Tag: cyber
-
Head Mare APT Exploits TrueConf Server RCE Flaws to Deliver PhantomCore Malware
Tags: access, apt, attack, conference, cyber, exploit, flaw, group, kaspersky, malware, rce, remote-code-execution, russia, supply-chainThe Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore malware to video conference participants. Kaspersky researchers identified this activity while investigating attacks against Russian organizations. Attackers hosted legitimate-looking TrueConf client installers on compromised servers that silently deployed the remote-access malware…
-
Google Chrome 151 Update Fixes 7 Security Flaws Enabling Remote Code Execution and Sandbox Escape
Google has released Chrome version 151 to the Stable channel for desktop platforms, addressing seven security vulnerabilities. Among these vulnerabilities is a critical use-after-free flaw, along with several high-severity issues affecting various components of the browser, including V8, DOM, Workers, networking, and Linux toolkit theming. The update is being rolled out as version 151.0.7922.173/.174 for…
-
Russia-Linked Hackers Exploit Legitimate Login Flows to Bypass 2FA and Steal Account Access
Tags: 2fa, access, authentication, credentials, cyber, defense, espionage, exploit, government, hacker, login, password, russiaThree suspected Russian cyber espionage clusters abusing legitimate authentication mechanisms to hijack accounts belonging to academics, diplomats, defense personnel, government staff, and think-tank researchers across Europe and the United States. Rather than relying solely on credential-harvesting pages, the operators manipulate users into completing genuine app-password, OAuth, device-code, and device-linking workflows that can hand attackers authenticated…
-
Peer2Profit Turns Employee Devices Into AstroProxy Nodes That Can Expose Internal Networks
Residential proxy networks have become a key enabler for fraud, credential stuffing, account takeover, spam, and large-scale automated abuse. New research shows that PEER2PROFIT, a bandwidth-sharing application, can turn employee or personal devices into commercial proxy exit nodes that are then monetized through ASTROPROXY potentially exposing corporate IP space and internally reachable resources. The relationship…
-
Backup, Recovery, Cyber-Resilienz und Storage-Optimierung – Pink Elephant stärkt neue TDN-Einheit ‘Data Resilience Services”
First seen on security-insider.de Jump to article: www.security-insider.de/pink-elephant-staerkt-neue-tdn-einheit-data-resilience-services-a-0a50766c05258d5246c7a2bacc0ab1ab/
-
Compromised Rust Crate With 18,000+ Downloads Steals Source Code During Builds
A malicious update to the Rust crate called onering has been discovered, which exfiltrates source code changes from developers’ machines during the build process. Security researchers identified this behavior in version 1.4.1 of the package on June 10, 2026. The onering crate, designed as a high-throughput synchronous queue and channels library, has garnered over 18,000…
-
Windows Defender Driver Abuse Enables Kernel-Level EDR and Antivirus Bypass
Security researcher Jiřà Vinopal has published a detailed analysis of BTR.sys, the Microsoft Defender Boot-Time Removal driver. His research reveals how this legitimate, Microsoft-signed component can be exploited to perform file and registry operations under attacker control from kernel mode. This study, titled >>BTR Reforged,<< does not rely on traditional memory-corruption vulnerabilities or the Bring…
-
Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials
Threat actors are exploiting interest in generative AI software to distribute the Vidar information stealer through a fake Google Gemini installer hosted via Google Colab. Darktrace investigated the July 2026 intrusion in an EMEA customer environment, where a user downloaded and executed a malicious file named Download_Google_Gemini_For_Windows.exe The campaign did not rely on a conventional…
-
New Manic Android Malware Targets 169 Apps, Steals PINs and Exfiltrates Data via Wi-Fi Mesh
A newly discovered Android malware family called Manic, which combines banking fraud functions with advanced spyware and remote device control capabilities. The operation’s active infrastructure dates back to February 2026, with early wrappers and implants emerging in late May. Manic has rapidly evolved through July, incorporating stronger anti-analysis protections, in-memory DEX loading, lock-screen phishing, and…
-
SilkParasite Uses Google Drive as C2 to Hide RAT Traffic Inside Trusted Cloud Services
SilkParasite, a long-running cyberespionage operation targeting government bodies across Central Asia through a compact but highly mature arsenal of remote access trojans. Assessed with medium confidence as China-nexus activity, the campaign stands out for using Google Drive as a command-and-control channel, allowing malware traffic to blend into cloud activity that many enterprises inherently trust. The…
-
Anxiety over war, wildfires and cyber-attacks leads to growth in cash stocks in EU
Value of banknotes in circulation rises from Euro1bn in 2016 to Euro1.6bn in 2026 as people advised to keep stash of cashThe number of banknotes in circulation in the EU is increasing despite widespread smartphone payments, new data shows, with wildfires ripping through parts of Europe fuelling demand for an emergency stash of cash.While cash…
-
Army establishes new task force to explore AI in cyber command
First seen on scworld.com Jump to article: www.scworld.com/brief/army-establishes-new-task-force-to-explore-ai-in-cyber-command
-
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S.These clusters include UNC6293, UNC7005, and UNC5976.”These clusters engage in persistent, adaptive First seen on…
-
Calling on Cyber Pros to Help Defend City Hall
Government agencies with smaller budgets need support, and here’s how you can help. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/calling-on-cyber-pros-to-help-city-hall
-
Is Cyber missing the Marque?
In this week’s newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/is-cyber-missing-the-marque/
-
Money and Mindset: The Two Biggest Roadblocks to Cyber Policing
Law enforcement training is not keeping pace with the volume and rapid evolution of cybercrimes, though officers really only need to learn the basics, but focus and budgets hinder progress. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/money-and-mindset-the-two-biggest-roadblocks-to-cyber-policing
-
Hackers Actively Target Siemens PLCs With AI Cyberattacks
‘We Are Crossing a Threshold’ Warns Critical Infrastructure Security Expert. An artificial intelligence-assisted cyberattack campaign is targeting widely used online operational technology devices made by Siemens, the U.S. cyber defense agency warned Wednesday – the first time it’s called out an AI-assisted cyber campaign against OT. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hackers-actively-target-siemens-plcs-ai-cyberattacks-a-32616
-
MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data
MacSync Stealer is expanding its macOS-focused theft operation through a rotating network of more than 30 domains, using stable execution and network patterns to steal credentials, browser data, cloud access keys, SSH material, and sensitive user files. Earlier research by RST Cloud identified MacSync infrastructure and observed command-and-control replacement after public disclosure. Microsoft’s subsequent telemetry-led…
-
New Zombie Card Attack Lets Expired Visa Cards Make Contactless Payments
Security researchers have demonstrated a “Zombie Card” attack that can reactivate certain expired Visa contactless cards, allowing them to be used for NFC payments. This attack exploits a vulnerability in Visa’s EMV Kernel 3 regarding the handling of card expiry data. An attacker, positioned between the card and the payment terminal, can modify the expiry…
-
New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts
Security researchers Tom Stacey from PortSwigger and Tobia Righi from TurtleSec have introduced a new category of HTTP request smuggling attacks known as >>CRLF-Powered Desync Attacks.<< This method exploits a frequently overlooked HTTP header injection vulnerability, which can lead to full account takeovers, theft of HTTPOnly cookies, and even the creation of self-propagating desync worms.…
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
Cisco BroadWorks Vulnerability Allows Remote Attackers to Access Sensitive Files
Cisco has issued security updates for a high-severity vulnerability in Cisco BroadWorks that could allow unauthenticated remote attackers to access sensitive configuration files on affected systems. This vulnerability is tracked as CVE-2026-20320 and is characterized as an out-of-band blind XML External Entity (XXE) injection vulnerability in the Open Client Interface (OCI) XML Parser. Cisco assigned…
-
OpenAI Slows AI Model Development as Astra Approaches Critical Cyber Capabilities
OpenAI has temporarily slowed the development of its latest frontier AI models after initial testing suggested that its upcoming Astra system may meet the company’s >>Critical<< cybersecurity capability threshold. This decision follows a recent security incident involving OpenAI and Hugging Face. It reflects growing concerns that advanced models could significantly increase the risks of cyber…
-
Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security
Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact infection chain that begins with a victim manually executing a malicious PowerShell command. In late July 2026, multiple ClickFix campaigns generated through the ErrTraffic malware-as-a-service platform and used to deliver Cruciferra, a loader advertised…
-
Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Multicluster Engine for Kubernetes. This flaw has a CVSS v3.1 score of 9.3. It could allow an unauthenticated remote attacker to use a publicly accessible route to access otherwise isolated services across managed clusters. Published on August…
-
Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE
Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code execution (RCE) flaw in the Splunk MCP Server app. The vulnerabilities encompass deserialization, access control, server-side request forgery (SSRF), denial-of-service, certificate validation, and information disclosure. Tracked as SVD-2026-0808 and published on August 19, 2026, the…
-
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View…
-
Geopolitical DDoS Attacks: What Cybersecurity Teams Need to Know
Geopolitical tensions are increasingly spilling into the cyber domain, with DDoS attacks becoming a common form of retaliatory hacktivism. Unlike financially motivated attacks, these campaigns can be triggered by events such as military escalation, elections, sanctions, or other geopolitical developments”, and can begin within hours. For security teams, the challenge is not only understanding who…

