Tag: framework
-
Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App
Researchers linked the Flying Eagle Android RAT to fake police apps, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started with a fraudulent Android app impersonating a Chinese Provincial Public Security Bureau service and ended up mapping a sprawling criminal ecosystem built around a leaked Android RAT framework called…
-
CastleLoader Campaign Deploys NeedleStealer to Steal Crypto Wallet Seeds and Browser Sessions
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and LevelBlue, confirming that CastleLoader remains a central delivery mechanism for multi-stage intrusions while introducing new tooling written in Rust and Golang.…
-
Apple iOS 26.6 Update Fixes Flaws Allowing Kernel-Level Code Execution and Root Access
Apple has released iOS 26.6 and iPadOS 26.6, a significant security update that addresses numerous vulnerabilities across core operating system components, media frameworks, WebKit, wireless services, and application frameworks. Released on July 27, 2026, this update is available for iPhone 11 and later models, as well as supported iPads. It should be prioritized for deployment…
-
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
Tags: ai, cisco, cloud, crowdstrike, framework, group, ibm, intelligence, linux, microsoft, network, nvidia, open-source, software, toolNVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux…
-
Keyfactor Expands Into AI Agent Identity With Cofide Deal
Deal Extends Certificate-Based Trust Framework to AI Agents and Software Workloads. Cleveland-based Keyfactor plans to acquire London-based startup Cofide to expand its trust platform into software workloads and autonomous AI agents, betting enterprise demand for dynamic, standards-based machine identities will accelerate as AI adoption grows. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/keyfactor-expands-into-ai-agent-identity-cofide-deal-a-32331
-
Apple Biome Data Reveals Safari Activity, Wallet Transactions and Location Visits
Apple’s internal Biome framework is rapidly emerging as one of the most valuable sources of forensic intelligence on iOS, with newly analyzed data revealing detailed records of Safari browsing activity, Wallet transactions. Originally misunderstood due to its name, Biome is not مرتبط with biometrics but instead powers Apple’s predictive intelligence ecosystem, including Siri suggestions, personalization,…
-
How CIOs can navigate federal, state AI regulation uncertainty
AI laws are evolving across the EU, U.S. states and the U.S. federal government. An effective governance framework helps organizations meet requirements across all jurisdictions. First seen on techtarget.com Jump to article: www.techtarget.com/searchcio/news/366646236/How-CIOs-can-navigate-federal-state-AI-regulation-uncertainty
-
CISA orders urgent action on actively exploited Langflow RCE flaw
Tags: ai, cisa, cybersecurity, exploit, flaw, framework, government, infrastructure, rce, remote-code-execution, update, vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw/
-
AI can’t fix cybersecurity’s hiring problem
Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/cybersecurity-workforce-trends-report/
-
Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers
Hackers are increasingly abusing decentralized infrastructure and legitimate development frameworks to evade detection, with a newly observed campaign leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated عبر malicious websites, file-sharing platforms such as Google Drive, MEGA, GoFile, and Wormhole, and spoofed download portals designed to…
-
New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops
In a significant evolution of the Project CAV3RN tooling, a new .NET Native AOT communication module dubbed AzureCommunication.dll has been deployed to replace the framework’s earlier HTTP/WebSocket C2 component. A stealthy channel that abuses Outlook calendar events over Microsoft Graph and a DNS-based recovery mechanism for Microsoft 365 credentials. This shift reinforces CAV3RN’s positioning as…
-
Choose Wisely: AI-Generated Coding Risk Varies, A Lot
AI-generated code introduces 15 vulnerabilities on average per codebase, but the actual risk depends on framework pairing more than the model used. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/choose-wisely-ai-generated-coding-risk-varies
-
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.Researchers demonstrated that chain, plus six other attacks,…
-
PR3TACK preemptive framework maps threats before attackers use them
Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/first-pr3tack-preemptive-framework/
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…
-
Hugging Face Says Autonomous AI Agents Breached Data, Credentials
Tags: access, ai, cloud, credentials, cyberattack, data, exploit, flaw, framework, infrastructure, vulnerabilityAttackers Exploited Dataset Processing Flaws to Access Internal Clusters. Hugging Face said an autonomous AI agent framework exploited dataset processing vulnerabilities to compromise internal infrastructure, harvest cloud credentials and move laterally across clusters, exposing both the rise of agentic cyberattacks and the limits of AI safety guardrails during incident response. First seen on govinfosecurity.com Jump…
-
KI-generierter Quellcode bei neuem Botnetz TuxBot v3 entdeckt
Sicherheitsforscher haben das IoT-Botnetz-Framework TuxBot v3 Evolution entdeckt. Es wurde nachweislich unter Einsatz von künstlicher Intelligenz entwickelt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-generierter-quellcode-botnetz
-
An AI SOC Evaluation Guide for Security Leaders
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/an-ai-soc-evaluation-guide-for-security-leaders/
-
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hollowgraph-microsoft-calendars/
-
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues
Microsoft has released KB5121767, an out-of-band (OOB) cumulative update for Windows 11 versions 22H2 and 21H2. This update addresses a system performance issue related to the Intel Innovation Platform Framework (Intel IPF) drivers. The update was made available on July 18, 2023, specifically for devices affected by this issue, which arose after installing recent Windows…
-
Identity Security als Schlüssel für sichere AI-Agenten
Warum AI nur dann sicher skaliert, wenn jede maschinelle Identität, vom Agenten bis zur MCP-Verbindung, von Anfang an verwaltet wird. Kaum eine Technologie entwickelt sich derzeit so schnell wie agentenbasierte AI. Im Wochentakt erscheinen neue Modelle, Frameworks und Protokolle. Anbieter überbieten sich mit autonomen Assistenten, die eigenständig planen, Werkzeuge aufrufen und Aufgaben über Systemgrenzen… First…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter CrashStealer: C++ macOS infostealer posing as crash reporter Lucide Proxy: Turning Student Web Proxies into DDoS Bots AsyncAPI npm organization compromised, 2M weekly downloads affected OkoBot: new sophisticated malware framework targets cryptocurrency users […]…
-
OkoBot greift Kryptowallets an und tarnt sich als legitime Software
Kaspersky warnt vor einem neuen Malware-Framework, das gezielt auf Kryptowährungsnutzer und Entwickler abzielt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/okobot-kryptowallets-an
-
New OkoBot framework deploys 20 payloads to steal data, crypto
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-okobot-framework-deploys-20-payloads-to-steal-data-crypto/
-
TuxBot v3: The IoT Botnet Built With AI Bugs, Disclaimers and All
TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an unusual detail: the developer used a large language model to write significant portions…
-
Illinois Enacts First US Law Mandating AI Safety Audits
SB 315 Requires Annual Independent Audits, 72-Hour Incident Reporting for AI Giants. Gov. JB Pritzker signed bipartisan legislation making Illinois the first state to require annual independent safety audits of frontier AI developers, going beyond California and New York frameworks with incident reporting deadlines, whistleblower protections and penalties up to $3 million. First seen on…
-
New VEXAIoT AI Agents Autonomously Exploit IoT Vulnerabilities With 95% Success Rate
VEXAIoT, an autonomous multi-agent framework designed to discover and exploit vulnerabilities in the Internet of Things (IoT) within controlled test environments. In 200 attack trials against the intentionally vulnerable IoTGoat platform, the system completed 189 attacks, achieving an overall success rate of 94.5% (rounded to 95%). New VEXAIoT AI Agents Attack Workflow VEXAIoT, short for…
-
Everest Ransomware Encryptor Uses ConfuserEx-Protected .NET Binary With Wake-on-LAN Capability
A recent technical analysis of an Everest ransomware encryptor reveals a purpose-built, ConfuserEx-protected .NET 4.0 binary that combines heavy obfuscation, misleading cryptographic declarations, and uncommon network tactics to maximize impact and impede response. The analyzed sample (hlntqyun.exe, SHA-256 1df92b…) is a 114 KB C# assembly compiled for .NET Framework 4.0 and protected with ConfuserEx anti-tamper,…
-
OpenMatter Network Joins HOL Initiative to Help Define Standards for Verifiable AI Collaboration and Security
Melbourne, Florida, United States, July 8th, 2026, CyberNewswire OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop standards, policies and verification frameworks for secure autonomous AI systems and agentic computing environments. As organizations increasingly deploy AI agents…

