Tag: tool
-
ATF cancels controversial commercial geolocation contract
Tags: toolThe agency told CyberScoop the tool was a pilot that didn’t meet their needs. Members of Congress say it was accessed for hundreds of active cases. First seen on cyberscoop.com Jump to article: cyberscoop.com/atf-cancels-penlink-ad-surveillance-contract/
-
Chinese APT CL1062 Expands Attacks on Southeast Asian Critical Infrastructure With Custom Malware
Chinese-speaking APT CL-STA-1062 targeted Southeast Asian government and energy networks open-source tools, and a new TinyRCT backdoor. Palo Alto Networks Unit 42 researchers published a detailed report on a Chinese-speaking threat actor, tracked as CL-STA-1062, that has been running persistent operations across East Asia since at least March 2022 and shifted focus to Southeast Asian…
-
23 Top Open Source Penetration Testing Tools in 2026
Review and compare 23 of the best open-source pen testing tools in 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/applications/open-source-penetration-testing-tools/
-
AWS unveils agent security, data access tools
The updates reflect Anthropic’s Mythos model and the speed at which vulnerabilities can be surfaced. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/aws-continuum-ai-security-claude-mythos/823393/
-
macOS Flaw Allowed Standard Users to Disable CrowdStrike and Kandji Security Tools
A macOS XPC flaw let regular users disable CrowdStrike and Kandji tools, exposing security gaps that vendors patched after XM Cyber reported the security issue. First seen on hackread.com Jump to article: hackread.com/macos-flaw-users-disable-crowdstrike-kandji-security-tools/
-
Activist Phone Hacked With Cellebrite After Russia Contract Cancellation
Russian authorities used Cellebrite tools to unlock an activist’s iPhone and analyze private data despite canceled support, raising abuse concerns. On May 31, 2021, Russian security services pulled opposition activist Andrey Pivovarov off a flight at St. Petersburg airport and confiscated his iPhone 12 and MacBook. He never consented to a search and never gave…
-
Russian Authorities Used Cellebrite UFED to Break Into Human Rights Activist’s iPhone
Russian authorities leveraged Cellebrite’s Universal Forensic Extraction Device (UFED) to gain access to a detained human rights activist’s iPhone, according to a detailed forensic investigation that raises fresh concerns over the use of commercial digital forensics tools in political repression. The findings as per reported by CitizenLabs, based on technical analysis and corroborated by official…
-
Russia Used Cellebrite on Jailed Activist’s iPhone Months After Sales Cutoff
Russian authorities used Cellebrite’s UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop selling its tools and services to Russia and Belarus.The finding, published June 25 by the Citizen Lab, rests on two things that rarely line up: traces…
-
Healthcare leaders see a fatal cyber incident as inevitable
Healthcare practices run on a chain of outside vendors. An EMR system holds clinical records, a billing platform processes claims, a telehealth tool supports remote visits, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/cyber-incident-healthcare-vendor-risk/
-
Interview mit Georgeta Toth Wer den Prozess weglässt, hat das Tool umsonst gekauft
Viele Unternehmen haben ihre Sicherheitsarchitektur mit Tools zugeschüttet und trotzdem keine Kontrolle. Georgeta Toth, Senior Regional Director Central Europe bei der Rapid7 Germany GmbH, erklärt, warum Security-Operations-Center-Projekte scheitern, wie KI die Angreiferseite verändert und weshalb NIS2 für IT-Verantwortliche ein Befreiungsschlag war. First seen on ap-verlag.de Jump to article: ap-verlag.de/interview-mit-georgeta-toth-wer-den-prozess-weglaesst-hat-das-tool-umsonst-gekauft/105574/
-
Feds Expand AI to Combat Healthcare Fraud
$6.5B Takedown Highlights AI’s Growing Role in Fraud Detection. A federal effort, bolstered with by data analytics and AI tools, helped bust $6.5 billion in false healthcare claims, U.S. government officials said this week. Moving forward, AI will play an even bigger role in identifying potential fraud before criminals can cash out, they promised. First…
-
Krypto-Clipper tarnt sich auf Software-Plattformen
Angreifer nutzen KI-Stimmen, Fake-Reviews und manipulierte Downloadzahlen, um eine Schadsoftware für Krypto-Diebstahl als sichere Tools zu tarnen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/krypto-clipper-software-plattformen
-
Russia used Cellebrite phone-hacking tool to crack down on dissident after firm cut off country
The continued use of the powerful data extraction product soon after the company in March 2021 said it would stop working with Russia suggests the firm has been unable to pull back its technology from authoritarian government customers, researchers say. First seen on therecord.media Jump to article: therecord.media/russia-used-cellebrite-tool-after-company-pulled-out-of-country
-
Cellebrite said it cut off Russia, but Russia used its tools anyway
Security researchers found evidence that Russian authorities hacked the iPhone of a political opponent using a phone-unlocking device made by Cellebrite, even after the company said it would stop selling to Putin’s government. First seen on techcrunch.com Jump to article: techcrunch.com/2026/06/25/cellebrite-said-it-cut-off-russia-but-russia-used-is-tools-anyway/
-
macOS attack technique bypasses endpoint security tools
First seen on scworld.com Jump to article: www.scworld.com/brief/macos-attack-technique-bypasses-endpoint-security-tools
-
AI is raising the cost of MSP tool sprawl
First seen on scworld.com Jump to article: www.scworld.com/native/msps-cant-run-ai-on-a-fragmented-tech-stack
-
SuperOps, Guardz target MSP tool sprawl with a unified AI-ready stack
First seen on scworld.com Jump to article: www.scworld.com/news/superops-guardz-target-msp-tool-sprawl-with-a-unified-ai-ready-stack
-
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst’s artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact.The malware has been codenamed Gaslight owing to this deceptive behavior. It’s been assessed with high…
-
Betrug mit KI-Videos: Neues Bitdefender-Tool soll Deepfakes entlarven
Deepfakes sind immer schwieriger zu erkennen. Mit Bitdefender Realcheck kommen Anwender Betrügern zuvor. Doch die Sache hat einen Haken. First seen on golem.de Jump to article: www.golem.de/news/betrug-mit-ki-videos-bitdefender-will-mit-realcheck-deepfakes-ueberfuehren-2606-210167.html
-
Check Point Becomes One of First Security Vendors to Embed OpenAI Frontier Models in Live Customer Defences
Check Point Software has announced it is embedding OpenAI’s frontier cyber capabilities directly into its customer-facing security products, becoming one of a select group of vendors accepted into OpenAI’s Daybreak Cyber Partner Programme. The move represents a significant escalation in the deployment of advanced AI in enterprise security, not as a back-end research tool but…
-
Algerian national accused of running cybercrime marketplaces extradited to US
An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/24/algerian-cybercrime-marketplace-operator-extradited-to-us/
-
macOS Backdoor Uses Prompt Injection to Evade AI Triage
SentinelLabs found a North Korea-linked macOS backdoor using prompt injection on AI triage tools First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/macos-gaslight-rust-backdoor/
-
Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords
JFrog warns of malicious npm packages that mimic PostCSS tooling, drop a Windows RAT, and target Chrome-stored passwords through a staged infection setup route. First seen on hackread.com Jump to article: hackread.com/fake-npm-packages-postcss-tool-steal-chrome-password/
-
In a first, a court takedown goes after two cybercrime tools at once
Microsoft, with law enforcement and industry partners, disrupted more than 200 command and control servers for Amadey and StealC, often used in conjunction. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-amadey-stealc-takedown/
-
Apple’s MacOS Gap Lets Users Disable Security Tools
Attackers can exploit the issue to disable security and integrated browser tools without needing administrator privileges or kernel exploits. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/apple-macos-security-gap-users-disable-security-tools
-
LastPass customer data exposed through Klue supply chain attack
LastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/24/lastpass-klue-data-breach-salesforce-environment/
-
Best Crypto Payment Solutions for E-Commerce Businesses
Compare crypto payment gateways for ecommerce, including checkout tools, stablecoin payments, fiat settlement, plugins, APIs and business payouts. First seen on hackread.com Jump to article: hackread.com/best-crypto-payment-solutions-e-commerce-businesses/
-
Praxen: Open-source AI agent behavior verification
Praxen is an open-source tool with a simple job: it checks whether an AI agent does what it claims to do. The tool takes an agent’s declared policy, looks at how the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/24/praxen-open-source-ai-agent-behavior-verification/
-
Coupang’s $409M Fine Shows the Real Cost of Weak AI Governance
Recent AI and data security actions show why AI governance now belongs with boards, not just IT teams managing tools and access. The post Coupang’s $409M Fine Shows the Real Cost of Weak AI Governance appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-coupang-fine-ai-governance-board-risk/

