Tag: infrastructure
-
RedLine Infostealer Thread Reveals Hidden Maritime Phishing and BEC Infrastructure
A routine threat-feed alert for a RedLine Stealer command-and-control (C2) IP morphed into a full-scale pivot investigation that exposed a tailored maritime spear”‘phishing and business email compromise (BEC) ecosystem. The starting signal a UniqueSignal entry from VMRay identified 194[.]156.79.122:55615 as a RedLine-associated host. That solitary indicator, combined with targeted forensic pivots across VirusTotal, FOFA, Censys…
-
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Cybersecurity researchers have warned of a “massive, ongoing, automated password spray attack” aimed at Microsoft’s Azure command-line interface (CLI), compromising dozens of accounts in the process.The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/32) controlled by internet infrastructure provider LSHIY LLC (AS32167).”Between June 12 and June 26, the threat First seen on thehackernews.com…
-
Leaders call for workforce overhaul as AI reshapes critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/analysis/leaders-call-for-workforce-overhaul-as-ai-reshapes-critical-infrastructure
-
Leaders call for workforce overhaul as AI reshapes critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/analysis/leaders-call-for-workforce-overhaul-as-ai-reshapes-critical-infrastructure
-
ICIT founder on AI, quantum and critical infrastructure
First seen on scworld.com Jump to article: www.scworld.com/feature/icit-founder-on-ai-quantum-and-critical-infrastructure
-
DHS proposes new system for public-private infrastructure security collaboration
The Trump administration eliminated the previous framework in 2025, sparking a backlash from experts and infrastructure operators. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-infrastructure-collaboration-dhs-anchor-ci/824081/
-
DHS to unveil replacement council for critical infrastructure cybersecurity
The Department of Homeland Security is bringing back a key cybersecurity information sharing effort with critical infrastructure, more than a year after the Trump administration shuttered an existing nerve center between government and private sector. The Alliance of National Councils for Homeland Operational Resilience Critical Infrastructure program,first reported by CyberScoop in January, is meant […]…
-
DHS proposes new framework for public-private infrastructure security collaboration
The Trump administration eliminated the previous system in 2025, sparking a backlash from experts and infrastructure operators. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/critical-infrastructure-collaboration-dhs-anchor-ci/824081/
-
What the Numbers Say About FIFA 2026 Cyber Risk
The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-planned, months out, across three sectors and at least ten languages.Check Point Exposure Management published the FIFA World Cup 2026 Cyber…
-
Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments
Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical usability refinements that will matter to both pentesters and platform maintainers. The release emphasizes polish and performance rather than headline-grabbing features: GNOME advances to version 50 and KDE Plasma to 6.6.…
-
JSP webshells being dropped on unpatched PTC Windchill instances
The US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/29/ptc-windchill-cve-2026-12569-exploited/
-
Reconnaissance in the Age of AI: Exploring Modern ML Infrastructure
First seen on resecurity.com Jump to article: www.resecurity.com/blog/article/reconnaissance-in-the-age-of-ai-exploring-modern-ml-infrastructure
-
Straiker Raises $64M to Safeguard Autonomous AI Agents
Series A Funding Supports Pre-Training, Reinforcement Learning for Security Models. AI security startup Straiker closed a $64 million Series A funding round to expand GPU infrastructure, develop specialized security models and strengthen defenses against increasingly autonomous enterprise AI agents capable of operating with minimal human oversight. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/straiker-raises-64m-to-safeguard-autonomous-ai-agents-a-32093
-
Ghostwriter Hackers Use Real-Time WebSocket Relay to Bypass SMS and OTP MFA
UNC1151 tracked by many as Ghostwriter or FrostyNeighbor has advanced a credential-phishing technique that uses a real-time WebSocket relay to defeat SMS and OTP-based multi-factor authentication (MFA). The method was observed in a recent campaign that targeted Belarusian politician Yury Hubarevich and multiple Ukrainian portals, and Censys pivots show the infrastructure spans dozens of domains…
-
Think tank warns US markets face hidden infrastructure risks
First seen on scworld.com Jump to article: www.scworld.com/analysis/think-tank-warns-us-markets-face-hidden-infrastructure-risks
-
Security News This Week: LastPass Users Had Their Data Stolen”, Again
Plus: Former national security advisor John Bolton pleads guilty in classified-materials case, Microsoft helps take down major infostealer infrastructure, and more. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-lastpass-users-had-their-data-stolen-again/
-
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
Tags: attack, cisa, cisco, communications, cybersecurity, exploit, flaw, infrastructure, update, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-sets-urgent-deadline-to-fix-cisco-flaw-exploited-in-attacks/
-
Chinese APT CL1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware
Chinese-speaking APT CL-STA-1062 targeted Southeast Asian government and energy networks open-source tools, and a new TinyRCT backdoor. Palo Alto Networks Unit 42 researchers published a detailed report on a Chinese-speaking threat actor, tracked as CL-STA-1062, that has been running persistent operations across East Asia since at least March 2022 and shifted focus to Southeast Asian…
-
Chinese Development Framework Linked to Global Scam Infrastructure
More than 236,000 scam domains were linked to the legitimate DCloud Uni-App framework. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/chinese-development-framework-linked-to-global-scam-infrastructure/
-
Chinese Development Framework Linked to Global Scam Infrastructure
More than 236,000 scam domains were linked to the legitimate DCloud Uni-App framework. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/chinese-development-framework-linked-to-global-scam-infrastructure/
-
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia.The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has been attributed to a threat actor called CL-STA-1062, which Palo…
-
Resist the point product sale to advise on AI security
The conclusions of a recent Gigamon survey have underlined the need to gain visibility over customer infrastructure First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366644970/Resist-the-point-product-sale-to-advise-on-AI-security
-
CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue
Tags: attack, cisa, cybersecurity, data, exploit, flaw, infrastructure, kev, rce, remote-code-execution, software, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerability in question is First seen on thehackernews.com…
-
Guardian Agents: The Next Layer of Identity Governance
AI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built to govern human access wasn’t designed for autonomous actors, and the gap between what enterprises are deploying and what their governance programs actually cover is widening fast. This guide breaks First…
-
U.S. CISA adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco and PTC Windchill and FlexPLM flaws to its Known Exploited Vulnerabilities (KEV) catalog. The two flaws added to the catalog are: CVE-2026-12569 is a critical remote…
-
Synology issues critical fix for MailPlus Server vulnerabilities
Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/synology-mailplus-server-vulnerabilities/
-
China-Linked Malware Found in Counterfeit USB Drives Used on Japan Defense Force Classified Networks
Japan’s defense infrastructure has faced scrutiny following an investigation that revealed members of the Japan Self-Defense Forces (JSDF) used counterfeit USB drives embedded with malware linked to China on systems handling classified information. According to findings reported by Nikkei, these compromised USB devices were acquired at significantly lower costs through unofficial channels. They were subsequently…
-
China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor
A China-linked threat group has been targeting critical infrastructure in Southeast Asia with a new custom backdoor called TinyRCT First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/china-hackers-asian-cni-backdoor/
-
The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest
Tags: ai, automation, breach, cyber, cybersecurity, data, data-breach, hacker, infrastructure, intelligence, international, iran, risk, service, threatThis week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services, and regulated AI applications, organizations are increasingly exposed to faster-moving threats where traditional security assumptions are being challenged by automation…
-
The Cyber Express Weekly Roundup: Five Eyes AI Warning, KDDI Data Breach, Garfield AI Legal Milestone, and Iranian Hacker Arrest
Tags: ai, automation, breach, cyber, cybersecurity, data, data-breach, hacker, infrastructure, intelligence, international, iran, risk, service, threatThis week’s weekly roundup of cybersecurity developments highlights a rapid shift in global cyber risk conditions driven by artificial intelligence acceleration, large-scale data breaches, and expanding international enforcement actions. Across infrastructure, enterprise systems, public services, and regulated AI applications, organizations are increasingly exposed to faster-moving threats where traditional security assumptions are being challenged by automation…

