Tag: cyber
-
OpenAI, Anthropic, Warn of ‘Limited Window’ for AI Cyber Defense
OpenAI and Anthropic are among more than 100 tech companies that are calling for a collective action for creating stronger protections against the threats emerging with the powerful AI models that they’re building. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/openai-anthropic-warn-of-limited-window-for-ai-cyber-defense/
-
Breach Roundup: A Call for Cyber Defense Collective Action
e=4>This week: a call for cyber defense, OpenAI banned Russian ChatGPT accounts, critical Gitea flaw, U.K. airport passenger data theft, North Korean remote workers, Barcelona police data, Norway services hit by DDoS, Taiwan charged 9 over AI server exports and Nigeria advanced a sovereign cloud push. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-call-for-cyber-defense-collective-action-a-32673
-
White House bans foreign-made equipment for power generation over cyber backdoor concerns
The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology. First seen on therecord.media Jump to article: therecord.media/trump-cyber-electricity-parts
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Salt Typhoon Is Already Inside Encryption Doesn’t Solve the Problem
Tags: access, advisory, ai, api, china, cisa, cloud, communications, control, credentials, cyber, cybersecurity, data, defense, detection, encryption, endpoint, exploit, government, identity, infrastructure, intelligence, Internet, microsoft, network, resilience, risk, router, saas, service, software, strategy, switch, technology, theft, threat, tool<div cla COMMUNICATIONS SECURITY BRIEFING What Volt Typhoon and Salt Typhoon reveal about the next front in communications security, and why hardened transport is the missing layer Volt Typhoon and Salt Typhoon mark a deliberate shift in how state-sponsored cyber campaigns operate. Rather than chasing endpoints or applications, these actors have gone after the infrastructure…
-
Chinese Hacking Operation Targeted U.S. Senate, NASA, Federal Reserve
U.S. authorities have disabled two hacking platforms allegedly operated by a China-based company whose customers included Chinese intelligence and military organizations, disrupting a cyber campaign that targeted major U.S. government agencies and critical infrastructure. The Justice Department and FBI seized domains supporting QScan and QTRouter, two platforms operated by a state-sponsored hacking group known as..…
-
100-plus companies call for ‘global surge’ in AI-powered cyber defense
OpenAI, Anthropic, Google, Microsoft, and others say there’s a narrow “defenders’ window” to strengthen security before AI-powered attacks become more sophisticated. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-cyber-defense-global-surge/
-
Peers propose report into Computer Misuse Act reform
After previous proposals were brushed aside, Computer Misuse Act reform may be back on the agenda under a new amendment to the Cyber Security and Resilience Bill. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649543/Peers-propose-report-into-Computer-Misuse-Act-reform
-
Can We Trust AI Agents With Security Decisions? Adarsh Kant Sinha Explains
As organizations race to move from AI chatbots and copilots toward autonomous AI agents, security leaders are being forced to answer a harder question than “should we adopt AI?”, it’s “can we trust AI to make security decisions?” To unpack this, The Cyber Express sat down with Adarsh Kant Sinha, Founder and CEO of ANVE.AI.…
-
AI Agents Used by 68% of Top-Performing Cybersecurity Teams
AI agents are already finding their way into the working methods of some of the highest-performing cybersecurity teams, according to new three-year benchmark data from Hack The Box (HTB). The 2026 Global Cyber Skills Benchmark found that 68% of the top 25 teams included an AI agent, despite AI agents accounting for just 2.7% of…
-
Three UK airports hit by cyber-attack with data of 8.7m customers accessed
Company that runs Manchester, Stansted and East Midlands hubs says passenger safety is unaffected<ul><li><a href=”https://www.theguardian.com/business/live/2026/aug/27/asian-technology-shares-ride-high-ai-optimism-nvidias-stunning-results-jackson-hole-live-updates”>Business live latest updates</li></ul>Manchester, London Stansted and East Midlands airports have been hit by a cyber-attack, with hackers accessing the data of about 8.7 million customers.Hackers obtained their email addresses, phone numbers, vehicle registration numbers and postcodes, as the incident affected…
-
AWS Security Teams Can Correlate CloudTrail, VPC and Route 53 Logs to Detect Attacks
AWS security teams can improve detection of multi-stage intrusions by correlating API activity in CloudTrail with network metadata in VPC Flow Logs and DNS activity in Route 53 Resolver query logs. The approach turns isolated alerts into an attack narrative spanning credential abuse, reconnaissance, privilege escalation, lateral movement and data exfiltration. A suspicious GetCallerIdentity request…
-
Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency
Suspected Chinese-speaking operators exploited the critical ownCloud flaw CVE-2023-49105 to steal nuclear material records, research reactor data, personnel files, and encryption key material from a Philippine nuclear research organization. Hunt.io discovered an exposed file directory on August 13, 2026, hosted at 31.58.209[.]241:8000, an Amsterdam-based server registered to CGI Global Limited. The directory was served through…
-
UK airports operator hit by cyber-attack and customer data accessed
Company that runs Manchester, Stansted and East Midlands airports says passenger safety is unaffected<ul><li><a href=”https://www.theguardian.com/business/live/2026/aug/27/asian-technology-shares-ride-high-ai-optimism-nvidias-stunning-results-jackson-hole-live-updates”>Business live latest updates</li></ul>Three UK airports have been hit by a “cybersecurity incident” in which the data of about 8.7 million customers was accessed, Manchester Airport Group (Mag) has said.The company, which operates Manchester Airport, London Stansted and East Midlands airport,…
-
Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power
AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways, RAGFlow retrieval platforms, and Kestra workflow orchestration environments to steal model-provider credentials, establish persistence, access backend data, and deploy cryptominers. The appeal is clear. AI gateways often centralize OpenAI, Azure, Anthropic, Gemini, and other provider API keys; retrieval platforms hold…
-
CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability
Tags: cisa, citrix, cve, cyber, cybersecurity, exploit, infrastructure, kev, mitigation, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. This vulnerability was added on August 26, 2026, and federal civilian agencies are required to apply vendor-recommended mitigations by August 29, 2026. Citrix…
-
TP-Link Kasa Smart Home Flaw Lets Attackers Forge Control Messages and Take Control of Devices
TP-Link has revealed a critical vulnerability in Kasa smart home devices that could allow an attacker on the same local network to intercept, replay, or forge control messages, potentially manipulating affected products. This issue, tracked as CVE-2026-76784, arises from inadequate cryptographic protections in the protocol used for local communications among Kasa devices. TP-Link has assigned…
-
Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations
A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow. It contained victim-specific directories, shell history,…
-
CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability
Tags: cisa, cve, cyber, cybersecurity, exploit, infrastructure, kev, microsoft, rce, remote-code-execution, service, sql, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution vulnerability affecting Microsoft SQL Server, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. This vulnerability allows an attacker to execute code in the security context of the SQL Server Database Engine service account. Microsoft SQL Server…
-
FBI Seizes China State-Sponsored Hacker Platforms Used to Target U.S. Critical Infrastructure
The U.S. Justice Department and the FBI have seized domains associated with two hacking platforms linked to China, QScan and QTRouter. This court-authorized operation aims to disrupt attacks against U.S. critical infrastructure and sensitive government networks. Unsealed court documents from the Southern District of California revealed that these platforms were operated by a state-sponsored group…
-
Boston Scientific Reveals Global Disruption After Cyber Incident
MedTech giant Boston Scientific has revealed IT outages following a cyber incident First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/boston-scientific-global/
-
UK’s small power plants face higher cyber risk into 2030s despite Iran-linked hack
Decision not to improve resilience sooner described as ‘unacceptable gamble with our national security’Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged.Officials this week briefed energy bosses on the breach, which is understood to have shut…
-
AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale
Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ, a platform for building, running, and governing AI agents across teams and workflows. AgentZ brings the agent, its execution environment, tools, workflows, permissions, and governance into a single platform, so organizations can move agents from experiment to production without assembling…
-
GitLab Duo Claude AI Agent Flaw Lets Attackers Execute Arbitrary Commands in CI Pipelines
GitLab has released security updates for both its Community Edition and Enterprise Edition, addressing seven vulnerabilities, including a high-severity flaw in its Duo Claude AI agent. This vulnerability could allow authenticated developers to execute arbitrary commands within a CI (Continuous Integration) context. GitLab Duo Claude AI Agent Flaw The issue, tracked as CVE-2026-18252, arises from…
-
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Authentication From Service Accounts
Veeam has released security updates for a critical vulnerability in Veeam ONE that could allow an unauthenticated network attacker to coerce SMB authentication from the account running an affected service. Tracked as CVE-2026-65641, the vulnerability received a CVSS v4.0 severity score of 9.3. Veeam disclosed the issue through Knowledge Base article 4905, published on August…
-
UK’s small power plants face continued cyber risk after Iran-linked hack
Government measures to improve resilience are not due until 2030 and July’s hack has not altered this timeline<br><br> Hundreds of Britain’s smallest power plants could remain at a higher risk to state-sponsored cyber-attacks until the 2030s despite a successful Iran-linked hack last month, it has emerged.Officials this week briefed energy bosses on the breach, which…
-
AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale
Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ, a platform for building, running, and governing AI agents across teams and workflows. AgentZ brings the agent, its execution environment, tools, workflows, permissions, and governance into a single platform, so organizations can move agents from experiment to production without assembling…
-
Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Tags: access, authentication, credentials, cyber, espionage, exploit, flaw, infrastructure, phishing, russia, softwareRussian-linked cyber espionage operators are expanding account-compromise operations by combining OAuth abuse, device-code phishing, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups. GTIG assesses with moderate confidence that UNC6293 is an initial-access subcluster of ICE RELIC, formerly tracked as APT29, Cozy Bear, and Midnight Blizzard. Rather than exploiting a software flaw, the operators abuse legitimate authentication…
-
SLEEPWALKER Backdoor Uses Magic Packet, DLL Side-Loading and In-Memory Shellcode Execution
A newly documented Windows backdoor named SLEEPWALKER combines passive network monitoring, DLL side-loading, and encrypted bytecode to remain dormant until attackers deliver a precisely crafted trigger packet. The malware does not beacon to a conventional command-and-control server, making it particularly difficult to identify through outbound-traffic monitoring alone. The 59,904-byte unsigned file masquerades as Microsoft’s dpapi.dll…

