Tag: network
-
Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day
Hackers leveraged a compromised Microsoft IIS server to gain initial access and deploy a previously unseen ransomware payload across an enterprise network within 24 hours, highlighting a highly coordinated and operationally mature intrusion chain observed in June 2026. The campaign reflects a fast-paced, hands-on-keyboard intrusion combined with automated lateral movement, signaling a threat actor capable…
-
US Charges Two Over $43M Chinese Money Laundering Operation
U.S. authorities have charged two New York residents, including Zhuoying Chen, in connection with an alleged Chinese money laundering network accused of laundering at least $43 million generated through cyber investment fraud schemes. The indictment, unsealed in Brooklyn, alleges the operation ran between 2020 and 2022 and involved an extensive network of shell companies and bank accounts. First seen…
-
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders.It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains…
-
TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data
TP-Link has revealed several serious vulnerabilities affecting its Kasa EC70 and EC71 smart camera models, which could expose users to credential theft and geolocation data leakage. These vulnerabilities are CVE-2026-9770 and CVE-2026-13230 and specifically affect version 4 of both devices. Attackers with access to the same local network could exploit these flaws, raising concerns about…
-
GoSerpent Silently Steals Government Files for Weeks Before Sending Them to Hackers
A sophisticated cyber espionage campaign targeting government and diplomatic organizations across Southeast Asia has used a Go-based remote access Trojan, dubbed GoSerpent, to collect sensitive documents for weeks before exfiltrating them via network shares. Researchers first identified the activity in February 2026, although evidence indicates the operation began in late 2025. The attackers deployed GoSerpent…
-
Zoom Patches Critical Windows Flaw Enabling Account Takeover
Zoom has released security updates to fix CVE-2026-53412, a critical Improper Input Validation vulnerability affecting its Windows software, which could allow attackers to take over user accounts via network access. The flaw primarily impacts the Zoom Desktop Client and other Windows-based Zoom products, prompting the company to urge users to install the latest updates. First…
-
Gaps in network security, oversight strategy hamper US’s aviation cybersecurity regulators
A new government audit identified several weaknesses at the two agencies that protect air travel from hackers. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/aviation-cybersecurity-faa-tsa-gao-report/825416/
-
Top 10 Firewall Solutions Setting New Cybersecurity Standards in 2026
Thefirewallcategory is reinventing itself faster than at any point since NGFW arrived and2026’sleadersaren’tjust shipping betterboxes,they’reredefining what”firewall”means. Palo Alto Networks is setting the bar for AI-driven inline prevention, Fortinet for hybrid mesh execution, and HPE Juniper for the quantum-safe era, while Zscaler and Cloudflare are proving the most consequentialfirewallof all might be no appliance whatsoever. Here…
-
Statement von Extreme Networks zum AI-Appreciation-Day 2026
Anlässlich des AI-Appreciation-Day teilen Markus Nispel und Carolina Bessega von Extreme Networks ihre Einschätzungen dazu, wie KI Führung, Produktivität und fachliche Arbeit verändert und welche Rolle menschliches Urteilsvermögen dabei weiterhin spielt. Markus Nispel, CTO EMEA and Head of AI Engineering, Extreme Networks: ‘KI verändert die Arbeit von Führungskräften, weil sie ihnen bessere Datengrundlagen, tiefere Einblicke und…
-
TuxBot v3: The IoT Botnet Built With AI Bugs, Disclaimers and All
TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an unusual detail: the developer used a large language model to write significant portions…
-
Dutch Police and Europol Disrupt Global Investment Scam Infrastructure and Arrest Key Suspects
Dutch police, working with international law-enforcement partners including Europol, have disrupted a sprawling investment-fraud operation alleged to have defrauded victims across multiple countries of more than Euro100 million every month. The investigation has resulted in arrests in Poland, Cyprus, Belgium, and Greece, targeting a network that operated around twenty fraudulent call centers staffed by more…
-
‘Keys to the kingdom’: hackers who gained access to heart of London transport network jailed
Thalha Jubair, 20, and Owen Flowers, 19, sentenced to five and a half years each for cyber-attack that cost Transport for London £39mThe data of millions of commuters was stolen, Londoners were left out of pocket and 27,000 Transport for London staff were forced to reset their passwords.Over four days in 2024 a pair of…
-
New Spirals ransomware encrypts victim network in under 24 hours
A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours/
-
Police take down investment fraud network that stole Euro100 million a month
Dutch police, working alongside Belgian authorities and Europol, have dismantled a major criminal network accused of operating a global investment fraud scheme through dozens … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/16/dutch-police-investment-fraud-ring-dismantled/
-
Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report says
The Iranian government exploited well-known flaws in cellphone networks to locate and then strike U.S. military personnel in the build-up and beginning of the war. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/
-
Iran abused mobile networks’ vulnerabilities to locate U.S. military in the Middle East, report says
The Iranian government exploited well-known flaws in cellphone networks to locate and then strike U.S. military personnel in the build-up and beginning of the war. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/
-
Download: The ultimate guide to network operations management
Modern network operations are too manual. Today’s IT and security teams are managing growing complexity across networks, infrastructure, tools, and workflows. The result? … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/tines-network-operations-management-guide/
-
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
Tags: attack, credentials, cyber, data, ddos, government, group, infrastructure, iran, leak, network, service, technologyA decentralized network of pro-Iran hacktivist groups is intensifying cyber operations against critical infrastructure, government entities, technology providers, and organizations perceived as aligned with U.S., Israeli, or Western interests. The activity is dominated by distributed denial-of-service attacks, defacements, credential-focused operations, data-leak claims, and propaganda designed to convert limited technical disruption into outsized psychological and reputational…
-
Pro-Iran Hacktivist Groups Launch DDoS and Hack-and-Leak Attacks Against Critical Infrastructure
Tags: attack, credentials, cyber, data, ddos, government, group, infrastructure, iran, leak, network, service, technologyA decentralized network of pro-Iran hacktivist groups is intensifying cyber operations against critical infrastructure, government entities, technology providers, and organizations perceived as aligned with U.S., Israeli, or Western interests. The activity is dominated by distributed denial-of-service attacks, defacements, credential-focused operations, data-leak claims, and propaganda designed to convert limited technical disruption into outsized psychological and reputational…
-
Your vendor’s vendor might be the real breach risk
In this Help Net Security video, Chris Boehm, Field CTO, Zero Networks, breaks down how a vendor breach can become your breach. He explains that attackers now target the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/vendor-breach-risk-video/
-
NSA Warns Russian State-Sponsored Hackers Exploiting Vulnerable Routers to Target Critical Infrastructure
Tags: access, advisory, cyber, cybersecurity, exploit, hacker, infrastructure, international, network, router, russia, threat, vulnerabilityThe U.S. National Security Agency (NSA) and international cybersecurity partners have issued a warning that Russian state-sponsored threat actors are actively exploiting vulnerable and poorly configured network routers to access organizations in critical infrastructure sectors. In a joint Cybersecurity Advisory (CSA) titled >>Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting,<< released on July 13,…
-
States are building their own election defense networks as federal support evaporates
Election officials are facing an impossible choice: follow federal directives they don’t trust, or risk becoming targets of a criminal investigation. First seen on cyberscoop.com Jump to article: cyberscoop.com/trump-administration-eac-firings-doj-election-officials-threat/
-
Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI
Apple would not comment on the “security breach,” which allegedly allowed a former employee to download sensitive files from Apple’s network long after he departed the company for rival OpenAI. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/13/apple-says-former-employee-exploited-rare-bug-to-download-confidential-files-after-leaving-for-openai/
-
Vectra AI CEO: Network Data Drives Predictive Security
Hitesh Sheth: Cloud, SaaS, Data Center Visibility Boosts Enterprise Risk Assessment. Vectra AI CEO Hitesh Sheth says comprehensive network observability provides the most reliable foundation for predictive cybersecurity because it spans cloud, SaaS and on-premises infrastructure while offering telemetry that attackers are far less able to manipulate than endpoint logs. First seen on govinfosecurity.com Jump…
-
Officials once again warn defenders that Russian hackers are targeting network devices
State-sponsored attackers are targeting critical infrastructure networks in defense, communications, energy, finance, government and health care. First seen on cyberscoop.com Jump to article: cyberscoop.com/russian-fsb-cisco-joint-cybersecurity-advisory/
-
EU sanctions Russian GRU military hackers over cyberattacks
The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/
-
Vibe-Coded Malware Caught in Active Directory Attack
Huntress found a threat actor using vibe-coded PowerShell to map an Active Directory network First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/vibe-coded-malware-ai-powershell/
-
NSA revives ‘Tailored Access Operations’ name for elite hacking unit
NSA last week changed the moniker of its Office of Computer Network Operations (CNO) back to Tailored Access Operations (TAO), a name that is sure to elicit nostalgia among the broader digital community for a group with roots in the early 1990s. First seen on therecord.media Jump to article: therecord.media/nsa-revives-tao-name-for-elite-hacking-unit
-
HP Linux Imaging and Printing Software Flaw Enables Privilege Escalation Attacks
A critical vulnerability has been discovered in HP Linux Imaging and Printing Software (HPLIP), which exposes Linux systems to potential privilege escalation and remote code execution attacks. This vulnerability, tracked as CVE-2026-14544, has a CVSS v3 score of 9.8, indicating maximum severity due to its potential for network exploitation, low attack complexity, and lack of…
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181

