ποΈ β‘ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don't file tickets. That's the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a queue too.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the change, and quietly steer its answers in later sessions. When it works, the person reads an ordinarylooking reply and never learns their assistant was tampered with. The.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A new phishingasaservice PhaaS operation called Forg365 is using a combination of device code phishing, adversaryinthemiddle AitM tactics, antibot evasion, artificial intelligence AIassisted lure creation, and postcompromise mailbox operations targeting Microsoft 365 accounts. Distributed via Telegram and costing 400 a month or 3,800 per year, attack chains leverage phishing.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Meta has filed a patent application for an AI that listens to your voice throughout the day, works out how it thinks you are feeling from the way you sound, and keeps a timestamped log of every read. Each read gets pinned to the moment it happened the time, your location, what you were doing, even how you were using your phone. Some versions in the filing would listen all day others would.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A few days ago, I was sitting with the CISO of a Fortune 50 company, walking through how his security team was thinking about AI agents in the SOC. Smart team. Serious program. They had already connected Claude to a few detection tools and were seeing real value in specific investigations. But as we mapped out the broader architecture, something kept nagging at me. The design they were building.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibecoded PowerShell script for Active Directory AD enumeration. "The script looked for the Domain Controller DC and mapped users, computers, and domains, before creating a directory and exporting out a number of files, and finally creating ADReport.html to measure the success of the.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it python3 m http.server 8080, was still sitting in the readable .bashhistory. From that one lapse, French security firm Lexfo lifted the operator's entire toolkit and pivoted through it to two more.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA has added two maximumseverity security flaws impacting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities KEV catalog, following reports of zeroday exploitation in the wild. The vulnerabilities, both rated 10.0 on the CVSS scoring system, are below CVE202648939 A vulnerability in the.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π¨ UK and Allies urge critical sectors to improve defences against Russian intelligence targeting π¨
π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
New advisory highlights Russian state cyber actors global exploitation of poorly configured routers.π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
National Cyber Security Centre
UK and Allies urge critical sectors to improve defences against Russian intelligence targeting
New advisory highlights Russian state cyber actorsβ global exploitation of poorly configured routers
π Open Directory Exposes Three Evilginx Phishing Operators π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Open Directory Exposes Three Evilginx Phishing Operators
Misconfigured server exposed three phishing operators running Evilginx forks to bypass MFA
π Pakistani Police Systems Hit by Chinese and Indian Espionage π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Pakistani Police Systems Hit by Chinese and Indian Espionage
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found
π Novel OAuth Client ID Spoofing Technique Targets Cloud Environments π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
New research reveals cyberattackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments
π Progress Software Warns of "External Security Threat" to ShareFile π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Progress Software, the provider of the popular filesharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone Controller.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Progress Software Warns of βExternal Security Threatβ to ShareFile
Progress Software, the provider of the popular file-sharing and data storage solutions, has urged customers to shut down the server hosting their Storage Zone Controller
π Russian State Hackers Target Vulnerable Routers Worldwide, Joint Advisory Warns π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Cybersecurity agencies from 12 countries have warned that Russian statebacked hackers are actively targeting vulnerable routers using weak SNMP credentials.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Russian State Hackers Target Vulnerable Routers Worldwide
Cybersecurity agencies from 12 countries have warned that Russian state-backed hackers are actively targeting vulnerable routers using weak SNMP credentials
π Hacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware Charges π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
An Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operation.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Hacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware Charge
An Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operation
π Australian Cyber Agency Warns of Global CMS Exploitation Campaign π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Australian Cyber Agency Warns of Global CMS Exploitation Campaign
Australian Cyber Security Centre warns CMS users of mass scanning and exploitation campaign
π The Budget Line That Did Not Exist Last Year: Where AI SOC Sits in a 2027 Plan π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Explore how to fund the new AI SOC budget line through tool consolidation, NIST CSF mapping, and a boardready lossexposure story. The post The Budget Line That Did Not Exist Last Year Where AI SOC Sits in a 2027 Plan appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
The Budget Line That Did Not Exist Last Year: Where AI SOC Sits in a 2027 Plan
Explore how to fund the new AI SOC budget line through tool consolidation, NIST CSF mapping, and a board-ready loss-exposure story.
π AI SOC Pricing: What are the parameters you should account for? The hidden Costs and TCO π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
AI SOC pricing rarely matches the quote. Discover the hidden costs, real TCO, and pricing models security leaders must model first. The post AI SOC Pricing What are the parameters you should account for? The hidden Costs and TCO appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
AI SOC Pricing: What are the parameters you should account for?
AI SOC pricing rarely matches the quote. Discover the hidden costs, real TCO, and pricing models security leaders must model first.
π Lawyer π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
The post Lawyer appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Lawyer - UnderDefense
π’ Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
UAT11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe
UAT-11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims
π’ Why Microsoft paused Patch Tuesday updates for some Dell devices π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Select devices running Intel Innovation Platform Framework drivers encountered poor performance.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Why Microsoft paused Patch Tuesday updates for some Dell devices
Select devices running Intel Innovation Platform Framework drivers encountered βpoor performanceβ