Tag: infrastructure
-
U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Catalyst SD-WAN Manager flaw, tracked as CVE-2026-76504 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability resides in Cisco Catalyst SD-WAN Manager’s…
-
Metamask discloses security incident affecting its infrastructure
On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/metamask-discloses-security-incident-affecting-its-infrastructure/
-
KI-Agenten absichern: Sechs Bausteine für eine belastbare Architektur
Mit KI-Agenten wird aus einer fehlerhaften Antwort schnell eine geschäftskritische Aktion. Unternehmen brauchen deshalb mehr als Modellschutz: Gefragt ist eine Sicherheitsarchitektur, die Identitäten, Daten, Berechtigungen, Endgeräte, Überwachung und Wiederherstellung miteinander verzahnt und autonome Systeme jederzeit kontrollierbar hält. Management Summary KI-Sicherheit ist Architekturaufgabe: Schutz muss Infrastruktur, Modelle, Daten, Identitäten, Anwendungen und Endgeräte durchgängig umfassen. Agenten… First…
-
Anthropic Prospectus Reveals Surging Sales, Worsening Losses
Amazon and Google Marketplaces Handled 47% of the Frontier AI Lab’s 2025 Sales. Anthropic’s prospectus shows rapid Claude revenue growth increasingly tied to Amazon and Google, while soaring compute costs, customer concentration and hundreds of billions of dollars in infrastructure commitments amplify the financial risks behind its expansion. First seen on govinfosecurity.com Jump to article:…
-
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-critical-pre-auth-rce-flaw-in-mikrotik-routeros/
-
PaperPhone Cluster Shows How One Bot Operator Can Look Like Thousands of Mobile Users
A large-scale scraping cluster dubbed PaperPhone, exposing how one operator can manufacture the appearance of tens of thousands of legitimate mobile users across dozens of countries. The operation used roughly 75,000 IP addresses across 230 address blocks in 43 countries. However, browser-fingerprinting and network-analysis signals pointed to a centrally coordinated infrastructure rather than a genuinely…
-
Saudi Arabia’s next AI challenge is turning infrastructure into capability
Magna AI executive says governance, operational ownership and sovereign control will determine whether organisations can scale artificial intelligence beyond pilots First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651211/Saudi-Arabias-next-AI-challenge-is-turning-infrastructure-into-capability
-
Saudi Arabia’s next AI challenge is turning infrastructure into capability
Magna AI executive says governance, operational ownership and sovereign control will determine whether organisations can scale artificial intelligence beyond pilots First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366651211/Saudi-Arabias-next-AI-challenge-is-turning-infrastructure-into-capability
-
Critical MikroTik RouterOS Vulnerability Exposes Devices to Remote Code Execution
Tags: cve, cvss, cyber, cybersecurity, infrastructure, remote-code-execution, service, vulnerabilityA critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute code on vulnerable devices or trigger a denial-of-service condition. This vulnerability, tracked as CVE-2026-84411, affects MikroTik RouterOS versions earlier than 7.24 and carries a CVSS v3 severity score of 9.8. The Cybersecurity and Infrastructure Security Agency (CISA) disclosed this issue on September…
-
U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS…
-
U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS…
-
Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover
Tags: access, cloud, credentials, cyber, identity, infrastructure, kubernetes, microsoft, software, supply-chain, theftMicrosoft has detailed a cloud-focused intrusion attributed to Storm-3068, in which attackers turned a compromised user account into a launch point for Azure DevOps abuse, Kubernetes credential theft, and potential access to connected cloud environments. The campaign demonstrates how identity compromise can quickly escalate into a software supply-chain and production-infrastructure incident when development platforms have…
-
Storm-3068 Hijacks Azure DevOps Pipelines to Steal Kubernetes Credentials After Account Takeover
Tags: access, cloud, credentials, cyber, identity, infrastructure, kubernetes, microsoft, software, supply-chain, theftMicrosoft has detailed a cloud-focused intrusion attributed to Storm-3068, in which attackers turned a compromised user account into a launch point for Azure DevOps abuse, Kubernetes credential theft, and potential access to connected cloud environments. The campaign demonstrates how identity compromise can quickly escalate into a software supply-chain and production-infrastructure incident when development platforms have…
-
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
-
South Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
-
US is looking to weave AI into critical infrastructure for cybersecurity, national cyber director says
Sean Cairncross said CEOs need to be cognizant of how it’s being used, however. First seen on cyberscoop.com Jump to article: cyberscoop.com/national-cyber-director-ai-critical-infrastructure-cybersecurity/
-
GAO report spotlights industry’s concerns about overlapping cybersecurity regulations
Representatives of three critical infrastructure sectors identified the conflicting and redundant rules that they said made their jobs much more difficult. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cybersecurity-regulation-industry-feedback-harmonization-gao/831619/
-
Wie wählen Unternehmen den optimalen Gigabit-Anschluss?
Die Anforderungen an die digitale Anbindung von Betrieben, die heute mit einer Vielzahl datenintensiver Anwendungen und vernetzter Prozesse konfrontiert sind, steigen kontinuierlich an, sodass Unternehmen zunehmend gezwungen sind, ihre bestehende Infrastruktur regelmäßig zu überprüfen und an die veränderten technischen Gegebenheiten anzupassen. Cloud-Anwendungen, hochauflösende Videokonferenzen, große Datentransfers und vernetzte Standorte setzen leistungsstarke Verbindungen voraus. Ein Gigabit-Anschluss…
-
New AI-Powered Botnet x47.c Steals Credentials and Drains AI Account Credits
Tags: ai, api, botnet, control, credentials, cyber, ddos, infrastructure, intelligence, malware, service, theft, threat, windowsA newly identified Windows botnet dubbed x47.c is marketing a blend of conventional DDoS tooling, credential theft, SOCKS5 proxying, fast-flux command-and-control infrastructure, and an “AI API drain” capability designed to exhaust victims’ paid artificial-intelligence service credits. Qrator Research Labs identified the previously undocumented malware platform during threat hunting. They traced its sale to an operator…
-
DPRK-Linked Hackers Add HashHiding to Blockchain C2 Network for Takedown-Resistant Malware
DPRK-linked operators behind the Cross-Chain TxDataHiding (XCTDH) campaign have expanded their blockchain-backed command-and-control infrastructure with a new Ethereum-based recovery channel dubbed HashHiding. The technique stores an active C2 IP address and port inside the recipient address of ordinary Ethereum transfers, allowing infected systems to recover attacker infrastructure without relying on domains, smart contracts, or transaction…
-
SilverFox Built Fake Software Sites That Know When Researchers Are Watching
SilverFox-linked operators are evolving beyond counterfeit software portals and signed-binary abuse by using visitor-aware delivery infrastructure that can distinguish potential victims from security researchers. Pelagosx recently investigated a related Windows malware delivery chain that began with a finance-themed WhatsApp message targeting Malaysian users. The message urged recipients to forward a report for verification and open…
-
SilverFox Built Fake Software Sites That Know When Researchers Are Watching
SilverFox-linked operators are evolving beyond counterfeit software portals and signed-binary abuse by using visitor-aware delivery infrastructure that can distinguish potential victims from security researchers. Pelagosx recently investigated a related Windows malware delivery chain that began with a finance-themed WhatsApp message targeting Malaysian users. The message urged recipients to forward a report for verification and open…
-
Keio Railway Confirms Ransomware Attack Disrupted Business Systems
Keio Corporation has confirmed that a ransomware attack has caused a system failure within parts of its group infrastructure, disrupting certain business systems at its affiliated companies. The Japanese railway operator stated that train services continue to operate and that it has not yet confirmed any data breach. In a public notice issued on September…
-
Nvidia Alliance to Tackle Security Across AI Agent Stack
Independent Controls Aim to Contain Agents Regardless of Model Decisions. Nvidia and 100 industry, research and public-sector organizations are building layered controls to constrain AI agents across applications, runtimes and infrastructure, as autonomous systems gain access to sensitive enterprise data, APIs, tools and credentials. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/nvidia-alliance-to-tackle-security-across-ai-agent-stack-a-32960
-
Niche AI tools pose major cybersecurity risk to infrastructure operators
Security vetting tools and processes weren’t designed with obscure AI services in mind, according to TrendAI. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-apps-niche-cybersecurity-risk-trendai/831486/
-
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
Tags: ai, breach, control, credentials, cyber, cybercrime, data, data-breach, infrastructure, Internet, phishing, toolAn internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assisted automation. Custom command-and-control tooling, phishing resources, stolen credentials, target lists, and internal operator communications. The exposure is notable not only for the scale of the material recovered, but also for its irony. Weeks later, infrastructure attributed…
-
Beyond Account-Level Risk: An Evidence-to-Action Pipeline for Detecting Fraud Rings
Linkage analysis connects accounts, devices and infrastructure to detect coordinated fraud rings that traditional account-level risk controls may fail to identify. First seen on hackread.com Jump to article: hackread.com/account-level-risk-pipeline-detecting-fraud-rings/
-
Souveräne Infrastruktur – Worldstream: Architektur wird zur Grundlage digitaler Souveränität
Tags: infrastructureFirst seen on security-insider.de Jump to article: www.security-insider.de/worldstream-architektur-wird-zur-grundlage-digitaler-souveraenitaet-a-f15ae7443140420b1a0dc54b9cfad37d/
-
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.The vulnerabilities are listed below – CVE-2026-88771 (CVSS score: 9.5) – An improper input validation vulnerability that could allow an unauthenticated attacker to First seen…
-
U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, citrix, cve, cybersecurity, exploit, flaw, infrastructure, kev, remote-code-execution, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-88771 (CVSS score: 9.5) is a remote code execution vulnerability caused by improper input validation that could allow an unauthenticated remote…

