Tag: Internet
-
Telco giant KDDI says data breach affects over 12 million people
Japanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/
-
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices.According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor that’s responsible for maintaining and proliferating LapDogs, an ORB network that first came to light…
-
Chinese hackers develop LONGLEASH malware to expand ORB network
Chinese hackers tracked as ‘UAT-7810’ are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/chinese-hackers-develop-longleash-malware-to-expand-orb-network/
-
Major Japanese telco says cyberattack exposed 12 million emails
The company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers. First seen on therecord.media Jump to article: therecord.media/major-japanese-telco-cyberattack-12-million-emails
-
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig.The vulnerability in question is CVE-2026-20896 (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the “X-WEBAUTH-USER” header from any source IP address, effectively allowing an unauthenticated internet client to get elevated…
-
Warum Internet-Intelligence so wichtig für Security-Operations ist
Künstliche Intelligenz verändert die Bedrohungslage in der Cybersecurity grundlegend. KI-gestützte Angriffe beschleunigen Kampagnen und machen bekannte Angriffsmuster noch skalierbarer, gezielter und schwerer berechenbar. Dadurch entstehen nicht unbedingt neue Angriffsmethoden. Vielmehr werden bestehende Angriffsformen verstärkt, effizienter und haben eine deutlich größere Reichweite. Und selbst technisch weniger versierte Akteure können automatisierte Angriffe durchführen, für die bislang deutlich…
-
Law enforcememt operation disrupted Malicious Residential Proxy Networks NetNut
Google disrupted NetNut, a major proxy network that routed internet traffic through compromised home devices used by cybercriminals. Google has disrupted NetNut, one of the world’s largest residential proxy networks. The service routed internet traffic through home devices, allowing customers to hide their real location and identity. >>Today, in coordination with the FBI, Lumen, and…
-
Non-interactive SSH attacks dominate after login
Anyone who runs a server with SSH exposed to the internet sees the same pattern in the logs. A steady stream of automated scanners tries to log in, hour after hour, from … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/03/research-non-interactive-ssh-attacks/
-
SharkLoader Malware Uses Perfect DLL Hijacking to Execute Cobalt Strike in Memory
SharkLoader, used by an intrusion cluster tracked as StrikeShark to deliver Cobalt Strike Beacon entirely in memory across a wide international footprint. The campaign combines opportunistic exploitation of exposed internet-facing infrastructure with custom droppers disguised as trusted installers to establish initial access, then relies on layered, memory-only execution techniques and “Perfect DLL Hijacking” to minimize…
-
SharkLoader Malware Uses Perfect DLL Hijacking to Execute Cobalt Strike in Memory
SharkLoader, used by an intrusion cluster tracked as StrikeShark to deliver Cobalt Strike Beacon entirely in memory across a wide international footprint. The campaign combines opportunistic exploitation of exposed internet-facing infrastructure with custom droppers disguised as trusted installers to establish initial access, then relies on layered, memory-only execution techniques and “Perfect DLL Hijacking” to minimize…
-
Cloudflare will das Agentic Internet fairer machen und setzt neue Regeln für KI-Bots
Neue Klassifizierungen, verbesserte Analysen und Partnerschaften sollen Website-Betreibern und transparenten KI-Unternehmen helfen, gemeinsam ein florierendes “Agentic Internet” aufzubauen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cloudflare-will-das-agentic-internet-fairer-machen/a45655/
-
950 Oracle E-Business Suite Instances Exposed as CVE-2026-46817 Attacks Observed in the Wild
Around 950 internet-facing Oracle E-Business Suite (EBS) instances have been identified as exposed following enhanced scanning efforts. At the same time, active exploitation attempts tied to CVE-2026-46817 have already been observed in the wild. The findings were disclosed by The Shadowserver Foundation, which recently expanded its fingerprinting capabilities through domain-based scanning in collaboration with Validin.…
-
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted into a production MySQL/Nacos deployment to carry out a destructive, database-focused extortion playbook without a…
-
Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed
Oracle E-Business Suite flaw CVE-2026-46817 is under active attack, with about 950 vulnerable internet-facing instances still exposed. This week, Defused Cyber researchers warned that a critical vulnerability in Oracle E-Business Suite, tracked as CVE-2026-46817, is being actively exploited. The flaw affects Oracle Payments versions 12.2.3 through 12.2.15 and allows unauthenticated attackers to take over vulnerable…
-
Ist Cybersecurity bereits voll von KI-Schrott?
Das Nebenprodukt des KI-Hypes ist KI-Schrott. Man denke an die schludrig produzierten Videos und Reels, die das Internet überschwemmen und auf den ersten Blick gut aussehen, bis sich zeigt, dass sie mit billigen KI-Tools zusammengeschustert wurden. Während das für den Durchschnittsmenschen lediglich ärgerlich ist, wird es zu einem ernsteren Problem, wenn dieses Verhalten in wichtige…
-
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
Cybersecurity researchers have warned of a “massive, ongoing, automated password spray attack” aimed at Microsoft’s Azure command-line interface (CLI), compromising dozens of accounts in the process.The activity, per Huntress, originates from an IPv6 address range (2a0a:d683::/32) controlled by internet infrastructure provider LSHIY LLC (AS32167).”Between June 12 and June 26, the threat First seen on thehackernews.com…
-
House passes kids’ online safety bill, but Senate approval unlikely
Tags: InternetThe Kids Internet and Digital Safety (KIDS) Act passed with bipartisan support by a 267-117 margin, winning the two-thirds majority needed to greenlight the legislation under a process that speeds up a bill’s path to a vote but requires more than a simple majority. First seen on therecord.media Jump to article: therecord.media/house-passes-kids-online-safety-bill-senate-unlikely
-
NDSS Symposium Heads to Seoul in 2027 to Expand Global Cybersecurity Collaboration
DC, United States, June 30th, 2026, CyberNewswire The Internet Society today announced that 2027 Network and Distributed System Security (NDSS) Symposium will take place in Seoul, Republic of Korea, from 2226 March 2027. Recognized as one of the world’s top four cybersecurity research conferences, the NDSS Symposium brings together hundreds of top scholars, academics, and…
-
Langflow RCE Vulnerability Exploited to Deploy Monero Cryptominer on Exposed AI Servers
Tags: ai, cve, cyber, data-breach, exploit, Internet, rce, remote-code-execution, tactics, threat, vulnerabilityThreat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution (RCE) vulnerability in Langflow, to compromise internet-exposed AI application servers and silently deploy a customized Monero (XMR) cryptominer. Tracked and documented by Trend Micro researchers Simon Dulude and John Zhang, the campaign marks a significant pivot in commodity cryptominer delivery tactics, from traditional…
-
DOJ Seizes Nearly 400 Domains Used for Illegal World Cup Streaming and Malware Threats
The U.S. Department of Justice (DOJ) has announced the seizure of nearly 400 internet domains used to stream FIFA World Cup 2026 matches illegally. This operation represents one of the largest coordinated anti-piracy enforcement actions related to a global sporting event. Conducted under the title “Operation Offsides,” it targeted websites that were distributing real-time broadcasts…
-
DOJ Seizes Nearly 400 Domains Used for Illegal World Cup Streaming and Malware Threats
The U.S. Department of Justice (DOJ) has announced the seizure of nearly 400 internet domains used to stream FIFA World Cup 2026 matches illegally. This operation represents one of the largest coordinated anti-piracy enforcement actions related to a global sporting event. Conducted under the title “Operation Offsides,” it targeted websites that were distributing real-time broadcasts…
-
KDDI Data Breach Impacts up to 14.2 Million Email Accounts at Six ISPs
KDDI Corporation disclosed a breach affecting up to 14.2 million email accounts after attackers exploited a vulnerability in third-party software. KDDI Corporation disclosed a data breach that exposed up to 14.2 million email accounts across six Japanese internet service providers. KDDI Corporation is one of Japan’s largest telecommunications companies. It employs more than 60,000 people…
-
Data breach exposes up to 14.2 million email logins at six ISPs
Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/data-breach-exposes-up-to-142-million-email-logins-at-six-isps/
-
Mahnung von Novavitalia.de erhalten Was tun?
Momentan tauchen im Internet vermehrt Meldungen über Mahnungen des KI-Ernährungsplananbieters Novavitalia.de aus Hongkong (China) auf. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/rechtssachen/mahnung-von-novavitalia-de-erhalten-was-tun-330822.html
-
Ransomware attacks grew in 2025 as traditional data breaches fell
In a new report, Bitsight charted a massive surge in internet-exposed AI services. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-data-breaches-ai-bitsight/823649/
-
New Forescout Data Reveals Slow Progress Toward Quantum-Safe Security
Despite growing awareness of quantum computing risks and increasing pressure on organisations to prepare for the transition to post-quantum cryptography (PQC), most internet-facing systems remain unprepared for a quantum-safe future, according to new research from Forescout Research Vedere Labs. The report, published today, reveals that while adoption of PQC-capable technologies has accelerated over the The…
-
KDDI Data Breach May Have Exposed Up to 14.22 Million Email Accounts
Japanese telecommunications company KDDI has disclosed a major cybersecurity incident in which up to 14.22 million email addresses and passwords may have been exposed through systems used by multiple internet service providers. The KDDI data breach has now become one of the most recent security events involving shared ISP infrastructure in Japan. First seen on…
-
Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity”¯
DC, United States, 23rd June 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/internet-society-foundation-opens-global-call-for-common-good-cyber-fund-to-strengthen-cybersecurity/
-
Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity”¯
DC, United States, June 23rd, 2026, CyberNewswire Applications open 23 June4 August 2026 to support nonprofits strengthening cybersecurity for civil society. TheInternet Society Foundationtoday announced the opening of a global call for applications to the”¯Common Good Cyber Fund”¯(CGCF), a multi-year funding initiative supporting nonprofit organizations that protect civil society and strengthen the Internet’s core cybersecurity…
-
LG and Samsung Smart TV Apps Found Monetizing Users’ IP Addresses via Proxy SDKs
A large-scale analysis of smart TV applications has revealed that thousands of apps available on LG webOS and Samsung Tizen platforms are covertly transforming consumer devices into residential proxy nodes, raising significant security and privacy concerns. Researchers scanned 6,038 smart TV applications and identified 2,058 apps that embed proxy software development kits, monetizing users’ internet…

