Tag: cyber
-
18 Malicious npm Packages Deploy Cross-Platform RAT Against Alibaba Developers
18 malicious npm packages have been used in a tightly coordinated software supply chain attack to deliver a cross”‘platform RAT that specifically targets developers working with Alibaba’s internal Aone tooling and @ali-scoped packages. The operation came to light after researchers analyzed a seemingly simple malicious npm package, lib-mtop, which acted as a downloader and exposed…
-
US water facilities targeted by ‘malicious cyber actors’ who’s to blame?
Despite Trump’s efforts to blame Tim Walz and Minnesota, officials suspect Iran behind attacks on US infrastructureLate last week, federal authorities issued a stern warning saying “malicious cyber actors” were targeting water and wastewater facilities in at least seven states across the US. Minnesota appeared to be the hardest hit with 30 of its water…
-
Automating incident response to reduce impact for UK SMEs
For many UK SMEs, the biggest cost of a cyber incident is not just the attack itself. It is the delay. Every extra hour spent working out what happened, who should act, and which systems need attention can increase downtime, damage customer trust, and create avoidable pressure on a small team. That is why automating……
-
How companies could share cyber risks without exposing their secrets
A cryptographic technique could let companies prove they’re vulnerable to critical flaws without revealing the sensitive data that attackers could exploit. First seen on cyberscoop.com Jump to article: cyberscoop.com/zero-knowledge-proofs-cyber-risk-sharing-op-ed/
-
Critical Gitea Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code
A critical vulnerability in Gitea has been identified, potentially allowing unauthenticated remote attackers to read arbitrary files on vulnerable servers and escalate to remote code execution (RCE). This vulnerability is tracked as CVE-2026-59774 and GHSA-6v53-hr58-556r, affecting Gitea versions from 1.22.11.22.11.22.1 to 1.27.01.27.01.27.0. It has been assigned a critical CVSS score of 3.1, with an attack…
-
Critical Adobe Campaign Flaws Let Unauthenticated Attackers Execute Arbitrary Code
Adobe has released an urgent security update for Adobe Campaign Classic, addressing multiple critical vulnerabilities that could allow remote attackers to execute arbitrary code on vulnerable servers without authentication. The update is documented in bulletin APSB26-120, published on August 3, 2026, and carries Adobe’s highest Priority 111 rating. The company urges organizations that use affected…
-
macOS CUPS Flaw Lets Local Attackers Write Arbitrary Files as Root
A recently disclosed privilege-related vulnerability in the Common UNIX Printing System (CUPS) on macOS could allow an unprivileged local user to create attacker-controlled files in arbitrary locations outside the protection of System Integrity Protection (SIP), thereby gaining root ownership. This flaw, tracked as CVE-2026-39875, affects Apple devices running macOS Sonoma, Sequoia, and Tahoe versions before…
-
The U.S. Cyber Strategy Has a Scaling Problem and AI Is Exposing It
AI can discover and weaponize software vulnerabilities faster than organizations can patch them, making exploit mitigation and runtime protection essential to cybersecurity. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-u-s-cyber-strategy-has-a-scaling-problem-and-ai-is-exposing-it/
-
AI Agent Governance: How Enterprises Can Approach It – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/ai-agent-governance-how-enterprises-can-approach-it-kovrr/
-
Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers
Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on vulnerable Security Management Servers and Multi-Domain Security Management Servers (MDS). This vulnerability is tracked as CVE-2026-18574 and is detailed in Check Point Security Alert sk185222. It affects multiple legacy and current versions of their management platform.…
-
OctLurk-Linked Hackers Deploy BINDCLOAK Backdoor Against Middle East Governments
The published Part 2 of a two-part technical analysis exposing BINDCLOAK, a previously undocumented modular backdoor deployed against government entities in the Middle East by an East Asia-linked threat actor tracked as OctLurk. The disclosure follows Part 1, which detailed the TELESHIM backdoor and the MIXEDKEY loader used earlier in the same multi-stage intrusion chain.…
-
cPanel Database Privilege Escalation Flaw Enables Full Administrative Access
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an authenticated cPanel user to execute arbitrary database commands with full administrative privileges. cPanel Database Privilege Escalation Flaw All supported versions of cPanel & WHM before the recently released security updates are affected. As WebPros states, an…
-
ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi”‘Fi credentials from travelers connecting to compromised hospitality networks worldwide. The operation, dubbed “CaptiveCrunch,” poisons DNS and HTTP flows on guest networks so that travelers attempting to reach legitimate Microsoft 365 or update endpoints are…
-
NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet
NullReceiver is a lean, stealth-focused evolution of DPRK’s blockchain C2 tradecraft that hides a reusable attacker wallet behind ordinary-looking Ethereum transfers, while still exposing just enough bytes to resolve a live command server. Two trojanized npm packages, bianira-ui@1.27.0 and fluid-type-ui@2.0.8, both Tailwind CSS plugin lookalikes, implement a new blockchain-based C2 resolution technique we’re calling NullReceiver.…
-
Apple Removes Telegram From App Store Worldwide
Telegram Messenger was temporarily removed from Apple’s App Store in several countries late Monday, preventing new users from downloading the messaging platform and blocking reinstalls for users who had previously deleted the app. This global delisting caused widespread confusion on the social media platform X, where users shared screenshots of App Store messages that read,…
-
Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data
Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This vulnerability could allow nearly undetectable manipulation of DNA test data files before analysis. The issue, tracked as CVE-2026-17583, carries a CVSS v4 score of 8.2 and affects .fsa and .hid file outputs used in forensic…
-
Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials
Tags: cyberAn analyst opening a queue on Monday morning will spend most of it on tickets that amount to nothing. Stellar Cyber’s Agentic Auto Triage closed 8,047 of those tickets … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/stellar-cyber-agentic-auto-triage/
-
Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint
Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by Google-synced passkeys. This can occur without stealing a password, capturing a fingerprint, or requiring the victim to unlock their device. In research published on August 23, 2023, Palo Alto Networks’ Unit 42 detailed…
-
New York Pours $9M Into Water Cyber Defense Amid Attacks
New York Fast-Tracks Utilities Grants as Hackers Disrupt Water Systems Nationwide. New York is awarding more than $9 million in cybersecurity grants to water and wastewater systems statewide, fast-tracking the funding after a wave of cyberattacks disrupted utility operations across at least seven states and federal standards efforts remain stalled. First seen on govinfosecurity.com Jump…
-
Google’s Cyber Threat Actor Naming System Ditches Jargon, Makes Intelligence More Actionable
A cyber threat actor by any other name”¦can probably be found in Google Threat Intelligence Group’s new taxonomy for tracking threat actors. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/googles-cyber-threat-actor-naming-system-ditches-jargon-makes-intelligence-more-actionable/
-
How volunteer cyber experts are helping protect rural water systems
A first-in-the-nation program is seeing promising results as it charts a path for supporting the U.S.’s most vulnerable infrastructure. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/water-cybersecurity-def-con-franklin-outcomes/826517/
-
TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely
TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device. This vulnerability is tracked as CVE-2026-12935 and has a CVSS v4.0 score of 8.7, categorized as high. TP-Link TL-WR940N Router Flaw According…
-
Escape joins OpenAI’s Trusted Access for Cyber (TAC) to advance AI-powered offensive security
We’ve been approved for OpenAI’s Trusted Access for Cyber preview. For years we’ve been building toward one idea: offensive security that runs continuously inside engineering, instead of arriving twice a year as a PDF nobody reads past the executive summary. Business-logic DAST first, then First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/escape-joins-openais-trusted-access-for-cyber-tac-to-advance-ai-powered-offensive-security/
-
How to Quantify Cyber Risk: A Practical Guide – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-to-quantify-cyber-risk-a-practical-guide-kovrr/
-
North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names
North Korea’s national antivirus appears to have quietly pivoted to ClamAV’s open”‘source engine, recompiled it, and shipped it under four different domestic product names underscoring Pyongyang’s reliance on foreign code to secure tightly controlled networks while obscuring the software’s true origin. ClamAV is a widely used open”‘source antivirus engine maintained by the Cisco Talos team,…
-
The OpenAI Hack Shows the Genie Is Out of the Bottle
This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company. The story is kind of wild. OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6. In particular, it…
-
Securing AI in the Browser for Enterprises – Kovrr
Articles related to cyber risk quantification, cyber risk management, and cyber resilience. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/securing-ai-in-the-browser-for-enterprises-kovrr/

