Tag: cyber
-
Apache Tomcat Vulnerabilities Let Attackers Bypass Authentication and Security Constraints
The Apache Software Foundation has disclosed two security vulnerabilities in Apache Tomcat that can lead to authentication bypass and improper enforcement of security constraints. These vulnerabilities impact various deployments across enterprise environments. They are tracked as CVE-2026-55957 (Important severity) and CVE-2026-55956 (Moderate severity) and affect multiple supported versions of Tomcat. If left unpatched, these issues…
-
Hack The Box expands its cyber readiness platform for the AI era
First seen on scworld.com Jump to article: www.scworld.com/news/hack-the-box-expands-its-cyber-readiness-platform-for-the-ai-era
-
Hack The Box expands its cyber readiness platform for the AI era
First seen on scworld.com Jump to article: www.scworld.com/news/hack-the-box-expands-its-cyber-readiness-platform-for-the-ai-era
-
Kremlin Expands AI-Backed Campaigns Across Europe, US
GenAI Is Accelerating Propaganda, Planning and Content Creation. Google Threat Intelligence Group says Russia is expanding AI-enabled influence operations beyond Ukraine to target the European Union and NATO, relying on proxy networks, hacktivists and coordinated cyber campaigns to undermine Western cohesion while reducing attribution. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/google-kremlin-expands-ai-backed-campaigns-across-europe-us-a-32120
-
Medtronic Notifying Patients Affected by Data Theft Hack
Ransomware Gang ShinyHunters Gang Claimed It Stole 9M Records From Device Maker. Medical device maker Medtronic has begun notifying a yet undisclosed number of patients that their information, including health records and Social Security numbers – was compromised in an April cyber incident. ShinyHunters had earlier claimed to steal more than 9 million of the…
-
Why Cyber Resilience Must Outpace AI-Driven Threats
Former National Cyber Director Chris Inglis Calls for Coalition Defense Strategy. Cybersecurity leaders must shift from information sharing to true collaboration as AI accelerates ransomware and nation-state threats. Halcyon’s Chris Inglis explains why resilience, coalition defense and human accountability will help security teams outpace increasingly sophisticated attackers. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-resilience-must-outpace-ai-driven-threats-a-32119
-
Why Identity Security Is Your Cyber Career Entry Point
As AI reshapes cybersecurity workflows, John Paul Cunningham, CISO at SIlverfort, says the technology is creating opportunities rather than eliminating jobs, and there are more ways than ever to break into the essential field. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/identity-security-cyber-career-entry-point
-
Nissan Traces Data Breach to PeopleSoft Zero-Day Exploit
Extortionists Add National Association of Insurance Commissioners to Breach List. Japanese automotive giant Nissan and the U.S. National Association of Insurance Commissioners are the latest organizations to confirm they fell victim to cyber extortionists who recently wielded a zero-day exploit against Oracle PeopleSoft, leading to the theft of data. First seen on govinfosecurity.com Jump to…
-
NDSS Symposium Heads to Seoul in 2027 to Expand Global Cybersecurity Collaboration
DC, United States, June 30th, 2026, CyberNewswire The Internet Society today announced that 2027 Network and Distributed System Security (NDSS) Symposium will take place in Seoul, Republic of Korea, from 2226 March 2027. Recognized as one of the world’s top four cybersecurity research conferences, the NDSS Symposium brings together hundreds of top scholars, academics, and…
-
Reflectiz to Host Webinar, Joined by Taboola, on Securing Third-Party Marketing in the AI Era
Boston, Massachusetts, June 30th, 2026, CyberNewswire Reflectiz, the web exposure management platform, today announced a live webinar with Taboola, >>Securing Third-Party Marketing in the AI Era,<< taking place July 8 at 9 AM EDT / 3 PM CEST. Every marketing vendor a company approves can silently introduce third and fourth-party scripts that no security team…
-
Reflectiz to Host Webinar, Joined by Taboola, on Securing Third-Party Marketing in the AI Era
Boston, Massachusetts, June 30th, 2026, CyberNewswire Reflectiz, the web exposure management platform, today announced a live webinar with Taboola, >>Securing Third-Party Marketing in the AI Era,<< taking place July 8 at 9 AM EDT / 3 PM CEST. Every marketing vendor a company approves can silently introduce third and fourth-party scripts that no security team…
-
AppViewX Launches Global Partner Program Amid Rising Demand for Machine and Agent Identity Security
New York, United States, June 30th, 2026, CyberNewswire Building on the momentum of its Agent Identity Security launch, AppViewX invests in partner success through enhanced enablement and co-selling support AppViewX, the only machine and agent identity security company built for the AI and quantum era, today announced the launch of its first global Partner Program.…
-
Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution
Progress’s Kemp LoadMaster, a widely deployed edge load balancer and ADC, is at the center of a critical pre-authentication Remote Code Execution (RCE) vulnerability tracked as CVE-2026-8037. The flaw allows unauthenticated attackers with access to the device API to run arbitrary shell commands by exploiting an uninitialized-memory/string-termination bug in LoadMaster’s API handling. Given LoadMaster’s position…
-
What the Numbers Say About FIFA 2026 Cyber Risk
The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-planned, months out, across three sectors and at least ten languages.Check Point Exposure Management published the FIFA World Cup 2026 Cyber…
-
BumbleBee and AdaptixC2 Deliver Akira Ransomware Through Bing SEO Poisoning
BumbleBee and AdaptixC2 are being used in a highly efficient intrusion chain that starts with Bing SEO poisoning and ends with Akira ransomware deployment, showing how trusted search traffic is now being turned into an enterprise compromise vector. The campaign is notable not for novelty in any single stage, but for how tightly each stage…
-
PoC Released for NTLM reflection bypass Vulnerability that Emanbles SYSTEM Access on Windows Server
A proof-of-concept has been published that bypasses Microsoft’s mitigation for the NTLM reflection vulnerability tracked as CVE-2025-33073 and allows escalation to NT AUTHORITY\SYSTEM on Windows Server. The exploit leverages two conceptual weaknesses left unaddressed by the original patch: the mitigation was limited to the SMB client path, and recent SMB features let attackers coerce privileged…
-
SystemBC Malware Turns Windows Machines Into SOCKS5 Proxies for Ransomware Attacks
SystemBC (also tracked as Coroxy) remains a versatile and persistent Windows malware family that operators routinely deploy to convert compromised hosts into SOCKS5 proxy gateways and to maintain remote access for follow-on operations. First observed as a payload in exploit kits around 20182019, SystemBC has evolved into a widely traded commodity tool used by multiple…
-
Multiple AirDrop and Quick Share Vulnerabilities Allow Attackers to Crash Devices
Tags: access, android, apple, attack, authentication, cyber, data-breach, flaw, google, vulnerability, windowsA new technical analysis has exposed six proximity-transfer flaws across Apple AirDrop, Samsung Quick Share on Android, and Google Quick Share for Windows, showing that device-sharing stacks still contain fragile pre-authentication attack surfaces that can be abused from wireless range. The findings include three AirDrop access crashes, two Quick Share protocol bypasses, and one Windows…
-
Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments
Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical usability refinements that will matter to both pentesters and platform maintainers. The release emphasizes polish and performance rather than headline-grabbing features: GNOME advances to version 50 and KDE Plasma to 6.6.…
-
Boss Scam Uses DLL Sideloading to Hijack WhatsApp Web and Defraud Enterprises
The new “Boss Scam” is a sharp escalation in CEO fraud: attackers now combine impersonation, Windows DLL sideloading, and WhatsApp Web session theft to turn trusted executive channels into fraud infrastructure. The campaign was highlighted in advisories tied to India’s I4C and NCTAU, which warned that attackers pose as regulators or senior bosses, deliver malicious…
-
UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks
SonicWall records 264,000 events in first five months of 2026 as UK hospitals come under siege First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uk-healthcare-tenfold-increase/
-
Japan Hotel Industry Targeted With TONResolver RAT and Guest Complaint Phishing Emails
Japan’s hotel sector is the latest target of a sophisticated phishing and remote-access trojan (RAT) campaign that leverages guest-complaint lures and an unusual resilience mechanism: a TON blockchainbased dead-drop resolver. Beginning in late May 2026, attackers sent highly targeted emails to Booking.com partner properties in Japan with subject lines such as “é‡è¦ï¼šã‚²ã‚¹ãƒˆæ»žåœ¨ãƒ¬ãƒ“ューä¾é ¼” (Important: Guest Stay…
-
Mustang Panda Targets India’s Government and Energy Sectors With ZOHOMURK and MINIRECON
Two concurrent espionage campaigns by Mustang Panda targeting Indian government and energy-sector organisations, deploying a novel malware suite that includes SHARDLOADER, MINIRECON and ZOHOMURK. The intrusions, observed in June 2026, focused on hydropower entities and government offices engaged in MOUs with Taiwanese institutions, using geopolitically themed lures and weaponised archives that sideload malicious DLLs via…
-
Malicious Chromium Extension Spoofs Perplexity AI to Hijack Browser Searches
A malicious Chromium extension that impersonated the Perplexity AI brand to intercept browser searches and capture keystrokes before delivering users to legitimate search results. The extension, listed as “Search for perplexity ai” (ID flkebkiofojicogddingbdmcmkpbplcd, version 2.2), used Manifest V3 capabilities, declarativeNetRequest (DNR) rules, and a typosquatted domain perplexity-ai[.]online to create a stealthy two”‘hop interception pipeline…
-
Mistic Malware Blends Into Microsoft Endpoint Components Using Malicious EndpointDlp.dll
A newly identified Windows backdoor, dubbed Mistic, that has been observed in intrusions since April 2026 and appears designed for stealthy, long-term access. The malware uses DLL sideloading, in-memory execution, and self-deletion to blend into enterprise environments and minimize forensic traces. Mistic is introduced via a DLL sideloading chain that abuses a legitimate executable named…
-
U.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App Attacks
The U.S. offers up to $10M for information on Russian hackers targeting Signal and WhatsApp accounts of officials and journalists. The U.S. government is offering rewards of up to $10 million for information leading to the identification of members of the Russian-linked groups UNC5792 and UNC4221. The hackers target government officials, military personnel, journalists, and…
-
Austria Urges Anthropic to Move to EU to Avoid US Controls
Mythos and Fable Export Controls Deprive EU of ‘Cutting-Edge Innovation,’ Security. Stung by the Trump administration’s export controls on Anthropic’s most powerful cyber-capable models, Mythos and Fable, the Austrian government wants Europe to tempt Anthropic into moving across the Atlantic. Austria told the EU sovereignty leader that we must act now. First seen on govinfosecurity.com…
-
British public won’t tolerate cyber disruption any more
The British public’s tolerance for cyber disruption, particularly at high-profile organisations such as retailers, is wearing thin, according to a TalkTalk Business study First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645293/British-public-wont-tolerate-cyber-disruption-any-more
-
US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp
Russia-linked hacking groups tracked as UNC5792 and UNC4221 have socially engineered their way into the messaging accounts of government officials. First seen on therecord.media Jump to article: therecord.media/10million-reward-us-russian-hackers-unc4221-unc5792
-
Splunk Secure Gateway RCE Vulnerability Lets Low-Privileged Attackers Execute Arbitrary Code
A newly disclosed high-severity vulnerability in Splunk Secure Gateway (SSG) allows low-privileged authenticated users to achieve remote code execution (RCE) on affected systems, significantly increasing the attack surface for enterprise Splunk deployments. This vulnerability, tracked as CVE-2026-20251, has been assigned a CVSS score of 8.8. It arises from the unsafe deserialization of user-controlled data using…

