Tag: hacker
-
North Korea’s APT Capabilities Are No Longer State-Exclusive
Tags: access, apt, cyber, finance, group, hacker, infrastructure, korea, lazarus, malware, military, north-korea, ransomware, skillsAhnLab Found Shared Malware, SSH Keys and Infrastructure Across Two Campaigns. Shared malware, infrastructure and access methods link Lazarus Group to Gunra ransomware activity, while former North Korean military hackers allegedly used state-trained skills to steal bank funds, exposing cyber capability diffusion and blowback inside the regime. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/north-koreas-apt-capabilities-are-no-longer-state-exclusive-a-32392
-
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January”¯2025.These targeted organizations operate across several sectors, such as healthcare, research, government offices, First seen on thehackernews.com Jump to article:…
-
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/
-
US authorities see ‘significant escalation’ in attacks on water system devices
Hackers have locked operators out of their own OT networks, modified passwords and changed IP addresses. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/us-authorities-escalation-attacks-water-system-devices/826715/
-
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Palo Alto Networks’ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session.The operator, tracked through the aliases knaithe and KnYuan, First seen…
-
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
Created by legendary hardware hacker Andrew “bunnie” Huang, the badges for this year’s famed security conference aim to push the boundaries of security and transparency. First seen on wired.com Jump to article: www.wired.com/story/defcon-34-badge-baochip-andrew-bunnie-huang/
-
Chinese-Speaking Hacker Uses DeepSeek Agent to Launch Autonomous Cyberattacks
Chinese-speaking threat actor “knaithe” (aka KnYuan) has been caught running an AI-enabled autonomous attack stack built around DeepSeek and the Hermes Agent framework, proving that large language models can now drive end”‘to”‘end offensive operations with minimal human oversight. Hermes provided terminal access, skills orchestration, and Model Context Protocol (MCP) integrations. At the same time, DeepSeek…
-
Suspected Iranian Campaign Disrupts Minnesota Water Systems
U.S. and Minnesota investigators believe Iranian hackers were likely responsible for a cyberattack on roughly 36 municipal water systems in Minnesota, The New York Times reported Thursday. Officials cautioned that the attribution remains a preliminary assessment and could change as investigators gather more evidence. The attacks occurred Monday and were focused on technology that municipalities..…
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Exploits can give persistent server access that survives credential rotation and disk re-imaging. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/
-
Breach Roundup: OpenAI Models on a Hacking Tear
Also, Russian Hackers Exploit Outlook Flaw, Coca-Cola Restarts Fairlife Production. This week: Sam Altman on hacking, Russia exploited an Outlook web access flaw, Coca-Cola restarted Fairlife production, U.K. education department and Angola teleco breached, SonicWall credential stuffing, Telegram founder charged in Russia, hidden prompt turns Microsoft Copilot into an AI worm. First seen on govinfosecurity.com…
-
Kremlin hackers are exploiting Exchange flaw to backdoor unpatched networks
Exploits can give persistent server access that survives credential rotation and disk re-imaging. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/kremlin-hackers-are-exploiting-exchange-flaw-to-backdoor-unpatched-networks/
-
CareCloud begins to notify hundreds of thousands after hackers stole medical records
The health tech data giant, which handles vast amounts of patients’ medical data, said hackers struck one of its protected health data stores. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/30/carecloud-begins-to-notify-hundreds-of-thousands-after-hackers-stole-medical-records/
-
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers/
-
Flailing Ransomware Hackers Resorting to Extreme Tactics
Silent Ransom Bucks Trend of Fewer Victims Paying, and Paying Less When They Do. Fewer ransomware victims are choosing to pay a ransom than ever before, bar some big payoffs that largely trace to high-profile law firms that got hit by a group called Silent Ransom, which the FBI says has a penchant for infiltrating…
-
Many More Bugs But Exploits Stay Steady
Data Shows Hackers Not Using More Exploits, But They Are Exploiting Flaws Quicker. The coming of the vulnocalypse – our artificial intelligence-instigated moment of drastically accelerating flaw discovery – has yet to be matched with an equivalent rise in exploits, shows analysis of common vulnerabilities and exposure data from the first half of this year.…
-
Microsoft launches agentic security platform designed to combat AI-based attacks
The rollout comes amid growing concerns about the ability of hackers to launch campaigns using autonomous methods.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/microsoft-agentic-security-platform-ai-attacks/826365/
-
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
-
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
Analysis of real-life incident response cases by Cisco Talos warns that phishing remains a powerful method of initial compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/
-
New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal…
-
Chinese Hackers Use RedRelay Multi-Hop Network to Conceal Global Cyber Operations
Chinese state-linked hackers are increasingly relying on a covert multi-hop infrastructure dubbed RedRelay (also known as ORBWEAVER) to mask the origins of global cyber operations, with evidence pointing to little-known Guangdong Chanming as a key enabler behind the network. Guangdong Chanming, a low”‘visibility company with no public”‘facing products or marketing, has quietly amassed a portfolio…
-
Coca-Cola confirms hackers stole data in Fairlife ransomware attack
Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/coca-cola-fairlife-dairy-subsidiary-ransomware-attack/
-
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor
An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks. Aligning with tactics observed…
-
EUVD-2026-45270 / CVE-2026-8635 – Hacker können sich Superuser-Rechte in IBM Langflow verschaffen
First seen on security-insider.de Jump to article: www.security-insider.de/ibm-langflow-oss-kritische-schwachstelle-update-1-10-1-a-c146e1daa10105f960b3a7a824cbbe8a/
-
The enduring mystery of hacker Phineas Fisher
Tags: hackerFirst seen on scworld.com Jump to article: www.scworld.com/brief/the-enduring-mystery-of-hacker-phineas-fisher
-
Wyden Calls for Edge Device Annihilation in US Government
US Senator Says Zero Trust Must Replace Legacy Edge Devices in 2028. Network devices conversion into nation-state hackers’ favorite initial access vector has a U.S. senator urging the federal government to phase out legacy, public-facing remote access systems in favor of zero trust architecture. Security experts have long flagged network edge devices as a risk.…
-
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
-
CPA Gets Prison Time in $5.3M Healthcare Fraud Case
Vendor Email Compromise Scam Diverted Children’s Healthcare of Atlanta Payment. A former certified public accountant will serve four years in federal prison following his recent conviction in a money laundering scheme in which a hacker compromised a vendor’s email account and instructed a Georgia children’s hospital to divert a $5.3 million payment to a fraudulent…

