Tag: Internet
-
FBI Seizes NightmareStresser DDoSHire Domains Used in Hundreds of Thousands of Attacks
The FBI has seized internet domains linked to NightmareStresser, a long-standing distributed denial-of-service (DDoS)-for-hire platform allegedly used to launch hundreds of thousands of attacks or attempted attacks worldwide since 2022. The U.S. Attorney’s Office for the District of Alaska announced the action, which targets the infrastructure that allowed paying customers to overwhelm victims’ networks and…
-
Manufacturers make patching progress, but identity management still major weakness
Misconfigurations remain widespread in the manufacturing sector, including internet-accessible remote-access software, a new report found. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/manufacturing-cybersecurity-weaknesses-ransomware-black-kite/830299/
-
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH).A sender with no credentials can crash the server process, named, with a single request that…
-
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser.The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the site are now greeted by a seizure banner that states -“This domain has been seized by the First seen on…
-
BIND 9.20.29 Fixes 14 Security Flaws Enabling DNSSEC Bypass and DenialService Attacks
The Internet Systems Consortium (ISC) has released BIND 9.20.29, which addresses 14 security vulnerabilities. These vulnerabilities could enable remote attackers to bypass DNSSEC protections, poison resolver caches, exhaust CPU or memory resources, and crash the named service. This update is particularly important for organizations that operate recursive, DNSSEC-validating resolvers, as they are primarily exposed to…
-
Hackers Turn AI Agent Into a Cyber Weapon After Deleting Its Safety Refusals
A French-speaking cybercrime crew calling itself BlackHatSect0r && DXQRTXX allegedly disabled safety controls in a self-hosted AI agent and used the resulting system to automate mass credential harvesting, target discovery, phishing preparation, and attack orchestration. The internet-exposed server reportedly contained 4.9 GB of material across 9,299 files, including a custom Go-based command-and-control platform named DXSCAN,…
-
BlackHatSect0r Hackers Disable AI Safety Controls to Automate Credential Theft and Cyberattacks
Tags: ai, attack, control, credentials, cyber, cyberattack, cybercrime, data-breach, hacker, Internet, phishing, theftA French-speaking cybercrime crew calling itself BlackHatSect0r && DXQRTXX allegedly disabled safety controls in a self-hosted AI agent and used the resulting system to automate mass credential harvesting, target discovery, phishing preparation, and attack orchestration. The internet-exposed server reportedly contained 4.9 GB of material across 9,299 files, including a custom Go-based command-and-control platform named DXSCAN,…
-
Attackers Target Vite Servers in Scanning Campaign to Steal AWS, Azure Info
F5 researchers saw a sharp spike in automated reconnaissance operations against developer tools in August, including a wide-ranging scanning campaign targeting vulnerable internet-exposed Vite development servers to steal AWS and Azure secrets. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/attackers-target-vite-servers-in-scanning-campaign-to-steal-aws-azure-info/
-
Daily OT Security News: September 16, 2026
Today’s updates include multiple CISA ICS advisories for high-risk vulnerabilities in surveillance, maritime, and industrial management products, plus a reported exploitation campaign that targeted internet-facing Gitea instances and impacted industrial software repositories. CISA issues advisory for Digital Watchdog VMAX DVR… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-16-2026/
-
China-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic into apparent gambling activity. The activity expands on earlier findings by Trend Micro, which identified PeckBirdy as a flexible JScript-based C2 framework used by China-aligned…
-
Black Axe Members Extradited to US Over Internet Fraud Claims
Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/black-axe-members-extradited-us/
-
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Tags: cloud, credentials, cybersecurity, data-breach, exploit, flaw, infrastructure, Internet, microsoft, serviceCybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data.The first is an automated effort aimed at internet-exposed Vite development servers that’s designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs.The First seen on thehackernews.com…
-
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker’s own…
-
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign.”Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems,” Acronis Threat Research Unit (TRU)…
-
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/
-
Six Nigerians extradited to US over $6M online romance scam
Alleged members of Black Axe criminal network that swindled US women out of $6m flown from South AfricaSix Nigerian nationals linked to an organized criminal network that allegedly swindled American women out of more than $6m through <a href=”https://apnews.com/article/scams-online-scams-ai-internet-safety-phishing-fraud-takeaways-b1350fd421cce73ac585a649b07332d5″>online romance scams were extradited to the United States on Friday.<a href=”https://www.theguardian.com/world/southafrica”>South African police confirmed they were…
-
From Hacks to Bioweapons, Claude Misuse Is Now Everywhere
Plus: The US disrupts the internet’s biggest black market, a Conti ransomware hacker gets prison time, Meta fails to stop AI-generated videos of child abuse. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-from-hacks-to-bioweapons-claude-misuse-is-now-everywhere/
-
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, flaw, gitlab, infrastructure, Internet, kev, mitigation, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects both GitLab Community Edition and Enterprise Edition and requires urgent mitigation, particularly for internet-accessible GitLab instances. CVE-2026-85706 is a path traversal vulnerability…
-
GitLab’s critical flaw is already drawing internet-wide probes
One flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately. First seen on cyberscoop.com Jump to article: cyberscoop.com/gitlab-critical-flaws-path-traversal-scans/
-
The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears quickly when the infrastructure itself is exposed to the public…
-
What an external penetration test is and how one is actually run
Exploiting a vulnerability has been the most common way attackers break in for six years running, 32% of intrusions in 2025 (Mandiant’s M-Trends 2026), and those flaws sit on your internet-facing perimeter, the surface an external penetration test covers. A… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/what-an-external-penetration-test-is-and-how-one-is-actually-run/
-
New IoT Malware Uses Public Linux Exploits to Gain Root and Launch DDoS Attacks
A newly observed IoT malware family dubbed KATARU targets internet-exposed devices through Telnet credential brute-forcing, then attempts to gain root privileges with publicly available Linux kernel exploits before enrolling compromised systems in a DDoS botnet. The sample combines familiar Mirai-style flooding functions with encrypted command-and-control, broad persistence logic, anti-analysis checks and decoy network activity designed…
-
Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft
Tags: access, ai, authentication, cloud, credentials, cyber, data-breach, hacker, Internet, theft, vulnerabilityNearly one in 10 internet-exposed LiteLLM AI gateways accepted the widely documented default master key, sk-1234, or required no authentication, creating a direct path to LLMjacking, sensitive credential exposure, and in vulnerable versions root-level code execution inside the gateway container. Their internet scan of 3,074 publicly reachable instances found that 294 systems, or 9.6%, accepted…
-
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide.LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway’s administrator credential.Anyone who holds…
-
OpenAI Confirms AI Agents Used German Wiki to Bypass Restrictions
OpenAI agents used a German wiki to coordinate and bypass restrictions, exposing gaps in read-only internet controls and AI agent containment. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-openai-agents-wiki-restrictions-emea-germany/
-
AI Can Jump Sandboxes. Easy-Peasy. The World Needs New Borders That Can Actually Contain It.
In the coming months, “AI-enabled cyberattacks will become much more widespread and sophisticated. As these models become more capable, the companies and public services we all rely on, hospitals, water treatment plants, even the backbone of the internet, … First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ai-can-jump-sandboxes-easy-peasy-the-world-needs-new-borders-that-can-actually-contain-it/
-
Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland’s national … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/07/mikrotik-routeros-ssh-vulnerabilities-exploited/
-
OpenAI Confirms AI Agents Wrote to Multiple Internet Sites in ‘Wiki Incident’
OpenAI has acknowledged that its AI agents posted content on multiple internet sites during an event it has termed the “wiki incident.” The company characterizes this episode as a real-world example of model misalignment rather than a typical cybersecurity breach. In a statement shared on X, OpenAI emphasized that the incident highlights the need for…
-
Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
Tags: adobe, attack, cyber, exploit, Internet, open-source, rce, remote-code-execution, vulnerability, zero-daySecurity researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Source and Adobe Commerce. This vulnerability, known as StyleSmuggler, allows attackers to inject PHP payloads into Magento’s template system and execute them via standard application workflows. Sansec’s Forensics Team reported that attacks began on September 4, targeting internet-facing…
-
Hackers Actively Exploiting MikroTik RouterOS MikroTrick Flaws to Take Full Control of Routers
Threat actors are actively exploiting critical vulnerabilities in MikroTik RouterOS, collectively known as MikroTrick, to compromise internet-exposed routers and gain complete administrative control. The attacks primarily target devices with SSH management access that are exposed to public networks, prompting urgent patching recommendations from MikroTik, CERT Polska, and Latvia’s national CERT.LV. On September 3, MikroTik issued…

