Tag: threat
-
U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Zimbra Collaboration Suite (ZCS) flaw CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors…
-
Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks
A Chinese-speaking threat actor has been observed using DeepSeek through the Hermes Agent framework to automate reconnaissance, vulnerability research, exploit acquisition, and attack attempts against internet-facing infrastructure. According to Unit 42, the actor tracked under the aliases knaithe and KnYuan built an AI-assisted offensive environment that combined DeepSeek’s reasoning capabilities with Hermes Agent’s terminal access,…
-
Rethinking Threat Intelligence: New Tactics for the Age of AI
Joe Hladik, head of Rubrik Zero Labs, sat down with the CEO and founder of the Techstrong Group, Alan Shimel, at Black Hat 2026 to talk about how Zero Labs is taking novel approaches to threat intelligence. One emerging source of threat intelligence, Hladik said, has historically been overlooked in threat detection: backup data. “When..…
-
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.”The malware spread through the…
-
What we know so far about the hacking campaign against US water systems
Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/what-we-know-so-far-about-the-hacking-campaign-against-us-water-systems/828374/
-
The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw
Tags: ai, breach, cyber, cybersecurity, data, data-breach, exploit, flaw, gitlab, government, risk, software, threat, vulnerabilityThis weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-tax-breach-ai-gitlab-flaw/
-
The Cyber Express Weekly Roundup: Tax Data Breach, AI Security Risks, and Critical GitLab Flaw
Tags: ai, breach, cyber, cybersecurity, data, data-breach, exploit, flaw, gitlab, government, risk, software, threat, vulnerabilityThis weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach to a critical GitLab vulnerability, recent incidents demonstrate how attackers continue to exploit sensitive data, digital systems, and emerging technologies. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/weekly-roundup-tax-breach-ai-gitlab-flaw/
-
Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Tags: access, authentication, conference, cyber, defense, espionage, google, group, intelligence, phishing, russia, tactics, threat, toolGoogle tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead. Threat actors target researchers,…
-
Hackers abuse FTP server banners to deliver new Windows malware
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/
-
Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw
CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a critical vulnerability in Zimbra Collaboration Suite tracked as CVE-2026-73570. The flaw allows unauthenticated remote code execution and was…
-
Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing
Quarkslab has argued that LLM-assisted reverse engineering does not make obfuscation obsolete, but it changes the defender’s threat model. Its latest experiment found that autonomous coding agents routinely avoid difficult deobfuscation, pivot to dynamic analysis, and often stop once they obtain an answer that appears credible even if it is wrong. The research firm tested…
-
Hackers Use Fake Google Gemini Installer to Deploy Vidar Stealer and Steal Browser Credentials
Threat actors are exploiting interest in generative AI software to distribute the Vidar information stealer through a fake Google Gemini installer hosted via Google Colab. Darktrace investigated the July 2026 intrusion in an EMEA customer environment, where a user downloaded and executed a malicious file named Download_Google_Gemini_For_Windows.exe The campaign did not rely on a conventional…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Feynman Bet: Why You Still Won’t Vibe Code Your SIEM (Today)
Gemini about this blog The Feynman Betting Strategy and the Inertia of Security Many years ago, I read a book by the legendary quantum physicist Richard Feynman. One story from his time at Los Alamos during the war has always stuck with me. Feynman entertained himself by making bets with his colleagues about various wartime events in Europe.…
-
The Elephants in the Technology Room – Part 5
Why Enterprise’s Fastest-Growing Risk Has No Owner, No Identity and No Audit Trail As autonomous AI agents move into production, organizations face a new insider threat they were never built to govern. Shared credentials, weak oversight and limited audit trails leave agents without clear identities or accountability, creating security blind spots that can quickly become…
-
Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S.These clusters include UNC6293, UNC7005, and UNC5976.”These clusters engage in persistent, adaptive First seen on…
-
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline
Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development…
-
Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist
Tags: threatKyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. First seen on cyberscoop.com Jump to article: cyberscoop.com/764-member-sentenced-longest-prison-sentence-kyle-spitze/
-
Essential Cybersecurity Audits for Regulated Industries by Continuum GRC
In 2026, organizations operating in regulated industries face an increasingly complex web of cybersecurity audits driven by evolving threats and stricter enforcement of frameworks like CMMC 2.0 and NIST SP 800-171 Rev 3. Cybersecurity audits have become essential not merely for checkbox compliance but for establishing robust governance that protects sensitive data and maintains operational”¦…
-
Pakistan’s Transparent Tribe Refreshes Toolset for Afghan Cyberattacks
A nation-state threat actor is picking on immature organizations run by the Taliban, but failing against more prepared government agencies in India. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/pakistan-transparent-tribe-afghan-cyberattacks

