Tag: tool
-
SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia.The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, GoginRAT, and NodeEdgeRAT. SilkParasite, first discovered in late 2025, is assessed to be a First seen…
-
Reverse-Lookup Service Exposed Millions of Photos of People’s Faces
The people-search tool ClarityCheck says its reverse image search service is “private and secure””, but it left a database containing more than 9 million image files exposed. First seen on wired.com Jump to article: www.wired.com/story/reverse-lookup-service-exposed-millions-of-photos-of-peoples-faces/
-
Flock Has a Powerful New AI Tool for Police. We Got Its Code
Flock’s surveillance cameras have already sparked outrage. WIRED reconstructed its next-generation AI system, already in use by some police, to confirm it goes much further than tracking license plates. First seen on wired.com Jump to article: www.wired.com/story/flock-safety-os-investigate/
-
Google’s AI security agents found 100+ critical software vulnerabilities in just two days
Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/19/google-mandiant-avdh-ai-vulnerability-discovery-tool/
-
RAVEN Tool Steals Entire Elasticsearch Databases and Rebuilds Deleted Backdoors
The RAVEN offensive framework can turn compromised Elasticsearch and Kibana environments into durable data-theft and persistence operations. RAVEN, short for Reconnaissance & Attack on Vulnerable Elasticsearch Nodes, is an open-source modular framework built to assess Elasticsearch and Kibana security posture across reconnaissance, exploitation, exfiltration, persistence, and cleanup workflows. Its latest walkthrough focuses on post-exploitation against…
-
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single…
-
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single…
-
Perplexity Builds Guardrails to Rein in Rogue AI Agents
Open-Source Numbat Blocks Agent Actions That Violate Enterprise Security Policies. Perplexity designed its open-source tool Numbat tool to detect and block AI agents from stepping outside enterprise safety policies. The tool sits between when the agent starts to think about doing something and when it takes action, so it will stop agents from going rogue.…
-
BSidesSF 2026 From Auditions To Opening Night: Selecting Security Tools That Hits The High Notes
Tags: toolPresenter: Saurabh Sharma Our thanks to Security BSides San Francisco for publishing their Creators, Authors and Presenter’s outstanding BSidesSF 2026 content on the Organizations’ YouTube Channel. Permalink First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/bsidessf-2026-from-auditions-to-opening-night-selecting-security-tools-that-hits-the-high-notes/
-
Taiwan Reports AI-Agent Cyberattacks on Government Networks
Taiwan says AI agents helped target government systems, highlighting how autonomous tools could accelerate cyberattacks and challenge defenders. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-ai-assisted-government-cyberattacks-apac-taiwan/
-
Cybercriminals Turn to Indirect Prompt Injection Attacks
Cybercriminals are developing indirect prompt injection tools to target AI agents. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cybercriminals-turn-to-indirect-prompt-injection-attacks/
-
Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity
Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully functioning document converters, meal planners, recipe tools, and PDF utilities. The applications deliver their advertised features, but their shared codebase also enables runtime JavaScript execution and access to desktop-capture functionality creating a serious surveillance and post-compromise risk. Search-optimized…
-
Proton launches free tool to show enterprises what ChatGPT and Claude know about employees
Privacy-focused tech company Proton has launched a free tool designed to show users exactly what large language models such as ChatGPT and Claude have learned about them from months or years of conversation history, a capability that speaks directly to the shadow AI problem now facing enterprise security teams. The tool, called AI Paper Trail,…
-
Securing Model Context Protocol (MCP) tool integrations
Model Context Protocol, or MCP, is becoming a practical way to connect large language models to internal tools, data sources, and workflows. For security teams, that changes the control problem. A chat-only assistant can still leak information or be manipulated, but an MCP-enabled assistant can also trigger actions in business systems, query sensitive data, and……
-
Securing Model Context Protocol (MCP) tool integrations
Model Context Protocol, or MCP, is becoming a practical way to connect large language models to internal tools, data sources, and workflows. For security teams, that changes the control problem. A chat-only assistant can still leak information or be manipulated, but an MCP-enabled assistant can also trigger actions in business systems, query sensitive data, and……
-
Microsoft starts removing WMIC tool used by cybercriminals
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/
-
Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX, a cryptocurrency fraud campaign that combined account enumeration, branded phishing, targeted voice calls, and trojanized wallet software to capture victims’ recovery phrases. The campaign’s exposed operational server also revealed an unusually detailed view of how the operator incorporated AI coding tools into active fraud development. Named after the Asterisk telephony platform found on…
-
Hackers Turn Claude Code and Codex Into AI-Powered Tools for Credential Theft and Cloud Attacks
Threat actors are increasingly using coding assistants as operational tools. Detailed research from Gambit Security highlights three campaigns where Claude Code, OpenAI Codex, and large language models facilitated activities ranging from ransomware preparation to the harvesting of secrets on a large scale and exploiting cloud accounts. These cases demonstrate how AI can speed up attackers’…

