Tag: cyber
-
Chinese Hackers Impersonate US Officials for AI Cyber Espionage
An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/chinese-actor-impersonates-us-officials-cyber-espionage
-
Japanese media group Nikkei discloses intrusions targeting employees and users
The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources. First seen on therecord.media Jump to article: therecord.media/nikkei-cyberattack-japan-data
-
Belarusian hacktivists spent two years inside Russian healthcare network, researchers say
Russian cybersecurity researchers attributed a quiet two-year espionage campaign to the Belarusian Cyber Partisans, a group better known for public attacks against governments and infrastructure. First seen on therecord.media Jump to article: therecord.media/belarusian-hacktivists-two-years-Russian-healthcare-network
-
Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads
A critical heap-buffer-overflow vulnerability in libheif could allow authenticated WordPress users to achieve remote code execution by uploading a specially crafted HEIC image through the standard Media Library workflow. The issue, tracked as GHSA-x8r2-mggj-j6wr, affects the library’s uncompressed-image (unci) decoder and has been fixed in libheif 1.23.3. In affected WordPress deployments, uploaded HEIC files can…
-
Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads
A critical heap-buffer-overflow vulnerability in libheif could allow authenticated WordPress users to achieve remote code execution by uploading a specially crafted HEIC image through the standard Media Library workflow. The issue, tracked as GHSA-x8r2-mggj-j6wr, affects the library’s uncompressed-image (unci) decoder and has been fixed in libheif 1.23.3. In affected WordPress deployments, uploaded HEIC files can…
-
Japanese media group Nikkei discloses cyberattack targeting journalistic sources
The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources. First seen on therecord.media Jump to article: therecord.media/nikkei-cyberattack-japan-data
-
Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability
Every October, security teams roll out refreshed training, posters and phishing simulations. But according to Rob Gregory, CISO at Optiv, organizations that treat the month as the centerpiece of their awareness efforts are missing the point. “I believe Cyber Awareness Month (CAM) is a valuable amplifier and another reminder about the importance we all play in an organization’s cybersecurity…
-
New RemoveMacAI Tool Removes Apple Intelligence Models and Reclaims Mac Storage
A new open-source command-line utility called RemoveMacAI lets Apple silicon Mac users running macOS 27 disable Apple Intelligence, remove downloaded on-device AI models, and prevent the operating system from automatically downloading them again. Developed by Om Lahore and released under the MIT license, RemoveMacAI addresses storage and manageability concerns for users who have disabled Apple…
-
New RemoveMacAI Tool Removes Apple Intelligence Models and Reclaims Mac Storage
A new open-source command-line utility called RemoveMacAI lets Apple silicon Mac users running macOS 27 disable Apple Intelligence, remove downloaded on-device AI models, and prevent the operating system from automatically downloading them again. Developed by Om Lahore and released under the MIT license, RemoveMacAI addresses storage and manageability concerns for users who have disabled Apple…
-
New RemoveMacAI Tool Removes Apple Intelligence Models and Reclaims Mac Storage
A new open-source command-line utility called RemoveMacAI lets Apple silicon Mac users running macOS 27 disable Apple Intelligence, remove downloaded on-device AI models, and prevent the operating system from automatically downloading them again. Developed by Om Lahore and released under the MIT license, RemoveMacAI addresses storage and manageability concerns for users who have disabled Apple…
-
Apple Strengthens macOS Privacy Controls as AI Agents Become More Autonomous
Apple has announced plans to strengthen macOS controls for Full Disk Access, citing concerns that increasingly autonomous AI agents could raise privacy and security risks by giving applications extensive access to users’ devices. In a developer update on October 2, Apple stated it will introduce additional controls for macOS Full Disk Access, a powerful permission…
-
Google Gemini to Gain Full Computer Access With New Permission
Google is reportedly testing a new Gemini Desktop feature that could give its AI agent extensive control over a user’s Mac. This includes access to files, interaction with installed applications, and network communication, all with fewer prompts requiring user approval for each action. Currently, Google has not publicly released this capability, and it has not…
-
Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads
A critical heap-buffer-overflow vulnerability in libheif could allow authenticated WordPress users to achieve remote code execution by uploading a specially crafted HEIC image through the standard Media Library workflow. The issue, tracked as GHSA-x8r2-mggj-j6wr, affects the library’s uncompressed-image (unci) decoder and has been fixed in libheif 1.23.3. In affected WordPress deployments, uploaded HEIC files can…
-
CISA Flags Citrix NetScaler Flaw Exploited in Ongoing Attacks
Tags: attack, cisa, citrix, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-88779, a high-severity vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. Tracked as CVE-2026-88779, this vulnerability involves an improper restriction of operations within the bounds of a memory buffer, also referred…
-
MediaTek Fixes 31 Security Flaws Affecting Modem, Video and AI Components
MediaTek has released its October 2026 Product Security Bulletin, which addresses 31 vulnerabilities across modem, video, AI processing, display, trusted execution, and system components used in a wide range of its chipsets. The fixes include two critical modem out-of-bounds write vulnerabilities and nine high-severity flaws that could potentially lead to memory corruption, privilege escalation, or…
-
Google Tightens Open-Source Bug Bounty Rules After Surge in AI-Generated Vulnerability Reports
Google has stopped accepting new >>product vulnerability<< reports through its Open Source Software Vulnerability Reward Program (OSS VRP) due to a significant increase in automated submissions that are predominantly invalid. This restriction took effect on October 1, 2026, and Google plans to provide an update regarding this part of the program in the first quarter…
-
AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft
Tags: access, ai, authentication, credentials, cyber, flaw, open-source, theft, update, vulnerabilityAWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration. These vulnerabilities could allow unauthenticated administrative takeover, disclosure of OAuth2 credentials, and access to internal services. The company strongly urges users to upgrade all Loom deployments and forks to version 1.7.0. AWS announced these issues in Security Bulletin…
-
More UK Schools Are Recovering Faster from Cyber Incidents
Ofqual study finds growing number of UK schools are bouncing back “immediately” from cyber-attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uk-schools-recovering-faster/
-
CISA Adds Zammad Vulnerabilities to KEV Following Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in the Zammad helpdesk platform to its Known Exploited Vulnerabilities (KEV) Catalog following reports of active exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in the Zammad helpdesk platform to its Known Exploited Vulnerabilities (KEV) Catalog following reports…
-
Autonomous AI Agent Chains Two Zammad Zero-Days in Machine-Speed Cyberattack
An autonomous AI agent breached the Dutch Institute for Vulnerability Disclosure (DIVD) after chaining two previously undisclosed vulnerabilities in the Zammad helpdesk platform, turning an initial application compromise into root access within seconds. The incident, first detected on September 22 after the attacker accessed DIVD systems a day earlier, offers a stark example of how…
-
12 Best ITDR Tools Compared (2026): Features Pricing
Microsoft Defender for Identity is the best ITDR solutions starting point for most estates often already licensed while CrowdStrike leads platform-consolidated enforcement and Silverfort the inline-prevention lane. This comparison maps 12 tools across four coverage lanes (AD core, EDR-platform, SaaS/IdP, recovery) because no single product does all four jobs, whatever the datasheet implies. Quick Verdict:…
-
11 Best CIAM Solutions Compared (2026): Features Pricing
Okta’s Auth0 line is the best CIAM for most product teams the benchmark ecosystem with the procurement fast-pass while Amazon Cognito and Microsoft Entra External ID win the price-floor fight for AWS- and Azure-committed builders. Evaluating the broader market across the top Identity and Access Management (IAM) companies reveals how customer identity has evolved from…
-
12 Best Passwordless Authentication Solutions Compared (2026): Features Pricing
Microsoft is the best passwordless starting point for most workforces passkeys and Windows Hello ride licensing you already own while HYPR leads the dedicated-platform lane and Stytch the product-login lane. This comparison prices 12 vendors across workforce, product, hardware, and OEM lanes, because “passwordless” spans four different purchases with four different bills. Quick Verdict: Best…
-
GlassWorm Supply Chain Attack Hides Malware Inside VS Code Color Themes
A GlassWorm-linked software supply chain campaign has abused seemingly harmless Visual Studio Code color themes to distribute malicious loaders across the Visual Studio Marketplace and Open VSX Registry. The activity demonstrates how extensions designed only to change editor colors can become high-impact initial-access vectors when they include unnecessary executable JavaScript. Both extensions presented themselves as…
-
Attackers Abuse Legitimate ScreenConnect Client in Phishing Campaign to Gain Remote Access
Threat actors are increasingly bypassing conventional malware detection by abusing legitimate remote monitoring and management software instead of deploying custom implants. In a recent phishing operation, attackers delivered a genuine, digitally signed ConnectWise ScreenConnect client configured to establish remote access to infrastructure controlled by the operator. The message claimed that a payment of $5,745.65 had…
-
Microsoft Releases Emergency Exchange Server Update to Fix CVE-2026-96940
Microsoft has released a revised security update package for on-premises Exchange Server, dated September 2026, which includes a fix for CVE-2026-96940. This V2 release applies to Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016. Customers using Exchange Online are already protected and do not need this update. The revised update was published…
-
Microsoft Releases Emergency Exchange Server Update to Fix CVE-2026-96940
Microsoft has released a revised security update package for on-premises Exchange Server, dated September 2026, which includes a fix for CVE-2026-96940. This V2 release applies to Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016. Customers using Exchange Online are already protected and do not need this update. The revised update was published…
-
South Korea Orders Investigation Into AI-Powered Cyberattacks on Major Banks
South Korean President Lee Jae Myung has ordered a comprehensive investigation into a series of data breaches impacting major banks and other financial institutions. Concerns have been raised that attackers may have utilized AI-enabled offensive security tools. These incidents have prompted emergency regulatory action and a sector-wide effort to strengthen defenses against increasingly automated intrusions.…

