Tag: service
-
FBI Seizes NightmareStresser DDoSHire Domains Used in Hundreds of Thousands of Attacks
The FBI has seized internet domains linked to NightmareStresser, a long-standing distributed denial-of-service (DDoS)-for-hire platform allegedly used to launch hundreds of thousands of attacks or attempted attacks worldwide since 2022. The U.S. Attorney’s Office for the District of Alaska announced the action, which targets the infrastructure that allowed paying customers to overwhelm victims’ networks and…
-
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough.So the…
-
States Expand Cyber Support Beyond Their Own Networks
Local Control and Funding Gaps Complicate Critical Infrastructure Protection. States are extending cyber support to local utilities and other essential services they do not control. Closing the gap will require more than grants and tools. Local operators need sustained monitoring, OT expertise and stronger, consistent vendor controls. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/states-expand-cyber-support-beyond-their-own-networks-a-32858
-
States Expand Cyber Support Beyond Their Own Networks
Local Control and Funding Gaps Complicate Critical Infrastructure Protection. States are extending cyber support to local utilities and other essential services they do not control. Closing the gap will require more than grants and tools. Local operators need sustained monitoring, OT expertise and stronger, consistent vendor controls. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/states-expand-cyber-support-beyond-their-own-networks-a-32858
-
States Expand Cyber Support Beyond Their Own Networks
Local Control and Funding Gaps Complicate Critical Infrastructure Protection. States are extending cyber support to local utilities and other essential services they do not control. Closing the gap will require more than grants and tools. Local operators need sustained monitoring, OT expertise and stronger, consistent vendor controls. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/states-expand-cyber-support-beyond-their-own-networks-a-32858
-
Cisco alerts customers to second actively exploited zero-day in as many days
The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. First seen on cyberscoop.com Jump to article: cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/
-
Moderne Cyber Defense: Threat-Hunting-asService
Nicht jeder Cyberangriff löst einen Alarm aus: Angreifer vermeiden in der Regel gezielt bekannte Erkennungsmuster und bewegen sich unterhalb der Schwelle klassischer Security-Lösungen. Vor diesem Hintergrund gewinnt Threat Hunting zunehmend an Bedeutung. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/threat-hunting-as-a-service
-
Authorities seize popular, long-running DDoS-for-hire service domains
Cybercriminals used NightmareStresser to launch hundreds of thousands of DDoS attacks since at least 2022. Threat actors behind the operation claimed links to Russia. First seen on cyberscoop.com Jump to article: cyberscoop.com/fbi-seizes-nightmarestresser-ddos-for-hire-domains/
-
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday.It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links.Helpfeel said…
-
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.”This vulnerability is due to insufficient authentication control on an API endpoint,” Cisco said. “An attacker First seen on thehackernews.com…
-
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser.The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the site are now greeted by a seizure banner that states -“This domain has been seized by the First seen on…
-
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/aws-middle-east-outage-permanent-data-loss-bahrain-uae/
-
CISO-as-a-Service wächst: Sophos-Studie zeigt neue Chancen für Managed Service Provider
Sophos-Studie: 84 Prozent der MSPs erwarten mehr Nachfrage nach CISO-Services. Compliance, KI und komplexe Security treiben den Wandel zum vCISO. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ciso-as-a-service-waechst-sophos-studie-zeigt-neue-chancen-fuer-managed-service-provider/a46416/
-
Why The Post-Quantum Shift Could Leave Older IT Systems Behind: Experts
Many legacy IT systems may be unable to support post-quantum cryptography, leaving businesses exposed to future quantum-powered attacks and creating significant hardware and services opportunities for channel partners. First seen on crn.com Jump to article: www.crn.com/news/security/2026/why-the-post-quantum-shift-could-leave-older-it-systems-behind-experts
-
Aurora-MDR-Connect von Arctic Wolf speziell für ManagedProvider
Arctic Wolf gibt die Einführung von Aurora-MDR-Connect bekannt, einer neuen Stufe von Aurora-Managed-Detection and Response (MDR), die exklusiv für Managed-Service-Provider (MSPs) entwickelt wurde. Aurora-MDR-Connect basiert auf der Aurora-Superintelligence-Platform und dem Aurora-Agentic-SOC, welches auch dem bewährten MDR-Angebot von Arctic Wolf zugrunde liegt. Damit können MSPs moderne Security-Operations, einschließlich 24/7-Erkennung, Untersuchung von Vorfällen und vorab autorisierter Reaktion,…
-
NightmareStresser Goes Offline in Global DDoSHire Crackdown
The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The Justice Department just made that a…
-
GPT4Free Privacy Risks Expose AI Prompts to Third-Party Servers and Hidden Logs
Users of the GPT4Free hosted platform might believe they are directly interacting with the selected artificial intelligence model in its web interface. However, recent research suggests that prompts submitted through g4f.dev may travel through a complex network of provider code, intermediary services, external model endpoints, and potentially unrelated AI servers. These findings raise significant privacy…
-
FBI takes down one of the longest-running DDoS-for-hire services
The FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running >>booter<< operations in existence. The … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/fbi-nightmarestresser-ddos-for-hire-service-seized/
-
BIND 9.20.29 Fixes 14 Security Flaws Enabling DNSSEC Bypass and DenialService Attacks
The Internet Systems Consortium (ISC) has released BIND 9.20.29, which addresses 14 security vulnerabilities. These vulnerabilities could enable remote attackers to bypass DNSSEC protections, poison resolver caches, exhaust CPU or memory resources, and crash the named service. This update is particularly important for organizations that operate recursive, DNSSEC-validating resolvers, as they are primarily exposed to…
-
US takes down NightmareStresser DDoShire platform
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world’s longest-running distributed denial-of-service (DDoS) platforms. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/
-
Kubernetes Attack Lets Hackers Steal SPIFFE Workload Identities and Impersonate Applications
A post-exploitation technique that lets attackers with root-level access to a Kubernetes node steal workload identities issued through SPIFFE/SPIRE and impersonate legitimate applications running on the same host. The technique undermines the node-trust assumption behind cloud-native machine identity systems, potentially enabling attackers to access services protected by mutual TLS and identity-based authorization. Palo Alto Networks…
-
U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog
Tags: api, authentication, backup, cisa, cisco, cve, cybersecurity, exploit, flaw, google, identity, infrastructure, kev, service, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, CiscoISE, and Google Pixelflaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw…
-
CISOs to Watch in Charlotte: From Theme Parks to Financial Services
Charlotte’s reputation runs on banking, but the security leaders in this piece protect a far wider slice of American consumer life: aircraft engines and building controls, a lending marketplace, packaging for half the products on a grocery shelf, payroll software,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cisos-to-watch-in-charlotte-from-theme-parks-to-financial-services/
-
Chosen Brick, Iran’s Surveillance Malware
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the…
-
Chosen Brick, Iran’s Surveillance Malware
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the…
-
Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/
-
Hybrid AI Is Coming. Is Your Infrastructure Ready?
A few months ago, I wrote about why I believe enterprise AI is evolving toward Hybrid AI, with organizations using different models and services for different workloads rather than relying on a single provider. The economics, performance, security, governance, and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/hybrid-ai-is-coming-is-your-infrastructure-ready/
-
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories.Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the First seen on…
-
Treasury’s Scott Bessent says no liability exemptions for AI labs
The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.” First seen on fedscoop.com Jump to article: fedscoop.com/treasury-scott-bessent-ai-labs-liability-exemptions/

