Tag: cyber
-
Google Gemini also Broke Out of Its Test Environment
Google Gemini escaped a cyber test environment, reached three real companies, and exposed why AI security tests need strict isolation. Google has confirmed that one of its Gemini models broke into the systems of three real companies during a cybersecurity test in May. The incident is the first publicly known case in which a Google…
-
Google Gemini AI Hacked 3 Real Companies After Cybersecurity Test Exposed It to Internet
Google has confirmed that its Gemini artificial intelligence model accidentally accessed protected systems belonging to three real companies during a cybersecurity evaluation. The incident stemmed from a configuration error that exposed the AI agent to the public internet. Google Gemini AI Hacked This situation highlights how autonomous AI systems can breach intended testing boundaries when…
-
North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto
North Korean threat actors, known as WaterPlum (also referred to as Contagious Interview), have infected at least 30,000 devices in over 100 countries by luring software developers and IT professionals into malicious job interviews. This campaign specifically targets web developers, freelancers, blockchain specialists, and cryptocurrency professionals. The attackers use persuasive recruitment messages that mimic legitimate…
-
AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes
Researchers have identified a new Android banking Trojan called RatHat that utilizes artificial intelligence to automate device compromise and steal financial credentials, PINs, and one-time passcodes. Zimperium’s zLabs researchers analyzed this malware, which represents a significant evolution in Android threats. AI-Powered RatHat Android Trojan Unlike traditional malware that relies on fixed scripts, RatHat offers a…
-
PowerShell Malware Abuses Registry and DNS TXT Records to Deploy XMRig Crypto Miner
A sophisticated cryptomining campaign is employing multiple layers of obfuscation to conceal malicious PowerShell payloads and ultimately deploy an XMRig-based cryptocurrency miner. This obfuscation includes Windows Registry entries, DNS TXT records, PNG images, and WAV audio files. The infection was detected after repeated security alerts indicated suspicious PowerShell activity. The initial execution command launched PowerShell…
-
Cyber Defense Alone Can’t Keep Critical Services Running
States Must Map Dependencies and Engineer Safeguards for Water and Hospitals. State CIOs must decide which water systems, hospitals and other essential services need protection first. NASCIO data shows why states should rank infrastructure by consequence, test simultaneous failures and pair cyber defenses with engineering safeguards. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-defense-alone-cant-keep-critical-services-running-a-32871
-
Post-Mythos Security Rally Rewards Broad Cyber Platforms
6 Major Security Vendors Have Doubled in Value Since Anthropic Unveiled Mythos Six prominent cybersecurity vendors have doubled their valuations since Anthropic announced Claude Mythos in April, led by Okta’s 131% stock surge as investors bet that AI agents will drive demand for identity, data, network and integrated security platforms. First seen on govinfosecurity.com Jump…
-
ISMG Editors: Even Valid Email Addresses Can’t Be Trusted
Also: States Inherit America’s Cyber Burden, AI Agents Reshape the MSSP Market. In this week’s panel, four ISMG editors discuss an unusual breach at U.K. digital banking platform Revolut, the growing role of U.S. state governments in protecting local critical infrastructure and what a new cybersecurity acquisition tells us about the AI-powered SOC. First seen…
-
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum”, a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. First seen on therecord.media Jump to article: therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme
-
US cyber agency endorses ‘decoy’ tactics
Official US guidance suggests organisations consider using cyber decoys to strengthen their detection and response capabilities. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650815/US-cyber-agency-endorses-decoy-tactics
-
AI Governance Is Key”, But Don’t Let It Slow Down Cyber Defense: Optiv CISO
While businesses must make governance an essential part of their AI strategies, it’s also important to not allow policies and approval processes to prevent defenders from moving as quickly as today’s increasingly machine-speed attackers, according to Optiv security chief Rob Gregory. First seen on crn.com Jump to article: www.crn.com/news/security/2026/ai-governance-is-key-but-don-t-let-it-slow-down-cyber-defense-optiv-ciso
-
The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown
This weekly roundup covers a stark small-business cyberattack report out of the UK, a hardware flaw exposing Nintendo Switch owners to nearby attackers, the largest known seizure of AI deepfake porn websites, a candid conversation on AI’s role in offensive security, new US legislation targeting elder fraud, and a fresh national threat-intelligence partnership in the…
-
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation…
-
PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains
China-aligned threat actors are using low-quality Chinese-language casino and adult websites to conceal PeckBirdy command-and-control infrastructure, creating a detection challenge for enterprises that routinely deprioritize gambling-related domains. Infoblox telemetry found that just over 3% of enterprise customers resolved at least one PeckBirdy-related C2 domain, indicating that the infrastructure is appearing well beyond the campaign’s apparent…
-
Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware
Feral Wolf has expanded its ransomware tradecraft by abusing exposed Atlassian Confluence servers and insecure 1C:Enterprise deployments to gain access to Russian corporate networks before deploying GenieLocker ransomware. The campaign, tracked from May through August 2026, targeted organizations in the retail, construction, manufacturing, and IT sectors. BI.ZONE DFIR investigators found that the threat actor combined…
-
New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems
A newly observed ransomware operation dubbed SETTRA is abusing the legitimate MeshAgent remote monitoring and management platform for persistence while using recovery-inhibition and defense-evasion techniques to maximize the impact of Windows encryption attacks. Huntress investigated two SETTRA incidents in July and September 2026, uncovering a repeatable operational pattern involving victim-specific ransomware binaries, Windows log clearing,…
-
JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data
Tags: ai, attack, cyber, data, data-breach, extortion, group, infrastructure, intelligence, ransomware, threat, trainingJADEPUFFER, the agentic threat actor first linked to an autonomous ransomware operation against exposed Langflow infrastructure, has evolved its tooling to target artificial intelligence models, training datasets, and vector data. Its latest payload, ENCFORGE, marks a shift from conventional database extortion toward destruction-focused attacks on high-value AI and machine-learning assets. The group’s ENCFORGE locker targets…
-
GISEC: UAE advances collective cyber resilience in AI and quantum era
The UAE Cyber Security Council is advancing a strategy built on AI, cyber readiness and emerging technologies as organisations prepare for the next generation of threats First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650673/GISEC-UAE-advances-collective-cyber-resilience-in-AI-and-quantum-era
-
Filigran Backs Security Serious Unsung Heroes Awards as New Sponsor
Nominations are open for the 2026 Security Serious Unsung Heroes Awards, celebrating the people working behind the scenes to make the UK safer and better protected from cyber threats. This year’s awards will take place on 20 October at Balfour St Barts in London, bringing together cybersecurity professionals, educators, researchers, journalists and industry leaders during Cybersecurity…
-
Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities
Google has released Chrome version 153 to the Stable desktop channel, addressing 16 security vulnerabilities, including two critical-severity flaws affecting the Dawn graphics component and WebGL. This update is rolling out as version 153.0.8010.52 for Windows and macOS. Linux users will receive version 153.0.8010.52 over the coming days and weeks. Google Chrome 153 Update Fixes…
-
Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability
Tags: ai, control, cyber, data-breach, intelligence, rce, remote-code-execution, threat, vulnerability, wordpressMore than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could allow low-privileged users to take control of vulnerable servers. The vulnerability was discovered on August 23, 2026, by Wordfence Argus, an AI-assisted vulnerability research agent, and validated by the Wordfence Threat Intelligence team.…
-
Researchers Find Security Risks in 73.6% of 61,500 Abandoned IoT Apps
Researchers have identified significant security and privacy risks across 61,500 abandoned Android Internet-of-Things (IoT) companion applications. Their study found that 73.6% of these apps contained at least one potential vulnerability, risky embedded resource, or insecure communication path. Risks in Abandoned IoT Apps Titled >>When Apps Outlive Vendors: Security Implications of IoT Abandonware,<< the study examines…
-
Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials
A critical vulnerability in pgAdmin 4 could allow unauthenticated remote attackers to impersonate arbitrary users, including existing administrator accounts, by supplying a malicious HTTP identity header. This vulnerability, tracked as CVE-2026-86863, affects installations using pgAdmin’s Webserver authentication mode and has a CVSS 3.1 score of 9.8 out of 10. The issue impacts pgAdmin 4 versions…
-
ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
Threat actors are increasingly impersonating OpenAI’s ChatGPT service in credential-phishing campaigns, exploiting the growing use of generative AI across both enterprise and personal environments. A recently observed campaign uses a fraudulent subscription-payment notice to lure victims into disclosing OpenAI account credentials and potentially payment details through a convincing fake ChatGPT login page. The lure claims…
-
Linux Kernel Hit by 4 LPE Flaws Enabling Attackers to Gain Root Shell
Linux administrators are being urged to patch four newly disclosed local privilege escalation (LPE) vulnerabilities, collectively known as DirtyAH6, TUNderflow, PPPoEject, and DiagSpill. These vulnerabilities can allow attackers to corrupt kernel memory and gain root-level access on affected systems. The vulnerabilities are tracked under the following CVE identifiers: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469. They affect…
-
Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI
A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interaction. Researchers Or Nevo, Dor Granat, and Niv Hoffman have identified that the issue impacts Anthropic Claude Code, OpenAI Codex,…
-
Hackers Exploit MikroTik Vulnerabilities to Take Over MikroTik Routers Without Authentication
Attackers are actively exploiting a critical vulnerability chain dubbed MikroTrick to seize full administrative control of internet-exposed MikroTik RouterOS devices without valid credentials. CERT Polska disclosed six RouterOS vulnerabilities on September 5, 2026, warning that two critical vulnerabilities could be chained to take over publicly reachable routers. The Polish national CSIRT said it had confirmed…
-
12 Best Multi-Cloud Security Platforms Compared (2026): Features Pricing
Quick Answer: Multi-cloud doesn’t just triple your attack surface it triples your billing surface, and vendors price the same workload differently per provider. Wiz and Prisma Cloud sell one-contract parity; Microsoft publishes rates that now extend to AWS/GCP connectors; Fortinet and Check Point bundle into fabric ELAs; Aviatrix bills the network layer everyone else ignores.…
-
12 Best CDR Solutions Compared (2026): Features Pricing
Quick Answer: Cloud detection has a real free floor Falco (OSS, on this list in its own right) plus usage-priced native services (GuardDuty-class) so paid CDR must justify itself on correlation and response speed. CrowdStrike, Wiz, and Palo Alto bill CDR inside platform units; Sysdig monetizes the Falco lineage; specialists Permiso (identity), Stream.Security (real-time model),…
-
WordPress 7.1.1 Fixes 11 Security Flaws Including Stored XSS and Path Traversal
WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST API functionality, comments, XML-RPC, and plugin management. Site administrators are strongly urged to update immediately due to the potential impacts of stored cross-site scripting, authenticated path traversal, authorization bypasses, and information disclosure flaws. This release…

