Tag: cyber
-
Researchers Find 543,699 Active Credentials Leaked in Public GitHub Repos
Security researchers have identified 543,699 unique credentials that remain valid despite being exposed in public GitHub repositories. This highlights a persistent failure to revoke secrets once they enter source code. These credentials were verified as active in July 2026, even though many had been publicly accessible for years. Researchers at Truffle Security examined The Stack…
-
SC WordPress Malware Rebuilds Itself After Removal Using Database and Memory Persistence
A newly analyzed WordPress malware family, tracked as SC for the “SC_” markers embedded in its injected code, uses a self-healing persistence mesh that can restore a deleted backdoor within seconds. Researchers found that SC does not rely on a single web shell or plugin. Instead, the malware creates at least eight interdependent persistence points,…
-
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program.”It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense,” Koray Kavukcuoglu, First…
-
HPE Instant On AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
HPE has released security updates for its Networking Instant On access points after identifying 18 vulnerabilities, including several critical flaws that could allow unauthenticated attackers to execute arbitrary code or commands with privileged operating-system access. These vulnerabilities are detailed in advisory HPESBNW05150 rev. 1 and affect Instant On AP software versions 3.4.1.0 and earlier. HPE…
-
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions. Not all of the newly published advisories currently have CVE identifiers; the project has indicated that CVE requests have been submitted via GitHub but remain unassigned for several issues. The recently…
-
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions. Not all of the newly published advisories currently have CVE identifiers; the project has indicated that CVE requests have been submitted via GitHub but remain unassigned for several issues. The recently…
-
Multiple ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules and Execute Malicious Requests
OWASP ModSecurity has disclosed multiple vulnerabilities that could let attackers bypass web application firewall rules, evade request and response inspection, or trigger denial-of-service conditions. Not all of the newly published advisories currently have CVE identifiers; the project has indicated that CVE requests have been submitted via GitHub but remain unassigned for several issues. The recently…
-
Critical Cisco SD-WAN Vulnerability Lets Remote Attackers Bypass Authentication as Admin
Cisco has disclosed a critical authentication bypass vulnerability in the Catalyst SD-WAN Manager, which could allow unauthenticated remote attackers to access the management API with administrator privileges. This vulnerability, tracked as CVE-2026-76504, has a CVSS v3.1 score of 9.8 and affects the Cisco Catalyst SD-WAN Manager regardless of its configuration. On September 30, 2026, Cisco…
-
Hackers Hide Microsoft Defender Exclusions From Admins to Evade Antivirus Scans
Threat actors are increasingly abusing Microsoft Defender Antivirus exclusions to keep malicious files outside the reach of endpoint scans, and a little-known policy setting can conceal those exclusions from administrators using normal management tools. Huntress researchers found that attackers can combine broad Defender exclusions with the HideExclusionsFromLocalAdmins setting, creating a stealthy defense-evasion path that leaves…
-
Zimbra Vulnerability Exploited to Gain Root Access and Steal Mailbox Authentication Secrets
An active exploitation of CVE-2026-73570, a high-severity unauthenticated OS command-injection vulnerability in Zimbra Collaboration Suite. Attackers used to obtain root access, establish persistent control, and collect mailbox authentication secrets. The issue resides in Zimbra’s SNMP notification processing path. An attacker can send a specially crafted SMTP request containing shell metacharacters, allowing attacker-controlled input to reach…
-
AI Agents Expose 13,000+ Developer Screenshots Across 900+ GitHub Repositories
AI coding agents have inadvertently exposed over 13,000 internal developer screenshots in public GitHub repositories. These exposures potentially revealed sensitive information such as customer records, credentials, financial interfaces, and unreleased product features. The issue, referred to as >>PixelLeak<< by Glow Labs, affected developers across more than 300 organizations and spanned over 900 repositories. AI Agents…
-
AI Agents Expose 13,000+ Developer Screenshots Across 900+ GitHub Repositories
AI coding agents have inadvertently exposed over 13,000 internal developer screenshots in public GitHub repositories. These exposures potentially revealed sensitive information such as customer records, credentials, financial interfaces, and unreleased product features. The issue, referred to as >>PixelLeak<< by Glow Labs, affected developers across more than 300 organizations and spanned over 900 repositories. AI Agents…
-
New 2CLoader Malware Uses Anti-VM and API Hooking to Deliver Vidar and Remus Stealers
A new Windows malware loader, tracked as 2CLoader, that combines extensive anti-analysis logic, indirect system calls, API tampering, and flexible in-memory execution to deliver Vidar and Remus information stealers. Researchers also observed the loader distributing XWorm RAT, indicating that its operators can use the framework to deploy multiple payload families. Its layered design makes it…
-
New 2CLoader Malware Uses Anti-VM and API Hooking to Deliver Vidar and Remus Stealers
A new Windows malware loader, tracked as 2CLoader, that combines extensive anti-analysis logic, indirect system calls, API tampering, and flexible in-memory execution to deliver Vidar and Remus information stealers. Researchers also observed the loader distributing XWorm RAT, indicating that its operators can use the framework to deploy multiple payload families. Its layered design makes it…
-
Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative
Washignton, DC, USA, September 30th, 2026, CyberNewswire The Internet Society today launched the Online Trust and Safety Hub, a free global resource center in multiple languages, offering practical tools to help people stay safer and more confident online. The Hub is a key part of the Internet Society’s Safer Internet Initiative, which works to equip…
-
FBI’s Operation Blackout Takes Down Overseas Scammers Targeting Americans
The FBI has intensified its global effort to crack down on large-scale scam operations targeting Americans. Director Kash Patel announced that Operation Blackout has seized approximately $17 billion linked to transnational fraud networks. In a post on X, Patel stated that the operation has resulted in hundreds of arrests, the rescue of thousands of trafficked…
-
Google says Gemini 4 Argon can find and patch critical software flaws
Google announced Gemini 4 Argon, its new frontier AI model, and is rolling it out to a set of trusted cyber defenders through its Fairwind Program. Google says the model can … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/01/google-gemini-4-argon/
-
After reports on suicide deaths, Pentagon puts Cyber Command on notice
Tags: cyberAn August 31 memo obtained by Recorded Future News shows that the Pentagon’s assistant secretary for cyber policy made specific demands of U.S. Cyber Command leadership after reports of a cluster of suicide deaths. First seen on therecord.media Jump to article: therecord.media/cyber-command-suicide-deaths-pentagon-memo
-
Accenture Cyber Exec: Industry Is Moving Beyond ‘WhackMole’ Patching Amid AI-Driven Vulnerability Surge
Many businesses are moving beyond an initial focus on faster patching in response to surging vulnerability discovery by frontier AI models, and are increasingly rethinking how to identify and reduce security exposures in a broader way, Accenture’s Jason Lewkowicz tells CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/accenture-cyber-exec-industry-is-moving-beyond-whack-a-mole-patching-amid-ai-driven-vulnerability-surge
-
National cyber director defends private-sector hacking program, urges focus on security basics
Letting businesses help the government deter cybercrime will benefit all Americans, Sean Cairncross said. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/oncd-white-house-sean-cairncross-regulation-deterrence-ai/831768/
-
RedFlick Uses Scheduled Tasks and Password-Protected Archives to Deploy CosmicPulse Backdoor
Russian state-linked threat actor Star Blizzard has expanded its cyberespionage operations in 2026 with a phishing and malware-delivery technique tracked by Microsoft as RedFlick. Microsoft Threat Intelligence reported that the group, which CISA attributes to Russia’s Federal Security Service (FSB) Center 18, conducted at least 13 phishing campaigns between January and August 2026. The activity…
-
CyberASAP Celebrates 10th Anniversary with Special Event Exploring Future of UK Cyber Security Innovation
In 2026, the Cyber Security Academic Startup Accelerator Programme (CyberASAP), which is funded by the UK Government’s Department for Digital, Culture, Media and Sport (DCMS) and delivered by Innovate UK, celebrates its 10th anniversary. Over the past decade, the programme has bridged the gap between academia and industry, accelerating the commercialisation of cutting-edge cyber technologies…
-
Docker CopyEscape CVE-2026-17106 Lets Malicious Containers Overwrite Host Files
A critical Docker vulnerability tracked as CVE-2026-17106, also known as CopyEscape, could allow a malicious container to overwrite files on the host machine when a user runs the `docker cp` command. This vulnerability affects copy-out operations, where Docker retrieves data from a container and extracts it onto the system running the Docker Command Line Interface…
-
PaperPhone Cluster Shows How One Bot Operator Can Look Like Thousands of Mobile Users
A large-scale scraping cluster dubbed PaperPhone, exposing how one operator can manufacture the appearance of tens of thousands of legitimate mobile users across dozens of countries. The operation used roughly 75,000 IP addresses across 230 address blocks in 43 countries. However, browser-fingerprinting and network-analysis signals pointed to a centrally coordinated infrastructure rather than a genuinely…
-
Cyber security without humans? The rise of agentic AI
The next evolution of cyber security may be autonomous, but industry leaders warn that trust, governance and human judgement can’t be automated First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651209/Cyber-security-without-humans-The-rise-of-agentic-AI
-
Sweden boosts cyber threat security defences amid AI advances
Sweden is strengthening its national security defences against cyber attacks First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651435/Sweden-boosts-cyber-threat-security-defences-amid-AI-advances
-
Claude Compliance API Lets Security Teams Monitor Chats, Files and Agent Activity
Anthropic has enhanced enterprise security visibility for its AI assistant, Claude, with the Compliance API. This feature lets organizations extract data on activity, conversations, files, projects, and agent sessions into their existing governance and security operations platforms. The Compliance API is available to both Claude Enterprise and Claude Platform customers, although the breadth of accessible…
-
Critical MikroTik RouterOS Vulnerability Exposes Devices to Remote Code Execution
Tags: cve, cvss, cyber, cybersecurity, infrastructure, remote-code-execution, service, vulnerabilityA critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute code on vulnerable devices or trigger a denial-of-service condition. This vulnerability, tracked as CVE-2026-84411, affects MikroTik RouterOS versions earlier than 7.24 and carries a CVSS v3 severity score of 9.8. The Cybersecurity and Infrastructure Security Agency (CISA) disclosed this issue on September…
-
Attackers Target Developer Credentials to Expand Supply Chain Intrusions Beyond Source Code
Software supply chain attacks are increasingly evolving into cloud identity breaches, as attackers weaponize trusted packages to steal credentials from developer workstations and CI/CD environments before an application is ever executed. The result is a dangerous pivot: a routine dependency installation can give threat actors access to cloud accounts, source-code repositories, container platforms, secrets-management systems,…
-
12 Best IGA Tools in 2026: The Ranked Buyer’s Guide
Identity governance and administration has become essential as organizations manage employees, contractors, service accounts, machine identities, and AI agents across increasingly complex environments. The best IGA tools help security teams answer three critical questions: Who has access? Why do they have it? Should they continue to have it? Modern IGA platforms go beyond periodic access…

