Tag: cyber
-
North Korean IT Workers Pay People to Sit Through Job Interviews While They Control the Computer
North Korean IT-worker operators are recruiting foreign nationals to sit on camera during remote job interviews. At the same time, the real candidate provides answers, completes coding tasks, or remotely controls the proxy’s computer, according to new research from Silent Push. The campaign turns ordinary job seekers into identity and payment intermediaries, creating a direct…
-
SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
A wider cluster of SpiceRAT command-and-control infrastructure has been linked to the SilkParasite cyber-espionage activity targeting government, telecommunications, and energy-related entities across Central Asia. The infrastructure findings extend the operational footprint around servers previously associated with the suspected China-nexus cluster, but do not establish that any impersonated organization was compromised. Detection logic derived from Cisco…
-
GPT4Free Privacy Risks Expose AI Prompts to Third-Party Servers and Hidden Logs
Users of the GPT4Free hosted platform might believe they are directly interacting with the selected artificial intelligence model in its web interface. However, recent research suggests that prompts submitted through g4f.dev may travel through a complex network of provider code, intermediary services, external model endpoints, and potentially unrelated AI servers. These findings raise significant privacy…
-
BIND 9.20.29 Fixes 14 Security Flaws Enabling DNSSEC Bypass and DenialService Attacks
The Internet Systems Consortium (ISC) has released BIND 9.20.29, which addresses 14 security vulnerabilities. These vulnerabilities could enable remote attackers to bypass DNSSEC protections, poison resolver caches, exhaust CPU or memory resources, and crash the named service. This update is particularly important for organizations that operate recursive, DNSSEC-validating resolvers, as they are primarily exposed to…
-
Cyber Essentials Has Record Year but Takeup Remains Low
New government figures reveal a 20% annual increase in certifications First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cyber-essentials-has-record-year/
-
San Diego’s CISOs to Watch: A City That Keeps Its Security Leaders
San Diego’s security community is unusually well organized for a city its size. The San Diego CISO Roundtable, the Cyber Center of Excellence, SIM San Diego, and the local InfraGard chapter all appear in the careers below, and several of… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/san-diegos-cisos-to-watch-a-city-that-keeps-its-security-leaders/
-
FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments
China-aligned advanced persistent threat group FamousSparrow has replaced its long-running SparrowDoor implant with a new modular C++ backdoor, SparroWocky, in a sustained cyberespionage campaign against government entities across Latin America. ESET says the malware has been active in the region since at least August 2025, following a sharp shift in the group’s victim targeting that…
-
CISA Urges Organizations to Deploy Cyber Decoys to Detect Hackers Inside Networks
Tags: cisa, credentials, cyber, cybersecurity, data, detection, hacker, infrastructure, network, strategyThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to deploy cyber decoys, which include fake credentials, systems, data, and services. This strategy aims to expose attackers sooner and enhance post-compromise detection. In new guidance titled >>Using Cyber Decoys to Strengthen Detection and Response,<< published on September 16, 2026, CISA outlined how defenders…
-
Kubernetes Attack Lets Hackers Steal SPIFFE Workload Identities and Impersonate Applications
A post-exploitation technique that lets attackers with root-level access to a Kubernetes node steal workload identities issued through SPIFFE/SPIRE and impersonate legitimate applications running on the same host. The technique undermines the node-trust assumption behind cloud-native machine identity systems, potentially enabling attackers to access services protected by mutual TLS and identity-based authorization. Palo Alto Networks…
-
12 Best DSPM Tools Compared (2026): Features Pricing
Quick Answer: DSPM has the scariest pricing curve in security bills track data volume, and data only grows. Microsoft Purview publishes pay-as-you-go rates (the anchor); Cyera leads the independents; BigID and Varonis bring privacy and on-prem lineage; CrowdStrike (Flow) and Tenable (Eureka-lineage) mark the consolidation wave. Negotiate volume caps before your data does the negotiating.…
-
12 Best DSPM Tools Compared (2026): Features Pricing
Quick Answer: DSPM has the scariest pricing curve in security bills track data volume, and data only grows. Microsoft Purview publishes pay-as-you-go rates (the anchor); Cyera leads the independents; BigID and Varonis bring privacy and on-prem lineage; CrowdStrike (Flow) and Tenable (Eureka-lineage) mark the consolidation wave. Negotiate volume caps before your data does the negotiating.…
-
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
Ports, railroads, and utilities keep the military operational. They’re all vulnerable to Iranian cyberattacks. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/
-
APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal
Pakistan-nexus threat actor APT36 has launched a renewed espionage campaign targeting government and defense organizations in India and Afghanistan. Deploying a new Rust-based malware suite designed for covert command-and-control, data theft, and propagation into isolated networks. Tracked by Zscaler ThreatLabz as Operation RapidRust, the activity was observed in August 2026 and reflects a significant evolution…
-
12 Serverless Security Options Compared (2026): Features Pricing
Quick Answer: There is no standalone serverless-security SKU worth buying in 2026 functions are a line item inside CNAPP or observability contracts. Datadog publishes per-function rates (the category’s only clean anchor); Prisma Cloud carries the deepest lineage (PureSec); Aqua, Sysdig, Wiz, CloudGuard, and Fortinet (Lacework) bill functions inside platform units. Graveyard warning: Thundra and Epsagon…
-
NightEagle Hackers Abuse Microsoft Dev Tunnels and GhostContainer to Breach Russian Companies
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks. Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously…
-
RatHat Abuses Android Wireless Debugging to Gain Shell Access and Steal Banking PINs
RatHat, a newly identified Android banking malware family that combines Accessibility abuse, local Android Debug Bridge (ADB) pairing, native shell-level components, and generative-AI-assisted interface automation. The operation appears linked to China-based threat actors and is primarily designed to steal banking credentials, payment PINs, one-time passwords, device-unlock secrets, and other high-value data from infected Android devices.…
-
Hackers Turn AI Agent Into a Cyber Weapon After Deleting Its Safety Refusals
A French-speaking cybercrime crew calling itself BlackHatSect0r && DXQRTXX allegedly disabled safety controls in a self-hosted AI agent and used the resulting system to automate mass credential harvesting, target discovery, phishing preparation, and attack orchestration. The internet-exposed server reportedly contained 4.9 GB of material across 9,299 files, including a custom Go-based command-and-control platform named DXSCAN,…
-
Docker Sandboxes Vulnerabilities Let Malicious Guests Escape Workspace and Access Host Files
Docker has released security fixes for two serious vulnerabilities in Docker Sandboxes that could let a malicious guest environment bypass workspace isolation and access sensitive resources on the host. These flaws, identified as CVE-2026-77179 and CVE-2026-79994, were addressed in Docker Sandboxes version 0.42.0, which was released on September 7. Docker Sandboxes isolate development agents and…
-
BlackHatSect0r Hackers Disable AI Safety Controls to Automate Credential Theft and Cyberattacks
Tags: ai, attack, control, credentials, cyber, cyberattack, cybercrime, data-breach, hacker, Internet, phishing, theftA French-speaking cybercrime crew calling itself BlackHatSect0r && DXQRTXX allegedly disabled safety controls in a self-hosted AI agent and used the resulting system to automate mass credential harvesting, target discovery, phishing preparation, and attack orchestration. The internet-exposed server reportedly contained 4.9 GB of material across 9,299 files, including a custom Go-based command-and-control platform named DXSCAN,…
-
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Tags: advisory, credentials, cyber, flaw, rce, remote-code-execution, theft, update, vulnerability, xssJenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. The advisory, dated September 16, 2026, also addresses stored cross-site scripting (XSS), server-side request forgery (SSRF), credential exposure, path traversal, OAuth token hijacking,…
-
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Tags: advisory, credentials, cyber, flaw, rce, remote-code-execution, theft, update, vulnerability, xssJenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. The advisory, dated September 16, 2026, also addresses stored cross-site scripting (XSS), server-side request forgery (SSRF), credential exposure, path traversal, OAuth token hijacking,…
-
NightEagle Hackers Target Russian Companies Using GhostContainer Backdoor
The NightEagle advanced persistent threat group, tracked as APT-Q-95, has expanded its operations to target businesses in Russia, combining stolen VPN credentials, a stealthy Microsoft Exchange backdoor, and legitimate tunneling technologies to move through victim networks. Researchers from Kaspersky’s Global Emergency Response Team said the group has been active since at least 2023 and previously…
-
AI, Cryptanalysis and Offensive Security: Rahul Singh Choudhary on What Comes Next
The Cyber Express First seen on thecyberexpress.com Jump to article: thecyberexpress.com/ai-cryptanalysis-crypto-security/
-
Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication
Check Point has issued a high-severity security alert for CVE-2026-91843, which is a critical stack overflow vulnerability in the login process of its Security Management and Log Server products. This flaw could allow an unauthenticated remote attacker to execute arbitrary code with root privileges, posing a significant risk to organizations utilizing affected Check Point management…
-
Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication
Check Point has issued a high-severity security alert for CVE-2026-91843, which is a critical stack overflow vulnerability in the login process of its Security Management and Log Server products. This flaw could allow an unauthenticated remote attacker to execute arbitrary code with root privileges, posing a significant risk to organizations utilizing affected Check Point management…
-
Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication
Check Point has issued a high-severity security alert for CVE-2026-91843, which is a critical stack overflow vulnerability in the login process of its Security Management and Log Server products. This flaw could allow an unauthenticated remote attacker to execute arbitrary code with root privileges, posing a significant risk to organizations utilizing affected Check Point management…
-
Hugging Face Calls for Wider Access to AI Cyber Defenses
CEO Clem Delangue Urges Frontier Labs to Share Models, Compute and Threat Data. Organizations need more transparency and access to models and tools to fight against cyberattacks, according to Hugging Face CEO Clem Delangue, who said Wednesday that frontier should provide more compute and information. Hugging Face asked OpenAI for $100 million in compute. First…
-
Black Hat USA 2026 | OpenAI’s Deep Dive Into Hugging Face Incident
At Black Hat USA, OpenAI engineers reconstruct the Hugging Face incident and explore lessons learned about AI safeguards and cyber resilience. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/bhusa26huggingfacetalk
-
Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’
U.S. personnel boarded an oil tanker in the Gulf of Mexico to “ensure integrity of the vessel’s operational and information technology systems,” after an apparent cyberattack, the U.S. Coast Guard said. First seen on therecord.media Jump to article: therecord.media/oil-tanker-cyberattack-coast-guard-fbi

