Tag: cyber
-
The 12 Best Managed Firewall Services, Compared and Priced
Best value overall: Fortinet. Delivered directly and through the largest partner network in security, at price points the premium providers can’t approach provided you vet the actual delivery partner. Best detection quality: Secureworks. Best global reach: NTT Data. Best if you want to stop owning firewalls: Cato Networks. Best for SMB: Barracuda MSP. Managed firewall…
-
OpenAI pledges $1B to provide resources, training for frontline cyber defenders
Amid heightened scrutiny, the company will use frontier AI to help water, power and local government providers fight malicious actors. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/openai-pledges-1-billion-resources-cyber-defenders/829676/
-
Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence…
-
Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence…
-
Hackers Hijack Coder Module Registry to Distribute Credential-Stealing Malicious Packages
Coder has reported a significant software supply chain incident in which an unidentified threat actor redirected part of its official module registry traffic to attacker-controlled infrastructure. This led to the temporary distribution of tampered Terraform modules intended to steal credentials. The incident affected the registry at registry.coder.com on August 31, 2026, between 07:35 UTC and…
-
Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA
Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed BigBear 2.0 to intercept authenticated Microsoft 365 sessions, allowing them to take over accounts even after victims complete multi-factor authentication (MFA). CloudSEK’s TRIAD team uncovered the operation after gaining administrative access to its control panel in June 2026 The campaign demonstrates a critical reality for Microsoft…
-
Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through
A known Shai-Hulud npm worm payload has resurfaced after 111 days of inactivity, raising fresh questions about the effectiveness of registry-level malware screening. The May campaign demonstrated how quickly a single compromised maintainer account can turn into a software supply-chain incident. Attackers pushed malicious versions across npm packages, including widely used visualization and frontend dependencies.…
-
Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365
Switzerland’s Federal Chancellery is advancing a sovereign digital workplace initiative following a feasibility study that demonstrated how open-source collaboration and office software can effectively support essential workflows within the federal administration. This initiative, announced to the Federal Council on September 2, aims to establish an open-source workplace platform that will operate alongside Microsoft 365 without…
-
Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff
Mathspace, an online mathematics learning platform used by schools in Australia and New Zealand, has reported a data breach affecting 1,079,819 students, parents or guardians, teachers, and staff members. The company stated that attackers exploited a critical vulnerability in its self-hosted Metabase reporting environment, allowing them to gain administrator-level access without legitimate credentials. Mathspace Data…
-
New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away
Security researchers have unveiled InjectEave, an electromagnetic side-channel attack that can turn ordinary headphones into unintended transmitters. By directing radio-frequency energy at vulnerable hardware and collecting the resulting emissions, an attacker can reconstruct audio playing through a target device. In a long-range experiment using amplified equipment, researchers successfully recovered audible speech from wireless headphones at…
-
Berlin Responds After Data Leaked by Cyber Extortion Group
Hack and Shakedown by Cyber-Extortion Group Happened Weeks Before State Elections. Cyber-extortion group Rhysida has leaked terabytes of data, much of it sensitive, that it stole from the administration that runs the German state of Berlin, triggering political fallout and national security questions as incident responders seek to understand just what’s been stolen and leaked.…
-
Mate Security, Palo Alto Networks, and ServiceNow Join OpenAI’s First-Day Cyber Defense Signatories
The cybersecurity market is approaching a moment when artificial intelligence could alter the balance between attackers and defenders. As increasingly capable models become available, the question facing security leaders is no longer whether AI will influence cyber defense, but how… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mate-security-palo-alto-networks-and-servicenow-join-openais-first-day-cyber-defense-signatories/
-
Cloudflare and CrowdStrike Bring AI Agents Into the Cyber Defense Fight
Cloudflare is using OpenAI GPT-5.6 Cyber to automate vulnerability discovery and remediation as AI agents reshape enterprise security operations. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-cloudflare-openai-gpt-5-6-cyber-vulnerability-remediation/
-
Cloudflare and CrowdStrike Bring AI Agents Into the Cyber Defense Fight
Cloudflare is using OpenAI GPT-5.6 Cyber to automate vulnerability discovery and remediation as AI agents reshape enterprise security operations. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-cloudflare-openai-gpt-5-6-cyber-vulnerability-remediation/
-
Daily OT Security News: September 07, 2026
Today’s selection covers IoT, OT, ICS and cyber-physical-system security developments that may affect edge networking, management platforms, industrial assets and healthcare devices. Hackers exploit new MikroTik RouterOS flaws to hijack routers Attackers are actively exploiting a chain of two MikroTik… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-07-2026/
-
PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells
Tags: access, backdoor, cve, cyber, exploit, flaw, linux, malware, remote-code-execution, vulnerabilityA sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with exploitation of CVE-2025-53521, an unauthenticated remote code execution flaw affecting BIG-IP APM when an access policy is configured on a virtual server. F5 has confirmed exploitation of the vulnerability and links the related compromise activity…
-
The UK’s Cyber Community Comes North as CyberFest returns for 2026
The North East’s biggest cyber security festival returns this October. Now in its ninth year, CyberFest has grown into a major national platform for showcasing the region’s cyber and secure AI excellence. Taking place across the North East throughout October, the festival will connect businesses, innovators, government and specialist clusters from across the UK, putting…
-
Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data
Natural Resources Wales (NRW) has reported a personal data breach involving sensitive diversity-monitoring information from both former and current employees. The breach affected individuals whom NRW employed between April 2013 and March 2018. An internal investigation revealed that a spreadsheet containing employee data was accidentally published online, making the information accessible before the issue was…
-
ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions
ConnectWise has announced a security issue affecting file transfer functionality in ScreenConnect Remote Access Support and Access sessions. This issue affects both cloud-hosted and on-premises ScreenConnect deployments. In response, the company has issued immediate mitigation guidance. At the same time, it is working on an official patch and securing a CVE identifier. The advisory, released…
-
Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials
Tags: access, control, credentials, cyber, email, google, infrastructure, network, phishing, serviceA large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly personalized credential-harvesting pages, and, in some cases, install ScreenConnect remote-access software. The campaign’s central advantage is that it presents trusted Google-owned domains at nearly every point a gateway, proxy, or analyst is likely to…
-
OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure
OpenAI has announced a $1 billion global commitment to expanding access to its Daybreak AI cybersecurity platform for frontline defenders who protect critical infrastructure, public services, and under-resourced organizations. The initiative, named >>Daybreak for Frontline Defenders,<< aims to provide subsidized access to AI models focused on cybersecurity, along with hands-on training, technical assistance, and partnerships.…
-
Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks
A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems. It has no symbols, uses NX protection and partial RELRO, and carries a SHA-256 hash…
-
The 12 Best Wireless / Wi-Fi Security Solutions, Compared and Priced
Best value overall: Ubiquiti. Published hardware pricing, no mandatory licensing, and WPA3 with VLAN segmentation included for organizations whose compliance requirements don’t demand enterprise wireless intrusion prevention. Best capability: HPE Aruba. Best management: Cisco Meraki and Juniper Mist. Best if you own the firewall: Fortinet, utilizing your existing FortiGate firewalls. The critical cost question in…
-
The 12 Best Network Sandboxing Solutions, Compared and Priced
Best value overall: ANY.RUN. It publishes its pricing, offers a free community tier that analysts genuinely use daily, and its interactive model lets you click through the malware yourself which defeats evasion techniques that beat automated sandboxes. Best evasion resistance: VMRay. Best if you already own the platform: Fortinet, Palo Alto, Check Point, or Cisco.…
-
The 12 Best Software-Defined Perimeter (SDP) Solutions, Compared and Priced
Best value overall: Cloudflare. Published per-user pricing, a free tier you can genuinely deploy on, and a global edge network behind it. Best for small technical teams: Twingate. Best enterprise scale: Zscaler. Most specialized: Appgate for regulated environments and Nozomi (Tempered) for OT. One warning before the table: four of the twelve names on the…
-
The 12 Best Secure Web Gateway (SWG) Solutions, Compared and Priced
Best value overall: Cloudflare. It publishes per-user pricing, offers a free tier that lets you test the model properly, and delivers from one of the largest edge networks in the world. Best capability: Zscaler and Netskope. Best if you already own it: Fortinet and Cisco Umbrella. Below, 12 gateways scored across five weighted criteria, a…
-
BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations
A newly documented Windows attack pattern, dubbed Bring Your Own Trusted Caller (BYOTC), shows how attackers can bypass driver-level authorization controls without exploiting a traditional memory-corruption flaw. Instead of attacking a privileged kernel driver directly, an adversary compromises or abuses the legitimate user-mode application that the driver already trusts. The technique expands on the well-known…
-
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Sekoia and Kudelski Security have observed that North Korea’s Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korea-lazarus-six-cyber/
-
Check Point Brings OpenAI’s Daybreak Models Into Its Security Platform to Speed Up Threat Validation and Remediation
Check Point Software Technologies has announced it is integrating OpenAI’s Daybreak frontier AI models across its security platform, extending a partnership aimed at helping defenders detect, validate, and remediate cyber risk faster. The move builds on Check Point’s existing collaboration with OpenAI through the Daybreak Defense Network, first expanded three months ago, and follows the…

