Tag: framework
-
ToxicPanda 2.0 Steals PINs From 140+ Banking and Cryptocurrency Apps Using Invisible Overlays
ToxicPanda 2.0, an evolved Android banking Trojan that significantly expands its fraud, device control, and credential theft capabilities. The updated malware uses invisible overlays to capture PIN input from more than 140 banking and cryptocurrency applications, while its broader phishing framework targets 349 banking, financial, e-wallet, and crypto applications across 16 countries. ToxicPanda was previously…
-
NIST AI RMF vs. NIST SP 800-53: Which Framework Do You Need for AI Risk?
<div cla First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/nist-ai-rmf-vs-nist-sp-800-53-which-framework-do-you-need-for-ai-risk/
-
Critical vulnerability in Ray framework allows remote code execution
First seen on scworld.com Jump to article: www.scworld.com/brief/critical-vulnerability-in-ray-framework-allows-remote-code-execution
-
NIST Frameworks and SOC 2 Reporting via Continuum GRC Services
As organizations navigate an increasingly complex regulatory environment in 2026, integrating NIST frameworks with SOC 2 reporting offers a strategic advantage that reduces audit fatigue while strengthening overall governance, risk, and compliance postures. Continuum GRC enables this interoperability through unified control mapping that aligns NIST SP 800-53, NIST SP 800-171 Rev 3, and CMMC 2.0″¦…
-
Premier League Introduces Mandatory Cybersecurity Standards, Backed by Fines of Up to £100,000
The Premier League has introduced mandatory cybersecurity requirements for its clubs for the first time, with non-compliant clubs facing fines of up to £100,000. The rules, which apply from the start of the 2026-27 season, mark a shift away from the league’s previous non-prescriptive security guidance towards a formal framework with fixed deadlines and evidence-based…
-
RAVEN Tool Steals Entire Elasticsearch Databases and Rebuilds Deleted Backdoors
The RAVEN offensive framework can turn compromised Elasticsearch and Kibana environments into durable data-theft and persistence operations. RAVEN, short for Reconnaissance & Attack on Vulnerable Elasticsearch Nodes, is an open-source modular framework built to assess Elasticsearch and Kibana security posture across reconnaissance, exploitation, exfiltration, persistence, and cleanup workflows. Its latest walkthrough focuses on post-exploitation against…
-
China-Linked Hacker Shows AI Capabilities in APAC Attack
In the first purported near-autonomous attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/china-linked-hacker-ai-capabilities-apac-attack
-
Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity
Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully functioning document converters, meal planners, recipe tools, and PDF utilities. The applications deliver their advertised features, but their shared codebase also enables runtime JavaScript execution and access to desktop-capture functionality creating a serious surveillance and post-compromise risk. Search-optimized…
-
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Tags: control, credentials, cybersecurity, framework, hacker, infrastructure, microsoft, network, serviceCybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.”TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,” Ontinue said in a technical report shared with The Hacker News. “Tasking flows through SharePoint Online file First seen on thehackernews.com Jump to article:…
-
Silent ‘TwinLoot’ Cyber Threat Operates Entirely From Microsoft’s Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud
-
CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability
Tags: ai, cisa, computing, cve, cyber, cybersecurity, data, exploit, flaw, framework, infrastructure, injection, intelligence, kev, open-source, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, tracked as CVE-2025-62593, is a code injection flaw in the Ray Project, a widely used open-source distributed computing framework often deployed for artificial intelligence workloads, machine learning development, data processing, and scalable Python…
-
JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud
JWR, an undocumented phishing-as-a-service (PhaaS) framework that turns conventional credential theft into an operator-led, real-time banking and payment fraud operation. Rather than waiting for a victim to submit a form, JWR streams keystrokes to an attacker over an AES-CTR-encrypted WebSocket channel, allowing the operator to react while card numbers, passwords and one-time codes are still…
-
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Tags: ai, cisa, computing, cybersecurity, exploit, flaw, framework, github, infrastructure, intelligence, kev, open-source, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than First seen…
-
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the First seen…

