Tag: service
-
Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications.”Manic sits at the intersection of Android banking malware and mobile spyware, combining financial-fraud First seen on thehackernews.com Jump to…
-
AWS limits AI agents’ data access, even when manipulated
AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/aws-ai-agents-access-controls/
-
Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security
Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact infection chain that begins with a victim manually executing a malicious PowerShell command. In late July 2026, multiple ClickFix campaigns generated through the ErrTraffic malware-as-a-service platform and used to deliver Cruciferra, a loader advertised…
-
Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Multicluster Engine for Kubernetes. This flaw has a CVSS v3.1 score of 9.3. It could allow an unauthenticated remote attacker to use a publicly accessible route to access otherwise isolated services across managed clusters. Published on August…
-
Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE
Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code execution (RCE) flaw in the Splunk MCP Server app. The vulnerabilities encompass deserialization, access control, server-side request forgery (SSRF), denial-of-service, certificate validation, and information disclosure. Tracked as SVD-2026-0808 and published on August 19, 2026, the…
-
Claude AI Finds Authentication Bypass Flaws in Multiple SAML Implementations
Multiple critical vulnerabilities in SAML implementations after employing Anthropic’s Claude Code in an AI-assisted vulnerability research pipeline. Security researcher Eric Chiang, the CTO of Oblique Security, investigation uncovered full authentication bypasses, signature-validation flaws, information disclosure risks, arbitrary logout issues, and denial-of-service conditions across several open-source SAML products. Claude AI Finds Authentication Bypass Flaws Chiang’s research…
-
‘TWINLOOT’ Python implant abuses Microsoft services for stealthy C2
First seen on scworld.com Jump to article: www.scworld.com/news/twinloot-python-implant-abuses-microsoft-services-for-stealthy-c2
-
EHR Vendor Notifying 3.8 Million Patients of Data Theft Hack
CareCloud Said Compromise Involved One of Its AWS Cloud Environments. CareCloud, a provider of cloud-based, artificial intelligence-powered electronic health records, is notifying nearly 3.8 million individuals that their personal and health information was potentially stolen in a March hacking incident involving one of its Amazon Web Services environments. First seen on govinfosecurity.com Jump to article:…
-
Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/
-
Rogue ransomware affiliate poses as data recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/
-
Sakura Internet hack exposes data of up to 1.36 million accounts
Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-up-to-136-million-accounts/
-
Electronic health record company CareCloud says 3.7 million people affected by breach
Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s electronic health record environments. First seen on therecord.media Jump to article: therecord.media/electronic-health-record-company-carecloud-data-breach
-
NIST Frameworks and SOC 2 Reporting via Continuum GRC Services
As organizations navigate an increasingly complex regulatory environment in 2026, integrating NIST frameworks with SOC 2 reporting offers a strategic advantage that reduces audit fatigue while strengthening overall governance, risk, and compliance postures. Continuum GRC enables this interoperability through unified control mapping that aligns NIST SP 800-53, NIST SP 800-171 Rev 3, and CMMC 2.0″¦…
-
Scammers are using fake crypto AML checkers to drain your wallet
We found wallet-checking sites impersonating real anti-money laundering services that trick people into approving access to scammers. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/scammers-are-using-fake-crypto-aml-checkers-to-drain-your-wallet/
-
CISA Warns Microsoft Internet Key Exchange RCE Flaw Is Actively Exploited
Tags: cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, Internet, kev, microsoft, rce, remote-code-execution, service, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability, tracked as CVE-2026-33824, is currently being actively exploited. The issue is classified as a double-free vulnerability, which means it affects the memory management of Microsoft…
-
Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-harvesting kit. It operates as a subscription-based criminal service that rents access to affiliates, lowering the barrier for telemarketing fraud groups and inexperienced…
-
Benefits of automated response in cyber security
For many UK SMEs, the real cost of a cyber incident is not just the security issue itself. It is the lost time, the interruption to customer service, the pressure on a small IT team, and the damage to trust if the business cannot respond quickly. That is why the benefits of automated response in……
-
Medusa ransomware gang has hit over 500 organizations, CISA warns
Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/19/medusa-ransomware-cisa-warning/
-
Critical RCE flaw in Windows IKE Extension now actively exploited
Tags: cybersecurity, exploit, flaw, hacker, infrastructure, Internet, rce, remote-code-execution, service, windowsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-flaw-now-exploited-in-attacks/
-
Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
The people-search tool ClarityCheck says its reverse image search service is “private and secure””, but it left a database containing more than 9 million image files exposed. First seen on wired.com Jump to article: www.wired.com/story/reverse-lookup-service-exposed-millions-of-photos-of-peoples-faces/
-
Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments…

