Tag: cyber
-
Millenium RAT Uses Base64 and XOR Configuration to Hide Telegram C2 Settings
Millenium RAT version 4.* exposes a compact but potent evolution: the malware has migrated from .NET to native C++, while retaining a stealthy Telegram-based command-and-control (C2) model that requires no bespoke server infrastructure. The sample set and telemetry analyzed by Group-IB show the RAT embeds its entire configuration inside an RCDATA resource, masks that configuration…
-
DCloud Uni-App Framework Powers 236,000+ Scam Domains Across Global Fraud Economy
DCloud Uni-App has become a mass-production layer for fraud, with more than 236,000 distinct scam domains tied to a sprawling ecosystem of fake exchanges, wallet drainers, phishing portals, and investment schemes. The scale matters because it shows scam operations are no longer bespoke; they are templated, repeatable, and easy to clone across languages, regions, and…
-
China’s Zhipu AI Model GLM-5.2 Detects Software Vulnerabilities Like Claude Mythos
Zhipu AI’s newly released GLM-5.2 model is attracting significant attention from the cybersecurity community due to its vulnerability detection capabilities, which are comparable to those of Anthropic’s restricted Claude Mythos system. This development raises new concerns about the effectiveness of U.S. export control policies on advanced artificial intelligence. Released on June 13, 2026, under a…
-
OpenAI Launches GPT-5.6 Sol AI Model With Advanced Cyber Capabilities And Layered Safeguards
OpenAI has announced the limited preview of its next-generation AI model family, GPT”‘5.6, headlined by the flagship “Sol” model, which introduces significant advancements in cybersecurity capabilities alongside a newly engineered layered safeguard architecture. The release, disclosed on June 26, 2026, positions GPT”‘5.6 Sol as the company’s most capable model to date, with measurable improvements across…
-
Rokarolla Uses Fake Google Play Protect App to Target Banking and Cryptocurrency Users
Rokarolla, a sophisticated Android banking trojan distributed via malicious websites that masquerade as trusted applications such as TikTok, Google Chrome and even Google Play Protect. Unlike simple credential stealers, Rokarolla is a multi-functional fraud platform that targets at least 217 banking and cryptocurrency apps and combines Accessibility Service abuse, phishing overlays, SMS interception, keylogging, screenshot…
-
Top Cyber Range Providers: A Comparison of 15 Leading Platforms
Compare 15 cyber range platforms across live-fire exercises, AI testing, SOC training, OT realism, deployment options, pricing models, and data residency needs. First seen on hackread.com Jump to article: hackread.com/top-cyber-range-providers-comparison-leading-platforms/
-
Top Cyber Range Providers: A Comparison of 15 Leading Platforms
Compare 15 cyber range platforms across live-fire exercises, AI testing, SOC training, OT realism, deployment options, pricing models, and data residency needs. First seen on hackread.com Jump to article: hackread.com/top-cyber-range-providers-comparison-leading-platforms/
-
Channel Brief: MSPs have a bigger role in SMB cyber insurance readiness
First seen on scworld.com Jump to article: www.scworld.com/news/channel-brief-smb-ai-gap-is-the-next-msp-opportunity
-
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the U.S.The systematic cyber attacks aimed at stealing sensitive First seen…
-
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards
OpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government.While Sol is the latest flagship model and the most powerful, Terra strikes a balance between efficiency and power, and Luna is fine-tuned…
-
Claude Mythos 5 Redeployed to Help U.S. Organizations Strengthen Cyber Defense
Anthropic has officially restored access to its Claude Mythos 5 artificial intelligence model for a select group of U.S. organizations tasked with defending critical national infrastructure. This reinstatement ends a two-week suspension that began on June 12, 2026, which prompted direct, high-level engagement between the AI developer and federal authorities. Access to both Claude Mythos…
-
Critical Linux Kernel Flaw Allows Unprivileged Users to Gain Full Root Access
A newly disclosed flaw in the Linux kernel’s traffic-control subsystem, now assigned CVE-2026-46331 and referred to as >>Pedit COW,<< has been found to grant any unprivileged local user full root access on vulnerable systems. Within just 24 hours of the CVE being formally assigned on June 16, 2026, a working proof-of-concept exploit dubbed packet_edit_meme surfaced…
-
Cloud Bucket Hijacking Lets Attackers Silently Exfiltrate AWS, Google Cloud Data
A critical cloud storage attack technique that exploits a fundamental architectural vulnerability shared across all major cloud service providers. The technique, dubbed cloud bucket hijacking, allows attackers to silently redirect active data streams, including audit logs, telemetry pipelines, and sensitive objects, to attacker-controlled storage environments with minimal risk of detection. Discovered by security researchers at…
-
Linux Kernel DirtyClone Vulnerability Lets Local Attackers Gain Root Privileges
A critical Local Privilege Escalation flaw has been uncovered within the Linux kernel, allowing unprivileged local users to seamlessly gain root access by manipulating the system’s page cache. This vulnerability, designated as CVE-2026-43503, represents a severe gap in the XFRM/IPsec subsystem’s packet-processing path that bypasses earlier mitigations. By exploiting this flaw, attackers can execute a…
-
Amazon Q Developer Vulnerability Allows Code Execution via Malicious Repositories
A critical security flaw discovered in the Amazon Q Developer Extension for Visual Studio Code (VS Code) left developers vulnerable to arbitrary code execution and cloud credential theft. Tracked as CVE-2026-12957 and CVE-2026-12958, these high-severity vulnerabilities highlight significant risks in how AI coding assistants manage trust boundaries. The root cause of this vulnerability lies in…
-
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts.Kaspersky, which is tracking the activity under the moniker StrikeShark, said the campaign has targeted a diplomatic organization in Indonesia, government organizations in Taiwan, First seen…
-
AI Won’t Wipe-Out Entry-Level Cybersecurity Jobs
Instead of eliminating jobs for early-career cyber pros, AI is creating new opportunities for candidates with strong human decision-making skills. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/ai-wont-wipe-out-entry-level-cybersecurity-jobs
-
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia.The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has been attributed to a threat actor called CL-STA-1062, which Palo…
-
Turla group adds more malware to Russia’s espionage efforts against Ukraine
Threat intelligence researchers at Google described StockStay, the latest malware developed by the Russian cyber-espionage group known as Turla. First seen on therecord.media Jump to article: therecord.media/russia-turla-espionage-ukraine-stockstay-malware
-
Water and Wastewater Systems Become Strategic Targets for Russia, China, and Iran
Water and wastewater systems have become strategic gray”‘zone targets for Russia, China, and Iran, driven by chronic underinvestment and weak operational”‘technology (OT) defenses that make these utilities easy to probe and exploit. Internet”‘facing human”‘machine interfaces (HMIs), exposed programmable logic controllers (PLCs), default credentials, and poor IT/OT segmentation create low”‘cost access paths whose impact is disproportionately…
-
As cyber risk evolves, the insurance industry tightens guardrails
C-suite executives are concerned about resilience, but claims are increasingly tied to strict underwriting standards. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cyber-risk-insurance-industry-guardrails/823762/
-
macOS Flaw Allowed Standard Users to Disable CrowdStrike and Kandji Security Tools
A macOS XPC flaw let regular users disable CrowdStrike and Kandji tools, exposing security gaps that vendors patched after XM Cyber reported the security issue. First seen on hackread.com Jump to article: hackread.com/macos-flaw-users-disable-crowdstrike-kandji-security-tools/
-
FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE
A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is exposing instances to potential full database compromise and remote code execution (RCE), with early signs of active exploitation appearing shortly after public disclosure. This flaw is documented under GitHub advisory GHSA-57mv-jm88-66jc and affects all versions up to 0.7.2. It has been patched…
-
China-Linked Malware Found in Counterfeit USB Drives Used on Japan Defense Force Classified Networks
Japan’s defense infrastructure has faced scrutiny following an investigation that revealed members of the Japan Self-Defense Forces (JSDF) used counterfeit USB drives embedded with malware linked to China on systems handling classified information. According to findings reported by Nikkei, these compromised USB devices were acquired at significantly lower costs through unofficial channels. They were subsequently…
-
The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest
Tags: ai, automation, breach, cyber, cybersecurity, data, data-breach, hacker, infrastructure, intelligence, international, iran, risk, service, threatThis week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services, and regulated AI applications, organizations are increasingly exposed to faster-moving threats where traditional security assumptions are being challenged by automation…
-
The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest
Tags: ai, automation, breach, cyber, cybersecurity, data, data-breach, hacker, infrastructure, intelligence, international, iran, risk, service, threatThis week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services, and regulated AI applications, organizations are increasingly exposed to faster-moving threats where traditional security assumptions are being challenged by automation…
-
Hackers Exploit WinRAR CVE-2025-8088 to Plant Startup Shortcut and Run PowerShell Loader
Hackers have weaponized a WinRAR path-traversal flaw tracked as CVE-2025-8088 to silently plant a Startup shortcut and run a multi-stage PowerShell loader that maps a headerless, reflectively loaded PE in memory. The campaign reuses the Ukrainian reconnaissance-themed lure seen in earlier UAC-0226/GIFTEDCROOK activity but significantly advances operational packaging: instead of relying on a user to…
-
Russian Authorities Used Cellebrite UFED to Break Into Human Rights Activist’s iPhone
Russian authorities leveraged Cellebrite’s Universal Forensic Extraction Device (UFED) to gain access to a detained human rights activist’s iPhone, according to a detailed forensic investigation that raises fresh concerns over the use of commercial digital forensics tools in political repression. The findings as per reported by CitizenLabs, based on technical analysis and corroborated by official…
-
CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach
The UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cmc-analysis-education-canvas-data/

