Tag: service
-
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience
Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.…
-
âš¡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Tags: ai, attack, breach, data-breach, malware, rce, remote-code-execution, service, wordpress, zero-dayA single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being…
-
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Tags: advisory, cctv, cybersecurity, intelligence, Internet, military, russia, service, spy, ukraineAt least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and military…
-
20th July Threat Intelligence Report
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/20th-july-threat-intelligence-report/
-
Microsoft confirms Windows Server Update Services sync delays
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-wsus-server-sync-delays-and-timeouts/
-
Apps Marketed to US Troops Are Shipping Chinese and Russian Code
A first-of-its-kind analysis found more than one in eight apps built for US service members carried foreign code”, some from firms in nations the Pentagon designates as adversaries. First seen on wired.com Jump to article: www.wired.com/story/apps-marketed-to-us-troops-are-shipping-chinese-and-russian-code/
-
AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models. Hugging Face disclosed that an…
-
SoftBank leverages OpenAI for AI-driven cybersecurity patching service
First seen on scworld.com Jump to article: www.scworld.com/brief/softbank-leverages-openai-for-ai-driven-cybersecurity-patching-service
-
AWS: Airbus schickt sensible Daten in die französische Cloud
Airbus verlagert kritische Systeme von Amazon Web Services zum französischen Anbieter Scaleway. First seen on golem.de Jump to article: www.golem.de/news/aws-airbus-schickt-sensible-daten-in-die-franzoesische-cloud-2607-211034.html
-
OpenSSL Fixes HollowByte Memory Exhaustion Bug
Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 bytes. A remote, unauthenticated attacker sends that payload and the server allocates up to 131 KB of memory…
-
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload
A newly disclosed vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. The Okta Red Team recently discovered >>HollowByte,<< a Denial of Service (DoS) flaw in OpenSSL that allows a remote, unauthenticated attacker to force a server to allocate disproportionate memory chunks before any security handshake even begins, using a payload just…
-
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts.OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta’s…
-
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/
-
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys.A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and…
-
Government Agencies Falling Victim to Ransomware Daily, Warns Study
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/government-ransomware-daily/
-
AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers
Amazon Web Services (AWS) is currently investigating a significant billing issue affecting its Cost Explorer tool. This problem caused some cloud customers to see alarmingly inflated cost estimates, with figures reportedly reaching into the trillions of dollars. AWS Support acknowledged the issue on July 17, 2026, which has caused confusion and concern within the cloud…
-
AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers
Amazon Web Services (AWS) is currently investigating a significant billing issue affecting its Cost Explorer tool. This problem caused some cloud customers to see alarmingly inflated cost estimates, with figures reportedly reaching into the trillions of dollars. AWS Support acknowledged the issue on July 17, 2026, which has caused confusion and concern within the cloud…
-
Zelensky appoints Ukraine’s acting security service chief as acting defense minister
Yevhenii Khmara, a major general with deep experience in intelligence, counterterrorism and long-range strikes against Russia, is Ukraine’s new acting defense minister. First seen on therecord.media Jump to article: therecord.media/ukraine-acting-defense-minister-yevhenii-khmara
-
Spirals ransomware locks down victim systems in under 24 hours
A previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/spirals-ransomware-south-asia/
-
LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHive GitHub repository, abuses Windows’ User Profile Service to mount a target user’s UsrClass.dat hive into a registry location…
-
AnyDesk Zero-Day Flaw Allows Local Attackers to Trigger System-Wide DenialService
A newly disclosed zero-day vulnerability in AnyDesk has the potential to allow a local attacker to trigger a denial-of-service condition by exploiting the remote-access software’s “Send Support Information” feature. The advisory, tracked as ZDI-26-401 and ZDI-CAN-26645, was published by Trend Micro’s Zero Day Initiative (ZDI) on July 8, 2026. The flaw has been assigned CVE-2026-15682…
-
HHS Wants Input on Cyber, AI for Regulations on Clinical Labs
Experts Say Clinical Laboratory Improvement Amendments Are Seriously Outdated. The Department of Health and Human Services is seeking public feedback pertaining to cybersecurity matters and the use of artificial intelligence for potentially updating decades-old, rules-of-the-road regulations for U.S. clinical laboratories that test human specimens for health conditions. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hhs-wants-input-on-cyber-ai-for-regulations-on-clinical-labs-a-32246
-
Anubis ransomware: what you need to know
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard – but they are not the only ones at risk. First seen on fortra.com Jump to article: www.fortra.com/blog/anubis-ransomware
-
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw-lets-malicious-extensions-trigger-ai-actions/
-
UK investigates TikTok for alleged age-verification lapses, exposing kids to online harms
“Age checks are a cornerstone of the UK’s online safety laws,” said Ofcom’s Chief Executive, Melanie Dawes. “Too many services have no or inadequate age checks in place, which is not good enough.” First seen on therecord.media Jump to article: therecord.media/ofcom-investigation-tiktok-age-verification
-
Google Makes Security Objections to EU Order Opening Android
EU Forces Google to Give Rival AI Services Android Access and to Share Search Data. Google sounded security alarms after the European Commission ordered it to open up deep Android functionality to rival artificial intelligence providers, and also to give third-party search providers access to Google Search data. The orders enforce the Digital Markets Act.…
-
Two Scattered Spider Members Sentenced to 5.6 Years Over TfL Cyberattack
Nearly two years after a cyberattack disrupted Transport for London’s (TfL) online services and exposed customer data, two… First seen on hackread.com Jump to article: hackread.com/two-scattered-spider-members-sentenced-tfl-cyberattack/
-
Hacker können BindFunktion in Windows zum Erstellen virtueller Pfade in Datensystemen missbrauchen
Legitime Tools und Dienste bieten Hackern eine effektive Möglichkeit, ihre Living-off-the-Land (LOTL)- oder Living-off the-Services (LOTS)-Angriffe zu verbergen. Mit der Tarnkappe einer legitimen Funktion wie auch eines Dienstes oder Tools unterlaufen solche Angriffe die Erkennung von Endpoint-Detection and Response (EDR) oder anderer Analysetools. Weitere Beispiele für ein solches Mimikri haben die Experten der […] First…

