Tag: infrastructure
-
FortiBleed Hacks Tied to INC Ransom and Lynx Operation
Theat Actor Accessed INC and Lynx Ransom Negotiation Panels. SOCRadar linked the FortiBleed credential-harvesting operation to ransomware groups INC Ransom and Lynx, citing evidence that a sophisticated initial access broker compromised more than 430,000 FortiGate firewalls, prioritized high-value organizations and enabled ransomware attacks against governments, critical infrastructure and major enterprises. First seen on govinfosecurity.com Jump…
-
U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, update, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of May, Microsoft released security updates…
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
CISA Adds Actively Exploited Microsoft SharePoint Vulnerability to KEV Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has recently added a newly discovered vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) Catalog. This addition highlights the active exploitation risks present in enterprise environments. The vulnerability falls under the CWE-502 (Deserialization of Untrusted Data) category, allowing an authenticated attacker to…
-
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions.”An operator tied to FortiBleed’s infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment First seen on thehackernews.com Jump to…
-
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue First seen…
-
LSHIY Password Spray Attack Hits Microsoft 365 Accounts With 81 Million Login Attempts
A large-scale password spray campaign linked to the infrastructure provider LSHIY LLC has targeted Microsoft 365 environments, resulting in over 81 million login attempts. This campaign has led to at least 78 confirmed account compromises across 64 organizations between June 12 and June 26, 2026. According to researchers from Huntress, the activity primarily originates from…
-
MeetingTV Sues Palo Alto Networks Over Koi Threat Report
Tags: ai, china, cybercrime, cybersecurity, infrastructure, intelligence, malware, network, threat, toolMeetingTV Says Koi’s AI Analysis Tool Wrongly Tied it to Malware Infrastructure. MeetingTV alleges an AI-assisted threat intelligence report published by Koi Security falsely linked its infrastructure to a Chinese cybercrime operation, while Koi parent Palo Alto Networks argues the report reflects protected cybersecurity analysis rather than actionable false statements. First seen on govinfosecurity.com Jump…
-
Turning Indicators into Intelligence in OpenCTI with Criminal IP
Threat intelligence is only as useful as the context behind it. Criminal IP explains how its integration enriches threat indicators in OpenCTI with risk scoring, infrastructure intelligence, and phishing analysis. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/turning-indicators-into-intelligence-in-opencti-with-criminal-ip/
-
Mitigating Attacks Before They Impact Infrastructure: Link11 provides next generation network DDoS protection
Frankfurt am Main, Deutschland, July 1st, 2026, CyberNewswire Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing complexity of modern network attacks. Today’s DDoS attacks are not just simple volume or protocol attacks anymore. They can originate…
-
Mitigating Attacks Before They Impact Infrastructure: Link11 provides next generation network DDoS protection
Frankfurt am Main, Deutschland, July 1st, 2026, CyberNewswire Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing complexity of modern network attacks. Today’s DDoS attacks are not just simple volume or protocol attacks anymore. They can originate…
-
Mitigating Attacks Before They Impact Infrastructure: Link11 provides next generation network DDoS protection
Frankfurt am Main, Deutschland, 1st July 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/mitigating-attacks-before-they-impact-infrastructure-link11-provides-next-generation-network-ddos-protection/
-
Mitigating Attacks Before They Impact Infrastructure: Link11 provides next generation network DDoS protection
Frankfurt am Main, Deutschland, 1st July 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/mitigating-attacks-before-they-impact-infrastructure-link11-provides-next-generation-network-ddos-protection/
-
CISA Adds Actively Exploited SimpleHelp Vulnerability to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical vulnerability in SimpleHelp, tracked as CVE-2026-48558, and added it to its Known Exploited Vulnerabilities (KEV) catalog. This indicates that the vulnerability is actively being exploited in the wild, and CISA is urging immediate remediation. The flaw, classified as CWE-347 (Improper Verification of Cryptographic…
-
CISA Adds Actively Exploited SimpleHelp Vulnerability to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical vulnerability in SimpleHelp, tracked as CVE-2026-48558, and added it to its Known Exploited Vulnerabilities (KEV) catalog. This indicates that the vulnerability is actively being exploited in the wild, and CISA is urging immediate remediation. The flaw, classified as CWE-347 (Improper Verification of Cryptographic…
-
The Gentlemen Ransomware Targets Large Corporations and Critical Infrastructure Worldwide
The Gentlemen ransomware group has emerged in 2026 as a highly adaptive and technically sophisticated ransomware-as-a-service (RaaS) operation targeting large corporations and critical infrastructure across multiple regions. Public reporting places The Gentlemen among the top 10 ransomware actors by victim announcements on its data leak site during the first half of 2026 (see ransomware.live/stats/2026), and…
-
RedLine Infostealer Thread Reveals Hidden Maritime Phishing and BEC Infrastructure
A routine threat-feed alert for a RedLine Stealer command-and-control (C2) IP morphed into a full-scale pivot investigation that exposed a tailored maritime spear”‘phishing and business email compromise (BEC) ecosystem. The starting signal a UniqueSignal entry from VMRay identified 194[.]156.79.122:55615 as a RedLine-associated host. That solitary indicator, combined with targeted forensic pivots across VirusTotal, FOFA, Censys…
-
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Cybersecurity researchers have warned of a “massive, ongoing, automated password spray attack” aimed at Microsoft’s Azure command-line interface (CLI), compromising dozens of accounts in the process.The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/32) controlled by internet infrastructure provider LSHIY LLC (AS32167).”Between June 12 and June 26, the threat First seen on thehackernews.com…
-
Leaders call for workforce overhaul as AI reshapes critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/analysis/leaders-call-for-workforce-overhaul-as-ai-reshapes-critical-infrastructure
-
Leaders call for workforce overhaul as AI reshapes critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/analysis/leaders-call-for-workforce-overhaul-as-ai-reshapes-critical-infrastructure
-
ICIT founder on AI, quantum and critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/feature/icit-founder-on-ai-quantum-and-critical-infrastructure
-
DHS proposes new system for public-private infrastructure security collaboration
The Trump administration eliminated the previous framework in 2025, sparking a backlash from experts and infrastructure operators. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-infrastructure-collaboration-dhs-anchor-ci/824081/
-
DHS to unveil replacement council for critical infrastructure cybersecurity
The Department of Homeland Security is bringing back a key cybersecurity information sharing effort with critical infrastructure, more than a year after the Trump administration shuttered an existing nerve center between government and private sector. The Alliance of National Councils for Homeland Operational Resilience Critical Infrastructure program,first reported by CyberScoop in January, is meant […]…
-
DHS proposes new framework for public-private infrastructure security collaboration
The Trump administration eliminated the previous system in 2025, sparking a backlash from experts and infrastructure operators. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-infrastructure-collaboration-dhs-anchor-ci/824081/
-
What the Numbers Say About FIFA 2026 Cyber Risk
The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-planned, months out, across three sectors and at least ten languages.Check Point Exposure Management published the FIFA World Cup 2026 Cyber…
-
Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments
Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical usability refinements that will matter to both pentesters and platform maintainers. The release emphasizes polish and performance rather than headline-grabbing features: GNOME advances to version 50 and KDE Plasma to 6.6.…
-
JSP webshells being dropped on unpatched PTC Windchill instances
The US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/29/ptc-windchill-cve-2026-12569-exploited/
-
Reconnaissance in the Age of AI: Exploring Modern ML Infrastructure
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/reconnaissance-in-the-age-of-ai-exploring-modern-ml-infrastructure
-
Straiker Raises $64M to Safeguard Autonomous AI Agents
Series A Funding Supports Pre-Training, Reinforcement Learning for Security Models. AI security startup Straiker closed a $64 million Series A funding round to expand GPU infrastructure, develop specialized security models and strengthen defenses against increasingly autonomous enterprise AI agents capable of operating with minimal human oversight. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/straiker-raises-64m-to-safeguard-autonomous-ai-agents-a-32093

