Tag: defense
-
Shattering the Dream When a Job Offer Becomes a Zero-Day Attack
ey Points Introduction Since early 2026, Check Point Research has tracked a wave of theOperation Dream Jobcampaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially…
-
The Art of Detonating Malware: Lessons from a Research Lab
Modern ransomware operators are no longer content to simply encrypt data and hope for a payout. They are actively working to evade every layer of enterprise defense, from sandboxes and EDR to backup infrastructure itself, using techniques observed in Cohesity’s in-house REDLab malware research environment. For security leaders, backup and recovery systems can no longer..…
-
NATO and an AI startup can now name and track software vulnerabilities
Tags: ai, communications, cyber, cybersecurity, defense, flaw, intelligence, software, startup, vulnerabilityNATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week. The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company…
-
Whither CMMC? Another Battle Over Troubled DOD Cyber Regs
Defense Cyber Vendors Blindsided by Pause to Program 7 Years in the Making. The deadline for industry comments on how to fix the Cybersecurity Maturity Model Certification process at the Department of Defense is at the end of this week, setting the stage for a battle royale over the future of the program. It feels…
-
Margarita Howard’s HX5 Operationalizes CMMC Compliance Before AI Rules Arrive
Margarita Howard has spent two decades running a company in a government contracting market where the rules rarely hold still. HX5, the defense and aerospace services firm she founded in 2004 and still leads, supports Department of Defense and NASA missions and has employed over 1,000 people across 34 states and 90 government locations over…
-
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used…
-
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own…
-
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.PortSwigger researcher Gareth…
-
F5’s Sean Murphy on securing frontier AI as attack and defense accelerate
First seen on scworld.com Jump to article: www.scworld.com/resource/f5s-sean-murphy-on-securing-frontier-ai-as-attack-and-defense-accelerate
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
Check Point Puts AI Traffic Controls Into Its Existing Firewalls
Check Point has launched an AI Network Firewall that brings visibility and enforcement for AI applications, agents and Model Context Protocol traffic into the physical and virtual firewalls organizations already operate. Introduced July 30 ahead of Black Hat USA 2026, the product is delivered through Check Point’s AI Defense Plane and firewall software release R82.20……
-
Sophos, OpenAI Partner to Bring Frontier Models to Managed Service Providers
Sophos said it is partnering with OpenAI to bring OpenAI frontier models to managed service providers through Sophos Fusion, the company’s connected cyber defense system. Announced Aug. 6 during Black Hat USA 2026, the partnership is intended to give MSPs a way to deliver AI security services and build offerings around detection, investigation and response……
-
Salesforce’s Agentforce 360 platform approved for sensitive Defense Department data
First seen on scworld.com Jump to article: www.scworld.com/brief/salesforces-agentforce-360-platform-approved-for-sensitive-defense-department-data
-
Google’s John Hultquist on outpacing the adversary with AI threat defense
First seen on scworld.com Jump to article: www.scworld.com/resource/googles-john-hultquist-on-outpacing-the-adversary-with-ai-threat-defense
-
AI Accelerates Financial Services Fraud
Coinbase’s Lunglhofer on Deepfakes, Supply-Chain Risk and Human Expertise. AI is helping criminals clone voices, exploit software flaws and guide fraud schemes in real time. Coinbase Chief Security Officer Jeff Lunglhofer explains why faster attacks demand AI-enabled defense backed by cybersecurity experts. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-accelerates-financial-services-fraud-a-32450

