Tag: cyber
-
C2Looper v2 Uses GitHub Repositories as Full CommandControl Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver tasks, receive results, maintain beacon records, and host payloads. ThreatLabz identified the malware in July 2026 and assesses, with low-to-medium confidence, that it is delivered through…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
EU AI Act Standards: What to Do Before Citation – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/eu-ai-act-standards-what-to-do-before-citation-kovrr/
-
Hackers Turn Claude Code and Codex Into AI-Powered Tools for Credential Theft and Cloud Attacks
Threat actors are increasingly using coding assistants as operational tools. Detailed research from Gambit Security highlights three campaigns where Claude Code, OpenAI Codex, and large language models facilitated activities ranging from ransomware preparation to the harvesting of secrets on a large scale and exploiting cloud accounts. These cases demonstrate how AI can speed up attackers’…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
VMware vCenter RCE Gives Attackers a Path From One Appliance to Entire Virtual Infrastructure
Tags: cve, cyber, data-breach, exploit, infrastructure, rce, remote-code-execution, vcenter, vmware, vulnerabilityA critical VMware vCenter vulnerability is being actively exploited in a fast-moving campaign that turns a single exposed management appliance into a launch point for broad virtual-infrastructure compromise. Incident responders at QUIRSO linked the activity to exploitation of CVE-2026-59310, while identifying a separate, possibly unrelated track involving CVE-2026-59309. CVE-2026-59310 is a directory-traversal vulnerability in the…
-
Shadow hVNC Malware Kit Gives Hackers Hidden Windows Desktop for Covert Remote Control
A newly advertised malware-as-a-service toolkit named Shadow hVNC combines browser credential theft, hidden virtual desktop control, reverse proxying, and extensive persistence into a single Windows-focused payload. Marketed by a user known as “RemoteX” in March 2026, the kit gives operators a parallel Win32 desktop where they can browse, run tools, and interact with hijacked sessions…
-
PoC Exploit Released for Microsoft SCCM Vulnerability Enabling SYSTEM-Level Code Execution
A recently disclosed proof-of-concept (PoC) exploit for Microsoft Configuration Manager, previously known as System Center Configuration Manager (SCCM), demonstrates how an authenticated domain user could potentially escalate privileges to SYSTEM on a vulnerable Primary Site Server. This issue, tracked as CVE-2026-47301, was reported by security researcher Omri Baso and is characterized as an exploit chain…
-
Pokémon Center Data Breach Exposes Customers’ Personal and Order Data
Pokémon Center has begun notifying customers in the United Kingdom and Germany that personal information from their online orders was exposed following a cyberattack on CEVA Logistics, its third-party fulfillment partner. The retailer clarified that the incident did not originate from Pokémon Center’s own systems or website. Instead, attackers compromised the systems CEVA uses to…
-
Attackers turn to AI for help identifying files worth stealing
AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/gambit-security-ai-cyberattack-tools-report/
-
Unleashing Hackers to Be the US Government’s Bounty Hunters
Trump Presidential Memo a Risky Proposition for Corporations and the Internet. Even those who support a White House push to involve the private sector in offensive cyber operations against foreign online crime groups admit that the strategy is laden with risk – for the companies that take part and for the broader global internet. First…
-
Unleashing Hackers to Be the US Government’s Bounty Hunters
Trump Presidential Memo a Risky Proposition for Corporations and the Internet. Even those who support a White House push to involve the private sector in offensive cyber operations against foreign online crime groups admit that the strategy is laden with risk – for the companies that take part and for the broader global internet. First…
-
Unleashing Hackers to Be the US Government’s Bounty Hunters
Trump Presidential Memo a Risky Proposition for Corporations and the Internet. Even those who support a White House push to involve the private sector in offensive cyber operations against foreign online crime groups admit that the strategy is laden with risk – for the companies that take part and for the broader global internet. First…
-
Multiple organisations investigating fresh wave of Cl0p breaches
Multinational giants such as Philips and Shell may have been affected after the Cl0p cyber extortion gang hacked a popular piece of PLM software. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366648757/Multiple-organisations-investigating-fresh-wave-of-Cl0p-breaches
-
Trump enlists private sector for offensive cyber operations
Tags: cyberPrivate sector cyber companies will support US federal agencies on offensive cyber operations under a new programme First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366648818/Trump-enlists-private-sector-for-offensive-cyber-operations
-
OpenMatter Network to Take Verification Message to Belgrade Blockchain Week 2026
Melbourne, Florida, August 17th, 2026, CyberNewswire Head of Operations and Partnerships Chris Biele to lead sessions on secure scientific collaboration, agentic AI and the need to move from trust to cryptographic proof Continuing its effort to build global awareness of the need to move computing from assumption-based trust to cryptographic proof, OpenMatter Network today announced…
-
Hacking Back Is Back: White House to Enable Cyber Privateers
In an Aug. 12 National Security Presidential Memorandum, President Donald Trump set out guidance for more private-sector action in global cyber battles. Here’s the rest of the story. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/hacking-back-is-back-white-house-to-enable-cyber-privateers/
-
Concentration Risk in Your Vendor Stack – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/concentration-risk-in-your-vendor-stack-kovrr/
-
NIST wants to overhaul its vulnerability database for the AI age
NIST is seeking public input to modernize the National Vulnerability Database to keep pace with AI-driven cyber threats and machine-scale security data. First seen on cyberscoop.com Jump to article: cyberscoop.com/nist-national-vulnerability-database-ai-overhaul/
-
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT”‘5.6″‘Cyber that it said is focused on vulnerability research, penetration testing, and incident response.”Built on GPT”‘5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero-day vulnerabilities and developing exploit chains) and to reduce refusals for certain higher-risk First seen on…
-
Plug Pwn Attack Exploits Windows PnP to Gain SYSTEM Access With Zero Clicks
Security researchers Alejandro Hernando, also known as 0xedh, and Borja MartÃnez have unveiled a research project titled >>Plug & Pwn.<< This project demonstrates how the Windows Plug and Play (PnP) driver installation workflows can be exploited to execute vendor-supplied code with NT AUTHORITY\SYSTEM privileges. Presented at DEF CON 34, the research explores the risky intersection…
-
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Tags: ai, attack, breach, cloud, credentials, cyber, infrastructure, malicious, pypi, software, supply-chain, theftThe March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstream software supply chain abuse. The packages were available for roughly 40 minutes before quarantine, but their brief…
-
Water Water Everywhere Possible Iranian Attack to Water Infrastructure
In recent days, a multistate cyber campaign has reached the programmable controllers that run American water and wastewater systems, depriving operators of monitoring and control and, in some cases, contributing to loss of pressure and flooding. Beginning July 27, the FBI and Environmental Protection Agency said, utilities in at least seven states reported intrusions into..…
-
Suisan City, California, Responds to Cyber Incident Amid Wave of US Local Government Attacks
Police and fire response has been impacted by the attack on Suisan City, while two other local authorities have been hit by cyber incidents in the past week also First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/suisan-cyber-incident-government/
-
Copeland XWEB Pro Vulnerabilities Let Attackers Gain Root Access and Manipulate Refrigeration Systems
Security researchers have discovered 23 vulnerabilities in Copeland’s XWEB Pro commercial refrigeration controllers, with 21 rated as high severity. These vulnerabilities could allow unauthenticated attackers to gain root-level remote code execution and control connected cooling equipment. Claroty’s Team82 found that an attacker could exploit a combination of authentication flaws, predictable administrator credentials, and command-injection vulnerabilities…
-
OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/openai-daybreak-blue-red-gpt-cyber/
-
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure
Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous subkey was unintentionally committed to a private GitHub repository. The affected signing infrastructure includes selected release files, such as Linux tarballs, RPM packages, and checksum files. Mozilla’s investigation into available audit logs…

