Tag: threat
-
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
-
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January”¯2025.These targeted organizations operate across several sectors, such as healthcare, research, government offices, First seen on thehackernews.com Jump to article:…
-
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/
-
ISMG Editors: A New Front in the Naming War
Also: The AI Spending Reality Check, Nvidia Takes on Closed AI. In this week’s panel, four ISMG editors discussed Google’s controversial new threat actor naming system and the need for standardization, whether the artificial intelligence boom is built on solid economic foundations, and the growing battle between open and closed AI models. First seen on…
-
Amazon pins multiple open source compromises on North Korea
Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 incident affecting the axios NPM library First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646561/Amazon-pins-multiple-open-source-compromises-on-North-Korea
-
ESET tracks rise in malicious AI skills and adaptable malware
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET’s new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/eset-tracks-rise-in-malicious-ai-skills-and-adaptable-malware/
-
Sprachbasierte Bedrohungen mit fortschrittlicher Vishing-Simulation bekämpfen
KnowBe4 hat seine neue Vishing-Simulationsfähigkeit angekündigt, die Unternehmen dabei helfen soll, die mittlerweile am schnellsten wachsende Lücke im Sicherheitsbewusstsein zu schließen: die Kommunikation über das Telefon. Vishing hat sich von einer Nischentaktik zu einem gängigen Angriffsvektor entwickelt. Der Global-Threat-Report 2025von Crowdstrike verzeichnete zwischen der ersten und zweiten Jahreshälfte 2024 einen Anstieg der Vishing-Aktivitäten um 442…
-
XRP Volatility Surges as Cybersecurity Threats and Market Changes Raise New Concerns
XRP volatility drives faster crypto trading as AI tools gain traction, while phishing, exchange attacks and automation risks test digital asset safeguards. First seen on hackread.com Jump to article: hackread.com/xrp-volatility-cybersecurity-threats-market-changes/
-
What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery
An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted security review that cost roughly USD 3,140 in API calls. The review identified 29…
-
The Cyber Express Weekly Roundup: AI Fraud, Data Leaks, Malware Campaigns, and Critical Infrastructure Threats
Tags: ai, cyber, cyberattack, data, exploit, finance, fraud, government, infrastructure, intelligence, leak, malicious, malware, software, threatThis weekly roundup highlights the growing complexity of digital threats affecting governments, businesses, developers, and consumers. From artificial intelligence being misused for financial fraud to large-scale customer data exposures, malicious software targeting developer ecosystems, and cyberattacks against critical infrastructure, recent incidents demonstrate how attackers are exploiting both emerging technologies and existing security weaknesses. First seen…
-
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing – the abuse of the OAuth 2.0 device authorization grant to steal access tokens – has evolved from a niche red-team technique to an industrial-scale threat in under six months.Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range…
-
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Palo Alto Networks’ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session.The operator, tracked through the aliases knaithe and KnYuan, First seen…
-
BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations
BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operations against Japanese organizations, signaling ongoing toolchain evolution and focused targeting of enterprise Linux environments. Originally published on GitHub with Chinese-language documentation, BlueShell has seen limited but consistent abuse by China-based threat actors, including…
-
Chinese-Speaking Hacker Uses DeepSeek Agent to Launch Autonomous Cyberattacks
Chinese-speaking threat actor “knaithe” (aka KnYuan) has been caught running an AI-enabled autonomous attack stack built around DeepSeek and the Hermes Agent framework, proving that large language models can now drive end”‘to”‘end offensive operations with minimal human oversight. Hermes provided terminal access, skills orchestration, and Model Context Protocol (MCP) integrations. At the same time, DeepSeek…
-
CISA Urges Water Utilities to Remove Publicly Exposed PLCs From the Internet
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert to the Water and Wastewater Systems (WWS) Sector due to a significant rise in cyber threat activity targeting internet-exposed programmable logic controllers (PLCs). Released on July 30, 2026, the advisory urges critical infrastructure owners, operators, and system integrators to immediately identify and…
-
OctLurk and SilkLurk Backdoors Target Central Asian Governments in Cyberespionage Campaign
OctLurk and SilkLurk are highly customized, memory”‘resident backdoors used in an ongoing cyberespionage campaign against government and critical”‘sector networks across Central Asia and Syria, operated by a Chinese”‘speaking threat actor but not yet linked to a known APT. Active since January 2025, the operation leverages victim”‘specific loaders, multi”‘plugin frameworks, and shared infrastructure, along with Linux”‘focused…
-
The Recovery Illusion
When a cyber threat hits the headlines, the instinct is always the same. Organizations like to spend more, add another tool, and tighten the audit schedule so the box stays checked. But when ransomware hits a company that did all of that, the result usually still looks like chaos. Teams scramble and find out the..…
-
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
AiTM phishing is now the top entry point into law firms, with identity behind 56% of threats First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aitm-phishing-top-entry-point-law/
-
Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure. First seen on darkreading.com Jump to article: www.darkreading.com/ics-ot-security/minnesota-water-utility-attacks-expose-sector-cyber-risks
-
Okta’s deal for Permiso aims to close gaps in identity threat detection
Ely Kahn, Okta’s chief product officer, told CyberScoop the deal enriches the company’s current threat detection tools and gives it deeper visibility into AI agent activity across enterprise systems. First seen on cyberscoop.com Jump to article: cyberscoop.com/okta-acquires-permiso-security-ai-identity-threat-detection/
-
Okta buys AI security startup Permiso, source says for about $200M
The deal gives Okta identity threat detection capabilities as enterprises seek to secure AI agents and other non-human identities across cloud environments. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/30/okta-buys-ai-security-startup-permiso-source-says-for-about-200m/
-
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.The defining aspect of the attack is that bogus macOS software…
-
Authorities investigating a coordinated cyberattack against Minnesota water systems
The two-day attack comes days after federal officials warned of state-linked threat groups targeting a wider set of industrial devices. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/authorities-investigating-a-coordinated-cyberattack-against-minnesota-water/826427/
-
FastJson RCE Zero-Day Actively Targets Organizations
Threat actors are actively exploiting the FastJson CVE-2026-16723 zero-day, with no patch available for affected FastJson 1.x versions. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/fastjson-rce-zero-day-actively-targets-organizations/
-
‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates
-
Companies fear AI risks more than common cybersecurity threats
That misprioritization could blind companies to the threats they should be focusing on, Arctic Wolf said in a new report. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-cybersecurity-threats-business-fears/826352/
-
AI-assisted security tools are finding more bugs, but the threat level has not changed
Analysis from vulnerability intelligence firm VulnCheck shows AI-discovered flaws aren’t being exploited any faster than traditional ones. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-assisted-security-tools-are-finding-more-bugs-but-the-threat-level-has-not-changed/
-
Tanaka Dominates Data Leak Landscape With 25 Leak Posts
Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble. First seen…
-
Dismantled Kratos Phishing Kit Becomes Blueprint for Attacks on Microsoft 365 Users
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ongoing campaigns targeting Microsoft 365 environments. Despite being disrupted under Operation Olympus Blade, which led to the seizure of…

