Tag: cyber
-
Black Hat USA 2026 | OpenAI’s Deep Dive Into Hugging Face Incident
At Black Hat USA, OpenAI engineers reconstruct the Hugging Face incident and explore lessons learned about AI safeguards and cyber resilience. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/bhusa26huggingfacetalk
-
Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’
U.S. personnel boarded an oil tanker in the Gulf of Mexico to “ensure integrity of the vessel’s operational and information technology systems,” after an apparent cyberattack, the U.S. Coast Guard said. First seen on therecord.media Jump to article: therecord.media/oil-tanker-cyberattack-coast-guard-fbi
-
Cybersecurity Innovation Takes Centre Stage in International Cyber Expo Awards Shortlist
International Cyber Expo has revealed the ten finalists shortlisted for its 2026 Innovation Awards & Trail, with cybersecurity technologies featuring prominently among the products selected by the independent judging panel. Making its debut at International Cyber Expo following its success at International Security Expo, the Innovation Awards & Trail will showcase technologies addressing some of…
-
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be part of a much broader cyber incident involving compromised Italian government infrastructure. Revolut has confirmed that its systems were not breached. Instead,…
-
TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Tags: access, authentication, cctv, cve, cyber, cybersecurity, flaw, infrastructure, network, password, vulnerabilitySecurity researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass administrator authentication or disrupt the device’s management service. Khoi Tran and Thai Do from OPSWAT Unit 515 discovered these vulnerabilities, tracked as CVE-2026-15315 and CVE-2026-15316, during the company’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. TP-Link…
-
Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems
Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware has been active since at least mid-2016 but was long mistaken for variants of Gh0st RAT, Rekoobe, and other…
-
Parallels Desktop Flaw Lets Unprivileged Mac Users Gain Root Access
A critical local privilege escalation vulnerability in Parallels Desktop could allow an unprivileged macOS user or a malicious process to gain root-level access to the host system. The issue, tracked as CVE-2026-90894, was disclosed by Yuval Moravchick from JFrog’s Vulnerability Research team and has been named “ParaShells.” This flaw was demonstrated against Parallels Desktop version…
-
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cyber-vendors-mitre-uk-testing/
-
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cyber-vendors-mitre-uk-testing/
-
Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional
Stamford, CT, September 16th, 2026, CyberNewswire Now in early access, AxoDetect runs Sigma rules in stream alerts travel to the SIEM, and full-fidelity logs land in AxoLake, a low-cost security data lake Detection engineers do not need more detections. They need their existing detections to fire earlier, on cleaner data, without paying SIEM ingest rates…
-
Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time passwords, online-banking credentials, identity information, and digital-wallet logins. Group-IB attributed the activity to an operator sub-cluster tracked as Outsider, which appears to operate as a customer within the wider phishing-as-a-service ecosystem rather…
-
Quorum Cyber Adds Autonomous SOC Through Ontinue Acquisition
Proposed Purchase Combines Agentic SOC Technology With Managed Security Expertise. Quorum Cyber’s planned acquisition of Swiss Microsoft Gold Partner Ontinue would combine Microsoft-focused managed security with agentic SOC technology designed to investigate threats at machine speed while giving customers control over when AI can act autonomously. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/quorum-cyber-adds-autonomous-soc-through-ontinue-acquisition-a-32826
-
Cyber-Attacks Cost Organizations $52,000 on Average
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cyberattacks-cost-organizations/
-
Cyber-Attacks Cost Organizations $52,000 on Average
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cyberattacks-cost-organizations/
-
12 Best Kubernetes Security Tools Compared (2026): Features Pricing
Quick Answer: Kubernetes security quotes hinge on the node-vs-cluster-vs-developer unit choice, and the OSS floor (Kubescape, Falco, Calico, NeuVector, Cilium/Tetragon) resets every negotiation. Sysdig and Aqua lead paid runtime/lifecycle; Cisco (Isovalent) now owns the eBPF network layer; Fairwinds sells governance-as-guardrails; Microsoft Defender publishes the anchor rates. Kubernetes made compute cheap to sprawl and expensive to…
-
Acronis Backup Plugin Vulnerability Exploited in the Wild to Gain Elevated Linux Privileges
Acronis has released an urgent security update for a high-severity local privilege escalation vulnerability affecting its Backup plugin for cPanel & WHM on Linux. The company confirmed that attackers have already exploited this flaw in limited, targeted attacks against vulnerable deployments. This vulnerability is tracked as CVE-2026-87886 and is described as an insecure file permissions…
-
12 Best Container Security Tools Compared (2026): Features Pricing
Quick Answer: Container security has the deepest free floor in the industry Trivy, Falco, and SUSE NeuVector (fully open-sourced) cover scan, runtime, and full-lifecycle at $0 so commercial spend must justify itself on enforcement and scale. Sysdig, Aqua, and Prisma bill per workload/node; Snyk bills per developer; Microsoft publishes per-vCore rates. The billable-unit choice changes…
-
PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the available evidence does not support definitive attribution…
-
PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the available evidence does not support definitive attribution…
-
PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the available evidence does not support definitive attribution…
-
Apache Superset SQL Injection Flaw Gets Public PoC Exploit
A public proof-of-concept exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset installations running versions earlier than 6.0.0. The Apache Superset project disclosed this issue in February. It classified it as an improper neutralization of special elements in a SQL command. Apache reports that the vulnerability allows an authenticated user with…
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists
Iranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through social messaging apps and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/iranian-hackers-chosen-brick-malware-dissidents-journalists/
-
UK, US and Netherlands warn of Iranian state spyware campaign
Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650300/UK-US-and-Netherlands-warn-over-Iranian-state-spyware-campaign
-
China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic into apparent gambling activity. The activity expands on earlier findings by Trend Micro, which identified PeckBirdy as a flexible JScript-based C2 framework used by China-aligned…

