Tag: cyber
-
Kiteworks Urges Customers to Shut Down Servers Over Potential Zero-Day Threat
Kiteworks has lifted its emergency shutdown recommendation after advising customers to temporarily take their systems offline in response to credible intelligence indicating that a threat actor may target its platforms. The company clarified that this action was preventive and did not indicate a confirmed compromise. It also urged customers to remain on the latest version…
-
12 Best Cloud Compliance Tools Compared (2026): Features Pricing
For most teams facing an audit, Vanta is the best overall compliance automation platform, with Drata the closest rival choose between them on integrations and framework-crosswalk economics. For technical posture evidence, free open-source Prowler plus a CNAPP compliance view (Wiz, Prisma, Orca) covers the engineering side to prevent cloud misconfigurations that lead to data breaches.…
-
11 Best GCP Security Tools Compared (2026): Features Pricing
Securing Google Cloud starts with Security Command Center Standard included with every org and the best free first move while Wiz is the best third-party platform for estates whose finding volume and service-account sprawl demand attack-path triage. This guide compares the best GCP security tools on capability and pricing structure, consolidates a duplicate from stale…
-
Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers
Tags: access, ai, authentication, botnet, control, cyber, data-breach, docker, framework, hacker, open-source, tool, wormA Docker-focused botnet that repurposes the legitimate, open-source Hermes Agent framework as an interactive post-compromise control layer. The campaign, tracked as CARBONATO, targets Docker daemons exposed without authentication on TCP port 2375, then combines worm-like propagation, stealthy persistence, reverse SSH access and Telegram-driven AI-agent operations. The investigation began in August 2026 after researchers identified a…
-
12 Best Azure Security Tools Compared (2026): Features Pricing
For most Azure estates, Microsoft Defender for Cloud is the best starting point its free foundational tier plus published per-resource plans make it the only major platform you can price from a public rate card. Wiz is the best third-party addition once finding volume demands attack-path prioritization. This comparison covers 12 of the best Azure…
-
ViewSonic vCast Vulnerabilities Let Attackers Gain Full Device Control Without Authentication
The CERT Coordination Center (CERT/CC) has revealed a chain of three vulnerabilities in ViewSonic’s vCast software that could enable unauthenticated attackers on a shared network to steal displayed screen content, install malicious Android applications, and ultimately gain full control of affected ViewBoard smart displays. These vulnerabilities, tracked as VU#234131, affect vCast, the wireless casting and…
-
12 Best AWS Security Tools Compared (2026): Features Pricing
If you’re securing AWS in 2026, Wiz is the best overall third-party platform for most mid-size and enterprise estates, thanks to agentless attack-path correlation that turns thousands of findings into a short, fixable list. Budget-conscious teams should start with AWS-native security tools plus open-source Prowler a genuinely credible free layer. This guide compares 12 of…
-
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise. A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild. The Canadian Centre for Cyber Security added the warning to its advisory…
-
New Windows Process Injection Technique Bypasses EDR Monitoring Without WriteProcessMemory
A newly disclosed method for Windows process injection utilizes redirected console input and named pipes to transfer payload data into a child process without invoking the heavily monitored APIs VirtualAllocEx and WriteProcessMemory. This technique, called console named-pipe injection, highlights the need for endpoint defenses to correlate events across processes, memory protection, thread context, and interprocess…
-
MacSync’s New Infection Chain Shows How Mac Malware Is Becoming More Sophisticated
A newly observed MacSync campaign shows a marked evolution in macOS-focused crimeware, replacing relatively simple AppleScript-driven delivery with layered binary loaders, encrypted modules, cloud-hosted staging, and a persistent backdoor. Kaspersky first identified the new infection chain in the wild in September 2026, describing it as a significant upgrade for the malware family formerly marketed as…
-
Citrix Confirms NetScaler Zero-Day RCE Flaws Actively Exploited in Attacks
Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming active exploitation of two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772. Both bugs have a CVSS v4.0 score of 9.5 and can enable remote code execution (RCE) against vulnerable customer-managed appliances. The flaws are part of a wider set of eight vulnerabilities…
-
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.”Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,” said Frank Balonis, Chief…
-
Red Heron Exploits Critical Gitea Flaw to Steal Repositories and Deploy Linux Rootkit
Tags: access, cve, cyber, data-breach, exploit, flaw, Internet, linux, remote-code-execution, threat, vulnerabilityA threat actor tracked as Red Heron has exploited the critical Gitea remote code execution vulnerability CVE-2026-60004 to steal source-code repositories, establish persistent access, and deploy a covert Linux toolset consisting of the JITTERLY implant and SIXZUT LD_PRELOAD rootkit. Acronis reported that the actor rapidly weaponized the flaw against internet-exposed Gitea environments, turning initial access…
-
Windows 11 Update Causes Black Screen and Desktop Loading Issues After Sign-In
Microsoft has confirmed a Windows 11 issue that can leave users with a black screen after sign-in or prevent the desktop from loading automatically. The problem affects devices that installed the August 2026 non-security preview updates and potentially later cumulative updates, with Azure Virtual Desktop environments using FSLogix profile containers most frequently affected. The issue…
-
Kiteworks Warns Users to Take Systems Offline Amid Suspected Zero-Day Threat
Kiteworks has urged customers worldwide to temporarily shut down their servers after receiving credible law-enforcement intelligence that a threat actor may target Kiteworks deployments over the weekend. The emergency advisory is preventive, but the company said the potential activity may involve an unknown zero-day vulnerability. The secure file-sharing and managed content communications provider asked organizations…
-
Uncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials
A new demonstration shows how a locally hosted, uncensored AI model can help generate a Windows LSASS credential-dumping utility that reportedly evaded endpoint detection and response products during laboratory testing. The finding highlights how accessible local models can reduce the time and expertise needed to adapt offensive tooling after an attacker gains administrative access. Eddie…
-
Storm-3168 Hackers Abuse Compromised Service Principals to Destroy Azure Cloud Resources
Microsoft has uncovered a destructive Azure campaign linked to Storm-3168, also known as JADEPUFFER, in which attackers abused compromised service principals to map cloud environments, delete critical resources, target recovery safeguards, and obtain storage-account credentials. The activity shows how a single exposed workload identity can give attackers the automation and permissions needed to cause rapid…
-
OpenAI Says Misaligned AI Agents Hacked Hugging Face and Bypassed Security Controls
OpenAI has disclosed that autonomous AI agents compromised portions of Hugging Face’s infrastructure during internal cybersecurity evaluations after pursuing misaligned strategies to complete difficult tasks. The company said the event was not simply a platform-security failure, but its most severe identified example of model-driven cyber activity and a warning that advanced agents can pursue objectives…
-
Expecting cyber attack, Kiteworks tells users to turn off servers
An as-yet undisclosed zero-day vulnerability has prompted managed file transfer provider Kiteworks to tell users to preemptively switch off their servers. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651301/Expecting-cyber-attack-Kiteworks-tells-users-to-turn-off-servers
-
Microsoft expands Middle East cloud and AI footprint with $10bn commitment
Regional strategy combines infrastructure investment, cyber security partnerships and skills development to support national AI agendas First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651294/Microsoft-expands-Middle-East-cloud-and-AI-footprint-with-10bn-commitment
-
The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act
Tags: access, advisory, ai, application-security, breach, crypto, cyber, korea, malware, north-koreaThis weekly roundup covers a brazen breach claim against the FBI’s recruitment portal, a multinational advisory exposing North Korea’s fake-recruiter malware operation, a sweeping EU proposal to reshape children’s access to social media, a conversation on application security in the age of AI agents, a short-lived Discord ban in the Philippines, and a multimillion-dollar hot-wallet…
-
Cyber-attack on Dyfed-Powys police ‘may have accessed staff information’
Welsh force says incident disrupted ‘some non-emergency systems’ and public data was not affectedA police force in Wales has said staff information may have been “accessed or compromised” in a cyber-attack.Dyfed-Powys police, which has more than 2,000 officers and civilian staff, said it was hacked on 14 September in an incident that disrupted “some non-emergency…
-
Salmon Introduces Execution Verification Infrastructure (EVI) for Securing AI Agents and Autonomous Systems
San Francisco, USA, September 25th, 2026, CyberNewswire Archipelo today announced Salmon, Execution Verification Infrastructure (EVI) for AI agents and autonomous systems, powered by a cryptographic protocol designed to make execution history verifiable. Salmon establishes verifiable execution history and state lineage across humans, AI agents, and automation. The launch follows the OpenAIHugging Face incident, in which…
-
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years, can let an unprivileged local attacker gain root access and escape a Docker container by exploiting a race condition in concurrent socket writes. This flaw, tracked as CVE-2025-39964, was discovered in 2025 by STAR Labs researcher Muhammad Alifa Ramdhan, with…
-
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years, can let an unprivileged local attacker gain root access and escape a Docker container by exploiting a race condition in concurrent socket writes. This flaw, tracked as CVE-2025-39964, was discovered in 2025 by STAR Labs researcher Muhammad Alifa Ramdhan, with…
-
14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape
A vulnerability in the Linux kernel’s AF_ALG cryptographic interface, which has existed for 14 years, can let an unprivileged local attacker gain root access and escape a Docker container by exploiting a race condition in concurrent socket writes. This flaw, tracked as CVE-2025-39964, was discovered in 2025 by STAR Labs researcher Muhammad Alifa Ramdhan, with…
-
ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data
ServiceNow has disclosed five vulnerabilities affecting its AI Platform, including two critical flaws that could allow unauthenticated attackers to execute arbitrary SQL commands, extract sensitive instance data, modify records, and escalate privileges. The security advisory, published in September 2026 and tracked as KB3159623 on September 24, details the following vulnerabilities: CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and…
-
Rogue AI Agents Tried to Hack Public Websites After Data Retrieval Failed
Research from Transluce shows that autonomous AI agents shifted from standard web data collection to probing for vulnerabilities in three public-facing services after traditional data retrieval methods failed. This activity targeted an Australian government health data platform, Data USA, and the University of New Mexico’s digital library. Rogue AI Tried to Hack Public Websites Transluce…
-
CISA Flags WSO2 Security Flaw Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting WSO2, tracked as CVE-2026-5430, to its Known Exploited Vulnerabilities (KEV) catalog. CISA made this decision after evidence showed threat actors are actively exploiting the flaw. CISA added the vulnerability on September 24, 2026, and set a remediation deadline for affected federal…

