Tag: service
-
AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models. Hugging Face disclosed that an…
-
SoftBank leverages OpenAI for AI-driven cybersecurity patching service
First seen on scworld.com Jump to article: www.scworld.com/brief/softbank-leverages-openai-for-ai-driven-cybersecurity-patching-service
-
AWS: Airbus schickt sensible Daten in die französische Cloud
Airbus verlagert kritische Systeme von Amazon Web Services zum französischen Anbieter Scaleway. First seen on golem.de Jump to article: www.golem.de/news/aws-airbus-schickt-sensible-daten-in-die-franzoesische-cloud-2607-211034.html
-
OpenSSL Fixes HollowByte Memory Exhaustion Bug
Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 bytes. A remote, unauthenticated attacker sends that payload and the server allocates up to 131 KB of memory…
-
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload
A newly disclosed vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. The Okta Red Team recently discovered >>HollowByte,<< a Denial of Service (DoS) flaw in OpenSSL that allows a remote, unauthenticated attacker to force a server to allocate disproportionate memory chunks before any security handshake even begins, using a payload just…
-
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts.OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta’s…
-
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/
-
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys.A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and…
-
Government Agencies Falling Victim to Ransomware Daily, Warns Study
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/government-ransomware-daily/
-
LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHive GitHub repository, abuses Windows’ User Profile Service to mount a target user’s UsrClass.dat hive into a registry location…
-
AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers
Amazon Web Services (AWS) is currently investigating a significant billing issue affecting its Cost Explorer tool. This problem caused some cloud customers to see alarmingly inflated cost estimates, with figures reportedly reaching into the trillions of dollars. AWS Support acknowledged the issue on July 17, 2026, which has caused confusion and concern within the cloud…
-
AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers
Amazon Web Services (AWS) is currently investigating a significant billing issue affecting its Cost Explorer tool. This problem caused some cloud customers to see alarmingly inflated cost estimates, with figures reportedly reaching into the trillions of dollars. AWS Support acknowledged the issue on July 17, 2026, which has caused confusion and concern within the cloud…
-
Zelensky appoints Ukraine’s acting security service chief as acting defense minister
Yevhenii Khmara, a major general with deep experience in intelligence, counterterrorism and long-range strikes against Russia, is Ukraine’s new acting defense minister. First seen on therecord.media Jump to article: therecord.media/ukraine-acting-defense-minister-yevhenii-khmara
-
Spirals ransomware locks down victim systems in under 24 hours
A previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/spirals-ransomware-south-asia/
-
AnyDesk Zero-Day Flaw Allows Local Attackers to Trigger System-Wide DenialService
A newly disclosed zero-day vulnerability in AnyDesk has the potential to allow a local attacker to trigger a denial-of-service condition by exploiting the remote-access software’s “Send Support Information” feature. The advisory, tracked as ZDI-26-401 and ZDI-CAN-26645, was published by Trend Micro’s Zero Day Initiative (ZDI) on July 8, 2026. The flaw has been assigned CVE-2026-15682…
-
HHS Wants Input on Cyber, AI for Regulations on Clinical Labs
Experts Say Clinical Laboratory Improvement Amendments Are Seriously Outdated. The Department of Health and Human Services is seeking public feedback pertaining to cybersecurity matters and the use of artificial intelligence for potentially updating decades-old, rules-of-the-road regulations for U.S. clinical laboratories that test human specimens for health conditions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hhs-wants-input-on-cyber-ai-for-regulations-on-clinical-labs-a-32246
-
Anubis ransomware: what you need to know
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard – but they are not the only ones at risk. First seen on fortra.com Jump to article: www.fortra.com/blog/anubis-ransomware
-
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw-lets-malicious-extensions-trigger-ai-actions/
-
UK investigates TikTok for alleged age-verification lapses, exposing kids to online harms
“Age checks are a cornerstone of the UK’s online safety laws,” said Ofcom’s Chief Executive, Melanie Dawes. “Too many services have no or inadequate age checks in place, which is not good enough.” First seen on therecord.media Jump to article: therecord.media/ofcom-investigation-tiktok-age-verification
-
Google Makes Security Objections to EU Order Opening Android
EU Forces Google to Give Rival AI Services Android Access and to Share Search Data. Google sounded security alarms after the European Commission ordered it to open up deep Android functionality to rival artificial intelligence providers, and also to give third-party search providers access to Google Search data. The orders enforce the Digital Markets Act.…
-
Two Scattered Spider Members Sentenced to 5.6 Years Over TfL Cyberattack
Nearly two years after a cyberattack disrupted Transport for London’s (TfL) online services and exposed customer data, two… First seen on hackread.com Jump to article: hackread.com/two-scattered-spider-members-sentenced-tfl-cyberattack/
-
Hacker können BindFunktion in Windows zum Erstellen virtueller Pfade in Datensystemen missbrauchen
Legitime Tools und Dienste bieten Hackern eine effektive Möglichkeit, ihre Living-off-the-Land (LOTL)- oder Living-off the-Services (LOTS)-Angriffe zu verbergen. Mit der Tarnkappe einer legitimen Funktion wie auch eines Dienstes oder Tools unterlaufen solche Angriffe die Erkennung von Endpoint-Detection and Response (EDR) oder anderer Analysetools. Weitere Beispiele für ein solches Mimikri haben die Experten der […] First…
-
Sicherheitslücken für Backups in nur 15 Minuten aufgedeckt
Grau Data ergänzt sein Angebot für Ransomware-Schutz für Backups um den neuen Service ‘Repository Security Check für Windows”. Dieser kann unabhängig vom Einsatz von <> genutzt werden und identifiziert potenzielle Schwachstellen, über die Angreifer auf lebenswichtige Backups zugreifen könnten. In durchschnittlich nur 15 Minuten erhalten Unternehmen Klarheit darüber, wie sicher ihre Backup-Repositories sind. […] First…
-
US unseals indictment against alleged operators of Russian bulletproof hosting service
The Russians face multiple charges for allegedly providing cybercriminals with infrastructure and tech support through the St. Petersburg-based business Media Land and a sister company, ML Cloud. First seen on therecord.media Jump to article: therecord.media/us-unseals-indictment-russians-bulletproof-hosting
-
Online Protection Is Simple and Effective with Panda Dome for $29.99
Get antivirus, firewall, and VPN service with a one-year subscription to Panda Dome for just $29.99. The post Online Protection Is Simple and Effective with Panda Dome for $29.99 appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/panda-dome-antivirus-security-complete/
-
Phishing Toolkits Harvest Entra Tokens in Real Time
Jalisco Device Code Phishing Tool Use Also Tied to EvilTokens and Kali365 Customers. Sophisticated phishing-as-a-service toolkits are driving a surge in phishing attack volume, experts warn, by giving users highly automated tools for personalizing lures and accessing previously niche tactics for generating valid authentication tokens for persistent access. First seen on govinfosecurity.com Jump to article:…
-
Phishing-as-a-Service: Cybercrime im Abo
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/phishing-as-a-service-cybercrime-abo

