Tag: cyber
-
Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit
Tags: access, china, credentials, cyber, exploit, hacker, linux, rce, remote-code-execution, threat, vulnerabilityA Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution (RCE) vulnerability in Gitea to steal private source code, harvest credentials, establish persistent access, and move laterally within victim infrastructures. Researchers from the Acronis Threat Research Unit (TRU) have linked this operation to a newly documented Linux implant called JITTERLY,…
-
Suspected Black Axe gang leaders face cybercrime charges in the US
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/black-axe-gang-members-extradited-to-us-face-cybercrime-charges/
-
Telegram Desktop XSS Vulnerability Lets Attackers Steal Entire Chat Histories
A stored cross-site scripting (XSS) vulnerability in Telegram Desktop could enable attackers to steal the contents of exported chat histories by embedding malicious code in an inline keyboard button, according to security researchers. This issue affects the HTML chat export feature in Telegram Desktop builds released before Beta version 6.9.4 and Stable version 7.0.1. Researchers…
-
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
Tags: authentication, credentials, cve, cyber, exploit, flaw, hacker, rce, remote-code-execution, threat, vulnerabilityA threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds, according to the Sysdig Threat Research Team. This vulnerability, tracked as CVE-2026-39987, affects marimo versions up to 0.20.4 and…
-
DDRop Attack Forces Intel TDX Confidential VMs Into Debug Mode and Exposes Memory
A newly disclosed hardware attack dubbed DDRop can undermine Intel Trust Domain Extensions (TDX) by manipulating DDR5 memory traffic, allowing an attacker with physical server access to force confidential virtual machines into debug mode and extract private memory in plaintext. Researchers from KU Leuven, ETH Zurich, Google, Durham University, and other institutions released proof-of-concept code,…
-
Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware
Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as behavior requiring process, identity, and endpoint context.…
-
Linux Kernel ZcopyReaper Vulnerability Lets Local Attackers Gain Root Privileges
Security researchers have disclosed a local privilege escalation vulnerability in the Linux kernel related to the Reliable Datagram Sockets (RDS) zero-copy send path. This vulnerability could let an unprivileged local attacker gain root privileges. It is tracked as CVE-2026-43502 and is referred to as “ZcopyReaper.” NebuSec researcher Yuan Tan reported the issue in a disclosure…
-
Microsoft Offers $60,000 Bounty for Critical Cross-Tenant Vulnerabilities
Microsoft has expanded its incentives for security researchers focusing on Dynamics 365 and Power Platform, offering rewards ranging from $1,250 to $60,000 for qualifying vulnerabilities. The program prioritizes flaws that have a direct and demonstrable security impact in supported cloud services, including cross-tenant issues that could compromise isolation between customer environments. Microsoft Offers $60,000 Bounty…
-
Hackers Deploy Agentic AI to Automate Exploitation and Mass Credential Harvesting
Threat actors are moving from using artificial intelligence as a productivity aid to deploying autonomous agentic systems that can execute major portions of an intrusion with minimal human intervention. Google Threat Intelligence Group (GTIG) has documented a financially motivated actor that used a multi-agent framework to plan, build, and run a mass credential-harvesting operation in…
-
12 Best CNAPP Platforms Compared (2026): Features Pricing
Quick Answer: CNAPP quotes swing 23× on identical estates because “workload” definitions differ. Microsoft Defender for Cloud is the only major with fully published per-resource rates; Wiz and Orca quote per workload; Prisma Cloud uses credits; challengers like Upwind and Uptycs undercut on runtime-first models. This guide compares all 12 on how the money actually…
-
12 Best CWPP Solutions Compared (2026): Features Pricing
Quick Answer: Sysdig (built on open-source Falco) leads container/K8s runtime depth; Prisma Cloud leads workload breadth including serverless; Aqua leads cloud-native lifecycle security; Wiz and CrowdStrike lead platform correlation. Category notes: Illumio is microsegmentation and Fidelis is NDR/XDR containment and detection layers rather than classic CWPP. CSPM tells you how the cloud is configured; CWPP…
-
11 Best CSPM Tools Compared (2026): Features Pricing
Quick Answer: Wiz leads agentless attack-path CSPM; Prisma Cloud leads breadth; Microsoft Defender for Cloud offers a free foundational tier plus published per-resource plans; Orca pioneered agentless SideScanning. Consolidation note: Ermetic is now Tenable Cloud Security and Lacework is now Fortinet’s FortiCNAPP our list reflects both. Misconfiguration a public bucket, an over-permissive role, an exposed…
-
12 Best Enterprise Browsers Compared (2026): Features Pricing
Quick Answer: Island and Palo Alto (Talon) lead purpose-built enterprise browsers; Chrome Enterprise (free Core tier) and Edge for Business (bundled) secure the browsers you already run; LayerX and Seraphic add enterprise controls without switching browsers. Note: Mammoth Cyber has ceased operations treat any references as historical. Work happens in the browser now 90%+ of…
-
12 Best Enterprise Browsers Compared (2026): Features Pricing
Quick Answer: Island and Palo Alto (Talon) lead purpose-built enterprise browsers; Chrome Enterprise (free Core tier) and Edge for Business (bundled) secure the browsers you already run; LayerX and Seraphic add enterprise controls without switching browsers. Note: Mammoth Cyber has ceased operations treat any references as historical. Work happens in the browser now 90%+ of…
-
12 Best Browser Isolation Solutions Compared (2026): Features Pricing
Quick Answer: Zscaler and Cloudflare lead RBI delivered inside SSE platforms; Menlo Security leads isolate-everything efficacy; Garrison (Everfox) owns hardware-grade high assurance for government; Authentic8 Silo dominates managed OSINT/investigations; Kasm is the self-host value play. RBI typically prices per user per month. The browser executes more untrusted code than any other program on an endpoint…
-
TIBER-EU and the Future of Cyber Resilience: Why Continuous Security Validation Is No Longer Optional
Sep 14, 2026 TIBER-EU and the Future of Cyber Resilience: Why Continuous Security Validation Is No Longer Optional A point-in-time red team exercise proves resilience once. Here’s what it takes to prove it every day in between. Summary TIBER-EU is… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/tiber-eu-and-the-future-of-cyber-resilience-why-continuous-security-validation-is-no-longer-optional/
-
Sonar Supports OpenAI’s Call for Collective Action on Cyber Defense
The window to strengthen cyber defense is narrowing, as advanced AI models compress the time between vulnerability disclosure and exploitation from months to minutes. It’s the responsibility of the defenders to match that pace. That is why we’ve signed OpenAI’s… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/sonar-supports-openais-call-for-collective-action-on-cyber-defense/
-
Daily OT Security News: September 14, 2026
This is the Daily OT Security News briefing for September 14, 2026. OT-ISAC, NCSA, TXOne conduct Predictive Resilience exercise, focus on evidence-driven OT cybersecurity decisions OT-ISAC, Thailand’s National Cyber Security Agency (NCSA), and TXOne Networks conducted a Predictive Resilience Exercise… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-14-2026/
-
Cybersecurity Leaders to Watch in London: Securing Britain’s Business Capital
London hosts the head offices of insurers, payment providers, publishers, industrial groups, and consumer brands, each operating under a regulatory environment shaped by GDPR, NIS2, FCA supervision, and the UK’s evolving cyber resilience legislation. The security leaders below have built… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cybersecurity-leaders-to-watch-in-london-securing-britains-business-capital/
-
Chicago’s CISOs to Watch: Security Leadership Citywide
Chicago has always been a city of markets, underwriters, and makers, and its security leadership reflects that mix. The CISOs below run cyber programmes at a ratings agency, a derivatives exchange, a mutual insurance group, a pharmaceutical manufacturer, and an… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/chicagos-cisos-to-watch-security-leadership-citywide/
-
ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities
The EU Agency for Cybersecurity switched on the Cyber Resilience Act’s Single Reporting Platform on 11 September 2026, the same day the law’s reporting obligations … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/14/enisa-cra-single-reporting-platform/
-
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/defense-cyber-spending-attacks/
-
Cyber Threat Landscape: Real Attack Alerts and Recent Incidents
The Current Threat PictureThe supplied Seceon overview presents a clear picture of a modern enterprise threat landscape. Credential attacks, suspicious cloud authentication, VPN brute force, data-loss events, and major external campaigns can occur alongside one another. The most important operational… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cyber-threat-landscape-real-attack-alerts-and-recent-incidents/
-
Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities
A newly identified Cyclops Blink variant has resurfaced on compromised Cisco Secure Firewall Management Center (FMC) appliances, adding active internal-network scanning and programmable packet-sniffing capabilities to an already mature modular implant. Assessed with high confidence that the activity has a Russian nexus, with a moderate-confidence link to IRON VIKING also tracked as Sandworm and Seashell…
-
China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-51990, the vulnerability chains an insecure custom protocol handler, unrestricted embedded-browser navigation, and an obsolete Chromium build running without sandbox protections. Tencent addressed…
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoice Details.bat”, which relies on user interaction to trigger execution. While the precise delivery method…
-
Cyber Resilience Act trifft Frontier AI: Warum Unternehmen mehr Schwachstellen schneller managen müssen
Mit dem Cyber Resilience Act wird Schwachstellenmanagement zur Managementaufgabe. KI-gestützte Analysen entdecken mehr Sicherheitslücken in kürzerer Zeit zugleich erhöhen enge Meldefristen, wachsende Patch-Mengen und komplexe Lieferketten den operativen Druck. Unternehmen müssen deshalb Prozesse, Datenbasis und Wiederanlaufplanung jetzt auf kontinuierliche Cyberresilienz ausrichten. Management Summary Regulatorischer Zeitdruck: Ab 11. September 2026 greifen die Meldepflichten des Cyber… First…

