Tag: cybersecurity
-
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis.”The portal combined build generation, finance, First seen on thehackernews.com…
-
US House Votes to Extend Cyber Sharing Law for 10 Years
Lawmakers Advance 10-Year Renewal of Key Cyber Law, Setting Up Looming Senate Fight. The U.S. House of Representatives passed a fiscal year 2027 defense authorization bill with a provision extending the Cybersecurity Information Sharing Act of 2015 through 2036. The decade-long renewal faces an uphill climb in the Senate. First seen on govinfosecurity.com Jump to…
-
Russian Espionage Hackers Hit Zimbra With Half-Click Attacks
Tags: attack, cyberespionage, cybersecurity, data, email, espionage, hacker, malicious, russia, update, vulnerabilityViewing Malicious Email in Vulnerable Webmail Client Triggers Data-Stealing Attack. Russian cyberespionage hackers are targeting a vulnerability in Zimbra Collaboration Suite – a patch is available – that enables them to execute a malicious, data- and email-stealing script simply if a user of a vulnerable client opens their email, warn Western cybersecurity agencies. First seen…
-
Ein klarer Weg für Microsoft-Partner – Cybersecurity erfolgreich vermarkten
First seen on security-insider.de Jump to article: www.security-insider.de/microsoft-security-umsatzpotenziale-mittelstand-a-718639b91ba2f13260a14c2f2f874b63/
-
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim’s organization.The vulnerability has been codenamed AgentForger by Zenity Labs. The issue has since been addressed by OpenAI as of June…
-
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
Tags: advisory, apt, cybersecurity, email, exploit, flaw, government, group, infrastructure, international, russiaUS agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT…
-
Top 10 Best 24/7 Security Monitoring Companies in 2026
A comprehensive and proactive security posture is non-negotiable for organizations in 2026. With a rapidly evolving threat landscape and a global shortage of cybersecurity talent, relying on an internal team alone to provide round-the-clock protection is often unfeasible. 24/7 security monitoring companies fill this critical gap by serving as an extension of an organization’s security…
-
Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails
Tags: advisory, cyber, cybersecurity, defense, email, espionage, exploit, government, group, hacker, russia, technology, threat, vulnerability, zero-dayRussian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education,…
-
How AI guardrails are impeding the work of offensive cybersecurity researchers
We spoke with several cybersecurity researchers, who look for unknown vulnerabilities and develop tools to exploit them, about how OpenAI’s and Anthropic’s guardrails affect their work. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/23/how-ai-guardrails-are-impeding-the-work-of-offensive-cybersecurity-researchers/
-
Employees’ shadow AI use is poorly monitored, survey finds
Employee behavior has always presented one of the biggest enterprise cybersecurity challenges. Add AI into the equation, and education and governance become even more critical. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366646095/Employees-shadow-AI-use-is-poorly-monitored-survey-finds
-
Employees’ shadow AI use is poorly monitored, survey finds
Employee behavior has always presented one of the biggest enterprise cybersecurity challenges. Add AI into the equation, and education and governance become even more critical. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366646095/Employees-shadow-AI-use-is-poorly-monitored-survey-finds
-
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: The first flaw added to the KeV…
-
GAO report details scope of cybersecurity regulation overlap
A morass of rules is forcing companies to report the same information multiple times — and sometimes, those rules conflict. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cybersecurity-regulations-overlap-harmonization-gao/826012/
-
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.Accomplish AI, which shared details of the vulnerability with The Hacker News ahead of…
-
New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes
Moonshot AI’s newly unveiled Kimi K3 model is attracting considerable attention in the cybersecurity community after successfully demonstrating its ability to autonomously identify critical vulnerabilities in Redis within minutes. This 2.8-trillion-parameter AI agent reportedly discovered multiple remote code execution (RCE) vulnerabilities across various Redis versions, specifically 6.2.22, 7.4.9, 8.6.4, and 8.8.0. This highlights the increasing…
-
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances.The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13, First seen on thehackernews.com…
-
Hackers Lurked for 10 Months Inside South Korea Diplomatic System
The National Diplomatic Academy data breach has raised significant cybersecurity concerns in South Korea after the Ministry of Foreign Affairs confirmed that hackers maintained access to the academy’s online education system for nearly 10 months. The cyberattack resulted in the exposure of personal information belonging to current and former ministry employees, including diplomats serving overseas. First seen on thecyberexpress.com…
-
Check Point warns of SmartConsole zero-day exploited in attacks
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company’s SmartConsole graphical user interface (GUI) admin panel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-day-exploited-in-attacks/
-
Horizon3.ai-Report ‘The State of Assumed Security” – Fast alle CISOs vertrauen ihrer Cybersecurity zurecht?
First seen on security-insider.de Jump to article: www.security-insider.de/ciso-vertrauen-sicherheitskontrollen-ungetestet-a-8e6a8bd900fdd0ea707727593fc99496/
-
AI models caught cheating in cybersecurity evaluations
First seen on scworld.com Jump to article: www.scworld.com/brief/ai-models-caught-cheating-in-cybersecurity-evaluations
-
Most federal cybersecurity reporting rules are duplicative, study finds
The Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping. First seen on cyberscoop.com Jump to article: cyberscoop.com/gao-report-duplicate-cybersecurity-regulations-harmonization/
-
Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill
A 10-year renewal of the cybersecurity information-sharing law known as CISA 2015 passed as part of the House’s fiscal 2027 defense authorization bill. First seen on therecord.media Jump to article: therecord.media/cisa-2015-extension-passes-house-ndaa
-
How OpenAI’s human mistake led to the AI-powered hack on Hugging Face
OpenAI made a mistake setting up what it called a “highly isolated” testing environment and sandbox. According to cybersecurity experts, that human mistake is what made the AI-powered attack on Hugging Face possible. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/22/how-an-openais-human-mistake-led-to-the-ai-powered-hack-on-hugging-face/
-
AI Models Caught Cheating in Cyber Evaluations
OpenAI, Anthropic Models Broke Test Rules, Left Few Reasoning Clues. Five frontier models from OpenAI and Anthropic cheated during cybersecurity evaluations monitored by the U.K. AI Security Institute, using online answers and out-of-scope attacks. The models rarely admitted breaking the rules and their reasoning traces contained little evidence of the misconduct. First seen on govinfosecurity.com…
-
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as…
-
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data.The shortcoming has been codenamed HermeticReader by Guardio Labs. It’s officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability First…
-
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
“This is day one for cybersecurity in the age of agents,” Hugging Face CEO says. First seen on arstechnica.com Jump to article: arstechnica.com/ai/2026/07/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack/
-
Pixels Tracking Every Loan You Take on EU Bank Websites
Jscrambler Detects Cookies Exporting Detailed View of Customer Financial Intent. Many European and American bank websites are quietly – and perhaps unwittingly – sending sensitive customer data to third parties such as TikTok without user consent or sufficient anonymization, the cybersecurity firm Jscrambler found. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/pixels-tracking-every-loan-you-take-on-eu-bank-websites-a-32296
-
How an OpenAI benchmark test turned into a real-world cyberattack
“This is day one for cybersecurity in the age of agents,” Hugging Face CEO says. First seen on arstechnica.com Jump to article: arstechnica.com/ai/2026/07/how-an-openai-benchmark-test-turned-into-a-real-world-cyberattack/

