Tag: cyber
-
Hackers Turn Trusted npm Mirrors Into Hosts for Fake Cloudflare ClickFix Pages.
Threat actors are abusing npm’s package-distribution ecosystem to host convincing fake Cloudflare verification pages on trusted mirror domains, turning developer infrastructure into a phishing delivery layer. OX Security said it identified 24 malicious npm packages containing identical HTML code designed to render a fake CAPTCHA page and redirect visitors to attacker-controlled infrastructure. The campaign does…
-
Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems
Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to execute malicious JavaScript and TypeScript payloads. The campaign demonstrates how trusted developer tooling can be turned into an effective execution layer for malware while reducing the value of file-signature and hash-based detection. The…
-
Critical WordPress TranslatePress Flaw Lets Attackers Take Over Admin Accounts
A critical vulnerability in the TranslatePress multilingual WordPress plugin could enable unauthenticated attackers to take control of administrator accounts and fully compromise affected websites. This vulnerability, tracked as CVE-2026-19632, has a CVSS score of 9.8 and affects all TranslatePress versions up to 3.3.1. The flaw affects a plugin installed on over 400,000 WordPress sites. Security…
-
Google Chrome 152 Patches 327 Security Flaws, Including 10 Critical Vulnerabilities
Google has released Chrome version 152 for Windows, macOS, and Linux, addressing 327 security vulnerabilities, including 10 rated as Critical. This stable-channel update is being rolled out as version 152.0.7977.64 for Linux and 152.0.7977.64/.65 for Windows and macOS. This update is significant due to the sheer number and severity of memory-safety issues fixed across Chrome’s…
-
NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding
A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents through a single visit to a malicious website. Researchers Elad Luz and Ofek Itach from Oasis Security discovered that NemoClaw’s local Ollama configuration exposes an unauthenticated API, making it susceptible to DNS rebinding attacks.…
-
INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects.”The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks such as the Black Axe and other similar groups,”…
-
Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code
Microsoft SharePoint Server administrators are being urged to patch two vulnerabilities that could be combined to allow unauthenticated remote code execution on exposed on-premises servers. The flaws, tracked as CVE-2026-55040 and CVE-2026-63520, affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft SharePoint Flaws The urgency has increased after Defused reported…
-
28,000 Exposed .git Repositories Leak Active AWS, OpenAI, Stripe and GitHub Credentials
A large-scale internet scan has uncovered 28,000 publicly accessible .git repositories exposing credentials for AWS, OpenAI, Stripe, GitHub, and other services, illustrating how a basic web server misconfiguration can turn source code history into an immediate cloud access risk. The research, published by attack-surface management firm Intruder, examined 3.5 million live HTTP hosts selected from…
-
Linux Turns 35 as Open-Source Kernel Powers Global Critical Infrastructure
Linux has now reached 35 years old, serving as a reminder of the modern world’s reliance on an open-source kernel. On August 25, 1991, a 21-year-old student at the University of Helsinki, Linus Torvalds, announced his work on the comp.os newsgroup.minix Usenet group. He introduced a free operating system for 386/486 AT clones that he…
-
Linux Turns 35 as Open-Source Kernel Powers Global Critical Infrastructure
Linux has now reached 35 years old, serving as a reminder of the modern world’s reliance on an open-source kernel. On August 25, 1991, a 21-year-old student at the University of Helsinki, Linus Torvalds, announced his work on the comp.os newsgroup.minix Usenet group. He introduced a free operating system for 386/486 AT clones that he…
-
Nigeria Looks to Sovereign Cloud for Cyber, National Security
The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/nigeria-sovereign-cloud-cyber-national-security
-
AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users
Mexico’s financial sector is facing an industrialized phishing Balonx Sistema, a Mexico-focused Phishing-as-a-Service (PhaaS) platform that has harvested credentials and financial data from more than 1,100 banking users since at least October 2025. The service targets over 20 Mexican financial institutions and combines live phishing, Android malware, and AI-driven voice fraud in one subscription-based operation.…
-
OpenSSL Flaws Allow Remote Attackers to Crash Servers With Malformed Packets
OpenSSL has released security updates addressing nine vulnerabilities that could allow remote attackers to crash QUIC, DTLS, CMS, CMP, and TLS-enabled applications through malformed network packets or cryptographic messages. The advisory dated August 25, 2026, highlights three moderate-severity issues and six low-severity flaws. Most of these problems could lead to denial-of-service (DoS) conditions due to…
-
Hackers Hide Malware Inside Plain English Words to Infect Windows Users With Amatera Stealer
Threat actors behind ClearFake campaigns are using a newly identified loader, WordlistLoader, to deliver the Amatera Stealer to Windows systems. The loader disguises executable shellcode as sequences of ordinary English words, helping malware evade static inspection before reconstructing and launching the final payload in memory. Microsoft previously observed ACR Stealer operators using fake verification prompts,…
-
WhatsApp Passkeys Now Protect Over 1 Billion Users Against Account Takeover Attacks
WhatsApp has announced that over one billion people now use passkeys to secure their accounts, enhancing phishing-resistant authentication across one of the world’s largest messaging platforms. This update, revealed on August 25, introduces support for multiple passkeys, stronger two-step verification credentials, and additional context for calls from unknown numbers. These changes target common account takeover…
-
AI vulnerability discovery scores the highest impact of 20 emerging risks
Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/ai-vulnerability-discovery-emerging-risks/
-
Microsoft Teams Outage Disrupts Meetings and Screen Sharing for Users
Microsoft confirmed that some customers were unable to use multiple features of Microsoft Teams. However, the company reported that monitoring indicated the disruption was largely under control. In a customer update posted at 7:26 a.m. IST on August 26, Microsoft stated that engineers would continue to monitor the service for another 15 to 30 minutes…
-
CISA Red Team Achieves Full Domain Compromise Across Critical Infrastructure Networks
CISA’s latest red team assessment shows how common failures in Active Directory, cloud identity, and SOC processes can turn a phishing foothold into an enterprise-wide compromise. The August 25 advisory contrasts two critical-infrastructure organizations: one missed the intrusion entirely, while the other contained initial access quickly but still exposed major identity and cloud security weaknesses.…
-
Core Werewolf Hackers Deploy New CoreRAT Malware Against Russian Government and Defense Organizations
The Core Werewolf espionage cluster has introduced a previously undocumented remote access trojan dubbed CoreRAT in targeted attacks on Russian public-sector bodies and defense-industry organizations. The shift is notable because Core Werewolf, previously associated with the abuse of legitimate UltraVNC remote-access software and smaller custom backdoors, now operates a full-featured C++ RAT of its own.…
-
US Lawmakers Urge Probe of Trump Cyber Workforce Cuts
House Lawmakers Ask Watchdog to Assess Staffing Losses at US Cyber Agency. House Democrats are asking the Government Accountability Office to examine how staffing reductions and cuts at the Cybersecurity and Infrastructure Security Agency have affected the agency’s ability to defend federal networks and critical infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/us-lawmakers-urge-probe-trump-cyber-workforce-cuts-a-32653
-
Iran-Linked Hackers Blamed for UK Energy Cyberattack
A cyberattack reportedly linked to Iran forced a small UK energy generator offline for four days, raising fresh concerns about the security of the country’s critical infrastructure and smaller operators that may sit outside existing regulatory thresholds. The UK government has confirmed that a small-scale generator was affected by a cyber incident in July. It…
-
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an “unprecedented, whole-of-government, economic campaign” against the nation and its enablers.”We are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical…
-
Democratic Lawmakers Call for GAO Investigation of CISA Workforce Cuts
A group of Congressional Democrats are asking the GAO to investigate whether the deep cuts to CISA’s workforce under the Trump Administration has hobbled the agency’s abilities at a time when cyber threats against federal networks and critical infrastructure by nation-state actors are growing. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/democratic-lawmakers-call-for-gao-investigation-of-cisa-workforce-cuts/
-
Chinese Hackers Accelerate Cyberattacks Using Low-Cost AI Tools: Research
Tags: ai, china, cyber, cyberattack, cybersecurity, group, hacker, intelligence, network, open-source, toolState-affiliated Chinese hackers are dramatically scaling up foreign cyberattacks by integrating open-source artificial intelligence (AI) models into their operations, according to new research from cybersecurity firms TeamT5 and Palo Alto Networks Inc.’s Unit 42. By offloading mundane tasks and automated target-mapping to cheap, accessible AI tools, state-backed cyber groups have more than doubled their attack..…
-
MDR May Be Splitting Into Three Managed Services
I have argued for a while that MDR has to move beyond alert triage and become a cyber risk reduction service. A recent conversation with an experienced MDR operator added another piece to that thesis. The future may not be one ever-expanding MDR bundle. We may be forcing three different jobs into one category: The……
-
Is Cyber Facing an Affordability Crisis?
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/is-cyber-facing-an-affordability-crisis-
-
AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands
ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into proposed operational actions. The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 model output to controller-side functions including local shell execution, file writes, remote SSH commands, persistent state changes, and cross-compilation. Analysis published by Joe Reverser…
-
Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records
A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities in Asia, stealing thousands of personnel records, cracking employee credentials, and establishing persistent access to state infrastructure, according to Dream Research Labs. Researchers discovered a 160 MB operational archive containing 1,395 files generated over about 4 days of activity, from…
-
Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud
A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products, disclosing personal and banking information, and granting remote access to their computers. The sites, branded as SysScan, claim to assess whether an antivirus product is functioning properly. Their conclusion is predetermined: the victim’s computer is allegedly…

