Tag: cyber
-
CrowdStrike warns AI agents are creating a cyber battleground for GCC organisations
Artificial intelligence is lowering the barrier to entry for cyber criminals, accelerating attack speeds and increasing the complexity of threats, prompting organisations to rethink resilience, governance and security operations First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650857/CrowdStrike-warns-AI-agents-are-creating-a-cyber-battleground-for-GCC-organisations
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning systems in Pyongyang and Russia’s Far East. The certificate’s Subject Alternative Name field lists the platform’s publicly exposed servers alongside a carrier-grade NAT address, offering an unusual glimpse into how the service may be…
-
Hackers Abuse Microsoft Teams to Pose as IT Support and Steal Employee Passwords
Threat actors are increasingly abusing Microsoft Teams’ external chat capabilities to impersonate corporate IT help desks. They trick employees into installing malware, granting remote access, and stealing Windows credentials. These attacks exploit a simple vulnerability: employees tend to distrust suspicious emails but often do not apply the same caution to collaboration platforms like Teams. Attackers…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches
Security researchers have unveiled a cache poisoning technique called cache key injection that lets attackers bypass access controls, expose cached sensitive pages, trigger denial-of-service conditions, and potentially execute stored cross-site scripting (XSS) attacks against vulnerable Nginx deployments. Research by YesWeHack researcher Alex Brumen highlights flaws that occur when web caches create cache keys by directly…
-
Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized Terraform lock files in fake job-interview repositories to infect DevOps engineers with macOS backdoors. SentinelOne identified an Indian IT services provider compromised with the same FLATROOF and ROOFDECK implants previously linked to the April 2026 KelpDAO-LayerZero attack. The campaign…
-
HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise
Tags: attack, cyber, data, flaw, github, malicious, rce, remote-code-execution, supply-chain, technology, threat“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote code execution, sensitive-data exposure, and account compromise across major technology and enterprise platforms. The research, published by Hacktron, highlights a familiar but increasingly dangerous supply-chain weakness: applications often trust native image-decoding…
-
Exim Mail Server Hit by 4 Security Flaws Enabling SMTP Smuggling and Heap Corruption
Exim maintainers have released version 4.100.1 to address four security vulnerabilities affecting the widely used mail transfer agent. This update resolves issues that could potentially enable SMTP smuggling and heap-memory corruption under certain configurations. The release, announced on September 18, fixes the following vulnerabilities: GCVE-25-2026-09-50-1, GCVE-25-2026-09-51-1, GCVE-25-2026-09-55-1, and GCVE-25-2026-09-56-1. Administrators using vulnerable installations of Exim…
-
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds harvest browser data, password-manager and 2FA-extension artifacts, cryptocurrency-wallet files, application credentials, and AI assistant credential folders, potentially exposing…
-
New Remus Infostealer Steals OpenAI and Anthropic API Tokens, Passwords and Crypto Wallets
A newly tracked Windows infostealer dubbed Remus is expanding its credential-theft playbook by targeting API tokens and local usage data tied to AI platforms, including OpenAI and Anthropic. Researchers at SpyCloud Labs found that recent Remus builds harvest browser data, password-manager and 2FA-extension artifacts, cryptocurrency-wallet files, application credentials, and AI assistant credential folders, potentially exposing…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
BragJack Attack Hijacks AI Assistants in 5 Popular Browsers With Zero Clicks
Security researchers have revealed a zero-click attack technique known as BragJack, which could enable a malicious browser extension to hijack built-in AI assistants in popular browsers like Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The research, published on September 16 by Gal Weizman of Forever Security, describes a common architectural…
-
BragJack Attack Hijacks AI Assistants in 5 Popular Browsers With Zero Clicks
Security researchers have revealed a zero-click attack technique known as BragJack, which could enable a malicious browser extension to hijack built-in AI assistants in popular browsers like Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. The research, published on September 16 by Gal Weizman of Forever Security, describes a common architectural…
-
Click2Shell WordPress Flaw Lets Hackers Execute PHP Code and Take Over Websites
A recently disclosed WordPress vulnerability, known as Click2Shell, could let attackers execute remote PHP code on vulnerable sites after convincing a logged-in administrator to click a specially crafted link. WordPress version 7.1.1, released on September 17, 2026, addresses this issue. Researchers at PWNAI reported that the flaw exploits WordPress’s theme-preview workflow to install a theme…
-
Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credential. CrowdSec stated that the compromise originated from a former employee’s account, which remained in the company’s GitHub organization for…
-
Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credential. CrowdSec stated that the compromise originated from a former employee’s account, which remained in the company’s GitHub organization for…
-
Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credential. CrowdSec stated that the compromise originated from a former employee’s account, which remained in the company’s GitHub organization for…
-
Hackers Abuse Critical cPanel Authentication Bypass to Compromise Hosting Servers
Threat actors rapidly exploited a critical authentication bypass in cPanel and WHM to compromise internet-facing hosting servers, with Japanese telemetry data linking the campaign to a sharp rise in Mirai-like scanning and attack traffic targeting Telnet services. The activity centers on CVE-2026-41940, a critical vulnerability in cPanel and WHM’s session-management layer that enables a remote,…
-
UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day
The UAE faced 640,000 cyberattacks in one day, its cyber chief says, highlighting risks from unpatched software, ransomware, and deepfakes. The post UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-uae-640000-cyberattacks-deepfakes-ransomware-emea/
-
Google Gemini also Broke Out of Its Test Environment
Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity test in May. The incident is the first publicly known case in which a Google…

