Tag: cyber
-
CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each
Used-car platform CARS24 has alleged that confidential information belonging to approximately 3,100 customers was stolen and supplied to a rival business and outside dealers. The company claims that leads were offered for about ₹1,000 each, resulting in an estimated commercial loss of ₹5.70 crore. The complaint was filed at a Cyber Crime Police Station by…
-
Cyber Talk 13 Qualys: What Security Leaders Can Learn From Its Evolution From Vulnerability Scanning to Risk Operations
The real question is not whether Qualys is old, but whether its most successful playbook still fits the next era of securityAt Black Hat 2026, Qualys CEO Sumedh Thakar made a very practical point: if organizations could simply fix every… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cyber-talk-13-qualys-what-security-leaders-can-learn-from-its-evolution-from-vulnerability-scanning-to-risk-operations/
-
How Recent Cyber Earnings Show Growth Alone No Longer Pays
Faster Hiring Coincided With Weaker Stock Performance Across Most Security Vendors Seven of eight major cyber and technology vendors posted at least 25% annual year-over-year sales growth, but five stocks fell after earnings as investors favored profitability while CEOs outlined how AI agents will reshape security, identity and enterprise infrastructure. First seen on govinfosecurity.com Jump…
-
Cyber Resilience Starts With a Unified Recovery Strategy
Learn why cyber resilience requires a unified recovery strategy that restores data, configurations, identities, cloud systems, and critical dependencies. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cyber-resilience-strategy/
-
US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure
Amir Yaryab is the leader of the IRGC’s cyber unit and oversees hacker groups such as the CyberAv3ngers, the State Department said in posting a reward for information about him. First seen on therecord.media Jump to article: therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks
-
Humans have edge over AI in Dutch hacking contest
As machines become crucial for cyber security, humans wonder where they stand First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649310/Humans-have-edge-over-AI-in-Dutch-hacking-contest
-
QA: Viasat Tests Satellite Resilience With AI as Cyber Expert Warns an Attack Could ‘Hurt an Entire Country’
Tags: ai, attack, communications, country, cyber, data-breach, network, resilience, russia, ukraine, vulnerabilityAn AI-assisted platform has been used to test whether Viasat’s satellite communications links can meet operational thresholds under interference and adversarial jamming. Announced this month, the work with Atalanta has renewed scrutiny of the vulnerabilities exposed by Russia’s 2022 attack on Viasat’s KA-SAT network, which disrupted communications across Ukraine and several European countries. Gil Baram,…
-
OpenAI Pledges $1B to Arm Cyber Defenders With Frontier AI
Daybreak Expansion Targets US Public Sector and Critical Infrastructure Security. OpenAI is committing $1 billion to subsidize access to its cyber-capable models for defenders and is launching a center to train security professionals in the American public sector. Daybreak for Frontline Defenders offers security engineers and other defenders the ability to use frontier AI models.…
-
OpenAI Pledges $1B to Arm Cyber Defenders With Frontier AI
Daybreak Expansion Targets US Public Sector and Critical Infrastructure Security. OpenAI is committing $1 billion to subsidize access to its cyber-capable models for defenders and is launching a center to train security professionals in the American public sector. Daybreak for Frontline Defenders offers security engineers and other defenders the ability to use frontier AI models.…
-
OpenAI Pledges $1B to Arm Cyber Defenders With Frontier AI
Daybreak Expansion Targets US Public Sector and Critical Infrastructure Security. OpenAI is committing $1 billion to subsidize access to its cyber-capable models for defenders and is launching a center to train security professionals in the American public sector. Daybreak for Frontline Defenders offers security engineers and other defenders the ability to use frontier AI models.…
-
OpenAI pledges $1 billion to provide resources, training for frontline cyber defenders
Amid heightened scrutiny, the company will use frontier AI to help water, power and local government providers fight malicious actors. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/openai-pledges-1-billion-resources-cyber-defenders/829676/
-
OpenAI Pledges $1 Billion in AI Cybersecurity Tools to Protect Critical Infrastructure
Tags: access, ai, cyber, cybersecurity, infrastructure, intelligence, openai, threat, tool, trainingOpenAI announced a $1 billion initiative on Thursday to provide subsidized access to its artificial intelligence (AI) cybersecurity tools, technical support, and training for critical infrastructure operators. The rollout comes amid mounting warnings that AI-driven cyber threats are rapidly escalating. The company’s Daybreak for Frontline Defenders global program aims to equip under-resourced organizations protecting essential..…
-
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Tags: backdoor, control, cyber, data-breach, group, hacker, infrastructure, malware, ransomware, threat, tool, windowsThe financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its…
-
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Tags: backdoor, control, cyber, data-breach, group, hacker, infrastructure, malware, ransomware, threat, tool, windowsThe financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its…
-
G7 urges organizations to prepare for quantum cyber threats
In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now. First seen on therecord.media Jump to article: therecord.media/g7-urges-organizations-to-prepare-for-quantum-threats
-
G7 urges organizations to prepare for quantum cyber threats
In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now. First seen on therecord.media Jump to article: therecord.media/g7-urges-organizations-to-prepare-for-quantum-threats
-
Protecting Against Zero-Click Attacks
By Aimee Steele, threat intelligence analyst at Talion Cyber Security Last month, the UK’s National Cyber Security Centre (NCSC) issued an advisory around a new phishing campaign targeting organisations in the West that was being carried out by the Russian state-sponsored threat actor known as Laundry Bear. The campaign, saw the threat actors exploiting a…
-
OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques
Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to exchange answers to tasks, inspect their operating environment, and discuss methods to circumvent sandbox controls. This finding, published on September 4 by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas…
-
ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers
Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000 additional US customers. This significantly broadens the scope of an incident initially reported in August. The newly identified data pertains to Trezor orders processed during a prior partnership with ShipMonk, which lasted from November 2019…
-
ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers
Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000 additional US customers. This significantly broadens the scope of an incident initially reported in August. The newly identified data pertains to Trezor orders processed during a prior partnership with ShipMonk, which lasted from November 2019…
-
ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers
Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000 additional US customers. This significantly broadens the scope of an incident initially reported in August. The newly identified data pertains to Trezor orders processed during a prior partnership with ShipMonk, which lasted from November 2019…
-
ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers
Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000 additional US customers. This significantly broadens the scope of an incident initially reported in August. The newly identified data pertains to Trezor orders processed during a prior partnership with ShipMonk, which lasted from November 2019…
-
ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers
Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000 additional US customers. This significantly broadens the scope of an incident initially reported in August. The newly identified data pertains to Trezor orders processed during a prior partnership with ShipMonk, which lasted from November 2019…
-
The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks
This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-claude-papercut-citrix/
-
Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign
Tags: ai, china, country, cyber, cyberattack, cyberespionage, government, hacker, intelligence, threatHunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into live cyberespionage operations, this time hitting Taiwan’s Kuomintang Party archives, Indonesia’s Ministry of Foreign Affairs, government and education systems in…
-
Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud
Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in…
-
NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft
A major upgrade to the Python-based NodeStealer malware, transforming the Facebook-focused infostealer into a broader spyware platform capable of logging keystrokes, monitoring clipboard data, capturing screenshots, and harvesting extensive Facebook profile information. The newly observed variant, identified in August 2026, also expands browser and local data theft, using a split Telegram command-and-control (C2) design to…
-
Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered
Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security issues in older versions. The recommended versions are Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The company advises that all server owners and desktop users upgrade to the latest release…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…

