Tag: cyber
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Malicious VPN Extensions Turn Browser Users Into Residential Proxy Servers
A cluster of 31 Russian-language Chrome extensions, marketed as “VPN for X” tools, has been discovered using a shared codebase to redirect browser traffic through remotely controlled proxy infrastructure. This ongoing campaign, revealed on September 19, 2026, has affected about 356,000 users, effectively turning their installed browsers into nodes in a residential proxy network. Researchers…
-
Kiteworks lifts shutdown order after incident-free weekend
Tags: cyberKiteworks customers are back up and running after a highly-unusual preemptive shutdown that came amid indications of an impending cyber attack. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651473/Kiteworks-lifts-shutdown-order-after-incident-free-weekend
-
FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
The bureau has not yet publicly confirmed a breach, but has told its agents that their personal information and Social Security numbers were exposed. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/28/fbi-reportedly-declares-cyber-security-incident-after-hackers-steal-agents-personal-data/
-
New Guide from Filigran Highlights the Many Routes Women Take into Cyber Threat Intelligence
A new guide featuring the experiences of 16 women working in cyber threat intelligence (CTI) is challenging the idea that professionals need a conventional technical background to enter the field. Published by threat management company Filigran, Women in CTI: The Careers, Lessons, and Stories Shaping Cyber Threat Intelligence explores career paths spanning marketing, political science,…
-
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
Tags: ai, breach, control, credentials, cyber, cybercrime, data, data-breach, infrastructure, Internet, phishing, toolAn internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assisted automation. Custom command-and-control tooling, phishing resources, stolen credentials, target lists, and internal operator communications. The exposure is notable not only for the scale of the material recovered, but also for its irony. Weeks later, infrastructure attributed…
-
OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face
A newly released forensic investigation has reconstructed how a swarm of about 700 OpenAI evaluation agents allegedly used nearly one million chained URLs to bypass restricted internet access and compromise parts of Hugging Face’s infrastructure. This incident illustrates how seemingly limited web-access capabilities can be combined with third-party services to create a functional execution, command-and-control,…
-
NVIDIA Launches In-Silicon Security Platform to Monitor and Control Autonomous AI Agents
NVIDIA has launched its Open Agent Safety Platform, a security architecture designed for out-of-band monitoring, runtime policy enforcement, and hardware-backed control for autonomous AI agents. This platform combines the open-source NVIDIA OpenShell runtime with NVIDIA Sentry protections on BlueField-4 data processing units (DPUs), aiming to prevent agents from exceeding their authorized access or operating limits.…
-
Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations
Tags: cve, cyber, exploit, extortion, government, healthcare, oracle, technology, threat, vulnerabilityThe ShinyHunters-linked threat cluster tracked as UNC6240 has renewed mass exploitation of Oracle PeopleSoft servers vulnerable to CVE-2026-35273. Expanding beyond its earlier focus on higher education into technology, healthcare, government, transportation, agriculture, and IT services. The campaign demonstrates how quickly financially motivated actors can adapt when organizations rely on perimeter workarounds rather than applying vendor-issued…
-
Microsoft Entra TrustSink Attack Uses Rogue MFA Provider to Steal Passwords
TrustSink, a post-compromise credential-phishing technique that abuses Microsoft Entra External Authentication Methods (EAMs) to place a rogue password prompt inside an otherwise legitimate Microsoft sign-in flow. The attack enables an adversary with elevated tenant privileges to capture plaintext passwords while returning a valid signed token to Entra, allowing the victim’s login to complete without an…
-
670 Jev Domains Registered After Launch as Fake AI Marketplaces Target Users
A surge of lookalike domains targeting users of TypeSafe AI’s newly launched Jev decision model, with roughly 670 “jev”-branded domains obtaining TLS certificates within eight days of the product’s debut. Several sites are already operating as unofficial API storefronts, charging customers up to 11.5 times the official rate while proxying prompts to TypeSafe’s infrastructure. TypeSafe…
-
Lumma, RedLine and Vidar Infostealers Fuel Cloud Credential Theft Campaigns
Tags: api, attack, cloud, credentials, cyber, data-breach, exploit, identity, infrastructure, malware, theft, threatInfostealer malware is increasingly becoming the bridge between a compromised developer workstation and an enterprise cloud environment, with Lumma, RedLine, and Vidar emerging as major threats to credentials, API keys, and active browser sessions. Identity, rather than exposed infrastructure, remains the most valuable cloud attack surface. Attackers no longer need to exploit a public-facing server…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Wachstumsmarkt Cloud-Sicherheit
Der Umsatz mit Cloud-Sicherheitslösungen in Deutschland könnte bis 2030 auf 280 Mio. Euro steigen. Für 2026 rechnen die Expertinnen und Experten der Statista Market Insights mit einem Umsatz von 157 Millionen Euro. Auch innerhalb des gesamten Marktes für Cyber-Sicherheitslösungen gewinnt das Cloud-Segment an Gewicht: Der Anteil steigt von 2,8 Prozent im Jahr 2023 auf 6,1……
-
New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies
A Python-based information stealer that targets data from 17 Chromium-based browsers, alongside Firefox, to harvest saved credentials, payment-card details, browsing history and active session cookies. The malware is delivered through a builder framework that enables operators to generate customized Windows payloads and configure their own data-exfiltration webhook. The archive included a “TokenGrabber Builder” folder containing…
-
Kiteworks Urges Customers to Shut Down Servers Over Potential Zero-Day Threat
Kiteworks has lifted its emergency shutdown recommendation after advising customers to temporarily take their systems offline in response to credible intelligence indicating that a threat actor may target its platforms. The company clarified that this action was preventive and did not indicate a confirmed compromise. It also urged customers to remain on the latest version…
-
12 Best Cloud Compliance Tools Compared (2026): Features Pricing
For most teams facing an audit, Vanta is the best overall compliance automation platform, with Drata the closest rival choose between them on integrations and framework-crosswalk economics. For technical posture evidence, free open-source Prowler plus a CNAPP compliance view (Wiz, Prisma, Orca) covers the engineering side to prevent cloud misconfigurations that lead to data breaches.…
-
11 Best GCP Security Tools Compared (2026): Features Pricing
Securing Google Cloud starts with Security Command Center Standard included with every org and the best free first move while Wiz is the best third-party platform for estates whose finding volume and service-account sprawl demand attack-path triage. This guide compares the best GCP security tools on capability and pricing structure, consolidates a duplicate from stale…
-
Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers
Tags: access, ai, authentication, botnet, control, cyber, data-breach, docker, framework, hacker, open-source, tool, wormA Docker-focused botnet that repurposes the legitimate, open-source Hermes Agent framework as an interactive post-compromise control layer. The campaign, tracked as CARBONATO, targets Docker daemons exposed without authentication on TCP port 2375, then combines worm-like propagation, stealthy persistence, reverse SSH access and Telegram-driven AI-agent operations. The investigation began in August 2026 after researchers identified a…

