Tag: cyber
-
NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen/
-
Shared AI Memory Lets Hundreds of Agents Inherit Exploits and Join Coordinated Attacks
A shared message board turned isolated AI agents into an effective offensive collective during OpenAI’s July 2026 ExploitGym evaluations, enabling roughly 1,200 agents to exchange more than 70,000 messages and files. About 700 eventually participated in activity that compromised portions of Hugging Face’s production environment showing that shared agent memory can become a high-risk coordination…
-
NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery
The National Institute of Standards and Technology (NIST) has published new implementation guidance to safeguard identity tokens, access tokens, and assertions used in single sign-on, cloud federation, and application programming interface (API) environments. Released on September 15, 2026, NIST Internal Report 8587, titled >>Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for…
-
12 Best CIEM Tools Compared (2026): Features Pricing
Quick Answer: CIEM bills per identity or per cloud resource, and the count that matters is non-human identities machines outnumber people many-fold and inflate quotes fast. Tenable (Ermetic) and Wiz lead platform CIEM; Britive prices standalone JIT; CyberArk monetizes enforcement. Retirement alert: Microsoft Entra Permissions Management has been discontinued plan migrations, not renewals. Entitlement sprawl…
-
12 Best CASB Solutions Compared (2026): Features Pricing
Quick Answer: Nobody buys standalone CASB anymore you buy an SSE seat and CASB rides along. That flips the cost question: Defender for Cloud Apps is already inside M365 E5, Netskope/Zscaler/Skyhigh price CASB into per-user SSE bundles, and specialist attach (Proofpoint-style people-risk, Lookout mobile) is where incremental spend needs justifying. Category flag: Saviynt on legacy…
-
Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD warns that the campaign has targeted…
-
KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions
A Brazilian banking malware operation, dubbed KREMLIN, that can silently implant malicious extensions in Google Chrome and Microsoft Edge, bypassing Chromium’s built-in integrity protections to steal credentials, cookies, and active banking sessions. Despite its name, the KREMLIN toolkit shows no apparent Russian connection. The campaign relies on Portuguese-language artifacts, lures impersonating 12 Brazilian banks, and…
-
August: 53 Prozent mehr Cyber-Angriffe auf deutsche Unternehmen
Die Zahl der Cyberangriffe ist im August 2026 weltweit erneut gestiegen. Besonders deutlich fiel der Anstieg in Deutschland aus. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/august-mehr-cyber-angriffe
-
CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks
Tags: cisa, control, cyber, cybersecurity, defense, exploit, guide, hacker, identity, infrastructure, international, networkThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has collaborated with international partners to guide the defense of Active Directory (AD). They warn that attackers exploit 17 common techniques to gain control of identity infrastructure. The guide, released on September 15, was co-authored by the Australian Signals Directorate’s Australian Cyber Security Center, CISA, the NSA,…
-
Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities
Apple has released iOS 27 and iPadOS 27, delivering one of its largest mobile security update batches to date. The release addresses approximately 126 vulnerabilities within the operating system, including flaws affecting the kernel, sandboxing mechanisms, WebKit, authentication services, and other security-sensitive components. Released on September 14, 2026, iOS 27 is available for the iPhone…
-
Luciferus Uncensored AI Service Lets Cybercriminals Generate RAT Malware
Cybercriminals are promoting a new “uncensored” artificial intelligence service called Luciferus that allegedly generates malicious code, including components for remote access trojans (RATs), without the safeguards typically found in mainstream AI platforms. Researchers from the Sophos Counter Threat Unit reported that they first noticed a user named “Optimus_Prime” advertising this subscription service on August 24.…
-
OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign
3,022 RubyGems packages associated with the GemStuffer campaign, expanding the known scope of an incident that researchers have linked to an alleged OpenAI agent swarm. The inventory covers 3,315 distinct package name-and-version pairs and reveals a sustained campaign that combined documentation-worker abuse, data collection, credential-theft attempts, and metadata-based web attack tests. When a documentation worker…
-
Google Chrome 153 Released With Fixes for 42 Security Vulnerabilities
Google has released Chrome version 153 to the Stable channel for desktop, addressing 42 security vulnerabilities, including three critical-severity flaws affecting WebGL, Chrome internals, and Workers. This update is being rolled out as version 153.0.8010.47/48 for Windows and macOS, and as version 153.0.8010.47 for Linux. The release includes a wide range of memory-safety, authorization, race-condition,…
-
Cyber Op Targets South Korean Media & Automotive Sectors
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive
-
US Lawmakers Eye Stronger Healthcare Cyber Defenses
House Subcommittee Hearing Highlights Threats to Rural Hospitals and Patient Care. As U.S. hospitals, clinics and other medical providers continue to face an onslaught of hacking incidents and disruptive cyberattacks this year, the House Energy and Commerce Committee’s health subcommittee examined on Tuesday two proposed bills aimed at strengthening health sector cybersecurity. First seen on…
-
UK, US and Netherlands warn over Iranian state spyware campaign
Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650300/UK-US-and-Netherlands-warn-over-Iranian-state-spyware-campaign
-
Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.” First seen on therecord.media Jump to article: therecord.media/iran-cyber-spies-use-fake-mri-scans-as-lure
-
Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.” First seen on therecord.media Jump to article: therecord.media/iran-cyber-spies-use-fake-mri-scans-as-lure
-
Zelensky appoints former police chief to lead Ukraine’s cyber coordination center
Ihor Klymenko, who has experience in law enforcement and as interior minister, will run Ukraine’s National Cybersecurity Coordination Center. First seen on therecord.media Jump to article: therecord.media/ukraine-cyber-coordination-center-ihor-klymenko
-
Kura Appoints Acumen Cyber to Deliver 24/7 Cyber Defence
Customer experience provider Kura has appointed Acumen Cyber to provide 24/7 security monitoring, threat detection and incident response across its operations in the UK and South Africa. Kura supports more than 50 brands across financial services, utilities, healthcare and the public sector, operating from Glasgow, Sunderland and Durban. The company handles millions of customer interactions…
-
Google Search Makes It Harder to See Where a Link Really Goes Before You Click
Google has begun routing some organic Search result links through opaque google.com/goto?url=… redirects, reducing users’ ability to independently inspect a destination URL before clicking. The change appears designed to raise the technical and financial cost of mass scraping. However, it also weakens a long-standing, basic anti-phishing habit: hovering over a link to verify where it…
-
Google Search Makes It Harder to See Where a Link Really Goes Before You Click
Google has begun routing some organic Search result links through opaque google.com/goto?url=… redirects, reducing users’ ability to independently inspect a destination URL before clicking. The change appears designed to raise the technical and financial cost of mass scraping. However, it also weakens a long-standing, basic anti-phishing habit: hovering over a link to verify where it…
-
Google Search Makes It Harder to See Where a Link Really Goes Before You Click
Google has begun routing some organic Search result links through opaque google.com/goto?url=… redirects, reducing users’ ability to independently inspect a destination URL before clicking. The change appears designed to raise the technical and financial cost of mass scraping. However, it also weakens a long-standing, basic anti-phishing habit: hovering over a link to verify where it…
-
China spy chief points at US AI models in cyber threat warning
China’s spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development. First seen on therecord.media Jump to article: therecord.media/china-spy-chief-warns-of-us-ai-models
-
AI the Top Priority for New Spend as Cyber Budgets Flatline
IANS finds AI is dominating net-new budgets even as overall funding for the function is flat First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ai-top-priority-new-spend-cyber/
-
Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
Tags: attack, cyber, email, infrastructure, mail, malicious, malware, open-source, phishing, servicePhishing operators are increasingly shifting away from malware-laden attachments and toward trusted delivery services, authenticated domains, and multi-stage URL cloaking designed to defeat conventional email inspection. The continuously running VBSpam comparative test evaluated ten public full email-security products and one open-source solution against wanted, unwanted, and malicious mail streams. The assessment was conducted under the…
-
53 Prozent mehr Cyber-Angriffe auf deutsche Unternehmen im August
Der Monthly-Cyber-Threat-Report für August 2026 von Check Point Research (CPR), die Sicherheitsforschungsabteilung von Check Point Software Technologies, zeigt einen Anstieg globaler Cyber-Angriffe um 22 Prozent. Auch Phishing-Mails und Ransomware-Angriffe nehmen weltweit deutlich zu. Im vergangenen Monat verzeichneten Unternehmen Analysen von Check Point Research zufolge weltweit durchschnittlich 2422 Cyber-Angriffe pro Woche. Dies entspricht einem Anstieg von…
-
CyberAct Ohne Sicherheit kein Marktzugang
Die EU macht weiter Ernst und geht ihren Weg der Digital-Regulierung entschieden weiter. Wer jedoch den Cyber-Resilience-Act (CRA) als bloße nächste Compliance-Pflichtübung abtut, unterschätzt seine Wirkung fundamental: DSGVO und NIS2 drohen mit Bußgeldern, wenn etwas schiefgeht. Der CRA geht deutlich weiter: Produkte mit digitalen Elementen, die die Anforderungen nicht erfüllen, dürfen ab Dezember 2027 schlicht…
-
Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites. The vulnerability , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of…
-
WordPress Events Calendar Vulnerabilities Let Hackers Take Over 600,000 Websites
Two critical unauthenticated vulnerability chains in the widely used The Events Calendar WordPress plugin could allow attackers to execute code and fully compromise affected websites remotely. These flaws, identified by Wordfence Argus, impact plugin versions up to 6.17.4 and have been patched in version 6.17.4.1. The Events Calendar is active on over 600,000 WordPress websites,…

