Tag: control
-
BlackHatSect0r Hackers Disable AI Safety Controls to Automate Credential Theft and Cyberattacks
Tags: ai, attack, control, credentials, cyber, cyberattack, cybercrime, data-breach, hacker, Internet, phishing, theftA French-speaking cybercrime crew calling itself BlackHatSect0r && DXQRTXX allegedly disabled safety controls in a self-hosted AI agent and used the resulting system to automate mass credential harvesting, target discovery, phishing preparation, and attack orchestration. The internet-exposed server reportedly contained 4.9 GB of material across 9,299 files, including a custom Go-based command-and-control platform named DXSCAN,…
-
BambooToken: The Malware That Speaks MQTT to Stay Under the Radar
Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control…
-
SpearKampagne mit In-Memory-InfoStealer entdeckt
Konkret erstellten die Angreifer der jüngst durch Arctic Wolf aufgedeckten Spear-Phishing-Kampagne Phishing-Köder, die sich in drei Ländern als Baltic Control ausgaben. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/spear-phishing-memory-infostealer
-
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension.Once the extension was installed, it could access each product’s built-in AI with a single click.…
-
Apple Adds New Parental Controls to iPhone, iPad and Mac: Here’s What Changes
Apple is rolling out new parental controls for iPhone, iPad and Mac, including website approvals, Screen Time changes and expanded safety tools. The post Apple Adds New Parental Controls to iPhone, iPad and Mac: Here’s What Changes appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-apple-ios-27-parental-controls-child-safety/
-
Quorum Cyber Adds Autonomous SOC Through Ontinue Acquisition
Proposed Purchase Combines Agentic SOC Technology With Managed Security Expertise. Quorum Cyber’s planned acquisition of Swiss Microsoft Gold Partner Ontinue would combine Microsoft-focused managed security with agentic SOC technology designed to investigate threats at machine speed while giving customers control over when AI can act autonomously. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/quorum-cyber-adds-autonomous-soc-through-ontinue-acquisition-a-32826
-
36,769 Self-Hosted AI Services Exposed Online, What Security Teams Should Check
A new scan found 36,769 self-hosted AI endpoints reachable online, highlighting gaps in access controls, patching, and monitoring. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-self-hosted-ai-security/
-
China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic into apparent gambling activity. The activity expands on earlier findings by Trend Micro, which identified PeckBirdy as a flexible JScript-based C2 framework used by China-aligned…
-
CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks
Tags: cisa, control, cyber, cybersecurity, defense, exploit, guide, hacker, identity, infrastructure, international, networkThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has collaborated with international partners to guide the defense of Active Directory (AD). They warn that attackers exploit 17 common techniques to gain control of identity infrastructure. The guide, released on September 15, was co-authored by the Australian Signals Directorate’s Australian Cyber Security Center, CISA, the NSA,…
-
Exaforce Extends Cybersecurity Reach to Create AI Agent Kill Switch
Exaforce today extended the reach of its artificial intelligence (AI) for security operations centers (SOC) to AI agents and associated applications in a way that enables cybersecurity controls and policies to be enforced in real time. Aqsa Taylor, chief security evangelist for Exaforce, said the Exaforce AI Security capability makes it possible to connect the..…
-
Exaforce Extends Cybersecurity Reach to Create AI Agent Kill Switch
Exaforce today extended the reach of its artificial intelligence (AI) for security operations centers (SOC) to AI agents and associated applications in a way that enables cybersecurity controls and policies to be enforced in real time. Aqsa Taylor, chief security evangelist for Exaforce, said the Exaforce AI Security capability makes it possible to connect the..…
-
Defining What Counts as AI Spending
CIOs Build New Budget Models for Agents, Tokens and Failed Experiments. AI spending no longer fits neatly into software or cloud budgets. As model access, agents, data preparation and governance drive costs across the enterprise, CIOs are creating new ways to track experimentation, control consumption and demonstrate long-term business value. First seen on govinfosecurity.com Jump…
-
Daily OT Security News: September 15, 2026
The threat landscape for operational technology (OT) and industrial control systems (ICS) remains critical as organizations face increasing vulnerabilities and targeted attacks. Recent reports highlight significant breaches, regulatory updates, and emerging threats that require immediate attention from security teams. Key… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-15-2026/
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems.The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South…
-
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/
-
What Zero-Day Response Should Be in the Post-Mythos Era
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/what-zero-day-response-should-be-in-the-post-mythos-era/
-
Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites. The vulnerability , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of…
-
AI Agent Identity and Access Control: A Framework for B2B SaaS
An AI agent needs four things human IAM does not provide: an identity of its own rather than a borrowed one, delegation semantics that keep the human’s authority visible without impersonating them, authorization scoped to a task rather than a… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-agent-identity-and-access-control-a-framework-for-b2b-saas/
-
12 Best Enterprise Browsers Compared (2026): Features Pricing
Quick Answer: Island and Palo Alto (Talon) lead purpose-built enterprise browsers; Chrome Enterprise (free Core tier) and Edge for Business (bundled) secure the browsers you already run; LayerX and Seraphic add enterprise controls without switching browsers. Note: Mammoth Cyber has ceased operations treat any references as historical. Work happens in the browser now 90%+ of…
-
12 Best Enterprise Browsers Compared (2026): Features Pricing
Quick Answer: Island and Palo Alto (Talon) lead purpose-built enterprise browsers; Chrome Enterprise (free Core tier) and Edge for Business (bundled) secure the browsers you already run; LayerX and Seraphic add enterprise controls without switching browsers. Note: Mammoth Cyber has ceased operations treat any references as historical. Work happens in the browser now 90%+ of…
-
Assume Breach Must Now Mean Assume Impersonation
‘Assume breach’ is a useful operating principle for enterprise security: Build as if an attacker will eventually get past the perimeter. That mindset led teams to adopt Zero Trust, stronger endpoint controls, network segmentation, and tighter identity and access management. The premise… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/assume-breach-must-now-mean-assume-impersonation/
-
Cymphony Raises $30M to Turn Access Data Into Remediation
Israeli Startup Focuses on What Compromised Identities Can Do With Existing Access. Israeli startup Cymphony raised $30 million from Sequoia Capital and SMBC Fin Atlas Beyond Fund to continuously map identities, permissions and activity as attackers and AI tools make dormant access-control weaknesses more easy to discover and exploit. First seen on govinfosecurity.com Jump to…
-
AI CEOs Call for Slower Frontier Development as Stocks Fall
Amodei, Altman and Musk Back AI Pacing as Trump Rejects New Guardrails. Discourse about the potential of unchecked AI systems and frontier labs’ ability to control rogue AI agents culminated in several AI executives calling for slower AI development, a move that saw AI-related stocks fall and drew rebuke from the U.S. president. First seen…
-
Apple parental controls in iOS 27 let kids ask before opening new websites
Apple has overhauled the child-safety tools that ship across iPhone, iPad, and Mac. One idea runs through the redesign. Give a child a device that does very little, then open … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/apple-parental-controls-ios-27/
-
Homebrew 7.0.0 gets built-in GUI, better security controls
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/homebrew-700-gets-built-in-gui-better-security-controls/
-
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker’s own…

