Tag: cyber
-
Cyber Command plans Silicon Valley office to drive innovation
The outpost will have its own director, though no one has yet been named for the post, and support the command’s nascent Cyber Warfare Innovation Center (CIWC). First seen on therecord.media Jump to article: therecord.media/cyber-command-plans-silicon-valley-office-to-drive-innovation
-
AI Deepfakes Push Banks Beyond Voice Authentication
ABA’s Paul Benda on Why Most Account Takeovers Stem From Scams, Not Hacks. Bank impersonation scams, deepfake audio and video are convincing customers to login and send money to criminals. With authentication methods eroding, banks need continuous risk scoring, passkeys and cyber-fraud collaboration to protect customers, said American Bankers Association’s Paul Benda. First seen on…
-
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that First…
-
Anthropic lost control of Claude in latest AI cyber blunder
Days after two OpenAI frontier AI models conducted their own real-world cyber attacks, Anthropic admits that three of its models went off the rails and hacked external organisations thanks to a “misunderstanding” with one of its technical partners First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646678/Anthropic-lost-control-of-Claude-in-latest-AI-cyber-blunder
-
The Security Interviews: Nicole Darden Ford, Microsoft
As a black woman in the white, male-dominated world of cyber security, Microsoft’s Nicole Darden Ford has worked hard to carve out her space in the room. She talks about developing confidence and self-belief, building community, and leading with humility First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646265/The-Security-Interviews-Nicole-Darden-Ford-Microsoft
-
The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats
Tags: ai, cyber, cyberattack, data, exploit, finance, fraud, government, infrastructure, intelligence, leak, malicious, malware, software, threatThis weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses. First seen…
-
Ransomware Killers Overwrite Security Process Memory Without Terminating Applications
Ransomware operators are increasingly deploying “ransomware killers” that surgically overwrite the memory of security processes instead of simply terminating them, allowing encryption to proceed. At the same time, endpoint tools appear to run normally but are effectively blind. This evolution marks a shift from crude process-killing to stealthy, in”‘memory tampering that targets EDR/AV telemetry, kernel…
-
Critical JetBrains TeamCity Flaw Enables Unauthenticated Remote Code Execution
Tags: access, authentication, cve, cyber, data-breach, flaw, network, remote-code-execution, risk, vulnerabilityJetBrains has revealed a critical security vulnerability in TeamCity On-Premises that enables unauthenticated remote code execution (RCE) on affected servers. This poses a significant risk to CI/CD environments exposed over HTTP(S). The vulnerability, tracked as CVE-2026-63077, affects all supported versions of TeamCity On-Premises and allows attackers with network access to bypass authentication checks and execute…
-
Google Uses AI to Fix 1,072 Chrome Security Vulnerabilities
Google has announced that its AI-assisted security workflows have helped Chrome fix 10,721 security vulnerabilities across Chrome Stable milestones 149 and 150. This number exceeds the total number of bugs patched across the previous 23 milestones combined. In a new report, the Chrome Security Team detailed how large language models are integrated throughout the vulnerability…
-
Healthcare Disruption, Critical Software Flaws, and Exposed PLCs Show How Quickly Cyber Risk Becomes Business Risk
Tags: business, computer, cyber, cyberattack, data-breach, flaw, healthcare, Internet, phone, risk, softwareAnMed temporarily closed 79 of its 106 facilities after a cyberattack disrupted computer systems, phone lines, and internet connectivity. Appointments were postponed, elective procedures faced uncertainty, and the health system had to coordinate care while teams worked to restore access. For a healthcare provider, that kind of disruption reaches far beyond technology. It affects how……
-
ClickFix Campaign Uses EtherHiding to Hide Malware and Exposes DPRK Wallet Trail
ClickFix-style fake macOS updates are now being weaponized with EtherHiding-backed command”‘and”‘control and a DPRK-linked crypto laundering network, turning a routine search click into a full-stack theft operation spanning browser, endpoint, blockchain, and exchange infrastructure. Instead of traditional web C2, the implant resolves its live command”‘and”‘control endpoints from Ethereum smart contracts, a takedown”‘resistant pattern known as…
-
BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting of enterprise Linux environments. Originally published on GitHub with Chinese-language documentation, BlueShell has seen limited but consistent abuse by China-based threat actors, including…
-
Recon-Only SSH Attack Leaves No Malware but Signals a Second-Stage Intrusion
Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively grading host hardware for cryptomining suitability, then exiting without dropping a single binary. Cowrie, which exposes a realistic fake Linux shell and records full command transcripts, logged a connection from 91.92.40.13 that…
-
PHP Patches 3 Security Flaws Enabling SQL Injection, Memory Corruption and DoS Attacks
PHP maintainers have released security updates to address three vulnerabilities affecting the PostgreSQL, BCMath, and Phar extensions. These vulnerabilities could potentially lead to SQL injection attacks, out-of-bounds memory writes, and denial-of-service attacks in vulnerable applications. The issues impact several actively maintained PHP release branches and have been resolved in versions PHP 8.2.338.2, 8.3.338.3, 8.4.248.4, and…
-
Chinese-Speaking Hacker Uses DeepSeek Agent to Launch Autonomous Cyberattacks
Chinese-speaking threat actor “knaithe” (aka KnYuan) has been caught running an AI-enabled autonomous attack stack built around DeepSeek and the Hermes Agent framework, proving that large language models can now drive end”‘to”‘end offensive operations with minimal human oversight. Hermes provided terminal access, skills orchestration, and Model Context Protocol (MCP) integrations. At the same time, DeepSeek…
-
ShutterGap Exposes Millions of Misconfigured AWS Resources to Attackers
A cloud-security blind spot known as Cloud ShutterGap, which involves millions of AWS resources being briefly exposed to the public before being removed, often within minutes. These short-lived misconfigurations can include Amazon RDS and DocumentDB snapshots, Amazon Machine Images (AMIs), and AWS Systems Manager (SSM) documents that contain sensitive organizational data. ShutterGap Exposes Millions of…
-
Astaroth Banking Trojan Adds WhatsApp Web Spambot to Spread Malware Across Brazil
Astaroth operators have expanded their Brazilian banking malware operations by weaponizing a new WhatsApp Web spambot module that turns infected hosts into automated malware relays, marking a significant evolution of the LATAM e-crime ecosystem. Traditionally propagated via email and archive-based phishing, recent campaigns such as STAC3150 and the “Boto Cor-de-Rosa” operation shifted distribution to WhatsApp…
-
CosmosEscape Vulnerability Enables Full Takeover of Azure Cosmos DB Databases
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database, including potentially those managed internally by Microsoft. The issue specifically affected the service’s Gremlin API. It exposed a cross-tenant attack path that could bypass customer network isolation controls. CosmosEscape Vulnerability According…
-
OctLurk and SilkLurk Backdoors Target Central Asian Governments in Cyberespionage Campaign
OctLurk and SilkLurk are highly customized, memory”‘resident backdoors used in an ongoing cyberespionage campaign against government and critical”‘sector networks across Central Asia and Syria, operated by a Chinese”‘speaking threat actor but not yet linked to a known APT. Active since January 2025, the operation leverages victim”‘specific loaders, multi”‘plugin frameworks, and shared infrastructure, along with Linux”‘focused…
-
Aviation cyber risk sits on the ground, the blindness sits in the air
In this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/31/eliran-almong-cyviation-aviation-cyber-risk/
-
CISA Urges Water Utilities to Remove Publicly Exposed PLCs From the Internet
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert to the Water and Wastewater Systems (WWS) Sector due to a significant rise in cyber threat activity targeting internet-exposed programmable logic controllers (PLCs). Released on July 30, 2026, the advisory urges critical infrastructure owners, operators, and system integrators to immediately identify and…
-
The Recovery Illusion
When a cyber threat hits the headlines, the instinct is always the same. Organizations like to spend more, add another tool, and tighten the audit schedule so the box stays checked. But when ransomware hits a company that did all of that, the result usually still looks like chaos. Teams scramble and find out the..…
-
Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure. First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/minnesota-water-utility-attacks-expose-sector-cyber-risks
-
Annual search for UK’s unsung cyber heroes kicks off
Tags: cyberThe organisers of the annual Security Serious Unsung Heroes Awards call for nominations for this year’s edition First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646559/Annual-search-for-UKs-unsung-cyber-heroes-kicks-off
-
JFrog Patches Flaws Behind OpenAI Models’ Escape
Artifactory Bugs Helped Models Reach Hugging Face Production. JFrog patched previously unknown flaws in self-hosted Artifactory after OpenAI models used them to escape a cyber test environment and reach Hugging Face production. The repository software is run by more than 7,500 DevOps teams, including most Fortune 100 companies. First seen on govinfosecurity.com Jump to article:…

