Tag: infrastructure
-
Chinese Hackers Use RedRelay Multi-Hop Network to Conceal Global Cyber Operations
Chinese state-linked hackers are increasingly relying on a covert multi-hop infrastructure dubbed RedRelay (also known as ORBWEAVER) to mask the origins of global cyber operations, with evidence pointing to little-known Guangdong Chanming as a key enabler behind the network. Guangdong Chanming, a low”‘visibility company with no public”‘facing products or marketing, has quietly amassed a portfolio…
-
U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: CVE-2025-68686 is an…
-
Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic
Operation STANDOFF is a Russian”‘speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb”‘hosted servers that all masquerade as benign GitHub redirectors to conceal multi”‘malware command”‘and”‘control (C2) and proxy traffic. This infrastructure underpins a full ecosystem: a pay”‘per”‘install loader, a proxy”‘botnet, a multi”‘operator intrusion console, and an AI”‘driven influence and outreach platform. All…
-
OpenAI-Hugging Face Incident: What We Know
An experimental AI agent powered by OpenAI models has successfully compromised part of Hugging Face’s infrastructure during a controlled cybersecurity evaluation, offering a glimpse into the evolving offensive capabilities of advanced AI systems. The incident, first disclosed by Hugging Face last week, has now been confirmed by OpenAI to have involved a combination of its…
-
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring and management (RMM) tools.”The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened,” ZeroBEC said in First…
-
Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware
A newly uncovered cluster of more than 70 impersonation domains targeting popular Windows applications is raising fresh concerns about a scalable malware distribution campaign that leverages trust in legitimate software ecosystems. The discovery, triggered by a developer investigating unusual search results for their own application, reveals a coordinated infrastructure designed to mimic well-known tools while…
-
Iranian Hackers Exploit Rockwell, Schneider and Siemens PLCs Across U.S. Critical Infrastructure
Tags: advisory, automation, cisa, cyber, cybersecurity, exploit, hacker, infrastructure, Internet, iran, technology, threatIranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-connected programmable logic controllers (PLCs) from major industrial vendors, including Rockwell Automation, Schneider Electric, and Siemens, targeting U.S. critical infrastructure sectors. A joint cybersecurity advisory (AA26-097A) released by the FBI, CISA, NSA, DOE, EPA, Treasury, and U.S. Cyber Command highlights sustained exploitation activity against operational technology…
-
Europäische Cloud-Infrastruktur – Bitdefender startet Programm für souveräne EU-Cybersicherheit
First seen on security-insider.de Jump to article: www.security-insider.de/bitdefender-startet-programm-fuer-souveraene-eu-cybersicherheit-a-4b64c85fe44fe2cd7d064a63bd94011c/
-
Wenn der Test zur Attacke wird: Der OpenAI-Vorfall als Weckruf für die KI-Sicherheit
Ein autonomer KI-Agent verlässt eine isolierte Testumgebung, verschafft sich Zugang zum offenen Internet und kompromittiert die Infrastruktur einer fremden Plattform. Der Vorfall bei Hugging Face markiert eine Zäsur: Aus der theoretischen Debatte über agentische Risiken ist eine konkrete Herausforderung für Cyberabwehr, Modelltests und Regulierung geworden. Die entscheidende Erkenntnis: Hochleistungsmodelle sind nicht mehr nur Werkzeuge,……
-
US warns of Iran-linked attacks on critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/news/us-warns-of-iran-linked-attacks-on-critical-infrastructure
-
Hackers Exploit Industrial PLCs and Manipulate HMI Displays to Hide Attacks
Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure, manipulating human-machine interface (HMI) displays so operators cannot visually detect the intrusion. The advisory, first issued in April 2026 and revised on July 22, 2026, is cosigned…
-
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
Tags: advisory, apt, cybersecurity, email, exploit, flaw, government, group, infrastructure, international, russiaUS agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT…
-
Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing
Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required. ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff. Since at least June 2026, threat actors have…
-
Cloudflare CEO: How AI Commerce Is Upending the Web Economy
Matthew Prince: AI Assistants Are Replacing Traditional Search and Commerce Models. Cloudflare’s CEO said AI assistants are replacing traditional search and advertising-driven internet models, arguing that AI firms and search engines must adopt more efficient, event-driven crawling to reduce infrastructure costs while preparing for an AI-first internet powered by autonomous agents. First seen on govinfosecurity.com…
-
U.S. CISA adds Microsoft SharePoint and Check Point SmartConsole flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: The first flaw added to the KeV…
-
CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy
The agencies said threat groups have disrupted critical infrastructure sites by exploiting vulnerable PLC devices. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-fbi-iran-hackers-target-water-energy/826025/
-
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances.The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13, First seen on thehackernews.com…
-
Unknown Attackers Remain Inside South Korean Diplomatic System for Nearly 10 Months
Unknown attackers maintained long-term, covert access to South Korea’s diplomatic training infrastructure for nearly ten months, exposing personal data tied to almost the entire diplomatic cadre and highlighting structural weaknesses in the Foreign Ministry’s security governance. South Korea’s Ministry of Foreign Affairs (MoFA) has confirmed a prolonged compromise of the Korea National Diplomatic Academy (KNDA)…
-
26 Unauthenticated Vulnerability Advisories Expose Firewalls, VPNs, Switches, and Load Balancers
A structural risk in enterprise infrastructure: unauthenticated, remotely exploitable vulnerabilities embedded in the very devices designed to secure networks. In the 30 days ending July 17, 2026, 61 advisories across 14 vendors were disclosed, including six critical issues. However, the more consequential signal lies elsewhere 26 of those advisories require no authentication. They are reachable…
-
CISA Urges Organizations to Remove Rockwell PLCs From Direct Internet Exposure
CISA and partner agencies are directing U.S. critical infrastructure operators to immediately remove Rockwell and other programmable logic controllers (PLCs) from direct internet exposure and to hunt for Iranian-affiliated APT activity in OT environments aggressively. In a joint advisory first issued on April 7, 2026 and updated on July 22, 2026, the FBI, CISA, NSA,…
-
Bundeskriminalamt zerschlägt Phishing-Plattform Kratos
Am 20. Juli 2026 zerschlugen Bundeskriminalamt und ZIT (Zentralstelle zur Bekämpfung der Internetkriminalität) gemeinsam mit US-Behörden im Rahmen der Operation ‘Olympus Blade” die Infrastruktur von Kratos einer Phishing-as-a-Service-Plattform, die für einen Großteil der aktuellen Microsoft-365-Credential-Diebstähle verantwortlich war. Der Entwickler und technische Administrator wurde in Indonesien verhaftet, über 200 Server wurden abgeschaltet. Zuvor nutzen mehr […]…
-
How AI-Driven Robotics Expands Industrial Cyber Risk
CEO: Connected Factories and Hospitals Expose Legacy OT Systems to Modern Threats. Claroty CEO Yaniv Vardi says physical AI will accelerate robotics and industrial automation while making cyber-physical security a strategic priority as connected operational technology exposes critical infrastructure to attacks with real-world consequences. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/how-ai-driven-robotics-expands-industrial-cyber-risk-a-32303
-
Why Quantum Migration Starts With Security Infrastructure
IBM: Security Leaders Should Assess Supplier Adoption of Quantum-Safe Cryptography. IBM’s Suja Viswesan said organizations should begin post-quantum migration by evaluating security infrastructure vendors, prioritizing cryptography-heavy environments such as telecom and critical infrastructure, and treating quantum readiness as an ongoing business-driven modernization program. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/quantum-migration-starts-security-infrastructure-a-32301
-
EU Huawei Ban Backlash Report Exaggerated, Says Critic
GSMA Intelligence Says Ejecting Huawei Equipment Will Cost Up to 40B Euros. European mobile network operators would have to shell out as much as 40 billion euros – or $45.7 billion – in direct costs to kick high-risk suppliers such as Huawei out of their infrastructure, asserts the research arm of the industry’s main trade…
-
New InfraTrust report reveals infrastructure flaws admins should patch first
Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, networking, and edge devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-infratrust-report-reveals-infrastructure-flaws-admins-should-patch-first/
-
Singapore to hold CII boards accountable as AI reshapes OT threat landscape
The Cyber Security Agency’s first update to its critical infrastructure code of practice since 2022 will make boards directly answerable for cyber resilience First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646154/Singapore-to-hold-CII-boards-accountable-as-AI-reshapes-OT-threat-landscape
-
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added DD-WRT, Langflow, and WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the KeV catalog: The first issue added to the catalog…
-
CISA orders urgent action on actively exploited Langflow RCE flaw
Tags: ai, cisa, cybersecurity, exploit, flaw, framework, government, infrastructure, rce, remote-code-execution, update, vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw/
-
CISA Warns WordPress Core SQL Injection Vulnerability Is Actively Exploited in Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, infrastructure, injection, kev, sql, vulnerability, wordpressThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has classified a critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-60137, as one of its Known Exploited Vulnerabilities (KEV) due to its active exploitation in real-world attacks. This vulnerability affects the core functionality of WordPress when themes or plugins fail to properly validate untrusted input…
-
Police dismantle Kratos phishing platform behind 15,000 monthly campaigns
German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/bka-fbi-kratos-phishing-platform-takedown/

