Tag: cyber
-
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM.According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that’s dressed up as a system service. The…
-
OpenAI Agent Bypassed an Australian Government Health Portal During Internal Research
OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australian government health statistics portal in June, accessing both public and non-public files in what Australian authorities are treating as a serious AI-related cyber incident. The case was…
-
UK Government Shifts to Service-Led Cyber Governance After Stinging Audit
Whitehall is shifting from mandatory cyber controls to service-led governance following a critical audit exposing failures of its 2022 cyber strategy First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uk-government-service-led-cyber/
-
Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication
A highly severe vulnerability in Roundcube Webmail is being actively exploited, posing risks to unpatched email servers through unauthenticated SQL injection attacks. This vulnerability, tracked as CVE-2026-48842, affects Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. On September 21, the Canadian Center for Cyber Security updated advisory AV26-503, warning that reports from the…
-
Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks
Tags: attack, authentication, cve, cvss, cyber, exploit, flaw, hacker, rce, remote-code-execution, update, vpn, vulnerability, zero-dayCheck Point has warned customers about the active exploitation of two critical vulnerabilities in its VPN gateway and Security Management products: CVE-2026-85102 and the newly disclosed CVE-2026-93616. Both vulnerabilities have a CVSS score of 9.8 and allow for pre-authentication attacks, making immediate patching and reducing exposure essential. Check Point Flaws CVE-2026-85102 is an improper certificate-validation…
-
Operation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files
Tags: cyber, cyberespionage, intelligence, korea, malicious, malware, north-korea, powershell, russia, threat, ukraine, windowsNorth Korea-linked threat actor Konni has launched a targeted cyberespionage operation against Ukraine-focused entities using malicious Windows shortcut files disguised as PDF documents. The campaign, tracked by SOCRadar Threat Research Unit as Operation Conflict Compass, deploys a modular PowerShell malware family dubbed VelvetCake to collect intelligence on the Russia-Ukraine war. The activity appears designed to…
-
New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network
AvisLoader, a newly observed Windows malware loader designed to maintain operator access even when conventional command-and-control infrastructure is disrupted. Instead of relying on a fixed domain, IP address, or centralized server, the malware uses the encrypted Tox peer-to-peer messaging network to receive commands and deliver follow-on payloads. The discovery highlights a growing challenge for defenders:…
-
Microsoft Rebuilds the SOC With AI Agents to Fight Machine-Speed Cyberattacks
An Integrated Security Operations Center (ISOC) in Microsoft Defender, unifying security information and event management (SIEM) and threat-protection capabilities in a platform designed for AI-assisted, continuous defense. The company’s premise is direct: traditional SOC architectures cannot match adversaries that use AI agents to automate reconnaissance, intrusion execution, lateral movement, and operational decision-making at machine speed.…
-
RemControl Android Malware Targets 30+ Banking Apps to Steal PINs and Credentials
A newly uncovered Android banking trojan dubbed RemControl is targeting customers of more than 30 financial institutions across Europe, the Middle East, and Canada. The malware combines fake Google Play pages, Android Accessibility Service abuse, credential-stealing overlays, real-time screen streaming, and remote-control functions to compromise mobile banking sessions. The company tracks the operator behind the…
-
cPanel Permissions Flaw Allows Local Users to Read Other Accounts’ Calendar Data
cPanel has released patches for CVE-2026-68490, a vulnerability related to incorrect permissions in its CalDAV/CardDAV implementation. This flaw could allow a local user on a shared server to access calendar events and contacts from other hosting accounts. The issue affects cPanel/WHM version 120 and later, highlighting the risks associated with tenant isolation in shared-hosting environments.…
-
Apache Tomcat 11.0.26 Fixes 12 Security Flaws Enabling WebSocket Bypass and DoS Attacks
Apache Tomcat 11.0.26 has been released with fixes for 12 security vulnerabilities, including a significant flaw that could allow attackers to bypass security constraints protecting WebSocket endpoints. This release also addresses several denial-of-service (DoS) issues affecting WebSocket, AJP, HTTP/2, and HTTP/1.0 request handling. Dated September 15, 2026, the release addresses flaws that were publicly disclosed…
-
New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group
A newly identified ransomware operation tracked as Galago has emerged with apparent operational links to the Panzer ransomware group, raising concerns of an expanding double-extortion ecosystem targeting organizations worldwide. Researchers began directly monitoring Galago’s dark leak site (DLS) on 15 September 2026. At the time of observation, the group’s Tor-based leak portal was inactive and…
-
GitLab Email Token Lets Attackers Push Code to Main and Execute CI/CD Jobs
A long-lived GitLab incoming email token embedded in project email addresses for the >>Email work item<< feature can be exploited to push attacker-controlled code, create merge requests, and trigger CI/CD pipelines using the permissions of the token owner. This issue can also bypass GitLab's IP restrictions, as incoming email is explicitly excluded from those controls.…
-
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators, separate from another administration-proposed pilot program. First seen on cyberscoop.com Jump to article: cyberscoop.com/gottheimer-ai-cyber-defense-act-cisa-pilot/
-
Shai-Hulud Attack Nips Cyber-Firm CrowdSec’s GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee’s computer through the TanStack npm supply chain attack. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data
-
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, September 22nd, 2026, CyberNewswire Aembit, the identity and access management (IAM) company for AI agents, today announced support for Cross App Access (XAA), an open protocol introduced by Okta that lets a user’s existing enterprise identity authorize access to downstream applications without a separate consent step for each connection. Launching this…
-
Insurance sector begins to offer clarity on AI-related cyber claims
The emergence of agentic AI and frontier models has led to widespread uncertainty for policyholders. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/insurance-sector-begins-to-offer-clarity-on-ai-related-cyber-claims/831028/
-
Eco-Verband bringt Internet-Security-Days erstmals auf die it-sa
Der Eco Verband der Internetwirtschaft e. V. bringt die Internet-Security-Days am 28. Oktober 2026 erstmals auf die it-sa Expo&Congress in Nürnberg. Mit NIS2, dem Cyber-Resilience-Act und weiteren europäischen Vorgaben geht die Cybersicherheitsregulierung zunehmend von der Gesetzgebung in die praktische Umsetzung über. Im Mittelpunkt des Kongresstags stehen daher Fragen, die für Unternehmen angesichts neuer europäischer […]…
-
AI is set to help cyber attackers much more than defenders, says UK official
Dave Chismon, the NCSC’s chief technology officer for architecture, said in a blog post that the imbalance in AI means cyberattacks would likely grow as automated defenses struggle to keep pace. First seen on therecord.media Jump to article: therecord.media/ai-set-to-help-attackers-more-than-defenders
-
Critical Linux KVM Flaw Enables GuestHost Escape on ARM64 Systems
A critical vulnerability in the Linux Kernel-based Virtual Machine (KVM) for ARM64 systems could let attackers escape a virtual machine and gain read and write access to host kernel memory. This flaw, tracked as CVE-2026-89775, specifically affects ARM64 hosts with nested virtualization enabled and has been addressed in the mainline Linux kernel. Security researcher Hyunwoo…
-
TASK#STOMP PowerShell Backdoor Steals Business Documents and Executes Remote Commands
A Windows-focused backdoor dubbed TASK#STOMP that uses VBScript, PowerShell, Scheduled Tasks, and runtime C# compilation to establish resilient persistence and continuously steal business documents. The implant also captures screenshots, extracts saved Wi-Fi passwords, harvests clipboard data, and executes arbitrary commands received from its operators. While the original delivery method is unconfirmed, the location is consistent…
-
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa.The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been First seen…
-
Hackers Exploit Veeam Agent Vulnerability to Gain SYSTEM-Level Access on Windows
A newly discovered privilege escalation flaw in Veeam Agent for Microsoft Windows could allow attackers with local access to compromised endpoints to execute commands as NT AUTHORITY\SYSTEM. Public proof-of-concept (PoC) code for CVE-2026-32996 was released on September 14, increasing the urgency for organizations to patch affected Veeam deployments. CVE-2026-32996 impacts Veeam Agent for Microsoft Windows…
-
Red Hat OpenShift Flaw Lets Attackers Poison Disconnected Registries With Malicious Releases
Red Hat disclosed an important OpenShift vulnerability that could let attackers bypass release-image signature checks and introduce malicious payloads into disconnected registries. This issue, tracked as CVE-2026-75939, affects the `openshift/oc-mirror` tool and has a preliminary CVSS v3.1 score of 7.4. Administrators use `oc-mirror` to retrieve release images from upstream sources and then copy them to…
-
Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration
A Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts, execute shell commands, and transfer files through broker-mediated topics. Analysis of a statically linked x86-64 ELF sample shows that its configuration, task routing, and network payloads are obfuscated with separate XOR routines. The examined sample, SHA-256…
-
Critical MaxKB AI Agent Flaw Lets Prompt Injection Execute System Commands
A critical vulnerability in the MaxKB AI knowledge-base platform could let attackers exploit prompt injection and run operating system commands on vulnerable deployments, including directly on the underlying host in some configurations. This flaw, tracked as CVE-2026-77521 and GHSA-f36j-f34j-h3rx, affects MaxKB versions up to and including 2.10.3-lts. The issue has received a maximum CVSS v3.1…
-
Splunk helps US research uni embrace ‘student-powered’ security
When she was asked to let IT students run its SOC, New Jersey Institute of Technology CISO Sharon Kelley ran a mile. Find out why she changed her mind, and how Splunk is helping her raise a new generation of cyber analysts First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650824/Splunk-helps-US-research-uni-embrace-student-powered-security
-
Hackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer Data
Master of Malt reported a customer data breach after attackers allegedly compromised an application key linked to Ribon, a third-party BigCommerce app managed by Be A Part Of that identifies itself as a Fastr brand. BigCommerce notified the retailer of the incident on September 18, 2026, prompting Master of Malt to reach out to affected…
-
Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a previously undocumented backdoor. The activity occurred on September 3 and 4, 2026, while the targeted vulnerabilities remained unpatched in Google Chrome. It followed Volexity’s September 9 disclosure that UTA0560 and…
-
D-Link DIR-822A Router Vulnerability Scores CVSS 10.0 With Public PoC Available
D-Link has announced a critical stack-based buffer overflow vulnerability affecting the non-US DIR-822A router, identified as CVE-2026-86296. This vulnerability has received a maximum CVSS v3.1 score of 10.0 and a CVSS v4.0 score of 10.0. Furthermore, a public proof-of-concept (PoC) exploit is reportedly available. The company published advisory SAP10516 on September 18 and updated it…

