Tag: infrastructure
-
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/
-
The Art of Detonating Malware: Lessons from a Research Lab
Modern ransomware operators are no longer content to simply encrypt data and hope for a payout. They are actively working to evade every layer of enterprise defense, from sandboxes and EDR to backup infrastructure itself, using techniques observed in Cohesity’s in-house REDLab malware research environment. For security leaders, backup and recovery systems can no longer..…
-
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned. First seen on therecord.media Jump to article: therecord.media/ransomware-south-korea-fbi-gunra
-
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
The ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-south-korea-gunra-ransomware-warning/
-
CISA Flags Progress LoadMaster Command Injection Vulnerability Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical command injection vulnerability in Progress LoadMaster, tracked as CVE-2026-8037, to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active exploitation. This vulnerability allows unauthenticated attackers to execute arbitrary commands on vulnerable appliances, posing a significant risk to organizations that expose LoadMaster…
-
Critical Progress LoadMaster flaw now actively exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-critical-progress-loadmaster-flaw-exploited-in-attacks/
-
Payroll Pirates Abuse Microsoft Graph to Find HR and Finance Staff After Account Compromise
A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph to identify employees handling payroll, finance, HR, benefits, invoices, and banking workflows. The activity closely overlaps with Microsoft’s “Payroll Pirates” cluster, tracked as Storm-2755. Researchers also found similarities with activity previously documented by Security Risk Advisors, indicating that…
-
The AI safety test is becoming a safety risk
AI agents are escaping cybersecurity testing environments and reaching real-world systems, raising questions about whether safety infrastructure, industry standards and regulation can keep pace with increasingly powerful models. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/09/the-ai-safety-test-is-becoming-a-safety-risk/
-
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, injection, kev, remote-code-execution, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9.6), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is an OS Command Injection Remote Code Execution issue…
-
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress”¯Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary First seen on…
-
Horizon3 Raises $250M to Prove What Attackers Can Exploit
Startup Says Autonomous Testing Can Demonstrate Business Impact Without Disruption. San Francisco-based Horizon3 raised a $250 million Series E funding round at a $2 billion valuation to expand autonomous testing across infrastructure, identity and web applications as AI gives attackers new ways to discover, exploit and traverse enterprise weaknesses at machine speed. First seen on…
-
AI Phishing Now Frighteningly Normal, Hard to Detect
StrongestLayer’s Alan LeFort on Personalization, Evasion and First-Seen Attacks. AI-generated phishing no longer looks unusual or obviously malicious, lending legacy filters ineffective. StrongestLayer CEO Alan LeFort explains how personalization, trusted infrastructure and evasion techniques are making first-seen attacks harder to detect. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-phishing-now-frighteningly-normal-hard-to-detect-a-32466
-
China Opens Cybersecurity Review of Palo Alto Networks Products
China has opened a cybersecurity review of Palo Alto Networks products, raising potential risks for critical infrastructure customers and foreign vendors. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-china-palo-alto-networks-cybersecurity-review/
-
Financial Services Under Fire From Rebranded Extortionists
What’s in a Name? Vishing-Savvy BlackFile Rebrands as Redact, Pink, Helix, Falcon. Data theft extortion group BlackFile claimed retire in May. Threat researchers at Google said telemetry and attack infrastructure shows that the group has carried on using a variety of new brand names and shifted its focus to targeting financial services. First seen on…
-
Top 10 Breaches of the Week
Security Boulevard’s weekly after-action roundup looks at the breaches and security incidents that mattered most over the past two weeks. This edition spans large healthcare exposures, attacks on government and financial infrastructure, a fast-moving software supply-chain compromise, and incidents where the final scope is still being established. #1: Unlimited Technology Systems: 3.8 million healthcare records..…
-
Cogent Launches VR-1 Cyber Reasoning Model for Enterprise Attack Paths
Cogent Security has introduced Cogent VR-1, a frontier reasoning model trained to investigate enterprise environments and prove whether multi-step attack paths are reachable. The model starts with a foothold and an objective, then maps the surrounding environment and connects weaknesses across systems. Cogent said VR-1 can work across cloud infrastructure, identity systems and internal tools,..…
-
Hackers grow more willing to destroy, not just disrupt, OT systems
Experts said the alarming trend has further stressed infrastructure providers that are already struggling with strong passwords, comprehensive logging and other basics. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-infrastructure-destructive-cyberattacks-black-hat/827260/
-
NSFOCUS LAS: Comprehensive Log Management for Security Visibility and Compliance
The Log Management Challenge Most enterprises accumulate log sources the same way they accumulate infrastructure: one device at a time, each generating data in its own proprietary format. The result is logs scattered across security appliances, network devices, servers, databases, middleware, applications, and cloud workloads, with no unified view and unknown device status. Any issue……
-
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices First…
-
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Tags: attack, cybercrime, group, infrastructure, Internet, malware, software, supply-chain, threat, trainingA new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain.”The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend…
-
Souveräne IT-Infrastruktur – Schwarz Digits und Zscaler launchen Cloud-Sicherheitsplattform
First seen on security-insider.de Jump to article: www.security-insider.de/schwarz-digits-und-zscaler-launchen-cloud-sicherheitsplattform-a-8f53b0cfa3d11dc9be8d034d94b92987/
-
Hackers Can Abuse Microsoft WSUS Servers to Deploy Malicious Updates via NTLM Relay
Security researchers have shown how attackers could exploit Microsoft Windows Server Update Services (WSUS) infrastructure to distribute malicious software updates across enterprise networks. This technique relies on NTLM authentication coercion and relay attacks targeting WSUS deployments that utilize a separate Microsoft SQL Server database. WSUS is commonly used by organizations to centrally manage, approve, and…
-
Top 10 Best External Attack Surface Management (EASM) Platforms 2026
In the sprawling digital ecosystem of 2026, organizations grapple with an increasingly complex and often poorly understood external attack surface. This attack surface encompasses all internet-facing assets that are discoverable and potentially exploitable by malicious actors. These assets extend far beyond traditional network perimeters to include cloud resources, web applications, APIs, orphaned infrastructure, exposed databases,…
-
Hackers grow more willing to destroy, not just disrupt OT systems
Experts said the alarming trend has further stressed infrastructure providers that are already struggling with strong passwords, comprehensive logging and other basics. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-infrastructure-destructive-cyberattacks-black-hat/827260/
-
TeamPCP Traced Back to 2020 Cryptojacking Operation
Tags: infrastructureOligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/teampcp-shadowray-ta-natalstatus/
-
Ein VLAN ist kein Air-Gap Kritische Infrastruktur braucht echte Trennung
Tags: infrastructureEnde Juli wurden mehr als 30 kommunale Wassersysteme im US-Bundesstaat Minnesota innerhalb von wenigen Tagen Opfer eines koordinierten Cyberangriffs. In der Stadt Braham ging eine Wasseraufbereitungsanlage offline, in der Stadt Plymouth wurde die Mobilfunkkommunikation zu zwei Wassertürmen und Abwasser-Hebestationen unterbrochen. In der Stadt Maple Plain wurde sogar der lokale Notstand ausgerufen. Erste Berichte wiesen auf…
-
KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft
Tags: credentials, cyber, data, infrastructure, injection, oracle, rce, remote-code-execution, sql, theft, threatKHunt shows how a “routine” SQL injection against an Oracle”‘backed web app can be weaponized into SYSTEM”‘level remote code execution and credential theft by compiling a full post”‘exploitation toolkit directly inside the database engine. This incident materially shifts the Oracle threat model: the database itself becomes attacker infrastructure, not just a data store. Subsequent triage…
-
U.S. CISA adds a JetBrains TeamCity flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a JetBrains TeamCity vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a JetBrains TeamCity vulnerability, tracked as CVE-2026-63077 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of July, JetBrains released security updates for TeamCity…
-
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent’s tools with no check that a model turn had authorized them.In several of the attack paths, the model never ran at all, so system prompts, content filters, and model-level guardrails never got a chance…

