Tag: cyber
-
Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks
Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat Intelligence Group (GTIG) on July 3, 2026. This action is part of an ongoing campaign to…
-
How Dragos Acquisition Expands Accenture’s OT Security Reach
Joint Accenture-Dragos Platform Adds OT, Threat Intelligence and Incident Response. Accenture says its acquisition of Dragos combines managed security services with leading OT threat intelligence, asset discovery and incident response capabilities, helping industrial organizations strengthen defenses as AI adoption and IT-OT convergence increase cyber risk. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-dragos-acquisition-expands-accentures-ot-security-reach-a-32148
-
Launch of UK’s National Cyber Action Plan delayed amid Labour leadership crisis
Tags: cyberThe plan had been due for publication on Monday, the sources said. It has been postponed amid the uncertainty over the governing Labour Party’s leadership contest, which opens July 9. First seen on therecord.media Jump to article: therecord.media/launch-of-uk-national-cyber-action-plan-delayed
-
US cyber agency warns over forgotten SharePoint flaw
An RCE vulnerability in Microsoft SharePoint that was mistakenly omitted from the May Patch Tuesday bulletin is being exploited in the wild, says Cisa. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645307/US-cyber-agency-warns-over-forgotten-SharePoint-flaw
-
Most cybersecurity workers have been told to conceal a breach, report finds
The security firm Bitdefender’s annual survey also found that U.S. companies were simultaneously more confident and more strained on cyber defense than foreign peers. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/data-breach-coverups-ai-bitdefender/824331/
-
Safe Events Start With Threat Intel & Digital Security
Planning ahead to defend against cyber threats is the work that keeps events uneventful. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/safe-events-threat-intel-digital-security
-
Opera Browser Adds Native Paste Protect to Stop Clipboard Hijacking and Code Injection Attacks
Opera has announced a new native security feature called “Paste Protect,” which aims to combat clipboard hijacking and command injection attacks directly within the browser. This marks a significant advancement in proactive endpoint protection at the user interaction level. Introduced on July 2, 2026, the feature is enabled by default. It addresses a rapidly growing…
-
Hackers Abuse ScreenConnect Remote Access Tool to Deploy AsyncRAT Through Fake Installers
A wide-reaching campaign in which attackers abused the legitimate remote administration tool ScreenConnect to deploy AsyncRAT via faux software installers. The infection chain leverages trusted binaries, DLL sideloading, reflective loading and process hollowing to achieve stealthy persistence and remote control an approach that capitalizes on the very trust enterprises place in remote management tools. The…
-
Phishing Campaign Uses Fake Invoice PDF to Drop AsyncRAT, VenomRAT, and XWorm
A sophisticated phishing campaign that uses a fake invoice PDF to mask the delivery of multiple remote access trojans primarily AsyncRAT, but also VenomRAT and XWorm via layered shortcuts. TryCloudflare quick tunnels, and disguised Python packages. The campaign echoes an August attack previously analysed by X”‘Labs and reinforces the group’s 2025 Future Insights prediction that…
-
950 Oracle E-Business Suite Instances Exposed as CVE-2026-46817 Attacks Observed in the Wild
Around 950 internet-facing Oracle E-Business Suite (EBS) instances have been identified as exposed following enhanced scanning efforts. At the same time, active exploitation attempts tied to CVE-2026-46817 have already been observed in the wild. The findings were disclosed by The Shadowserver Foundation, which recently expanded its fingerprinting capabilities through domain-based scanning in collaboration with Validin.…
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
CISA Adds Actively Exploited Microsoft SharePoint Vulnerability to KEV Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has recently added a newly discovered vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition highlights the active exploitation risks present in enterprise environments. The vulnerability falls under the CWE-502 (Deserialization of Untrusted Data) category, allowing an authenticated attacker to…
-
Hackers Use Geofenced Webpages to Deliver Ousaban Banking Trojan in Spain and Portugal
A targeted phishing campaign delivering the Ousaban banking Trojan to users in Spain and Portugal, notable for its use of geofenced webpages, layered evasion techniques, and a modular delivery chain. The threat actor repurposes a playbook seen previously in Brazil but has refined access controls and server-side checks to ensure malware reaches only the intended…
-
ValleyRAT Uses RC4 Encryption, Donut Shellcode, and rundll32 Injection for Stealth
A recent surge in ValleyRAT activity that combines RC4-encrypted payloads, Donut-generated shellcode, and in-memory execution via suspended rundll32 processes to evade detection. First named by Proofpoint in 2023, ValleyRAT continues to evolve: LevelBlue’s telemetry shows a marked increase in successful detections beginning May 2025 and accelerating into 2026. The threat now presents through two primary…
-
Apple Hide My Email Vulnerability Lets Attackers Reveal Users’ Real Email Addresses
Apple’s Hide My Email privacy feature currently faces a significant flaw that may expose users’ real email addresses, compromising one of iCloud+’s core anonymity protections. According to 404 Media and independent tests, this issue has reportedly remained unaddressed for over a year since it was reported to Apple. Apple Hide My Email Vulnerability Hide My…
-
Claude Mythos und GPT Cyber verändern die Cybersicherheit – Spezialisierte KI-Modelle übernehmen komplette Angriffsketten
First seen on security-insider.de Jump to article: www.security-insider.de/ki-modelle-angriffsketten-claude-mythos-cybersicherheit-a-dcf8a81beef48a33a578e3428b080c00/
-
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted into a production MySQL/Nacos deployment to carry out a destructive, database-focused extortion playbook without a…
-
ChocoPoC Campaign Abuses GitHub PoC Repositories to Steal Browser Credentials
A coordinated supply-chain campaign has been weaponizing GitHub proof-of-concept (PoC) repositories to compromise vulnerability researchers and penetration testers, delivering a stealthy Python Remote Access Trojan (RAT) dubbed “ChocoPoC.” The lure is simple and effective: newly disclosed high-severity CVEs create urgency for fast PoC and scanner module development. Adversaries create seemingly legitimate PoC repositories that include…
-
Attackers Downgrade WDigest Protection to Dump Plaintext Credentials With Mimikatz
An incident that began with innocuous enumeration commands but quickly escalated into a focused, multi-stage effort to impair detection and extract credentials. The intruder uploaded a steganographic webshell to an IIS server, used the process w3wp.exe to run OS reconnaissance such as whoami, and then deployed an extensive defence-impairment script (i.bat) that prefaced a credential-dump…
-
LSHIY Password Spray Attack Hits Microsoft 365 Accounts With 81 Million Login Attempts
A large-scale password spray campaign linked to the infrastructure provider LSHIY LLC has targeted Microsoft 365 environments, resulting in over 81 million login attempts. This campaign has led to at least 78 confirmed account compromises across 64 organizations between June 12 and June 26, 2026. According to researchers from Huntress, the activity primarily originates from…
-
Critical Cursor IDE Flaws Let Attackers Execute Code via Zero-Click Prompt Injection
Two significant remote code execution (RCE) vulnerabilities in the widely used Cursor ID expose developers to zero-click attacks driven by prompt injection. These vulnerabilities, tracked as CVE-2026-50548 and CVE-2026-50549, collectively known as >>DuneSlide,<< carry a CVSS score of 9.8. They demonstrate how development environments powered by large language models (LLMs) can unintentionally increase the attack…
-
FortiBleed Campaign Linked to INC and Lynx Ransomware Operations
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes, significantly increasing the threat posed by exposed firewall infrastructure. FortiBleed Campaign Linked to INC and…
-
Scattered Spider Hacker Arrested in Finland and Extradited to U.S. Over Cyber Intrusion Charges
U.S. authorities have announced federal charges against an alleged member of the notorious cybercriminal group Scattered Spider, following his arrest in Finland and extradition to the United States. The defendant, identified as 19-year-old Peter Stokes, a dual national of the U.S. and Estonia, is accused of participating in a widespread conspiracy involving cyber intrusions and…
-
Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed
Oracle E-Business Suite flaw CVE-2026-46817 is under active attack, with about 950 vulnerable internet-facing instances still exposed. This week, Defused Cyber researchers warned that a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being actively exploited. The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable…
-
Ransomware-Proof Backup: 7 Strategies for Enterprise IT Teams
Ransomware-proof backup planning helps IT teams protect clean data copies, isolate storage, test recovery, and keep operations running after cyber attacks fast. First seen on hackread.com Jump to article: hackread.com/ransomware-proof-backup-strategies-enterprise-it-teams/
-
Turning Indicators into Intelligence in OpenCTI with Criminal IP
Torrance, California, USA, July 1st, 2026, CyberNewswire Cyber threat intelligence becomes more valuable when indicators are enriched with context that supports investigation, correlation, and decision-making. Through the Criminal IP integration with OpenCTI, security teams can transform IP addresses, domains, and URLs from isolated indicators into structured intelligence within the OpenCTI knowledge graph. The integration automatically…
-
Mitigating Attacks Before They Impact Infrastructure: Link11 provides next generation network DDoS protection
Frankfurt am Main, Deutschland, July 1st, 2026, CyberNewswire Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing complexity of modern network attacks. Today’s DDoS attacks are not just simple volume or protocol attacks anymore. They can originate…

