Tag: cyber
-
AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoice Details.bat”, which relies on user interaction to trigger execution. While the precise delivery method…
-
Cyber Resilience Act trifft Frontier AI: Warum Unternehmen mehr Schwachstellen schneller managen müssen
Mit dem Cyber Resilience Act wird Schwachstellenmanagement zur Managementaufgabe. KI-gestützte Analysen entdecken mehr Sicherheitslücken in kürzerer Zeit zugleich erhöhen enge Meldefristen, wachsende Patch-Mengen und komplexe Lieferketten den operativen Druck. Unternehmen müssen deshalb Prozesse, Datenbasis und Wiederanlaufplanung jetzt auf kontinuierliche Cyberresilienz ausrichten. Management Summary Regulatorischer Zeitdruck: Ab 11. September 2026 greifen die Meldepflichten des Cyber… First…
-
Thorough reorganization at NSA will create five ‘mission centers,’ including cyber and AI
The largest electronic spy agency in the world is reorganizing. And fast. First seen on therecord.media Jump to article: therecord.media/nsa-reorganization-five-mission-centers
-
Daily OT Security News: September 12, 2026
Today’s briefing covers five OT/IoT developments: maritime operational-technology monitoring challenges, expanded U.S. critical-infrastructure support, the start of EU Cyber Resilience Act vulnerability reporting for actively exploited flaws, a U.S. Department of Energy request for input on bulk-power system risks, and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-12-2026/
-
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/
-
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber…
-
Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data
Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and reduce the technical expertise needed to run complex intrusions. Anthropic’s report details cyber espionage, financially motivated extortion, supply-chain compromise, and hacktivist activity disrupted between December 2025 and August 2026. Rather than using an AI chatbot only for occasional coding assistance,…
-
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on September 1, 2026, as using identical browser-to-kernel exploit components but ultimately installing separate espionage payloads: the GRIMWEDGE JScript backdoor and the LONGTALE credential-stealing Chrome…
-
New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system reconnaissance, and potentially deploy payloads designed to steal credentials and local secrets. Fortra’s Intelligence and Research Experts (FIRE) said the activity began in June and remains active, with operators regularly recompiling malware samples to…
-
OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem’s documentation build process to execute code remotely and attempting to steal user API keys through a then-undisclosed server-side flaw. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said…
-
Trotz Meldepflichten: Nur 3 % der deutschen Industrieunternehmen sind vollständig auf EU Cyber Resilience Act vorbereitet
PwC-Studie: Bewusstsein für CRA-Anforderungen ist hoch, operative Umsetzung bleibt weit dahinter zurück. Jedes zweite Unternehmen hat noch nicht mit der CRA-Umsetzung begonnen. Mittelständische Unternehmen liegen in nahezu allen Bereichen hinter größeren Unternehmen. Die Meldepflichten des EU Cyber Resilience Act (CRA) gelten seit dem 11. September 2026. Doch die deutsche Industrie ist auf die neue… First…
-
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, flaw, gitlab, infrastructure, Internet, kev, mitigation, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects both GitLab Community Edition and Enterprise Edition and requires urgent mitigation, particularly for internet-accessible GitLab instances. CVE-2026-85706 is a path traversal vulnerability…
-
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate
-
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate
-
Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens
Tags: access, breach, cloud, credentials, cyber, data, data-breach, defense, exploit, extortion, github, group, infrastructureCyber Extortion Group Continues to Target Exposed Cloud-Based Data Over Endpoints. Cyber extortion group FulcrumSec continues to find hardcoded credentials in public-facing IT infrastructure and exploit them as part of what it’s dubbed a Hardcoded Horrorshow that counts Ozempic maker Novo Nordisk among its victims. Here are defenses organizations need to put in place now.…
-
Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/papercut-ai-swarm-attack-cyber-kill-chain
-
State authorities warn they lack resources to address cyber threat to critical sectors
A report shows that state CIOs and CISOs need additional funding, personnel and training to protect water, energy and healthcare. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/state-infrastructure-resources-cyberthreats/830178/
-
EU Gets Access to Anthropic Cyber AI, But Not Its Newest Model
ENISA has gained access to Anthropic’s Mythos 5, giving EU officials a chance to independently test the cyber AI after months of negotiations. The post EU Gets Access to Anthropic Cyber AI, But Not Its Newest Model appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-enisa-anthropic-mythos-5-cyber-ai-access-europe-emea/
-
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026.The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial First seen on thehackernews.com Jump…
-
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands for Generative Threat Group), which aligns with broader reporting linking…
-
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On September 10, CISA listed CVE-2026-67277 and CVE-2026-86060, giving affected organizations until September 13 to implement vendor-recommended mitigations. MikroTik RouterOS Flaws CVE-2026-67277…
-
How a Penetration Test Is Conducted
Modern cyber attacks are not a question of if they happen, but when; to mitigate business disruption, the most proactive organisations already use professional penetration testing as part of their security defences. Penetration testing is the practice of hiring an… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-a-penetration-test-is-conducted/
-
How a Penetration Test Is Conducted
Modern cyber attacks are not a question of if they happen, but when; to mitigate business disruption, the most proactive organisations already use professional penetration testing as part of their security defences. Penetration testing is the practice of hiring an… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-a-penetration-test-is-conducted/
-
How a Penetration Test Is Conducted
Modern cyber attacks are not a question of if they happen, but when; to mitigate business disruption, the most proactive organisations already use professional penetration testing as part of their security defences. Penetration testing is the practice of hiring an… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-a-penetration-test-is-conducted/
-
Anthropic caught Russia-linked spies using Claude in hacking operations
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations. First seen on therecord.media Jump to article: therecord.media/anthropic-russia-hackers-claude
-
The Cyber Express Weekly Roundup: Iranian Bounty, Airline Data Leak, and AI-Model Prompt Injection
This weekly roundup covers a bounty offer targeting an alleged Iranian cyber official, a massive data-exposure incident affecting airline travelers, a breach of an education platform used by students, a flaw exposing ChatGPT users’ Gmail data, and a new EU compliance deadline for connected-product manufacturers. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-iran-bounty-airline-leak/
-
Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader called OfferLoader, indicating a distribution pipeline far larger than the individual intrusions initially observed. Rather than relying on a…
-
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers. The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of…

