Tag: cyber
-
OpenAI Cancels GPT-6.1 Astra Release Over Internal Safety Concerns
OpenAI has canceled the planned October release of GPT-6.1 Astra after internal testing revealed that the next-generation model did not meet the company’s safety and alignment standards. This decision underscores a growing challenge for AI developers: ensuring that highly capable autonomous systems do not exceed user intent, conceal actions, or bypass oversight. The model was…
-
Anthropic MCP Python SDK Flaw Enables OAuth Credential Theft and Account Takeover
Security researchers have disclosed a high-severity vulnerability in Anthropic’s Model Context Protocol (MCP) Python SDK. This flaw could allow a malicious MCP server to steal OAuth credentials, potentially taking over user accounts. The vulnerability affects MCP client deployments that use HTTP transport and includes vulnerable SDK releases from versions 1.9.1 to 2.1.1. Research from Cycode…
-
Octopus Server Flaw Lets Authenticated Attackers Execute Arbitrary Code
Octopus Deploy has announced a high-severity vulnerability in Octopus Server that could allow authenticated users with project or environment editing permissions to execute arbitrary code within the Octopus Server process. Tracked as CVE-2026-101169, this issue stems from insecure JSON deserialization and affects multiple Octopus Server releases running on both Linux and Microsoft Windows. Organizations using…
-
GitHub AI Agent Uncovers 24 Android App Vulnerabilities
GitHub Security Lab has disclosed 24 vulnerabilities in Android applications discovered through its open-source AI security agent and specialized audit taskflows. The findings highlight issues that could enable covert location tracking in the OsmAnd navigation app and account takeover attacks against Wikipedia users on Android. Kevin Stubbings, a researcher at GitHub Security Lab, developed targeted…
-
OpenSUpdater Malware Hides Inside 7-Zip Installers to Evade Detection
Threat actors behind the OpenSUpdater malware family are concealing a reflective loader inside recompiled 7-Zip self-extracting archive components, allowing malicious code to blend into otherwise legitimate-looking installers and evade conventional triage. Rather than relying solely on a malicious embedded executable, the operators modify the decompression stub itself the code responsible for unpacking an embedded archive,…
-
New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits
Tags: ai, api, botnet, control, credentials, cyber, ddos, infrastructure, intelligence, malware, service, theft, threat, windowsA newly identified Windows botnet dubbed x47.c is marketing a blend of conventional DDoS tooling, credential theft, SOCKS5 proxying, fast-flux command-and-control infrastructure, and an “AI API drain” capability designed to exhaust victims’ paid artificial-intelligence service credits. Qrator Research Labs identified the previously undocumented malware platform during threat hunting. They traced its sale to an operator…
-
wolfSSL 5.9.4 Patches 11 Security Flaws Affecting TLS and Certificate Validation
wolfSSL has released version 5.9.4, which addresses 11 security vulnerabilities related to TLS and DTLS handshakes, X.509 certificate validation, certificate revocation, OCSP stapling, session resumption, and memory safety. This release is particularly important for deployments utilizing OpenSSL-compatible settings, optional certificate validation features, or persistent, long-running TLS contexts. The most critical issue, tracked as CVE-2026-93302, affects…
-
DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware
DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have expanded their blockchain-backed command-and-control infrastructure with a new Ethereum-based recovery channel dubbed HashHiding. The technique stores an active C2 IP address and port inside the recipient address of ordinary Ethereum transfers, allowing infected systems to recover attacker infrastructure without relying on domains, smart contracts, or transaction…
-
Critical WatchGuard AP Flaws Let Unauthenticated Attackers Execute Arbitrary Commands
WatchGuard has announced the discovery of three high-impact vulnerabilities in its wireless access point platform. Two of these critical issues allow unauthenticated network attackers to gain API access and execute arbitrary operating-system commands. These vulnerabilities affect WatchGuard AP firmware versions 1.0 through 3.4.7 and were addressed in version 3.4.8, which the vendor released as a…
-
SilverFox Built Fake Software Sites That Know When Researchers Are Watching
SilverFox-linked operators are evolving beyond counterfeit software portals and signed-binary abuse by using visitor-aware delivery infrastructure that can distinguish potential victims from security researchers. Pelagosx recently investigated a related Windows malware delivery chain that began with a finance-themed WhatsApp message targeting Malaysian users. The message urged recipients to forward a report for verification and open…
-
SilverFox Built Fake Software Sites That Know When Researchers Are Watching
SilverFox-linked operators are evolving beyond counterfeit software portals and signed-binary abuse by using visitor-aware delivery infrastructure that can distinguish potential victims from security researchers. Pelagosx recently investigated a related Windows malware delivery chain that began with a finance-themed WhatsApp message targeting Malaysian users. The message urged recipients to forward a report for verification and open…
-
Japanese Railway Operators Hit with Weekend Cyber Attacks
Tokyo Metro and Keio have revealed separate cyber-attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/japanese-railway-operators-cyber/
-
Japanese Railway Operators Hit with Weekend Cyber Attacks
Tokyo Metro and Keio have revealed separate cyber-attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/japanese-railway-operators-cyber/
-
Japanese Railway Operators Hit with Weekend Cyber Attacks
Tokyo Metro and Keio have revealed separate cyber-attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/japanese-railway-operators-cyber/
-
Attackers Hid Behind Trusted RMM Software Before Deploying a Full Surveillance RAT
Threat actors are abusing trusted remote monitoring and management (RMM) software to gain legitimate-looking access to Windows endpoints before deploying a previously undocumented .NET remote access trojan dubbed AgtaBackup RAT. The operation starts with a fraudulent Microsoft Store-style page impersonating a popular videoconferencing application, but ultimately hands the victim’s machine to an attacker-controlled RMM tenant.…
-
Keio Railway Confirms Ransomware Attack Disrupted Business Systems
Keio Corporation has confirmed that a ransomware attack has caused a system failure within parts of its group infrastructure, disrupting certain business systems at its affiliated companies. The Japanese railway operator stated that train services continue to operate and that it has not yet confirmed any data breach. In a public notice issued on September…
-
Microsoft Tracks NeedyMantis Malware Targeting Telecoms and Government Contractors
Microsoft Threat Intelligence has discovered NeedyMantis, a modular post-compromise malware framework that targets specific industries, including telecommunications firms, government contractors, universities, medical nonprofits, and intergovernmental organizations. Unlike typical malware that serves as an initial access point, NeedyMantis is designed to maintain an attacker’s access and support follow-on operations after an initial breach. NeedyMantis activity has…
-
Microsoft Tracks NeedyMantis Malware Targeting Telecoms and Government Contractors
Microsoft Threat Intelligence has discovered NeedyMantis, a modular post-compromise malware framework that targets specific industries, including telecommunications firms, government contractors, universities, medical nonprofits, and intergovernmental organizations. Unlike typical malware that serves as an initial access point, NeedyMantis is designed to maintain an attacker’s access and support follow-on operations after an initial breach. NeedyMantis activity has…
-
Apple Fixes iOS Zero-Day Exploited in Sophisticated Targeted Attacks
Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address CVE-2026-86950, a zero-day vulnerability in CoreGraphics that may have been exploited in sophisticated, targeted attacks against specific individuals. Apple’s latest security updates fix an out-of-bounds write vulnerability in CoreGraphics, the graphics rendering framework used on iPhone and iPad devices. This flaw, tracked as CVE-2026-86950, could…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…

