Tag: threat
-
U.S. Agencies: AI-Based Attacks Threaten Water, Manufacturing, Other CI Sectors
CISA, the EPA, and other U.S. agencies are warning that unnamed threat groups are using AI to help breach Siemens S7 Series PLCs in attempts to attack critical infrastructure systems in such sectors as water, agriculture, manufacturing, and chemicals. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/u-s-agencies-ai-based-attacks-threaten-water-manufacturing-other-ci-sectors/
-
Hackers Use Fake CAPTCHA to Deploy Malware That Shuts Down Endpoint Security
Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact infection chain that begins with a victim manually executing a malicious PowerShell command. In late July 2026, multiple ClickFix campaigns generated through the ErrTraffic malware-as-a-service platform and used to deliver Cruciferra, a loader advertised…
-
Agentic AI Presents New Insider Threat Model for Orgs
Katie Moussouris of Luta Security talks with the Dark Reading News Desk about how enterprises will now need to monitor risks posed by their own agents in the wake of the recent Hugging Face attack. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/agentic-ai-new-insider-threat-model
-
40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed…
-
CISA warns of hackers exploiting critical MLflow vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-mlflow-vulnerability/
-
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View…
-
US agencies warn of AI-powered attacks on Siemens industrial controllers
Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/20/usa-ai-attacks-siemens-s7-plcs-critical-infrastructure/
-
Hackers Trick AI Agents Into Telling Users to Install the Malware Themselves
A supply-chain campaign targeting OpenClaw has shown how threat actors can turn autonomous AI agents into persuasive malware-delivery intermediaries. Rather than relying only on exploit code, attackers poisoned the ClawHub skill registry with seemingly legitimate extensions whose instructions prompted users to install fake prerequisite tools or paste obfuscated commands into a terminal. The campaign, tracked…
-
Security Analytics in NetFlow Analyzer: Spot Behavioral Threats Early Respond With Context
Your network is already being mapped. You just can’t see it yet. Modern attacks don’t make a sound. They don’t kick down the door. They find an unlocked window, slip through, and spend weeks quietly mapping your network before making a move. By the time your monitoring tool fires an alert, the attack is already..…
-
Hackers Impersonate Claude, ChatGPT and Copilot to Deliver Infostealers and Backdoors
Threat actors are increasingly abusing the popularity of generative AI brands to distribute malware, turning trusted names such as Claude, ChatGPT and Microsoft Copilot into convincing lures for infostealers, browser hijackers and remote-access backdoors. Sophos X-Ops reviewed 12 months of Managed Detection and Response (MDR) investigations, spanning July 2, 2025 to June 29, 2026. They…
-
T-Mobile Physically Cuts Network Cable to Evict Chinese Salt Typhoon Hackers
In 2024, T-Mobile’s security team took an unusually direct approach to contain a cybersecurity threat: they physically cut a network cable to terminate suspected access by the Chinese state-backed hackers known as Salt Typhoon. According to CSN, this action came after months of incident response efforts within T-Mobile’s network, during which defenders investigated signs of…
-
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. First seen on cyberscoop.com Jump to article: cyberscoop.com/hackers-use-ai-target-siemens-plcs-critical-infrastructure/
-
Bluesky Hit by Second Major DDoS Attack in Months
Bluesky suffered its second major DDoS attack in months, causing hours of disruption as a threat group claimed responsibility for the outage. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-bluesky-second-ddos-attack-outage/
-
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/
-
Quantum-Safe Isn’t Cyber-Safe
Tags: access, ai, api, breach, communications, compliance, computer, computing, credentials, cryptography, cyber, data, defense, encryption, exploit, flaw, google, group, ml, openai, password, radius, risk, threat, update<div cla In the same week federal agencies began scoping migrations under the White House’s new Post-Quantum Cryptography Executive Order, a group of academic researchers published a paper that, on its face, had nothing to do with quantum computing at all. It described a flaw in how three of the most security-conscious engineering organizations on…
-
Fake Crypto Exec Used Booby-Trapped Google Doc to Target Security Researcher After DEF CON
A threat actor impersonating a senior executive at a well-known cryptocurrency media outlet attempted to infect a Huntress researcher with malware in the days following this year’s Black Hat and DEF CON conferences, according to new research from the security vendor. The campaign began on X (formerly Twitter), where an account impersonating the executive sent…
-
Education Now the World’s Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School
Education has overtaken every other industry to become the most targeted sector for cyberattacks worldwide, according to new research from Check Point, with threat actors ramping up activity in the run-up to the new academic year. Between January and July 2026, schools, colleges, universities and research institutes faced an average of 4,696 weekly cyberattacks per…
-
Wie das ‘Bulletproof”-Kit Secure-EGateways und Multi-Factor-Authentification umgehen kann
Die Sicherheitsforscher des KnowBe4 Threat Labs haben eine aktive Phishing-Infrastruktur untersucht, die gezielt eine Schwachstelle klassischer E-Mail-Sicherheitsmechanismen ausnutzt. Das von den Angreifern selbst als ‘Bulletproof” bezeichnete Redirector-Kit versteckt die eigentliche Phishing-Infrastruktur hinter kompromittierten, legitimen Websites. Dadurch können schädliche Links Secure-E-Mail-Gateways (SEGs) und klassische URL-Reputationsprüfungen umgehen. Das Umgehen von SEGs ist jedoch nur ein sekundärer Vorteil.…
-
China-Nexus Hackers Target Myanmar Diplomats With QUICAgent Go Backdoor via Malicious VHD Files
A China-nexus threat actor is targeting Myanmar government and diplomatic personnel with a multi-stage malware campaign that delivers a custom Go-based backdoor, dubbed QUICAgent, through Virtual Hard Disk (VHD) files disguised as benign images. The campaign relies on highly targeted social engineering. One malicious file, named TrainingAnnouncement.jpg, is not an image but a VHD container.…
-
Balonx PhaaS Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-harvesting kit. It operates as a subscription-based criminal service that rents access to affiliates, lowering the barrier for telemarketing fraud groups and inexperienced…
-
Google Mandiant AI Agents Find Over 100 Critical Vulnerabilities in Source Code Within Two Days
Tags: ai, breach, corporate, cyber, google, group, incident response, intelligence, mandiant, penetration-testing, RedTeam, threat, vulnerabilityGoogle’s Threat Intelligence Group has announced that its Agentic Vulnerability Discovery Harness (AVDH) identified over 100 critical true-positive vulnerabilities in stolen corporate source code repositories within just two days. This result highlights how agentic AI can significantly accelerate vulnerability discovery during incident response, red teaming, penetration testing, and proactive secure code reviews, especially when adversaries…
-
Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments…

