Tag: infrastructure
-
Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk
Cyberattacks on oil tankers show how connected ships can expose navigation and critical systems, threatening safety, ports and global trade. U.S. Coast Guard personnel and FBI agents boarded two Texas”‘bound energy tankers last month after cyberattacks hit the vessels while they were underway, according to U.S. officials. One of the ships was the VL Prosperity,…
-
SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets
Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command”‘and”‘control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the…
-
Hackers claim breach of Russian election systems days before parliamentary vote
An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament. First seen on therecord.media Jump to article: therecord.media/russia-election-hackers-breach
-
CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-critical-infrastructure-cyber/
-
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/aws-middle-east-outage-permanent-data-loss-bahrain-uae/
-
CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled >>Using Cyber Decoys to Strengthen Detection and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/cisa-guidance-for-implementing-cyber-decoys/
-
SilkParasite Hackers Use SpiceRAT Infrastructure to Target Central Asian Governments and Energy Firms
A wider cluster of SpiceRAT command-and-control infrastructure has been linked to the SilkParasite cyber-espionage activity targeting government, telecommunications, and energy-related entities across Central Asia. The infrastructure findings extend the operational footprint around servers previously associated with the suspected China-nexus cluster, but do not establish that any impersonated organization was compromised. Detection logic derived from Cisco…
-
CISA Urges Organizations to Deploy Cyber Decoys to Detect Hackers Inside Networks
Tags: cisa, credentials, cyber, cybersecurity, data, detection, hacker, infrastructure, network, strategyThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations to deploy cyber decoys, which include fake credentials, systems, data, and services. This strategy aims to expose attackers sooner and enhance post-compromise detection. In new guidance titled >>Using Cyber Decoys to Strengthen Detection and Response,<< published on September 16, 2026, CISA outlined how defenders…
-
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
Ports, railroads, and utilities keep the military operational. They’re all vulnerable to Iranian cyberattacks. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/
-
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin’s AI use
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/
-
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
Tags: api, authentication, backup, cisa, cisco, cve, cybersecurity, exploit, flaw, google, identity, infrastructure, kev, service, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, CiscoISE, and Google Pixelflaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw…
-
CISA promotes a fresh way to deter cyberattackers: Lie to them
It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries. First seen on cyberscoop.com Jump to article: cyberscoop.com/cisa-guidance-cyber-decoys-critical-infrastructure/
-
BTS #82 Firmware Analysis, Linux Malware, Future of AI
Below the Surface episode 82 was recorded on September 10, 2026, with host Paul Asadoorian joined by Vlad Babkin and Chase Snyder. The conversation moves across several current security stories, but its center of gravity is clear: modern infrastructure depends… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/bts-82-firmware-analysis-linux-malware-future-of-ai/
-
CISA looks to recruit general infrastructure security experts rather than sector-focused advisers
“I need people that can pivot from day to day,” the agency’s acting chief told reporters. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-critical-infrastructure-experts-hiring-ai-election-security/830550/
-
Hybrid AI Is Coming. Is Your Infrastructure Ready?
A few months ago, I wrote about why I believe enterprise AI is evolving toward Hybrid AI, with organizations using different models and services for different workloads rather than relying on a single provider. The economics, performance, security, governance, and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hybrid-ai-is-coming-is-your-infrastructure-ready/
-
Wie Angreifer die Microsoft-365-Funktion ‘Direct Send” ausnutzen
KnowBe4 Threat Lab dokumentiert fast 30.000 gefälschte interne E-Mails in nur zwei Monaten, versendet über die eigene Infrastruktur der Opfer und ganz ohne Passwort oder gestohlene Zugangsdaten. E-Mails genießen im Arbeitsalltag einen Vertrauensvorschuss. Wenn eine Nachricht scheinbar aus der Personalabteilung, der Buchhaltung oder von der Geschäftsführung kommt, wird sie selten hinterfragt. Genau diesen Reflex machen…
-
Wie Angreifer die Microsoft-365-Funktion ‘Direct Send” ausnutzen
KnowBe4 Threat Lab dokumentiert fast 30.000 gefälschte interne E-Mails in nur zwei Monaten, versendet über die eigene Infrastruktur der Opfer und ganz ohne Passwort oder gestohlene Zugangsdaten. E-Mails genießen im Arbeitsalltag einen Vertrauensvorschuss. Wenn eine Nachricht scheinbar aus der Personalabteilung, der Buchhaltung oder von der Geschäftsführung kommt, wird sie selten hinterfragt. Genau diesen Reflex machen…
-
Wie Angreifer die Microsoft-365-Funktion ‘Direct Send” ausnutzen
KnowBe4 Threat Lab dokumentiert fast 30.000 gefälschte interne E-Mails in nur zwei Monaten, versendet über die eigene Infrastruktur der Opfer und ganz ohne Passwort oder gestohlene Zugangsdaten. E-Mails genießen im Arbeitsalltag einen Vertrauensvorschuss. Wenn eine Nachricht scheinbar aus der Personalabteilung, der Buchhaltung oder von der Geschäftsführung kommt, wird sie selten hinterfragt. Genau diesen Reflex machen…
-
TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Tags: access, authentication, cctv, cve, cyber, cybersecurity, flaw, infrastructure, network, password, vulnerabilitySecurity researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass administrator authentication or disrupt the device’s management service. Khoi Tran and Thai Do from OPSWAT Unit 515 discovered these vulnerabilities, tracked as CVE-2026-15315 and CVE-2026-15316, during the company’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. TP-Link…
-
Critical ScreenConnect flaw now actively exploited in attacks
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw/
-
Pakistan Finalizes 90-Day Cybersecurity Action Plan, Federal CERT to Lead Rollout
Pakistan’s federal government has completed work on a 90-day cybersecurity action plan designed to build a more coordinated national defense against digital threats, bringing together federal and provincial governments, regulators and operators of critical infrastructure under one framework. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/pakistan-cybersecurity-action-plan/
-
Pakistan Finalizes 90-Day Cybersecurity Action Plan, Federal CERT to Lead Rollout
Pakistan’s federal government has completed work on a 90-day cybersecurity action plan designed to build a more coordinated national defense against digital threats, bringing together federal and provincial governments, regulators and operators of critical infrastructure under one framework. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/pakistan-cybersecurity-action-plan/
-
China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic into apparent gambling activity. The activity expands on earlier findings by Trend Micro, which identified PeckBirdy as a flexible JScript-based C2 framework used by China-aligned…
-
CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks
Tags: cisa, control, cyber, cybersecurity, defense, exploit, guide, hacker, identity, infrastructure, international, networkThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has collaborated with international partners to guide the defense of Active Directory (AD). They warn that attackers exploit 17 common techniques to gain control of identity infrastructure. The guide, released on September 15, was co-authored by the Australian Signals Directorate’s Australian Cyber Security Center, CISA, the NSA,…
-
U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
Tags: cisa, cisco, cve, cybersecurity, email, exploit, flaw, infrastructure, kev, vulnerability, zero-dayU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76461 this week;…
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
From the massive DOGE data breach and the compromise of critical infrastructure to the hack of federal surveillance systems, here are the most damaging security incidents and data breaches of 2026 so far. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/15/the-worst-hacks-and-breaches-of-2026-so-far/

