Tag: defense
-
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it. First seen on cyberscoop.com Jump to article: cyberscoop.com/biotech-critical-infrastructure-cybersecurity-legislation/
-
House and Senate members propose legislation for CISA to step up cyber defenses for biotech
Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it. First seen on cyberscoop.com Jump to article: cyberscoop.com/biotech-critical-infrastructure-cybersecurity-legislation/
-
AI is set to help cyber attackers much more than defenders, says UK official
Dave Chismon, the NCSC’s chief technology officer for architecture, said in a blog post that the imbalance in AI means cyberattacks would likely grow as automated defenses struggle to keep pace. First seen on therecord.media Jump to article: therecord.media/ai-set-to-help-attackers-more-than-defenders
-
Contagious Interview: 30,000 devices infected by a fake job interview
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview.…
-
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-script-defenses-at-runtime/
-
Cyber Defense Alone Can’t Keep Critical Services Running
States Must Map Dependencies and Engineer Safeguards for Water and Hospitals. State CIOs must decide which water systems, hospitals and other essential services need protection first. NASCIO data shows why states should rank infrastructure by consequence, test simultaneous failures and pair cyber defenses with engineering safeguards. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-defense-alone-cant-keep-critical-services-running-a-32871
-
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum”, a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. First seen on therecord.media Jump to article: therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme
-
AI Governance Is Key”, But Don’t Let It Slow Down Cyber Defense: Optiv CISO
While businesses must make governance an essential part of their AI strategies, it’s also important to not allow policies and approval processes to prevent defenders from moving as quickly as today’s increasingly machine-speed attackers, according to Optiv security chief Rob Gregory. First seen on crn.com Jump to article: www.crn.com/news/security/2026/ai-governance-is-key-but-don-t-let-it-slow-down-cyber-defense-optiv-ciso
-
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation…
-
New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems
A newly observed ransomware operation dubbed SETTRA is abusing the legitimate MeshAgent remote monitoring and management platform for persistence while using recovery-inhibition and defense-evasion techniques to maximize the impact of Windows encryption attacks. Huntress investigated two SETTRA incidents in July and September 2026, uncovering a repeatable operational pattern involving victim-specific ransomware binaries, Windows log clearing,…
-
Moderne Cyber Defense: Threat-Hunting-asService
Nicht jeder Cyberangriff löst einen Alarm aus: Angreifer vermeiden in der Regel gezielt bekannte Erkennungsmuster und bewegen sich unterhalb der Schwelle klassischer Security-Lösungen. Vor diesem Hintergrund gewinnt Threat Hunting zunehmend an Bedeutung. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/threat-hunting-as-a-service
-
APT36 Targets Indian Government and Defense Organizations With New Rust Malware Arsenal
Pakistan-nexus threat actor APT36 has launched a renewed espionage campaign targeting government and defense organizations in India and Afghanistan. Deploying a new Rust-based malware suite designed for covert command-and-control, data theft, and propagation into isolated networks. Tracked by Zscaler ThreatLabz as Operation RapidRust, the activity was observed in August 2026 and reflects a significant evolution…
-
Hugging Face Calls for Wider Access to AI Cyber Defenses
CEO Clem Delangue Urges Frontier Labs to Share Models, Compute and Threat Data. Organizations need more transparency and access to models and tools to fight against cyberattacks, according to Hugging Face CEO Clem Delangue, who said Wednesday that frontier should provide more compute and information. Hugging Face asked OpenAI for $100 million in compute. First…
-
Mate Security CEO Asaf Wiener’s LinkedIn Post Draws Attention To The AI Cybersecurity Debate
As artificial intelligence becomes increasingly central to both cybersecurity defense and offensive operations, a debate is emerging over how quickly the technology should advance. A recent LinkedIn post from Asaf Wiener, CEO and co-founder of Mate Security, has drawn significant… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/mate-security-ceo-asaf-wieners-linkedin-post-draws-attention-to-the-ai-cybersecurity-debate/
-
Pakistan Finalizes 90-Day Cybersecurity Action Plan, Federal CERT to Lead Rollout
Pakistan’s federal government has completed work on a 90-day cybersecurity action plan designed to build a more coordinated national defense against digital threats, bringing together federal and provincial governments, regulators and operators of critical infrastructure under one framework. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/pakistan-cybersecurity-action-plan/
-
Pakistan Finalizes 90-Day Cybersecurity Action Plan, Federal CERT to Lead Rollout
Pakistan’s federal government has completed work on a 90-day cybersecurity action plan designed to build a more coordinated national defense against digital threats, bringing together federal and provincial governments, regulators and operators of critical infrastructure under one framework. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/pakistan-cybersecurity-action-plan/
-
CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks
Tags: cisa, control, cyber, cybersecurity, defense, exploit, guide, hacker, identity, infrastructure, international, networkThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has collaborated with international partners to guide the defense of Active Directory (AD). They warn that attackers exploit 17 common techniques to gain control of identity infrastructure. The guide, released on September 15, was co-authored by the Australian Signals Directorate’s Australian Cyber Security Center, CISA, the NSA,…
-
Cybersecurity als Eintrittskarte in den Verteidigungsmarkt
Nicht jeder, der will, kommt rein: Sebastian Dännart, Director Cybersecurity Consulting bei infodas, erklärt im Gespräch mit Lars Becker, stellvertretender Chefredakteur it security, welche Compliance-Hürden Unternehmen auf dem Weg in den Defense-Markt nehmen müssen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/cybersecurity-im-verteidigungsmarkt
-
US Lawmakers Eye Stronger Healthcare Cyber Defenses
House Subcommittee Hearing Highlights Threats to Rural Hospitals and Patient Care. As U.S. hospitals, clinics and other medical providers continue to face an onslaught of hacking incidents and disruptive cyberattacks this year, the House Energy and Commerce Committee’s health subcommittee examined on Tuesday two proposed bills aimed at strengthening health sector cybersecurity. First seen on…
-
Iranian Hackers Dodging Corporate Defenses to Reach Critics
Joint Advisory Details Chosen Brick Spyware Used Against Iran’s Critics Abroad. Iranian state hackers are steering dissidents, activists and journalists away from corporate devices and onto personal computers to plant spyware that can capture screens, record audio and steal messages, according to a joint advisory from British, U.S. and Dutch intelligence agencies. First seen on…
-
The Illusion of the AI SOC
Why security copilots are stalling against machine-speed attackers and what genuinely autonomous defense requires instead. Talk to any CISO or SOC director off the record, and the confession is almost always the same: they bought into the generative AI hype,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-illusion-of-the-ai-soc/
-
eBook: Identity-First Threat Intelligence
Attackers increasingly bypass traditional defenses by logging in with credentials that have already been stolen, exposed, or sold on the Dark Web. As infostealer malware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/enzoic-ebook-identity-first-threat-intelligence/
-
Sonar Supports OpenAI’s Call for Collective Action on Cyber Defense
The window to strengthen cyber defense is narrowing, as advanced AI models compress the time between vulnerability disclosure and exploitation from months to minutes. It’s the responsibility of the defenders to match that pace. That is why we’ve signed OpenAI’s… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/sonar-supports-openais-call-for-collective-action-on-cyber-defense/
-
âš¡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination.The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems,…
-
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/defense-cyber-spending-attacks/
-
Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens
Tags: access, breach, cloud, credentials, cyber, data, data-breach, defense, exploit, extortion, github, group, infrastructureCyber Extortion Group Continues to Target Exposed Cloud-Based Data Over Endpoints. Cyber extortion group FulcrumSec continues to find hardcoded credentials in public-facing IT infrastructure and exploit them as part of what it’s dubbed a Hardcoded Horrorshow that counts Ozempic maker Novo Nordisk among its victims. Here are defenses organizations need to put in place now.…
-
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise.A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent…
-
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise.A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent…
-
Anthropic caught Russia-linked spies using Claude in hacking operations
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations. First seen on therecord.media Jump to article: therecord.media/anthropic-russia-hackers-claude
-
Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly used to triage suspicious code. ESET researchers linked the activity to Russia-aligned threat actor UAC-0099, which used the method during an attack against an organization in Ukraine. The group inserted a safety-sensitive, weapon-related request…

