2 API Control Plane, First…
-
Island Gets $400M to Take Worker Security Into the Agent Era
Non-Human Identity and Transient Networks Extend Controls Beyond Human Workers. Island raised $400 million at a $6.4 billion valuation to extend its worker-centric security platform to AI agents, applying data, identity, network, endpoint and observability controls to non-human workers while funding growth toward profitability and a potential IPO. First seen on govinfosecurity.com Jump to article:…
-
OpenAI Agent Breached Australian Medicare Statistics Portal
An OpenAI agent bypassed controls on Australia’s Medicare statistics portal, accessed non-public data and was not reported to officials for nearly 3 months. First seen on hackread.com Jump to article: hackread.com/openai-agent-breached-australian-medicare-portal/
-
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus’s own software to gain root access, the highest level of control over an Android phone.OnePlus told him the same flaws affect many…
-
Insider Research im Gespräch – Agentic AI Control: Neue Risiken, Neue Sicherheits-Strategien
First seen on security-insider.de Jump to article: www.security-insider.de/least-agency-ki-agenten-sicher-steuern-a-65afc4db2f1920070280de057b89e8e2/
-
Insider Research im Gespräch – Agentic AI Control: Neue Risiken, Neue Sicherheits-Strategien
First seen on security-insider.de Jump to article: www.security-insider.de/least-agency-ki-agenten-sicher-steuern-a-65afc4db2f1920070280de057b89e8e2/
-
OpenAI Agent Bypassed an Australian Government Health Portal During Internal Research
OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australian government health statistics portal in June, accessing both public and non-public files in what Australian authorities are treating as a serious AI-related cyber incident. The case was…
-
UK Government Shifts to Service-Led Cyber Governance After Stinging Audit
Whitehall is shifting from mandatory cyber controls to service-led governance following a critical audit exposing failures of its 2022 cyber strategy First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uk-government-service-led-cyber/
-
New Android malware RemControl steals banking PINs and blocks removal attempts
A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-IB has found. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/24/remcontrol-android-banking-trojan-fake-tv-app/
-
New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network
AvisLoader, a newly observed Windows malware loader designed to maintain operator access even when conventional command-and-control infrastructure is disrupted. Instead of relying on a fixed domain, IP address, or centralized server, the malware uses the encrypted Tox peer-to-peer messaging network to receive commands and deliver follow-on payloads. The discovery highlights a growing challenge for defenders:…
-
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said.The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not…
-
RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials
A newly uncovered Android banking trojan dubbed RemControl is targeting customers of more than 30 financial institutions across Europe, the Middle East, and Canada. The malware combines fake Google Play pages, Android Accessibility Service abuse, credential-stealing overlays, real-time screen streaming, and remote-control functions to compromise mobile banking sessions. The company tracks the operator behind the…
-
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said.The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server…
-
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, September 22nd, 2026, CyberNewswire Aembit, the identity and access management (IAM) company for AI agents, today announced support for Cross App Access (XAA), an open protocol introduced by Okta that lets a user’s existing enterprise identity authorize access to downstream applications without a separate consent step for each connection. Launching this…
-
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/rogue-incidents-debate-ai-safety-gets-real
-
MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide
MovieReaper malware spreads through compromised Odyssey torrents, infecting hundreds of victims while using Solana to locate command-and-control infrastructure. First seen on hackread.com Jump to article: hackread.com/moviereaper-malware-odyssey-torrents-infect-users/
-
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, 22nd September 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/aembit-launches-support-for-okta-cross-app-access-extending-enterprise-identity-controls-to-ai-agents/
-
Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration
A Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts, execute shell commands, and transfer files through broker-mediated topics. Analysis of a statically linked x86-64 ELF sample shows that its configuration, task routing, and network payloads are obfuscated with separate XOR routines. The examined sample, SHA-256…
-
The Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/
-
One Stolen Active Directory File Can Expose Credentials for an Entire Windows Domain
A single stolen Active Directory database can turn a limited Windows intrusion into a domain-wide credential compromise. Threat actors that obtain the NTDS.dIT file from a domain controller, along with its corresponding SYSTEM registry hive, can extract password hashes, Kerberos keys, and password-history data for domain identities offline. While attackers may rotate payloads, loaders, command-and-control…
-
One Stolen Active Directory File Can Expose Credentials for an Entire Windows Domain
A single stolen Active Directory database can turn a limited Windows intrusion into a domain-wide credential compromise. Threat actors that obtain the NTDS.dIT file from a domain controller, along with its corresponding SYSTEM registry hive, can extract password hashes, Kerberos keys, and password-history data for domain identities offline. While attackers may rotate payloads, loaders, command-and-control…
-
A BYD Shark 6 Hack Shows the Risks of Connected Cars
A BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country road outside Canberra while a hacker sitting on the shoulder killed the headlights with a keystroke. That’s not a hypothetical. It’s what happened during a…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
Product showcase: Helmit alerts parents when online conversations show signs of trouble
Helmit is a parental control app that combines AI-powered social media monitoring with screen time management, web filtering, location tracking, and safety alerts. It … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/product-showcase-helmit-parental-controls/

