Tag: cyber
-
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View…
-
Geopolitical DDoS Attacks: What Cybersecurity Teams Need to Know
Geopolitical tensions are increasingly spilling into the cyber domain, with DDoS attacks becoming a common form of retaliatory hacktivism. Unlike financially motivated attacks, these campaigns can be triggered by events such as military escalation, elections, sanctions, or other geopolitical developments”, and can begin within hours. For security teams, the challenge is not only understanding who…
-
US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign
The US charged 17 Iranians over a years-long hacking campaign that stole 31TB from universities, companies and government agencies worldwide. Eight years after the original indictment first went public, US prosecutors just added eight more names to the list. The Justice Department unsealed a superseding indictment this week charging 17 members of the Mabna Institute,…
-
CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access
Tags: access, ai, attack, authentication, cve, cyber, data-breach, flaw, Internet, jobs, rce, remote-code-execution, vulnerabilityResearchers have revealed a pre-authentication remote code execution (RCE) vulnerability chain in CyberPanel that could allow an internet-based attacker to execute commands on vulnerable servers without any credentials. This attack combines exposed AI Scanner interfaces, an authentication flaw tracked as CVE-2026-41473, stored cross-site scripting (XSS) tracked as CVE-2026-41472, and CyberPanel’s built-in cron-job functionality. CyberPanel is…
-
CyberPanel Pre-Auth RCE Flaws Let Attackers Gain Remote Server Access
Tags: access, ai, attack, authentication, cve, cyber, data-breach, flaw, Internet, jobs, rce, remote-code-execution, vulnerabilityResearchers have revealed a pre-authentication remote code execution (RCE) vulnerability chain in CyberPanel that could allow an internet-based attacker to execute commands on vulnerable servers without any credentials. This attack combines exposed AI Scanner interfaces, an authentication flaw tracked as CVE-2026-41473, stored cross-site scripting (XSS) tracked as CVE-2026-41472, and CyberPanel’s built-in cron-job functionality. CyberPanel is…
-
Claude AI Finds Authentication Bypass Flaws in Multiple SAML Implementations
Multiple critical vulnerabilities in SAML implementations after employing Anthropic’s Claude Code in an AI-assisted vulnerability research pipeline. Security researcher Eric Chiang, the CTO of Oblique Security, investigation uncovered full authentication bypasses, signature-validation flaws, information disclosure risks, arbitrary logout issues, and denial-of-service conditions across several open-source SAML products. Claude AI Finds Authentication Bypass Flaws Chiang’s research…
-
Hackers Trick AI Agents Into Telling Users to Install the Malware Themselves
A supply-chain campaign targeting OpenClaw has shown how threat actors can turn autonomous AI agents into persuasive malware-delivery intermediaries. Rather than relying only on exploit code, attackers poisoned the ClawHub skill registry with seemingly legitimate extensions whose instructions prompted users to install fake prerequisite tools or paste obfuscated commands into a terminal. The campaign, tracked…
-
AI-Driven Vulnerability Exploitation Is Now Fast and Cheap
AI is making vulnerability exploitation faster and cheaper, forcing defenders to rethink vulnerability management, continuous exposure detection and agentic cyber defense. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/ai-driven-vulnerability-exploitation-is-now-fast-and-cheap/
-
Zimbra RCE Vulnerability Lets Remote Attackers Execute System Commands
An urgent alert regarding an actively exploited remote code execution vulnerability affecting the Zimbra Collaboration Suite, a widely used enterprise email and collaboration platform. This vulnerability, tracked as CVE-2026-73570, is an unauthenticated OS command injection issue that allows attackers to execute arbitrary shell commands as the zimbra user. Zimbra RCE Vulnerability The flaw affects Zimbra…
-
Microsoft Defender Update Crashes Virus Scans on Windows PCs
Microsoft Defender has been aborting Quick, Full, and Offline virus scans on Windows systems following a series of Security Intelligence updates released on August 18, 2026. This issue has affected both consumer devices and Microsoft Defender for Endpoint-managed environments, disrupting a critical malware-detection capability for administrators and home users alike. Microsoft Defender Update Crashes Virus…
-
Hackers Impersonate Claude, ChatGPT and Copilot to Deliver Infostealers and Backdoors
Threat actors are increasingly abusing the popularity of generative AI brands to distribute malware, turning trusted names such as Claude, ChatGPT and Microsoft Copilot into convincing lures for infostealers, browser hijackers and remote-access backdoors. Sophos X-Ops reviewed 12 months of Managed Detection and Response (MDR) investigations, spanning July 2, 2025 to June 29, 2026. They…
-
13 Malicious Rabby Firefox Extensions Steal Wallet Keyrings Before They Are Encrypted
A broad Firefox add-on campaign that includes 13 malicious Rabby Wallet impersonators engineered to exfiltrate wallet keyring data before the application encrypts it locally. The activity is part of a larger operation, provisionally tracked as “Offside Wallet Theft Factory,” which links 77 Firefox extension identities through cloned code, reused infrastructure, deceptive listings, stable add-on IDs,…
-
Critical Citrix NetScaler Flaw Allows Attackers to Bypass Authentication
Cloud Software Group has issued a critical security bulletin regarding two vulnerabilities that affect customer-managed NetScaler ADC and NetScaler Gateway appliances. Among these, there is an authentication-bypass flaw that could expose remote-access environments to unauthenticated breaches. Citrix NetScaler Flaw The most severe issue, tracked as CVE-2026-19490, has a CVSS v4 base score of 9.3 and…
-
Critical Citrix NetScaler Flaw Allows Attackers to Bypass Authentication
Cloud Software Group has issued a critical security bulletin regarding two vulnerabilities that affect customer-managed NetScaler ADC and NetScaler Gateway appliances. Among these, there is an authentication-bypass flaw that could expose remote-access environments to unauthenticated breaches. Citrix NetScaler Flaw The most severe issue, tracked as CVE-2026-19490, has a CVSS v4 base score of 9.3 and…
-
CISA, NSA and FBI Warn Hackers Using AI-Generated Scripts to Target Siemens S7 PLCs
U.S. cybersecurity agencies have issued an urgent warning about an active campaign targeting Siemens S7 series programmable logic controllers (PLCs). Attackers are utilizing AI-generated scripts disguised as legitimate industrial monitoring tools. This joint advisory, published by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the…
-
T-Mobile Physically Cuts Network Cable to Evict Chinese Salt Typhoon Hackers
In 2024, T-Mobile’s security team took an unusually direct approach to contain a cybersecurity threat: they physically cut a network cable to terminate suspected access by the Chinese state-backed hackers known as Salt Typhoon. According to CSN, this action came after months of incident response efforts within T-Mobile’s network, during which defenders investigated signs of…
-
Critical Snowflake GitHub Actions Flaw Allows Attackers to Steal Internal Jira Credentials
A significant GitHub Actions injection vulnerability in Snowflake’s public snowflake-connector-net repository. This flaw could have allowed unauthenticated attackers to execute commands on a GitHub-hosted runner and potentially steal internal Jira credentials. The vulnerability was discovered by Wiz Red Agent, an autonomous AI-powered security research tool, just five days after the vulnerable workflow was deployed. Snowflake…
-
Aeternum Operators Use Polygon Smart Contracts to Rotate Malware C2 Domains Dynamically
Aeternum operators are abusing Polygon smart contracts as a decentralized dead-drop resolver, allowing malware to retrieve and rotate command-and-control (C2) domains without depending on conventional attacker-owned servers. The approach turns a public blockchain into resilient C2 infrastructure that is substantially harder to disrupt through domain seizures, hosting takedowns, or sinkholing. Rather than contacting a fixed…
-
They escaped south-east Asia’s scam compounds. Then they realised they were still trapped
The cyber-fraud industry has flourished in Thailand, Cambodia and Myanmar, with thousands of people trafficked into the industry. But even those who have managed to find a way out often cannot return homeArtillery fire thundered. Windows shattered. Roofs caved in. And thousands of foreign workers many who had been tricked and trafficked into the vast…
-
Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level
Adelaide, Australia, August 19th, 2026, CyberNewswire Independent assessment provides Australian organisations with additional evidence when evaluating application control for sensitive, government, defence and critical infrastructure environments. Airlock Digital, a global provider of application control and allowlisting solutions, today announced that it has completed an independent Information Security Registered Assessors Program (IRAP) assessment at the PROTECTED…
-
Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level
Adelaide, Australia, August 19th, 2026, CyberNewswire Independent assessment provides Australian organisations with additional evidence when evaluating application control for sensitive, government, defence and critical infrastructure environments. Airlock Digital, a global provider of application control and allowlisting solutions, today announced that it has completed an independent Information Security Registered Assessors Program (IRAP) assessment at the PROTECTED…
-
Premier League to phase in cyber compliance regime
The Premier League is introducing mandatory cyber compliance rules, but they won’t be fully enforced until the end of the decade. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649555/Premier-League-to-phase-in-cyber-compliance-regime
-
OpenAI Slows Frontier AI Training as Astra Nears Critical Cyber Threshold
OpenAI slows frontier AI training as Astra nears a critical cyber threshold, raising new questions about AI security, autonomy, and defense. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-openai-astra-critical-cybersecurity-threshold/
-
Researchers say OpenAI revoked their access to limited cyber program
The idea behind OpenAI’s Trusted Access for Cyber program is to give trusted defenders better models so they can report bugs and vulnerabilities to companies, with the aim of getting flaws patched faster. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/19/researchers-complain-that-openai-revoked-their-access-to-limited-cyber-program/
-
Researchers say OpenAI revoked their access to limited cyber program
The idea behind OpenAI’s Trusted Access for Cyber program is to give trusted defenders better models so they can report bugs and vulnerabilities to companies, with the aim of getting flaws patched faster. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/19/researchers-complain-that-openai-revoked-their-access-to-limited-cyber-program/
-
Quantum-Safe Isn’t Cyber-Safe
Tags: access, ai, api, breach, communications, compliance, computer, computing, credentials, cryptography, cyber, data, defense, encryption, exploit, flaw, google, group, ml, openai, password, radius, risk, threat, update<div cla In the same week federal agencies began scoping migrations under the White House’s new Post-Quantum Cryptography Executive Order, a group of academic researchers published a paper that, on its face, had nothing to do with quantum computing at all. It described a flaw in how three of the most security-conscious engineering organizations on…
-
Former Ping Identity and CyberArk Executives Join AppViewX to Scale Machine and Agent Identity Security
New York, New York, August 19th, 2026, CyberNewswire New revenue leader and board member join as AppViewX’s identity security business continues its rapid growth AppViewX, the leading machine and agent identity security company built for the AI and quantum enterprise, today announced the appointment of Mike Durso as Chief Revenue Officer and the addition of…
-
China-Nexus Hackers Target Myanmar Diplomats With QUICAgent Go Backdoor via Malicious VHD Files
A China-nexus threat actor is targeting Myanmar government and diplomatic personnel with a multi-stage malware campaign that delivers a custom Go-based backdoor, dubbed QUICAgent, through Virtual Hard Disk (VHD) files disguised as benign images. The campaign relies on highly targeted social engineering. One malicious file, named TrainingAnnouncement.jpg, is not an image but a VHD container.…
-
CISA Warns Microsoft Internet Key Exchange RCE Flaw Is Actively Exploited
Tags: cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, Internet, kev, microsoft, rce, remote-code-execution, service, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability, tracked as CVE-2026-33824, is currently being actively exploited. The issue is classified as a double-free vulnerability, which means it affects the memory management of Microsoft…

