Tag: infrastructure
-
CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance
On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/16/cisa-coordinated-vulnerability-disclosure-guidance/
-
20+ Hijacked Government Websites BecameӬan Attack Channel
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions.The investigation revealed previously undocumented backdoor behavior, hidden infrastructure relationships, and multiple attack arms behind a campaign First seen on thehackernews.com Jump to…
-
Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes
A Russian-speaking threat actor known as >>bandcampro<< used a jailbroken Gemini CLI, Google's open-source terminal-based AI agent, to deploy and operate a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/16/jailbroken-google-gemini-cli-botnet/
-
Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects
Dutch police, working with international law-enforcement partners including Europol, have disrupted a sprawling investment-fraud operation alleged to have defrauded victims across multiple countries of more than Euro100 million every month. The investigation has resulted in arrests in Poland, Cyprus, Belgium, and Greece, targeting a network that operated around twenty fraudulent call centers staffed by more…
-
CISA Warns of Actively Exploited Oracle E-Business Suite Flaw
Tags: business, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, oracle, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting CVE-2026-46817, an improper privilege management vulnerability in Oracle E-Business Suite that can lead to a takeover of Oracle Payments. The agency added the issue to its Known Exploited Vulnerabilities Catalog on July 15, 2026, and directed affected federal civilian executive…
-
Critical JetBrains Flaws Impact IntelliJ IDEA, TeamCity, and YouTrack Users
JetBrains has released security updates for IntelliJ IDEA, TeamCity, and YouTrack that address six vulnerabilities, including a critical path traversal issue that could enable code execution in IntelliJ IDEA. The fixes affect core developer tooling, CI/CD infrastructure, and issue-tracking environments, making prompt patching important for organizations that use JetBrains products in software development workflows. The…
-
US unseals indictment against alleged operators of Russian bulletproof hosting service
The Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud. First seen on therecord.media Jump to article: therecord.media/us-unseals-indictment-russians-bulletproof-hosting
-
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
U.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure. The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and infrastructure to ransomware groups that have caused billions of dollars in losses to…
-
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries.Miggo’s security team, which discovered and reported the flaws, said one “leaks the broker’s confidential OAuth First seen on thehackernews.com…
-
Phishing-as-a-Service Wenn Cyberkriminalität zum Abo-Modell wird
Mitte Juni hat das FBI im Rahmen der Operation Ghost-Hook gemeinsam mit Google und Black Lotus Labs die Plattform Outsider vom Netz genommen, einer der größten bislang bekannten Phishing-as-a-Service-Anbieter. Seit 2023 lieferte der Dienst Cyberkriminellen Phishing-Infrastruktur mit über 290 fertigen Vorlagen, die Banken, Behörden, Telekommunikationsanbieter und Einzelhändler imitierten. Die Ermittler nehmen an, dass seit der…
-
Download: The ultimate guide to network operations management
Modern network operations are too manual. Today’s IT and security teams are managing growing complexity across networks, infrastructure, tools, and workflows. The result? … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/tines-network-operations-management-guide/
-
xAI Grok CLI Exposed Developer Code Through Automatic Whole-Repository Uploads
According to a reproducible wire-level analysis of version 0.2.93, xAI’s Grok Build CLI allegedly transmitted entire Git repositories, including unread files and commit history, to xAI infrastructure by default. The researcher noted that the behavior also sent the contents of files accessed by the agent, including a test .env file containing simulated credentials, without redaction.…
-
CISA Adds Cisco IOS CSRF Flaw Enabling Arbitrary Command Execution to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2008-4128, a cross-site request forgery (CSRF) vulnerability affecting Cisco IOS, to its Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability was officially listed on July 13, 2026, with a remediation deadline of July 16, 2026, for Federal Civilian Executive Branch agencies. Although this vulnerability dates back…
-
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
Tags: attack, credentials, cyber, data, ddos, government, group, infrastructure, iran, leak, network, service, technologyA decentralized network of pro-Iran hacktivist groups is intensifying cyber operations against critical infrastructure, government entities, technology providers, and organizations perceived as aligned with U.S., Israeli, or Western interests. The activity is dominated by distributed denial-of-service attacks, defacements, credential-focused operations, data-leak claims, and propaganda designed to convert limited technical disruption into outsized psychological and reputational…
-
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
Tags: attack, credentials, cyber, data, ddos, government, group, infrastructure, iran, leak, network, service, technologyA decentralized network of pro-Iran hacktivist groups is intensifying cyber operations against critical infrastructure, government entities, technology providers, and organizations perceived as aligned with U.S., Israeli, or Western interests. The activity is dominated by distributed denial-of-service attacks, defacements, credential-focused operations, data-leak claims, and propaganda designed to convert limited technical disruption into outsized psychological and reputational…
-
NSA Warns Russian State-Sponsored Hackers Exploiting Vulnerable Routers to Target Critical Infrastructure
Tags: access, advisory, cyber, cybersecurity, exploit, hacker, infrastructure, international, network, router, russia, threat, vulnerabilityThe U.S. National Security Agency (NSA) and international cybersecurity partners have issued a warning that Russian state-sponsored threat actors are actively exploiting vulnerable and poorly configured network routers to access organizations in critical infrastructure sectors. In a joint Cybersecurity Advisory (CSA) titled >>Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,<< released on July 13,…
-
Sentra CEO: Small AI Models Cut Cost of Data Classification
Yoav Regev Says Small LMs Deliver High Accuracy Without Large Infrastructure. Sentra co-founder and CEO Yoav Regev says advances in small language models enable organizations to classify unstructured data with high accuracy inside customer environments, improving privacy, reducing infrastructure costs and strengthening AI-driven data governance. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/sentra-ceo-small-ai-models-cut-cost-data-classification-a-32217
-
Vectra AI CEO: Network Data Drives Predictive Security
Hitesh Sheth: Cloud, SaaS, Data Center Visibility Boosts Enterprise Risk Assessment. Vectra AI CEO Hitesh Sheth says comprehensive network observability provides the most reliable foundation for predictive cybersecurity because it spans cloud, SaaS and on-premises infrastructure while offering telemetry that attackers are far less able to manipulate than endpoint logs. First seen on govinfosecurity.com Jump…
-
U.S. CISA adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cisco, cve, cybersecurity, exploit, flaw, infrastructure, kev, router, service, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco IOS flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco IOS flaw, tracked as CVE-2008-4128, to its Known Exploited Vulnerabilities (KEV) catalog. Cisco IOS 12.4 running on Cisco 871 Integrated Services Routers contains multiple CSRF flaws in…
-
UK and EU impose sanctions on hacking groups linked to Kremlin
Tags: attack, credentials, group, hacker, hacking, infrastructure, intelligence, router, russia, theft, vulnerabilityHackers linked to Russian intelligence behind attack on Poland’s energy infrastructure, theft of credentials and using vulnerable routers to attack critical national infrastructure First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645662/UK-and-EU-impose-sanctions-on-hacking-groups-linked-to-Kremlin
-
Officials once again warn defenders that Russian hackers are targeting network devices
State-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care. First seen on cyberscoop.com Jump to article: cyberscoop.com/russian-fsb-cisco-joint-cybersecurity-advisory/
-
CISA warns of actively exploited RCE flaws in Joomla extensions
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-rce-flaws-in-joomla-extensions/
-
EU Targets FSB-Linked Hackers in New Sanctions Over Cyber Sabotage
EU sanctions target nine people and four entities tied to Russia’s FSB over a 15-year cyberespionage and critical infrastructure sabotage campaign. The European Union imposed sanctions on Monday targeting nine individuals and four entities linked to a Russian cyberespionage and sabotage operation that Brussels says has been running since 2010. The targets include Russian military…
-
US and allies warn of Russian critical infrastructure attacks
Cybersecurity agencies from the United States and eight other countries have issued a joint warning that Russian state hackers are targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-and-allies-share-defense-tips-against-russian-hackers-targeting-critical-infrastructure/
-
CISA Warns of Actively Exploited Joomla Zero-Day Vulnerabilities
Tags: attack, cisa, cvss, cybersecurity, exploit, flaw, infrastructure, kev, malicious, vulnerability, zero-dayThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities (KEV) catalog after reports confirmed active zero-day attacks targeting the iCagenda and Balbooa extensions for Joomla. Both flaws carry the maximum CVSS severity score of 10.0 and can allow attackers to upload malicious files that ultimately lead to remote code execution. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/cisa-cve-2026-48939-cve-2026-56291/
-
CISA Warns of Actively Exploited iCagenda and Balbooa Forms File Upload Flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two file-upload vulnerabilities, affecting iCagenda and Balbooa Forms, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation in the wild. The alert was issued on July 10, 2026, identifying these flaws as vulnerabilities that allow unrestricted file uploads of dangerous types.…
-
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation in the wild.The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below – CVE-2026-48939 – A vulnerability in the First…
-
AI Gateways Offer Attackers the Keys to the Kingdom
A cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ai-gateways-keys-kingdom
-
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains.The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved…

