Tag: cyber
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
Adaptive Malware Could Evade Signature Detection by Regenerating Its Attack Capabilities
Adaptive, AI-driven malware could challenge a foundational assumption in enterprise defense: that a malicious program’s exploitation logic remains fixed after deployment. New research on adaptive computer worms argues that a self-replicating agent paired with an onboard reasoning loop could assess different environments, select target-specific attack paths, and regenerate capabilities as older methods become less effective.…
-
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/novel-spoofing-technique-targets/
-
Debian 13.6 Released With Security Updates for Linux, Apache, Curl, QEMU, and More
The Debian Project has released Debian 13.6, the sixth point update for its stable Debian 13 “trixie” distribution. This update, released on July 11, 2026, includes a collection of security fixes, critical bug corrections, and updated installation images. It does not introduce a new version of Debian; existing systems can be upgraded to the latest…
-
BusySnake Stealer Uses Reverse SSH Tunnels and AI-Generated Loaders to Evade Detection
Armored Likho, a previously undocumented threat group also tracked as Eagle Werewolf based on circumstantial evidence, is targeting government institutions and electric-power organizations across Russia, Brazil, and Kazakhstan with a new Python-based infostealer named BusySnake. The group’s activity reflects an unusual overlap between cyber-espionage and financially motivated operations. Armored Likho targets organizations for intelligence collection…
-
Cyber-Resilienz – So schützen sich Unternehmen vor Wiper-Angriffen
First seen on security-insider.de Jump to article: www.security-insider.de/so-schuetzen-sich-unternehmen-vor-wiper-angriffen-a-64488aeb163e7c42c831541039014416/
-
CISA Warns of Actively Exploited iCagenda and Balbooa Forms File Upload Flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two file-upload vulnerabilities, affecting iCagenda and Balbooa Forms, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation in the wild. The alert was issued on July 10, 2026, identifying these flaws as vulnerabilities that allow unrestricted file uploads of dangerous types.…
-
Spear-Phishing Campaign Uses Proton Drive Links and LNK Files to Deliver SpyGlace
The APT-C-60 threat actor has continued targeting Japanese organizations with a spear-phishing campaign that abuses Proton Drive, Windows shortcut files, trusted developer platforms, and native Windows utilities to deliver the SpyGlace malware. While the group retains several established tradecraft elements, including the abuse of legitimate services and the use of git.exe to execute malicious scripts,…
-
Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access
A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score of 9.8. This flaw, tracked as CVE-2026-57807, affects all plugin versions up to and including version 38.5.8. As of now, it remains unpatched, with no official fix available from the vendor.…
-
Australian Cyber Agency Warns of Global CMS Exploitation Campaign
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/australia-warns-global-cms/
-
South Korea Military Faces Highest Cyberattack Volume Since 2021
Cyberattacks on South Korea military reached their highest level in five years in 2025, highlighting growing cybersecurity risks as the Ministry of National Defense struggles to retain trained cyber specialists. The rise in attacks, coupled with phishing emails and concerns over North Korea’s expanding cyber capabilities, has intensified calls for stronger defense measures. First seen on thecyberexpress.com Jump to…
-
South Korea Military Faces Highest Cyberattack Volume Since 2021
Cyberattacks on South Korea military reached their highest level in five years in 2025, highlighting growing cybersecurity risks as the Ministry of National Defense struggles to retain trained cyber specialists. The rise in attacks, coupled with phishing emails and concerns over North Korea’s expanding cyber capabilities, has intensified calls for stronger defense measures. First seen on thecyberexpress.com Jump to…
-
New VEXAIoT AI Agents Autonomously Exploit IoT Vulnerabilities With 95% Success Rate
VEXAIoT, an autonomous multi-agent framework designed to discover and exploit vulnerabilities in the Internet of Things (IoT) within controlled test environments. In 200 attack trials against the intentionally vulnerable IoTGoat platform, the system completed 189 attacks, achieving an overall success rate of 94.5% (rounded to 95%). New VEXAIoT AI Agents Attack Workflow VEXAIoT, short for…
-
Jscrambler npm Supply Chain Attack Steals Cloud Credentials and Crypto Wallet Secrets
A malicious actor compromised the Jscrambler npm package and published several trojanized versions that included a hidden, cross-platform credential-stealing payload. The attack targeted developers, build pipelines, and CI/CD systems, where npm installations could access source code, cloud credentials, deployment tokens, and sensitive environment variables. Jscrambler npm Supply Chain Attack Socket’s Research Team detected the initial…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Operation Capsule Vault Uses Malicious ISO Files and Process Injection to Deliver RokRAT
Operation Capsule Vault began with spear-phishing emails sent on June 22, 2026, posing as notices distributing materials from a legitimate academic event. The lures referenced the “Why Wonsan-Kalma Tourism Now?” conference, held at Seoul COEX on June 12, and incorporated publicly available event details, including its subject matter and host organizations. By reusing real-world conference…
-
Microsoft Tests AI-Powered Copilot Tool to Diagnose Windows 11 Performance Issues
Microsoft is gradually rolling out an optional Copilot feature called PC Insights, which provides the AI assistant with access to real-time information about Windows 11 hardware and performance. This feature, first reported by Windows Latest, is currently being tested with users in the United States and is not yet widely available. PC Insights aims to…
-
New GhostCommit Technique Hides Exploits in Images to Evade AI Code Reviewers
Researchers have revealed a technique called >>GhostCommit,<< which involves prompt injection by hiding malicious instructions within images included in pull requests. This technique has the potential to bypass text-only AI code reviewers and later manipulate coding agents into exposing repository secrets. The ASSET Research Group explained that this technique leverages the widening gap between automated…
-
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup
The Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests. The attack The attack … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/09/microsoft-365-fake-passkey-setup-enrollment/
-
GodDamn Ransomware Attack Uses PsExec Lateral Movement and NirSoft Toolkit for Credential Theft
A targeted GodDamn ransomware incident shows the payload is not entirely new but the latest rebrand of a long-running family. Analysis reveals strong code overlap with Beast (the 2024 rebrand of Monster), and the operational playbook mirrors earlier Hyadina campaigns. Stealthy foothold, credential harvesting using NirSoft utilities, kernel-level defense subversion, remote-access tooling, and PsExec-driven lateral…
-
Cyber field doubts promise of Cyber Shield
The NCSC has shared more details of its national AI Cyber Shield initiative, but experts say the project faces serious delivery challenges First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645655/Cyber-field-doubts-promise-of-Cyber-Shield
-
Attackers Exploit WordPress Plugin Vulnerabilities for Remote Code Execution and Webshell Access
A large-scale exploitation campaign is actively weaponising known vulnerabilities across multiple content management systems, with WordPress plugins forming the primary attack surface. Cyber actors are scanning the internet for vulnerable sites and chaining unauthenticated file upload, remote code execution (RCE), server-side request forgery (SSRF) and deserialization vulnerabilities to deploy webshells that grant persistent remote access.…
-
75% CISOs Fear Executives Don’t Understand Cybersecurity Risks Employees Face
Survey of cybersecurity leaders by MetaCompliance finds that many feel boards are uninterested in ever-evolving cyber risks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisos-fear-execs-dont-understand/
-
HP Linux Imaging and Printing Software Flaw Enables Privilege Escalation Attacks
A critical vulnerability has been discovered in HP Linux Imaging and Printing Software (HPLIP), which exposes Linux systems to potential privilege escalation and remote code execution attacks. This vulnerability, tracked as CVE-2026-14544, has a CVSS v3 score of 9.8, indicating maximum severity due to its potential for network exploitation, low attack complexity, and lack of…
-
AssuranceAmerica Confirms Massive Data Breach Exposing Driver’s License and Insurance Data
AssuranceAmerica, a U.S. provider of auto and renters insurance, has confirmed a significant data breach that exposed the personal information and driver’s license data of approximately 6.99 million people. This incident marks the largest known leak of Americans’ driver’s license information this year. Founded in 1998, the Atlanta-based insurer operates in more than a dozen…
-
RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging
RedHook, an Android Remote Access Trojan (RAT) first profiled in July 2025, has resurfaced with a markedly more dangerous capability: autonomous abuse of Android’s ADB Wireless Debugging to acquire shell-level privileges (uid 2000). While its baseline toolkit screen streaming, keylogging, Accessibility-driven UI manipulation and credential theft remains intact, the latest RedHook builds demonstrate a deliberate…
-
RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging
RedHook, an Android Remote Access Trojan (RAT) first profiled in July 2025, has resurfaced with a markedly more dangerous capability: autonomous abuse of Android’s ADB Wireless Debugging to acquire shell-level privileges (uid 2000). While its baseline toolkit screen streaming, keylogging, Accessibility-driven UI manipulation and credential theft remains intact, the latest RedHook builds demonstrate a deliberate…
-
GhostApproval Attack Impacts Amazon Q, Claude Code, Cursor, Google Antigravity, and Windsurf
A newly disclosed vulnerability pattern known as >>GhostApproval<< is exposing significant flaws in the trust boundary of leading AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Cursor, Google Antigravity, Augment, and Windsurf. This issue demonstrates how attackers can exploit symbolic links (symlinks) to bypass workspace isolation and manipulate Human-in-the-Loop safeguards, potentially resulting in…
-
Foxit Patches Multiple UseFree Flaws Leading to Remote Code Execution
Foxit has released critical security updates to address multiple use-after-free vulnerabilities that could lead to remote code execution (RCE) in its widely used PDF Reader and PDF Editor products. The vulnerabilities, disclosed in Foxit’s July 8, 2026 security bulletin, affect Windows versions of Foxit PDF Reader and Foxit PDF Editor across multiple release branches, highlighting…

