L'Actu de la presse spécialisée
Is Cyber Facing an Affordability Crisis?
As breach costs reach record highs and defense spending nears 0 billion, small businesses are dangerously exposed, threatening supply chain security.
https://www.darkreading.com/cybersecurity-operations/is-cyber-facing-an-affordability-crisis-
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hospital operator Nutex Health says data stolen in cyberattack
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
https://www.bleepingcomputer.com/news/security/hospital-operator-nutex-health-says-data-stolen-in-cyberattack/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route for malware delivery. The campaign relies on impersonation rather than a software flaw, placing the decision to install a supposed fix directly in front of an employee. Attackers contact targets through Teams messages and voice phishing, also called vishing, while […]
The post SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams appeared first on Cyber Security News.
https://cybersecuritynews.com/synkloader-mimic-as-it-support/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real attack operations. Instead of using a model only to write text, the malware feeds system and botnet data into an AI service, then turns selected replies into proposed commands. That design gives operators a faster way to judge what to […]
The post ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions appeared first on Cyber Security News.
https://cybersecuritynews.com/toxnetv2-linux-botnet/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into the messaging app, marking one of the largest passwordless authentication rollouts in consumer tech history. Alongside this milestone, Meta’s flagship messaging platform is rolling out a major upgrade to two-step verification, replacing the long-standing six-digit PIN with a full alphanumeric […]
The post WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords appeared first on Cyber Security News.
https://cybersecuritynews.com/whatsapp-passkeys-reach-1-billion/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside the company, detected on July 28 and confirmed the next day. In a breach notification dated August 21, 2026, ASOS said it identified unusual activity involving customer accounts and launched an investigation immediately. The retailer determined that an unauthorized third […]
The post ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials appeared first on Cyber Security News.
https://cybersecuritynews.com/asos-warns-customer-accounts-were-accessed/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records
A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85 employee accounts, and stole more than 2,500 personnel records, according to research from Dream. The campaign demonstrates how coordinated AI agents can now execute large parts of an intrusion operation at machine speed. Dream researchers uncovered a 160 MB archive […]
The post Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records appeared first on Cyber Security News.
https://cybersecuritynews.com/eight-ai-agents-breach-government-systems/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access
A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing the antivirus software protecting their computers. The pages claim to inspect a device, report serious security failures, and insist that third-party antivirus products are no longer supported by Windows. The message is false, but it is designed to feel urgent […]
The post Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access appeared first on Cyber Security News.
https://cybersecuritynews.com/fake-microsoft-security-scan/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting
AliExpress’s homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears to power an aggressive device-fingerprinting system while producing an unexpected real-world side effect: interfering with Bluetooth multipoint audio switching on connected headphones. Security researcher Laserphile, using multipoint Bluetooth headphones that stay simultaneously paired to a PC and a phone, noticed […]
The post AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting appeared first on Cyber Security News.
https://cybersecuritynews.com/aliexpress-webaudio-device-fingerprinting/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.
The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident
https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Tata's B2B Platform Flaw Enables Account Takeover Just by Knowing Victim's Phone Number
A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium businesses in India, allowed attackers to take over accounts by knowing only a registered mobile number. The platform reportedly exposed the one-time password used for login within a decryptable API response, removing the need to intercept SMS messages, phish users, […]
The post Tata's B2B Platform Flaw Enables Account Takeover Just by Knowing Victim's Phone Number appeared first on Cyber Security News.
https://cybersecuritynews.com/tatas-b2b-platform-vulnerability/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
From Fake Workers to Account Recovery: The Growing Identity Verification Risk
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access. [...]
https://www.bleepingcomputer.com/news/security/from-fake-workers-to-account-recovery-the-growing-identity-verification-risk/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Microsoft PowerToys adds Alt+Tab-style switching for an app's windows
Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-powertoys-adds-alt-plustab-style-switching-for-an-apps-windows/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands
ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into proposed operational actions. The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 model output to controller-side functions including local shell execution, file writes, remote SSH commands, persistent state changes, and cross-compilation. Analysis published by Joe Reverser […]
The post AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/toxnetv2-linux-botnet/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ARTAXERXES
Advanced Multi-Technology Stress Testing Framework
Educational Cybersecurity Tool for High-Performance Network Testing
https://kitploit.com/en/tools/gitlab/toxy4ny/artaxerxes
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method.
The tech giant said more than 1 billion people use a passkey to log into WhatsApp. Support for passkeys was first introduced in Android in October 2023,
https://thehackernews.com/2026/08/whatsapp-adds-multiple-passkeys-for.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer
ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is delivered through fake verification pages, software downloads, and malicious game installers before pulling in malware. The activity makes victim part of the execution chain. A fake CAPTCHA may tell someone to copy and run a command, while an installer can […]
The post ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer appeared first on Cyber Security News.
https://cybersecuritynews.com/clickfix-campaigns-pavinloader/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Microsoft August 2026 Update Breaks When Generating PDF/XPS Content
Microsoft has confirmed that its August 2026 .NET Framework cumulative updates are causing printing failures and PDF/XPS generation errors in Windows Presentation Foundation (WPF) applications, creating fresh headaches for enterprises just days after patching a batch of security flaws. The issue stems from the August 2026 updates released on August 11, 2026, including KB5120710 for […]
The post Microsoft August 2026 Update Breaks When Generating PDF/XPS Content appeared first on Cyber Security News.
https://cybersecuritynews.com/microsoft-august-2026-update-pdf-xps/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Security Poverty Line: Fireside Chat At Black Hat USA 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 25, 2026 – Watch the Video In 2011, when Wendy Nather was at 451 Research, she coined the term Security Poverty Line, the line below which an organization cannot be effectively secured. The arrival
The post The Security Poverty Line: Fireside Chat At Black Hat USA 2026 appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/the-security-poverty-line-fireside-chat-at-black-hat-usa-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Enterprise NAC Migration Done Right: Zero-Trust Principles For Large-Scale Platform Cutover
The Migration Nobody Plans For — Until It’s Too Late Most enterprise security teams treat Network Access Control as infrastructure — stable, durable, unglamorous. Honestly, it's the kind of system...
The post Enterprise NAC Migration Done Right: Zero-Trust Principles For Large-Scale Platform Cutover appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/enterprise-nac-migration-done-right-zero-trust-principles-for-large-scale-platform-cutover/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
WhatsApp adds stronger two-step verification, multiple passkeys
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]
https://www.bleepingcomputer.com/news/security/whatsapp-adds-stronger-two-step-verification-multiple-passkeys/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
SecOPD
Research implementation for mitigating adaptive prompt injections via on-policy distillation, with training recipes and evaluators for SEP, PISmith, and AgentDojo benchmarks.
https://kitploit.com/en/tools/github/pppyb/secopd
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records
A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities in Asia, stealing thousands of personnel records, cracking employee credentials, and establishing persistent access to state infrastructure, according to Dream Research Labs. Researchers discovered a 160 MB operational archive containing 1,395 files generated over about 4 days of activity, from […]
The post Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/multi-agent-ai-framework-compromises-government-systems/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record.
The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode.
The vulnerability, tracked
https://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hackers breached over 270 Zimbra servers in ongoing attacks
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]
https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zimbra-servers-in-ongoing-attacks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Check Point Threat Brief: Critical Infrastructure Breaches and Emerging AI Attack Surfaces
Widespread Infrastructure Breaches and Novel AI Threats Several significant security breaches and new exploitation patterns are highlighted in the Check Point Research threat bulletin, which was released on August 24,...
The post Check Point Threat Brief: Critical Infrastructure Breaches and Emerging AI Attack Surfaces appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/check-point-threat-brief-critical-infrastructure-breaches-and-emerging-ai-attack-surfaces/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud
A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products, disclosing personal and banking information, and granting remote access to their computers. The sites, branded as SysScan, claim to assess whether an antivirus product is functioning properly. Their conclusion is predetermined: the victim's computer is allegedly […]
The post Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/scammers-impersonate-microsoft-to-push-fake-security-scans-and-refund-fraud/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.
According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.
Mirage2FA Campaign
https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages.
"While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor's use of npm isn't to infect developers who install it, but to use the
https://thehackernews.com/2026/08/24-npm-packages-abuse-unpkg-mirrors-to.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
key-transparency-auditor v20260818.0.0
Continuously fetches and cryptographically verifies key transparency log updates, maintains a condensed prefix and log tree view, and returns signed tree heads when updates are valid.
https://kitploit.com/en/posts/github-signalapp-key-transparency-auditor-2026081800
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Grok fooled into stealing user chat, location data, and more
Researchers found that prompt injection attacks can hide malicious instructions in encrypted text to get them past AI guardrails.
https://www.malwarebytes.com/blog/ai/2026/08/encrypted-instructions-can-fool-ai-assistants-like-grok-and-gemini
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.
While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development
https://thehackernews.com/2026/08/e4del-and-pinhole-rats-turn-ftp-banners.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers
ASOS has started notifying affected customers in the U.S. after detecting unauthorized access to accounts linked to login credentials obtained from outside its systems. According to a breach notification issued by ASOS US Sales LLC, unusual activity was detected in certain ASOS accounts on July 28, 2026. An investigation conducted the following day revealed that […]
The post ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/asos-warns-customers-of-data-breach/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
SliverMirage
Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants
https://kitploit.com/en/tools/github/daniomass/slivermirage
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Frontier AI: Vulnerability Management's Systemic Revolution
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationship required thoughtful care and feeding from both sides, both sides were aiming to work toward a
https://thehackernews.com/2026/08/frontier-ai-vulnerability-managements.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Multiple Zscaler Client Connector Flaws Enable Remote Code Execution
Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to execute arbitrary code within the product's context. This vulnerability, tracked as CVE-2026-59568, is rated as Critical, with a CVSS v3.1 score of 9.1. The attack vector is network-accessible and requires no privileges or user interaction. Multiple […]
The post Multiple Zscaler Client Connector Flaws Enable Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/multiple-zscaler-client-connector-flaws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Police arrests dozens of suspects in global cybercrime crackdown
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. [...]
https://www.bleepingcomputer.com/news/security/police-arrests-dozens-of-suspects-in-global-cybercrime-crackdown/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply chain remediation event that Sonatype estimates impacts 209,569 software components. The advisory issued on August 20 highlights the widening gap between AI-accelerated vulnerability discovery and organizations’ ability to identify, fix, rebuild, and deploy affected software. […]
The post 91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/91-spring-cves-impact-over-209000-software-components/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
GTA 6 leak hunt could expose data belonging to thousands of Discord users
Take-Two is demanding IP addresses, phone numbers, device IDs, and other data as it tries to identify whoever leaked GTA 6 footage.
https://www.malwarebytes.com/blog/privacy/2026/08/gta-6-leak-hunt-could-expose-data-belonging-to-thousands-of-discord-users
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.
https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Why Financial Services Is the Canary in the Code Mine
Organizations have long known that attackers publish malicious packages to public open source registries. The more consequential question is if those packages are actually reaching enterprise development environments.
https://www.sonatype.com/blog/why-financial-services-is-the-canary-in-the-code-mine
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2
PavinLoader, a multi-stage .NET malware loader, operating across ClickFix, fake software-download, and malicious game campaigns. The activity shows how attackers are moving beyond a single delivery vector. A victim may be lured to a fake Cloudflare or Google verification page and instructed to paste a command, persuaded to install apparently legitimate software, or tricked into […]
The post PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/pavinloader-uses-clickfix/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
SaaS Breach Risk: Visionet Shows How to Approach SaaS Security Risk to Prevent a Data Breach
Prevent SaaS data breaches & supply chain risks. Secure your SaaS environment & apps from third-party threats. Mitigate critical SaaS security risks effectively
https://hackernoon.com/saas-breach-risk-visionet-shows-how-to-approach-saas-security-risk-to-prevent-a-data-breach?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Mirage2FA Hijacks Companies' Microsoft 365 Sessions, with Over 4K Victims in the US
Mirage2FA uses AiTM phishing to steal Microsoft 365 credentials and authenticated sessions, bypassing conventional MFA and enabling account takeover.
https://hackernoon.com/mirage2fa-hijacks-companies-microsoft-365-sessions-with-over-4k-victims-in-the-us?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Oro Raises M as Investors Bet on AI-Native DeFi
While one may be tempted to believe that venture capital money has exited crypto in a big way this year, that narrative is not entirely correct. To elaborate, DeFi, a category that was the poster child for massive investments just a year or two ago pulled in around 4 million over the first half of 2026, even though VC funding reached nearly billion during the same stretch.Even more interestingly, AI-related crypto projects pulled in roughly double that amount, thereby giving birth to a gap that says less about DeFi's tech prowess and more about where investors currently see a repeatable path to users. In all of this, Oro sits squarely in the category still getting funded.
The Dubai-based startup, which converts plain-language financial instructions into multi-step DeFi transactions...
https://hackernoon.com/oro-raises-m-as-investors-bet-on-ai-native-defi?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical, unauthenticated vulnerability […]
https://securityaffairs.com/197801/security/u-s-cisa-adds-maximum-severity-oracle-flaw-to-its-known-exploited-vulnerabilities-catalog.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls
Anthropic has expanded Claude Enterprise's Model Context Protocol (MCP) security capabilities with enterprise-managed authorization, allowing organizations to centrally provision and govern connector access through their identity provider (IdP). The feature, now generally available, removes the need for individual users to authorize each MCP connector after an administrator enables it. Instead, administrators can authorize a connector […]
The post Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/anthropic-expands-claude-mcp-security-with-enterprise-managed-identity-controls/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to forge SAML assertions and log in as any existing user, including site administrators. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8. Research conducted by DigitalOcean’s security team and later […]
The post Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/critical-miniorange-saml-sso-flaws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.
The vulnerabilities, as disclosed by Patchstack, are listed below -
CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation
https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in the password reset process and seize control of arbitrary user accounts. Tracked as CVE-2026-18963, the flaw affects the keycloak-services component, the core identity and access management engine behind the […]
The post Critical Red Hat Keycloak Password Reset Flaw Enables Unauthenticated Account Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/critical-red-hat-keycloak-password-reset-flaw/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
TikTok phishing: How to spot fake login and verification pages
Scammers use fake TikTok login pages, warnings, and verification offers to trick you into handing over your account details.
https://www.malwarebytes.com/blog/threat-intel/2026/08/tiktok-phishing-how-to-spot-fake-login-and-verification-pages
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Mageia Kernel-linus Security Advisory CVE Fixes 2026-0337
A security advisory for Mageia 10 announces updates addressing multiple vulnerabilities fixed in the kernel version 6.18.44, involving numerous CVEs, enhancing overall system security.
https://linuxsecurity.com/advisories/mageia/mageia-2026-0337-kernel-linus
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Mageia Kernel Important Update CVE-2026-64227 2026-0336
Mageia 10 has updated its kernel to version 6.18.44, addressing multiple vulnerabilities and bugs, while specific packages were also revised for compatibility with the new kernel.
https://linuxsecurity.com/advisories/mageia/mageia-2026-0336-kernel
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Mageia 10 Advisory 2026-0105 Hyprland Fix for lxqt Wayland Session
An update for Mageia 10 improves installation of lxqt on Wayland, recommending suitable window managers and enhancing usability, while disabling sessions for niri and hyprland.
https://linuxsecurity.com/advisories/mageia/mageia-2026-0105-hyprland
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Mageia 10 Draksnapshot Copyright Update Advisory 2026-0104
Mageia released updates for version 10 to correct outdated copyright dates in various tools and packages, ensuring the accuracy of copyright information in the software.
https://linuxsecurity.com/advisories/mageia/mageia-2026-0104-draksnapshot
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Mageia opencpn-radar-plugin Bugfix Update Released for 2026-0103
The opencpn-radar-plugin version 5.7.2 released on Aug 25, 2026, addresses a bug by implementing a 1 MB stack for radar locator threads in navico and raymarine.
https://linuxsecurity.com/advisories/mageia/mageia-2026-0103-opencpn-radar-plugin
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Debian LTS Thunderbird DLA-4754-1 Security Update for Multiple Issues
Debian has released an advisory regarding multiple security vulnerabilities in Thunderbird, recommending upgrades for versions 1:140.14.0esr-1~deb11u1 and 1:140.14.0esr-1~deb12u1 to prevent arbitrary code execution and information disclosure.
https://linuxsecurity.com/advisories/deblts/debian-dla-4754-1-thunderbird
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown
WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and multiple file-hosting accounts that are still spreading the infostealer despite a disruption to its command-and-control […]
https://securityaffairs.com/197784/malware/fake-minecraft-sites-are-still-spreading-weedhack-after-c2-takedown.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A Note on Pentesting Passkeys
Some months ago, I performed a web application penetration test on an application that used passkey for authentication. As part of the assessment, I also tested the passkey implementation and noticed some unusual behavior. During the debugging process, I created two short JavaScript helper functions that can be used to hook the browser APIs involved in passkey operations, allowing the passkey configuration to be inspected and manipulated. This gave me the ability to reliably perform some passkey tests and assess the configuration and implementation.
https://blog.compass-security.com/2026/08/a-note-on-pentesting-passkeys/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to
https://thehackernews.com/2026/08/actively-exploited-oracle-weblogic-flaw.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
semgrep-rules
Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple languages.
https://kitploit.com/en/tools/github/trailofbits/semgrep-rules
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
redact v0.2.2
Zero-dependency Go library stripping credential-like patterns (API keys, JWTs, Authorization headers, URL userinfo) before they reach logs/telemetry.
https://kitploit.com/en/posts/gitlab-phpboyscoutgo-redact-v022
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
cvedb
CVE querying library and utility that uses a local store syncing directly to the National Vulnerability Database
https://kitploit.com/en/tools/github/trailofbits/cvedb
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Claude Opus 5 Code Quality: What Sonar's Benchmark Reveals
Claude Opus 5 hits an 88.6% coding pass rate, with lower bug and vulnerability density—but generates 2.3× more code than Opus 4.8.
https://hackernoon.com/claude-opus-5-code-quality-what-sonars-benchmark-reveals?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How to Govern AI in Production With WSO2 AI Gateway
How I went from sleepless nights about rogue LLM outputs to confidently shipping AI-powered features in production.
https://hackernoon.com/how-to-govern-ai-in-production-with-wso2-ai-gateway?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Debian Erlang Multiple Issues Denial of Service 2026-6464-1
Debian advises users to upgrade erlang packages due to multiple vulnerabilities that could lead to denial of service, information disclosure, and code execution, affecting various components.
https://linuxsecurity.com/advisories/debian/debian-dsa-6464-1-erlang
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
pyATS vs Ansible: Choosing the Right Tool for Network Automation
Should you learn pyATS or Ansible first? Learn how both tools work, where they differ, and why network engineers ultimately need both.
https://hackernoon.com/pyats-vs-ansible-choosing-the-right-tool-for-network-automation?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
polytracker
An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.
https://kitploit.com/en/tools/github/trailofbits/polytracker
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Best Companies to Hire a Dedicated Software Development Team in 2026
Discover the best companies to hire a dedicated software development team in 2026. Compare top providers, expertise, pricing models, and key selection criteria.
https://hackernoon.com/best-companies-to-hire-a-dedicated-software-development-team-in-2026?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How to Connect Claude AI to Cisco ACI Using MCP: A Step-by-Step Guide
Connect Claude AI to a live Cisco ACI fabric using MCP. Learn how to build an MCP server for Cisco APIC automation, validation, and safe operations.
https://hackernoon.com/how-to-connect-claude-ai-to-cisco-aci-using-mcp-a-step-by-step-guide?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Your Employees' AI Agents Are Creating Access Paths You Never Approved
AI agents can create hidden access paths between business systems. Here's how to keep employee-built automation useful without losing control.
https://hackernoon.com/your-employees-ai-agents-are-creating-access-paths-you-never-approved?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Databricks vs Snowflake: Who Will Own the Enterprise AI Entry Point?
Enterprise AI is moving beyond models. The real competition is about data, context, governance, and task ownership.
https://hackernoon.com/databricks-vs-snowflake-who-will-own-the-enterprise-ai-entry-point?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
What Would Shannon Think About Today's AI?
Claude Shannon, father of Information Theory at Bell Labs, walks into a modern AI lab — and recognizes every machine in the room. But an angry mob is waiting...
https://hackernoon.com/what-would-shannon-think-about-todays-ai?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
sentrygrid
ML-driven threat detection and continuous monitoring platform built for federal zero trust architectures.
https://kitploit.com/en/tools/gitlab/kreotic/sentrygrid
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
NGINX Heap-Based Buffer Overflow
What is the Vulnerability?
FortiGuard Labs is tracking an exploitation risk associated with CVE-2026-42533, a heap-based buffer overflow vulnerability affecting NGINX Open Source and NGINX Plus. The flaw occurs when the map directive uses regex matching and capture variables in a specific configuration pattern. An unauthenticated remote attacker can send crafted HTTP requests that may crash the NGINX worker process, resulting in denial of service, and potentially achieve remote code execution when ASLR is disabled or bypassed.
The vulnerability was publicly disclosed by F5 on July 15, 2026, with NGINX releasing fixed versions the same day.
Fortinet has conducted an internal security review of products and...
https://fortiguard.fortinet.com/threat-signal-report/6508
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
test-fuzz
Rust macros and Cargo subcommand to automate fuzzing with afl.rs, including corpus generation and harness implementation, integrated with Rust's testing framework.
https://kitploit.com/en/tools/github/trailofbits/test-fuzz
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
fickling
A Python pickling decompiler and static analyzer
https://kitploit.com/en/tools/github/trailofbits/fickling
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
bearer v2.1.1
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
https://kitploit.com/en/posts/github-bearer-bearer-v211
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Migrating From UIKit to SwiftUI in Large Production Apps
Learn how to migrate large UIKit apps to SwiftUI using a phased strategy with interoperability, observability, testing, and performance best practices.
https://hackernoon.com/migrating-from-uikit-to-swiftui-in-large-production-apps?source=rss
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fedora 43 Kernel Update Important Fixes Advisory 2026-6d18f005f1
Fedora 43 released a kernel update to version 7.1.10 on August 23, 2026, addressing critical issues with added security specifications and support for specific audio hardware quirks.
https://linuxsecurity.com/advisories/fedora/fedora-43-kernel-2026-6d18f005f1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fedora 43 java-latest-openjdk Update August CPU Advisory 2026-760df8d7e8
Fedora 43 has released a new update for java-latest-openjdk version 26.0.2.1.0, enhancing the OpenJDK runtime environment, which can be installed via the dnf update program.
https://linuxsecurity.com/advisories/fedora/java-fedora-43-2026-760df8d7e8
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fedora 43 java-25-openjdk Security Fix August CPU 2026-760df8d7e8
Fedora 43 has released an update for java-25-openjdk, version 25.0.4.1.1, related to August CPU vulnerabilities, with installation instructions provided.
https://linuxsecurity.com/advisories/fedora/fedora-43-java-25-openjdk
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fedora 43 Java-21-OpenJDK-Portable Monthly Release 2026-40b2544dda
Fedora 43 has released the OpenJDK 21 portable edition with various updates and improvements, marking its first monthly cadence release candidate for enhanced runtime functionality.
https://linuxsecurity.com/advisories/fedora/fedora-java-21-openjdk-2026-40b2544dda-1787620684
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fedora 43 Nextcloud Security Advisory XSS Security Bypass 2026-625cbe86c8
The Fedora 43 update for NextCloud version 34.0.3 addresses multiple security vulnerabilities including XSS and prototype pollution, enhancing the file sync and share server's safety.
https://linuxsecurity.com/advisories/fedora/fedora-nextcloud-2026-625cbe86c8
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
L'Actu de la presse
Russia threatens to attack British factories - The Telegraph
... cyber attack by “unknown sources”. “There might be different political steps and I cannot exclude 100 per cent that there might be some semi ...
https://www.telegraph.co.uk/world-news/2026/08/25/russia-threatens-attack-british-factories-ukraine/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Real estate firm hit by cyber security attack - RNZ
A March cyber attack on the Hutt City Council has exposed the identity and financial information. Private healthcare provider IntraCare hit by ...
https://www.rnz.co.nz/news/crime-and-justice/1118363/real-estate-firm-hit-by-cyber-security-attack
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Meet the Sponsor: SES Secure | BCI
... Cyber Attack Lessons. How can the BCI community connect with your company via the BCI Corporate Sponsorship? For BCI members interested in learning ...
https://www.thebci.org/news/meet-the-sponsor-ses-secure.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Soutenez No Hack Me sur Tipeee
L'Actu de la veille (Presse spécialisée)
Exploited Zimbra Flaw Highlights Shrinking Window to Patch
CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
https://www.darkreading.com/vulnerabilities-threats/zimbra-flaw-exploitation-shrinking-window-patch
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]
https://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Foul Language: WordlistLoader Disguises Malware as Ordinary Text
ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer.
https://www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Claude Mythos 5 Can Find the Vulnerabilities. But Which Ones Actually Matter?
https://www.legitsecurity.com/blog/claude-mythos-5-can-find-the-vulnerabilities.-but-which-ones-actually-matter
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
HKCERT Issues High-Risk Advisory for Zimbra Collaboration Suite Flaws
HKCERT Bulletin Overview On August 24, 2026, the Hong Kong Computer Emergency Response Team Coordination Center (HKCERT) published security notice S26-0824-01, warning businesses of a number of Zimbra Collaboration Suite...
The post HKCERT Issues High-Risk Advisory for Zimbra Collaboration Suite Flaws appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/hkcert-issues-high-risk-advisory-for-zimbra-collaboration-suite-flaws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hackers target WordPress sites in miniOrange auth bypass attacks
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
TikTok reaches 0M settlement with US over COPPA violations
The U.S. Department of Justice announced a 0 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). [...]
https://www.bleepingcomputer.com/news/legal/tiktok-reaches-400m-settlement-with-us-over-coppa-violations/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work.
The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can
https://thehackernews.com/2026/08/shipping-more-ai-code-than-you-can.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients.
McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,
https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cybercriminals Turn GTA VI Leaks Into Malware Bait
A fake 113GB GTA VI build is packed with malware, using massive empty files to hide a tiny malicious payload. GTA VI hype has reached the point where people are volunteering to infect their own computers just to check if a leak is real. Someone on X asked their followers to “take one for the […]
https://securityaffairs.com/197772/malware/cybercriminals-turn-gta-vi-leaks-into-malware-bait.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
USN-8671-1: FFmpeg vulnerabilities
Adrian Junge was discovered that FFmpeg incorrectly handled certain media
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-66036, CVE-2026-66039)
Adrian Junge discovered that FFmpeg incorrectly handled certain media
files. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2026-66038)
https://ubuntu.com/security/notices/USN-8671-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fake GTA 6 Extended Look and demo sites deliver an infostealer
Bogus “Play Now” sites are exploiting the GTA 6 leak hype to spread malware that steals passwords stored in browsers.
https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
USN-8670-1: curl vulnerability
Joshua Rogers discovered that curl incorrectly handled reusing connections
when client certificate settings changed. This could result in the wrong
client certificates being used, contrary to expectations.
https://ubuntu.com/security/notices/USN-8670-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ReliaQuest confirms failed data-theft attack after ShinyHunters breach
Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]
https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Tricky 'SynkLoader' Multitool May Herald Ransomware
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.
https://www.darkreading.com/threat-intelligence/tricky-synkloader-multitool-ransomware
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fake Microsoft security scans trick victims into uninstalling their antivirus
We found fake Microsoft-branded scanners that invent security problems, tell victims to uninstall AV, and then steer them into a refund scam.
https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
What happens to your data when you die? (Lock and Code S07E17)
This week on the Lock and Code podcast, we speak with Tamara Kneese about the many ways your data remains long after your die.
https://www.malwarebytes.com/blog/podcast/2026/08/your-data-doesnt-die-when-you-do-lock-and-code-s07e17
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ToxicPanda Banking Trojan Matures Into Enterprise Threat
The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.
https://www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.
That's roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.
Plenty to clean up. Here's the short version.
⚡ Threat of the Week
U.S.
https://thehackernews.com/2026/08/weekly-recap-ai-powered-plc-attacks.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AliExpress caught using silent audio to fingerprint visitors' browsers
Silent audio processing on the AliExpress website was found helping to fingerprint visitors' browsers without relying on cookies.
https://www.malwarebytes.com/blog/privacy/2026/08/aliexpress-caught-using-silent-audio-to-fingerprint-visitors-browsers
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Microsoft Teams now lets admins block external bots from meetings
Microsoft is rolling out a new Teams meeting protection policy that allows administrators to automatically block all identified external bots from joining Teams meetings. [...]
https://www.bleepingcomputer.com/news/security/microsoft-teams-now-lets-admins-block-external-bots-from-meetings/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
South Korean startup platform breach exposes key management failures
A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. [...]
https://www.bleepingcomputer.com/news/security/south-korean-startup-platform-breach-exposes-key-management-failures/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Vulnerability Gap: Why Discovery Is Outrunning Repair
AI is discovering more vulnerabilities, faster, and under a tightening regulatory environment, making this an all-hands-on-deck moment for the cybersecurity community.
https://www.darkreading.com/cybersecurity-operations/vulnerability-gap-why-discovery-is-outrunning-repair
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ToxicPanda 2.0 can take over your Android phone and banking apps
A new version of the Android banking Trojan can seize control of infected phones and block access to Google Play and Google Play Services.
https://www.malwarebytes.com/blog/mobile/2026/08/toxicpanda-2-0-can-take-over-your-android-phone-and-banking-apps
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Who's Who In Cyberinsurance For Small Businesses
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 24, 2026 – Read the Full Story Many small business owners operate under the dangerous misconception that they're too small to be a target. The reality? Cybercriminals often view small businesses
The post Who’s Who In Cyberinsurance For Small Businesses appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/whos-who-in-cyberinsurance-for-small-businesses/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Shadow AI Is the New Shadow IT — And Policy Is Just the Starting Line
Every few weeks I talk to a security leader who tells me they have shadow AI in progress. They wrote an acceptable use policy. They published a list of approved...
The post Shadow AI Is the New Shadow IT — And Policy Is Just the Starting Line appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/shadow-ai-is-the-new-shadow-it-and-policy-is-just-the-starting-line/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Tracking PavinLoader across ClickFix and fake download campaigns
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware.
https://www.malwarebytes.com/blog/threat-intel/2026/08/tracking-pavinloader-across-clickfix-and-fake-download-campaigns
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Slovakia Warns of Cyber Risks in Road Speed Cameras
Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia's National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber threat. The alert is not about someone deleting a speeding ticket. It is about […]
https://securityaffairs.com/197764/hacking/slovakia-warns-of-cyber-risks-in-road-speed-cameras.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
TikTok Settles U.S. Child Privacy Case for 0 Million
TikTok will pay 0 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay 0 million to settle a 2024 lawsuit over children's privacy. “Today, the Department of Justice announced a 0 million settlement with TikTok, ByteDance, […]
https://securityaffairs.com/197713/laws-and-regulations/tiktok-settles-u-s-child-privacy-case-for-400-million.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
iAuthFlow v2: The ,000 Phishing Toolkit That Survives Your Password Reset
iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for ,000 base price. The author also offers for sale additional capability modules separately. The headline feature is […]
https://securityaffairs.com/197748/cyber-crime/iauthflow-v2-the-10000-phishing-toolkit-that-survives-your-password-reset.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A week in security (August 17 – August 23)
A list of topics we covered in the week of August 17 to August 23 of 2026
https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-august-17-august-23
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
I Changed One “User_Id” and the API Said “Sure” — From Password Reset to Mass Account Takeover
Account takeover vulnerabilities are among the most impactful findings in web and API security assessments. Sometimes they involve complex authentication bypasses, token manipulation, or sophisticated exploit chains. Other times, the vulnerability comes down to one fundamental mistake: the backend trusts the client to tell it whose password should be changed.Password reset functionality is supposed to help users who forget their passwords.This one was a little more generous.It was willing to reset other people's passwords too.During an authorized API penetration test, I came across a password-reset endpoint that looked completely normal at first. A few Burp Repeater requests later, I realized the backend had essentially implemented:Client: Hey API, I'm User 3. Change my password.API: Any...
https://infosecwriteups.com/i-changed-one-user-id-and-the-api-said-sure-from-password-reset-to-mass-account-takeover-9d4d4e15e022?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Lakera's Break The Agent Challenge— Solace AI Write-up
How I spent a day trying to make an AI bot curse me.Recently I've been obsessed with LLM security, and Lakera' agent breaking game was suggested in many resources as an effective practice for command injection. So I spent a day on Solace AI challenge. Solace AI, is supposed to be an LLM-powered mental health support chatbot that provides 24/7 emotional support and the attack objective is to “Manipulate the mental health chatbot so it only responds with profane and foul language. At least 25% of the output should consist of profane words.” which basically means making the chatbot to curse you! So in advance I apologies for all the curse words you are gonna face in this write-up.Before we start, I strongly suggest trying the challenge yourself first and then reading this write-up. I've...
https://infosecwriteups.com/lakeras-break-the-agent-challenge-solace-ai-write-up-5f99a48c6c69?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
L'Actu de la veille (Presse)
Washington Officials Warn Agencies of Water Cyber Threat - GovTech
Cyber attack concept. Bright text on digital lcd display with reflection. 3D rendering. Cybersecurity · Amid Cyber Threats, Oklahoma Commission ...
https://www.govtech.com/security/washington-officials-warn-agencies-of-water-cyber-threat
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
maharashtra-cyber-police-suspects-cyber-attack-behind-mumbai-power-outage
maharashtra-cyber-police-suspects-cyber-attack-behind-mumbai-power-outage · Also Visit · Social Media ...
https://theindependent.sg/maharashtra-cyber-police-suspects-cyber-attack-behind-mumbai-power-outage/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
MONDAY REPORT NEWS ~24TH AUG, 2026 - YouTube
... channel TBN Israel · BREAKING: Iran CYBER Attack Hits Europe; Hormuz Opens; Israel Strikes Near Turkey | TBN Israel. TBN Israel•127K views. Fundraiser.
https://www.youtube.com/watch%3Fv%3DxgFm2K6OHjg
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
UK briefs energy chiefs after Iran-linked cyber attack reports - Ground News
UK briefs energy chiefs after Iran-linked cyber attack reports. United Kingdom. 10h ago. ARND WIEGMANN/Reuters. Source Analysis.
https://ground.news/daily-briefing/uk-briefs-energy-chiefs-after-iran-linked-cyber-attack-reports_14f89e
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
IRAN HACKS UK POWER PLANT? Massive Security Scare Sparks Panic As Middle East ...
... channel TBN Israel. BREAKING: Iran CYBER Attack Hits Europe; Hormuz Opens; Israel Strikes Near Turkey | TBN Israel. TBN Israel•125K views. Fundraiser.
https://www.youtube.com/watch%3Fv%3D5shSW4atWMQ
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
No American Vessel Is Safe Anymore: Will Cannons Give Way to Codes? - World news
... cyber attack on the Aramco fleet, targeting a giant oil tanker of the company in the Strait of Gibraltar. He warned of the beginning of a new ...
https://www.tasnimnews.ir/en/news/2026/08/24/3679401/no-american-vessel-is-safe-anymore-will-cannons-give-way-to-codes
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Bessent announces new Iranian sanctions in 'Operation Economic Outcast' - YouTube
... channel TBN Israel · BREAKING: Iran CYBER Attack Hits Europe; Hormuz Opens; Israel Strikes Near Turkey | TBN Israel. TBN Israel•125K views. Fundraiser.
https://www.youtube.com/watch%3Fv%3Dn1lxhbuT_-Q
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Iran ramps up cyber warfare & 'Operation Economic Outcast' | FOX 5 News - YouTube
Recent reports link Iranian hackers to a cyber-attack that forced a ... Recent reports link Iranian hackers to a cyber-attack that forced a British ...
https://www.youtube.com/watch%3Fv%3DEa1uC19PFgo
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CT Settles With Online Tax Service In Alleged Data Sharing | CT News Junkie
22 AGs Press United Health Group To Protect Systems Following Feb. 1 Cyber Attack · Keep reading · Connecticut East podcast logo by ...
https://ctnewsjunkie.com/2026/08/24/ct-settles-with-online-tax-service-in-alleged-data-sharing/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
L'Actu à J-2 (Presse spécialisée)
NIUS - 6,090 breached accounts
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical addresses and payment details for purchases including either IBANs or partial credit card data (masked card number, type and expiry).
https://haveibeenpwned.com/Breach/NIUS
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between Banking Malware & Spyware […]
https://securityaffairs.com/197743/security/security-affairs-malware-newsletter-round-111.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
July 2026 Threat Trend Report on Ransomware
Purpose and Scope The July 2026 Threat Trend Report on Ransomware summarizes major Korean & global ransomware issues based on statistics regarding the quantity of new ransomware samples, the number of compromised systems, and statistics on targeted businesses. Statistics on targeted businesses were compiled based on information published on DLS (Dedicated Leak Sites, also referred […]
https://asec.ahnlab.com/en/95112/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Cyber Resilience Imperative: Why CISOs Must Shift from Prevention to Business Survival
For decades, cybersecurity strategies have been built around a single objective: preventing attacks. Organizations invested heavily in perimeter defenses, endpoint security, identity controls, and threat detection technologies with the expectation...
The post The Cyber Resilience Imperative: Why CISOs Must Shift from Prevention to Business Survival appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/the-cyber-resilience-imperative-why-cisos-must-shift-from-prevention-to-business-survival/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power plant for four days in what The Telegraph describes as the most successful cyberattack of its kind against UK energy […]
https://securityaffairs.com/197734/cyber-warfare-2/uk-power-plant-disabled-for-four-days-by-iran-linked-hackers-concurrent-with-us-water-attacks.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries Malware Hijacks Android Car Head Units […]
https://securityaffairs.com/197728/breaking-news/security-affairs-newsletter-round-591-by-pierluigi-paganini-international-edition.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection
New Cryptographic Context Injection technique bypasses AI guardrails via AES-encrypted payloads, leaking full Grok chat histories zero-click Adversa AI researcher Rony Utevsky devised a new attack technique, called Cryptographic Context Injection, that bypasses AI safety filters by sending instructions as AES-encrypted ciphertext and tricking the model into decrypting them inside its own code execution runtime. […]
https://securityaffairs.com/197717/hacking/zero-click-grok-chat-history-theft-adversa-ai-demonstrates-cryptographic-context-injection.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
L'Actu des jours précédents
Rethinking Cyber Readiness In Our Current Threat Landscape
Cybersecurity leaders are dealing with a threat landscape where disruption spreads quickly across systems, vendors, and business operations. AI is accelerating how quickly attackers identify and exploit weaknesses, while identity-based...
The post Rethinking Cyber Readiness In Our Current Threat Landscape appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/rethinking-cyber-readiness-in-our-current-threat-landscape/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Golf Canada - 568,972 breached accounts
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). Golf Canada didn't respond to multiple attempts to make contact, and it remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.
https://haveibeenpwned.com/Breach/GolfCanada
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls
The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.
https://unit42.paloaltonetworks.com/sdlc-supply-chain/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
USN-8658-2: Linux kernel (IBM) vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
https://ubuntu.com/security/notices/USN-8658-2
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
USN-8661-2: Linux kernel (Low Latency) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- NVME drivers;
- Ext4 file system;
- SMB network file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- Open vSwitch;
- SCTP...
https://ubuntu.com/security/notices/USN-8661-2
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How an Emerging Industrial Protocol Family Could Put OT at Risk
New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes.
https://www.darkreading.com/ics-ot-security/how-emerging-industrial-protocol-family-put-ot-at-risk
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AvePoint: Industry Highlights from Black Hat 2026
Most organizations think they’ve solved the data sensitivity problem. AvePoint’s research says otherwise. In the company’s third annual State of AI Report, 82.7% of organizations said they were “very” or...
The post AvePoint: Industry Highlights from Black Hat 2026 appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/avepoint-industry-highlights-from-black-hat-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Sysdig: Industry Highlights from Black Hat 2026
Sysdig is acknowledging the fact that CISOs don’t have time to click through a dashboard anymore. Conor Sherman, the company's Global CISO, argues the next era of cloud security has...
The post Sysdig: Industry Highlights from Black Hat 2026 appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/sysdig-industry-highlights-from-black-hat-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
USN-8669-1: Linux kernel (NVIDIA) vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Foo-over-UDP (FOU);
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Drivers core;
- Null block device driver;
- Bluetooth drivers;
- Counter interface drivers;
- DMA engine subsystem;
- DPLL subsystem;
- GPIO subsystem;
- GPU drivers;
- I2C subsystem;
- IIO ADC drivers;
- IIO subsystem;
- InfiniBand drivers;
- On-Chip Interconnect management framework;
- IOMMU subsystem;
- IRQ chip drivers;
- Modular ISDN driver;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- UACCE accelerator framework;
- MMC subsystem;
- Ethernet bonding...
https://ubuntu.com/security/notices/USN-8669-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
USN-8643-3: Linux kernel (NVIDIA) vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)
https://ubuntu.com/security/notices/USN-8643-3
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
USN-8659-2: Linux kernel (HWE) vulnerability
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
https://ubuntu.com/security/notices/USN-8659-2
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
91 Spring CVEs: The AI Vulnerability Consumption Problem
TL;DR
Broadcom released a large batch of Spring security advisories on August 20, 2026, with Sonatype tracking 91 CVEs across Spring Framework and related projects.
At the time of publishing, Sonatype Guide currently identifies 209,569 software components affected by the security event.
The disclosure comes amid a dramatic rise in AI-assisted vulnerability discovery. Broadcom previously reported a more than 1,700% increase in monthly Spring security advisories from March to April 2026.
AI is making vulnerability discovery faster, but organizations still have to determine where vulnerable components are deployed, prioritize risk, and identify safe remediation paths.
On August 20, 2026, Broadcom published a large collection of security advisories affecting...
https://www.sonatype.com/blog/91-spring-cves-highlight-the-growing-ai-vulnerability-consumption-problem
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
USN-8668-1: Linux kernel (GCP) vulnerabilities
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose sensitive information (kernel memory). (CVE-2023-45896)
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared resources in the operation cache. A local attacker could possibly
use this issue to corrupt instructions executed at a higher privilege
level, resulting...
https://ubuntu.com/security/notices/USN-8668-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
USN-8667-1: Linux kernel (KVM) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- Cryptographic API;
- InfiniBand drivers;
- Media drivers;
- NVIDIA Tegra memory controller driver;
- Network drivers;
- NVME drivers;
- File systems infrastructure;
- Ext4 file system;
- Network file system (NFS) server daemon;
- IPv4 networking;
- Network traffic control;
...
https://ubuntu.com/security/notices/USN-8667-1
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
USN-8662-2: Linux kernel (FIPS) vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- Cryptographic API;
- InfiniBand drivers;
- Media drivers;
- STMicroelectronics network drivers;
- Network drivers;
- Ext4 file system;
- IPv4 networking;
- TCP network protocol;
- Locking primitives;
- Ceph Core library;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
(CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31649,
CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266,
CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53006,
CVE-2026-53176, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)
https://ubuntu.com/security/notices/USN-8662-2
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
OWASP Flags Top AI Skill Risks in New Security Blueprint
The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.
https://www.darkreading.com/application-security/owasp-flags-top-ai-skill-risks-security-blueprint
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Zombie Card: An expired Visa credit card can be used for purchases
Scientific research showed that the expiration date on some Visa credit cards can be manipulated in so-called Zombie Card attacks.
https://www.malwarebytes.com/blog/news/2026/08/zombie-card-an-expired-visa-credit-card-can-be-used-for-purchases
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Calling on Cyber Pros to Help Defend City Hall
Government agencies with smaller budgets need support — and here's how you can help.
https://www.darkreading.com/cyber-risk/cyber-pros-help-city-hall
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
OpenAI Adds Controls That Should've Been There Already
The new AI security controls follow the Hugging Face incident last month, though experts say many of these additions should have been in place prior to the frontier models escaping.
https://www.darkreading.com/application-security/openai-adds-controls-already
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cybersecurity Ventures and World Economic Forum On The Global Cost of Cybercrime
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 21, 2026 – Read the full Irish Times Story A special report from The Irish Times declares cyber fraud is big business. According to Cybersecurity Ventures, global cyber fraud and cybercrime were on
The post Cybersecurity Ventures and World Economic Forum On The Global Cost of Cybercrime appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/cybersecurity-ventures-and-world-economic-forum-on-the-global-cost-of-cybercrime/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hardware Makers Implement Post-Quantum Cryptography as Security Threats Near
The coming threat of super-powerful computers capable of cracking today's algorithms requires upgrading encryption now. Tech companies have begun building defenses.
https://www.darkreading.com/cyber-risk/hardware-makers-implement-post-quantum-cryptography
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Zero Trust In The Age Of AI Driven Cyber Threats (Why Cisos Must Redefine Enterprise Trust Boundaries In 2026)
Enterprise cybersecurity is undergoing a structural shift driven by two converging forces: the collapse of traditional network perimeters and the rapid weaponization of artificial intelligence by threat actors. Industry research...
The post Zero Trust In The Age Of AI Driven Cyber Threats (Why Cisos Must Redefine Enterprise Trust Boundaries In 2026) appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/zero-trust-in-the-age-of-ai-driven-cyber-threats-why-cisos-must-redefine-enterprise-trust-boundaries-in-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The New Russian Playbook: Bypassing MFA Without Cracking Passwords
OAuth Exploitation Russian threat actors are shifting away from plain old password theft and moving toward legitimate platform features like OAuth permissions. Groups like UNC6293 and UNC7005 take their time...
The post The New Russian Playbook: Bypassing MFA Without Cracking Passwords appeared first on Cyber Defense Magazine.
https://www.cyberdefensemagazine.com/the-new-russian-playbook-bypassing-mfa-without-cracking-passwords/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Medical records, SSNs, and bank details exposed in CareCloud data breach
Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.
https://www.malwarebytes.com/blog/news/2026/08/medical-records-ssns-and-bank-details-exposed-in-carecloud-data-breach
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The invisible passenger in your car
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
https://securelist.com/android-head-unit-malware/121106/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Your AI Agent Has New Skills. Can You Trust Them?
https://www.legitsecurity.com/blog/your-ai-agent-has-new-skills.-can-you-trust-them
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Ongoing updates on Copy.fail and variants
Bulletin ID: 2026-030-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/13/2026 10:00 PM PDT
This is an ongoing issue. This bulletin will be updated as more information becomes available.
Description:
AWS is aware of the copy.fail or DirtyFrag class of issues - a set of privilege escalation issues affecting the Linux Kernel. We will update this bulletin as more information becomes available.
Please see below for current patching timelines for affected services related to the Copy.fail kernel issue and all its variants. AWS recommends that customers apply all updates addressing these issues as soon as they are available.
See more details at Security Bulletin (ID: 2026-030-AWS).
https://aws.amazon.com/security/security-bulletins/rss/2026-030-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded to your protected web application resources. We identified CVE-2026-13762 and CVE-2026-13763, which are issues affecting HTTP/2 multi-frame request body inspection by AWS WAF.
CVE-2026-13762 affects AWS WAF deployment with CloudFront. This issue was remediated server-side; no customer action is required.
CVE-2026-13763 affects AWS WAF deployment with AWS Application Load Balancer (ALB). Under certain conditions, a crafted multi-frame HTTP/2 request could cause only a partial request body to be inspected. This issue has been addressed on ALB, and customers can ensure...
https://aws.amazon.com/security/security-bulletins/rss/2026-048-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT
Description:
We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation and associated security controls. When the most recent message in an InvokeHarness request contained a tool-use content block, the agent event loop could dispatch the named tool directly, without model mediation.
Please note that potential impact was limited to the tools configured on a given harness. A harness with no configured tools could not execute any tool, and a harness with a restricted tool set was limited to that set.
Impacted versions:
Amazon Bedrock...
https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338)
Bulletin ID: 2026-005-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/02 14:30 PM PST
Description:
AWS-LC is an open-source, general-purpose cryptographic library. We identified three distinct issues:
- CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass in AWS-LC Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. - CVE-2026-3337: Timing Side-Channel in AES-CCM Tag Verification in AWS-LC Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. - CVE-2026-3338: PKCS7_verify...
https://aws.amazon.com/security/security-bulletins/rss/2026-005-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Issues with AWS Research and Engineering Studio (RES)
Bulletin ID: 2026-014-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/06 14:00 PM PDT
Description:
Research and Engineering Studio (RES) on AWS is an open source, web portal design for administrators to create and manage secure cloud-based research and engineering environments. We have identified the following issues with the AWS Research and Engineering Studio (RES).
CVE-2026-5707: Unsanitized input in an OS Command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name.
CVE-2026-5708: Improper control of user-modifiable attributes in the session...
https://aws.amazon.com/security/security-bulletins/rss/2026-014-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2026-15895: OS command injection in jsii-diff in AWS jsii
Bulletin ID: 2026-057-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 12:00 PM PDT
Description:
jsii-diff is a command line tool to compare the API differences between two jsii assemblies, and report errors if there are backwards-incompatible changes to the API. We identified CVE-2026-15895, an issue where specially formatted command line arguments can be used to execute shell commands via this tool.
Impacted versions: < 1.131.0
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
https://aws.amazon.com/security/security-bulletins/rss/2026-057-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass
Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT
Description:
OpenSearch SQL plugin is a plugin that enables SQL and PPL query capabilities on OpenSearch clusters, including direct query integration with external data sources via Apache Spark. An issue exists where the Flint extension query handler validates SQL queries without sufficient restrictions, allowing a user with async query access to bypass the SQL grammar deny list via the direct query endpoint.
Affected Products & Versions:
OpenSearch SQL Plugin (open-source, self-managed): - Affected: v2.13 to v3.6 - Fixed: versions 3.7 and 2.19.6
Amazon OpenSearch Service (AWS Managed): - Affected: v2.13 to v3.5 - Fixed: v2.13 to v3.5 (via service software update)...
https://aws.amazon.com/security/security-bulletins/rss/2026-081-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer Underflow
Bulletin ID: 2026-021-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/29 12:00 PM PDT
Description:
FreeRTOS-Plus-TCP is a scalable, open source, and thread-safe TCP/IP stack for FreeRTOS. - CVE-2026-7422: Insufficient packet validation in the IPv4 and IPv6 receive paths allows an adjacent network device to send a packet that bypasses checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the target device's own registered endpoints. - CVE-2026-7423: Integer underflow in the ICMP and ICMPv6 echo reply handlers allows an adjacent network device to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validating the...
https://aws.amazon.com/security/security-bulletins/rss/2026-021-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2026-13769 – Insecure file permissions in AWS CLI
Bulletin ID: 2026-049-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/01/2026 11:45 AM PDT
Description:
The AWS Command Line Interface (AWS CLI) is a unified tool for managing AWS services from the command line. We identified CVE-2026-13769 in AWS CLI on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) wrote credential and configuration files with world-readable permissions, which allows other local users on the same host to read credentials.
Impacted versions: <=1.44.77 (v1) AND <=2.34.28 (v2)
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
https://aws.amazon.com/security/security-bulletins/rss/2026-049-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT
Description:
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-16756 where the allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated "Slowloris" denial of service.
Impacted versions: aws-smithy-http-server <= 0.66.4
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
https://aws.amazon.com/security/security-bulletins/rss/2026-064-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
https://aws.amazon.com/security/security-bulletins/rss/2026-066-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins
Bulletin ID: 2026-047-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/23/2026 09:30 AM PDT
Description:
Language Servers for AWS provide the underlying language-server runtime that powers Amazon Q Developer's AI coding assistance across its IDE plugins (Visual Studio Code, JetBrains, Eclipse, and Visual Studio).
We identified CVE-2026-12957, an improper trust boundary enforcement issue in Language Servers for AWS before version 1.65.0. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted.
We identified CVE-2026-12958, a missing symlink-validation issue in Language Servers for AWS before version 1.69.0. This...
https://aws.amazon.com/security/security-bulletins/rss/2026-047-aws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
New CUSTODY Framework Constrains AI Agents Inside the Network
Enterprise cybersecurity expert Jake Williams joins the Dark Reading News Desk to explain why he decided to release his new agentic AI framework in the wake of the OpenAI attacks on Hugging Face.
https://www.darkreading.com/perimeter/new-custody-framework-constrains-ai-agents-inside-network
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Managing Air-Gapped Environments: Ensuring Security and Efficiency
For years, air-gapped environments have been the gold standard for protecting classified systems and critical infrastructure. Isolate the network, remove the path, reduce the risk. The logic held, and it still does. An air gap does exactly what it was designed to do.
https://www.sonatype.com/blog/an-air-gap-doesnt-remove-the-supply-chain.-it-makes-every-crossing-a-decision
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Editorial Style Videos Are The Cutting Edge Of Cybersecurity Journalism
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 20, 2026 – Read the Full Story An editorial style video uses journalistic narration and storytelling, changing scenes and angles, and b-roll, over plain, unedited or minimally edited footage that has
The post Editorial Style Videos Are The Cutting Edge Of Cybersecurity Journalism appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/editorial-style-videos-are-the-cutting-edge-of-cybersecurity-journalism/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Managing the cyber risk of agentic AI
Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.
https://www.ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Identity Abuse Through Trusted Communication Channels
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies.
The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
https://unit42.paloaltonetworks.com/communication-channel-identity-risks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level
Adelaide, Australia, 19th August 2026, CyberNewswire
Airlock Digital Completes Independent IRAP Assessment at the PROTECTED Level on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/08/20/airlock-digital-completes-independent-irap-assessment-at-the-protected-level/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
IAM Protects the Identity. ITDR Protects the Moment.
IAM Locks the Door. ITDR Catches the Intruders? – Christophe Briguet, Sr. Director of Product Management – AI & Security Analytics, Stellar Cyber San Jose, Calif. – Aug. 19, 2026 Your employee successfully authenticates. The account is valid. The permissions are legitimate. There’s just one
The post IAM Protects the Identity. ITDR Protects the Moment. appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/iam-protects-the-identity-itdr-protects-the-moment/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud.
The post Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/19/microsoft-named-a-leader-in-the-frost-radar-cloud-workload-protection-platforms-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Beyond Deepfakes: Zero Trust Security for the AI Economy
TL;DR: Deepfakes are not merely a detection challenge. They expose fundamental weaknesses in how organizations establish identity, grant authority, and protect data. Appearances alone can no longer serve as proof. CSA research shows how Zero Trust, IAM, and AI data security can provide the trust infrastructure organizations need.
A familiar face appears on a video call. A known voice delivers an urgent instruction. A senior executive requests an unusual payment, data transfer, or passwor...
https://cloudsecurityalliance.org/articles/beyond-deepfakes-zero-trust-security-for-the-ai-economy
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
OverviewOn August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges.NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality. Because these systems are frequently deployed in enterprise DMZs and exposed...
https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
YouTube Is The New Powerhouse For Marketing To CISOs And MSSPs
The top b2b focused cybersecurity media and event channels listed by number of subscribers and views per video – Steve Morgan, Editor-in-Chief Sausalito, Calif. – Aug. 19, 2026 As one of the world's largest social media platforms with more than 2.7 billion monthly users, YouTube
The post YouTube Is The New Powerhouse For Marketing To CISOs And MSSPs appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/cmo-report/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Hidden Risk in Data Transfer
Cybersecurity has become one of the most defining business challenges of recent times. Organisations have invested heavily in protecting their networks, securing cloud environments and strengthening identity and access management. At the same time, organisations are under increasing pressure to prove they are handling sensitive information securely, not just storing it safely but protecting it […]
The post The Hidden Risk in Data Transfer appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/08/19/the-hidden-risk-in-data-transfer/?utm_source=rss&utm_medium=rss&utm_campaign=the-hidden-risk-in-data-transfer
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
July 2026 Threat Trend Report on APT Groups
Purpose and Scope The July 2026 Threat Trend Report on APT Groups summarizes the trend in which state-sponsored threat actors and financially motivated attackers are employing a combination of supply chain attacks, account takeovers, cloud breaches, and social engineering techniques. Key targets include Microsoft 365, webmail accounts, cloud infrastructure, GitHub and development environments, VPN and […]
https://asec.ahnlab.com/en/95040/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Ransom & Dark Web Issues Week 3, August 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 3, August 2026 Customer and Operational Data of a South Korean Delivery Platform Offered for Sale Unauthorized Access Incident at a Japanese Cloud and Data Center Services Company ShinyHunters Threatens Data Disclosure Against a U.S. Live-Streaming Platform
https://asec.ahnlab.com/en/95046/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fake Crypto Exec Used Booby-Trapped Google Doc to Target Security Researcher After DEF CON
A threat actor impersonating a senior executive at a well-known cryptocurrency media outlet attempted to infect a Huntress researcher with malware in the days following this year’s Black Hat and DEF CON conferences, according to new research from the security vendor. The campaign began on X (formerly Twitter), where an account impersonating the executive sent […]
The post Fake Crypto Exec Used Booby-Trapped Google Doc to Target Security Researcher After DEF CON appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/08/19/fake-crypto-exec-used-booby-trapped-google-doc-to-target-security-researcher-after-def-con/?utm_source=rss&utm_medium=rss&utm_campaign=fake-crypto-exec-used-booby-trapped-google-doc-to-target-security-researcher-after-def-con
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Education Now the World's Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School
Education has overtaken every other industry to become the most targeted sector for cyberattacks worldwide, according to new research from Check Point, with threat actors ramping up activity in the run-up to the new academic year. Between January and July 2026, schools, colleges, universities and research institutes faced an average of 4,696 weekly cyberattacks per […]
The post Education Now the World’s Most-Attacked Sector as Cybercriminals Gear Up for Back-to-School appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/08/19/education-cyberattacks-back-to-school/?utm_source=rss&utm_medium=rss&utm_campaign=education-cyberattacks-back-to-school
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Binary Defense Launches NightBeacon, An AI-Driven SOC Platform Built For The Speed Of Modern Cyberattacks
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 19, 2026 – Watch the Video Binary Defense, a trusted Managed Detection and Response (MDR) and enterprise defense provider, earlier this year announced the launch of NightBeacon, an AI-powered security operations platform built
The post Binary Defense Launches NightBeacon, An AI-Driven SOC Platform Built For The Speed Of Modern Cyberattacks appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/binary-defense-launches-nightbeacon-an-ai-driven-soc-platform-built-for-the-speed-of-modern-cyberattacks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity
Recent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past few weeks have made it clear that cybersecurity is an important factor in ensuring the safe and reliable delivery of critical goods and services. For OT owners/operators, it can be challenging to address the range of cybersecurity threats, vulnerabilities and risks that can negatively impact their operations, especially with limited resources. Modern
https://www.nist.gov/blogs/cybersecurity-insights/nist-releases-tips-tactics-building-automation-control-system
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America
Cássio De Alcântara is Director, LATAM Sales at Rapid7.Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also introduce greater complexity and expanding attack surfaces.In this environment, security leaders are being asked to understand where risk exists across increasingly distributed environments and quickly eliminate blind spots like Shadow IT and Shadow AI – all without adding operational complexity.To help security leaders and practitioners address this complexity, Rapid7 is excited to announce a new strategic distribution partnership with Licencias OnLine (LOL) across Latin America.Helping organizations stay ahead of evolving threatsIn order to keep day-to-day...
https://www.rapid7.com/blog/post/c-licencias-online-partnership-accelerates-latam-cybersecurity-maturity-latin-america
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Premier League Introduces Mandatory Cybersecurity Standards, Backed by Fines of Up to £100,000
The Premier League has introduced mandatory cybersecurity requirements for its clubs for the first time, with non-compliant clubs facing fines of up to £100,000. The rules, which apply from the start of the 2026-27 season, mark a shift away from the league’s previous non-prescriptive security guidance towards a formal framework with fixed deadlines and evidence-based […]
The post Premier League Introduces Mandatory Cybersecurity Standards, Backed by Fines of Up to £100,000 appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/08/19/premier-league-cybersecurity-requirements/?utm_source=rss&utm_medium=rss&utm_campaign=premier-league-cybersecurity-requirements
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Why compliance does not guarantee cyber resilience
Cyber security has become one of the most audited and regulated areas of enterprise technology. Yet an organisation can satisfy every requirement on paper and still discover, during a real incident, that its systems, people or processes are not ready for the pressure that follows. Compliance can demonstrate that controls have been put in place; […]
The post Why compliance does not guarantee cyber resilience appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/08/19/why-compliance-does-not-guarantee-cyber-resilience/?utm_source=rss&utm_medium=rss&utm_campaign=why-compliance-does-not-guarantee-cyber-resilience
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Oz Hair and Beauty - 1,988,331 breached accounts
In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the company, which included 2M unique email addresses along with names, phone numbers, geographic locations (suburb and postcode) and purchases.
https://haveibeenpwned.com/Breach/OzHairAndBeauty
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fanlore - 144,520 breached accounts
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique email addresses along with usernames and passwords stored as either MD5 or PBKDF2 hashes. OTW self-submitted the exposed data to HIBP.
https://haveibeenpwned.com/Breach/Fanlore
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
State of AI Cybersecurity 2026: 77% of Security Stacks Include AI, But Trust is Lagging
Originally published by Darktrace.
AI is now embedded throughout the cybersecurity stack, but findings from the State of AI Cybersecurity 2026 show that adoption is growing much faster than trust or understanding. As vendors strive to capture market share, security leaders must learn how to distinguish the most valuable solutions from the hype.
Findings in this blog are taken from Darktrace's annual State of AI Cybersecurity Report 2026.
AI is a contributing member of nearly ...
https://cloudsecurityalliance.org/articles/state-of-ai-cybersecurity-2026-77-of-security-stacks-include-ai-but-trust-is-lagging
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
We Asked an AI Agent to Close a Linear Ticket. It Dropped a Production Table.
Originally published by Eve Security.
A developer opens Cursor, points it at a Linear ticket, and asks it to implement the fix. Cursor loads ticket-work, a small skill that standardizes how the agent pulls context from Linear and closes tickets. It's the kind of utility a team writes once and then forgets about.
The agent reads the ticket and loads the skill. A few tool calls later, the insurance_claims table is gone.
Unconfined agent drop — after “Implement RND-1277,” t...
https://cloudsecurityalliance.org/articles/we-asked-an-ai-agent-to-close-a-linear-ticket-it-dropped-a-production-table
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks.
The post Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18) appeared first on Unit 42.
https://unit42.paloaltonetworks.com/large-scale-credential-attacks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots.
The post Hunting MacSync Stealer infrastructure through behavioral pivots appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hacker Claims Millions of Records Stolen From Azure Tenants
A threat actor is claiming to have stolen millions of employee records from the Microsoft Azure environments of several major companies, raising concerns that the information could be used to launch targeted phishing, impersonation, and privilege escalation attacks. The threat actor, known as “TheHatman,” has reportedly posted internal employee directories belonging to companies including McDonald’s, […]
The post Hacker Claims Millions of Records Stolen From Azure Tenants appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/08/18/hacker-claims-millions-of-records-stolen-from-azure-tenants/?utm_source=rss&utm_medium=rss&utm_campaign=hacker-claims-millions-of-records-stolen-from-azure-tenants
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
2,000 Hacked WordPress Sites Were Secretly Running a Global Crime Ring
A newly identified cybercrime operation dubbed StopAndProtect has been quietly running its entire criminal infrastructure through close to 2,000 hacked WordPress websites, according to new research from Check Point. Rather than relying on dedicated command-and-control servers, which are relatively easy for defenders to identify and take down, the group behind StopAndProtect compromised thousands of legitimate […]
The post 2,000 Hacked WordPress Sites Were Secretly Running a Global Crime Ring appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/08/18/2000-hacked-wordpress-sites-were-secretly-running-a-global-crime-ring/?utm_source=rss&utm_medium=rss&utm_campaign=2000-hacked-wordpress-sites-were-secretly-running-a-global-crime-ring
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
You can't patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive programs. Success going forward can't be about patching as much as possible - it has to be about understanding what matters most and reducing the exposures attackers can actually reach.Here are the four trends that defined Q2 2026, and what they mean for your security program as you define priorities...
https://www.rapid7.com/blog/post/tr-new-report-ai-threats-q2-2026-ends-traditional-patch-cycles
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Queen Of Online Safety Talks Digital Self-Defense In An AI World
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 18, 2026 – Listen to the Podcast After cybercriminals hacked her network and devastated her finances, career, health, and marriage, Jocelyn King spent years in the cyber trenches, transforming her hard-won experience into
The post The Queen Of Online Safety Talks Digital Self-Defense In An AI World appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/the-queen-of-online-safety-talks-digital-self-defense-in-an-ai-world/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
International Cyber Expo Unveils New Talks for its Global Cyber Summit 2026
International Cyber Expo has announced a new line-up of speakers and sessions for its Global Cyber Summit, with discussions set to tackle some of the biggest issues facing cybersecurity leaders. Sponsored by Huntress, the Global Cyber Summit will bring together senior security professionals, government representatives and industry experts at Olympia London on 29 and 30 […]
The post International Cyber Expo Unveils New Talks for its Global Cyber Summit 2026 appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/08/18/international-cyber-expo-2026-new-talks/?utm_source=rss&utm_medium=rss&utm_campaign=international-cyber-expo-2026-new-talks
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Proton launches free tool to show enterprises what ChatGPT and Claude know about employees
Privacy-focused tech company Proton has launched a free tool designed to show users exactly what large language models such as ChatGPT and Claude have learned about them from months or years of conversation history, a capability that speaks directly to the shadow AI problem now facing enterprise security teams. The tool, called AI Paper Trail, […]
The post Proton launches free tool to show enterprises what ChatGPT and Claude know about employees appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/08/18/proton-launches-free-tool-to-show-enterprises-what-chatgpt-and-claude-know-about-employees/?utm_source=rss&utm_medium=rss&utm_campaign=proton-launches-free-tool-to-show-enterprises-what-chatgpt-and-claude-know-about-employees
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Legacy Operating Models Can't Keep Pace With IT Complexity, Cloud Security Alliance Survey Finds
Study reveals that fragmented ownership and limited visibility have made manual policy management a production risk
SEATTLE – Aug. 18, 2026 — Fragmented operating models spanning teams, tools, and environments and which are still heavily reliant on manual processes are taking a measurable toll on production uptime, deployment velocity, and compliance readiness, according to a new survey from the Cloud Security Alliance (CSA), the world's leading not-for-profit organization committed to A...
https://cloudsecurityalliance.org/articles/legacy-operating-models-can-t-keep-pace-with-it-complexity-cloud-security-alliance-survey-finds
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Securing Software at the Speed of AI: What Four Years of Data Reveal
AI-assisted development is changing the speed at which software gets built, but speed is only part of the story.
https://www.sonatype.com/blog/securing-software-at-the-speed-of-ai-what-four-years-of-data-reveal
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Downwind of the Labs
One of the first things they teach you in hazmat response is to stage uphill and upwind. (And the rule of thumb: if you can't cover the scene with your thumb, you're too close). Before you treat a single patient, before you even get out of the truck, you figure out where the plume is going. While most industrial accidents are self-contained, it's the ones that spread into the surrounding community that make the news.
This is how I'm now thinking about the Hugging Face and related AI “esc...
https://cloudsecurityalliance.org/articles/downwind-of-the-labs
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hacker Holidays 2026: Day 10 Walkthrough (The Hollow Shell)
A file upload accepted ZIP archives but never validated the paths inside. We used Zip Slip to plant a reverse shell in the server’s hooks…Continue reading on InfoSec Write-ups »
https://infosecwriteups.com/hacker-holidays-2026-day-10-walkthrough-the-hollow-shell-99df009baf37?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hacker Holidays 2026: Day 9 Walkthrough (CryptoCabana)
A hardcoded SAS token in the website’s JavaScript led to a service account. That service account unlocked an Azure Key Vault. The vault’s…Continue reading on InfoSec Write-ups »
https://infosecwriteups.com/hacker-holidays-2026-day-9-walkthrough-cryptocabana-a6a1caa9438a?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hacker Holidays 2026: Day 8 Walkthrough (Towel on the Sunbed)
A rewards system let you claim 50 points every 24 hours. We claimed it three times in the same millisecond. Welcome to race conditions.Continue reading on InfoSec Write-ups »
https://infosecwriteups.com/hacker-holidays-2026-day-8-walkthrough-towel-on-the-sunbed-4cd1f708eb3c?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hacker Holidays 2026: Day 7 Walkthrough (Do Not Disturb)
NoSQL injection bypassed the login. Server-Side Template Injection gave us code execution. A forgotten Node.js debugger running as a…Continue reading on InfoSec Write-ups »
https://infosecwriteups.com/hacker-holidays-2026-day-7-walkthrough-do-not-disturb-062dfc269d69?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hacker Holidays 2026: Day 6 Walkthrough (Overheard at Breakfast)
A conversation overheard at breakfast leaked an email address. That email led to a forgotten Gravatar profile. That profile contained the…Continue reading on InfoSec Write-ups »
https://infosecwriteups.com/hacker-holidays-2026-day-6-walkthrough-overheard-at-breakfast-e878ce13c189?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
TryHackMe — Guided Pentest: Infrastructure | Full Walkthrough
Room: Guided Pentest: Infrastructure Difficulty: Easy Category: Penetration Testing Tags: Nmap, Metasploit, UnrealIRCd, Privilege Escalation, LinuxIntroductionThis is a beginner-friendly penetration testing room on TryHackMe that walks you through a real-world infrastructure pentest workflow — from initial scanning all the way to rooting the machine. The methodology followed here is:Enumeration — Scan the target and gather informationVulnerability Analysis — Identify weaknesses in discovered servicesInitial Access — Exploit the vulnerability and get a shellPrivilege Escalation — Move from a low-privilege user to rootReporting — Document findings professionallyLet's get into it.Step 1: Connect to TryHackMe via VPNBefore anything, connect your machine...
https://infosecwriteups.com/tryhackme-guided-pentest-infrastructure-full-walkthrough-8984cd1806f4?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Behavioral Malware Analysis: Investigating a Multi-Stage Malware Sample Inside an Isolated Lab
How I investigated persistence, C2 communications, process injection, and data exfiltration using FLARE-VM, REMnux, Sysmon, Procmon, Wireshark, and MITRE ATT&CK.Static analysis provides a valuable starting point, but it rarely tells the complete story of what a piece of malware is truly capable of.Modern malware is designed to reveal its most dangerous behaviors only at runtime, establishing persistence, communicating with attacker-controlled infrastructure, fetching additional payloads, evading defensive controls, and exfiltrating sensitive data. Capturing and understanding these behaviors requires observing the sample as it executes within a controlled and monitored environment.To replicate the conditions of a real-world investigation, I constructed an isolated behavioral analysis...
https://infosecwriteups.com/behavioral-malware-analysis-investigating-a-multi-stage-malware-sample-inside-an-isolated-lab-fba44d152d5b?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Hacker Holidays Day 8 — Do Not Disturb(TryHackMe) Full Writeup
A walkthrough of a multi-stage Node.js/Express box: NoSQL auth bypass → SSTI → SSH pivot → Node Inspector RCE → disk-group privesc.Replace <TARGET_IP> and <ATTACKER_IP> with your lab's actual values throughout. IPs below are illustrative from my own run and will differ per-deployment on THM.1. Reconnaissancenmap -sC -sV -A -Pn <TARGET_IP>PORT STATE SERVICE VERSION22/tcp open ssh OpenSSH 9.6p1 Ubuntu 3ubuntu13.1880/tcp open http Node.js (Express middleware)|_http-title: Byte Lotus — PoolsideTwo open ports: SSH and an Express-based HTTP app. Loading the site shows a single login form, POSTing to /login. A content discovery scan (gobuster/ffuf) against common wordlists turned up nothing — no hidden endpoints found that way. That pushed the next step...
https://infosecwriteups.com/hacker-holidays-day-8-do-not-disturb-tryhackme-full-writeup-059061b7973e?source=rss----7b722bfd1b8d---4
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
When the Playbook Breaks: AI Incident Response for Systems That Don't Behave Like Anything Else
Three years after the explosion of GenAI in the enterprise, most organizations now have an inventory of their AI systems, an acceptable use policy, and — at best — a process for approving AI use cases. Far fewer, however, have answered a seemingly simple question about AI Incident Response: what exactly do we do on the day one of these tools is compromised?
Most security organizations have mature playbooks for ransomware, business email compromise, and cloud account takeover. Yet very fe...
https://cloudsecurityalliance.org/articles/when-the-playbook-breaks-ai-incident-response-for-systems-that-don-t-behave-like-anything-else
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cybercrime Magazine Announces Platinum Media Program for Cybersecurity Companies
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 17, 2026 – Read the Press Release Cybersecurity Ventures launched a Platinum Media Program for VC funded startups, emerging players, and the largest brands in the cybersecurity industry. “If your target market is
The post Cybercrime Magazine Announces Platinum Media Program for Cybersecurity Companies appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/cybercrime-magazine-announces-platinum-media-program-for-cybersecurity-companies/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Stronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity
When was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than a lesson, or a confusing security warning pop-up that interrupted your work. Or maybe you're on the other side of the equation, working as a cybersecurity professional who is wrangling a half dozen disconnected dashboards, drowning in alerts (all flagged "urgent"), or struggling to make a sound judgment call at midnight because you're tired and your tools
https://www.nist.gov/blogs/cybersecurity-insights/stronger-cybersecurity-programs-start-people-nist-wants-your-input-path
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
Operation ASTERIX overviewRapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered prompts, shell history, and project files show AI being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure, and prepare malware for distribution. When one model began resisting parts of that workflow, the operator switched providers and attempted...
https://www.rapid7.com/blog/post/tr-operation-asterix-crypto-fraud-vishing-phishing
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How QR-code phishing can slip past corporate security measures
Quishing has become a popular alternative to traditional phishing. Here's how businesses can close the gap.
https://www.welivesecurity.com/en/business-security/qr-code-phishing-slip-past-corporate-security-measures/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Africa's Cybersecurity Challenge Is Bigger Than Access to Technology
Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa.Across Egypt, Nigeria, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, context, and specialist capacity.As environments expand, the challenge is no longer finding another security product. It is turning existing technology and new investments into clearer risk decisions, faster investigations, and more consistent response, which requires more than software.Rapid7 and StarLink: From access to operational capabilityAfrica has been an important region for Rapid7 for many years, and we're...
https://www.rapid7.com/blog/post/c-starlink-distribution-partnership-africa
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Impacket for Pentester: SMBExec
Overview Remote command execution sits at the heart of nearly every successful Active Directory engagement. Once a penetration tester recovers valid credentials, the immediate objective
The post Impacket for Pentester: SMBExec appeared first on Hacking Articles.
https://www.hackingarticles.in/impacket-for-pentester-smbexec/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Metasploit Wrap Up: Lot of summer shells and fit http profiles
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/)!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the party...
https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-lot-of-summer-shells-and-fit-http-profiles
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The 80% Problem: Why AI resilience is more important than ever
AI has been transformational for the workplace, saving time on repetitive tasks and freeing skilled staff to focus on higher-value work. It has become so embedded in organisations that ISACA's research recently found that 82% of European companies expressly permit the use of AI at work. However, there is a difference between using AI and […]
The post The 80% Problem: Why AI resilience is more important than ever appeared first on IT Security Guru.
https://www.itsecurityguru.org/2026/08/14/the-80-problem-why-ai-resilience-is-more-important-than-ever/?utm_source=rss&utm_medium=rss&utm_campaign=the-80-problem-why-ai-resilience-is-more-important-than-ever
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
BreachLock: CISO Conversations Revealed At Black Hat USA 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 14, 2026 – Watch the YouTube video “One thing is really clear in all the CISO conversations I’ve had – is that everybody is worried about the number of CVEs (common vulnerabilities and
The post BreachLock: CISO Conversations Revealed At Black Hat USA 2026 appeared first on Cybercrime Magazine.
https://cybersecurityventures.com/breachlock-ciso-conversations-revealed-at-black-hat-usa-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Who's Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.
https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
What 50 open source projects taught us about security in the AI era
See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security.
The post What 50 open source projects taught us about security in the AI era appeared first on The GitHub Blog.
https://github.blog/open-source/maintainers/what-50-open-source-projects-taught-us-about-security-in-the-ai-era/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
And will today's surge in AI-driven vulnerability discovery eventually make tomorrow's software safer?
https://www.welivesecurity.com/en/business-security/black-hat-usa-2026-vulnerability-discovery-decline-ai-era/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cybercriminals Turn to Indirect Prompt Injection Attacks
https://www.proofpoint.com/us/newsroom/news/cybercriminals-turn-indirect-prompt-injection-attacks
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How BitLocker PINs help protect your data and devices
Using a PIN mitigates many BitLocker vulnerabilities. Make sure you're ready for the next one...
https://www.ncsc.gov.uk/blogs/how-bitlocker-pins-help-protect-your-data-and-devices
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
RingCentral - 1,596,490 breached accounts
In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addresses and phone numbers. In their disclosure notice, RingCentral advised that the incident affected "a limited portion of RingCentral customers" and that it was communicating directly with those affected.
https://haveibeenpwned.com/Breach/RingCentral
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
July 2026 Cyber Attacks Statistics Infographic
One page, every number that matters. This infographic distills July 2026's 188 confirmed cyber attacks into a fast visual read — who's behind them, how they broke in, what they targeted, and where in the world it happened.
https://www.hackmageddon.com/2026/08/13/july-2026-cyber-attacks-statistics-infographic/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
July 2026 Cyber Attacks Statistics
July 2026 saw 188 confirmed cyber attacks across 69 countries, with financially motivated Cyber Crime driving three in four incidents. Malware remained attackers' weapon of choice, exposed public-facing applications were the most common way in, and Information & Communication infrastructure absorbed the heaviest share of targeting. Here's the full breakdown of who attacked, how, and where.
https://www.hackmageddon.com/2026/08/13/july-2026-cyber-attacks-statistics/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How to Test for CORS Misconfigurations Like a Bug Bounty Hunter
A step-by-step method for finding and proving CORS misconfiguration vulnerabilities: the header checks, the edge cases developers miss, and how to fix them.
How to Test for CORS Misconfigurations Like a Bug Bounty Hunter on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/08/13/testing-cors-misconfiguration-vulnerability/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
https://www.welivesecurity.com/en/business-security/black-hat-usa-2026-hugging-face-hack-human-responsibility/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Armored Likho expands its cyber-espionage toolkit
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
https://securelist.com/armored-likho-still-toolkit/121033/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Major Themes at Black Hat 2026
Last week was the second time I've attended Black Hat, the first being over a decade ago, and it has certainly grown. The production value of the briefings and especially the keynotes was incredible, the vendor area was larger and grander, and the attendees were more numerous, swarming, even. That is to be expected though with one of the main security conferences on the planet. Last time I was there, the hot topic was IoT; this year, as you could have guessed, AI was mentioned in nearly every keynote, briefing, and conversation I had while there. Here are the major recurring themes that I observed this year.
https://www.sonatype.com/blog/major-themes-at-black-hat-2026
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
When Tokenmaxxing Leads to Riskmaxxing
AI fluency and tokenmaxxing are the new corporate obsessions. But where leadership sees opportunity, security sees friction.
It's no longer enough just to do your job well. Across industries, employees are expected to weave AI into every workflow so they can 10x productivity and innovation.
And when it comes to AI, today's workforce is single-minded. They're rising to the occasion to "use AI more" by seemingly any means necessary. They are seeking out new tools, signing up,...
https://cloudsecurityalliance.org/articles/when-tokenmaxxing-leads-to-riskmaxxing
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
SOC 2 vs. HITRUST: Which Framework is Right for Healthcare Organizations?
Healthcare organizations face growing pressure to protect sensitive patient data while meeting strict regulatory requirements. Two of the most recognized cybersecurity and compliance frameworks in the healthcare space are SOC 2 and HITRUST. While both frameworks strengthen security posture and build trust with stakeholders, choosing which one is the best next step for your organization depends on your goals, customer expectations, and compliance needs. In this blog, you will learn:
SOC...
https://cloudsecurityalliance.org/articles/soc-2-vs-hitrust-which-framework-is-right-for-healthcare-organizations
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Ransom & Dark Web Issues Week 2, August 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 2, August 2026. DragonForce Ransomware Attack on a South Korean Online Education Company Qilin Ransomware Attack on a South Korean Motor and Robotics Manufacturer ShinyHunters Claims Data Leak from a U.S. Digital Healthcare Company
https://asec.ahnlab.com/en/94968/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong
https://www.welivesecurity.com/en/business-security/black-hat-usa-2026-ai-racing-cybersecurity-controls/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AI is Working in the SOC. So Why are Security Executives More Worried Than Ever?
Something shifted in security operations over the last two years: AI stopped being a pilot program and became the plan.And if you survey 500 security professionals on whether that's going well – as Omdia did, commissioned by Rapid7 – you get a remarkable level of consensus: 97% report positive outcomes, 98% say AI reduces alert fatigue, and 95% say it's helping address staffing shortages.Those numbers are high enough that the story could stop there; AI is working, everyone agrees. Move on. But there's a more interesting finding sitting underneath that consensus, and it tells you something important about where security operations is actually headed.The confidence gap nobody is talking aboutWhile frontline SOC teams report strong confidence in AI, executive security leaders like CISOs,...
https://www.rapid7.com/blog/post/ai-report-500-security-leaders-reveal-security-operations-transformation
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Help shape the future of resilient private 5G
The NCSC wants to collaborate with organisations developing technologies and approaches for secure, resilient and deployable private 5G
https://www.ncsc.gov.uk/blogs/help-shape-the-future-of-resilient-private-5g
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Shaping the NVD for the Future: We Need Your Feedback on AI-Enabled Vulnerability Management
For over two decades, the NIST National Vulnerability Database (NVD) has served as the U.S. government repository for standards-based vulnerability management data and as a foundational resource for cybersecurity risk analysis, vulnerability management, compliance automation, and software security. New Opportunities for the NVD via Automation Our cybersecurity landscape is changing dramatically and is being reconfigured by artificial intelligence (AI) in unique, exciting, and yes, sometimes challenging ways. This is creating openings to potentially leverage AI systems to discover and exploit
https://www.nist.gov/blogs/cybersecurity-insights/shaping-nvd-future-we-need-your-feedback-ai-enabled-vulnerability
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Artificial Intelligence (AI) Emerges as an Attack Enabler and Target in Cloud Security Alliance's 2026 Top Threats Report
Identity, AI, software supply chains, and interconnected cloud ecosystems displace traditional infrastructure as top security concerns
SEATTLE – Aug. 13, 2026 – Security practitioners are increasingly concerned about the impact of AI on cloud security, according to the findings of the Top Threats to Cloud Computing Survey Report 2026. The latest installation in the Top Threats to Cloud Computing series from the Cloud Security Alliance (CSA), the world's leading not-for-profit organiza...
https://cloudsecurityalliance.org/articles/ai-emerges-as-an-attack-enabler-and-target-in-csa-2026-top-threats-report
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
HTTP/2 Bomb CVE-2026-49975
CVSSv3 Score:
5.8
CVE-2026-49975Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Revised on 2026-08-19 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-163
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Broken access control in the RADIUS type admin group
CVSSv3 Score:
8.8
An Improper Authentication vulnerability [CWE-287] in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password
Revised on 2026-08-12 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-158
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Content-Encoding WAF Evasion
CVSSv3 Score:
4.8
An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests.
Revised on 2026-08-12 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-157
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
FGFM Authentication Weakening via CLI Configuration
CVSSv3 Score:
7.3
An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate.
Revised on 2026-08-12 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-160
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Heap overflow in kernel driver due to missing size validation
CVSSv3 Score:
7.3
A buffer copy without checking size of input vulnerability [CWE-120] in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted host to execute arbitrary code via malicious packets.
Revised on 2026-08-12 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-156
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Server-Side Request Forgery (SSRF)
CVSSv3 Score:
3.4
A Server-Side request forgery (SSRF) [CWE-918] vulnerability in FortiSIEM GUI may allow an authenticated attacker to send HTTP requests originating from the targeted device via specially crafted HTTP requests
Revised on 2026-08-12 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-159
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Stack buffer overflow in WAD
CVSSv3 Score:
5.1
A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled.
Revised on 2026-08-12 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-161
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
UI DoS attack
CVSSv3 Score:
5.0
An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web interface via crafted HTTP requests.
Revised on 2026-08-12 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-162
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack
What is the Attack?
Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromises resulting in operational disruptions. Attackers have gained access to exposed PLCs and manipulated their operation, demonstrating the potential for Internet-accessible OT systems to be directly abused to disrupt physical processes.
While the reported activity specifically references Rockwell Automation/Allen-Bradley MicroLogix PLCs, the targeting is not necessarily limited to these products, and other internet-facing PLCs may also be at risk.
The activity does not involve a specific CVE. Instead, attackers are taking advantage...
https://fortiguard.fortinet.com/threat-signal-report/6498
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday, including 236 vulnerabilities in Windows. This is lower volume than last month's record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month.SharePoint: critical RCE chain by Rapid7Today...
https://www.rapid7.com/blog/post/em-patch-tuesday-august-2026
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Beware of phishing emails disguised as requests to review quotes (PhantomStealer)
The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. The threat actor impersonated a sales team member at a specific overseas company and, by claiming that a previous quote needed to be revised and product versions verified, tricked recipients into opening the […]
https://asec.ahnlab.com/en/95000/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
July 2026 Infostealer Trend Report
Content This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026. It was compiled based on results from AhnLab SEcurity intelligence Center (ASEC)'s automated data collection system, email honeypots, and automated C2 analysis, as well as diagnostic logs […]
https://asec.ahnlab.com/en/95066/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.Our full disclosure timeline for the exploit chain can be seen below in Figure 1.Figure 1: The road to disclosure.⠀CVE-2026-63520 affects all supported versions of Microsoft SharePoint. An attacker can leverage CVE-2026-63520 to execute arbitrary code on a vulnerable SharePoint server with the privileges...
https://www.rapid7.com/blog/post/etr-cve-2026-63520-microsoft-sharepoint-remote-code-execution-fixed
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
OverviewOn July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) script.Figure 1: The Rapid7 Labs PoC for CVE-2026-55040.⠀A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or administrator. The vulnerability is due to several issues in the JWT token validation pipeline.AnalysisThe following technical analysis is based upon SharePoint Server Subscription Edition version 16.0.19725.20210.A critical authentication bypass vulnerability exists in SharePoint Server Subscription Edition's...
https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf server.
https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Water sector example added to the NCSC's Secure connectivity principles
New guidance is the first content authored by the Industrial Control System COI to appear on ncsc.gov.uk.
https://www.ncsc.gov.uk/blogs/water-sector-example-added-to-the-ncscs-secure-connectivity-principles
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
https://securelist.com/project-cav3rn-continues/120991/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Kimwolf v7: An Evolution of the Kimwolf Botnet
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.
The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.
https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.
The post The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications appeared first on Unit 42.
https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
TL;DR
Sonatype Research Labs identified six npm packages delivering the same malicious payload: three hijacked legitimate packages and three additional malicious packages, tracked as sonatype-2026-005899 and sonatype-2026-005901.
The malware uses the same Ethereum wallet address identified by OpenSourceMalware in activity attributed to the DPRK-linked Contagious Interview campaign, using the "NullReceiver" technique to locate infrastructure hosting additional JavaScript payloads.
Organizations that installed the affected versions should remove them and investigate the impacted environment for follow-on payload execution or compromise.
On August 10, 2026, Sonatype Research Labs identified six npm packages containing the same malicious payload, including three...
https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise.
The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/10/microsoft-named-a-leader-in-the-2026-idc-marketscape-for-mdr-mxdr-for-the-enterprise/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
July 2026 Dark Web Breach Incident Trend Report
Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
https://asec.ahnlab.com/en/94912/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
July 2026 Dark Web Threat Actor Trend Report
Note The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified. Major Issues Handala claimed to have compromised the core infrastructure of an Internet service provider in […]
https://asec.ahnlab.com/en/94917/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
July 2026 Dark Web Issue Trend Report
Note The July 2026 Dark Web Issue Trend Report summarizes major issues that occurred on the deep web and dark web. Due to the nature of some sources, it may be difficult to fully verify the accuracy of certain information; therefore, it is necessary to cross-check these details against official announcements. Major Issues RaidForums changed […]
https://asec.ahnlab.com/en/94918/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Attack Cases for Domestic Web Servers Running SoftEther VPN in Korea
The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN. Attack cases involving the installation of SoftEther VPN, an open-source VPN, were previously discussed in the 2024 ASEC blog post titled “Analysis of Attack Cases Targeting ERP Servers in Korea to Install SoftEther […]
https://asec.ahnlab.com/en/94995/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.
The post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
IT threat evolution in Q2 2026. Non-mobile statistics
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
IT threat evolution in Q2 2026. Mobile statistics
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Are AI tutors safe for your kids?
AI tutors can offer useful support, but their quality and safeguards vary widely. Here's what parents should check before handing one to a child.
https://www.welivesecurity.com/en/kids-online/ai-tutors-safe-kids/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Beware of Phishing Emails Disguised as Transaction Receipts
Recently, the AhnLab SEcurity intelligence Center (ASEC) identified instances of phishing emails that were disguised as transaction receipts. The emails impersonated employees of a specific US company. The body of the message stated that a transaction receipt was attached and asked the recipient to review it and confirm whether funds had been deposited into their […]
https://asec.ahnlab.com/en/95001/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Security Issues in the Korean & Global Financial Sector in July 2026
Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
https://asec.ahnlab.com/en/95109/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Alcon - 218,395 breached accounts
In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and physical address.
https://haveibeenpwned.com/Breach/Alcon
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Brinks Home - 732,162 breached accounts
In July 2026, Brinks Home was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from the company, including 732k unique email addresses and other personal information relating to leads, customers and Brinks staff such as name, phone numbers and physical addresses. The data also included purchases from Brinks along with partial credit card data (last 4 digits, card type and expiry). In Brinks' disclosure notice, they acknowledged the incident and risk of disclosure, and advised that they would notify impacted parties "consistent with applicable law".
https://haveibeenpwned.com/Breach/BrinksHome
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Inside the Modern SOC: The Identity Front Door
Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond.
The post Inside the Modern SOC: The Identity Front Door appeared first on Unit 42.
https://unit42.paloaltonetworks.com/soc-identity-front-door/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV 1.5.4 and 1.4.6 security patch versions published
Today, we are publishing the 1.5.4 and 1.4.6 security patch versions. The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub with both Alpine and Debian containers. The images on Docker Hub may not be immediately available on release day. Continue reading to learn what changed in each version. 1.5.4ClamAV 1.5.4 is a patch release with the following fixes:CVE-2026-20337: Fixed ZIP catalogue capacity tracking that could write beyond a heap allocation while indexing local file headers.This issue affects ClamAV 1.5.0 through 1.5.3. The fix is included in 1.5.4.Thank you to Kevin Stubbings of the GitHub Security Lab team for identifying this issue.CVE-2026-20345: Fixed an indexing error...
https://blog.clamav.net/2026/08/clamav-154-and-146-security-patch.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Russian hackers can steal emails without a click
https://www.proofpoint.com/us/newsroom/news/russian-hackers-can-steal-emails-without-click
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unsafe deserialization vulnerability affecting JetBrains TeamCity. An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process.JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) catalog, confirming exploitation in the wild.Our analysis finds that a vulnerable TeamCity server creates a permissive XStream allowlist. This allowlist is intended to restrict which Java classes can be deserialized when servicing unauthenticated...
https://www.rapid7.com/blog/post/ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Exact Sciences - 10,869,543 breached accounts
In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign. The group claimed to have obtained data from the company's cancer diagnostics business, which they later published publicly. The breach contained 10.9M unique email addresses belonging to customers, patients and healthcare providers, along with names, addresses, phone numbers and health records. Abbott subsequently published a public notice advising that "some of the impacted files contain personal information and/or personal health information" and that more specific information would follow once their review of the incident was complete. For context, Exact Sciences is the maker of the Cologuard at-home colorectal cancer screening test.
https://haveibeenpwned.com/Breach/ExactSciences
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ChainDrop: Inside a Self-Propagating npm Worm
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing.
The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42.
https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.
https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How we took malware advisories beyond npm
GitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid.
The post How we took malware advisories beyond npm appeared first on The GitHub Blog.
https://github.blog/security/supply-chain-security/how-we-took-malware-advisories-beyond-npm/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
16-31 July 2026 Cyber Attacks Timeline Infographic
103 confirmed cyber incidents reported between 15 and 31 July 2026 — including attacker motivations, top techniques, initial access vectors, hardest-hit sectors, and targeted countries, all in one interactive HACKMAGEDDON timeline.
https://www.hackmageddon.com/2026/08/06/16-31-july-2026-cyber-attacks-timeline-infographic/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
16-31 July 2026 Cyber Attacks Timeline
103 confirmed cyber incidents reported between 15 and 31 July 2026 — including attacker motivations, top techniques, initial access vectors, hardest-hit sectors, and targeted countries, all in one interactive HACKMAGEDDON timeline.
https://www.hackmageddon.com/2026/08/06/16-31-july-2026-cyber-attacks-timeline/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.
The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.
https://unit42.paloaltonetworks.com/ai-token-jacking/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
MAESTRO Analysis of OpenAI and Anthropic Agent Hacking Incidents
Two evaluation escapes in one week. Mapped onto the seven MAESTRO layers, one is an operations failure, and the other is an alignment failure, and the fix lists barely overlap.
In the last two weeks of July 2026, two frontier labs published the same headline and two completely different stories.
On 21 July, OpenAI confirmed that models it was benchmarking on ExploitGym had broken out of an isolated research network, chained zero-days in a self-hosted JFrog Artifactory proxy, and...
https://cloudsecurityalliance.org/articles/maestro-analysis-of-openai-and-anthropic-agent-hacking-incidents
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Secure Fast, Not Slow: What We Learned Building VibeGuard 2.0
Why the answer to secure agentic development isn't tighter restrictions - it's better developer tooling.
https://www.legitsecurity.com/blog/secure-fast-not-slow-what-we-learned-building-vibeguard-2.0
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Inter-Con Security - 276,114 breached accounts
In June 2026, Inter-Con Security was targeted in a ShinyHunters “pay or leak” extortion campaign. The group subsequently published data it alleged was taken from the company, including 276k unique email addresses along with names, physical addresses, job titles and phone numbers. The data encompassed a combination of contacts, internal users and leads.
https://haveibeenpwned.com/Breach/InterConSecurity
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
New Chaos Malware Variant Exploiting Misconfigurations in the Cloud
Originally published by Darktrace.
Introduction
To observe adversary behavior in real time, Darktrace operates a global honeypot network known as “CloudyPots”, designed to capture malicious activity across a wide range of services, protocols, and cloud platforms. These honeypots provide valuable insights into the techniques, tools, and malware actively targeting internet‑facing infrastructure.
One example of software targeted within Darktrace's honeypots is Hadoop, an open...
https://cloudsecurityalliance.org/articles/new-chaos-malware-variant-exploiting-misconfigurations-in-the-cloud
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Multi-Cloud Data Pipelines: Why Key Management Can't Be an Afterthought
Data pipelines are rarely simple anymore. A typical enterprise pipeline might ingest data in AWS, process it in Azure, send a subset to a SaaS analytics platform, and store the results in Google Cloud. That useful flexibility also creates a security problem. Every stage that processes or transmits sensitive data needs a clear encryption and key management strategy.
CSA's new research on multi-cloud key management solutions (KMS) emphasizes that data pipelines process and transmit large v...
https://cloudsecurityalliance.org/articles/multi-cloud-data-pipelines-why-key-management-can-t-be-an-afterthought
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Flooding Dropper Hits npm With 850 Malicious Packages
TL;DR
Sonatype Research Labs is tracking an active malicious package campaign, dubbed 'Flooding Dropper,' spreading on npm, currently impacting 846 software components.
The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases in the 35.x.y range.
When installed, the packages download and execute a second-stage payload, using multiple delivery methods to improve the attack's chances of success.
Sonatype is tracking this campaign as sonatype-2026-005660. Impacted organizations should consider the host compromised, remove the package, investigate secondary payload execution and persistence, and rotate exposed credentials only...
https://www.sonatype.com/blog/flooding-dropper-hits-npm-with-850-malicious-packages
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Impacket for Pentester: reg
Overview The Windows registry is a hierarchical database that governs application behaviour, user profiles, service configurations, security policies, and system startup. For penetration testers, remote
The post Impacket for Pentester: reg appeared first on Hacking Articles.
https://www.hackingarticles.in/impacket-for-pentester-reg/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
TL;DR
A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted.
The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages.
Organizations that installed an affected version should treat the environment as potentially compromised. Remove the malware and any persistence before revoking credentials, then rebuild from known-good components.
On August 4, 2026, Shai-Hulud re-emerged in the keyv and cacheable ecosystems on npm, quickly expanding into packages controlled by other maintainers, including packages in the @servicetitan namespace.
The affected releases use...
https://www.sonatype.com/blog/mini-shai-hulud-npm-attack-more-than-2200-components-impacted
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report.
The post Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/05/microsoft-named-a-leader-in-the-kuppingercole-leadership-compass-for-cloud-native-application-protection-platforms-cnapp/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities.
The post From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guidance for detection, hunting, and remediation.
The post ChainDrop supply chain compromise: Anatomy of a self-propagating worm appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance.
The post Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/04/advance-zero-trust-for-ai-new-tools-and-guidance-to-secure-ai-agents-and-devsecops/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread.
The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/04/129-seconds-disruption-microsoft-defender-stops-ransomware-qnet/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security
Atlanta, GA, 4th August 2026, CyberNewswire
Airlock Digital Unveils Agentic AI Control & Governance to Extend Preventative Endpoint Security on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/08/04/airlock-digital-unveils-agentic-ai-control-governance-to-extend-preventative-endpoint-security/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
5 Reasons Why Developers Still Download Malicious Packages
Engineering organizations deploy dependency scanners, train developers, secure endpoints, and establish policies for open source components. Yet malicious packages still reach developer workstations, build systems, and CI/CD environments.
https://www.sonatype.com/blog/5-reasons-developers-still-download-malicious-packages
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain.
The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appeared first on Unit 42.
https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Almost Half of Malware Samples Communicate Direct to IP
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats.
The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.
https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How legitimate cloud platforms enable phishers to bypass MFA
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
https://securelist.com/cloud-platforms-in-phishing/120832/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
NCSC statement in response to recent incidents resulting from frontier AI evaluations
A statement from Ollie Whitehouse, Chief Technology Officer at the NCSC, on AI security following recent incidents.
https://www.ncsc.gov.uk/news/ncsc-statement-in-response-to-recent-incidents-resulting-from-frontier-ai-evaluations
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today's Most Sophisticated Threats
https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-joins-google-unified-security-recommended-program-help
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities
https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-launches-oem-program-help-security-providers-embed-trusted-threat
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Pipeleek v1 Release
Pipeleek 1.0 is here. What started as a GitLab pipeline secret scanner now covers seven CI/CD platforms and comes with helpers for runner exploitation, Renovate bot abuse, and lateral movement across repositories. This post walks through what is new, shows two real-world findings from the Tor Project and GitLab itself, and introduces the GitLab Attack Lab where you can try the full attack chain yourself.
https://blog.compass-security.com/2026/08/pipeleek-v1-release/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
An analysis of incidents at Brazilian educational institutions
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.
https://securelist.com/incidents-at-brazilian-educational-institutions/120803/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A malware campaign disguised as an “undetected” version of the Xeno Roblox script executor is directly affecting players looking to download a legitimate tool.
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor.
The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appeared first on Unit 42.
https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Device Code Phishing Is How Midnight Blizzard Beat MFA on Hotel Wi-Fi
A Storm-2945 campaign layers device code phishing onto hijacked hotel Wi-Fi to bypass MFA on Microsoft 365 accounts. Here's how it works and how to shut it off.
Device Code Phishing Is How Midnight Blizzard Beat MFA on Hotel Wi-Fi on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/08/03/device-code-phishing-detection/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public
CVE-2026-16232 lets an unauthenticated attacker seize full admin control of Check Point's management console. Check Point confirms in-the-wild attacks, and a Rapid7 PoC is now public.
Check Point SmartConsole Authentication Bypass Is Under Active Attack, and a PoC Is Now Public on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/08/02/smartconsole-authentication-bypass/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A Skipped Cookie Check Let Flatpak Apps Escape PipeWire's Sandbox Entirely
CVE-2026-5674 chains a broken PulseAudio auth check, default module loading, and an unrestricted dlopen() into a full PipeWire sandbox escape from inside Flatpak apps like Discord.
A Skipped Cookie Check Let Flatpak Apps Escape PipeWire’s Sandbox Entirely on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/08/02/pipewire-sandbox-escape-cve-2026-5674/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Impacket for Pentester: atexec
Overview This article delivers a practical, hands-on walkthrough of Impacket-atexec, one of the most reliable remote command-execution utilities in an attacker’s or penetration tester’s arsenal.
The post Impacket for Pentester: atexec appeared first on Hacking Articles.
https://www.hackingarticles.in/impacket-for-pentester-atexec/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Active Directory Enumeration with BloodHound-Python
Overview BloodHound-python delivers a fast, cross-platform way to map the attack paths hidden inside an Active Directory environment. Instead of manually querying LDAP, dumping group
The post Active Directory Enumeration with BloodHound-Python appeared first on Hacking Articles.
https://www.hackingarticles.in/active-directory-enumeration-with-bloodhound-python/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Arsenal-NG: A Terminal Cheat-Sheet Launcher for Faster Penetration Testing
Overview Arsenal-NG is an interactive, terminal-based launcher that turns a sprawling collection of offensive-security tools into a single searchable command cheat-sheet. Instead of memorising flags
The post Arsenal-NG: A Terminal Cheat-Sheet Launcher for Faster Penetration Testing appeared first on Hacking Articles.
https://www.hackingarticles.in/arsenal-ng-pentest-cheat-sheet/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
SplitVPN - 865,336 breached accounts
In July 2026, the Russian VPN service SplitVPN (previously known as NotVPN) suffered a data breach. The incident exposed millions of customer records, including 865k unique email addresses. Other impacted data included IP addresses, the user's country, and partial payment card data (first 6 and last 4 digits plus expiry date).
https://haveibeenpwned.com/Breach/SplitVPN
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.
The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
This month in security with Tony Anscombe – July 2026 edition
OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup
https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-july-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Network Anomaly Detection in KATA
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.
https://securelist.com/tr/network-anomaly-detection-in-kata/120892/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Challenges in Defining Community Open Source | Sonatype
Exemptions sound relatively simple until you try to make them fair.
https://www.sonatype.com/blog/defining-community-open-source-is-harder-than-it-looks
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
https://www.proofpoint.com/us/newsroom/news/max-severity-exchange-server-flaw-under-active-exploitation-kremlin-hackers
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.
https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Why Your Business Needs a Secure Messaging Platform
Business communication has shifted almost entirely to digital channels, creating unprecedented efficiency but also exposing…
Why Your Business Needs a Secure Messaging Platform on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/30/why-your-business-needs-a-secure-messaging-platform/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Beyond the screenshot: Why you should verify what you see
The screenshot may look convincing, but it doesn't necessarily prove that the payment, booking or conversation is genuine
https://www.welivesecurity.com/en/cybersecurity/beyond-screenshot-why-verify-you-see/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
WordPress Core Unauthenticated RCE (WP2Shell)
What is the Attack?
FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code execution (RCE) attack chain affecting WordPress Core. Unlike most WordPress attacks that rely on vulnerable plugins or themes, WP2Shell impacts the WordPress core application itself, allowing attackers to compromise default installations without requiring any plugins or authentication. Public proof-of-concept (PoC) exploits are widely available, and active exploitation has been reported shortly after technical details were disclosed.
Successful exploitation may allow attackers to:
• Execute arbitrary code on the web server.
• Create unauthorized administrator...
https://fortiguard.fortinet.com/threat-signal-report/6492
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Tame Dependabot: Group your updates, slow the cadence, keep security fast
Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project.
The post Tame Dependabot: Group your updates, slow the cadence, keep security fast appeared first on The GitHub Blog.
https://github.blog/security/supply-chain-security/tame-dependabot-group-your-updates-slow-the-cadence-keep-security-fast/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities
Las Vegas, USA, 29th July 2026, CyberNewswire
Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/29/sweet-security-brings-autonomous-protection-to-the-ai-enterprise-with-new-blocking-capabilities/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Making forensic observability the norm for network devices
Progress is being made, but too many network devices still remain difficult to investigate after compromise
https://www.ncsc.gov.uk/blogs/making-forensic-observability-the-norm-for-network-devices
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
PTC Windchill & FlexPLM RCE
What is the Attack?
A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Management (PLM) systems to deploy web shells, steal intellectual property, and carry out double-extortion ransomware attacks.
The campaign chains a pre-authentication information disclosure vulnerability in the FlexPLM endpoint with CVE-2026-12569 to achieve unauthenticated remote code execution. Following compromise, attackers deploy JSP web shells, perform file system discovery, exfiltrate sensitive information, and ultimately issue ransom demands to affected...
https://fortiguard.fortinet.com/threat-signal-report/6491
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Disrupting supply chain attacks on npm and GitHub Actions
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact.
The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on The GitHub Blog.
https://github.blog/security/supply-chain-security/disrupting-supply-chain-attacks-on-npm-and-github-actions/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Public Exploit Lands for vBulletin's Pre-Auth RCE, CVE-2026-61511
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here's how the eval() injection works and who still needs to patch.
Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511 on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/28/vbulletin-rce-vulnerability-cve-2026-61511/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
When cyber attacks happen: helping organisations recover
A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.
https://www.ncsc.gov.uk/blogs/when-cyber-attacks-happen-helping-organisations-recover
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Houston City College - 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic records, and other personal information relating to both current students and alumni.
https://haveibeenpwned.com/Breach/HoustonCityCollege
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Ill Bloom Vulnerability: How to Check If Your Wallet Is Exposed
A weak random-number generator behind the Ill Bloom vulnerability has let attackers drain over million from crypto wallets. Here's how to check exposure and fix it.
The Ill Bloom Vulnerability: How to Check If Your Wallet Is Exposed on Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses.
https://latesthackingnews.com/2026/07/26/ill-bloom-vulnerability-check/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors
https://www.proofpoint.com/us/newsroom/news/new-warnings-russian-operatives-are-targeting-emails-us-nuclear-scientists-and-defense
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
https://www.proofpoint.com/us/newsroom/news/russian-espionage-group-exploited-zimbra-zero-day-steal-mail-and-2fa-codes
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
US and allies say Russian hackers stole emails without social engineering
https://www.proofpoint.com/us/newsroom/news/us-and-allies-say-russian-hackers-stole-emails-without-social-engineering
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The case for a cooldown: Why Dependabot now waits before issuing version updates
A new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code.
The post The case for a cooldown: Why Dependabot now waits before issuing version updates appeared first on The GitHub Blog.
https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
UK and partners expose Russian state-supported actors for new ‘zero-click' phishing campaign targeting Western organisations
GCHQ's National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR' cyber threat group exposed for targeted phishing campaign
https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
1-15 July 2026 Cyber Attacks Timeline Infographic
Cyber Crime dominated the first half of July 2026, driving 76.5% of all confirmed activity, with Malware the clear weapon of choice at 43.5% of attack techniques. Exploitation of public-facing applications (MITRE T1190) led initial access methods at 27.6%, while Information & Communication infrastructure bore the brunt of targeting, accounting for 32% of sector hits — well ahead of Public Administration and Financial Services.
https://www.hackmageddon.com/2026/07/23/1-15-july-2026-cyber-attacks-timeline-infographic/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
1-15 July 2026 Cyber Attacks Timeline
85 confirmed cyber incidents shaped the first half of July 2026, with cyber crime accounting for more than three-quarters of all attacks. Malware — spanning RATs, infostealers, spyware, and backdoors — was the dominant weapon, involved in 37 of 85 incidents (43.5%). Information & Communication infrastructure emerged as the hardest-hit sector, targeted in nearly 1 in 3 sector mentions.
https://www.hackmageddon.com/2026/07/23/1-15-july-2026-cyber-attacks-timeline/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
If you pay a hacker's ransom, chances are that they'll come back for more
https://www.proofpoint.com/us/newsroom/news/if-you-pay-hackers-ransom-chances-are-theyll-come-back-more
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Next chapter: Restructuring GitHub's bug bounty program
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team.
The post Next chapter: Restructuring GitHub’s bug bounty program appeared first on The GitHub Blog.
https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Post-quantum cryptography (PQC) migration workshop report
No organisation can navigate the migration alone; key takeaways from our first PQC migration workshop.
https://www.ncsc.gov.uk/blogs/post-quantum-cryptography-pqc-migration-workshop-report
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective
https://www.proofpoint.com/us/newsroom/press-releases/proofpoint-research-finds-65-organizations-affected-ransomware-say-ai-made
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.
https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
We Wrote an Academic Paper on Conficker in 2026
And it’s over 16,000 words. While the rest of the cybersecurity world moves on with AI and next generation technologies, the OT cybersecurity community is oft left behind, dealing with increasingly unique legacy challenges and tech debt. One of the biggest issues we have had to start tackling is the discovery of deep, embedded commodity […]
https://tisiphone.net/2026/07/21/we-wrote-an-academic-paper-on-conficker-in-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Windows Privilege Escalation: SeRestorePrivilege
Overview SeRestorePrivilege is a Windows special privilege that allows its holder to restore files and directories, effectively bypassing discretionary access controls on the file system.
The post Windows Privilege Escalation: SeRestorePrivilege appeared first on Hacking Articles.
https://www.hackingarticles.in/windows-privilege-escalation-serestoreprivilege/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Hidden Privilege of Automation Platforms
Automation platforms such as n8n are often introduced as productivity tools: connect a few systems, automate repetitive work, maybe add some AI. Inside a corporate network, however, that framing is incomplete. A self-hosted workflow engine can reach internal systems, execute actions on behalf of users, and hold sensitive credentials. That puts it in the same […]
https://blog.compass-security.com/2026/07/the-hidden-privilege-of-automation-platforms/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Suno - 55,282,226 breached accounts
In November 2025, AI music generation tool Suno suffered a data breach that later came to light in July the following year. The data contained over 55M unique email addresses. Phone numbers were also present where they had been used as the sign-up method. Although representing a small portion of the corpus, the breach also included tens of thousands of Stripe records relating to purchases, containing names, physical addresses, purchase amounts and partial credit card data including the card type, expiry date and last 4 digits. The company advised that "Suno does not have access to customers' full credit card numbers in Stripe".
https://haveibeenpwned.com/Breach/Suno
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Joomla SP Page Builder RCE
What is the Vulnerability?
FortiGuard telemetry shows continued exploitation attempts targeting vulnerable Joomla SP Page Builder installations. CVE-2026-48908 is a critical unauthenticated remote code execution (RCE) vulnerability affecting the SP Page Builder extension for Joomla. The flaw allows attackers to upload arbitrary PHP files through the custom icon upload functionality without authentication, potentially enabling remote code execution and full server compromise.
Public proof-of-concept (PoC) exploit code is available, and active exploitation has been observed. The sustained increase in weekly exploitation activity indicates ongoing automated scanning campaigns targeting Internet-facing Joomla servers, highlighting...
https://fortiguard.fortinet.com/threat-signal-report/6489
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
H1 2026 Cyber Attacks Statistics Infographic
Last Updated on July 16, 2026 Bundled Page This page requires JavaScript to display. H1 Unpacking…
https://www.hackmageddon.com/2026/07/16/h1-2026-cyber-attacks-statistics-infographic/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
H1 2026 Cyber Attacks Statistics
In H1 I recorded 1,071 confirmed cyber incidents. Financially motivated Cyber Crime drove nearly 7 in 10 attacks, malware remained the top weapon (40.5% of attack-vector entries), and exploitation of public-facing applications was the leading initial access technique (23.7%). Cyber Espionage accounted for roughly 1 in 5 incidents, with the Information & Communication sector bearing the heaviest targeting (26.1% of classified events).
https://www.hackmageddon.com/2026/07/16/h1-2026-cyber-attacks-statistics/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Windows Privilege Escalation: SeTcbPrivilege
Overview SeTcbPrivilege — formally “Act as part of the operating system” — is one of the most powerful Windows privileges in existence. It grants the
The post Windows Privilege Escalation: SeTcbPrivilege appeared first on Hacking Articles.
https://www.hackingarticles.in/windows-privilege-escalation-setcbprivilege/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Helping small businesses with free, hands-on cyber consultancy
Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.
https://www.ncsc.gov.uk/blogs/helping-small-businesses-with-free-hands-on-cyber-consultancy
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Q2 2026 Cyber Attacks Statistics
Q2 2026 brought 578 recorded cyber incidents worldwide, with financially-motivated cyber crime accounting for over 71% of the total. Malware remained the attacker's weapon of choice, exploiting public-facing applications as the leading entry point. Information & Communication stood out as the hardest-hit sector.
https://www.hackmageddon.com/2026/07/14/q2-2026-cyber-attacks-statistics/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Q2 2026 Cyber Attacks Statistics Infographic
Last Updated on July 14, 2026 Cyber Attacks Statistics — Q2 2026 Q2 Threat Intelligence Briefing Cyber AttacksQ2 2026 543 confirmed incidents between 1 April and 30 June 2026. Financially motivated Cyber Crime drove over 7 in 10 attacks, Malware remained the weapon of choice, and Information & Communication infrastructure absorbed the heaviest targeting. 0 […]
https://www.hackmageddon.com/2026/07/14/q2-2026-cyber-attacks-statistics-infographic/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Forgotten UEFI shims undermining Secure Boot
ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old vulnerabilities
https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Buffer overread in authd and wad daemon
CVSSv3 Score:
4.1
A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-154
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cross-Site Scripting in Domain parameter
CVSSv3 Score:
5.3
An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests.
Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-149
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Header injection in Web Filter warning page
CVSSv3 Score:
3.4
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.
Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-152
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Header injection in captive portal authentication form
CVSSv3 Score:
3.1
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests.
Revised on 2026-07-14 00:00:00
https://fortiguard.fortinet.com/psirt/FG-IR-26-153
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Lessons Learned from CISA's Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.
https://krebsonsecurity.com/2026/07/lessons-learned-from-cisas-recent-github-leak/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Windows Privilege Escalation: SeTakeOwnershipPrivilege
Overview This article demonstrates how a single delegated user right — SeTakeOwnershipPrivilege — can be weaponised to elevate a standard domain user to full SYSTEM
The post Windows Privilege Escalation: SeTakeOwnershipPrivilege appeared first on Hacking Articles.
https://www.hackingarticles.in/windows-privilege-escalation-setakeownershipprivilege/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
UK and Allies urge critical sectors to improve defences against Russian intelligence targeting
New advisory highlights Russian state cyber actors' global exploitation of poorly configured routers
https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How GitHub gave every repository a durable owner
GitHub had over 14,000 repositories. Fewer than half had clear ownership. Here's how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed.
The post How GitHub gave every repository a durable owner appeared first on The GitHub Blog.
https://github.blog/security/application-security/how-github-gave-every-repository-a-durable-owner/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cyber Essentials Pathways: from proof of concept to cyber confidence
An alternative path to Cyber Essentials Plus certification, without compromising the integrity of the scheme.
https://www.ncsc.gov.uk/blogs/cyber-essentials-pathways-from-proof-of-concept-to-cyber-confidence
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Ubiquiti UniFi OS RCE
What is the Vulnerability?
Multiple critical vulnerabilities affecting Ubiquiti UniFi OS can be chained together to achieve unauthenticated remote code execution (RCE) with root privileges. The vulnerabilities include CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, which together bypass authentication, access protected resources, and execute arbitrary operating system commands.
The vulnerabilities impact UniFi OS deployments used to manage enterprise networking infrastructure, including gateways, network controllers, video surveillance, and access control systems. Researchers have publicly demonstrated the exploit chain, and the vulnerabilities have been confirmed as actively exploited in the wild. Organizations should...
https://fortiguard.fortinet.com/threat-signal-report/6475
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Windows Privilege Escalation: SeDebugPrivilege
Overview This article delivers an end-to-end walkthrough of how a single delegated user right — SeDebugPrivilege — collapses the security boundary between a standard domain
The post Windows Privilege Escalation: SeDebugPrivilege appeared first on Hacking Articles.
https://www.hackingarticles.in/windows-privilege-escalation-sedebugprivilege/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Wireless Pentesting with Claude Using the Aircrack MCP Server
Overview Wireless networks remain one of the most exposed and frequently overlooked attack surfaces across enterprise and consumer environments. This article introduces the Aircrack-ng MCP
The post Wireless Pentesting with Claude Using the Aircrack MCP Server appeared first on Hacking Articles.
https://www.hackingarticles.in/wireless-pentesting-with-claude-using-the-aircrack-mcp-server/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ESET Threat Report H1 2026
A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.
https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cyber Resilience Act – Part II
In this second part, we demonstrate how a Cyber Resilience Act (CRA) assessment is performed in practice. Using a low-cost IP camera as an example, we show how a product is classified, how threats are modelled, how hardware and firmware are analysed, and how compliance gaps against IEC 62443-4-2 can be identified. You may want […]
https://blog.compass-security.com/2026/07/cyber-resilience-act-part-ii/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Ivanti Sentry Pre-Authentication RCE
What is the Vulnerability?
FortiGuard Labs continues to observe exploitation attempts targeting CVE-2026-10520 following the public release of technical details and proof-of-concept (PoC) exploit code.
CVE-2026-10520 is a critical vulnerability affecting Ivanti Sentry that allows remote, unauthenticated attackers to execute arbitrary operating system commands with root privileges. The flaw stems from improper handling of internal configuration commands exposed through an externally accessible API, enabling complete device compromise without valid credentials.
Shortly after disclosure, watchTowr published a detailed technical analysis and public PoC, significantly lowering the barrier to exploitation and...
https://fortiguard.fortinet.com/threat-signal-report/6472
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cyber readiness for SMBs: Getting the basics right
AI is changing cybercrime, but SMB cyber readiness still largely depends on closing the familiar gaps
https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.
https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How GitHub used secret scanning to reach inbox zero
GitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here's how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months.
The post How GitHub used secret scanning to reach inbox zero appeared first on The GitHub Blog.
https://github.blog/security/application-security/how-github-used-secret-scanning-to-reach-inbox-zero/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV 1.5.3 and 1.4.5 security patch versions published
Today, we are publishing the 1.5.3 and 1.4.5 security patch versions. The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub with both Alpine and Debian containers. The images on Docker Hub may not be immediately available on release day. Continue reading to learn what changed in each version. 1.5.3 ClamAV 1.5.3 is a patch release with the following fixes:CVE-2026-20217: Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner.This issue affects ClamAV 1.5.2, 1.4.4, and all prior versions as far back as 2005. The fix is included in 1.5.3 and 1.4.5.Thank you to Atuin - Automated Vulnerability Discovery Engine, Tianchu...
https://blog.clamav.net/2026/07/clamav-153-and-145-security-patch.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
6 security settings every GitHub maintainer should enable this week
These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before.
The post 6 security settings every GitHub maintainer should enable this week appeared first on The GitHub Blog.
https://github.blog/security/6-security-settings-every-github-maintainer-should-enable-this-week/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
This month in security with Tony Anscombe – June 2026 edition
Three-day patching deadlines, exposed fuel-tank systems, scams costing billions of dollars, and social media bans for children all gave Tony plenty to unpack in June 2026
https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-june-2026/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Verifiable Digital Credential Presentment
This blog post is #4 in our series on Verifiable Digital Credentials (VDCs). Our other posts can be found via Post #1, Post #2, and Post #3. In earlier posts, we discussed how verifiable digital credentials (VDCs) are issued and compared the underlying credential formats (ISO/IEC “mdoc” vs. W3C Verifiable Credentials). In this post, we turn to the other side of the story: presentation; that is, how a holder shows their VDC to a verifier at runtime in both in-person and online contexts. We'll again explore the mobile driver's license (mDL) use case, consider the differences between ISO/IEC
https://www.nist.gov/blogs/cybersecurity-insights/verifiable-digital-credential-presentment
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Splunk Enterprise Authentication Bypass Vulnerability
What is the Attack?
A critical authentication bypass vulnerability, CVE-2026-20253 (CVSS 9.8), affects Splunk Enterprise versions 10.0.x and 10.2.x. The flaw stems from missing authentication on a PostgreSQL sidecar service endpoint, allowing an unauthenticated attacker to create or truncate arbitrary files on a vulnerable server.
Security researchers have demonstrated that the vulnerability can be leveraged toward pre-authentication remote code execution (RCE) under certain conditions, and active exploitation has been confirmed. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) Catalog, making it a high-priority patching target for organizations running exposed Splunk Enterprise instances.
...
https://fortiguard.fortinet.com/threat-signal-report/6470
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Inside the Advisory Database and what happens when vulnerability volume breaks records
The GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help.
The post Inside the Advisory Database and what happens when vulnerability volume breaks records appeared first on The GitHub Blog.
https://github.blog/security/supply-chain-security/inside-the-advisory-database-and-what-happens-when-vulnerability-volume-breaks-records/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Inside the inbox: Why cybercriminals want to break into your email account
Your inbox is an identity system all of its own: whoever owns it may own a lot more
https://www.welivesecurity.com/en/cybersecurity/inside-inbox-cybercriminals-want-break-email-account/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cyber Resilience Act – Part I
The Cyber Resilience Act (CRA) is a regulation introduced by the European Union to strengthen cybersecurity requirements for products with digital elements.In simple terms, the CRA sets mandatory cybersecurity rules for hardware and software sold in the EU. This includes everything from connected devices (IoT) to operating systems and even stand-alone software. Very important, this […]
https://blog.compass-security.com/2026/06/cyber-resilience-act-part-i/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Oracle PeopleSoft Zero-Day
What is the Attack?
Google Threat Intelligence Group (GTIG) and Mandiant have identified an active compromise and extortion campaign attributed to ShinyHunters (tracked as UNC6240) targeting Oracle PeopleSoft environments. The attackers exploited a previously unknown remote code execution vulnerability, CVE-2026-35273, before Oracle released an advisory and patches, making this a true zero-day attack. The campaign primarily targeted higher education institutions, with approximately 68% of identified victims belonging to the education sector.
Organizations running internet-accessible Oracle PeopleSoft Environment Management components are at highest risk. Successful exploitation enables unauthenticated remote code execution,...
https://fortiguard.fortinet.com/threat-signal-report/6468
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability
What is the Vulnerability?
Cisco has disclosed a critical security vulnerability, CVE-2026-20245, affecting Cisco Catalyst SD-WAN Manager and confirmed that it is being actively exploited in the wild. The vulnerability resides in the platform's command-line interface (CLI) and allows an authenticated attacker with netadmin privileges to execute arbitrary commands as root on the underlying operating system.
According to Cisco, successful exploitation has been observed in real-world attacks and has resulted in unauthorized configuration changes being pushed to managed SD-WAN edge devices. At the time of disclosure, Cisco had not released a software fix or workaround and instead provided indicators of compromise and investigation...
https://fortiguard.fortinet.com/threat-signal-report/6456
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Advancing Product Security: New IoT Guidance and New Engagement
It may be summertime, but the NIST Cybersecurity for the Internet of Things (IoT) Program isn't hitting the hammock! Organizations are managing growing device complexity, evolving threats, and pressure to turn guidance into operational decisions…so we remain focused on helping stakeholders apply security guidance in ways that are practical and actionable. What's Been Happening Lately? An initial public draft (IPD) of NIST SP 800-213 Revision 1, IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements is out now for your review and
https://www.nist.gov/blogs/cybersecurity-insights/advancing-product-security-new-iot-guidance-and-new-engagement
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.
https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
A Bitdefender Labs investigation identified more than 55 fake-shop campaigns targeting consumers across 12 European countries between March and May 2026. The campaigns mimicked some of the world's most recognizable brands, including Samsung, Nike, Adidas, ZARA, H&M, Amazon, Lidl, and SHEIN.
https://www.bitdefender.com/en-us/blog/labs/fake-shops-europe-samsung-world-cup-scams
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
GitHub Locks Down npm: What the New Install Defaults Mean for Your Supply Chain
https://www.legitsecurity.com/blog/github-locks-down-npm-what-the-new-install-defaults-mean-for-your-supply-chain
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Agentic AppSec: closing the remediation gap and automating application security
Application security has spent a decade getting brilliant at half of its job. This is about automating the other half – starting with the fix, and not stopping there.
https://www.legitsecurity.com/blog/agentic-appsec-closing-the-remediation-gap-and-automating-the-rest-of-application-security
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Government Just Made Our Case: Stop Fixing Everything, Fix What Matters.
CISA made risk-based prioritization federal policy. That's the problem we've been working on for years.
https://www.legitsecurity.com/blog/the-government-just-made-our-case-stop-fixing-everything-fix-what-matters
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Drupal Core CVE-2026-9082 Active Exploitation Confirmed Within Days of Disclosure
Sensor Intel Series: June 2026 CVE Trends
https://www.f5.com/labs/articles/drupal-core-cve-2026-9082-active-exploitation-confirmed-within-days-of-disclosure
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fable 5 Is Here. The AppSec Problem Hasn't Changed.
https://www.legitsecurity.com/blog/fable-5-is-here-the-appsec-problem-hasnt-changed
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Entra Agent ID from a Security Perspective
AI agents in your Entra ID tenant? They come with new identities, permissions, and fresh attack paths.
Christian Feuchter breaks down Entra Agent ID security, security-relevant capabilities, control paths, abuse scenarios, and how to review your exposure with EntraFalcon.
https://blog.compass-security.com/2026/06/entra-agent-id-from-a-security-perspective/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ComoDoS - Exploiting a Remote Kernel Vulnerability in Comodo Internet Security
Sometimes firewall stops attackers, sometimes attackers stop firewall. analyzing a zero-day vulnerability in Comodo Internet Security's Firewall driver.
https://malwaretech.com/2026/06/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Inside APAC's malvertising ecosystem: How scams spread through social media ads
Bitdefender Labs has uncovered a large-scale malvertising ecosystem operating across APAC, where scam campaigns are distributed through paid advertising on Meta platforms and quickly generate massive reach.
Key takeaways
* Bitdefender Labs identified 12,000 scam campaigns across 13 APAC countries
* These campaigns generated more than 400,000 ad sightings through paid ads on Meta platforms
* Health and finance are the leading scam categories, together accounting for 37.3% of all campaigns
https://www.bitdefender.com/en-us/blog/labs/inside-the-apac-malvertising-ecosystem
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Football Fever Fuels Scam Campaigns Across Email and Social Media
Football fans are increasingly targeted by scams exploiting club loyalty, national teams, football collectibles, streaming demand, and the growing excitement around the FIFA World Cup 2026, according to Bitdefender Labs.
Our most recent investigation uncovered more than 55 football-related malvertising campaigns targeting users through fake online stores, social media ads, IPTV piracy operations, fraudulent football apps, and FIFA-themed giveaway and lottery scams distributed through email.
K
https://www.bitdefender.com/en-us/blog/labs/football-fever-fuels-scam-campaigns-across-email-and-social-media
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
SSH Labs
SSH is a widely used protocol that provides secure access to remote systems. It enables encrypted communication, file transfers, command execution and shell access for system administration.
Visit https://sshlabs.compass-security.training to learn more about SSH security.
https://blog.compass-security.com/2026/05/ssh-labs/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Missing Security Layer in AI-First Development
https://www.legitsecurity.com/blog/the-missing-security-layer-in-ai-first-development
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Microsoft's MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
Bitdefender security researchers have discovered that attackers continue to exploit Microsoft HTML Application Host (MSHTA), a legacy utility available by default on Windows systems that can execute VBScript and JavaScript from local or remote files.
https://www.bitdefender.com/en-us/blog/labs/microsofts-mshta-legacy-malware-windows
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain for the Pixel 9, we wanted to see if it was possible to write a similar exploit chain for Pixel 10. Updating the Dolby Exploit Altering our exploit for CVE-2025-54957 was fairly straightforward. The majority of needed changes involved updating offsets calculated for the specific version of the library we targeted on the Pixel 9 to similar offsets in the library for Pixel 10. The only challenge (outside of wishing we'd better documented which syncframes contained offsets) was that the Pixel 10...
https://projectzero.google/2026/05/pixel-10-exploit.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Introducing RAPTR
I'm happy to announce that we are releasing the beta version of RAPTR, a fully open source, API driven collaboration platform built specifically for red and purple team engagements.
https://blog.compass-security.com/2026/05/introducing-raptr/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Stronger Cybersecurity, Stronger Business: NIST Celebrates 2026 National Small Business Week
Happy National Small Business Week! For over 60 years, the U.S. Small Business Administration has led this initiative to acknowledge the critical contributions of America's entrepreneurs and small business owners. Part of the U.S. Department of Commerce, NIST's mission is to drive U.S. innovation and global competitiveness, and the small business community is central to this mission. In this year's blog, we shine a spotlight on some new and upcoming NIST resources that are all focused on strengthening the cybersecurity and resilience of the nation's small business community. Build Your Small
https://www.nist.gov/blogs/cybersecurity-insights/stronger-cybersecurity-stronger-business-nist-celebrates-2026-national
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Operation Road Trap: Fake toll and parking texts are spreading worldwide
A new mass smishing campaign uncovered by Bitdefender Labs shows that scammers are sending tens of thousands of fraudulent text messages to mobile users across 12 countries, impersonating transport authorities, toll operators, and parking services.
Key takeaways
* Since December 2025, Bitdefender Labs researchers have been tracking smishing campaigns targeting drivers on a global scale. The scam campaigns are still active as of April 2026
* Over 79,000 fraudulent messages have already been
https://www.bitdefender.com/en-us/blog/labs/operation-road-trap
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
From DMV to Wallet: Understanding Verifiable Digital Credential Issuance
In our last post in this series, we compared two credential formats that shape the digital identity ecosystem: ISO/IEC 18013-5 and -7 mobile documents (mdocs) and W3C Verifiable Credentials (VCs). Both formats define how a credential is structured and shared, but neither can function without an issuance process. This blog post explores what it takes to issue verifiable digital credentials, with a focus on mobile driver's licenses (mDLs). We'll look at how issuance works today in practice, where inconsistencies exist, and how standards bodies (FIDO, ISO and OpenID Foundation) are working to
https://www.nist.gov/blogs/cybersecurity-insights/dmv-wallet-understanding-verifiable-digital-credential-issuance
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Tabletop Simulations: Where Theory Meets Reality
On paper, the vast majority of crisis plans look reasonable, actionable and complete. Once the rubber hits the road, however, chaos emerges quickly.
https://blog.compass-security.com/2026/04/tabletop-simulations-where-theory-meets-reality/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Scaling Our Vision: Welcoming Tamar Nulman and Omri Arnon to the Legit Team
https://www.legitsecurity.com/blog/scaling-our-vision-welcoming-tamar-nulman-and-omri-arnon-to-the-legit-team
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AI threats in the wild: The current state of prompt injections on the web
Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the security community, anticipating it as a primary attack vector for adversaries to target and compromise AI agents. But while the danger of IPI is widely discussed, are threat actors actually exploiting this vector today – and if so, how?To answer these questions and to uncover real-world abuse, we initiated a broad sweep of the public web to monitor for known indirect prompt injection patterns. This is what we found. The threat of indirect prompt injectionUnlike a direct injection where a user...
http://security.googleblog.com/2026/04/ai-threats-in-wild-current-state-of.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Azure-Hosted Scanning Cluster Launches WordPress Webshell Discovery Campaign
Sensor Intel Series: March 2026 CVE Trends
https://www.f5.com/labs/articles/azure-hosted-scanning-cluster-launches-wordpress-webshell-discovery-campaign
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Common Entra ID Security Assessment Findings – Part 4: Weak Conditional Access Policies
This post is part of a small blog series covering common Entra ID security findings observed during real-world assessments. Each article explores selected findings in more detail to provide a clearer understanding of the underlying risks and practical implications. Conditional Access Policies Conditional Access policies are among the most important security controls in Entra ID. […]
https://blog.compass-security.com/2026/04/common-entra-id-security-assessment-findings-part-4-weak-conditional-access-policies/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Just for Fun – An Unofficial Pen Test Game Module for D&D 5e
Friends, I built an unlicensed, totally unofficial module for my local gaming group based on Dungeons and Dragons 5th Edition, specifically the amazing “Keys from the Golden Vault” heist book. You can download it here. It cannot be resold, and please credit me in distribution. Love to hear your feedback from playtests!
https://tisiphone.net/2026/04/13/just-for-fun-an-unofficial-pen-test-game-module-for-dd-5e/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team
Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities. For Pixel 10, Google is advancing its proactive security measures further. Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware. The new Rust-based DNS parser significantly reduces our security risk by mitigating an entire class of vulnerabilities in a risky area, while also laying...
http://security.googleblog.com/2026/04/bringing-rust-to-pixel-baseband.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Mythos: Just One Piece of the Cybersecurity Puzzle
https://www.legitsecurity.com/blog/mythos-just-one-piece-of-the-cybersecurity-puzzle
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Protecting Cookies with Device Bound Session Credentials
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team
Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upcoming Chrome release. This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.
Session theft typically occurs when a user inadvertently downloads malware onto their device. Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server. Infostealer malware...
http://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Google Workspace's continuous approach to mitigating indirect prompt injections
Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user's query. This may even be possible without any input directly from the user.IPI is not the kind of technical problem you “solve” and move on. Sophisticated LLMs with increasing use of agentic automation combined with a wide range of content create an ultra-dynamic and evolving playground for adversarial attacks. That's why Google takes a sophisticated and comprehensive approach to these attacks. We're continuously...
http://security.googleblog.com/2026/04/google-workspaces-continuous-approach.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
VRP 2025 Year in Review
Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our vulnerability reward program (VRP) has seen constant additions and expansions over the past decade and a half, clearly indicating the value the programs under this umbrella contribute to the safety and security of Google and its users, but also highlighting their acceptance by the external research community, without which such programs cannot function.Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer. This was more evident...
http://security.googleblog.com/2026/03/vrp-2025-year-in-review.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Posted by Eric Lynch, Product Manager, Android and Dom Elliott, Group Product Manager, Google Play
Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve "impossible" problems in drug discovery, materials science, and energy—tasks that even the most powerful classical supercomputers cannot handle. However, the same unique ability to consider different options simultaneously also allows these machines to bypass our current digital locks. This puts the public-key cryptography we've relied on for decades at risk, potentially compromising everything from bank transfers to trade secrets. To secure our future, it is vital to adopt the new Post-Quantum Cryptography (PQC) standards National Institute of Standards and Technology (NIST) is urging...
http://security.googleblog.com/2026/03/post-quantum-cryptography-in-android.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
MSSQLand – Lightweight MS-SQL Interaction Tool for Lateral Movement and Post-Exploitation
MSSQLand enables red teams to interact with MS-SQL servers and linked instances in restricted environments without complex T-SQL queries. Assembly-ready tool for lateral movement.
https://www.darknet.org.uk/2026/03/mssqland-lightweight-ms-sql-interaction-tool-for-lateral-movement-and-post-exploitation/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Reflections from the Second NIST Cyber AI Profile Workshop
Thank you to everyone who participated in the Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile) Workshop in January! The input we received on the Preliminary Draft during this workshop has been invaluable and is informing the development of the next draft of the NIST Cyber AI Profile. We are working toward publishing a full workshop summary soon that captures themes and highlights from the event. In the interim, we would like to share a preview of what we heard… Background on the Second Cyber AI Profile Workshop This workshop was a continuation of the past months
https://www.nist.gov/blogs/cybersecurity-insights/reflections-second-nist-cyber-ai-profile-workshop
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
All aboard: the NIST Cybersecurity for IoT Program is headed to our next stop! Share your input on where we're headed during our Future Directions Two-Day Workshop on March 31st.
Workshop Details… We're looking forward to hearing from the community during our “Future Directions” Workshop! Date: March 31 - April 1, 2026 Where: NIST's Gaithersburg campus! Registration and Details: HERE Can't make it? We still want to hear from you – email us at IoTSecurity [at] nist.gov (IoTSecurity[at]nist[dot]gov). All Aboard for Product Cybersecurity The NIST Cybersecurity for Internet of Things (IoT) Program was established to help real-world practitioners navigate the gray areas between IT and connected products. This provides clarity when it comes to challenges, available existing resources, and understanding where
https://www.nist.gov/blogs/cybersecurity-insights/all-aboard-nist-cybersecurity-iot-program-headed-our-next-stop-share
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Windsurf IDE Extension Drops Malware via Solana Blockchain
Bitdefender researchers have discovered a malicious Windsurf IDE (integrated development environment) extension that deploys a multi-stage NodeJS stealer by using the Solana blockchain as the payload infrastructure.
https://www.bitdefender.com/en-us/blog/labs/windsurf-extension-malware-solana
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Windows and macOS Malware Spreads via Fake “Claude Code” Google Ads
Bitdefender's security researchers have discovered a malicious Google Ads campaign targeting anyone searching for downloads related to Claude, the large language model developed by Anthropic.
https://www.bitdefender.com/en-us/blog/labs/fake-claude-code-google-ads-malware
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Credential Stuffing in 2025 – How Combolists, Infostealers and Account Takeover Became an Industry
Credential stuffing drove 22% of all breaches in 2025. How combolists, infostealers and ATO tooling are fuelling enterprise account takeover at scale
https://www.darknet.org.uk/2026/03/credential-stuffing-in-2025-how-combolists-infostealers-and-account-takeover-became-an-industry/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Global Scam Machines: Inside a Meta-Powered Investment Fraud Ecosystem Spanning 25 Countries
In February-March 2026, Bitdefender Labs identified and mapped a sprawling global scam infrastructure and scalable disinformation-for-profit network that uses trusted news brands, real personalities, fabricated media narratives, emotional hooks, and advanced evasion techniques to drive victims into investment fraud funnels.
On February 9-March 5, 2026, we analyzed 310 malvertising campaigns distributed through paid advertising on Meta platforms.
Key findings:
* This is a global, coordinated
https://www.bitdefender.com/en-us/blog/labs/global-investment-scam-network-using-meta-ads
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
DumpBrowserSecrets – Browser Credential Harvesting with App-Bound Encryption Bypass
DumpBrowserSecrets extracts saved passwords, cookies, OAuth tokens and autofill data from Chrome, Edge, Firefox, Opera and Vivaldi, bypassing App-Bound Encryption via Early Bird APC injection.
https://www.darknet.org.uk/2026/03/dumpbrowsersecrets-browser-credential-harvesting-with-app-bound-encryption-bypass/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CASI Leaderboard Shifts: Sugar-Coated Poison, and the Expanding AI Attack Surface
AI Security Insights – March 2026
https://www.f5.com/labs/articles/casi-leaderboard-shifts-sugar-coated-poison-and-the-expanding-ai-attack-surface
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
On the Effectiveness of Mutational Grammar Fuzzing
Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar that describes the structure of the samples. When a sample gets mutated, the mutations happen in such a way that any resulting samples still adhere to the grammar rules, thus the structure of the samples gets maintained by the mutation process. In case of coverage-guided grammar fuzzing, if the resulting sample (after the mutation) triggers previously unseen code coverage, this sample is saved to the sample corpus and used as a basis for future mutations. This technique has proven capable of finding complex issues and I have used it successfully in the past, including to find issues in XSLT implementations in web browsers and even JIT engine bugs. However, despite the approach being effective, it...
https://projectzero.google/2026/03/mutational-grammar-fuzzing.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV 1.5.2 and 1.4.4 security patch versions published
Today, we are publishing the 1.5.2 and 1.4.4 security patch versions. The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub with both Alpine and Debian containers. The images on Docker Hub may not be immediately available on release day. Continue reading to learn what changed in each version. 1.5.2 ClamAV 1.5.2 is a patch release with the following fixes: CVE-2026-20031: Fixed an error handling bug in the HTML file parser that may crash the program and cause a denial-of-service (DoS) condition. This issue was introduced in version 1.1.0. The fix is included in 1.5.2 and 1.4.4. Fixed a possible infinite loop when scanning some JPEG files by upgrading affected ClamAV...
https://blog.clamav.net/2026/03/clamav-152-and-144-security-patch.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cultivating a robust and efficient quantum-safe HTTPS
Posted by Chrome Secure Web and Networking Team
Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a working group, PKI, Logs, And Tree Signatures (“PLANTS”), aiming to address the performance and bandwidth challenges that the increased size of quantum-resistant cryptography introduces into TLS connections requiring Certificate Transparency (CT). We recently shared our call to action to secure quantum computing and have written about challenges introduced by quantum-resistant cryptography and some of the steps we've taken to address them in earlier blog posts.
To ensure the scalability and efficiency of the ecosystem, Chrome has no immediate plan to add traditional...
http://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A Deep Dive into the GetProcessHandleFromHwnd API
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn't know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I thought I should take a closer look. I typically start by reading the documentation for an API I don't know about, assuming it's documented at all. It can give you an idea of how long the API has existed as well as its security properties. The documentation's remarks contain the following three statements that I thought were interesting: If the caller has UIAccess, however, they can use a windows hook to inject code into the target process, and from within the target process, send a handle back to the caller. GetProcessHandleFromHwnd is a convenience function...
https://projectzero.google/2026/02/gphfh-deep-dive.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Staying One Step Ahead: Strengthening Android's Lead in Scam Protection
Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse
We've shared how Android's proactive, multi-layered scam defenses utilize Google AI to protect users around the world from over 10 billion suspected malicious calls and messages every month1. While that scale is significant, the true impact of these protections is best understood through the stories of the individuals they help keep safe every day. This includes people like Majik B., an IT professional in Sunnyvale, California.
Despite his technical background, Majik recently found himself on a call that felt dangerously legitimate. While using his Pixel, he received a call that appeared to be from his bank. The number looked correct, the...
http://security.googleblog.com/2026/02/strengthening-android-lead-in-scam-protection.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Celebrating Two Years of CSF 2.0!
Celebrate this milestone with us! Email us at csf [at] nist.gov (csf[at]nist[dot]gov) or tag @NISTcyber on X telling us what your favorite CSF 2.0 resource is (or how your organization has benefitted from implementing the CSF 2.0). Today marks two years since the publication of the Cybersecurity Framework (CSF) 2.0! Published in 2024, the CSF 2.0 included the addition of a Govern Function, increased emphasis on cybersecurity supply chain risk management, updated categories and subcategories to address current threat and technology shifts, and expansion into a suite of resources designed to make the CSF 2.0 easier to
https://www.nist.gov/blogs/cybersecurity-insights/celebrating-two-years-csf-20
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Keeping Google Play & Android app ecosystems safe in 2025
Posted by Vijaya Kaza, VP and GM, App & Ecosystem Trust
The Android ecosystem is a thriving global community built on trust, giving billions of users the confidence to download the latest apps. In order to maintain that trust, we're focused on ensuring that apps do not cause real-world harm, such as malware, financial fraud, hidden subscriptions, and privacy invasions. As bad actors leverage AI to change their tactics and launch increasingly sophisticated attacks, we've deepened our investments in AI and real-time defenses over the last year to maintain the upper hand and stop these threats before they reach users.
Upgrading Google Play's AI-powered, multi-layered user protections
We've seen a clear impact from these safety efforts on Google Play. In 2025, we prevented over...
http://security.googleblog.com/2026/02/keeping-google-play-android-app-ecosystem-safe-2025.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Bypassing Administrator Protection by Abusing UI Access
In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn't exist. I described one of the ways I was able to bypass the feature before it was released. In total I found 9 bypasses during my research that have now all been fixed. In this blog post I wanted to describe the root cause of 5 of those 9 issues, specifically the implementation of UI Access, how this has been a long standing problem with UAC that's been under-appreciated, and how it's being fixed now. A Question of Accessibility Prior to Windows Vista any process running on a user's desktop could control any window created by another, such as by sending window messages. This behavior could be abused if a privileged user, such as SYSTEM,...
https://projectzero.google/2026/02/windows-administrator-protection.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
LummaStealer Is Getting a Second Life Alongside CastleLoader
Bitdefender researchers have discovered a surge in LummaStealer activity, showing how one of the world's most prolific information-stealing malware operations managed to survive despite being almost brought down by law enforcement less than a year ago.
LummaStealer is a highly scalable information-stealing threat with a long history, having operated under a malware-as-a-service model since it appeared on the scene in late 2022.
The threat quickly evolved into one of the most widely deployed in
https://www.bitdefender.com/en-us/blog/labs/lummastealer-second-life-castleloader
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Helpful Skills or Hidden Payloads? Bitdefender Labs Dives Deep into the OpenClaw Malicious Skill Trap
With hundreds of malicious OpenClaw skills blending in among legitimate ones, manually reviewing every script or command isn't realistic — especially when skills are designed to look helpful and familiar.
That's why Bitdefender offers a free AI Skills Checker, designed to help people quickly assess whether an AI skill might be risky before they install or run it.
Using the tool, you can:
* Analyze AI skills and automation tools for suspicious behavior
* Spot red flags like hidden execution,
https://www.bitdefender.com/en-us/blog/labs/helpful-skills-or-hidden-payloads-bitdefender-labs-dives-deep-into-the-openclaw-malicious-skill-trap
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Supporting Wayland's XDG activation protocol with Gtk/Glib
One of the biggest sore points with Wayland is its focus stealing protection. The idea is good: an application should not be able to bring itself into focus at an unexpected time, only when the currently active application allows it. Support is still lacking however, which might also be due to Gtk/Glib implementing the required XDG activation protocol but not really documenting it. It took me a bit of time to figure this out without any public information, this article will hopefully make things easier for other people.
Contents
How the XDG activation protocol works
State of implementation in Gtk/Glib
Starting applications via Gio.AppInfo
Starting applications by other means
How the XDG activation protocol works
The main idea behind the XDG activation protocol...
https://palant.info/2026/02/03/supporting-waylands-xdg-activation-protocol-with-gtk/glib/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529
In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-free vulnerability (CVE-2025-31235) in the coreaudiod system daemon through a process I call knowledge-driven fuzzing. While the first post focused on the process of finding the vulnerabilities, this post dives into the intricate process of exploiting the type confusion vulnerability. I'll explain the technical details of turning a potentially exploitable crash into a working exploit: a journey filled with dead ends, creative problem solving, and ultimately, success. The Vulnerability: A Quick Recap If you haven't already, I highly recommend reading my detailed writeup on this vulnerability before proceeding. As...
https://projectzero.google/2026/01/sound-barrier-2.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Android Trojan Campaign Uses Hugging Face Hosting for RAT Payload Delivery
Bitdefender researchers have discovered an Android RAT (remote access trojan) campaign that combines social engineering, the resources of the Hugging Face online platform as staging, and extensive use of Accessibility Services to compromise devices.
https://www.bitdefender.com/en-us/blog/labs/android-trojan-campaign-hugging-face-hosting-rat-payload
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
New Android Theft Protection Feature Updates: Smarter, Stronger
Posted by Nataliya Stanetsky, Fabricio Ferracioli, Elliot Sisteron, Irene Ang of the Android Security Team
Phone theft is more than just losing a device; it's a form of financial fraud that can leave you suddenly vulnerable to personal data and financial theft. That's why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.
Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.
Stronger Authentication Safeguards
We've expanded our security to protect you against an even wider range of threats. These updates are now available for Android devices running Android...
http://security.googleblog.com/2026/01/android-theft-protection-feature-updates.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Celebrating Data Privacy Week with NIST's Privacy Engineering Program
Grab your party hats – it's Data Privacy Week! Data Privacy Week is a global initiative led by the National Cybersecurity Alliance to spread awareness about online privacy and empower individuals and businesses to respect privacy, safeguard data, and enable trust. In celebration of this week, the NIST Privacy Engineering Program is reflecting on recent work and looking ahead to what's coming in the new year. Throughout 2026, we plan to continue collaborating with our privacy stakeholder community to develop and advance privacy risk management guidelines to help organizations of all sizes
https://www.nist.gov/blogs/cybersecurity-insights/celebrating-data-privacy-week-nists-privacy-engineering-program
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Bypassing Windows Administrator Protection
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Control (UAC) with a more robust and importantly, securable system to allow a local user to access administrator privileges only when necessary. This blog post will give a brief overview of the new feature, how it works and how it's different from UAC. I'll then describe some of the security research I undertook while it was in the insider preview builds on Windows 11. Finally I'll detail one of the nine separate vulnerabilities that I found to bypass the feature to silently gain full administrator privileges. All the issues that I reported to Microsoft have been fixed, either prior to the feature being officially released (in optional...
https://projectzero.google/2026/26/windows-administrator-protection.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?
While our previous two blog posts provided technical recommendations for increasing the effort required by attackers to develop 0-click exploit chains, our experience finding, reporting and exploiting these vulnerabilities highlighted some broader issues in the Android ecosystem. This post describes the problems we encountered and recommendations for improvement. Audio Attack Surface The Dolby UDC is part of the 0-click attack surface of most Android devices because of audio transcription in the Google Messages application. Incoming audio messages are transcribed before a user interacts with the message. On Pixel 9, a second process com.google.android.tts also decodes incoming audio. Its purpose is not completely clear, but it seems to be related to making incoming messages searchable.
https://projectzero.google/2026/01/pixel-0-click-part-3.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland context, the mediacodec context. As per the AOSP documentation, the mediacodec SELinux context is intended to be a constrained (a.k.a sandboxed) context where non-secure software decoders are utilized. Nevertheless, using my DriverCartographer tool, I discovered an interesting device driver, /dev/bigwave that was accessible from the mediacodec SELinux context. BigWave is hardware present on the Pixel SOC that accelerates AV1 decoding tasks, which explains why it is accessible from the mediacodec context. As previous research has copiously affirmed, Android drivers for hardware devices are prime places to find powerful local...
https://projectzero.google/2026/01/pixel-0-click-part-2.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby
Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. One effect of this change is increased 0-click attack surface, as efficient analysis often requires message media to be decoded before the message is opened by the user. One such feature is audio transcription. Incoming SMS and RCS audio attachments received by Google Messages are now automatically decoded with no user interaction. As a result, audio decoders are now in the 0-click attack surface of most Android phones. I've spent a fair bit of time investigating these decoders, first reporting CVE-2025-49415 in the Monkey's Audio codec on Samsung devices. Based on this research, the team reviewed the Dolby Unified Decoder, and Ivan Fratric...
https://projectzero.google/2026/01/pixel-0-click-part-1.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
When AI Gets Bullied: How Agentic Attacks Are Replaying Human Social Engineering
AI Security Insights – January 2026
https://www.f5.com/labs/articles/when-ai-gets-bullied-how-agentic-attacks-are-replaying-human-social-engineering
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Podcast – GirlsTalkCyber – Episode 24
I spoke to the GirlsTalkCyber podcast about understanding and being aware of threats against critical infrastructure. We talked about things you should think about as geopolitical, economic, and climate instability increase across the world and how that relates to cyber threats. https://girlstalkcyber.com/24-what-happens-if-hackers-poison-the-water-interview-with-lesley-carhart/
https://tisiphone.net/2026/01/13/podcast-girlstalkcyber-episode-24/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Smashing Security – 449: How to scam someone in seven days
I am so excited to be on Smashing Security! Such a huge pleasure to finally make it onto one my favorite podcasts of all time with Graham Cluley! While I spoke about the jobs market and what students and hiring managers should be doing about it, Graham told me that my star sign isn’t good […]
https://tisiphone.net/2026/01/07/smashing-security-449-how-to-scam-someone-in-seven-days/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Backdoors in VStarcam cameras
VStarcam is an important brand of cameras based on the PPPP protocol. Unlike the LookCam cameras I looked into earlier, these are often being positioned as security cameras. And they in fact do a few things better like… well, like having a mostly working authentication mechanism. In order to access the camera one has to know its administrator password.
So much for the theory. When I looked into the firmware of the cameras I discovered a surprising development: over the past years this protection has been systematically undermined. Various mechanisms have been added that leak the access password, and in several cases these cannot be explained as accidents. The overall tendency is clear: for some reason VStarcam really wants to have access to their customer's passwords.
A reminder: “P2P”...
https://palant.info/2026/01/07/backdoors-in-vstarcam-cameras/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Digital Identities: Getting to Know the Verifiable Digital Credential Ecosystem
Understanding mDL credential formats Standards in the VDC Ecosystem In our first blog post in this series, we highlighted that VDCs can represent a wide range of credentials, from a driver's license to a diploma to proof of age. The ability to use VDCs in a wide variety of use cases is a major reason why many are looking at the VDC ecosystem as technology that can change how we present identity and attributes (both in person and online). While credential variety is a good thing, interoperability requires a common set of standards and protocols for issuing, using, and verifying VDCs. The next
https://www.nist.gov/blogs/cybersecurity-insights/digital-identities-getting-know-verifiable-digital-credential-0
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Analysis of PPPP “encryption”
My first article on the PPPP protocol already said everything there was to say about PPPP “encryption”:
Keys are static and usually trivial to extract from the app.
No matter how long the original key, it is mapped to an effective key that's merely four bytes long.
The “encryption” is extremely susceptible to known-plaintext attacks, usually allowing reconstruction of the effective key from a single encrypted packet.
So this thing is completely broken, why look any further? There is at least one situation where you don't know the app being used so you cannot extract the key and you don't have any traffic to analyze either. It's when you are trying to scan your local network for potential hidden cameras.
This script will currently only work for cameras using plaintext communication....
https://palant.info/2026/01/05/analysis-of-pppp-encryption/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
My Top 5 Recommendations on OT Cybersecurity Student Upskilling
I get asked about where to start learning OT cybersecurity as a student a lot. I fully realize that attention spans are short and people are busy, so without further ado let’s get to my top five recommendations: I hope this gives you a few more ideas! Happy new year!
https://tisiphone.net/2026/01/04/my-top-5-recommendations-on-ot-cybersecurity-student-upskilling/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Destination Cyber Podcast on OT
Please see my recent podcast on OT foundations and current events with Destination Cyber from KBI.FM!
https://tisiphone.net/2026/01/04/destination-cyber-podcast-on-ot/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV Signature Retirement
As per our previous announcement ClamAV file signature retirement has been implemented.Users may notice that file sizes are much smaller today as a result of the signature retirements.After we retired impacted signatures our download file sizes are now:bytecode.cvd: 275 KiBmain.cvd: 85 MiBdaily.cvd: 22 MiBOur team is continuing to monitor alerts and the current threat landscape and we are committed to reintroducing retired signatures as needed.For more detailed information on the ClamAV signature please see our previous blog post.ClamAV Signature Retirement AnnouncementIf you have any questions please join our ClamAV mailer here: ClamAV contactOr our ClamAV Discord Server here: ClamAV Discord Server
https://blog.clamav.net/2025/12/clamav-signature-retirement.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Welcome to the new Project Zero Blog
While on Project Zero, we aim for our research to be leading-edge, our blog design was … not so much. We welcome readers to our shiny new blog! For the occasion, we asked members of Project Zero to dust off old blog posts that never quite saw the light of day. And while we wish we could say the techniques they cover are no longer relevant, there is still a lot of work that needs to be done to protect users against zero days. Our new blog will continue to shine a light on the capabilities of attackers and the many opportunities that exist to protect against them. From 2016: Windows Exploitation Techniques: Race conditions with path lookups by James Forshaw From 2017: Thinking Outside The Box by Jann Horn
https://projectzero.google/2025/12/welcome.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
2026 Cybersecurity Predictions
Whatever you think will happen… will happen faster and with more acronyms than ever before.
https://www.f5.com/labs/articles/2026-cybersecurity-predictions
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Unpacking VStarcam firmware for fun and profit
One important player in the PPPP protocol business is VStarcam. At the very least they've already accumulated an impressive portfolio of security issues. Like exposing system configuration including access password unprotected in the Web UI (discovered by multiple people independently from the look of it). Or the open telnet port accepting hardcoded credentials (definitely discovered by lots of people independently). In fact, these cameras have been seen used as part of a botnet, likely thanks to some documented vulnerabilities in their user interface.
Is that a thing of the past? Are there updates fixing these issues? Which devices can be updated? These questions are surprisingly hard to answer. I found zero information on VStarcam firmware versions, available updates or security fixes....
https://palant.info/2025/12/15/unpacking-vstarcam-firmware-for-fun-and-profit/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
HTTPS certificate industry phasing out less secure domain validation methods
Posted by Chrome Root Program Team
Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root Program and the CA/Browser Forum have taken decisive steps toward a more secure internet by adopting new security requirements for HTTPS certificate issuers.
These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation. By retiring these outdated practices, which rely on weaker verification signals like physical mail, phone calls, or emails, we are closing potential loopholes for attackers and pushing the ecosystem toward automated, cryptographically verifiable security.
To allow affected website operators...
http://security.googleblog.com/2025/12/https-certificate-industry-phasing-out.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Further Hardening Android GPUs
Posted by Liz Prucka, Hamzeh Zawawy, Rishika Hooda, Android Security and Privacy Team
Last year, Google's Android Red Team partnered with Arm to conduct an in-depth security analysis of the Mali GPU, a component used in billions of Android devices worldwide. This collaboration was a significant step in proactively identifying and fixing vulnerabilities in the GPU software and firmware stack.
While finding and fixing individual bugs is crucial, and progress continues on eliminating them entirely, making them unreachable by restricting attack surface is another effective and often faster way to improve security. This post details our efforts in partnership with Arm to further harden the GPU by reducing the driver's attack surface.
The Growing Threat: Why GPU Security Matters
The Graphics...
http://security.googleblog.com/2025/12/further-hardening-android-gpus.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fallacy Failure Attack
AI Security Insights for November 2025
https://www.f5.com/labs/articles/fallacy-failure-attack
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Systemic Ransomware Events in 2025 – How Jaguar Land Rover Showed What a Category 3 Supply Chain Breach Looks Like
Systemic ransomware events in 2025, how Jaguar Land Rover's shutdown exposed Category 3 supply chain risk, with lessons from Toyota, Nissan and Ferrari.
https://www.darknet.org.uk/2025/11/systemic-ransomware-events-in-2025-how-jaguar-land-rover-showed-what-a-category-3-supply-chain-breach-looks-like/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
SmbCrawler – SMB Share Discovery and Secret-Hunting
SmbCrawler is a credentialed SMB share crawler for red teams that discovers misconfigured shares and hunts secrets across Windows networks.
https://www.darknet.org.uk/2025/11/smbcrawler-smb-share-discovery-and-secret-hunting/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Heisenberg Dependency Health Check – GitHub Action for Supply Chain Risk
Heisenberg Dependency Health Check is a GitHub Action that flags risky or newly introduced dependencies in pull requests using supply-chain signals.
https://www.darknet.org.uk/2025/11/heisenberg-dependency-health-check-github-action-for-supply-chain-risk/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Dark Web Search Engines for Security Research: Monitoring, APIs and IOC Hunting
Compare public dark web search engines with enterprise monitoring platforms, APIs and IOC workflows for credentials, threats, brands and leaked data.
https://www.darknet.org.uk/2025/11/dark-web-search-engines-in-2025-enterprise-monitoring-apis-and-ioc-hunting/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV Signature Retirement Announcement
ClamAV was first introduced in 2002; since then, the
signature set has grown without bound, delivering as many detections as
possible to the community. Due to continually increasing database sizes and
user adoption, we are faced with significantly increasing costs of distributing
the signature set to the community.To address the issue, Cisco Talos has been working to
evaluate the efficacy and relevance of older signatures. Signatures which no
longer provide value to the community, based on today's security landscape,
will be retired.We are making this announcement as an advisory that our
first pass of this retirement effort will affect a significant drop in database
size for both the daily.cvd and main.cvd.Our goal is to ensure that detection content is targeted to
currently active threats...
https://blog.clamav.net/2025/11/clamav-signature-retirement-announcement.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
mcp-scan – Real-Time Guardrail Monitoring and Dynamic Proxy for MCP Servers
mcp-scan is a dynamic proxy and guardrail monitor for MCP servers, providing real-time traffic inspection and enforcement for agents and tools.
https://www.darknet.org.uk/2025/11/mcp-scan-real-time-guardrail-monitoring-and-dynamic-proxy-for-mcp-servers/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Initial Access Brokers (IAB) in 2025 – From Dark Web Listings to Supply Chain Ransomware Events
Initial access brokers in 2025, how dark web access listings feed ransomware supply chain events like JLR, and what CISOs can do to detect and disrupt them
https://www.darknet.org.uk/2025/11/initial-access-brokers-iab-in-2025-from-dark-web-listings-to-supply-chain-ransomware-events/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Reconnoitre – Open-Source Reconnaissance and Service Enumeration Tool
Reconnoitre automates network reconnaissance and service enumeration for penetration testers and red teams using structured, repeatable workflows.
https://www.darknet.org.uk/2025/11/reconnoitre-open-source-reconnaissance-and-service-enumeration-tool/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
An overview of the PPPP protocol for IoT cameras
My previous article on IoT “P2P” cameras couldn't go into much detail on the PPPP protocol. However, there is already lots of security research on and around that protocol, and I have a feeling that there is way more to come. There are pieces of information on the protocol scattered throughout the web, yet every one approaching from a very specific narrow angle. This is my attempt at creating an overview so that other people don't need to start from scratch.
While the protocol can in principle be used by any kind of device, it is mostly being used for network-connected cameras. It isn't really peer-to-peer as advertised but rather relies on central servers, yet the protocol allows to transfer the bulk of data via a direct connection between the client and the device. It's hard...
https://palant.info/2025/11/05/an-overview-of-the-pppp-protocol-for-iot-cameras/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Passively Downloading Malware Payloads Via Image Caching
Detailing an improved Cache Smuggling technique to turn 3rd party software into passive malware downloader.
https://malwaretech.com/2025/10/exif-smuggling.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV 1.5.1 patch version published
Today, we are publishing ClamAV 1.5.1. This version has been released shortly after ClamAV 1.5.0 in order to address several significant issues that were identified following its publication.The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub. The images on Docker Hub may not be immediately available on release day.ClamAV 1.5.1 is a patch release with the following fixes:Fixed a significant performance issue when scanning some PE filesFixed an issue recording file entries from a ZIP archive central directory which resulted in "Heuristics.Limits.Exceeded.MaxFiles" alerts when using the ClamScan --alert-exceeds-max command line option or ClamD AlertExceedsMax config file optionImproved...
https://blog.clamav.net/2025/10/clamav-151-patch-version-published.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV 1.5.0 released!
The ClamAV 1.5.0 is now available. You may find the source code and installers for this release at clamav.net/downloads or on the ClamAV GitHub release page. IMPORTANT: A major feature of the 1.5 release is a FIPS-mode compatible method for verifying the authenticity of CVD signature database archives and CDIFF signature database patch files. This feature relies on “.cvd.sign” signature files for the daily, main, and bytecode databases. The Freshclam with 1.5.0 will download these files as will the latest version of CVDUpdate. When they are not present, ClamAV will fall back to using the legacy MD5-based RSA signature check.Tip: If you are downloading the source from the GitHub release page, the package labeled "clamav-1.5.0.tar.gz" does not require an internet connection to build....
https://blog.clamav.net/2025/10/clamav-150-released.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Reasonable Expectations for Cybersecurity Mentees
Most of my audience is on the more senior end of the career spectrum. As a result, a lot of my writing about careers is aimed at senior cybersecurity professionals, encouraging managers and experienced practitioners to support the next generation. But that doesn't mean newcomers are free from responsibility in their career journey. If you're […]
https://tisiphone.net/2025/09/24/reasonable-expectations-for-cybersecurity-mentees/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Entra ID actor token validation bug allowing cross-tenant global admin
A critical vulnerability discovered in Microsoft's Entra ID (formerly Azure AD) allowed for cross-tenant
access and potential global admin privilege escalation. The flaw was found in the legacy Azure AD Graph API,
which improperly validated the originating tenant for undocumented "Actor tokens." An attacker could use a
token from their own tenant to authenticate as any user, including Global Admins, in any other tenant. This
vulnerability bypassed security policies like Conditional Access. The issue was reported to Microsoft, who
deployed a global fix within days.
https://www.cloudvulndb.org/global-admin-entra-id-actor-tokens
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
More Mozilla User-Agents, Please: a Deep Dive into an Inadvertent Disclosure Scanner
Sensor Intel Series: September 2025 Trends
https://www.f5.com/labs/articles/more-mozilla-user-agents-please-a-deep-dive-into-an-inadvertent-disclosure-scanner
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Top 10 Things I'd Like to See in University OT Cybersecurity Curriculum (2025 Edition)
Most of you who have been following me for a while know that I have a very strange and unusual job in cybersecurity. I’m one of maybe a hundred or so people on earth who does full time incident response and forensics for industrial devices and networks that are hacked. Things like power plants, trains, […]
https://tisiphone.net/2025/09/10/the-top-10-things-id-like-to-see-in-university-ot-cybersecurity-curriculum-2025-edition/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A look at a P2P camera (LookCam app)
I've got my hands on an internet-connected camera and decided to take a closer look, having already read about security issues with similar cameras. What I found far exceeded my expectations: fake access controls, bogus protocol encryption, completely unprotected cloud uploads and firmware riddled with security flaws. One could even say that these cameras are Murphy's Law turned solid: everything that could be done wrong has been done wrong here. While there is considerable prior research on these and similar cameras that outlines some of the flaws, I felt that the combination of severe flaws is reason enough to publish an article of my own.
My findings should apply to any camera that can be managed via the LookCam app. This includes cameras meant to be used with less popular apps of the...
https://palant.info/2025/09/08/a-look-at-a-p2p-camera-lookcam-app/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Open Online Mentoring Guide
I’ve had a sign up for open online career mentoring on my site for quite a number of years now (in addition to running similar career clinics in-person). As I’ve gotten more and more traction internationally on the program, a lot of senior folks have asked how to set up a program for office hours […]
https://tisiphone.net/2025/09/01/open-online-mentoring-guide/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Stories Ink Interviewed Me, and I love Stories.
I was recently at the Tech Leaders Summit in Hunter Valley and the imitable Jennifer O’Brien covered my backstory and how I got into the odd space of Operational Technology. This is a nice change of format for people who aren’t into podcasts and she tells such a good narrative. It was really cool to […]
https://tisiphone.net/2025/09/01/stories-ink-interviewed-me-and-i-love-stories/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Dataform cross-tenant path traversal
Dataform could have allowed a malicious customer to gain unauthorized cross-tenant access
to other customer's code repositories and data. By preparing a maliciously crafted package.json
file, an attacker could exploit a path traversal vulnerability in the npm package installation
process, thereby gaining read and write access in other customers' repositories. According to
Google, there was no evidence of exploitation in the wild.
https://www.cloudvulndb.org/dataform-path-traversal
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV 1.5.0 release candidate now available!
The ClamAV 1.5.0 release candidate is now available. You may find the source code and installers for this release at clamav.net/downloads or on the ClamAV GitHub release page. The release candidate phase is expected to last two to four weeks before we publish the stable release. This will depend on whether any changes are required to stabilize this version. Please take this time to evaluate ClamAV 1.5.0. Please help us validate this release by providing feedback via GitHub issues, via the ClamAV mailing list or on our Discord. IMPORTANT: A major feature of the 1.5 release is a FIPS-compliant method for verifying the authenticity of CVD signature database archives and CDIFF signature database patch files. The feature is ready to test in this release candidate, but we are not...
https://blog.clamav.net/2025/08/clamav-150-release-candidate-now.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AWS ECS Agent Information Disclosure Vulnerability
A vulnerability in the Amazon ECS agent could allow an introspection server to be accessed off-host.
This information disclosure issue, if exploited, could allow another instance in the same security
group to access the server's data. The vulnerability does not affect instances where off-host access
is set to 'false'. The issue has been patched in version 1.97.1 of the ECS agent.
https://www.cloudvulndb.org/aws-ecs-agent-information-disclosure-vulnerability
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
IoT Penetration Testing: From Hardware to Firmware
As Internet of Things (IoT) devices continue to permeate every aspect of modern life, homes, offices, factories, vehicles, their attack surfaces have become increasingly attractive to adversaries. The challenge with testing IoT systems lies in their complexity: these devices often combine physical interfaces, embedded firmware, network services, web applications, and companion mobile apps into a [...]
The post IoT Penetration Testing: From Hardware to Firmware appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/iot-hacking/iot-penetration-testing-from-hardware-to-firmware/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
SparkRAT: Exploiting Architectural Weaknesses in Open-Source Offensive Tools
Persistent trend in open-source offensive tooling & implications for defenders
https://www.f5.com/labs/articles/sparkrat-exploiting-architectural-weaknesses-in-open-source-offensive-tools
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Every Reason Why I Hate AI and You Should Too
maybe it's anti-innovation, maybe it's just avoiding hype. But one thing is clear, I'm completely done with hearing about AI.
https://malwaretech.com/2025/08/every-reason-why-i-hate-ai.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV 1.4.3 and 1.0.9 security patch versions published
Today, we are publishing the 1.4.3 and 1.0.9 security patch versions. We have also added Linux aarch64 (aka ARM64) RPM and DEB installer packages for the 1.4 LTS release.The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub. The images on Docker Hub may not be immediately available on release day. Continue reading to learn what changed in each version.1.4.3ClamAV 1.4.3 is a patch release with the following fixes: CVE-2025-20260: Fixed a possible buffer overflow write bug in the PDF file parser that could cause a denial-of-service (DoS) condition or enable remote code execution.This issue only affects configurations where both:The max file-size scan limit is set greater than or equal to 1024MB.The...
https://blog.clamav.net/2025/06/clamav-143-and-109-security-patch.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
F5 Labs Top CWEs & OWASP Top Ten Analysis
We expand our view to include CWE and OWASP, and we also examine the latest overall trends for June 2025.
https://www.f5.com/labs/articles/f5-labs-top-cwes-owasp-top-ten-analysis
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Delving Into the SparkRAT Remote Access Tool
Sensor Intel Series: May 2025 CVE Trends
https://www.f5.com/labs/articles/delving-into-the-sparkrat-remote-access-tool
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Remote Prompt Injection in GitLab Duo Leaks Source Code
A remote prompt injection vulnerability in GitLab Duo allowed attackers to steal source code from private projects, manipulate code suggestions, and exfiltrate confidential information. The attack chain involved hidden prompts, HTML injection, and exploitation of Duo's access to private data. GitLab has since patched both the HTML and prompt injection vectors.
https://www.cloudvulndb.org/gitlab-duo-prompt-injection-leak
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AWS Security Tool Introduces Privilege Escalation Risk
AWS's Account Assessment for AWS Organizations tool, designed to audit cross-account access, inadvertently introduced privilege escalation risks due to flawed deployment instructions. Customers were encouraged to deploy the tool in lower-sensitivity accounts, creating risky trust paths from insecure environments into highly sensitive ones. This could allow attackers to pivot from compromised development accounts into production and management accounts.
https://www.cloudvulndb.org/aws-security-tool-risk
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
FreeRTOS and coreSNTP Security Advisories
Security advisories were issued for FreeRTOS and coreSNTP releases containing unintended scripts that could potentially transmit AWS credentials if executed on Linux/macOS. Affected releases have been removed and users are advised to rotate credentials and delete downloaded copies.
https://www.cloudvulndb.org/freertos-coresntp-advisories
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Azure AZNFS-mount Utility Root Privilege Escalation
A critical vulnerability in AZNFS-mount utility, preinstalled on Azure HPC/AI images, allowed unprivileged users to escalate privileges to root on Linux machines. The flaw existed in versions up to 2.0.10 and involved a SUID binary. Azure classified it as low severity but fixed it in version 2.0.11.
https://www.cloudvulndb.org/azure-aznfs-mount-privilege-escalation
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AWS Default Roles Can Lead to Service Takeover
Research uncovered security flaws in default AWS service roles, granting overly broad permissions like full S3 access. This allows privilege escalation, cross-service access, and potential account compromise across services like SageMaker, Glue, and EMR. Attackers could exploit these roles to manipulate critical assets and move laterally within AWS environments. AWS has since updated default policies and documentation to mitigate risks.
https://www.cloudvulndb.org/aws-default-roles-service-takeover
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Google Cloud ConfusedComposer Privilege Escalation Vulnerability
Tenable discovered a privilege escalation vulnerability in Google Cloud Platform's Cloud Composer service, dubbed ConfusedComposer. It allowed users with composer.environments.update permission to escalate privileges to the default Cloud Build service account by injecting malicious PyPI packages. This could grant broad permissions across the victim's GCP project.
https://www.cloudvulndb.org/gcp-confused-composer-vulnerability
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Burning Data with Malicious Firewall Rules in Azure SQL
Varonis Threat Labs discovered a vulnerability in Azure SQL Server allowing privileged users to create malicious firewall rules that can delete Azure resources when triggered by admin actions. The exploit involves manipulating rule names via TSQL to inject destructive commands, potentially leading to large-scale data loss in affected Azure accounts.
https://www.cloudvulndb.org/burning-data-azure-sql-firewall
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Path Traversal in AWS SSM Agent Plugin ID Validation
A path traversal vulnerability in AWS SSM Agent's ValidatePluginId function allows attackers to create directories and execute scripts in unintended locations on the filesystem. This could lead to privilege escalation or other malicious activities, as files may be written to or executed from sensitive areas of the system with root privileges.
https://www.cloudvulndb.org/aws-ssm-agent-path-traversal
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ImageRunner: Privilege Escalation Vulnerability in GCP Cloud Run
An attacker with `run.services.update` and `iam.serviceAccounts.actAs` permissions but without
explicit registry access could deploy new revisions of Cloud Run services that pulled private
container images stored in the same GCP project. This was possible because Cloud Run uses a
service agent with the necessary registry read permissions to retrieve these images, regardless
of the caller's access level. By updating a service revision and injecting malicious commands
into the container's arguments (e.g., using Netcat for reverse shell access), attackers could
extract secrets or run unauthorized code. The flaw stemmed from the Cloud Run service agent's
trust model, which did not enforce a separate registry permission check on the deploying identity.
Google has since modified this behavior...
https://www.cloudvulndb.org/imagerunner
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV 1.5.0 beta now available!
The ClamAV 1.5.0 beta is now available. You may find the source code and installers for this release at clamav.net/downloads or on the ClamAV GitHub release page. The beta phase is expected to last two to four weeks before we publish the stable release or else publish a release candidate. This will depend on how many changes are required to stabilize this version. Please take this time to evaluate ClamAV 1.5.0. Please help us validate this release by providing feedback via GitHub issues, via the ClamAV mailing list or on our Discord. IMPORTANT: A major feature of the 1.5 release is a FIPS-compliant method for verifying the authenticity of CVD signature database archives and CDIFF signature database patch files. The feature is ready to test in this beta, but we are not yet distributing the...
https://blog.clamav.net/2025/03/clamav-150-beta-now-available.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
2025 Advanced Persistent Bots Report
Uncovering the true scale of persistent bot activity, and the advanced techniques that bot operators use in order to remain hidden from bot defenses.
https://www.f5.com/labs/articles/2025-advanced-persistent-bots-report
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The US Needs A New Cybersecurity Strategy: More Offensive Cyber Operations Isn't It
For a long time Chinese hackers have been operating in the grey area between espionage and warfare. The US has been struggling to defend its networks, but increasing offensive cyber operations in unlikely to help.
https://malwaretech.com/2025/03/the-us-needs-a-new-cybersecurity-strategy.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Advance notice: End of Life for ClamAV 0.103 database updates
ClamAV version 0.103 will reach its end of life (EOL) for database updates on September 14, 2025. After this date, this version will no longer receive the latest virus definitions. To ensure your systems remain protected, please upgrade to the latest supported version of ClamAV before the end-of-life date. This will provide continued access to essential security updates and features. We recommend that users update to the newest release, ClamAV 1.4 LTS. For users that are unable to upgrade to version 1.4, you may find that ClamAV 1.0 LTS is more suitable. The most recent version of ClamAV can be found on the ClamAV Downloads page, on the ClamAV GitHub Releases page, and through Docker Hub. Information about how to install ClamAV is available in our online documentation. The...
https://blog.clamav.net/2025/03/advance-notice-end-of-life-for-clamav.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Why Critical MongoDB Library Flaws Won't See Mass Exploitation
Discover how to mitigate CVE-2024-53900 and CVE-2025-23061, which expose Node.js APIs to remote attacks.
https://www.f5.com/labs/articles/why-critical-mongodb-library-flaws-wont-see-mass-exploitation
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Analysis of an advanced malicious Chrome extension
Two weeks ago I published an article on 63 malicious Chrome extensions. In most cases I could only identify the extensions as malicious. With large parts of their logic being downloaded from some web servers, it wasn't possible to analyze their functionality in detail.
However, for the Download Manager Integration Checklist extension I have all parts of the puzzle now. This article is a technical discussion of its functionality that somebody tried very hard to hide. I was also able to identify a number of related extensions that were missing from my previous article.
Update (2025-02-04): An update to Download Manager Integration Checklist extension has been released a day before I published this article, clearly prompted by me asking adindex about this. The update removes the malicious functionality...
https://palant.info/2025/02/03/analysis-of-an-advanced-malicious-chrome-extension/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
ClamAV 1.4.2 and 1.0.8 security patch versions published
Today, we are publishing the 1.4.2 and 1.0.8 security patch versions. The release files for the patch versions are available for download on the ClamAV downloads page, on the GitHub Release page, and through Docker Hub. The images on Docker Hub may not be immediately available on release day. Continue reading to learn what changed in each version.1.4.2
ClamAV 1.4.2 is a patch release with the following fixes: CVE-2025-20128: Fixed a possible buffer overflow read bug in the OLE2 file parser that could cause a denial-of-service (DoS) condition. This issue was introduced in version 1.0.0 and affects all currently supported versions. It will be fixed in:
1.4.2 and 1.0.8 Thank you to OSS-Fuzz for identifying this issue.
1.0.8
ClamAV 1.0.8 is a patch release with the following fixes:CVE-2025-20128:...
https://blog.clamav.net/2025/01/clamav-142-and-108-security-patch.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Malicious extensions circumvent Google's remote code ban
As noted last week I consider it highly problematic that Google for a long time allowed extensions to run code they downloaded from some web server, an approach that Mozilla prohibited long before Google even introduced extensions to their browser. For years this has been an easy way for malicious extensions to hide their functionality. When Google finally changed their mind, it wasn't in form of a policy but rather a technical change introduced with Manifest V3.
As with most things about Manifest V3, these changes are meant for well-behaving extensions where they in fact improve security. As readers of this blog probably know, those who want to find loopholes will find them: I've already written about the Honey extension bundling its own JavaScript interpreter and malicious extensions...
https://palant.info/2025/01/20/malicious-extensions-circumvent-googles-remote-code-ban/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Chrome Web Store is a mess
Let's make one thing clear first: I'm not singling out Google's handling of problematic and malicious browser extensions because it is worse than Microsoft's for example. No, Microsoft is probably even worse but I never bothered finding out. That's because Microsoft Edge doesn't matter, its market share is too small. Google Chrome on the other hand is used by around 90% of the users world-wide, and one would expect Google to take their responsibility to protect its users very seriously, right? After all, browser extensions are one selling point of Google Chrome, so certainly Google would make sure they are safe?
Unfortunately, my experience reporting numerous malicious or otherwise problematic browser extensions speaks otherwise. Google appears to take the “least effort required”...
https://palant.info/2025/01/13/chrome-web-store-is-a-mess/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
BIScience: Collecting browsing history under false pretenses
This is a guest post by a researcher who wants to remain anonymous. You can contact the author via email.
Recently, John Tuckner of Secure Annex and Wladimir Palant published great research about how BIScience and its various brands collect user data. This inspired us to publish part of our ongoing research to help the extension ecosystem be safer from bad actors.
This post details what BIScience does with the collected data and how their public disclosures are inconsistent with actual practices, based on evidence compiled over several years.
Screenshot of claims on the BIScience website
Contents
Who is BIScience?
BIScience collects data from millions of users
BIScience buys data from partner third-party extensions
BIScience receives raw...
https://palant.info/2025/01/13/biscience-collecting-browsing-history-under-false-pretenses/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6
Performing a root cause analysis & building proof-of-concept for CVE-2024-38063, a CVSS 9.8 Vulnerability In the Windows Kernel IPv6 Parser
https://malwaretech.com/2024/08/exploiting-CVE-2024-38063.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Bypassing EDRs With EDR-Preloading
Evading user mode EDR hooks by hijacking the AppVerifier layer
https://malwaretech.com/2024/02/bypassing-edrs-with-edr-preload.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Silly EDR Bypasses and Where To Find Them
Abusing exception handlers to hook and bypass user mode EDR hooks.
https://malwaretech.com/2023/12/silly-edr-bypasses-and-where-to-find-them.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
An Introduction to Bypassing User Mode EDR Hooks
Understanding the basics of user mode EDR hooking, common bypass techniques, and their limitations.
https://malwaretech.com/2023/12/an-introduction-to-bypassing-user-mode-edr-hooks.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
It might Be Time to Rethink Phishing Awareness
Phishing awareness can be a powerful security tool, or a complete disaster. It all hinges on how you implement it.
https://malwaretech.com/2023/09/it-might-be-time-to-rethink-phishing-awareness.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
A Realistic Look at Implications of ChatGPT for Cybercrime
Analyzing ChatGPT's capabilities and various claims about how it will revolutionize cybercrime.
https://malwaretech.com/2023/02/a-realistic-look-at-chatgpt-cybercrime.html
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2022-3602 and CVE-2022-3786: OpenSSL 3.0.7 patches Critical Vulnerability
On Tuesday, November 1 2022 between 1300-1700 UTC, the OpenSSL project announced the release of a new version of OpenSSL (version 3.0.7) that will patch a critical vulnerability in OpenSSL version 3.0 and above. Only OpenSSL versions between 3.0 and 3.0.6 are affected at the time of writing. At this moment the details of this [...]
The post CVE-2022-3602 and CVE-2022-3786: OpenSSL 3.0.7 patches Critical Vulnerability appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/general-tutorials/openssl-3-0-7-patches-critical-vulnerability/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Student Loan Breach Exposes 2.5M Records
2.5 million people were affected, in a breach that could spell more trouble down the line.
https://threatpost.com/student-loan-breach-exposes-2-5m-records/180492/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Watering Hole Attacks Push ScanBox Keylogger
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
https://threatpost.com/watering-hole-attacks-push-scanbox-keylogger/180490/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Tentacles of ‘0ktapus' Threat Group Victimize 130 Firms
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
https://threatpost.com/0ktapus-victimize-130-firms/180487/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Ransomware Attacks are on the Rise
Lockbit is by far this summer's most prolific ransomware group, trailed by two offshoots of the Conti group.
https://threatpost.com/ransomware-attacks-are-on-the-rise/180481/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
https://threatpost.com/cybercriminals-are-selling-access-to-chinese-surveillance-cameras/180478/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Twitter Whistleblower Complaint: The TL;DR Version
Twitter is blasted for security and privacy lapses by the company's former head of security who alleges the social media giant's actions amount to a national security risk.
https://threatpost.com/twitter-whistleblower-tldr-version/180472/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Firewall Bug Under Active Attack Triggers CISA Warning
CISA is warning that Palo Alto Networks' PAN-OS is under active attack and needs to be patched ASAP.
https://threatpost.com/firewall-bug-under-active-attack-cisa-warning/180467/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Fake Reservation Links Prey on Weary Travelers
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
https://threatpost.com/reservation-links-prey-on-travelers/180462/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
iPhone Users Urged to Update to Patch 2 Zero-Days
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
https://threatpost.com/iphone-users-urged-to-update-to-patch-2-zero-days-under-attack/180448/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Google Patches Chrome's Fifth Zero-Day of the Year
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
https://threatpost.com/google-patches-chromes-fifth-zero-day-of-the-year/180432/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Installing Rogue-jndi on Kali Linux
Following the previous tutorial in which we looked at the log4j vulnerability in VMWare vSphere server, I got some questions about how to set up a malicious LDAP server on Linux. The attacker controlled LDAP server is required to provide the malicious java class (with a reverse shell for example) in response to the forged [...]
The post Installing Rogue-jndi on Kali Linux appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/general-tutorials/installing-rogue-jndi-on-kali-linux/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Log4Shell VMware vCenter Server (CVE-2021-44228)
Log4Shell is a critical vulnerability with the highest possible CVSSv3 score of 10.0 that affects thousands of products running Apache Log4j and leaves millions of targets potentially vulnerable. CVE-2021-44228 affects log4j versions 2.0-beta9 to 2.14.1. Log4j is an incredibly popular logging library used in many different products and various Apache frameworks like Struts2, Kafka, and [...]
The post Log4Shell VMware vCenter Server (CVE-2021-44228) appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/exploit-tutorials/log4shell-vmware-vcenter-server-cve-2021-44228/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How to customize behavior of AWS Managed Rules for AWS WAF
AWS Managed Rules for AWS WAF provides a group of rules created by AWS that can be used help protect you against common application vulnerabilities and other unwanted access to your systems without having to write your own rules. AWS Threat Research Team updates AWS Managed Rules to respond to an ever-changing threat landscape in order […]
https://aws.amazon.com/blogs/security/how-to-customize-behavior-of-aws-managed-rules-for-aws-waf/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The Great Leak: Microsoft Exchange AutoDiscover Design Flaw
Recently a “design flaw” in the Microsoft Exchange’s Autodiscover protocol was discovered by researchers that allowed access to 372,072 Windows domain credentials and 96,671 unique sets of credentials from applications such as Microsoft Outlook and third-party email clients. According to Amit Serper , the person who discovered the flaw, the source of the leak is [...]
The post The Great Leak: Microsoft Exchange AutoDiscover Design Flaw appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/pentesting-exchange/the-great-leak-microsoft-exchange-autodiscover-design-flaw/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
The three most important AWS WAF rate-based rules
May 5, 2025: This post has been updated to reflect that the lowest allowable rate limit setting in AWS WAF rate-based rules has changed from 100 requests to 10. In this post, we explain what the three most important AWS WAF rate-based rules are for proactively protecting your web applications against common HTTP flood events, […]
https://aws.amazon.com/blogs/security/three-most-important-aws-waf-rate-based-rules/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Automatically update AWS WAF IP sets with AWS IP ranges
Note: This blog post describes how to automatically update AWS WAF IP sets with the most recent AWS IP ranges for AWS services. This related blog post describes how to perform a similar update for Amazon CloudFront IP ranges that are used in VPC Security Groups. You can use AWS Managed Rules for AWS WAF […]
https://aws.amazon.com/blogs/security/automatically-update-aws-waf-ip-sets-with-aws-ip-ranges/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AWS Shield threat landscape review: 2020 year-in-review
AWS Shield is a managed service that protects applications that are running on Amazon Web Services (AWS) against external threats, such as bots and distributed denial of service (DDoS) attacks. Shield detects network and web application-layer volumetric events that may indicate a DDoS attack, web content scraping, or other unauthorized non-human traffic that is interacting […]
https://aws.amazon.com/blogs/security/aws-shield-threat-landscape-review-2020-year-in-review/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
How to protect a self-managed DNS service against DDoS attacks using AWS Global Accelerator and AWS Shield Advanced
In this blog post, I show you how to improve the distributed denial of service (DDoS) resilience of your self-managed Domain Name System (DNS) service by using AWS Global Accelerator and AWS Shield Advanced. You can use those services to incorporate some of the techniques used by Amazon Route 53 to protect against DDoS attacks. […]
https://aws.amazon.com/blogs/security/how-to-protect-a-self-managed-dns-service-against-ddos-attacks-using-aws-global-accelerator-and-aws-shield-advanced/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Set up centralized monitoring for DDoS events and auto-remediate noncompliant resources
When you build applications on Amazon Web Services (AWS), it's a common security practice to isolate production resources from non-production resources by logically grouping them into functional units or organizational units. There are many benefits to this approach, such as making it easier to implement the principal of least privilege, or reducing the scope of […]
https://aws.amazon.com/blogs/security/set-up-centralized-monitoring-for-ddos-events-and-auto-remediate-noncompliant-resources/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Deploying defense in depth using AWS Managed Rules for AWS WAF (part 2)
In this post, I show you how to use recent enhancements in AWS WAF to manage a multi-layer web application security enforcement policy. These enhancements will help you to maintain and deploy web application firewall configurations across deployment stages and across different types of applications. In part 1 of this post I describe the technologies […]
https://aws.amazon.com/blogs/security/deploying-defense-in-depth-using-aws-managed-rules-for-aws-waf-part-2/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Defense in depth using AWS Managed Rules for AWS WAF (part 1)
In this post, I discuss how you can use recent enhancements in AWS WAF to manage a multi-layer web application security enforcement policy. These enhancements will help you to maintain and deploy web application firewall configurations across deployment stages and across different types of applications. The post is in two parts. This first part describes […]
https://aws.amazon.com/blogs/security/defense-in-depth-using-aws-managed-rules-for-aws-waf-part-1/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Houston consulate one of worst offenders in Chinese espionage, say U.S. officials
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: Reuters The United States ordered the consulate closed this week, leading China to retaliate on Friday by telling the United States to shut its consulate in the city of Chengdu, as relations between the world's two largest economies […]
The post Houston consulate one of worst offenders in Chinese espionage, say U.S. officials appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/07/24/houston-consulate-one-of-worst-offenders-in-chinese-espionage-say-u-s-officials/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Shocked I am. Shocked to find that underground bank-card-trading forums are full of liars, cheats, small-time grifters
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register The denizens of online forums dedicated to trading in stolen credit cards have been shown to be wretched hives of scum and villainy. This not-so-surprising news comes this week via academics at Washington State University (WSU) in the US, […]
The post Shocked I am. Shocked to find that underground bank-card-trading forums are full of liars, cheats, small-time grifters appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/07/24/shocked-i-am-shocked-to-find-that-underground-bank-card-trading-forums-are-full-of-liars-cheats-small-time-grifters/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
AWS Shield Threat Landscape report is now available
AWS Shield is a managed threat protection service that safeguards applications running on AWS against exploitation of application vulnerabilities, bad bots, and Distributed Denial of Service (DDoS) attacks. The AWS Shield Threat Landscape Report (TLR) provides you with a summary of threats detected by AWS Shield. This report is curated by the AWS Threat Research […]
https://aws.amazon.com/blogs/security/aws-shield-threat-landscape-report-now-available/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Vint Cerf suggests GDPR could hurt coronavirus vaccine development
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register TCP-IP-co-developer Vint Cerf, revered as a critical contributor to the foundations of the internet, has floated the notion that privacy legislation might hinder the development of a vaccination for the COVID-19 coronavirus. In an essay written for […]
The post Vint Cerf suggests GDPR could hurt coronavirus vaccine development appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/16/vint-cerf-suggests-gdpr-could-hurt-coronavirus-vaccine-development/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Brit defense contractor hacked, up to 100,000 past and present employees' details siphoned off – report
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register Britain’s Ministry of Defence contractor Interserve has been hacked, reportedly leaking the details of up to 100,000 of past and current employees, including payment information and details of their next of kin. The Daily Telegraph reports that up to […]
The post Brit defense contractor hacked, up to 100,000 past and present employees’ details siphoned off – report appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/16/brit-defense-contractor-hacked-up-to-100000-past-and-present-employees-details-siphoned-off-report/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
US officially warns China is launching cyberattacks to steal coronavirus research
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: CNN The US Department of Homeland Security and the FBI issued a “public service announcement” Wednesday warning that China is likely launching cyberattacks to steal coronavirus data related to vaccines and treatments from US research institutions and pharmaceutical […]
The post US officially warns China is launching cyberattacks to steal coronavirus research appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/14/us-officially-warns-china-is-launching-cyberattacks-to-steal-coronavirus-research/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
There's Norway you're going to believe this: World's largest sovereign wealth fund conned out of m in cyber-attack
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register The Norwegian Investment Fund has been swindled out of m (£8.2m) by fraudsters who pulled off what’s been described as “an advance data breach.” Norfund – the world’s largest sovereign wealth fund, created from saved North Sea […]
The post There’s Norway you’re going to believe this: World’s largest sovereign wealth fund conned out of m in cyber-attack appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/14/theres-norway-youre-going-to-believe-this-worlds-largest-sovereign-wealth-fund-conned-out-of-10m-in-cyber-attack/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Stop tracking me, Google: Austrian citizen files GDPR legal complaint over Android Advertising ID
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register Privacy pressure group Noyb has filed a legal complaint against Google on behalf of an Austrian citizen, claiming the Android Advertising ID on every Android device is “personal data” as defined by the EU’s GDPR and that […]
The post Stop tracking me, Google: Austrian citizen files GDPR legal complaint over Android Advertising ID appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/14/stop-tracking-me-google-austrian-citizen-files-gdpr-legal-complaint-over-android-advertising-id/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Cyber-attacks hit hospital construction companies
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: BBC Interserve, which helped build Birmingham’s NHS Nightingale hospital, and Bam Construct, which delivered the Yorkshire and the Humber’s, have reported the incidents to authorities. Earlier this month, the government warned healthcare groups involved in the response to […]
The post Cyber-attacks hit hospital construction companies appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/13/cyber-attacks-hit-hospital-construction-companies/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Researchers spot thousands of Android apps leaking user data through misconfigured Firebase databases
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register Security researchers at Comparitech have reported that an estimated 24,000 Android apps are leaking user data because of misconfigured Firebase databases. Firebase is a popular backend service with SDKs for multiple platforms, including Android, iOS, web, C++ and Unity (for […]
The post Researchers spot thousands of Android apps leaking user data through misconfigured Firebase databases appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/13/researchers-spot-thousands-of-android-apps-leaking-user-data-through-misconfigured-firebase-databases/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Papa don't breach: Contracts, personal info on Madonna, Lady Gaga, Elton John, others swiped in celeb law firm ‘hack'
Institute For Ethical Hacking Course and Ethical Hacking Training in Pune – India Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan Credits: The Register Hackers are threatening to release 756GB of A-list celebs’ contracts, recording deals, and other personal info allegedly stolen from a New York law firm. The miscreants have seemingly got their hands on confidential agreements, private correspondence, contact […]
The post Papa don’t breach: Contracts, personal info on Madonna, Lady Gaga, Elton John, others swiped in celeb law firm ‘hack’ appeared first on Extreme Hacking | Sadik Shaikh | Cyber Suraksha Abhiyan | Hackers Charity.
http://blog.extremehacking.org/blog/2020/05/13/papa-dont-breach-contracts-personal-info-on-madonna-lady-gaga-elton-john-others-swiped-in-celeb-law-firm-hack/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
CVE-2019-19781: Citrix ADC RCE vulnerability
A week before the 2019 holidays Citrix announced that an authentication bypass vulnerability was discovered in multiple Citrix products. The affected products are the Citrix Application Delivery Controller (formerly known as NetScaler AD), Citrix Gateway NetScaler ADC (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP appliance. Exploiting the vulnerability could allow an unauthenticated attacker [...]
The post CVE-2019-19781: Citrix ADC RCE vulnerability appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/exploit-tutorials/cve-2019-19781-citrix-adc-rce-vulnerability/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Vulnerability Scanning with OpenVAS 9 part 4: Custom scan configurations
For all scans so far, we've only used the default scan configurations such as host discovery, system discovery and Full & fast. But what if we don't want to run all NVTs on a given target (list) and only test for a few specific vulnerabilities? In this case we can create our own custom scan [...]
The post Vulnerability Scanning with OpenVAS 9 part 4: Custom scan configurations appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/scanning-tutorials/openvas-9-part-4-custom-scan-configurations/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Vulnerability Scanning with OpenVAS 9 part 3: Scanning the Network
In the previous parts of the Vulnerability Scanning with OpenVAS 9 tutorials we have covered the installation process and how to run vulnerability scans using OpenVAS and the Greenbone Security Assistant (GSA) web application. In part 3 of Vulnerability Scanning with OpenVAS 9 we will have a look at how to run scans using different [...]
The post Vulnerability Scanning with OpenVAS 9 part 3: Scanning the Network appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/scanning-tutorials/vulnerability-scanning-with-openvas-9-scanning-the-network/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Vulnerability Scanning with OpenVAS 9 part 2: Vulnerability Scanning
Is the previous tutorial Vulnerability Scanning with OpenVAS 9.0 part 1 we've gone through the installation process of OpenVAS on Kali Linux and the installation of the virtual appliance. In this tutorial we will learn how to configure and run a vulnerability scan. For demonstration purposes we've also installed a virtual machine with Metasploitable 2 [...]
The post Vulnerability Scanning with OpenVAS 9 part 2: Vulnerability Scanning appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/scanning-tutorials/vulnerability-scanning-openvas-9-0-part-2/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
Vulnerability Scanning with OpenVAS 9 part 1: Installation & Setup
A couple years ago we did a tutorial on Hacking Tutorials on how to install the popular vulnerability assessment tool OpenVAS on Kali Linux. We’ve covered the installation process on Kali Linux and running a basic scan on the Metasploitable 2 virtual machine to identify vulnerabilities. In this tutorial I want to cover more details [...]
The post Vulnerability Scanning with OpenVAS 9 part 1: Installation & Setup appeared first on Hacking Tutorials.
https://www.hackingtutorials.org/scanning-tutorials/vulnerability-scanning-openvas-9-pt-1/
Partager : LinkedIn / Twitter / Facebook / View / View (lite)
