Tag: service
-
Multiple FFmpeg Flaws Allow Arbitrary Memory Corruption via Malicious Videos
Multiple high-severity vulnerabilities in FFmpeg could allow attackers to corrupt memory, disclose process data, or exhaust system resources. This can happen if users or automated media-processing services are manipulated into handling specially crafted video, audio, image, or subtitle files. The vulnerabilities affect FFmpeg versions up to 8.1.28. Organizations operating transcoding pipelines, media upload platforms, streaming…
-
Apple iOS 26.6 Update Fixes Flaws Allowing Kernel-Level Code Execution and Root Access
Apple has released iOS 26.6 and iPadOS 26.6, a significant security update that addresses numerous vulnerabilities across core operating system components, media frameworks, WebKit, wireless services, and application frameworks. Released on July 27, 2026, this update is available for iPhone 11 and later models, as well as supported iPads. It should be prioritized for deployment…
-
ShinyHunters Claims EY Data Breach, Threatens to Leak Stolen Client Tax Data
ShinyHunters has claimed responsibility for the data breach at Ernst & Young (EY) and is threatening to publish allegedly stolen client tax information unless the professional services firm engages in negotiations before July 31, 2026. The extortion group posted about EY on its dark web leak site, describing the deadline as a “final warning” and…
-
Bitdefender adds EU-based MDR services to Sovereign Security Program
Tags: serviceFirst seen on scworld.com Jump to article: www.scworld.com/brief/bitdefender-adds-eu-based-mdr-services-to-sovereign-security-program
-
Keyfactor expands partner program for machine identity and post-quantum services
First seen on scworld.com Jump to article: www.scworld.com/news/keyfactor-expands-partner-program-for-machine-identity-and-post-quantum-services
-
US Space Cybersecurity: ‘No One Is in Charge’
Cyber Defense Falters Without Cabinet Agency or White House Champion for Security. No single senior official is in charge of U.S. efforts to help secure commercial satellites and their land-based infrastructure. That leadership void has hampered the ability to impose security standards on space vendors providing critical services to the U.S. government over the past…
-
New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/
-
New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/
-
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt.CNCERT, China’s national computer emergency response team, and XLab, the threat-intelligence lab of Chinese First seen…
-
Anyone With a Browser Could Access 700,000 Vatican Prayer App Accounts
A critical access control vulnerability in the Vatican’s official “Click to Pray” platform has exposed the personal data of more than 700,000 users, highlighting once again how basic web security misconfigurations continue to put large-scale user bases at risk. The service, operated by the Pope’s Worldwide Prayer Network, is widely used across the globe to…
-
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra.According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote First…
-
AWS validiert Skaylink als Managed Service Provider für geschäftskritische Cloud-Workloads
AWS validiert Skaylink als Managed Service Provider. Deutsche SRE-Teams betreiben kritische Cloud-, Daten- und KI-Workloads für regulierte Kunden. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/aws-validiert-skaylink-als-managed-service-provider-fuer-geschaeftskritische-cloud-workloads/a45879/
-
Windows WalletService Flaw Lets Standard Users Gain SYSTEM Privileges
Microsoft Windows WalletService is affected by a local privilege escalation vulnerability tracked as CVE-2026-49176. This flaw could allow a standard authenticated user to obtain SYSTEM-level privileges. The vulnerability arises from WalletService’s handling of user-controlled file paths during initialization. An attacker can exploit this by redirecting the service to a maliciously crafted Extensible Storage Engine (ESE)…
-
Microsoft Introduces KMS Hardware-Secured for Windows Server Activation
Microsoft has introduced KMS Hardware-Secured, an upcoming enhancement to Windows Server activation that utilizes Trusted Platform Module (TPM)-based attestation to validate Key Management Service (KMS) hosts before they can activate Windows devices. Announced in a July 2022 Windows IT Pro Blog post, this initiative addresses risks related to spoofed, cloned, or otherwise untrusted KMS infrastructure.…
-
Product showcase: LastPass Authenticator brings Face ID, Apple Watch, and cloud backup to 2FA
LastPass Authenticator is a free app that provides two-factor authentication (2FA) for accounts and any service that supports time-based one-time passwords (TOTP). It supports … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/27/product-showcase-lastpass-authenticator/
-
Golden Chickens malware-as-a-service resurfaces with four new families
First seen on scworld.com Jump to article: www.scworld.com/brief/golden-chickens-malware-as-a-service-resurfaces-with-four-new-families
-
ServiceService Authentication: Patterns for Securing API and Microservices
First seen on scworld.com Jump to article: www.scworld.com/tech-explainer/service-to-service-authentication-patterns-for-securing-api-and-microservice
-
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims.Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis.”The portal combined build generation, finance, First seen on thehackernews.com…
-
Google Fined Euro890M Under EU Digital Markets Act Over Search and Play Store Practices
EU fined Google Euro890M under the DMA for favoring its own services and restricting Play Store competition, with AI search features also under scrutiny. The European Commission hit Google with two fines totalling Euro890 million on Thursday for violating the Digital Markets Act, one for giving its own services preferential placement in Google Search and…
-
Golden Chickens Launches Four Modular Malware Families to Steal Chrome Credentials and Hijack Browser Sessions
Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation flexibility. The newly identified families TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator mark a clear architectural evolution in the group’s malware-as-a-service (MaaS) ecosystem, signaling a shift…
-
Microsoft tightens Windows enterprise activation security
Microsoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS), the on-premises service used for Windows volume … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/microsoft-kms-tpm-security-update/
-
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential First seen…
-
Why embodied AI security extends beyond the robot
As AI moves into robots, autonomous vehicles and industrial systems, attackers are likely to target the credentials, cloud services and update channels that control them First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646180/Why-embodied-AI-security-extends-beyond-the-robot
-
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
Tags: apache, authentication, cve, cyber, flaw, injection, remote-code-execution, service, sql, vulnerabilityApache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities include a self-service privilege escalation bug, multiple post-authentication remote code execution (RCE) pathways, authenticated server-side request forgery (SSRF), and SQL injection issues. Apache Syncope Flaws CVE-2026-62183 affects deployments that utilize the…
-
MI5 and PSNI ordered to pay damages to BBC journalist Vincent Kearney over unlawful surveillance
Tags: serviceThe Security Service, MI5 and the Police Service of Northern Ireland have been ordered to pay damages to a former BBC journalist, Vincent Kearney, following multiple attempts to identify his confidential sources First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646084/MI5-and-PSNI-ordered-to-pay-damages-to-BBC-journalist-Vincent-Kearney-over-unlawful-surveillance
-
Fake Claude app promoted by Bing ads pushes SectopRAT malware
A malvertising campaign on the Bing search service is pushing a fake Claude desktop app installer hosted on a legitimate Claude.ai domain to deliver the SectopRAT malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-pushes-sectoprat-malware/
-
Microsoft 365 outage affects Teams, SharePoint and other services
Microsoft Teams and several Microsoft 365 services are experiencing an ongoing outage, with users reporting problems accessing Teams, SharePoint, Excel and the Microsoft 365 Admin Center. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-365-outage-affects-teams-sharepoint-and-other-services/
-
KI greift eigenständig an Unternehmen müssen ihre Cyberabwehr neu denken
Die aktuelle Berichterstattung ruft erschreckende Zukunftsszenarien wach: Zum ersten Mal wurde ein selbstständiger Hackerangriff durch eine künstliche Intelligenz bekannt. Der KI-Anbieter OpenAI meldet einen neuartigen Sicherheitsvorfall, hervorgerufen von einer unternehmenseigenen KI-Technologie. Dan Schiappa, President Technology and Services bei Arctic Wolf, erklärt, was die Evolution eigenständig angreifender KI für die Cyberbedrohungslandschaft bedeutet. ‘KI ist zunehmend in…
-
The next managed security service: Deciding which AI agents get in
First seen on scworld.com Jump to article: www.scworld.com/perspective/the-next-managed-security-service-deciding-which-ai-agents-get-in
-
Bundeskriminalamt zerschlägt Phishing-Plattform Kratos
Am 20. Juli 2026 zerschlugen Bundeskriminalamt und ZIT (Zentralstelle zur Bekämpfung der Internetkriminalität) gemeinsam mit US-Behörden im Rahmen der Operation ‘Olympus Blade” die Infrastruktur von Kratos einer Phishing-as-a-Service-Plattform, die für einen Großteil der aktuellen Microsoft-365-Credential-Diebstähle verantwortlich war. Der Entwickler und technische Administrator wurde in Indonesien verhaftet, über 200 Server wurden abgeschaltet. Zuvor nutzen mehr […]…

