Tag: cyber
-
How ‘Subtractive’ Security Erases Attack Paths
Chris Frenz, Rectangle Health CISO, on Reducing Risk From Attackers in Healthcare. Healthcare security teams can reduce cyber risk by removing attacker options before an incident occurs rather than relying primarily on detection and response, said Chris Frenz, CISO at Rectangle Health, describing a new subtractive-hardening architecture standard he developed for OWSAP. First seen on…
-
Bipartisan Senate bill aims to prepare energy sector for Q-Day
Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector. First seen on cyberscoop.com Jump to article: cyberscoop.com/quantum-guard-act-electric-grid-cybersecurity/
-
German Cyber Agency Warns Fingerprints Can Be Spoofed
BSI Says AI, High-Resolution Photos and 3D Printing Increase Biometric Risks. Germany’s cybersecurity agency is warning against relying solely on fingerprint authentication, saying criminals can use high-resolution photos, AI and 3D printing to create synthetic fingerprints capable of spoofing some biometric systems. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/german-cyber-agency-warns-fingerprints-be-spoofed-a-32643
-
UK power plant shutdown highlights CNI cyber challenges
An alleged Iranian attack on a small reserve ‘peaker’ power plant went largely unnoticed despite causing four days of downtime. Cyber experts say the incident raises serious questions about CNI resilience. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649386/UK-power-plant-shutdown-highlights-CNI-cyber-challenges
-
What the latest UAE cyber attacks reveal about threats to critical sectors
ThreatLocker CEO Danny Jenkins explains why aviation, energy and education organisations remain attractive targets, and why prevention should take precedence over detection First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649634/What-the-latest-UAE-cyber-attacks-reveal-about-threats-to-critical-sectors
-
NIST Warns of Unique Security Risks in Multi-Cloud Environments
NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nist-risks-multi-cloud/
-
North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access
Tags: access, cyber, email, hacker, korea, malicious, north-korea, phishing, powershell, software, spear-phishing, theft, windowsNorth Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk, giving attackers persistent, interactive remote access while blending into legitimate software activity. The operation combines OneDrive-hosted lures, malicious Windows shortcut files, scheduled-task persistence, PowerShell payloads, and email theft across Thunderbird, Outlook, and Gmail. The archives…
-
Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages
Threat actors are increasingly using Google and Bing as phishing delivery channels, employing a cloaking technique that presents harmless pages to security scanners while serving credential-harvesting banking portals to genuine search users. The campaigns target users of major financial institutions and combine search-engine optimization abuse, recently registered lookalike domains, and referral-aware payload delivery to extend…
-
Mysterious Ox Alpha Stealth AI Model Emerges for Coding and Agentic Work
A newly discovered AI system called Ox Alpha has emerged on OpenRouter, sparking widespread speculation within the AI community regarding its origin, technical capabilities, and potential connections to major Chinese or Western model developers. Released on Thursday as a free preview model, Ox Alpha is described on OpenRouter as “a reasoning model designed for coding,…
-
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent.The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate…
-
Zimbra Collaboration Suite Flaw Actively Exploited to Execute Arbitrary Commands
Threat actors are actively exploiting a critical operating system command injection vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570. This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands with the privileges of the zimbra user. Zimbra Collaboration Suite Flaw The flaw specifically affects Zimbra deployments where the SNMP trap notification service is enabled…
-
Zimbra Collaboration Suite Flaw Actively Exploited to Execute Arbitrary Commands
Threat actors are actively exploiting a critical operating system command injection vulnerability in Zimbra Collaboration Suite, identified as CVE-2026-73570. This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands with the privileges of the zimbra user. Zimbra Collaboration Suite Flaw The flaw specifically affects Zimbra deployments where the SNMP trap notification service is enabled…
-
Open VSX Unblocks 3 IDs Used in 77-Extension Evil-Twin Malware Campaign
Open VSX has removed three extension identifiers from its malicious-extension list after the legitimate projects they impersonated began reclaiming their names. The move restores publishing access for the affected maintainers but highlights a supply-chain tracking gap: a single extension ID can represent both a removed malicious artifact and a later legitimate release. Between August 16…
-
Slovakia Warns of Cyber Risks in Road Speed Cameras
Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about…
-
Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant
Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cni-iranian-attack-shuts-uk-power/
-
Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant
Experts argue Iranian cyber-attack on UK power plant lays bare frailty of critical national infrastructure First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cni-iranian-attack-shuts-uk-power/
-
New SynkLoader Malware Uses Fake Windows Lock Screen to Steal Passwords and Pivot Networks
SynkLoader, a newly identified modular malware framework that combines Python, C#, C++, PowerShell, and memory-resident payloads to evade endpoint detection. Delivered through Microsoft Teams phishing, the operation uses a convincing fake Windows lock screen to capture credentials before enabling network tunneling and interactive access to compromised enterprise environments. Compile timestamps and file metadata indicate the…
-
Critical WordPress Pods Flaw Lets Unauthenticated Attackers Gain Admin Access
A critical vulnerability has been identified in the widely used Pods WordPress plugin, which could allow unauthenticated attackers to take complete control of affected websites by escalating privileges to the administrator level. This vulnerability, tracked as CVE-2026-19598, carries a CVSS score of 9.8 and affects Pods Custom Content Types and Fields versions up to […]…
-
Windows 11 Update Triggers Game Crashes on Systems With RGB Lighting Drivers
Microsoft is currently investigating a compatibility issue with Windows 11, in which certain games crash, freeze, or cause unexpected system restarts on devices equipped with RGB lighting hardware and related low-level drivers. This problem was reported following the release of Windows updates on August 11, 2026, including the KB5121003 update for OS Build 26100.9168. Microsoft…
-
AWS Network Firewall Adds Rule Hit Counts to Identify Unused Security Rules
AWS has introduced a new capability for AWS Network Firewall that tracks rule hit counts, providing security teams with direct visibility into how often individual stateful firewall rules match live network traffic. This feature aims to minimize reliance on manual log reviews. It helps organizations identify dormant, misordered, or ineffective rules across both custom and…
-
First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet
A multi-stage Android malware campaign that abuses the firmware-update mechanism of Android-based automotive head units to deploy ad-fraud tooling and enroll vehicles into a residential proxy botnet. The activity, discovered in June 2026, is the first documented malware infection chain purpose-built for automotive head units and has been attributed with high confidence to the MoYu…
-
Critical isolated-vm Flaw Lets Attackers Escape Sandbox and Hijack Host Control Flow
A critical vulnerability has been discovered in the widely used Node.js sandboxing library, isolated-vm. This flaw could potentially allow untrusted JavaScript to escape its V8 isolate and hijack control flow in the host process. The issue is tracked as GHSA-864f-rcv7-6rh4 and is awaiting CVE assignment. It affects isolated-vm versions before 7.0.1 and 6.2.0. Researchers have…
-
RedC2 Turns Compromised Linux Machines Into SOCKS5 Proxies for Internal Network Pivoting
A cluster of trojanized npm packages is delivering the RedC2 4.0 Linux implant, providing operators with a pathway from a seemingly harmless dependency import to internal network pivoting via SOCKS5 proxies and TCP forwarding. The campaign disguises malicious code inside functional calendar and streak-calculation utilities, underscoring how supply-chain abuse can bypass controls focused only on…
-
Iran-Linked Hackers Shut Down UK Power Plant for Four Days in Cyberattack
A cyberattack linked to Iranian threat actors forced a British power plant offline for four consecutive days in July, reportedly marking the first successful cyber incident to disrupt a UK energy-generation facility completely. This incident, first reported by The Telegraph, affected a small-scale electricity generator rather than a major power station. The UK government emphasized…
-
Anthropic Brings Claude Mythos 5 to Cyber Defenders for Vulnerability Scanning and Patching
Anthropic has enhanced its AI-driven cyber defense offerings by integrating Claude Mythos 5 into Claude Security. This new feature enables enterprise customers to scan their own codebases for security vulnerabilities and receive suggested remediation patches. This rollout, announced on August 21, 2026, introduces the company’s most advanced cyber model into a structured workflow that delivers…
-
Cybersecurity Newsletter Bulletin Top 50 Biggest Cybersecurity Stories of the Week Shell Azure Mega-Breaches, Salt Typhoon Evicted, Entra ID RCE, Chinese vCenter ESXi Ransomware More
Tags: breach, china, cisa, credentials, cyber, cybersecurity, exploit, flaw, mobile, ransomware, rce, remote-code-execution, theft, vcenterWelcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 1721, 2026. Breaches and exploited flaws dominated: Cl0p claimed 89GB from Shell, a mass Azure credential-theft campaign hit McDonald’s and Vodafone, and T-Mobile physically cut a cable to evict Salt Typhoon. CISA […]…
-
Army seeks AI agents for cyber defense amid evolving threats
First seen on scworld.com Jump to article: www.scworld.com/brief/army-seeks-ai-agents-for-cyber-defense-amid-evolving-threats

