Tag: cyber
-
US CISA Hires Stalled in Red Tape
About 250 Qualified New Hires for the Nation’s Cyber Agency Are in Limbo. The first tranche of a 600-strong staff plus up promised in June for the U.S. Cybersecurity and Infrastructure Security Agency by Homeland Security Secretary Markwayne Mullin is waiting for the paperwork to clear so they can start work, officials said Wednesday. First…
-
OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth
Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture platform now commercially available and continuing to add new capabilities, OpenMatter Network today announced a strategic realignment of its leadership team designed to accelerate subscription growth, expand industry partnerships and position the company for long-term commercial success. Effective September 1, Mike Anderson has been named…
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
-
Governments ‘buying time’ in race between innovation, security, national cyber director says
Sean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones. First seen on cyberscoop.com Jump to article: cyberscoop.com/national-cyber-director-ai-cybersecurity-threats/
-
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
Tags: access, ai, authentication, cloud, credentials, cyber, data-breach, hacker, Internet, theft, vulnerabilityNearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating a direct path to LLMjacking, sensitive credential exposure, and in vulnerable versions root-level code execution inside the gateway container. Their internet scan of 3,074 publicly reachable instances found that 294 systems, or 9.6%, accepted…
-
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from “45.142.193[.]132,” an IP address that has been linked…
-
UK appoints new commander of National Cyber Force
The individual has not yet been avowed, the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged, as routine security considerations are still being worked through. First seen on therecord.media Jump to article: therecord.media/uk-appoints-new-commander-of-national-cyber-force
-
UK appoints new commander of National Cyber Force
The individual has not yet been avowed, the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged, as routine security considerations are still being worked through. First seen on therecord.media Jump to article: therecord.media/uk-appoints-new-commander-of-national-cyber-force
-
UK appoints new commander of National Cyber Force
The individual has not yet been avowed, the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged, as routine security considerations are still being worked through. First seen on therecord.media Jump to article: therecord.media/uk-appoints-new-commander-of-national-cyber-force
-
Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone
Skullcandy Dime 3 wireless earbuds have a serious vulnerability related to unauthenticated Bluetooth pairing. This flaw allows nearby attackers to silently pair with the earbuds, disrupt legitimate audio sessions, and potentially capture microphone audio. This issue, tracked as VU#859658 by the CERT Coordination Center, affects the Skullcandy Dime 3 earbuds (model S2DCW) running firmware version…
-
Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly
Threat actors are increasingly exploiting Active Directory replication mechanisms to steal password hashes without directly compromising a domain controller. This technique, known as DCSync, allows attackers with privileged domain credentials to impersonate a legitimate domain controller and request sensitive directory replication data. Unlike noisy attacks that use malware on servers or attempt to extract credentials…
-
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fbi-cyber-strategy-disrupting/
-
Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds
A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O archive parser could allow a malicious static library to crash Xcode build processes or expose process memory through build logs. This flaw affects the parser used by Apple’s newer linker, ld-prime, as well as related developer tools, including libtool, ranlib, and potentially dyld_info. Apple Xcode Integer…
-
Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
Palo Alto Networks has announced a high-severity buffer overflow vulnerability in PAN-OS that may allow unauthenticated, network-based attackers to execute arbitrary code with root privileges on affected PA-Series hardware firewalls. This vulnerability is tracked as CVE-2026-0310 and stems from PAN-OS XML processing. It impacts both the firewall management web interfaces and the dataplane interfaces. The…
-
New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners
A phishing campaign that moves the credential-harvesting page out of attacker-controlled web infrastructure and into the victim’s browser. Unlike ordinary phishing kits, which host cloned login portals on domains that can eventually be detected and disrupted, this campaign delivers malicious content assembled only after a user follows the attack chain. A blob URL is a…
-
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Tags: credentials, crypto, cyber, cybercrime, data, exploit, malware, password, ransomware, theft, threatThreat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer. The campaign demonstrates how cybercriminals are turning one…
-
OpenAI Builds ‘Defense Factory’ as AI Agents Gain Ability to Chain Cyber Exploits
OpenAI has announced its plans for a >>Defense Factory,<< a cybersecurity operation that prioritizes agent-driven actions. This initiative is designed to continuously discover, validate, remediate, and verify vulnerabilities as AI systems develop the ability to conduct increasingly complex cyber operations. The initiative addresses growing concerns that long-running autonomous agents, especially those powered by widely accessible…
-
12 Best Application Control Allowlisting Tools Compared (2026): Features Pricing
Quick Answer: For dedicated deny-by-default allowlisting, ThreatLocker and Airlock Digital lead in 2026; Microsoft WDAC/AppLocker is the free native option for Windows estates with engineering capacity; CyberArk and BeyondTrust pair control with privilege management. Pricing is typically per endpoint; Microsoft’s is bundled. Application control flips endpoint defense from “block known bad” to “allow only known…
-
12 Best Patch Management Software Compared (2026): Features Pricing
Quick Answer: The best patch management software in 2026 depends on your estate: Action1 offers a genuinely free tier for smaller fleets, NinjaOne and Automox lead cloud-native automation, ManageEngine wins on third-party catalog value, and Tanium rules very large enterprises. Most tools price per endpoint per month or year. Unpatched known vulnerabilities remain one of…
-
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint mobile threat defence is included in appropriate Defender licensing, which means many organizations already own it. Best detection: Zimperium, with fully on-device analysis. Best for Apple estates on Jamf: Jamf. Best privacy positioning: Pradeo and Zimperium, both of which can analyse without shipping your traffic to a cloud.…
-
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint mobile threat defence is included in appropriate Defender licensing, which means many organizations already own it. Best detection: Zimperium, with fully on-device analysis. Best for Apple estates on Jamf: Jamf. Best privacy positioning: Pradeo and Zimperium, both of which can analyse without shipping your traffic to a cloud.…
-
The 12 Best Mobile Threat Defense (MTD) Solutions, Compared and Priced
Best value overall: Microsoft Defender for Endpoint mobile threat defence is included in appropriate Defender licensing, which means many organizations already own it. Best detection: Zimperium, with fully on-device analysis. Best for Apple estates on Jamf: Jamf. Best privacy positioning: Pradeo and Zimperium, both of which can analyse without shipping your traffic to a cloud.…
-
The 12 Best Mobile Device Management (MDM) Solutions, Compared and Priced
Best value overall: Microsoft Intune, included in Microsoft 365 E3 and E5. Best Apple pricing: Mosyle, with a free tier that genuinely works. Best Apple depth: Jamf. Best published mid-market pricing: ManageEngine, Hexnode, and Scalefusion. Best rugged: SOTI. Deploying dedicated MDM allows organizations to enforce policy baseline compliance and device health verification within a […]…
-
The 12 Best Unified Endpoint Management (UEM) Solutions, Compared and Priced
Best value overall: Microsoft Intune, included in Microsoft 365 E3 and E5, which means most organizations reading this already own it. Best published pricing: ManageEngine. Best Apple depth: Jamf. Best rugged and purpose-built devices: SOTI and 42Gears. Best cross-platform enterprise: Omnissa. Unified endpoint management platforms allow security and IT teams to govern mobile devices, […]…
-
New AI Workflow Identity Hijacking Attack Lets Hackers Exfiltrate Sensitive Data
Security researchers have recently disclosed a new enterprise AI attack technique known as Workflow Identity Hijacking. This method enables external attackers to exfiltrate sensitive corporate information by submitting seemingly harmless requests to AI-powered automations. Research published by Noma Labs researcher Sasi Levi reveals that this attack does not rely on prompt injection, stolen credentials, or…

