Tag: network
-
Security Affairs newsletter Round 589 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions Metabase Zero-Day Exploited in the Wild,…
-
Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions
China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing…
-
Detecting Cobalt Strike beacons with JA3 and JARM fingerprinting
Cobalt Strike remains a common post-compromise tool in intrusion sets because it gives an operator a flexible command-and-control channel, tasking framework, and a way to blend into normal network traffic. For defenders, the challenge is not just spotting malware on an endpoint. It is identifying the beaconing pattern that sits behind the traffic, especially when……
-
The Hidden Risks of Ignoring API Security During Mobile Application Security Testing
Mobile applications don’t operate in isolation. Behind every login screen, payment flow, and push notification sits a network of APIs quietly moving data between the app, the backend, and third-party services. Yet when organizations plan mobile application security testing, API security is often treated as an afterthought, something to “get to later” once the app’s……
-
China reviews Palo Alto Networks products, citing security concerns
First seen on scworld.com Jump to article: www.scworld.com/brief/china-reviews-palo-alto-networks-products-amid-security-concerns
-
China Opens Cybersecurity Review of Palo Alto Networks Products
China has opened a cybersecurity review of Palo Alto Networks products, raising potential risks for critical infrastructure customers and foreign vendors. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-china-palo-alto-networks-cybersecurity-review/
-
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Tags: ai, automation, conference, control, credentials, cve, cyber, cybersecurity, data, data-breach, defense, detection, exploit, flaw, group, iam, intelligence, ISO-27001, mitigation, network, nvidia, offense, open-source, RedTeam, risk, skills, soc, technology, threat, tool, usa, vulnerabilityAgentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
-
New NatJack NAT Attack Lets Hackers Hijack TCP Connections and DNS Responses
A newly disclosed attack class, NatJack, reveals significant weaknesses in the implementation of Network Address Translation (NAT) across modern network infrastructures. This vulnerability allows attackers to hijack TCP connections, tamper with DNS responses, and disrupt traffic flow. NatJack specifically targets the NAT state table, highlighting that traditional assumptions about cooperative network behavior are no longer…
-
NSFOCUS LAS: Comprehensive Log Management for Security Visibility and Compliance
The Log Management Challenge Most enterprises accumulate log sources the same way they accumulate infrastructure: one device at a time, each generating data in its own proprietary format. The result is logs scattered across security appliances, network devices, servers, databases, middleware, applications, and cloud workloads, with no unified view and unknown device status. Any issue……
-
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and First seen on…
-
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices First…
-
What is Penetration Testing?
Penetration testing, commonly known as “pen testing,” is an authorised attack where trusted cyber security experts evaluate physical and digital systems, networks, or applications. It … Read more First seen on securityboulevard.com Jump to article: https://securityboulevard.com/2026/08/what-is-penetration-testing-2/
-
Check Point Puts AI Traffic Controls Into Its Existing Firewalls
Check Point has launched an AI Network Firewall that brings visibility and enforcement for AI applications, agents and Model Context Protocol traffic into the physical and virtual firewalls organizations already operate. Introduced July 30 ahead of Black Hat USA 2026, the product is delivered through Check Point’s AI Defense Plane and firewall software release R82.20……
-
Top 10 Best External Attack Surface Management (EASM) Platforms 2026
In the sprawling digital ecosystem of 2026, organizations grapple with an increasingly complex and often poorly understood external attack surface. This attack surface encompasses all internet-facing assets that are discoverable and potentially exploitable by malicious actors. These assets extend far beyond traditional network perimeters to include cloud resources, web applications, APIs, orphaned infrastructure, exposed databases,…
-
Breach Roundup: Water Utilities in 12 US States Hit
Also, Chinese-Made SOHO Routers Contain Trojan, AI Fuels Cybercrime Across Africa. This week: water utilities in 12 U.S. states hit, Trojans in Chinese SOHO routers, banned Chinese companies in U.S. networks, AI fueled cybercrime in Africa, a U.K. police legal database breached, IBM Langflow AI flaw, a cyberattack delayed orders at a Dutch retailer and…
-
Palo Alto Networks Introduces PAN-OS 12.2 Ceres With AI Security Features
Palo Alto Networks has introduced PAN-OS 12.2 Ceres, a firewall operating system update that adds more than 55 innovations aimed at attacks accelerated by frontier AI. The release centers on Advanced Virtual Patching, Advanced IP Defense and six AI-powered Network Security Agents. Advanced Virtual Patching uses AI to identify unknown vulnerabilities and deliver network protections..…
-
Chinese telecom companies retain US network ties despite security concerns
First seen on scworld.com Jump to article: www.scworld.com/brief/chinese-telecom-companies-retain-u-s-network-ties-despite-security-concerns
-
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe. First seen on wired.com Jump to article: www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/
-
How AI Agents Helped Seal Visa’s $2.4B BioCatch
Behavioral Biometrics Vendor Is Latest in Payment Network Sector Buying Spree. Visa, the world’s largest card payment network, is acquiring behavioral intelligence firm BioCatch in an all-cash deal valued at $2.4 billion. It’s the company’s largest acquisition to date and the latest in a string of payment sector M&As aimed at fraud and cybersecurity solutions.…
-
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/15-tp-link-bugs-risks-zero-trust-provisioning
-
Miggo Adds DefenseDepth Mitigation to Close Patch Gaps in Minutes
Miggo Security has announced Defense-in-Depth Mitigation, a capability that coordinates protections at the network edge and inside an application while a permanent patch is being prepared. The release was issued from Black Hat USA and says Miggo is presenting the capability in Las Vegas during the event. The approach gives security teams multiple mitigation points..…
-
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes.To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region…
-
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.A third flaw could expose sensitive data and control-plane details through application programming…
-
From Inspection to Authorization: Securing Networks for AI Agents
Tags: access, ai, api, business, ceo, cloud, communications, control, crowdstrike, cryptography, data, encryption, endpoint, finance, firewall, identity, infrastructure, login, network, office, risk, saas, service, usa, vpn<div cla An Industry Perspective By Rajiv Pimplaskar, CEO, Dispersive Holdings, Inc. Agentic AI changes the network security problem from inspection to authorization. As more traffic is generated by agents, models, and workloads operating at machine speed, the network has to make trust decisions continuously, evaluate policy in real time, revoke access automatically, and keep…
-
C5-Type-1-Testat des BSI bestätigt die Sicherheit von <> für Organisationen mit hohen Anforderungen an Cloud-Sicherheit
Extreme Networks gibt bekannt, dass <> das BSI-C5-Type-1-Testat nach dem Cloud-Computing-Compliance-Criteria-Catalogue (C5) des Bundesamts für Sicherheit in der Informationstechnik (BSI) erhalten hat. Damit erfüllt die branchenweit einzige KI-gestützte All-in-One-Cloud-Networking-Plattform einen der strengsten staatlich unterstützten Cloud-Sicherheitsstandards Europas. Das BSI-C5-Type-1-Testat bestätigt unabhängig, dass Extreme-Platform-One die Anforderungen an sichere und regelkonforme Cloud-Netzwerkinfrastrukturen für stark regulierte Organisationen erfüllt […] First…
-
Robin Sage 2.0: How LinkedIn Became a Counterintelligence Battlefield
Five Eyes governments warn that foreign intelligence services are using fake recruiters, professional networks and paid consulting offers to extract sensitive information. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/robin-sage-2-0-how-linkedin-became-a-counterintelligence-battlefield/
-
15 TP-Link Omada Flaws Exploit Zero-Touch Provisioning to Hijack Devices and Infiltrate Networks
Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack devices, compromise controllers, expose credentials, and create access points into internal networks. The research, titled >>Zero Day Provisioning,<< was presented at Black Hat USA 2026 and focuses on weaknesses in the trust relationships that enable Omada…
-
TP-Link Zero-Touch Provisioning Flaws Could Expose Enterprise Networks, Warns Forescout
Forescout Vedere Labs research has uncovered 15 previously unknown vulnerabilities affecting TP-Link’s Omada Zero-Touch Provisioning (ZTP) ecosystem, warning that weaknesses in automated device deployment could allow attackers to compromise not just individual devices, but the management infrastructure responsible for entire networks. The research highlights an emerging security challenge as organisations increasingly rely on Zero-Touch Provisioning…
-
Real User Monitoring und synthetische Tests – Palo Alto Networks will Embrace übernehmen
First seen on security-insider.de Jump to article: www.security-insider.de/palo-alto-networks-will-embrace-uebernehmen-a-d08ce157492a97c90d4191f980900624/
-
Zimperium Launches Deep Insights for Automated Mobile Forensics
Zimperium has announced Deep Insights, a mobile security product that combines real-time Mobile Threat Defense with automated mobile forensics. Deep Insights automates forensic analysis and reconstructs the sequence of events around a mobile incident. Zimperium said it correlates configuration changes, application activity, permission shifts and suspicious network traffic to build a step-by-step attack timeline. The..…

