Tag: cyber
-
CISA Warns SonicWall SMA1000 Flaws Are Exploited in Ransomware Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, ransomware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SonicWall SMA1000 to its Known Exploited Vulnerabilities catalog, noting that the flaw has been used in ransomware campaigns. This vulnerability, tracked as CVE-2026-15409, is a server-side request forgery (SSRF) issue found in the Workplace interface of SonicWall SMA1000 appliances. It has…
-
Hackers Pivot Through Private APN to Sabotage Siemens PLCs at Polish Power Plant
Threat actors used a private cellular access-point-name (APN) network to pivot from a compromised wind farm into the operational technology environment. A Polish combined heat and power plant, where they disrupted Siemens programmable logic controllers and briefly interrupted cogeneration operations. The December 29, 2025 intrusion affected a CHP facility serving approximately 50,000 residents, forcing a…
-
CiscoClamAV Vulnerabilities Let Remote Attackers Crash Antivirus Scanning With Crafted Files
Cisco has disclosed seven high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning by submitting specially crafted files. These vulnerabilities are tracked as CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348, and have been assigned a maximum CVSS score of 7.5. ClamAV Vulnerabilities The issues are detailed in the Cisco…
-
Anthropic Adds Invisible Watermarks to Claude AI-Generated Text and Signed Metadata to Files
Anthropic has launched a machine-readable content-marking initiative for materials generated by its Claude models. This initiative combines invisible text watermarks with digitally signed provenance metadata for supported files. This move follows Anthropic’s commitment to the transparency guidelines outlined in Article 50(2) of the European Union AI Act. Anthropic Adds Invisible Watermarks to Claude According to…
-
Only Half of UK Manufacturers Have a Cyber Incident Response Plan
Make UK reveals major cyber resilience gaps as 30% of UK manufacturers report recent cyber incidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/half-uk-manufacturers-cyber/
-
GPT-5.6-Cyber refuses security researchers’ requests far less often
GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/11/openai-gpt-5-6-cyber-model/
-
OpenAI Launches GPT-5.6-Cyber to Find Zero-Day Vulnerabilities and Develop Exploit Chains
OpenAI has expanded its Daybreak cybersecurity program with the introduction of GPT-5.6-Cyber, a purpose-trained model specifically designed for authorized vulnerability research, exploit validation, and advanced security testing. Built on the foundation of GPT-5.6 Sol, this new model serves as a controlled-access tool for trusted defenders as AI-assisted offensive capabilities continue to evolve. GPT-5.6-Cyber to Find…
-
DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July 2025, the operation uses double extortion: encrypting enterprise data while threatening publication of stolen material. The encryptor’s pre-encryption routine is built to degrade both prevention and recovery. After XOR-decoding an embedded configuration,…
-
PassPasskey Attack Exploits Windows and Entra ID to Bypass MFA
Tags: attack, authentication, credentials, cyber, exploit, mfa, microsoft, passkey, phishing, windowsSecurity researchers have recently revealed a new attack family named “Pass-the-Passkey,” which enables adversaries to impersonate enterprise users and circumvent phishing-resistant multi-factor authentication (MFA) protections in Windows 11 and Microsoft Entra ID environments. This research challenges the belief that passkeys are inherently immune to credential replay and session abuse. Pass-the-Passkey Attack Exploits Windows The attack…
-
CISA Urges Organizations to Patch Exposed VPNs and Segment Networks Against Gunra Ransomware
Tags: advisory, breach, cisa, credentials, cyber, data, data-breach, encryption, exploit, firewall, infrastructure, international, law, network, organized, ransomware, service, theft, update, vpnCISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed edge infrastructure, including VPN gateways, firewall appliances and RDP-accessible systems, to breach enterprise networks. The advisory positions Gunra as an increasingly organized ransomware-as-a-service operation whose affiliates combine data theft, credential compromise and rapid encryption to pressure…
-
New Abyssos RAT Hijacks Browser Sessions, Steals Credentials and Gives Attackers Remote VNC Access
Abyssos, a modular C++ remote-access trojan that combines credential theft, browser-session hijacking, file exfiltration and hidden VNC control in a single post-compromise framework. Technical analysis from ThreatLabz indicates that Abyssos is designed for hands-on intrusion activity rather than opportunistic, single-purpose theft. The most concerning feature is its hidden VNC capability. The HVNC_START command opens a…
-
Red Hat Kubernetes Flaw Allows Attackers to Escalate Privileges to Cluster-Admin
Red Hat has disclosed a privilege-escalation vulnerability in Red Hat Advanced Cluster Management for Kubernetes (ACM) that could allow a low-privileged user to gain full cluster-admin control of an affected hub cluster. This vulnerability is tracked as CVE-2026-10090 and affects the Application Subscription controller, specifically the multicluster-operators-subscription. It has a CVSS v3.1 score of 9.9…
-
Claude Code Auto Mode Blocks 89% of Dangerous Commands and Prompt Injection Attacks
Anthropic will make Auto Mode the default setting in Claude Code for Pro, Max, and Team subscribers starting August 14, 2026. This change introduces an automated classifier to replace repetitive manual permission approvals during long-running development tasks. The goal is to reduce “permission fatigue,” a condition where developers approve prompts without thoroughly examining the associated…
-
Your security vendor gets the frontier cyber model, you get the findings
Selected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure. Those clients never get the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/11/openai-daybreak-cyber-models/
-
OpenAI says Daybreak will expand to offer specialized cyber services
The company rolled out “Red” and “Blue” programs for defenders, introduced a new model and announced partnerships with 16 major cybersecurity vendors. First seen on cyberscoop.com Jump to article: cyberscoop.com/openai-daybreak-expansion-specialized-cyber-services/
-
NATO and an AI startup can now name and track software vulnerabilities
Tags: ai, communications, cyber, cybersecurity, defense, flaw, intelligence, software, startup, vulnerabilityNATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week. The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company…
-
Whither CMMC? Another Battle Over Troubled DOD Cyber Regs
Defense Cyber Vendors Blindsided by Pause to Program 7 Years in the Making. The deadline for industry comments on how to fix the Cybersecurity Maturity Model Certification process at the Department of Defense is at the end of this week, setting the stage for a battle royale over the future of the program. It feels…
-
OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users
OpenAI has developed a new model called “GPT 5.6 Cyber,” designed for vulnerability research, penetration testing, incident response, and remediation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/openai-releases-chatgpt-56-cyber-but-its-only-for-approved-users/
-
Secure development can help turn the tables as AI alters cyber landscape
A top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/secure-development-ai-cyber-vulnerabilities-Black-Hat/827435/
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
Android Banking Droppers Surge as Malware Operators Change Packaging Tactics
Android banking malware operators are increasingly relying on dropper-based packaging to evade mobile app-store controls, shifting how threats are classified and delivered rather than simply expanding their overall distribution. Kaspersky telemetry for the second quarter of 2026 recorded 1,996,823 blocked attacks involving malware, adware, and potentially unwanted mobile software, down from 2,676,328 in Q1. Yet…
-
CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active exploitation. This vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable appliances, posing a significant risk to organizations that expose LoadMaster…
-
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe. The group’s use of a custom service binary named PSexesvc.exe, mimicking Microsoft Sysinternals PsExec, illustrates how attackers can turn routine Windows administration into cover for lateral movement and payload execution. The binary has been observed alongside…
-
GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This rollout is supported by a new GitHub Advisory Database importer for OpenSSF’s malicious-packages repository, which enhances supply chain detection across these eight ecosystems. GitHub Expands…
-
Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a Single Click
RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through a single malicious link. According to Varonis Threat Labs, the vulnerability exploits Rovo’s handling of URL-supplied prompts, enabling attackers to inject malicious instructions into an authenticated user’s AI session. The attack does not require traditional…
-
Fake Solidity Pro Extensions Turn Trusted Developer Tooling Into Credential-Stealing Malware
Malicious “Solidity Pro” extensions are abusing the trust developers place in VS Code and Open VSX tooling, evolving from delayed payload droppers into broad credential and cryptocurrency-wallet stealers. Yeeth Security identified two publishers, helper-beeps and web3devtoolsx, distributing related solidity-pro packages that use Solidity-themed branding, obfuscation, and version churn to target web3 developers. The campaign reflects…
-
HP ThinPro TPM Flaw Lets Attackers Bypass Full Disk Encryption and Steal LUKS Keys
A security researcher has revealed a critical design flaw in HP ThinPro versions 8 and 9, which allows attackers with physical access to a thin client’s storage drive to extract TPM-sealed LUKS disk-encryption keys. This vulnerability arises from an incomplete measured-boot policy that validates the GRUB bootloader but fails to measure the Linux kernel and…
-
Sophos Warns Unprotected Endpoints Let Interlock Credential Theft Go Undetected
Interlock ransomware incident that shows how unprotected endpoints can give attackers enough time to steal credentials, establish persistence, and reach a domain controller before defenders intervene. During a March 2026 response engagement, Sophos Emergency Incident Response investigators found the group abusing legitimate forensic utilities, including Volatility3 and WinPmem, to acquire memory and extract credential material…
-
Apple Private Cloud Compute Path Traversal Flaw Lets Attackers Write Files as Root
Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a privileged network attacker to write attacker-controlled files as root during node boot. This flaw affects the Apple Intelligence cloud-inference infrastructure. Apple has addressed the issue in PCC Release 5E290.3 and later, rating it as an…

