Tag: cyber
-
AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale
Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ, a platform for building, running, and governing AI agents across teams and workflows. AgentZ brings the agent, its execution environment, tools, workflows, permissions, and governance into a single platform, so organizations can move agents from experiment to production without assembling…
-
Russian Cyber Espionage Infrastructure Uses Evilginx and OAuth Phishing to Steal Accounts
Tags: access, authentication, credentials, cyber, espionage, exploit, flaw, infrastructure, phishing, russia, softwareRussian-linked cyber espionage operators are expanding account-compromise operations by combining OAuth abuse, device-code phishing, credential-harvesting infrastructure, and suspected Evilginx reverse-proxy setups. GTIG assesses with moderate confidence that UNC6293 is an initial-access subcluster of ICE RELIC, formerly tracked as APT29, Cozy Bear, and Midnight Blizzard. Rather than exploiting a software flaw, the operators abuse legitimate authentication…
-
SLEEPWALKER Backdoor Uses Magic Packet, DLL Side-Loading and In-Memory Shellcode Execution
A newly documented Windows backdoor named SLEEPWALKER combines passive network monitoring, DLL side-loading, and encrypted bytecode to remain dormant until attackers deliver a precisely crafted trigger packet. The malware does not beacon to a conventional command-and-control server, making it particularly difficult to identify through outbound-traffic monitoring alone. The 59,904-byte unsigned file masquerades as Microsoft’s dpapi.dll…
-
AI will not fix a governance problem in your camera estate
Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/27/rob-janssens-hikvision-europe-surveillance-camera-security/
-
AnonyMousKIT PhaaS Automates Apple ID, Device Passcode, and Live 2FA Harvesting Across Five Channels
AnonyMousKIT, an AI-enabled Phishing-as-a-Service (PhaaS) platform built to turn stolen Apple devices into monetizable assets. The service automates the collection of an owner’s device passcode, Apple ID credentials and live two-factor authentication (2FA) codes information that can enable criminals to remove Activation Lock and resell a stolen device. Rather than relying on a single phishing…
-
Ubiquiti Fixes 22 UniFi Flaws Enabling Command Injection, Authentication Bypass and Privilege Escalation
Ubiquiti has released security updates to address 22 vulnerabilities across its UniFi ecosystem. These updates include multiple critical flaws that could allow unauthenticated command injection, authentication bypass, and privilege escalation on exposed devices. Documented in Security Advisory Bulletin 067 and published on August 26, 2026, these vulnerabilities affect several components, including UniFi OS, UniFi Protect,…
-
Apache Tomcat Flaws Let Attackers Bypass Authentication and Security Controls, Trigger DoS Attacks
Apache has released version 11.0.25 of Apache Tomcat to address ten security vulnerabilities, including multiple flaws that could lead to authentication bypasses, access-control evasion, and denial-of-service (DoS) conditions. The most serious issues affect Tomcat’s processing of security constraints, authentication mechanisms, HTTP/2 implementation, and behavior of the RewriteValve. All ten vulnerabilities impact releases of Apache Tomcat…
-
The best human hacking team still out-solved the best AI team
Bring an AI agent to a hacking competition and you would expect to find it propping up the teams who were struggling. In the 2026 Global Cyber Skills Benchmark, agents showed … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/27/ai-ctf-security-teams/
-
Why mission risk should drive cyber operations strategies
First seen on scworld.com Jump to article: www.scworld.com/perspective/why-mission-risk-should-drive-cyber-operations-strategies
-
US lawmakers question CISA workforce cuts amid rising cyber threats
First seen on scworld.com Jump to article: www.scworld.com/brief/us-lawmakers-question-cisa-workforce-cuts-amid-rising-cyber-threats
-
UK government set to adjudicate on ‘risky’ tech purchases
New proposals for amendments to the Cyber Security and Resilience Bill would enable the UK government to clamp down on purchases of technology from suppliers linked to hostile foreign countries. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649781/UK-government-set-to-adjudicate-on-risky-tech-purchases
-
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. First seen on cyberscoop.com Jump to article: cyberscoop.com/energy-department-cybersecurity-executive-order-rules/
-
Cyber Novice Takes Top Prize in SANS AI Forensics Contest
Find Evil! Contest Winners Show That Evidence Controls Matter More Than AI Speed. SANS challenged participants to turn an experimental AI forensic agent into a trustworthy open-source tool. Entries had to investigate digital evidence autonomously while restricting system access, documenting their actions and correcting unsupported conclusions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-novice-takes-top-prize-in-sans-ai-forensics-contest-a-32662
-
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
GoCaracal is a new modular malware framework that broadens Dark Caracal’s capabilities to steal data and maintain access to victims. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/dark-caracal-adds-new-malware-cyber-espionage-arsenal
-
Stop Building a 2003 SOC with AI: Local Context, Failure Modes and Your Path (Part 3)
In Part 1 of this series, we dumped a pile of uncomfortable questions on you and promised answers. In Part 2 of the series, we talked about why 1990s-2000s alert triage must die. The core thesis, if you recall: if you add AI agents into a legacy, swivel-chair SOC structure, you are essentially building a robotic…
-
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka First seen on thehackernews.com…
-
CISA confirms hackers targeted over 100 US water systems during July
The federal cyber agency’s warning comes amid a wave of suspected Iran-backed cyberattacks targeting critical water systems across the United States. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/26/cisa-confirms-hackers-targeted-over-100-us-water-systems-during-july/
-
Kritische Schwachstellen zur Ausweitung von Active-Directory-Rechten
‘ResetNightmare” und ‘KerberLoss” nutzen Schwächen von Identitätssystemen in der Interpretation von Benutzer- und Dienstnamen aus, wodurch Angreifer möglicherweise Dienste stören, die Authentifizierung untergraben oder sich als privilegierte Benutzer ausgeben können. Der Experte für identitätsbasierte Cyber-Resilienz und Krisenbewältigung, Semperis, gab bekannt, dass Shai Laron, Sicherheitsforscher bei Semperis, zwei kritische Sicherheitslücken in Active-Directory (AD) entdeckt hat, die…
-
FBI disrupts proxy network enabling Chinese espionage operations
The FBI has disrupted infrastructure associated with a technical “quartermaster” that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/
-
Russia-Linked Operators Used ChatGPT to Run a Secretive Online Influence Campaign
OpenAI has disrupted a covert influence operation that used ChatGPT to promote a purported Israeli think tank, spread Russia-favorable narratives, and manufacture the appearance of academic legitimacy across major social platforms. The company banned a cluster of accounts it assessed as very likely originating in Russia after tracing AI-generated posts to a broader network built…
-
Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks
Iran-linked threat actor Tortoiseshell is expanding its espionage toolkit with reverse SSH tunneling utilities and a TWOSTROKE-like backdoor designed to give operators covert, durable access to compromised internal networks. The research began with public reporting from Kaspersky on Mirage Kitten’s newer malware ecosystem, which included the NightLedger backdoor and WebSocket tunneling tools ArcBridge and BridgeHead.…
-
R-tec Cyber Security Lagebericht – Externe Admins, interner Kontrollverlust
Tags: cyberFirst seen on security-insider.de Jump to article: www.security-insider.de/lagebericht-2025-dienstleisterzugang-cloud-risiko-a-abe25a01764c7440cdbd66f23d8e63ec/
-
(g+) Opinion Business Insight: AI has opened up big holes in cyber security
It is too late to stop the technology being used as a damaging weapon, so great investment in defences is urgently needed First seen on golem.de Jump to article: www.golem.de/news/opinion-business-insight-ai-has-opened-up-big-holes-in-cyber-security-2608-212328.html
-
How to Fix Enterprise Cyber Risk Platform Adoption
<div cla You’ve invested in an enterprise cyber risk management platform. Your security team completed training, your compliance officers signed off, and your board approved the budget. Six months later, adoption has stalled. Assessments still live in spreadsheets. Risk data remains fragmented across departments. Executive reports take days to compile manually. First seen on securityboulevard.com…
-
Ab dem 11. September steht Europas Software-Lieferkette unter einer 24-Stunden Meldefrist
Ab dem 11. September 2026 gilt die Anwendung von Artikel 14 des Cyber-Resilience-Act (CRA). Dann müssen Software-Hersteller aktiv schwerwiegende Sicherheitsvorfälle und ausgenutzte Schwachstellen über die Single-Reporting-Platform der <> melden. Diese Plattform ist zwar noch nicht geöffnet. Dennoch können fast alle Entscheidungen, die für eine reibungslose Erstellung des ersten Berichts gemäß den von ENISA im Juli…
-
Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code
WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary code on affected endpoints. These vulnerabilities, tracked as CVE-2026-57910 and CVE-2026-57909, have CVSS v4.0 scores of 9.3 and 9.4, respectively. Both issues impact WatchGuard Agent versions earlier than 1.25.13.0000. If exploited, these vulnerabilities could give an…
-
SonicWall NetExtender Flaw Lets Attackers Write Arbitrary Files as Root
SonicWall has released security updates for two high-severity vulnerabilities in its NetExtender Linux Client. One of these is a path traversal flaw that could allow attackers to write arbitrary files with root privileges. The most severe issue, tracked as CVE-2026-66152, has a CVSS score of 8.8/10 and affects NetExtender Linux Client versions 10.3.5 and earlier.…
-
Fake Claude Desktop Installer Deploys SectopRAT Using DLL Sideloading and Blockchain C2
A fake Claude Desktop installer campaign is using Bing malvertising to impersonate trusted Claude. ai-hosted content, DLL sideloading, and blockchain-based command-and-control to deploy the SectopRAT remote-access trojan. CyberProof researchers said an agent-led hunt scoped the full intrusion chain across endpoint telemetry in about ten minutes, turning a single suspicious scheduled task into a confirmed multi-stage…
-
Average Cyber Insurance Losses Increase Despite Fewer Claims
Chubb reported that growing privacy litigation has contributed to surging cyber claim costs in the US First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cyber-insurance-losses-increase/
-
Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.
Threat actors are abusing npm’s package-distribution ecosystem to host convincing fake Cloudflare verification pages on trusted mirror domains, turning developer infrastructure into a phishing delivery layer. OX Security said it identified 24 malicious npm packages containing identical HTML code designed to render a fake CAPTCHA page and redirect visitors to attacker-controlled infrastructure. The campaign does…

