Tag: cyber
-
Chinese Hackers Accelerate Cyberattacks Using Low-Cost AI Tools: Research
Tags: ai, china, cyber, cyberattack, cybersecurity, group, hacker, intelligence, network, open-source, toolState-affiliated Chinese hackers are dramatically scaling up foreign cyberattacks by integrating open-source artificial intelligence (AI) models into their operations, according to new research from cybersecurity firms TeamT5 and Palo Alto Networks Inc.’s Unit 42. By offloading mundane tasks and automated target-mapping to cheap, accessible AI tools, state-backed cyber groups have more than doubled their attack..…
-
MDR May Be Splitting Into Three Managed Services
I have argued for a while that MDR has to move beyond alert triage and become a cyber risk reduction service. A recent conversation with an experienced MDR operator added another piece to that thesis. The future may not be one ever-expanding MDR bundle. We may be forcing three different jobs into one category: The……
-
Is Cyber Facing an Affordability Crisis?
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/is-cyber-facing-an-affordability-crisis-
-
AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands
ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into proposed operational actions. The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 model output to controller-side functions including local shell execution, file writes, remote SSH commands, persistent state changes, and cross-compilation. Analysis published by Joe Reverser…
-
Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records
A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities in Asia, stealing thousands of personnel records, cracking employee credentials, and establishing persistent access to state infrastructure, according to Dream Research Labs. Researchers discovered a 160 MB operational archive containing 1,395 files generated over about 4 days of activity, from…
-
Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud
A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products, disclosing personal and banking information, and granting remote access to their computers. The sites, branded as SysScan, claim to assess whether an antivirus product is functioning properly. Their conclusion is predetermined: the victim’s computer is allegedly…
-
Multiple Zscaler Client Connector Flaws Enable Remote Code Execution
Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to execute arbitrary code within the product’s context. This vulnerability, tracked as CVE-2026-59568, is rated as Critical, with a CVSS v3.1 score of 9.1. The attack vector is network-accessible and requires no privileges or user interaction. Multiple…
-
91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply chain remediation event that Sonatype estimates impacts 209,569 software components. The advisory issued on August 20 highlights the widening gap between AI-accelerated vulnerability discovery and organizations’ ability to identify, fix, rebuild, and deploy affected software.…
-
91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply chain remediation event that Sonatype estimates impacts 209,569 software components. The advisory issued on August 20 highlights the widening gap between AI-accelerated vulnerability discovery and organizations’ ability to identify, fix, rebuild, and deploy affected software.…
-
PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2
PavinLoader, a multi-stage .NET malware loader, operating across ClickFix, fake software-download, and malicious game campaigns. The activity shows how attackers are moving beyond a single delivery vector. A victim may be lured to a fake Cloudflare or Google verification page and instructed to paste a command, persuaded to install apparently legitimate software, or tricked into…
-
Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls
Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP) security capabilities with enterprise-managed authorization, allowing organizations to centrally provision and govern connector access through their identity provider (IdP). The feature, now generally available, removes the need for individual users to authorize each MCP connector after an administrator enables it. Instead, administrators can authorize a connector…
-
Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to forge SAML assertions and log in as any existing user, including site administrators. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8. Research conducted by DigitalOcean’s security team and later…
-
US Sanctions Mabna Institute Hackers for Iranian Cyber-Attacks
The US has sanctioned individuals connected to hacking-for-hire group the Mabna Institute First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/us-sanctions-mabna-institute/
-
Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls
Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP) security capabilities with enterprise-managed authorization, allowing organizations to centrally provision and govern connector access through their identity provider (IdP). The feature, now generally available, removes the need for individual users to authorize each MCP connector after an administrator enables it. Instead, administrators can authorize a connector…
-
Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in the password reset process and seize control of arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the keycloak-services component, the core identity and access management engine behind the…
-
Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users
Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into manually executing malware through Terminal. The operation begins when users search for Codex-related terms, including “codex macos download.” Instead of selecting OpenAI’s legitimate listing, victims may encounter a sponsored result that…
-
EvilTokens Abuses Microsoft Device Codes to Hijack Accounts Without Stealing Passwords
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize an attacker-controlled session. The PhaaS operation was advertised on Telegram from mid-February 2026 and was later documented by Sekoia researchers as a turnkey…
-
TP-Link Archer Command Injection Flaws Enable Root-Level Code Execution
TP-Link has released firmware updates for three Archer router models due to the discovery of multiple command injection vulnerabilities. These vulnerabilities could enable attackers to execute arbitrary operating system commands with root privileges. The security advisory, updated on August 24, 2026, pertains to the Archer BE800 V1, Archer BE3600 V1, and Archer AX75 V1 devices.…
-
WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 Disruption
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods despite the campaign’s original command-and-control infrastructure being disrupted. The researchers found multiple active websites impersonating popular Minecraft projects, offering paid clients at no cost, and abusing well-known hosting platforms to make malicious downloads appear trustworthy.…
-
WeedHack Malware Spreads Through SEO-Poisoned Minecraft Sites Despite C2 Disruption
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods despite the campaign’s original command-and-control infrastructure being disrupted. The researchers found multiple active websites impersonating popular Minecraft projects, offering paid clients at no cost, and abusing well-known hosting platforms to make malicious downloads appear trustworthy.…
-
Fake GTA 6 Demo Sites Spread Vidar Stealer to Hijack Authenticated Browser Sessions
Cybercriminals are capitalizing on renewed interest in Grand Theft Auto VI by pushing fake Rockstar Games pages that advertise a non-existent GTA 6 demo but instead deliver the Vidar information stealer. The campaign targets browser credentials, session cookies, and other profile data that can let attackers access accounts even after victims change their passwords. The…
-
NIS2 macht Cyber-Resilienz zur Vorstandspflicht – Abwarten wird bei NIS2 zum Haftungsrisiko
First seen on security-insider.de Jump to article: www.security-insider.de/nis2-umsetzung-haftungsrisiko-management-a-50acd4ecb8cb7d2cf089f5a2c8aad888/
-
5 Palo Alto GlobalProtect Flaws Let Attackers Gain SYSTEM/Root Access and Steal AD Passwords
Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities affecting Palo Alto Networks’ GlobalProtect, an enterprise VPN and endpoint agent widely used across corporate environments on Windows, macOS, and Linux. The issues include local privilege escalation vulnerabilities that could allow a low-privileged attacker with access to an endpoint to gain full SYSTEM privileges on Windows…
-
Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data
Tags: access, cisa, cve, cyber, cybersecurity, data, exploit, flaw, hacker, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-21962, affects both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA classified this issue as…
-
Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data
Tags: access, cisa, cve, cyber, cybersecurity, data, exploit, flaw, hacker, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-21962, affects both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA classified this issue as…
-
US sanctions Iranian cyber actors as UK discloses power plant attack
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom. First seen on therecord.media Jump to article: therecord.media/iran-cyberattacks-us-uk
-
Russian Backdoor Found in Slovak Traffic Cameras
SMS Messages Could Enable Remote Access to Live Traffic Feeds. Slovakian cyber authorities have suspended the rollout of high-speed traffic cameras after a security investigation uncovered backdoors and multiple software weaknesses. The devices were reportedly rebranded versions of Russian-made cameras sold through a Cyprus-based company. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/russian-backdoor-found-in-slovak-traffic-cameras-a-32645
-
How ‘Subtractive’ Security Erases Attack Paths
Chris Frenz, Rectangle Health CISO, on Reducing Risk From Attackers in Healthcare. Healthcare security teams can reduce cyber risk by removing attacker options before an incident occurs rather than relying primarily on detection and response, said Chris Frenz, CISO at Rectangle Health, describing a new subtractive-hardening architecture standard he developed for OWSAP. First seen on…

