Tag: infrastructure
-
CISA scraps 6 free cybersecurity assessments for critical infrastructure operators
The agency’s decision, spurred by workload concerns, could leave organizations without valuable insights into their vulnerabilities. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/cisa-cybersecurity-assessments-ending/829371/
-
427 or 4 Devices?: Measuring Internet-Exposed Industrial Infrastructure in the UK
By Adrian Cheek, Senior Cybercrime Researcher On August 22, 2026, The Telegraph reported that a small UK power generator had been shut down for four days in July following a cyberattack by hackers linked to Iran. The government confirmed that… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/427-or-4-devices-measuring-internet-exposed-industrial-infrastructure-in-the-uk/
-
Sality botnet infrastructure dismantled in joint global takedown
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/
-
Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems
Tags: cyber, government, healthcare, infrastructure, kaspersky, malware, microsoft, software, technology, windowsAn active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise Windows devices. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, highlighting the broad appeal of software-download lures. Microsoft has not attributed the activity to a nation-state actor, but the campaign’s infrastructure, payload…
-
China-linked campaign targets high-value networks, critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/news/fire-ant-campaign-targets-high-value-networks-and-critical-infrastructure
-
Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025,…
-
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/
-
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/why-even-the-best-edge-security-still-misses-high-risk-sessions/
-
EtherHiding Exposed: What Security Leaders Need to Know
EtherHiding Exposed: What Security Leaders Need to Know September 1, 2026 Jean-Pierre Mouton BLOG 5 min. TL;DR A malware campaign has compromised at least 31 organizations’ websites to deploy a persistent backdoor. It identifies its command and control (C2) infrastructure using… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/etherhiding-exposed-what-security-leaders-need-to-know/
-
New Axonius Channel Leader On AI Growth Push: ‘We Can’t Do It Without Partners’
Axonius is looking to solution and service provider partners to play an even more pivotal role in the next phase of growth at the cybersecurity asset management vendor, which sees massive opportunities ahead in combating AI and infrastructure risk, according to newly appointed channel leader Dan Schoenbaum. First seen on crn.com Jump to article: www.crn.com/news/security/2026/new-axonius-channel-leader-on-ai-growth-push-we-can-t-do-it-without-partners
-
White House Launches Pilot Program in Texas to Protect Water Infrastructure
Project Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/white-house-texas-protect-water/
-
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cve, cybersecurity, exploit, flaw, healthcare, infrastructure, kev, office, remote-code-execution, software, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe following vulnerabilities to itsKnown Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578,…
-
Fire Ant Hackers Compromise Cisco Routers and TACACS Servers to Target Critical Infrastructure
China-nexus threat actor Fire Ant has expanded its espionage operations from VMware hypervisors to the trusted infrastructure layer, compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. Security firm Sygnia, which investigated the activity, said Fire Ant has remained active since it was first reported in 2025. The actor’s latest operations show…
-
BGP Hijacking Attack Delivers Malicious Virtualizor Updates to Servers
A BGP hijacking incident targeting Softaculous infrastructure redirected traffic for Virtualizor update services to attacker-controlled systems, allowing a malicious update package to be delivered to a small number of servers. The incident impacted the IP range 162.55.80.0/24, which is hosted within Hetzner’s infrastructure, from approximately 20:57 UTC on August 28 to 06:10 UTC on August…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities related to PaperCut NG/MF to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are being actively exploited. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, can be combined to enable unauthenticated attackers to modify server configurations and execute arbitrary Java bytecode…
-
Broadcom Unveils VMware AI Factory With Secure Sandboxes for Enterprise AI Workloads
Broadcom has announced the VMware AI Factory, a software-defined private AI platform designed to accelerate the transition from bare-metal servers to production-ready AI models. This platform enhances governance, infrastructure automation, and workload isolation. Unveiled during VMware Explore 2026, the VMware AI Factory serves as the foundation for VMware’s Private AI Cloud. It combines VMware Cloud…
-
Daily OT Security News: August 31, 2026
The threat landscape for Operational Technology (OT) security continues to evolve, with recent incidents underscoring the vulnerabilities in critical infrastructure and the need for robust defenses. Key vulnerabilities have been identified, and regulatory developments are pushing organizations to enhance their… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/daily-ot-security-news-august-31-2026/
-
OpenAI and 100+ Firms Warn AI Cyberattacks Could Surge Within Months
More than 100 organizations warn AI could accelerate cyberattacks faster than defenders can respond, putting critical infrastructure at greater risk. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-openai-ai-cyber-defense-critical-infrastructure/
-
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Tags: ai, attack, cybercrime, data-breach, group, infrastructure, intelligence, network, ransomware, russia, threatThreat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX’s artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its First seen on…
-
China-linked Fire Ant Hides Inside Trusted Infrastructure
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that connects them. Sygnia’s new report traces how the group expanded from compromising…
-
The AI Kill Switch Act is repeating the Clipper Chip’s mistakes
Mandating ‘kill switches’ for AI agents would threaten the security of America’s critical infrastructure and undercut U.S. AI leadership. Congress must reject the AI Kill Switch Act. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-kill-switch-act-clipper-chip-mistakes-op-ed/
-
AI Shopping Assistant Vulnerabilities Enable Remote Code Execution on Retailer’s Servers
Security researchers have demonstrated how flaws in the AI shopping assistant of a major unnamed U.S. retailer could be exploited to enable remote code execution (RCE) on the company’s backend infrastructure through its public-facing mobile application. Netanel Rubin, co-founder and CTO of Rein Security, along with researcher Dan Avraham, presented their findings during a Black…
-
Magecart Hackers Abuse Ethereum Smart Contracts to Steal Card Data From 40+ Online Stores
A Magecart campaign dubbed HexMage has compromised more than 40 e-commerce storefronts across at least 15 countries, using Ethereum smart contracts as a resilient delivery mechanism for payment-card skimmers. The operation blends traditional client-side checkout theft with EtherHiding, allowing attackers to conceal and rotate skimmer infrastructure through Ethereum’s Sepolia testnet. Because the malicious code is…
-
Infostealer Infection Exposes Blind Eagle-Linked Operator’s Malware Production Pipeline
A compromised attacker-side workstation has given researchers an unusual view into the operational ecosystem behind a suspected Blind Eagle malware campaign, exposing RAT builders, phishing templates, bulk-mail tooling, crypter activity and infrastructure tracking records. Rather than directly exposing a modified executable, the account hosted a legitimate AutoIt interpreter alongside separately retrievable malicious script logic an…
-
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines.The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of First…

