Tag: cyber
-
Splunk helps US research uni embrace ‘student-powered’ security
When she was asked to let IT students run its SOC, New Jersey Institute of Technology CISO Sharon Kelley ran a mile. Find out why she changed her mind, and how Splunk is helping her raise a new generation of cyber analysts First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650824/Splunk-helps-US-research-uni-embrace-student-powered-security
-
Hackers Abuse Stolen BigCommerce App Key to Steal Master of Malt Customer Data
Master of Malt reported a customer data breach after attackers allegedly compromised an application key linked to Ribon, a third-party BigCommerce app managed by Be A Part Of that identifies itself as a Fastr brand. BigCommerce notified the retailer of the incident on September 18, 2026, prompting Master of Malt to reach out to affected…
-
Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a previously undocumented backdoor. The activity occurred on September 3 and 4, 2026, while the targeted vulnerabilities remained unpatched in Google Chrome. It followed Volexity’s September 9 disclosure that UTA0560 and…
-
D-Link DIR-822A Router Vulnerability Scores CVSS 10.0 With Public PoC Available
D-Link has announced a critical stack-based buffer overflow vulnerability affecting the non-US DIR-822A router, identified as CVE-2026-86296. This vulnerability has received a maximum CVSS v3.1 score of 10.0 and a CVSS v4.0 score of 10.0. Furthermore, a public proof-of-concept (PoC) exploit is reportedly available. The company published advisory SAP10516 on September 18 and updated it…
-
CISA Flags Actively Exploited Flaw in Zyxel GS1900 Switches
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included a high-severity vulnerability affecting Zyxel GS1900 Series switches in its Known Exploited Vulnerabilities (KEV) Catalog. This warning highlights that the flaw, tracked as CVE-2026-7273, has been exploited in the wild. The vulnerability stems from a stack-based buffer overflow in the device’s CGI program. CISA added…
-
Hackers Compromise 65 GitHub Repositories and Poison npm Package With Hidden Backdoor
Threat actors have compromised at least 65 public GitHub repositories in a software supply-chain campaign that abused npm trusted publishing to distribute a stealthy backdoor through a legitimate package. The malicious package was identified as @dforge-core/dforge-mcp, an MCP-related npm package whose maintainer account was abused for roughly 105 minutes on September 9. Attackers initially pushed…
-
Contagious Interview: 30,000 devices infected by a fake job interview
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview.…
-
Hackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data
A suspected Chinese-speaking threat actor has exploited the critical WordPress “wp2shell” vulnerability chain to compromise government and small-business targets across 29 countries, stealing at least 18,566 sensitive records from one Western government organization. GreyNoise linked the activity to a malicious cyber actor (MCA) it has tracked through its Global Observation Grid since early June. The…
-
Windows 11 26H1 Security Update Expands Secure Boot Certificate Protection
Microsoft has released the cumulative security update for September 2026 for Windows 11 version 26H1. This update expands the range of systems that can automatically receive new Secure Boot certificates. KB5124012, released on September 8, brings devices to OS Build 28000.2954. It includes enhanced, high-confidence device-targeting data to improve certificate deployment coverage across supported PCs…
-
Microsoft to Disable SMS as Primary Entra ID Sign-In Method in 2027
Microsoft will turn off SMS as a primary sign-in method for Microsoft Entra ID workforce tenants on February 1, 2027, accelerating its transition to phishing-resistant authentication. This change affects workers who currently use a registered phone number and a one-time SMS code as their initial sign-in credential, a passwordless flow utilized by frontline organizations. Microsoft…
-
Vidar Uses Custom Bytecode Interpreter and ARX Stream Ciphers for Per-Build String Obfuscation
Vidar information stealer has introduced a lightweight custom virtual machine and per-build stream-cipher variations to conceal its embedded strings, raising the cost of static detection and automated reverse engineering. First observed in 2018, Vidar remains a widely tracked credential-stealing malware family. Its operators continually alter internal protections without necessarily changing the malware’s broader operational purpose:…
-
Vidar Uses Custom Bytecode Interpreter and ARX Stream Ciphers for Per-Build String Obfuscation
Vidar information stealer has introduced a lightweight custom virtual machine and per-build stream-cipher variations to conceal its embedded strings, raising the cost of static detection and automated reverse engineering. First observed in 2018, Vidar remains a widely tracked credential-stealing malware family. Its operators continually alter internal protections without necessarily changing the malware’s broader operational purpose:…
-
AWS Detects and Quarantines Exposed IAM Credentials in Public GitHub Repositories
AWS can automatically quarantine exposed Identity and Access Management (IAM) access keys that appear in public GitHub repositories. This process involves applying a restrictive managed policy within seconds to reduce the risk of cloud abuse. Researchers from Palo Alto Networks’ Unit 42 documented this response mechanism, showing that AWS employs the AWSCompromisedKeyQuarantine managed policy to…
-
Google Fined Euro403 Million for GDPR Violations Over Location Data Processing
Ireland’s Data Protection Commission (DPC) has imposed a Euro403 million administrative fine on Google Ireland Limited for breaching the EU General Data Protection Regulation (GDPR) by processing users’ location data. This decision follows an inquiry initiated in February 2020 after complaints from European consumer rights organizations, including BEUC. The investigation examined Google’s practices from May…
-
One Stolen Active Directory File Can Expose Credentials for an Entire Windows Domain
A single stolen Active Directory database can turn a limited Windows intrusion into a domain-wide credential compromise. Threat actors that obtain the NTDS.dIT file from a domain controller, along with its corresponding SYSTEM registry hive, can extract password hashes, Kerberos keys, and password-history data for domain identities offline. While attackers may rotate payloads, loaders, command-and-control…
-
One Stolen Active Directory File Can Expose Credentials for an Entire Windows Domain
A single stolen Active Directory database can turn a limited Windows intrusion into a domain-wide credential compromise. Threat actors that obtain the NTDS.dIT file from a domain controller, along with its corresponding SYSTEM registry hive, can extract password hashes, Kerberos keys, and password-history data for domain identities offline. While attackers may rotate payloads, loaders, command-and-control…
-
Meta’s Muse AI 0-Day Lets Hackers Hijack Dictation Traffic and Inject Malicious Prompts
A recent proof-of-concept (PoC) developed by security researcher Patrick Wardle reveals a local zero-day vulnerability in the Muse application. This vulnerability allows malware running under the logged-in user’s account to redirect dictation traffic to a server controlled by an attacker. Meta’s Muse AI 0-Day The issue is documented in Wardle’s >>not-a-mused<< research repository. It focuses…
-
ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers
Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server. First seen on hackread.com Jump to article: hackread.com/clickfix-chainscript-rat-fake-spotify-teams-installers/
-
Cyber Extortion War: ShinyHunters Holds Rival Clop to Ransom
Website Defacement Tied to Alleged Theft of Oracle E-Business Suite Exploits Russian cyber extortion group Cl0p appears to be under fire from Western rival ShinyHunters, which defaced Cl0p’s data-leak site, dropped names of the group’s alleged members, and demanded a large ransom in response to alleged death threats and the theft of its Oracle E-Business…
-
Cyber Extortion War: ShinyHunters Holds Rival Clop to Ransom
Website Defacement Tied to Alleged Theft of Oracle E-Business Suite Exploits Russian cyber extortion group Cl0p appears to be under fire from Western rival ShinyHunters, which defaced Cl0p’s data-leak site, dropped names of the group’s alleged members, and demanded a large ransom in response to alleged death threats and the theft of its Oracle E-Business…
-
EU states failing to exchange information on cross-border cyber security attacks
European Union urged to deploy real-time European cyber alert platform to share information with member states on cross-border cyber attacks First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650821/EU-states-failing-to-exchange-information-on-cross-border-cyber-security-attacks
-
EU states failing to exchange information on cross-border cyber security attacks
European Union urged to deploy real-time European cyber alert platform to share information with member states on cross-border cyber attacks First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650821/EU-states-failing-to-exchange-information-on-cross-border-cyber-security-attacks
-
Not So Harmonious: EU States Hoard Cyber Incident Data
Cross-Border Cooperation Hasn’t Reached Cybersecurity Incidents, Auditors Find. When hackers triggered cascading disruptions to European air travel in fall 2025, none of the affected countries – including Germany, Belgium and Ireland – activated European Union-level coordination to cope with the incident. The go-it-alone approach is endemic. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/so-harmonious-eu-states-hoard-cyber-incident-data-a-32881
-
EU-Gesetz zur Cyber-Resilienz ist in Kraft
Artikel 14 des EU-Gesetzes zur Cyber-Resilienz (CRA) ist jetzt in Kraft und verpflichtet Hersteller vernetzter Produkte, aktiv ausgenutzte Sicherheitslücken innerhalb von 24 Stunden der Europäischen Agentur für Cybersicherheit zu melden. Eine ausführlichere Meldung muss innerhalb von 72 Stunden folgen, und ein Abschlussbericht ist innerhalb von 14 Tagen vorzulegen, sobald eine Lösung verfügbar ist. Die Verpflichtung…
-
NightEagle Uses BlueKeep and DCSync to Move Toward Active Directory Domain Controllers
NightEagle, an espionage-focused threat group also tracked as APT-Q-95, has expanded its operations from Asian targets to Russian organizations, using a layered intrusion chain that culminates in attempts to compromise Active Directory domain controllers. The campaign illustrates a familiar but dangerous enterprise compromise pattern: attackers do not need a novel zero-day exploit when exposed remote…
-
10 Malicious npm Packages Linked to Runtime Malware Campaign With Millions of Downloads
A sophisticated npm supply-chain campaign has been linked to 10 malicious JavaScript packages that collectively recorded millions of downloads while bypassing npm’s lifecycle-script protections. The operation centers on a counterfeit package named indexed-btree, which impersonates the legitimate sorted-btree library and executes its malware only when an application uses the package at runtime. Unlike conventional npm…
-
PAYLOAD Ransomware Abuses Active Directory Group Policy to Disrupt Entire Windows Domain
A ransomware incident in which attackers used Active Directory Group Policy to disrupt operations without deploying a Windows encryptor or leaving malware running on endpoints. In April 2026, the attackers accessed a FortiGate SSL VPN using compromised domain credentials, then gained domain-admin-equivalent rights. PAYLOAD Ransomware On April 13, Kaspersky’s Global Emergency Response Team (GERT) created…
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…

