Tag: cyber
-
Justice Department seizes infrastructure used by cyber scam and criminal marketplace
lso Tuesday, the Treasury Department took action against the same Cambodian company, Huione Group, and affiliates. First seen on cyberscoop.com Jump to article: cyberscoop.com/doj-huione-group-cybercrime-seizure/
-
Feds seize alleged cyber-scam infrastructure connected to Southeast Asian company
The Department of Justice announced the “seizure of a cloud computing account” used by subsidiaries of the Huione Group, a conglomerate severed from the U.S. financial system last year. First seen on therecord.media Jump to article: therecord.media/feds-seize-alleged-cyber-scam-infrastructure-southeast-asia
-
The New Boardroom Mandate: Building Barriers to Limit Cyber Impact
As agentic AI expands the attack surface and accelerates cyberattacks, organizations must focus on containing breaches rather than preventing every intrusion, says Akamai’s Mani Sundaram. He explores AI-powered segmentation, securing AI factories and the convergence of browser security. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/interviews/new-boardroom-mandate-building-barriers-to-limit-cyber-impact-i-5549
-
OpenAI Expands Daybreak to Help Defenders Patch Flaws
OpenAI expanded Daybreak with a full GPT-5.5-Cyber release to help defenders patch software flaws First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/openai-daybreak-gpt-5-5-cyber/
-
LG and Samsung Smart TV Apps Found Monetizing Users’ IP Addresses via Proxy SDKs
A large-scale analysis of smart TV applications has revealed that thousands of apps available on LG webOS and Samsung Tizen platforms are covertly transforming consumer devices into residential proxy nodes, raising significant security and privacy concerns. Researchers scanned 6,038 smart TV applications and identified 2,058 apps that embed proxy software development kits, monetizing users’ internet…
-
Cordyceps Supply chain Vulnerability Impacting Code Repositories at thousands of Organizations
A pervasive CI/CD vulnerability pattern dubbed “Cordyceps” reveals a supply chain vulnerability that lets unauthenticated attackers seize control of Git-based workflows and, by extension, the software artifacts they produce. The issue is not a single bug in GitHub or any one tool; it is a systemic class of insecure workflow compositions. Command injection, broken authentication…
-
Five Eyes Agencies Warn AI Is Accelerating Cyber Threats and Zero-Day Exploitation
The Five Eyes cyber security agencies have issued a joint warning that artificial intelligence is rapidly accelerating cyber threats, including the exploitation of zero day vulnerabilities, and urged organizations to act immediately. In a statement released on June 22, 2026, senior leaders from agencies across the United States, United Kingdom, Canada, Australia, and New Zealand…
-
DifyTap Flaws Expose AI Data Across Tenants on Platform Powering 1M+ Apps
A series of critical vulnerabilities in the widely used open-source LLMOps platform Dify, which powers over one million AI applications. These vulnerabilities, collectively referred to as “DifyTap,” include four flaws, two rated as critical and two that require no authentication. They expose cross-tenant data leakage risks, allowing attackers to access private AI conversations, preview sensitive…
-
Over 2,000 LG and Samsung Smart TV Apps Found Running Residential Proxy SDKs
A large-scale analysis of smart TV applications has revealed that thousands of apps available on LG webOS and Samsung Tizen platforms are covertly transforming consumer devices into residential proxy nodes, raising significant security and privacy concerns. Researchers scanned 6,038 smart TV applications and identified 2,058 apps that embed proxy software development kits, monetizing users’ internet…
-
ANY.RUN Adds In-Browser Data Inspection to Reveal Phishing Redirects and DOM Changes
ANY.RUN today launched in-browser data inspection for its Interactive Sandbox, a capability that brings real browser-level visibility directly into URL analysis workflows and addresses longstanding blind spots in phishing investigations. Modern URL phishing increasingly leverages dynamic pages, layered redirect chains, client-side scripts, iframes and credential-harvesting flows that static scanners and screenshot-based sandboxes routinely miss. By…
-
AWS Urges Organizations to Turn Outbound Blind Spots Into Monitored Checkpoints
When securing an Amazon Web Services (AWS) estate, teams naturally concentrate on inbound protections firewalls, WAFs, and IAM policies because those defenses stop the most visible attacks. Yet outbound traffic often remains under-monitored, left permissive to avoid breaking dependencies or to simplify operations. That default laxity creates a blind spot: without egress visibility and controls,…
-
Tata Electronics Data Breach Exposes 200,000+ Files Linked to Apple and Tesla, Hackers Claim
Tags: apple, breach, cyber, cybersecurity, dark-web, data, data-breach, group, hacker, ransomware, threatTata Electronics has reported a cybersecurity incident following claims from a ransomware-linked threat group that it has exfiltrated and published over 200,000 files related to Apple and Tesla’s manufacturing operations. The leaked data, which is said to amount to more than 630 GB, has appeared on a dark web portal operated by the >>World Leaks<<…
-
Tata Electronics Data Breach Exposes 200,000+ Files Linked to Apple and Tesla, Hackers Claim
Tags: apple, breach, cyber, cybersecurity, dark-web, data, data-breach, group, hacker, ransomware, threatTata Electronics has reported a cybersecurity incident following claims from a ransomware-linked threat group that it has exfiltrated and published over 200,000 files related to Apple and Tesla’s manufacturing operations. The leaked data, which is said to amount to more than 630 GB, has appeared on a dark web portal operated by the >>World Leaks<<…
-
Microsoft Uncovers Parallel Threat Activity From Two Cyberattackers in Single Intrusion
Microsoft’s latest incident write-up shows that a single intrusion can mask two parallel threat activity streams, one tied to Storm-2603 and another to an unknown actor, making the attack far more complex than a conventional ransomware case. The incident began with activity against on-premises SharePoint servers and an attempt to establish internal footholds through exposed…
-
Schwachstellen-Benchmark – GPT-5.5-Cyber von OpenAI übertrifft Claude Mythos 5
Codex Security kann nun automatisiert Schwachstellen analysieren und beheben. Erste Benchmarks sehen das KI-Modell vor Claude Mythos 5. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/schwachstellen-benchmark-gpt-5-5-cyber-von-openai-uebertrifft-claude-mythos-5.98051
-
Scattered Spider Teens Convicted of TfL Cyber-Attack
Two young British men have pleaded guilty to hacking Transport for London as part of a Scattered Spider plot First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/scattered-spider-teens-convicted/
-
Critical libssh2 Vulnerability Lets Remote Attackers Execute Code via Crafted SSH Packets
A critical security vulnerability has been identified in libssh2, a widely used client-side SSH library. This flaw allows remote attackers to execute code by sending specially crafted SSH packets. The vulnerability, tracked as CVE-2026-55200, has a CVSS score of 9.2 and affects libssh2 versions up to and including 1.11.1. The issue has been resolved in…
-
Cybercriminals Abuse TDS Infrastructure to Bypass Firewalls and Hide Malicious Destinations
Cybercriminals are increasingly abusing traffic distribution systems (TDSs) to evade defenses, conceal malicious destinations, and funnel victims into phishing, fraud, and malware campaigns. Once considered a legitimate marketing tool to route visitors to different content or offers, TDS infrastructure is now being repurposed as a stealthy redirection layer that complicates detection and response for network…
-
Critical FFmpeg Vulnerability Lets Hackers Execute Remote Code via Malicious Media Files
A critical memory corruption vulnerability in FFmpeg has been disclosed, allowing for remote code execution through specially crafted media files. This flaw, tracked as CVE-2026-8461 and named “PixelSmash,” affects the MagicYUV decoder within FFmpeg’s libavcodec library and has a CVSS score of 8.8. Discovered by JFrog Security Research, the vulnerability arises from a heap out-of-bounds…
-
FlutterShell Malware Uses C2-Delivered JavaScript Payloads to Evade Sandbox Detection
Targeted macOS endpoint monitoring, the CL-CRI-1089 cluster tied to Operation FlutterBridge repurposes the Flutter framework to deliver a novel macOS malware family dubbed FlutterShell. Rather than rehashing prior campaign reporting, this piece treats recovered artifacts as a technical detection case study built from static analysis of ten Mach”‘O samples collected between December 2025 and March…
-
Philippine government taps Google Cloud to deploy AI agents
The Filipino government will equip public servants with Gemini Enterprise AI tools, launch a cross-agency cyber defence alliance and upgrade subsea network infrastructure First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366644982/Philippine-government-taps-Google-Cloud-to-deploy-AI-agents
-
CodeStorm Phishing Campaign Targets M365 Tenants With Token Reuse and Replay Attacks
A multi-organization phishing campaign attributed to the CodeStorm family is actively targeting Microsoft 365 tenants with a tenant-aware AiTM (adversary-in-the-middle) phishing kit that combines rotating frontends and backend replay behavior under a stable controller path, /google.php. The human recipient rarely scrolls to that dummy conversation, but automated secure email gateways frequently do; the added “conversation…
-
Two Scattered Spider Hackers Convicted Over Transport for London Cyber Attack
Two alleged members of the notorious Scattered Spider cybercrime collective have pleaded guilty to orchestrating a disruptive cyber attack against Transport for London (TfL). This marks a significant law enforcement victory against a group known for targeting large enterprises and critical infrastructure. The UK National Crime Agency and City of London Police confirmed that Thalha…
-
FortiBleed Campaign Uses FortigateSniffer to Harvest 110 Million Credentials From Fortinet Firewalls
A large-scale credential harvesting campaign called “FortiBleed” has been uncovered, revealing how threat actors are exploiting Fortinet FortiGate firewalls to capture authentication data on an unprecedented scale. Research from the SOCRadar Threat Research Unit (STRU) indicates that this operation has already compromised over 110 million credentials by targeting misconfigured or weakly secured devices, turning them…
-
OpenAI Launches Daybreak to Automate Vulnerability Patching With GPT-5.5-Cyber
OpenAI has announced Daybreak, a new cybersecurity initiative aimed at automating vulnerability patching on a large scale using its latest GPT-5.5-Cyber model. This marks a shift from merely discovering vulnerabilities to focusing on end-to-end remediation. The initiative addresses a growing challenge in the industry, AI-driven tools have greatly accelerated vulnerability identification, leaving organizations struggling to…
-
CalPhishing Campaigns Use Outlook Calendar Invites to Deliver Persistent Phishing Lures
A growing trend in which attackers weaponize Microsoft 365 collaboration features to deliver persistent phishing lures via Outlook calendar invites. By abusing Microsoft 365 Groups and Outlook calendar functionality, threat actors move malicious intent out of a single suspicious message and into routine productivity workflows, increasing the chance that targets will treat the interaction as…
-
CalPhishing Campaigns Use Outlook Calendar Invites to Deliver Persistent Phishing Lures
A growing trend in which attackers weaponize Microsoft 365 collaboration features to deliver persistent phishing lures via Outlook calendar invites. By abusing Microsoft 365 Groups and Outlook calendar functionality, threat actors move malicious intent out of a single suspicious message and into routine productivity workflows, increasing the chance that targets will treat the interaction as…
-
29-Year-Old Squid Proxy Vulnerability Exposes Authorization Headers and API Keys
A recently disclosed vulnerability in Squid Proxy, tracked as CVE-2026-47729 and referred to as “Squidbleed,” is exposing sensitive user data, including HTTP authorization headers and API keys. This issue arises from a decades-old memory-handling flaw in Squid’s codebase, dating back to at least 1997. It affects default configurations and illustrates how support for legacy protocols…
-
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
OpenAI on Monday said it’s releasing an improved version of its GPT”‘5.5″‘Cyber model to trusted defenders as part of the Daybreak initiative, the artificial intelligence (AI) company announced last month.Calling GPT”‘5.5″‘Cyber its “strongest model yet for finding and helping patch software vulnerabilities,” OpenAI said the model can “sustain deeper analysis across large codebases” to identify…

