Tag: cyber
-
Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Bug
Google has released Chrome version 154 for desktop platforms, addressing 32 security vulnerabilities, including a critical buffer overflow flaw in the ANGLE graphics translation layer. This update is being rolled out as version 154.0.8037.92/.93 for Windows and macOS, and version 154.0.8037.92 for Linux. Google Chrome 154 Update The most severe issue, tracked as CVE-2026-102331, is…
-
Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Bug
Google has released Chrome version 154 for desktop platforms, addressing 32 security vulnerabilities, including a critical buffer overflow flaw in the ANGLE graphics translation layer. This update is being rolled out as version 154.0.8037.92/.93 for Windows and macOS, and version 154.0.8037.92 for Linux. Google Chrome 154 Update The most severe issue, tracked as CVE-2026-102331, is…
-
Hackers Exploit Citrix NetScaler Zero-Day to Gain Root Access and Deploy Web Shells
Threat actors are actively exploiting a critical zero-day vulnerability in Citrix NetScaler, identified as CVE-2026-88772, to gain unauthenticated root-level access to vulnerable Application Delivery Controller (ADC) and Gateway appliances. After the initial compromise, they deploy custom PHP web shells and tools to tunnel within the internal network. Mandiant Consulting and the Google Threat Intelligence Group…
-
RSA Agent ID Secures AI Agents and MCP Servers With Identity-Based Access Controls
RSA has launched RSA Agent ID, an identity security platform that discovers, secures, and governs AI agents and Model Context Protocol (MCP) servers in highly regulated environments. The company states that this offering addresses a growing “agentic identity” gap by applying workforce-style identity governance, authorization controls, and auditability to non-human AI actors. Announced at The…
-
Attackers Use PaperCut RCE Chain to Steal Tokens and Access Domain Controller
Tags: access, authentication, cve, cyber, exploit, rce, remote-code-execution, service, threat, vulnerability, zero-dayThreat actors exploited a chained pair of PaperCut MF zero-day vulnerabilities to compromise an education-sector environment, steal a domain-privileged service account token, and reach a domain controller before attempting to extract the Active Directory database. The campaign abused CVE-2026-81578, an authentication-bypass vulnerability in PaperCut MF and NG’s web management interface, together with CVE-2026-82078, a critical…
-
Hackers Abuse MSP360 and ScreenConnect RMM Tools for Persistent Access and Credential Theft
Tags: access, credentials, cyber, exploit, hacker, malware, monitoring, phishing, software, theft, tool, vulnerability, windowsThe phishing campaigns that weaponize legitimate remote monitoring and management software to establish persistent access and support credential theft on Windows systems. The campaign demonstrates a recurring operational trend: rather than exploit a vulnerability or deploy obvious custom malware, attackers are abusing trusted administrative platforms already designed to execute commands, transfer files, deploy applications, and…
-
OperTraitor Finds Kubernetes Operators With Cluster-Wide Secret Access and Admin Paths
OperTraitor, an open-source, LLM-powered engine that identifies Kubernetes operators whose RBAC (Role-Based Access Control) privileges exceed their documented operational requirements. Research indicates that over 5% of assessed operators requested excessive permissions, including cluster-wide access to secrets and potential pathways to cluster-admin-level control. Kubernetes operators automate application deployment, configuration, and lifecycle management through Custom Resource Definitions…
-
Linux Kernel CVE-2026-72018 Flaw Lets Local Attackers Gain Root Access
A high-severity Linux kernel vulnerability, tracked as CVE-2026-72018, lets a local attacker with CAP_NET_ADMIN privileges escalate to root. This exploitation involves an out-of-bounds write in the Shared Memory Communications Direct (SMC-D) DIBS loopback implementation. Researchers at XBOW discovered and demonstrated the flaw, creating a local privilege escalation proof of concept using a constrained 16-byte zero-write…
-
Hackers Target 5,700 Microsoft 365 Accounts Using Forgotten Service Accounts With No MFA
Threat actors have targeted more than 5,700 Microsoft 365 accounts across 28 tenants in a password-spraying campaign that successfully breached seven forgotten service accounts lacking MFA. The activity, tracked by Proofpoint as UNK_CondorFiltration, focused heavily on Chilean retail and financial organizations and abused the TeamFiltration offensive framework. The framework, initially created for legitimate Microsoft 365…
-
Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover
Tags: access, cloud, credentials, cyber, identity, infrastructure, kubernetes, microsoft, software, supply-chain, theftMicrosoft has detailed a cloud-focused intrusion attributed to Storm-3068, in which attackers turned a compromised user account into a launch point for Azure DevOps abuse, Kubernetes credential theft, and potential access to connected cloud environments. The campaign demonstrates how identity compromise can quickly escalate into a software supply-chain and production-infrastructure incident when development platforms have…
-
Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover
Tags: access, cloud, credentials, cyber, identity, infrastructure, kubernetes, microsoft, software, supply-chain, theftMicrosoft has detailed a cloud-focused intrusion attributed to Storm-3068, in which attackers turned a compromised user account into a launch point for Azure DevOps abuse, Kubernetes credential theft, and potential access to connected cloud environments. The campaign demonstrates how identity compromise can quickly escalate into a software supply-chain and production-infrastructure incident when development platforms have…
-
Übernahme im MicrosoftMarkt – Quorum Cyber will Ontinue übernehmen und KI-Security bündeln
First seen on security-insider.de Jump to article: www.security-insider.de/quorum-cyber-will-ontinue-uebernehmen-und-ki-security-buendeln-a-2edbad08c416ce7cc0fc333c308c90e3/
-
Unsloth Fixes Arbitrary Code Execution Flaw Triggered by Malicious Hugging Face Models
Unsloth has addressed a critical arbitrary code execution vulnerability in its Studio web interface. This flaw allowed a malicious Hugging Face model repository to execute attacker-controlled Python code simply by a user selecting or inspecting it. Unsloth resolved the issue in version 2026.6.9, and users running Studio are urged to update immediately. Unsloth Fixes Arbitrary…
-
Android Malware Turns Gemini AI Into an Assistant for On-Device Attacks
A newly documented Android banking trojan named RATHat is demonstrating how generative AI can be operationalized inside mobile malware. The threat uses Google Gemini models to navigate unfamiliar Android interfaces, while its operator panel applies AI to identify higher-value victims from stolen SMS data. The malware disguises itself as legitimate applications, then relies on social…
-
SectopRAT Malware Hides in Legitimate Software to Steal Browser Credentials and Crypto Wallets
A newly analyzed SectopRAT campaign demonstrates how threat actors can weaponize trusted application components to conceal a full-featured remote access trojan and steal high-value data. The investigation found no evidence that the software vendor distributed a trojanized build or that the incident stemmed from a supply-chain compromise. Instead, attackers appear to have modified an existing…
-
EU Cyber Resilience Act requirements for containers and Kubernetes
Starting in full force on”¯Dec. 10, 2024, the EU Cyber Resilience Act (CRA)”¯is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/rapidfort-cra-container-compliance/
-
EU Cyber Resilience Act requirements for containers and Kubernetes
Starting in full force on”¯Dec. 10, 2024, the EU Cyber Resilience Act (CRA)”¯is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/rapidfort-cra-container-compliance/
-
OpenAI Launches Codex Security Cloud for Always-On Application Security Scanning
OpenAI has expanded its Codex platform with Codex Security Cloud, a cloud-hosted application security feature that continuously analyzes GitHub repositories, investigates potential vulnerabilities, and prepares remediation patches for human review. Announced as part of the company’s latest Codex updates, this service is designed to operate security workflows beyond a developer’s local machine. It can run…
-
OpenSSL High-Severity Flaw Lets Attackers Leak Heap Memory in Plaintext
OpenSSL has announced a high-severity vulnerability in its Datagram Transport Layer Security (DTLS) implementation that could allow a remote peer to read unintended plaintext heap memory during handshake data transmission or trigger a denial-of-service condition. This vulnerability, tracked as CVE-2026-84782, stems from an out-of-bounds read when handling DTLS handshake message retransmissions. The issue affects various…
-
FBI, Dutch Police Take Down Alleged ShinyHunters Cybercrime Group Leader
The FBI and Dutch National Police have announced the arrest of a 24-year-old man from Amsterdam who is suspected of playing a major role in the ShinyHunters cybercrime group. This development marks a significant step forward in an international investigation into a widespread data theft and extortion operation. The suspect was arrested on September 15,…
-
US Air Force members given over 6 years in prison for cyber theft of more than $2 million
According to court documents, both men pleaded guilty to wire fraud, identity theft and access device fraud charges in June. First seen on therecord.media Jump to article: therecord.media/us-air-force-members-given-6-year-sentence-cyber
-
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
Sean Cairncross said CEOs need to be cognizant of how it’s being used, however. First seen on cyberscoop.com Jump to article: cyberscoop.com/national-cyber-director-ai-critical-infrastructure-cybersecurity/
-
GPT-6 Astra is More Prone to Rogue Supply-Chain Attacks
UK Agency Found GPT-6 Astra Attacked Out-of-Scope Targets in Simulated Cyber Tests. The U.K. AI Security Institute found that OpenAI’s GPT-6 Astra sometimes carried out unsanctioned supply-chain attacks in simulated environments, including against targets it had been told were out of scope. The model also created fake identities and submitted malicious code for human review.…
-
Cyber authorities issue alerts over exploitation of Citrix vulns
The latest vulnerabilities to be uncovered in the frequently-targeted Citrix NetScaler product lines were being exploited well-before disclosure, prompting disquiet. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651460/Cyber-authorities-issue-alert-over-exploitation-of-Citrix-vulns
-
Why AI won’t fix your cybersecurity problem
James Gillies, Head of Cyber Security at Logicalis UKI There is no escaping the fact that AI is creating significant opportunities for cybersecurity teams, from analysing security data and identifying suspicious activity to accelerating detection, response and remediation. However, the same capabilities are also changing the threat landscape. This comes at a time when security…
-
OpenAI Cancels GPT-6.1 Astra Release Over Internal Safety Concerns
OpenAI has canceled the planned October release of GPT-6.1 Astra after internal testing revealed that the next-generation model did not meet the company’s safety and alignment standards. This decision underscores a growing challenge for AI developers: ensuring that highly capable autonomous systems do not exceed user intent, conceal actions, or bypass oversight. The model was…
-
Anthropic MCP Python SDK Flaw Enables OAuth Credential Theft and Account Takeover
Security researchers have disclosed a high-severity vulnerability in Anthropic’s Model Context Protocol (MCP) Python SDK. This flaw could allow a malicious MCP server to steal OAuth credentials, potentially taking over user accounts. The vulnerability affects MCP client deployments that use HTTP transport and includes vulnerable SDK releases from versions 1.9.1 to 2.1.1. Research from Cycode…
-
Octopus Server Flaw Lets Authenticated Attackers Execute Arbitrary Code
Octopus Deploy has announced a high-severity vulnerability in Octopus Server that could allow authenticated users with project or environment editing permissions to execute arbitrary code within the Octopus Server process. Tracked as CVE-2026-101169, this issue stems from insecure JSON deserialization and affects multiple Octopus Server releases running on both Linux and Microsoft Windows. Organizations using…
-
OpenSUpdater Malware Hides Inside 7-Zip Installers to Evade Detection
Threat actors behind the OpenSUpdater malware family are concealing a reflective loader inside recompiled 7-Zip self-extracting archive components, allowing malicious code to blend into otherwise legitimate-looking installers and evade conventional triage. Rather than relying solely on a malicious embedded executable, the operators modify the decompression stub itself the code responsible for unpacking an embedded archive,…

