Tag: cyber
-
Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion
Tags: advisory, attack, cisa, cyber, extortion, infrastructure, intelligence, ransomware, service, updateMedusa ransomware operators have compromised over 500 organizations across critical infrastructure sectors, according to a joint advisory issued by the FBI, CISA, and the U.S. Department of Health and Human Services (HHS) as part of their #StopRansomware initiative. An update released on August 18, 2026, provides expanded intelligence based on FBI investigations conducted as recently…
-
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single…
-
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single…
-
Critical Microsoft Copilot CoSnitch Flaw Lets Hackers Steal Sensitive Data With One Click
A critical one-click vulnerability in Microsoft Copilot Personal, tracked as CVE-2026-24301 and dubbed CoSnitch. This flaw could enable an attacker to trigger malicious Copilot prompts, access data from connected OAuth applications, and silently transmit that information to an attacker-controlled server. Microsoft addressed this issue on August 18, 2026, following Varonis’s responsible disclosure in December 2025.…
-
What the Iran cyberattacks can teach boards about cyber warfare
First seen on scworld.com Jump to article: www.scworld.com/perspective/what-the-iran-cyberattacks-can-teach-boards-about-cyber-warfare
-
What the Iran cyberattacks can teach boards about cyber warfare
First seen on scworld.com Jump to article: www.scworld.com/perspective/what-the-iran-cyberattacks-can-teach-boards-about-cyber-warfare
-
CISA Weighs Outsourcing Its Cyber Software Buying
CISA Issues Sources Sought Notice Floating $600M a Year, $6B Over Contract Life. The U.S. Cybersecurity and Infrastructure Security Agency is surveying industry on whether a contractor could take over cybersecurity software buying for federal civilian agencies – a service worth more than $600 million a year, according to a new notice. First seen on…
-
Every Company Now Needs An AI Risk Officer: Accenture Expert
For most companies, it has now become essential to clearly designate a single executive responsible for ensuring that the drive to deploy AI does not outpace cybersecurity and safety, according to Accenture cyber intelligence leader Ryan Whelan. First seen on crn.com Jump to article: www.crn.com/news/security/2026/every-company-now-needs-an-ai-risk-officer-accenture-expert
-
OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue
The ChatGPT maker says its upcoming Astra model may have reached “critical” cyber capabilities, prompting it to halt a significant number of training runs while it tightens internal safeguards. First seen on wired.com Jump to article: www.wired.com/story/openai-overhauls-safety-protocols-after-its-ai-agents-went-rogue/
-
Where Cybersecurity GRC Programs Break Down – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/where-cybersecurity-grc-programs-break-down-kovrr/
-
Where Cybersecurity GRC Programs Break Down – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/where-cybersecurity-grc-programs-break-down-kovrr/
-
President Trump Signs Memo Expanding Private Sector Role in Offensive Cyber Operations
Trump’s cybercrime memo directs a federal program for vetted U.S. firms to conduct supervised operations against foreign criminal groups. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-trump-private-sector-offensive-cyber-operations-us/
-
Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity
Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully functioning document converters, meal planners, recipe tools, and PDF utilities. The applications deliver their advertised features, but their shared codebase also enables runtime JavaScript execution and access to desktop-capture functionality creating a serious surveillance and post-compromise risk. Search-optimized…
-
International Cyber Expo Unveils New Talks for its Global Cyber Summit 2026
International Cyber Expo has announced a new line-up of speakers and sessions for its Global Cyber Summit, with discussions set to tackle some of the biggest issues facing cybersecurity leaders. Sponsored by Huntress, the Global Cyber Summit will bring together senior security professionals, government representatives and industry experts at Olympia London on 29 and 30…
-
Critical MLflow SSRF Flaw Exploited in the Wild
A critical unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, tracked as CVE-2026-64849, is being actively exploited within hours of its disclosure, according to watchTowr. This flaw affects MLflow versions before 3.15.0 and can expose cloud credentials, internal services, and other sensitive data to remote attackers. MLflow SSRF Flaw The vulnerability exists in MLflow’s model-registry…
-
BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims
BTMOB has evolved beyond a conventional Android banking trojan into a turnkey fraud platform that lets criminals build branded phishing apps, remotely operate infected phones, and automate theft. Its emergence illustrates how leaked malware source code and low-code tooling are turning mobile fraud into a scalable franchise. The malicious lnat-tv-pro.apk sample connected to server[.]yaarsa[.]com/con over…
-
OpenAI Warns Organizations to Automate Cybersecurity as AI-Powered Attacks Accelerate
OpenAI has issued a warning that organizations need to quickly automate core cybersecurity functions as increasingly advanced AI systems make it easier and cheaper to identify, exploit, and chain security vulnerabilities. In a recent security article titled “The Defender’s Window,” OpenAI President Greg Brockman explained that the OpenAI-Hugging Face incident showcased how highly capable attackers…
-
Silent ‘TwinLoot’ Cyber Threat Operates Entirely From Microsoft’s Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud
-
Apple Addresses 28 Security Flaws Across macOS, iOS, and iPadOS
Apple has released security updates for iPhones, iPads, and Macs to address 28 vulnerabilities across its latest operating systems. These updates, issued on August 17, 2026, include iOS 26.6.1, iPadOS 26.6.1, macOS Tahoe 26.6.2, and security fixes for older devices with iOS 18.7.10 and iPadOS 18.7.10. The patches impact a wide range of supported Apple…
-
CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability
Tags: ai, cisa, computing, cve, cyber, cybersecurity, data, exploit, flaw, framework, infrastructure, injection, intelligence, kev, open-source, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, tracked as CVE-2025-62593, is a code injection flaw in the Ray Project, a widely used open-source distributed computing framework often deployed for artificial intelligence workloads, machine learning development, data processing, and scalable Python…
-
Asruex Trojan Found Embedded in GEEKOM Mini PC Realtek Ethernet Driver
GEEKOM has confirmed that a malware-flagged Realtek LAN driver package was previously accessible through an outdated support page for its mini PCs, raising fresh supply-chain security concerns around vendor-hosted driver downloads. The company said the affected file was confined to a legacy resource, not its current support portal or factory-installed Windows images. The incident came…
-
JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an attacker over an AES-CTR-encrypted WebSocket channel, allowing the operator to react while card numbers, passwords and one-time codes are still…
-
Cyber Incident Disrupts Student Services at UT San Antonio
UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cyber-incident-ut-san-antonio/
-
AI Agents Gain Unintended Internet Access During Cybersecurity Evaluations
AI security evaluation firm has disclosed that several frontier AI models unintentionally accessed and acted against real internet-connected systems during controlled cybersecurity testing. This issue, which has since been resolved, stemmed from a single evaluation scenario in which internet access was permitted and a fictional target name overlapped with a real domain. Irregular stated that…
-
Octagon Android Bot Uses Hidden VNC and Accessibility Overlays to Steal Crypto Wallet Credentials
Octagon, a previously undocumented Android banking and cryptocurrency fraud platform marketed as malware-as-a-service by a Russian-speaking actor using the handle AndroidKitKat. First advertised on a Russian-language cybercrime forum on June 1, 2026, the toolkit combines abuse of accessibility, stealthy remote control, credential-stealing overlays, SMS interception, and device reconnaissance to enable direct account takeover and cryptocurrency…
-
Microsoft Adds Customizable Context Menu to Windows 11 File Explorer
Microsoft has introduced a redesigned and customizable context menu for the Windows 11 File Explorer, along with significant improvements in reliability and responsiveness. Announced for Windows Insiders on August 17, this update addresses a common issue in Windows 11: slow and cluttered right-click menus that can be affected by various application extensions and shell integrations.…
-
C2Looper v2 Uses GitHub Repositories as Full CommandControl Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver tasks, receive results, maintain beacon records, and host payloads. ThreatLabz identified the malware in July 2026 and assesses, with low-to-medium confidence, that it is delivered through…

