Tag: cyber
-
NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft
A major upgrade to the Python-based NodeStealer malware, transforming the Facebook-focused infostealer into a broader spyware platform capable of logging keystrokes, monitoring clipboard data, capturing screenshots, and harvesting extensive Facebook profile information. The newly observed variant, identified in August 2026, also expands browser and local data theft, using a split Telegram command-and-control (C2) design to…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to version 6.3.314 immediately. Super Forms WordPress Flaw Wordfence disclosed this unauthenticated arbitrary…
-
Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered
Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security issues in older versions. The recommended versions are Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The company advises that all server owners and desktop users upgrade to the latest release…
-
Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails
Threat actors have repurposed an AI prompt-injection technique known as ASCII smuggling to evade email security controls at massive scale, hiding invisible Unicode characters within financial phishing lures. Microsoft observed the activity reach more than 2.3 million messages per day, demonstrating how techniques first popularized in AI-security research can quickly migrate into conventional phishing operations.…
-
Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems
Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campaign targeting government, political, education and industrial organizations across Asia. The campaign is distinct from an earlier operation reported in July that used Claude Code and DeepSeek against government and financial-sector targets. In this newer…
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
Cloudflare und OpenAI wollen Schwachstellen schließen, bevor Angreifer sie ausnutzen
Cloudflare verbindet GPT-5.6 Cyber von OpenAI mit Echtzeit-Telemetrie, um Schwachstellen zu priorisieren, Angriffe an der Edge zu blockieren und Patches vorzubereiten. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cloudflare-und-openai-wollen-schwachstellen-schliessen-bevor-angreifer-sie-ausnutzen/a46341/
-
Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials
A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulnerability in Microsoft software or in ReliaQuest systems; instead, it exposes a limitation in how the control evaluates Direct Send traffic.…
-
Kentucky Appellate Court Data Caught in Multi-State Cyber Data Breach
The Kentucky Administrative Office of the Courts (AOC) has confirmed that Kentucky Appellate Court data was compromised in a cybersecurity breach traced to a third-party vendor. West Publishing Corporation, operating as Thomson Reuters Court Management Solutions (Thomson Reuters CMS), informed the AOC that the incident originated within file systems tied to its C-Track case management…
-
Google Chrome V8 Flaw Actively Exploited in the Wild, Update Released
Google has released an urgent update for Chrome Stable to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine that is actively being exploited. This flaw can allow remote attackers to execute code within Chrome’s sandbox by convincing a victim to open a specially crafted HTML page. The security update…
-
CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems
A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on Windows. CrowdStrike is actively investigating these claims and has advised customers to turn off the Microsoft Office File Suspicious Macro Removal policy while the assessment is ongoing. CrowdStrike Falcon Zero-Day The project was published on…
-
Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications
North Korea-linked Contagious Interview operators have expanded their developer-targeting malware delivery operation beyond booby-trapped Git hooks and coding repositories, using trojanized macOS applications distributed as disk images and installer packages. Jamf Threat Labs identified 14 malicious DMG and PKG samples impersonating legitimate Mac software, all of which ultimately deliver an OtterCookie-aligned JavaScript implant designed for…
-
Hackers Compromise More Than 14,500 Dahua Security Cameras in Massive Campaign
A large-scale campaign dubbed Operation CameraSwarm compromised at least 14,530 Dahua IP cameras and related surveillance devices in just 35 days. Exposing how unpatched flaws, weak credentials, and cloud-connected P2P features can turn video-security infrastructure into a remotely accessible attack surface. Threat intelligence firm Hunt.io reconstructed the operation after discovering an unsecured HTTP directory belonging…
-
LLMjacking Attack Abuses Leaked AWS Credentials to Hijack Amazon Bedrock AI Models
Threat actors are increasingly converting stolen cloud credentials into access to costly generative AI services, a technique known as LLMjacking. FortiGuard Labs reported an incident involving Amazon Bedrock in which a leaked, long-lived AWS IAM access key with AdministratorAccess permissions was used to create a new identity, subscribe to foundation models, and run inference at…
-
OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets
OpenAI committed $1 billion to subsidize access to its Daybreak cyber models, along with training and technical support, for organizations defending water and wastewater … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/04/openai-daybreak-frontline-defenders-access/
-
OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits in Cyber Tests
OpenAI has introduced GPT-6 Astra, a groundbreaking model that has reportedly achieved perfect results on ExploitBench and demonstrated improved controls during cybersecurity testing. This announcement positions Astra as a significant advancement in authorized security research, in which models must analyze unfamiliar software vulnerabilities, generate reliable proof-of-concept code, and operate within the parameters of a controlled…
-
OpenAI Launches GPT-6 Astra With Tighter Cyber Safeguards
New Model Can Develop Zero-Day Exploits But Adds More Human Oversight. OpenAI released what it calls its most intelligent and aligned model, GPT-6 Astra, its newest model after it paused some reinforcement training to align its safety and risk processes following agents attacking Hugging Face. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/openai-launches-gpt-6-astra-tighter-cyber-safeguards-a-32745
-
Analysts: Trump Cyber Program Could Cost Firms Legal Shields
New White House Program May Strip Providers of Legal Threat Sharing Protections. A White House program deputizing vetted companies to hack foreign cybercriminals could cost those firms the legal authorities they rely on to defend their own networks, analysts said during an Institute for Security and Technology session, weeks before agencies must finalize operating procedures.…
-
Lawmakers See ‘AI-Shaped Hole’ in UK’s New Cyber Bill
AI ‘Emergency Kill Switch’ for Government Features in the Proposed Amendments. Lawmakers advancing the Cyber Security and Resilience (Network and Information Systems) Bill through Parliament continue to debate artificial intelligence safeguards. While some see an AI-shaped hole in the bill, the government argues for a narrower, critical national infrastructure focus. First seen on govinfosecurity.com Jump…
-
How CrowdStrike’s Fal.Con Is Emerging As A ‘Mini-RSA’ For The Cyber Industry: Analysis
The cybersecurity industry may need to add another conference to the list of must-attend events”, presently consisting of RSAC and Black Hat/DEF CON”, after the major turnout, expansive exhibition floor and high-profile speaker lineup at CrowdStrike’s Fal.Con 2026. First seen on crn.com Jump to article: www.crn.com/news/security/2026/how-crowdstrike-s-fal-con-is-emerging-as-a-mini-rsa-for-the-cyber-industry-analysis
-
Fewer attacks, more force: Link11’s European Cyber Report finds new DDoS records for the first half of 2026
Frankfurt am Main, Germany, September 3rd, 2026, CyberNewswire Super-botnets and hijacked cloud servers drive new bandwidth and packet-rate records as international law-enforcement pressure pushes attack counts down Link11 has released its European Cyber Report for the first half of 2026, providing an overview of DDoS attack activity targeting European companies. Although the number of DDoS…
-
Daily OT Security News: September 03, 2026
Daily OT Security News, Viakoo, September 03, 2026 UK Advances Powers to Restrict High-Risk Technology Suppliers in Critical Infrastructure SecurityWeek reported September 2 that late amendments to the UK Cyber Security and Resilience Bill, tabled August 24, would… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-03-2026/
-
Daily OT Security News: September 3, 2026
Multinational joint guidance for service providers on IT and OT outage communications On September 2, 2026 the Canadian Centre for Cyber Security (Canada) joined CISA, ASD’s ACSC, NCSC”‘NZ, NCSC”‘UK and the FBI to publish joint guidance addressing IT and OT… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-3-2026/
-
How a Cyber Risk Platform Unifies Security Operations and Compliance
Key Takeaways Security operations and compliance run on separate tracks in most enterprises, and that split creates duplicated work, slower threat response, and a fragmented view of risk that no executive can act on. Enterprises struggle with cyber risk management… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-a-cyber-risk-platform-unifies-security-operations-and-compliance/
-
How a Cyber Risk Platform Unifies Security Operations and Compliance
Key Takeaways Security operations and compliance run on separate tracks in most enterprises, and that split creates duplicated work, slower threat response, and a fragmented view of risk that no executive can act on. Enterprises struggle with cyber risk management… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-a-cyber-risk-platform-unifies-security-operations-and-compliance/

