Tag: Internet
-
Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
A newly identified IoT botnet, Cling, disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate from Google’s public STUN infrastructure. The technique enables attackers to manage compromised internet-facing devices while blending activity into routine NAT-traversal traffic used by real-time communications platforms. Nozomi Networks Labs discovered the campaign while investigating a…
-
Citrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update
Citrix NetScaler administrators report repeated appliance crashes and forced reboots after deploying emergency updates for recently disclosed zero-day vulnerabilities, with the disruption now linked to a newly observed issue affecting SAML authentication deployments. The reports involve internet-facing NetScaler ADC and Gateway systems running patched releases, including version 14.1-73.37, which Citrix previously designated as a fixed…
-
Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion
A publicly exposed attacker staging server has provided a rare, detailed view of a Microsoft SQL Server-focused intrusion linked to a Viva Aerobus-side environment. The server, hosted at 151.243.232.123, functioned as both a tool-delivery point and a repository for stolen material. It was left accessible without authentication, allowing unrelated internet hosts to enumerate its directories…
-
Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative
Washignton, DC, USA, September 30th, 2026, CyberNewswire The Internet Society today launched the Online Trust and Safety Hub, a free global resource center in multiple languages, offering practical tools to help people stay safer and more confident online. The Hub is a key part of the Internet Society’s Safer Internet Initiative, which works to equip…
-
Internet Society Launches Global Online Trust and Safety Hub as Part of Its Safer Internet Initiative
Washignton, DC, USA, 30th September 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/internet-society-launches-global-online-trust-and-safety-hub-as-part-of-its-safer-internet-initiative/
-
WaterISAC reckons with range of threats after summer of cyberattacks
Internet-exposed tech, PLCs, outside integrators and inside protections are all factors the water sector’s information sharing and analysis center is watching. First seen on cyberscoop.com Jump to article: cyberscoop.com/water-utility-cyberattacks-waterisac-cyware-threat-intelligence/
-
Most open critical and high flaws are over 90 days old
Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their internet-facing systems … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/research-unpatched-vulnerabilities-backlog/
-
NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated. What started as stealthy targeting via zero-day exploits has now become … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/29/netscaler-zero-day-exploitation-escalates-into-mass-attacks-cve-2026-88771/
-
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions.”An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our…
-
OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face
A newly released forensic investigation has reconstructed how a swarm of about 700 OpenAI evaluation agents allegedly used nearly one million chained URLs to bypass restricted internet access and compromise parts of Hugging Face’s infrastructure. This incident illustrates how seemingly limited web-access capabilities can be combined with third-party services to create a functional execution, command-and-control,…
-
Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data
Tags: ai, breach, control, credentials, cyber, cybercrime, data, data-breach, infrastructure, Internet, phishing, toolAn internet-exposed cybercrime server linked to the BlackHatSect0r and DXQRTXX personas, revealing an operational environment that allegedly combined AI-assisted automation. Custom command-and-control tooling, phishing resources, stolen credentials, target lists, and internal operator communications. The exposure is notable not only for the scale of the material recovered, but also for its irony. Weeks later, infrastructure attributed…
-
Red Heron Exploits Critical Gitea Flaw to Steal Repositories and Deploy Linux Rootkit
Tags: access, cve, cyber, data-breach, exploit, flaw, Internet, linux, remote-code-execution, threat, vulnerabilityA threat actor tracked as Red Heron has exploited the critical Gitea remote code execution vulnerability CVE-2026-60004 to steal source-code repositories, establish persistent access, and deploy a covert Linux toolset consisting of the JITTERLY implant and SIXZUT LD_PRELOAD rootkit. Acronis reported that the actor rapidly weaponized the flaw against internet-exposed Gitea environments, turning initial access…
-
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
Ads appearing all over the Internet are trying to scam people. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/google-ads-caught-delivering-convincing-scareware-ads-to-unsuspecting-users/
-
Your uncle’s frozen Mac says it’s infected after viewing a Google ad. Now what?
Ads appearing all over the Internet are trying to scam people. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/google-ads-caught-delivering-convincing-scareware-ads-to-unsuspecting-users/
-
Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
The tech giant, which allows companies to send large datasets over the internet, said it received a “credible threat” from law enforcement about an imminent attack. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/25/kiteworks-urges-customers-to-shut-down-their-servers-amid-imminent-threat-of-cyberattack/
-
Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack
The tech giant, which allows companies to send large datasets over the internet, said it received a “credible threat” from law enforcement about an imminent attack. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/25/kiteworks-urges-customers-to-shut-down-their-servers-amid-imminent-threat-of-cyberattack/
-
Kyiv internet providers report major outages after Russian attacks damage data centers
At least four internet providers serving Kyiv and other parts of Ukraine suffered partial connectivity losses following Wednesday’s drone attack, according to internet monitoring group NetBlocks. First seen on therecord.media Jump to article: therecord.media/kyiv-internet-providers-report-outages-after-russian-strikes
-
Eco-Verband bringt Internet-Security-Days erstmals auf die it-sa
Der Eco Verband der Internetwirtschaft e. V. bringt die Internet-Security-Days am 28. Oktober 2026 erstmals auf die it-sa Expo&Congress in Nürnberg. Mit NIS2, dem Cyber-Resilience-Act und weiteren europäischen Vorgaben geht die Cybersicherheitsregulierung zunehmend von der Gesetzgebung in die praktische Umsetzung über. Im Mittelpunkt des Kongresstags stehen daher Fragen, die für Unternehmen angesichts neuer europäischer […]…
-
Censys Shifts To Channel-Only For New Business, Aims To Expand Internet Intelligence With Partners
Censys unveiled an expanded channel program Tuesday that includes a major shift in its sales strategy in the direction of partners, with the aim of accelerating growth for its Internet intelligence platform through the channel, Censys CRO Sarah Ashburn tells CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/censys-shifts-to-channel-only-for-new-business-aims-to-expand-internet-intelligence-with-partners
-
Russia’s internet shutdowns disrupt warnings about incoming drone attacks
Russia’s growing restrictions on mobile internet and cellular service are making it harder for people to receive warnings about incoming Ukrainian drone and missile attacks. First seen on therecord.media Jump to article: therecord.media/russia-internet-shutdowns-disrupt-warnings-about-drone-attacks
-
NTU uses AI agents to uncover flaws in mobile networks
Nanyang Technological University’s agentic AI tool checks mobile core network code against 3GPP specifications and has found 84 vulnerabilities, including one that lets an attacker hijack a subscriber’s internet session First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650777/NTU-uses-AI-agents-to-uncover-flaws-in-mobile-networks
-
Scammers impersonate cops, use arrest threats to extort victims
Scammers are posing as police officers and federal agents, threatening arrest unless victims pay up, the FBI warns. The FBI’s Internet Crime Complaint Center (IC3) … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/fake-police-federal-agents-scams/
-
Hackers Abuse Critical cPanel Authentication Bypass to Compromise Hosting Servers
Threat actors rapidly exploited a critical authentication bypass in cPanel and WHM to compromise internet-facing hosting servers, with Japanese telemetry data linking the campaign to a sharp rise in Mirai-like scanning and attack traffic targeting Telnet services. The activity centers on CVE-2026-41940, a critical vulnerability in cPanel and WHM’s session-management layer that enables a remote,…
-
Google Gemini AI Hacked 3 Real Companies After Cybersecurity Test Exposed It to Internet
Google has confirmed that its Gemini artificial intelligence model accidentally accessed protected systems belonging to three real companies during a cybersecurity evaluation. The incident stemmed from a configuration error that exposed the AI agent to the public internet. Google Gemini AI Hacked This situation highlights how autonomous AI systems can breach intended testing boundaries when…
-
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Google’s Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also…
-
Weltweiter Anstieg von exponierten industriellen Steuerungssystemen
In seinem jährlichen State of the Internet Report analysiert Censys, Experte für Internet-Intelligence, Attack-Surface-Management und Threat-Hunting, weltweite Bedrohungen und Sicherheitslücken sowie die Entwicklung des öffentlichen Internets. Der Forschungsbericht 2026 erscheint am 6. Oktober und beschäftigt sich unter anderem mit der weltweiten Exposition von industriellen Steuerungssystemen (ICS). Der Bericht zeigt, wie sich die weltweite ICS-Angriffsfläche verändert.…
-
Swedish teenager jailed for attempted murder, rape and assault committed online, with victims in Germany and Australia
Eighteen-year-old known as Chai was active in networks notorious for their sadistic exploitation of young peopleA Swedish teenager known as Chai has been sentenced to more than 10 years in jail for attempted murder, rape and aggravated assault crimes committed via the internet, <a href=”https://www.theguardian.com/technology/ng-interactive/2026/jul/21/764-network-gamification-of-harm-the-com-cybercrime-ntwnfb”>including against a teenage girl in Australia.The district court found that…
-
Researchers Find Security Risks in 73.6% of 61,500 Abandoned IoT Apps
Researchers have identified significant security and privacy risks across 61,500 abandoned Android Internet-of-Things (IoT) companion applications. Their study found that 73.6% of these apps contained at least one potential vulnerability, risky embedded resource, or insecure communication path. Risks in Abandoned IoT Apps Titled >>When Apps Outlive Vendors: Security Implications of IoT Abandonware,<< the study examines…
-
Hackers Exploit MikroTik Vulnerabilities to Take Over MikroTik Routers Without Authentication
Attackers are actively exploiting a critical vulnerability chain dubbed MikroTrick to seize full administrative control of internet-exposed MikroTik RouterOS devices without valid credentials. CERT Polska disclosed six RouterOS vulnerabilities on September 5, 2026, warning that two critical vulnerabilities could be chained to take over publicly reachable routers. The Polish national CSIRT said it had confirmed…

