Tag: cybersecurity
-
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka First seen on thehackernews.com…
-
North Korean Hackers Target Healthcare: What You Need to Know
North Korean cyberattacks reveal how trusted identities and workflows create healthcare cybersecurity risk, and how security teams can test them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/north-korean-hackers-target-healthcare-what-you-need-to-know/
-
Iran-Linked Hackers Abuse Legitimate Developer Tool to Hide Dindoor Backdoor
Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have legitimate uses on Windows systems, making malicious activity harder to distinguish from normal software behavior. According to Cybersecurity News, Iran-linked operators are abusing the legitimate Deno JavaScript…
-
Huntress Uncovers Five Cases of North Korean Operatives Posing as Remote IT, Sales and Healthcare Workers
Cybersecurity firm Huntress has confirmed five separate incidents this year in which suspected North Korean operatives were successfully hired into legitimate organisations under false identities, in a wave of activity researchers say shows how the country’s so-called >>remote IT worker<< scheme has expanded well beyond IT roles. The cases, disclosed in a new advisory, involved…
-
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process.In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that First seen on…
-
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes.Both organizations were fully compromised at the domain level, and in both, the red team also First seen…
-
Inside the Cybersecurity Vendor Stack: PAM, DNS Filtering and Endpoint
Dek: PAM, DNS Filtering and Endpoint Protection are three critical components that make up a strong, secure cybersecurity vendor stack. In the world of cybersecurity, there are numerous core domains, key principles, and defensive layers. As a result, it can be challenging to keep up with all the different components. One way to think about…The…
-
Hackers now exploit critical Gitea flaw in code injection attacks
Tags: attack, cybersecurity, exploit, flaw, hacker, infrastructure, injection, service, vulnerabilityAttackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks/
-
U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, open-source, oracle, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for…
-
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple’s Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.SOCRadar Threat Research Unit (STRU) said the platform, which it tracks as AnonyMousKIT, is credit-metered and drives lures…
-
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
Tags: access, attack, cve, cybersecurity, exploit, flaw, infrastructure, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea.The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as…
-
Hottest cybersecurity open-source tools of the month: August 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/26/hottest-cybersecurity-open-source-tools-august-2026/
-
US Lawmakers Urge Probe of Trump Cyber Workforce Cuts
House Lawmakers Ask Watchdog to Assess Staffing Losses at US Cyber Agency. House Democrats are asking the Government Accountability Office to examine how staffing reductions and cuts at the Cybersecurity and Infrastructure Security Agency have affected the agency’s ability to defend federal networks and critical infrastructure. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/us-lawmakers-urge-probe-trump-cyber-workforce-cuts-a-32653
-
The 90-Day AEO Plan for a Cybersecurity Vendor, Week by Week
Ninety days is enough to fix crawler access, baseline measurement, and restructure your ten highest-value pages. Week by week. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-90-day-aeo-plan-for-a-cybersecurity-vendor-week-by-week/
-
Oasis Security Researchers Reveal Security Flaw in NemoClaw AI Agent
Cybersecurity researchers from Oasis Security today disclosed a vulnerability in instances of the NemoClaw artificial intelligence (AI) agent running on a local machine that could lead to it being taken over. Elad Luz, head of research at Oasis Security, said the vulnerability (CVE-2026-65105) has been remediated in the latest update to NemoClaw but organizations will..…
-
Chinese Hackers Accelerate Cyberattacks Using Low-Cost AI Tools: Research
Tags: ai, china, cyber, cyberattack, cybersecurity, group, hacker, intelligence, network, open-source, toolState-affiliated Chinese hackers are dramatically scaling up foreign cyberattacks by integrating open-source artificial intelligence (AI) models into their operations, according to new research from cybersecurity firms TeamT5 and Palo Alto Networks Inc.’s Unit 42. By offloading mundane tasks and automated target-mapping to cheap, accessible AI tools, state-backed cyber groups have more than doubled their attack..…
-
CrowdStrike’s Daniel Bernard: Frontier AI Requires Cybersecurity’s ‘Greatest Mobilization’ Ever
Even as frontier AI models such as Anthropic’s Claude Mythos create new levels of urgency around cybersecurity, the only reasonable answer is for vendors and partners to come together to meet the challenge, CrowdStrike Chief Business Officer Daniel Bernard said during the latest episode of CRN’s Security or Else! First seen on crn.com Jump to…
-
District Administration – K12’s biggest cybersecurity risk isn’t devices. It’s everything beyond.
This article was originally published in District Administration on 8/18/26 by Charlie Sander. Recent conversations about technology in schools have centered around one main question: Are students spending too much time on screens? Now, this debate has expanded to include issues like AI, a ban on cellphones and/or tablets, and the broader role of digital learning.…
-
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.”While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to…
-
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the…
-
Frontier AI: Vulnerability Management’s Systemic Revolution
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming…
-
Sometimes Even a Great Cybersecurity Pedigree Can’t Save a Pedestrian Business Model
Minimus is shutting down despite strong technology, experienced founders and $51 million in funding, showing how technical excellence cannot overcome a business model that fails to capture enough market value. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/sometimes-even-a-great-cybersecurity-pedigree-cant-save-a-pedestrian-business-model/
-
Wie ungenutzte IT-Infrastruktur Sicherheitsvorfälle verursachen kann Die stille Gefahr
Ungepatchte Systeme und neue Angriffsmethoden durch künstliche Intelligenz dominieren derzeit die Cybersecurity-Debatte. Doch viele Sicherheitsvorfälle entstehen dort, wo Unternehmen gar nicht hinschauen: in ungenutzter digitaler Infrastruktur. Verwaiste Benutzerkonten, nie rotierte Zugangsdaten und vergessene Speichermedien können zu idealen Einfallstoren für Angreifer werden. First seen on ap-verlag.de Jump to article: ap-verlag.de/wie-ungenutzte-it-infrastruktur-sicherheitsvorfaelle-verursachen-kann-die-stille-gefahr/107031/
-
U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical, unauthenticated vulnerability…
-
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
Tags: access, cve, cybersecurity, data, exploit, flaw, infrastructure, kev, network, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to First seen on…
-
Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data
Tags: access, cisa, cve, cyber, cybersecurity, data, exploit, flaw, hacker, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-21962, affects both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA classified this issue as…
-
Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data
Tags: access, cisa, cve, cyber, cybersecurity, data, exploit, flaw, hacker, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-21962, affects both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA classified this issue as…
-
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,…
-
The Most Effective Cybersecurity Awareness Programs for Companies (2026)
<div cla The most effective cybersecurity awareness programs pair phishing simulation testing with role-based training, then tie both to live email threat detection. IRONSCALES, KnowBe4, Proofpoint, Cofense, and Mimecast lead this market. IRONSCALES is the only one that builds awareness training directly into an AI-powered email security platform, so the same system that trains your…

