Tag: infrastructure
-
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why…
-
New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network
AvisLoader, a newly observed Windows malware loader designed to maintain operator access even when conventional command-and-control infrastructure is disrupted. Instead of relying on a fixed domain, IP address, or centralized server, the malware uses the encrypted Tox peer-to-peer messaging network to receive commands and deliver follow-on payloads. The discovery highlights a growing challenge for defenders:…
-
Wie Fertigungsunternehmen produktionskritische Systeme mit Mikrosegmentierung schützen
Produktionsnetze müssen verfügbar bleiben auch während Sicherheitsmaßnahmen eingeführt werden. Identitätsbasierte Mikrosegmentierung und Just-in-Time-MFA begrenzen seitliche Bewegungen im Netz, schützen privilegierte Zugriffe und beziehen Altsysteme ein, ohne die gewachsene OT-Infrastruktur grundlegend umzubauen. Drei Praxisbeispiele zeigen, wie sich Resilienz, Nachweisfähigkeit und Betriebssicherheit zusammenführen lassen. Mikrosegmentierung teilt die vernetzte Produktion in kontrollierbare Sicherheitszonen und begrenzt privilegierte… First seen…
-
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators, separate from another administration-proposed pilot program. First seen on cyberscoop.com Jump to article: cyberscoop.com/gottheimer-ai-cyber-defense-act-cisa-pilot/
-
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a stack-based buffer overflow that could allow attackers…
-
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a stack-based buffer overflow that could allow attackers…
-
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a stack-based buffer overflow that could allow attackers…
-
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a stack-based buffer overflow that could allow attackers…
-
CISA orders feds to patch Zyxel flaw exploited for data theft
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/
-
CISA Flags Actively Exploited Flaw in Zyxel GS1900 Switches
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included a high-severity vulnerability affecting Zyxel GS1900 Series switches in its Known Exploited Vulnerabilities (KEV) Catalog. This warning highlights that the flaw, tracked as CVE-2026-7273, has been exploited in the wild. The vulnerability stems from a stack-based buffer overflow in the device’s CGI program. CISA added…
-
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating First seen on thehackernews.com…
-
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating First seen on thehackernews.com…
-
CISA alerts of active exploitation of three Linux kernel flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/
-
Russia reports thousands of cyberattacks on election infrastructure during vote
Claims by officials of cyberattacks against election infrastructure could not be independently verified. Russian officials provided little technical evidence about the attacks or who it claimed who was behind them. First seen on therecord.media Jump to article: therecord.media/russia-reports-cyberattacks-during-election
-
North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning systems in Pyongyang and Russia’s Far East. The certificate’s Subject Alternative Name field lists the platform’s publicly exposed servers alongside a carrier-grade NAT address, offering an unusual glimpse into how the service may be…
-
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.”ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software,” Blackpoint Adversary Pursuit Group (APG) First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
Tags: backdoor, banking, blockchain, business, control, credentials, cyber, infrastructure, malware, powershellA newly uncovered EtherHiding campaign has turned the Polygon blockchain into a resilient command-and-control mechanism, allowing operators to rotate malware infrastructure without modifying the payload deployed on victim systems. The operation, active since at least November 2025, has compromised at least 31 legitimate business websites and evolved from deploying a general-purpose PowerShell backdoor to distributing…
-
Digitale Infrastruktur: Warum Rechenzentren mehr Resilienz gegen Cyberrisiken und Energieengpässe brauchen
Digitale Infrastrukturen werden zum Rückgrat von Wirtschaft, KI und vernetzten Geschäftsmodellen. Doch mit dem Wachstum von Rechenzentren steigen auch die systemischen Risiken: Cyberangriffe, Energieengpässe, Klimafolgen und Lieferkettenstörungen wirken immer häufiger zusammen. Die Studie von Economist Enterprise und FM zeigt, dass Unternehmen zwar in Resilienz investieren, aber komplexe Krisenszenarien noch zu selten ganzheitlich testen [1]. Management……
-
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerabilities are listed below – CVE-2025-39682 (CVSS score: 9.8) – An improper check for unusual or exceptional conditions vulnerability in the TLS receive path First…
-
Cyber Defense Alone Can’t Keep Critical Services Running
States Must Map Dependencies and Engineer Safeguards for Water and Hospitals. State CIOs must decide which water systems, hospitals and other essential services need protection first. NASCIO data shows why states should rank infrastructure by consequence, test simultaneous failures and pair cyber defenses with engineering safeguards. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-defense-alone-cant-keep-critical-services-running-a-32871
-
ISMG Editors: Even Valid Email Addresses Can’t Be Trusted
Also: States Inherit America’s Cyber Burden, AI Agents Reshape the MSSP Market. In this week’s panel, four ISMG editors discuss an unusual breach at U.K. digital banking platform Revolut, the growing role of U.S. state governments in protecting local critical infrastructure and what a new cybersecurity acquisition tells us about the AI-powered SOC. First seen…
-
PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains
China-aligned threat actors are using low-quality Chinese-language casino and adult websites to conceal PeckBirdy command-and-control infrastructure, creating a detection challenge for enterprises that routinely deprioritize gambling-related domains. Infoblox telemetry found that just over 3% of enterprise customers resolved at least one PeckBirdy-related C2 domain, indicating that the infrastructure is appearing well beyond the campaign’s apparent…
-
JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data
Tags: ai, attack, cyber, data, data-breach, extortion, group, infrastructure, intelligence, ransomware, threat, trainingJADEPUFFER, the agentic threat actor first linked to an autonomous ransomware operation against exposed Langflow infrastructure, has evolved its tooling to target artificial intelligence models, training datasets, and vector data. Its latest payload, ENCFORGE, marks a shift from conventional database extortion toward destruction-focused attacks on high-value AI and machine-learning assets. The group’s ENCFORGE locker targets…
-
FBI Seizes NightmareStresser DDoSHire Domains Used in Hundreds of Thousands of Attacks
The FBI has seized internet domains linked to NightmareStresser, a long-standing distributed denial-of-service (DDoS)-for-hire platform allegedly used to launch hundreds of thousands of attacks or attempted attacks worldwide since 2022. The U.S. Attorney’s Office for the District of Alaska announced the action, which targets the infrastructure that allowed paying customers to overwhelm victims’ networks and…
-
States Expand Cyber Support Beyond Their Own Networks
Local Control and Funding Gaps Complicate Critical Infrastructure Protection. States are extending cyber support to local utilities and other essential services they do not control. Closing the gap will require more than grants and tools. Local operators need sustained monitoring, OT expertise and stronger, consistent vendor controls. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/states-expand-cyber-support-beyond-their-own-networks-a-32858
-
States Expand Cyber Support Beyond Their Own Networks
Local Control and Funding Gaps Complicate Critical Infrastructure Protection. States are extending cyber support to local utilities and other essential services they do not control. Closing the gap will require more than grants and tools. Local operators need sustained monitoring, OT expertise and stronger, consistent vendor controls. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/states-expand-cyber-support-beyond-their-own-networks-a-32858
-
States Expand Cyber Support Beyond Their Own Networks
Local Control and Funding Gaps Complicate Critical Infrastructure Protection. States are extending cyber support to local utilities and other essential services they do not control. Closing the gap will require more than grants and tools. Local operators need sustained monitoring, OT expertise and stronger, consistent vendor controls. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/states-expand-cyber-support-beyond-their-own-networks-a-32858
-
Korean AI Benchmark Exposes Gaps in Multilingual Safety
Scale AI Finds Model Guardrails Shift With Language and Cultural Context. AI infrastructure company Scale AI partnered with the Korean AI Safety Institute to develop a benchmark called ROK-Fortress. They found that many AI models adhere to safety guidelines more often when prompted in Korean, rather than English. First seen on govinfosecurity.com Jump to article:…

