Tag: usa
-
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, September 22nd, 2026, CyberNewswire Aembit, the identity and access management (IAM) company for AI agents, today announced support for Cross App Access (XAA), an open protocol introduced by Okta that lets a user’s existing enterprise identity authorize access to downstream applications without a separate consent step for each connection. Launching this…
-
Stolen passwords are exposing America’s water providers to hackers
Researchers say another looming threat hangs over some of America’s most important critical infrastructure. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/22/stolen-passwords-are-exposing-americas-water-providers-to-hackers/
-
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, 22nd September 2026, CyberNewswire First seen on hackread.com Jump to article: hackread.com/aembit-launches-support-for-okta-cross-app-access-extending-enterprise-identity-controls-to-ai-agents/
-
China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America
FamousSparrow is targeting Latin American governments with SparroWocky, a new C++ backdoor that exfiltrates files, takes screenshots and evades security tools. First seen on hackread.com Jump to article: hackread.com/china-famoussparrow-sparrowocky-backdoor-latin-america/
-
Black Hat USA 2026: Machine Speed, Human Consequence
ISMG Pulse Report Covers AI Attack Surface, Vulnerability Management and Identity. ISMG’s Pulse Report: Machine Speed, Human Consequence includes six chapters examining the agentic attack surface, vulnerability management, identity and authority, adversary operations, governance and liability, and the changing role of cybersecurity professionals. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/black-hat-usa-2026-machine-speed-human-consequence-a-32877
-
ISMG Editors: Even Valid Email Addresses Can’t Be Trusted
Also: States Inherit America’s Cyber Burden, AI Agents Reshape the MSSP Market. In this week’s panel, four ISMG editors discuss an unusual breach at U.K. digital banking platform Revolut, the growing role of U.S. state governments in protecting local critical infrastructure and what a new cybersecurity acquisition tells us about the AI-powered SOC. First seen…
-
Swedish teenager jailed for attempted murder, rape and assault committed online, with victims in Germany and Australia
Eighteen-year-old known as Chai was active in networks notorious for their sadistic exploitation of young peopleA Swedish teenager known as Chai has been sentenced to more than 10 years in jail for attempted murder, rape and aggravated assault crimes committed via the internet, <a href=”https://www.theguardian.com/technology/ng-interactive/2026/jul/21/764-network-gamification-of-harm-the-com-cybercrime-ntwnfb”>including against a teenage girl in Australia.The district court found that…
-
China’s FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China’s fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-spies-latin-america
-
China’s FamousSparrow hackers target Latin America with new backdoor
Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.” First seen on therecord.media Jump to article: therecord.media/china-hackers-latin-america-espionage
-
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025.”SparroWocky is a modular, C++ backdoor,” ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News…
-
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
Ports, railroads, and utilities keep the military operational. They’re all vulnerable to Iranian cyberattacks. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/
-
Black Hat USA 2026 | OpenAI’s Deep Dive Into Hugging Face Incident
At Black Hat USA, OpenAI engineers reconstruct the Hugging Face incident and explore lessons learned about AI safeguards and cyber resilience. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/bhusa26huggingfacetalk
-
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity.From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud First…
-
Black Hat USA 2026 | The ‘Breaking’ News: The OpenAIHugging Face Incident
The ‘Breaking’ News: The OpenAIHugging Face Incident – A Technical Reconstruction and Its Implications for AI First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/bhusa26huggingfacetalk
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
N0va Phishkit Targets North America and Europe Through Microsoft Logins
The N0va phishkit abuses Microsoft device-code authentication to obtain tokens even after users complete MFA. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-n0va-device-code-phishing-emea/
-
Hackers Use LLMs to Generate Exploit Scripts and Automate Post-Exploitation Across Latin America
Threat actors targeting organizations across Latin America are increasingly embedding commercial large language models (LLMs) into intrusion workflows, using AI-assisted scripting, troubleshooting, and proxy deployment to accelerate post-exploitation and data theft. The campaigns show that AI is no longer limited to phishing, content generation, or reconnaissance. Instead, attackers appear to be using LLMs as an…
-
Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests
Boston, MA, USA, September 8th, 2026, CyberNewswire Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation. Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across…
-
Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests
Boston, MA, USA, 8th September 2026, CyberNewswire First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/reflectiz-launches-agentic-pentesting-for-websites-up-to-10x-coverage-vs-conventional-pentests/
-
Why Stopping Upstream Scams Before Money Moves Is a Cybersecurity Problem
Financial institutions are realizing how upstream impersonation scams lead directly to downstream fraud. And potential lawsuits. New York Attorney General Letitia James sued Citibank and the company behind Zelle for failing to protect and reimburse consumers from impersonation-driven fraud last year. 86-year-old Nina Mortellito sued Bank of America and Merrill Lynch after losing $700,000 to..…
-
Keeper Security Names Jessica Krowel and Bill Grabner to Lead North America Private and Public Sector Sales
Keeper Security, the leading zero-trust and zero-knowledge identity security platform, today announces the appointment of Jessica Krowel as Senior Vice President of North America Sales, Private Sector, and Bill Grabner as Senior Vice President, Public Sector. Both will support Tim… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/keeper-security-names-jessica-krowel-and-bill-grabner-to-lead-north-america-private-and-public-sector-sales/
-
Black Hat Compendium 2026: AI Risks Get Real
ISMG Report Showcases Interviews on AI Threats, Defenses and Emerging Solutions. Welcome to ISMG’s Black Hat USA 2026 Compendium featuring the latest insights from the industry’s top cybersecurity researchers and defenders, as well as perspectives from CEOs, CISOs and government officials on the latest trends in cybersecurity and AI. First seen on govinfosecurity.com Jump to…
-
PassPasskey Bypasses MFA Without Breaking FIDO2
I have spent years arguing that passkeys are the right answer to phishing. The cryptography behind that argument is still sound. Research presented at Black Hat USA 2026 does not change it. What it changes is the assumption that deploying… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/pass-the-passkey-bypasses-mfa-without-breaking-fido2/
-
Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud
Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/anthropic-enterprise-frontier-safeguards/
-
The AI Kill Switch Act is repeating the Clipper Chip’s mistakes
Mandating ‘kill switches’ for AI agents would threaten the security of America’s critical infrastructure and undercut U.S. AI leadership. Congress must reject the AI Kill Switch Act. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-kill-switch-act-clipper-chip-mistakes-op-ed/
-
Could a Pattern on Your Clothing Fool Facial Recognition? Interview with Bill Swearingen
Can a pattern on your clothing change what a camera thinks it sees? Tom talks with Black Hat USA 2026 speaker Bill Swearingen about adversarial clothing research, why person detection and facial recognition are different problems, and what model limitations mean for biometric surveillance, privacy, and accountability. ** Links mentioned on the show ** Black……
-
Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
This installment of the Reporters’ Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI’s effects on vulnerability reporting and security research. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/agentic-ai-risks-cve-program-concerns-black-hat-usa-2026
-
AccuKnox Launches AgentZ to Help Enterprises Build, Run, and Govern AI Agents at Scale
Menlo Park, California, USA, August 27th, 2026, CyberNewswire AccuKnox today announced the launch of AgentZ, a platform for building, running, and governing AI agents across teams and workflows. AgentZ brings the agent, its execution environment, tools, workflows, permissions, and governance into a single platform, so organizations can move agents from experiment to production without assembling…

