Tag: intelligence
-
Shinyhunters starten neue Angriffswelle gegen Oracle-Peoplesoft
Tags: cve, cyberattack, cybercrime, firewall, google, group, intelligence, mandiant, oracle, threat, vulnerability, wafDie Cybercrime-Gruppe Shinyhunters hat ihre Angriffe auf Oracle-Peoplesoft deutlich ausgeweitet. Mandiant und die Google Threat Intelligence Group beobachten eine erneute massenhafte Ausnutzung der Schwachstelle CVE-2026-35273. Dabei umgehen die Angreifer vorhandene Web-Application-Firewalls (WAFs) und installieren Web-Shells sowie weitere Schadsoftware auf kompromittierten Systemen. Während die Schwachstelle zunächst vor allem gegen Einrichtungen aus dem Hochschulbereich eingesetzt wurde, hat…
-
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that’s targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent.”The implant installs the framework unchanged, then overwrites its SOUL.md persona file,” ThreatDown said. “The 39-line prompt directs it to execute tasks received through First seen on…
-
Renfe Cyberattack Hits Spain’s Rail Network as AI Role Probed
Spain’s state-owned railway operator Renfe confirmed on September 25 that a cyberattack had compromised some of its customers’ data. Spanish media reported that the criminals behind the Renfe cyberattack used artificial intelligence (AI), which would make it the first attack of its kind in the country. Train services across Spain have continued to run normally…
-
Kiteworks Urges Customers to Shut Down Servers Over Potential Zero-Day Threat
Kiteworks has lifted its emergency shutdown recommendation after advising customers to temporarily take their systems offline in response to credible intelligence indicating that a threat actor may target its platforms. The company clarified that this action was preventive and did not indicate a confirmed compromise. It also urged customers to remain on the latest version…
-
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 1
Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At…
-
OpenAI halts training of latest models as reports mount of AI agents going rogue
Decision follows disclosures that OpenAI agents searching government websites had acted in unexpected waysOpenAI said it has paused training of its latest artificial intelligence models as reports of AI agents going rogue mount.The decision to halt development came just hours after the company disclosed Friday that it was reviewing several incidents from the summer in…
-
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.”Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems,” said Frank Balonis, Chief…
-
Kiteworks Warns Users to Take Systems Offline Amid Suspected Zero-Day Threat
Kiteworks has urged customers worldwide to temporarily shut down their servers after receiving credible law-enforcement intelligence that a threat actor may target Kiteworks deployments over the weekend. The emergency advisory is preventive, but the company said the potential activity may involve an unknown zero-day vulnerability. The secure file-sharing and managed content communications provider asked organizations…
-
US Appeals Court Backs Pentagon Blacklisting of Anthropic
D.C. Circuit says Claude’s built-in restrictions can qualify as a supply chain risk. A federal three judge panel gave the U.S. Department of Defense the go-ahead to continue blacklisting Anthropic, a setback in the artificial intelligence giant’s bid to take on the Trump administration in court. The ruling may dissuade companies from working with Anthropic.…
-
US Appeals Court Backs Pentagon Blacklisting of Anthropic
D.C. Circuit says Claude’s built-in restrictions can qualify as a supply chain risk. A federal three judge panel gave the U.S. Department of Defense the go-ahead to continue blacklisting Anthropic, a setback in the artificial intelligence giant’s bid to take on the Trump administration in court. The ruling may dissuade companies from working with Anthropic.…
-
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/
-
Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.” First seen on therecord.media Jump to article: therecord.media/kiteworks-urges-customers-to-stop-using-systems-incident
-
Why Enterprises Must Own, Not Rent, Their Intelligence
Uniphore CEO Umesh Sachdev on Proprietary Data, Trade Secrets and Sovereign AI. Closed frontier AI models can learn an enterprise’s proprietary data and trade secrets and pass that edge to competitors. Uniphore CEO Umesh Sachdev said companies should own their intelligence by running core AI workloads on sovereign, on-premises infrastructure. First seen on govinfosecurity.com Jump…
-
Connected Data Alone Won’t Make AI a Better Decision-Maker
Teach AI How Businesses Operate Before Optimizing Them, Says Aily Labs’ Anghelina. Artificial intelligence can access all of a company’s inventory, commercial and financial data and still make the wrong call. Numbers alone often fail to capture the regulations, business strategy and human expertise that shape business decisions, says Aily Labs Founder and CEO Bianca…
-
SCOUTz Prospect Intelligence Platform Launches for MSPs with 30-Day Beta
Phoenix, Arizona, September 24th, 2026, CyberNewswire SCOUTz, a prospect intelligence platform built for managed service provider (MSP) security sales, is now available in open beta. The platform gives an MSP dated evidence about a prospect’s environment before the first meeting and keeps that evidence attached through delivery and reassessment. The open beta is available at…
-
SCOUTz Prospect Intelligence Platform Launches for MSPs with 30-Day Beta
Phoenix, Arizona, September 24th, 2026, CyberNewswire SCOUTz, a prospect intelligence platform built for managed service provider (MSP) security sales, is now available in open beta. The platform gives an MSP dated evidence about a prospect’s environment before the first meeting and keeps that evidence attached through delivery and reassessment. The open beta is available at…
-
SCOUTz Prospect Intelligence Platform Launches for MSPs with 30-Day Beta
Phoenix, Arizona, September 24th, 2026, CyberNewswire SCOUTz, a prospect intelligence platform built for managed service provider (MSP) security sales, is now available in open beta. The platform gives an MSP dated evidence about a prospect’s environment before the first meeting and keeps that evidence attached through delivery and reassessment. The open beta is available at…
-
Sicherheit für Microsoft-365 Coreview startet Intelligence-Labs
Der Spezialist für den Schutz und das Management von Microsoft-365-Tenants, Coreview, hilft mit seinen neuen Intelligence-Labs Sicherheitsexperten dabei, die Prozesse in ihren Microsoft-Tenants zu verstehen und bestehende sowie neu auftretende Sicherheitslücken zu schließen. Hierfür werden die Sicherheitsforscher unter der Leitung von Kasper Lindgaard technische Forschungsergebnisse und praktische Leitfäden zur Sicherheit von Microsoft-365 veröffentlichen. Die Einführung…
-
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
The legislation from Senate Intelligence Vice-Chairman. Mark Warner, D-Va., and Senate Commerce Chairman Ted Cruz, R-Tex., would create a government-industry group to write voluntary best practices. First seen on cyberscoop.com Jump to article: cyberscoop.com/senate-telecom-cybersecurity-resilience-act-salt-typhoon/
-
SCOUTz Prospect Intelligence Platform Launches for MSPs with 30-Day Beta
Phoenix, Arizona, 24th September 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/scoutz-prospect-intelligence-platform-launches-for-msps-with-30-day-beta/
-
Operation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files
Tags: cyber, cyberespionage, intelligence, korea, malicious, malware, north-korea, powershell, russia, threat, ukraine, windowsNorth Korea-linked threat actor Konni has launched a targeted cyberespionage operation against Ukraine-focused entities using malicious Windows shortcut files disguised as PDF documents. The campaign, tracked by SOCRadar Threat Research Unit as Operation Conflict Compass, deploys a modular PowerShell malware family dubbed VelvetCake to collect intelligence on the Russia-Ukraine war. The activity appears designed to…
-
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The…
-
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud. First seen on therecord.media Jump to article: therecord.media/two-arrested-in-uk-after-microsoft-takedown-eviltokens
-
Censys Shifts To Channel-Only For New Business, Aims To Expand Internet Intelligence With Partners
Censys unveiled an expanded channel program Tuesday that includes a major shift in its sales strategy in the direction of partners, with the aim of accelerating growth for its Internet intelligence platform through the channel, Censys CRO Sarah Ashburn tells CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/censys-shifts-to-channel-only-for-new-business-aims-to-expand-internet-intelligence-with-partners
-
Contagious Interview: 30,000 devices infected by a fake job interview
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview.…
-
21st September Threat Intelligence Report
Tags: breach, data, data-breach, exploit, government, intelligence, service, threat, vpn, vulnerabilityJapan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/21st-september-threat-intelligence-report/
-
Google says Gemini breached three companies during security test
Google’s artificial intelligence model Gemini accessed computer systems belonging to three real companies without authorization during a cybersecurity test in May, the latest in a string of similar incidents. First seen on therecord.media Jump to article: therecord.media/gemini-google-cyber-breach
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
CrowdStrike warns AI agents are creating a cyber battleground for GCC organisations
Artificial intelligence is lowering the barrier to entry for cyber criminals, accelerating attack speeds and increasing the complexity of threats, prompting organisations to rethink resilience, governance and security operations First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650857/CrowdStrike-warns-AI-agents-are-creating-a-cyber-battleground-for-GCC-organisations

