Tag: infrastructure
-
CISA Warns Hackers Are Actively Exploiting VMware vCenter Path Traversal Flaw
Tags: cisa, cve, cyber, cybersecurity, exploit, flaw, hacker, infrastructure, kev, vcenter, vmware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom VMware vCenter to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability, tracked as CVE-2026-59310, is a path traversal flaw that enables arbitrary code execution in affected vCenter deployments. VMware vCenter Path Traversal Flaw CVE-2026-59310 impacts the VMware vCenter Syslog Server…
-
Fake Claude Install Guide Steals Mac Passwords and Turns Trusted Crypto Wallet Apps Into Phishing Traps
A Google-sponsored search result for Claude installation instructions is being used to deliver a sophisticated macOS stealer and remote-access trojan (RAT) named MacSync. The campaign abuses a legitimate Claude shared-conversation page on the claude.ai domain, demonstrating how trusted AI-hosting infrastructure can be weaponized to bypass users’ normal phishing instincts. The intrusion investigated by Huntress began…
-
Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion
Tags: advisory, attack, cisa, cyber, extortion, infrastructure, intelligence, ransomware, service, updateMedusa ransomware operators have compromised over 500 organizations across critical infrastructure sectors, according to a joint advisory issued by the FBI, CISA, and the U.S. Department of Health and Human Services (HHS) as part of their #StopRansomware initiative. An update released on August 18, 2026, provides expanded intelligence based on FBI investigations conducted as recently…
-
CISA Weighs Outsourcing Its Cyber Software Buying
CISA Issues Sources Sought Notice Floating $600M a Year, $6B Over Contract Life. The U.S. Cybersecurity and Infrastructure Security Agency is surveying industry on whether a contractor could take over cybersecurity software buying for federal civilian agencies – a service worth more than $600 million a year, according to a new notice. First seen on…
-
More than 200 victims of Medusa ransomware identified over the last year, CISA says
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025, writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025. First seen on…
-
Interview mit Keyfactor Asymmetrische Verschlüsselung wird obsolet
Die asymmetrische Verschlüsselung ist in spätestens 5 Jahren obsolet, warnt Florian Bosch, Senior Regional Sales Director bei Keyfactor. Denn die rasante Entwicklung von Quanten-Computer macht die asymmetrische Verschlüsselung angreifbar. Welche Schritte Unternehmen jetzt initiieren sollten, um ihre PKI-Infrastruktur rechtzeitig auf Post-Quantum-Cryptography (PQC) bzw. auf hybride Verschlüsselungsverfahren umzustellen, darüber sprach Netzpalaver in einer Remote-Session mit Florian…
-
2,000 Hacked WordPress Sites Were Secretly Running a Global Crime Ring
A newly identified cybercrime operation dubbed StopAndProtect has been quietly running its entire criminal infrastructure through close to 2,000 hacked WordPress websites, according to new research from Check Point. Rather than relying on dedicated command-and-control servers, which are relatively easy for defenders to identify and take down, the group behind StopAndProtect compromised thousands of legitimate…
-
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
Tags: control, credentials, cybersecurity, framework, hacker, infrastructure, microsoft, network, serviceCybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.”TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services,” Ontinue said in a technical report shared with The Hacker News. “Tasking flows through SharePoint Online file First seen on thehackernews.com Jump to article:…
-
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
Tags: infrastructureA single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco.The activity, which Reco has named the City Forum campaign after a domain tied to the attacker’s IP address, traces back…
-
The AI Factory’s Blind Spot Is Trust: Why Confidential AI Is the Missing Infrastructure Layer
AI factories promise scalable enterprise AI, but traditional security leaves sensitive data and model weights exposed during processing. Confidential AI closes the gap by protecting data in use with hardware isolation, encryption and cryptographic attestation. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-ai-factorys-blind-spot-is-trust-why-confidential-ai-is-the-missing-infrastructure-layer/
-
Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/
-
CISA Warns of Active Exploitation of Ray-Project Ray Code Injection Vulnerability
Tags: ai, cisa, computing, cve, cyber, cybersecurity, data, exploit, flaw, framework, infrastructure, injection, intelligence, kev, open-source, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, tracked as CVE-2025-62593, is a code injection flaw in the Ray Project, a widely used open-source distributed computing framework often deployed for artificial intelligence workloads, machine learning development, data processing, and scalable Python…
-
OpenAI tightens defenses after AI agents breach research environment
Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/openai-strengthening-security-measures/
-
U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, remote-code-execution, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2025-62593 (CVSS score of 9.4), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2025-62593 is a critical remote code execution (RCE) vulnerability in Ray,…
-
From Demo to Production: Scaling Continuous Control Monitoring with ServiceNow and Atlassian
Enterprises answered the question: is my software actually working? about a decade ago. Not by hiring more people to read logs but by instrumenting the data plane once and letting anyone query it. Observability became infrastructure, and the people who used to read logs went and solved harder problems. GRC has never had that moment….The…
-
C2Looper v2 Uses GitHub Repositories as Full CommandControl Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver tasks, receive results, maintain beacon records, and host payloads. ThreatLabz identified the malware in July 2026 and assesses, with low-to-medium confidence, that it is delivered through…
-
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Tags: ai, cisa, computing, cybersecurity, exploit, flaw, framework, github, infrastructure, intelligence, kev, open-source, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than First seen…
-
VMware vCenter RCE Gives Attackers a Path From One Appliance to Entire Virtual Infrastructure
Tags: cve, cyber, data-breach, exploit, infrastructure, rce, remote-code-execution, vcenter, vmware, vulnerabilityA critical VMware vCenter vulnerability is being actively exploited in a fast-moving campaign that turns a single exposed management appliance into a launch point for broad virtual-infrastructure compromise. Incident responders at QUIRSO linked the activity to exploitation of CVE-2026-59310, while identifying a separate, possibly unrelated track involving CVE-2026-59309. CVE-2026-59310 is a directory-traversal vulnerability in the…
-
New PATCHCORD backdoor targets Afghan telecom and South Asian infrastructure
First seen on scworld.com Jump to article: www.scworld.com/brief/new-patchcord-backdoor-targets-afghan-telecom-and-south-asian-infrastructure

