Tag: cyber
-
HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This vulnerability allows a local user to control a privileged component. The code was published by a GitHub user named MSNightmare and is being presented as a zero-day vulnerability. However, the vendor has not confirmed it.…
-
Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
Research identified 19 malicious browser extensions 18 for Google Chrome and 1 for Microsoft Edge that use a modular malware framework to strip website Content Security Policy protections, inject attacker-controlled JavaScript. Socket determined that 14 extensions were created by the threat actor, while five were acquired from legitimate developers and subsequently weaponized. The most consequential…
-
Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency involving print management servers. The proposed module targets CVE-2026-81578 and CVE-2026-82078, two vulnerabilities that attackers can exploit to achieve remote code…
-
OpenClaw 2.0 Released With Enhanced AI Agent Security and Credential Protection
OpenClaw has launched version 2.0, offering a major overhaul of its AI-agent platform. This update emphasizes streamlined deployment, a rebuilt browser experience, collaborative cloud sessions, and enhanced security for credentials and connected services. The release on August 30 represents the largest update in the project’s history, according to the OpenClaw Foundation. It features contributions from…
-
China-linked Fire Ant Hides Inside Trusted Infrastructure
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising…
-
Microsoft Defender Bug Triggers False “Antivirus Turned Off” Alerts on Windows
Microsoft has confirmed an issue with Microsoft Defender Antivirus that generates false notifications on Windows systems, claiming >>Microsoft Defender Antivirus is turned off,<< even though the protection is still operational. These alerts may appear after installing the latest Defender updates, potentially causing unnecessary concern for administrators who observe that Defender settings are healthy and security…
-
AI Shopping Assistant Vulnerabilities Enable Remote Code Execution on Retailer’s Servers
Security researchers have demonstrated how flaws in the AI shopping assistant of a major unnamed U.S. retailer could be exploited to enable remote code execution (RCE) on the company’s backend infrastructure through its public-facing mobile application. Netanel Rubin, co-founder and CTO of Rein Security, along with researcher Dan Avraham, presented their findings during a Black…
-
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks.Sygnia, the incident response firm that investigated the intrusion, said the actor First seen…
-
Shai-Hulud Trinitite Worm Infects Popular TanStack Query npm Package to Steal Developer Secrets
A new Shai-Hulud supply-chain attack dubbed Trinitite has compromised the npm package @7nohe/openapi-react-query-codegen, a TanStack Query code-generation library with more than 150,000 weekly downloads. The malicious releases deploy an evolved Mini Shai-Hulud worm designed to steal developer, cloud, CI/CD, package-registry, Kubernetes, Vault, and source-control credentials before using recovered access to spread through additional packages. While…
-
Cyber Assessment Framework (CAF) Version 4.0
What is the Cyber Assessment Framework? The Cyber Assessment Framework (CAF) is a cybersecurity and resilience framework developed by the UK National Cyber Security Centre (NCSC). It helps organizations assess how effectively they manage cyber risks to their essential functions and services. CAF 4.0 is primarily relevant to organizations in critical sectors such as energy,……
-
Android 17 Adds New Network Security Features to Block 2G SMS Blaster Attacks
Android 17 introduces a new set of network security controls to reduce cellular downgrade attacks, protect local networks, and limit metadata exposure during encrypted web sessions. This update includes carrier-managed 2G shutdown capabilities designed to combat SMS blaster campaigns that increasingly target users in public spaces. Google states the Android 17 changes focus on four…
-
Magecart Hackers Abuse Ethereum Smart Contracts to Steal Card Data From 40+ Online Stores
A Magecart campaign dubbed HexMage has compromised more than 40 e-commerce storefronts across at least 15 countries, using Ethereum smart contracts as a resilient delivery mechanism for payment-card skimmers. The operation blends traditional client-side checkout theft with EtherHiding, allowing attackers to conceal and rotate skimmer infrastructure through Ethereum’s Sepolia testnet. Because the malicious code is…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in…
-
New Gryxa Toolkit Uses AI-Built Persistence to Fight Back Against Security Teams
A financially motivated threat actor using a new Windows toolkit named Gryxa that combines remote monitoring and management abuse, AI-assisted development, browser credential theft, and aggressive persistence designed to survive incomplete remediation. The toolkit’s most unusual feature is its ability to collect evidence of how defenders removed its visible access and send that information back…
-
Composer Path Traversal Flaw Lets Malicious Packages Expose Sensitive Files
Composer users are urged to update their software following the disclosure of a path-traversal vulnerability. This flaw could allow a malicious or compromised PHP package to change file permissions outside of its own installation directory. The vulnerability is tracked as CVE-2026-59944 and GHSA-96h3-5x6v-m776, affecting Composer versions 2.3.0 through 2.10.2 and versions 1.0 through 2.2.29. Composer…
-
Critical Microsoft UFO MCP Flaw Lets Attackers Remotely Control Android Devices Without Authentication
Tags: access, android, authentication, control, cve, cvss, cyber, flaw, microsoft, mobile, open-source, vulnerabilityA critical vulnerability in Microsoft’s open-source UFO Desktop AgentOS could allow remote attackers to access and control Android devices connected via the platform’s Mobile Model Context Protocol (MCP) servers without requiring authentication. This vulnerability is tracked as CVE-2026-73296 and GHSA-24fq-m9rr-g3mm, carrying a CVSS v3.1 score of 9.4. It affects UFO versions up to and including…
-
TerminalFix Uses Fake CAPTCHA, DLL Sideloading and Steganography to Breach Networks
A sophisticated ClickFix variant dubbed TerminalFix that uses fake Cloudflare CAPTCHA prompts to trick users into executing attacker-controlled PowerShell commands. Rather than delivering a conventional infostealer, the campaign builds persistent access and deploys a reverse-tunnel implant capable of turning an infected Windows endpoint into a proxy for reaching internal network resources The intrusion begins on…
-
Hackers Use Infostealer Malware to Steal Claude Session Cookies and Hijack Accounts
Anthropic’s Claude AI platform is currently dealing with two separate cybercrime campaigns that aim to steal account credentials, misuse paid subscriptions, and reinstall malware even after a victim believes their device has been cleaned. In response to this threat, Anthropic has started invalidating compromised sessions, removing saved payment methods, and refunding verified fraudulent charges. While…
-
Advanced AI threatens global financial stability, says Bank of England boss
Andrew Bailey warns G20 members about risk of cyber-disruption spreading ‘across jurisdictions’The Bank of England’s governor, Andrew Bailey, has joined the throng of figures warning about the global risks posed by the most advanced artificial intelligence technology.In a two-page letter sent to international finance ministers and central bank governors as part of his role as…
-
Simple Router DNS Tweak Blocks Malware and Phishing Across All Connected Devices
A recent router-level DNS change is gaining attention as a method to reduce exposure to phishing pages and malware across all devices connected to a home network. Cybersecurity expert Luis Catacora has recommended replacing a router’s default DNS resolvers with Cloudflare’s malware-filtering addresses: 1.1.1.2 as the primary resolver and 1.0.0.2 as the secondary. Simple Router…
-
Infostealer Infection Exposes Blind Eagle-Linked Operator’s Malware Production Pipeline
A compromised attacker-side workstation has given researchers an unusual view into the operational ecosystem behind a suspected Blind Eagle malware campaign, exposing RAT builders, phishing templates, bulk-mail tooling, crypter activity and infrastructure tracking records. Rather than directly exposing a modified executable, the account hosted a legitimate AutoIt interpreter alongside separately retrievable malicious script logic an…
-
OpenAI Warns Astra AI Model May Develop Zero-Day Exploits and Launch Autonomous Cyberattacks
Tags: ai, cyber, cyberattack, cybersecurity, exploit, intelligence, openai, update, vulnerability, zero-dayOpenAI has issued a warning regarding Astra, an upcoming artificial intelligence model, which may be close to a threshold of cybersecurity capabilities that would allow it to independently discover zero-day vulnerabilities and conduct complex cyberattacks against highly secured systems. In a security update dated August 7, 2026, the company noted that early testing and assessments…
-
HIPAA Risk Assessments 2026: Continuum GRC Healthcare Audits
In 2026, healthcare organizations face increasing pressure to maintain robust data protection measures under evolving regulatory landscapes. HIPAA risk assessments remain a cornerstone of compliance, helping providers identify vulnerabilities and safeguard protected health information. As cyber threats grow more sophisticated, proactive compliance assessments become essential for decision-makers seeking to minimize liability and ensure operational resilience.”¦…
-
Frontier AI tipping the scales toward cyber adversaries
Researchers at Palo Alto Networks’ Unit 42 warn that threat actors are already using AI to accelerate cyberattacks beyond the abilities of modern defenses. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/frontier-ai-tipping-scales-cyber-adversaries/829088/
-
You Need Cyber Deception for OT
The frustrating reality after an OT cyberattack: no data, no trail, and no history. First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/you-need-cyber-deception-ot
-
Der T-Rex-Moment der KI: Wenn Sicherheitszäune plötzlich nicht mehr reichen
Frontier AI verändert die Cyber-Bedrohungslage. Unternehmen müssen mit Zero Trust, Segmentierung, KI-Governance und defensiver KI ihre Resilienz stärken. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/der-t-rex-moment-der-ki-wenn-sicherheitszaeune-ploetzlich-nicht-mehr-reichen/a46289/
-
The AI Tunes Itself. Until It Doesn’t.
<div cla Two stories broke this week. One was loud, one was quiet, and both say the same thing about trusting autonomous AI. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-ai-tunes-itself-until-it-doesnt/

