Tag: cyber
-
JSCeal Crypto Stealer Uses V8 Bytecode to Steal Browser Credentials and Intercept HTTPS
A sophisticated cryptocurrency-focused information stealer that hides its malicious logic inside compiled V8 JavaScript bytecode. JSCeal, also tracked by some vendors as WEEVILPROXY or MeadowLocust, is not delivered as readable JavaScript. Instead, operators package the final payload as a .jsc file compiled V8 bytecode executed with a bundled Node.js runtime. This approach frustrates conventional JavaScript…
-
Critical JFrog Artifactory Authentication Bypass Exploited in the Wild
Security researchers have issued warnings that attackers are actively exploiting a critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329. This vulnerability allows the generation of administrator-level access tokens. According to a post from the security research firm watchTowr dated September 1, its threat intelligence team has already observed exploitation activities targeting this flaw.…
-
The Collective Cyber Defense letter wrote your next vendor questionnaire
More than 200 companies have now signed to an August 27 letter about improving cyber defenses in the age of AI. Buried in it are three metrics every one of them endorse under its own logo: coverage, containment speed, and whether fixes work. First seen on cyberscoop.com Jump to article: cyberscoop.com/collective-cyber-defense-letter-vendor-questionnaire-op-ed/
-
AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks
BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised corporate systems. Rather than behaving like a conventional infostealer, BraZetsu appears designed to support an Initial Access Broker operation, converting infected endpoints into cataloged access offerings for an underground marketplace. The framework is reportedly the…
-
Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials
Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan internet-facing servers for exposed secrets, according to a GreyNoise research report published on August 28, 2026. This activity involves automated scanners that use forged crawler user-agent strings to request sensitive files, including .env configurations, AWS…
-
SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications
A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections. Raw-packet activation, DNS-based tasking support, VMware VMCI communications, named-pipe capabilities, and in-memory payload execution. No threat actor, victim, delivery chain, or live campaign has yet been attributed to the malware. SLEEPWALKER is an unsigned 64-bit Windows DLL…
-
WordPress Uses Frontier AI Tools to Detect Vulnerabilities Before They Can Be Exploited
The WordPress project has launched a coordinated security program to improve how vulnerabilities are identified, prioritized, fixed, and released across the world’s most widely used content management system. This initiative, known as the Core Security Initiative, responds to a significant rise in security-related reports over the past year. According to Rudy Faile, a member of…
-
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
The Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AI First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/financial-stability-board-alarm/
-
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
The Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AI First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/financial-stability-board-alarm/
-
Fake Claude Opus 5 App Deploys RevStealer to Steal Passwords, Crypto Wallets and Sessions
Threat actors are exploiting demand for generative AI tools to distribute RevStealer, a Windows-focused information stealer hidden inside a trojanized Electron application that impersonates a free desktop version of Anthropic’s Claude Opus 5. Instead a stealthy credential theft tool engineered to evade sandboxes, endpoint monitoring, and post-infection investigation. The primary lure, branded “Claude Opus 5…
-
TDL 029 – Decoupling Digital Identity: Beyond Carrier-Level Defense – Mark Kreitzman
Why Your Phone Number Is the Ultimate Cyber Target”, and How to Secure It In a recent episode of The Defender’s Log, host David Redekop sat down with Mark Kreitzman, General Manager at Efani and a 25-year cybersecurity veteran, to discuss… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/tdl-029-decoupling-digital-identity-beyond-carrier-level-defense-mark-kreitzman/
-
Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages
A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen is exposing developer workstations and CI/CD runners to a credential-stealing, self-propagating payload. On August 28, 2026, attackers published ten malicious versions across every maintained release branch of the OpenAPI-to-TanStack Query code generator, which records roughly 150,000 weekly downloads. The releases appeared in two publishing waves approximately…
-
Fire Ant Hackers Compromise Cisco Routers and TACACS Servers to Target Critical Infrastructure
China-nexus threat actor Fire Ant has expanded its espionage operations from VMware hypervisors to the trusted infrastructure layer, compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Security firm Sygnia, which investigated the activity, said Fire Ant has remained active since it was first reported in 2025. The actor’s latest operations show…
-
PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain
Tags: advisory, attack, authentication, cve, cyber, microsoft, rce, remote-code-execution, vulnerabilityA public proof-of-concept (PoC) repository has garnered attention for a pre-authentication remote code execution chain targeting Microsoft Exchange Server. This repository highlights CVE-2026-62911, an Exchange authentication-bypass vulnerability disclosed following Pwn2Own Berlin 2026. Defenders should treat the published code as unverified until it is independently validated in an isolated laboratory environment. Both the official advisory and…
-
Hackers Launch Password Spraying Attacks Against AWS Root Accounts at 150+ Organizations
Research has discovered a password-spraying campaign targeting AWS root user accounts across more than 150 organizations. This highlights ongoing efforts by attackers to compromise the most privileged identities in cloud environments. The campaign ran from July 24 to August 23, 2026, and involved multiple failed authentication attempts against AWS root accounts. Most affected organizations recorded…
-
13 Malicious Packagist Themes Exploit iPhone Vulnerabilities to Steal Crypto Wallet Seeds
13 malicious Composer theme packages on Packagist that turn Vietnamese movie and comic streaming websites into delivery points for iPhone spyware, gambling redirects, ad fraud, and cryptocurrency-wallet theft. Once an operator installs one of the trojanized themes through Composer, the bundled front-end JavaScript is served to every visitor. Mobile users are selectively targeted, while iPhone…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
Broadcom Unveils VMware AI Factory With Secure Sandboxes for Enterprise AI Workloads
Broadcom has announced the VMware AI Factory, a software-defined private AI platform designed to accelerate the transition from bare-metal servers to production-ready AI models. This platform enhances governance, infrastructure automation, and workload isolation. Unveiled during VMware Explore 2026, the VMware AI Factory serves as the foundation for VMware’s Private AI Cloud. It combines VMware Cloud…
-
BGP Hijacking Attack Delivers Malicious Virtualizor Updates to Servers
A BGP hijacking incident targeting Softaculous infrastructure redirected traffic for Virtualizor update services to attacker-controlled systems, allowing a malicious update package to be delivered to a small number of servers. The incident impacted the IP range 162.55.80.0/24, which is hosted within Hetzner’s infrastructure, from approximately 20:57 UTC on August 28 to 06:10 UTC on August…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
Texas a Test Ground for White House Water Cybersecurity Push
Watershed 250 Promises Free Cyber Resources for Small Water Utilities. Texas Gov. Greg Abbott and White House National Cyber Director Sean Cairncross Monday announced the launch of Project Watershed 250, connecting Texas water utilities with free cyber defense resources in a pilot program the Trump administration hopes to scale nationwide. First seen on govinfosecurity.com Jump…
-
Iran Cyber Risk Climbs as US Resumes Strikes
Kinetic Escalation Has Preceded Every Wave of US Utility Intrusions. U.S. forces struck two Iranian rocket launchers near the Strait of Hormuz on Sunday, ending a monthlong lull in a conflict where every kinetic escalation has been followed by federal warnings about Iranian-linked probing of water and energy control systems. First seen on govinfosecurity.com Jump…
-
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
The six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.” First seen on cyberscoop.com Jump to article: cyberscoop.com/watershed-250-texas-water-cybersecurity-pilot/
-
Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI Credentials
Bnei Brak, Israel, 31st August 2026, CyberNewswire First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/lunar-cyber-launches-token-exposure-monitoring-as-infostealers-target-developer-and-ai-credentials/
-
Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks
Aurora ransomware operators have been observed using Cursor Agent, powered by Claude Sonnet, to support hands-on intrusion activity across ten victim organizations, while deploying a purpose-built Linux encryptor designed to disrupt VMware ESXi environments. The findings show how ransomware affiliates are integrating agentic AI into established post-compromise workflows rather than relying on it as a…

