Tag: service
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
Spear-Phishing Campaign Uses Proton Drive Links and LNK Files to Deliver SpyGlace
The APT-C-60 threat actor has continued targeting Japanese organizations with a spear-phishing campaign that abuses Proton Drive, Windows shortcut files, trusted developer platforms, and native Windows utilities to deliver the SpyGlace malware. While the group retains several established tradecraft elements, including the abuse of legitimate services and the use of git.exe to execute malicious scripts,…
-
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-forg365-phishing-platform-uses-ai-to-target-microsoft-365-accounts/
-
Warum ManagedProvider beim Manufacturing 4.0 IT und OT gemeinsam denken müssen
Die Konvergenz von IT und OT schreitet mit hoher Geschwindigkeit voran und sorgt für grundlegende Veränderungen in industriellen Infrastrukturen. Immer öfter sind Produktionsanlagen, Sensorik, Edge-Geräte, IoT-Sensoren und industrielle Steuerungssysteme (ICS) eng mit klassischen IT-Infrastrukturen vernetzt. Auch für Managed-Service-Provider (MSPs) bedeutet das einen tiefgreifenden Wandel ihrer Rolle. Denn anstelle von getrennten Silos erwarten Kunden von MSPs…
-
RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging
RedHook, an Android Remote Access Trojan (RAT) first profiled in July 2025, has resurfaced with a markedly more dangerous capability: autonomous abuse of Android’s ADB Wireless Debugging to acquire shell-level privileges (uid 2000). While its baseline toolkit screen streaming, keylogging, Accessibility-driven UI manipulation and credential theft remains intact, the latest RedHook builds demonstrate a deliberate…
-
RedHook Abuses Accessibility Service to Enable Developer Options and Wireless Debugging
RedHook, an Android Remote Access Trojan (RAT) first profiled in July 2025, has resurfaced with a markedly more dangerous capability: autonomous abuse of Android’s ADB Wireless Debugging to acquire shell-level privileges (uid 2000). While its baseline toolkit screen streaming, keylogging, Accessibility-driven UI manipulation and credential theft remains intact, the latest RedHook builds demonstrate a deliberate…
-
npm and PyPI Malware Campaign Exfiltrates CI/CD Secrets Through Fake Payment SDKs
A coordinated supply-chain campaign that pushed 17 malicious packages across npm and PyPI, masquerading as SDKs for well-known payment services including PaySafe, Skrill and Neteller. The campaign’s packages 17 npm modules published with four rapid versions each and four PyPI packages access with single malicious releases presented as convenient payment SDK facades but contained logic…
-
Accenture Confirms Security Incident After Hacker Claims Data Haul
Accenture acknowledged that it suffered a data breach, but said it has remediated it with no impact on operations or service delivery. First seen on crn.com Jump to article: www.crn.com/news/security/2026/accenture-confirms-security-incident-after-hacker-claims-data-haul
-
Greek victims file lawsuit against Intellexa over Predator spyware
The use of the spyware came to light in 2022, with traces of Predator found on dozens of phones. The scandal led to the resignation of Greece’s intelligence service chief and the prime minister’s chief of staff. First seen on therecord.media Jump to article: therecord.media/greek-victims-file-lawsuit-against-intellexa-spyware
-
American HackersHire Proposal Sparks Heavy Criticism
US Senate Committee Approves Private Sector Hacking Pilot. The United States could get its own hack-for-hire network of contractors deputized by the federal government to penetrate foreign adversaries under a provision approved by a Senate Committee on Armed Services in its version of an annual defense authorization bill. First seen on govinfosecurity.com Jump to article:…
-
RedWing Android Spyware Sold as a Service on Telegram
Zimperium found RedWing, an Android spyware sold as a service via Telegram to target banking apps First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/redwing-android-spyware-maas/
-
3 Ways AI Powers Service Desk Attacks and How to Prevent Them
Specops Software explains how AI is making service desk impersonation attacks more convincing, personalized, and scalable, along with practical steps organizations can take to strengthen onboarding and identity verification. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/3-ways-ai-powers-service-desk-attacks-and-how-to-prevent-them/
-
Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools
RedWing: The Android Banking Trojan You Can Rent on Telegram for Less Than a Coffee Subscription Zimperium’s zLabs team has uncovered RedWing, an Android spyware operation sold as a subscription service through Telegram, with links to Russian threat actors and apparent roots in the Oblivion malware family. It comes with documentation, tutorial videos, a referral…
-
Telco giant KDDI says data breach affects over 12 million people
Japanese telecommunications giant KDDI says that millions of people had their email addresses and passwords exposed after attackers breached an email platform used by five internet service providers (ISPs) in the country. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/
-
Thousands of malicious AI skills found capable of stealing data, running malware
AI agents can browse the web, use external tools, execute commands, and perform tasks on behalf of users. Many rely on skills that define how they interact with services and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/eset-ai-threat-trends-report/
-
AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts
The underground advertisement for the so-called Mycelium Framework reads like another feature”‘packed botnet sales pitch: cross”‘platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised purpose to treat compromised endpoints not as disposable bots but as a capability”‘aware. AI compute…
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…
-
Accenture confirms breach after hacker offers stolen data for sale
IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/
-
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim’s phone, steal their banking logins, and capture the one-time codes that protect their accounts.Zimperium’s zLabs, which found the operation, says it looks like a new variant of Oblivion,…
-
Huntress Signs Giacom to Widen UK MSP Access to Managed Detection and Response
Huntress has struck a new distribution partnership with UK channel marketplace Giacom, giving the managed service providers (MSPs) on Giacom’s Cloud Market platform direct access to Huntress’ Agentic Security Platform and its 24/7 AI-centric Security Operations Centre (SOC). The deal is one of two announced this week, alongside a parallel agreement with MSP Nordics covering Denmark, Finland, Iceland, Norway and Sweden, as Huntress looks…
-
Iran-linked MuddyWater espionage campaign targets organisations across four continents
A new threat intelligence report from WatchGuard is warning organisations worldwide to strengthen behavioural detection capabilities after uncovering an espionage campaign by the Iran-linked threat group MuddyWater that successfully targeted high-value organisations across four continents. The report details how the group, also known as Seedworm, targeted organisations across manufacturing, aviation, financial services, education, professional services…
-
Major Japanese telco says cyberattack exposed 12 million emails
The company said the breach affected an email system used to manage customer email accounts, webmail services and email storage for five Japanese internet service providers. First seen on therecord.media Jump to article: therecord.media/major-japanese-telco-cyberattack-12-million-emails
-
TSG, Databarracks and Genesys hit acquisition trail
Tags: serviceTrio of channel players take steps to add more expertise and depth to their service offerings First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366645419/TSG-Databarracks-and-Genesys-hit-acquisition-trail
-
TSG, Databarracks and Genesys hit acquisition trail
Tags: serviceTrio of channel players take steps to add more expertise and depth to their service offerings First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366645419/TSG-Databarracks-and-Genesys-hit-acquisition-trail
-
PHP PDO Emulated Prepares Expose pdo_pgsql to NULL Pointer Dereference Crash
A recent security audit of PHP’s PDO ecosystem uncovered a denial-of-service vector in the pdo_pgsql driver that can crash PHP processes when emulated prepared statements are enabled. PDO’s parser assumes a valid zend_string and dereferences it, triggering a NULL pointer dereference (SIGSEGV). The issue is tracked as CVE-2025-14180 and rated Moderate (6.3/10). PDO implements two…
-
Windows Device ID Helped Authorities Track Scattered Spider Hacking Group Member
Authorities used a persistent Windows Global Device ID, along with VPN telemetry and cloud service records, to connect the infrastructure used in a major extortion attack to a 19-year-old member of the Scattered Spider group, Peter Stokes. In a superseding criminal complaint filed in the Northern District of Illinois, the FBI outlines how Stokes, who…
-
Canadian spy agency reports hacking three criminal groups in 2025
A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada’s Communications Security Establishment. First seen on therecord.media Jump to article: therecord.media/canada-cse-2025-cyber-operations-ransomware-drugs-extremism
-
Vietnam arrests suspects behind HiAnime anime piracy service
Tags: serviceVietnamese authorities have arrested and are prosecuting seven suspects believed to have run HiAnime, the largest anime piracy streaming service before its shutdown in June. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/vietnam-arrests-suspects-behind-hianime-anime-piracy-service/

