π Inside a ClickFix Attack: How VeiloVPN Hid Its Command Server Inside a Polygon Smart Contract π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
CTOs and SOC Directors explore SOAR, XDR, and agentic AI options for 2026 incident response, with pricing, OSS alternatives, and 30day rollout plans. The post Inside a ClickFix Attack How VeiloVPN Hid Its Command Server Inside a Polygon Smart Contract appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Inside a ClickFix Attack: How VeiloVPN Hid C2 on Polygon
How UnderDefense investigated a ClickFix attack that hid its C2 in a Polygon smart contract using EtherHiding, from the EDR alert to full attribution
β€1
π Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsofts legitimate authentication infrastructure.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Check Point researchers detail phishing attack as an example of attackers dropping fake Microsoft login pages in favor of abusing Microsoftβs legitimate authentication infrastructure
π Google Releases Patches for 370 Vulnerabilities in Chrome 151 π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Google Releases Patches for 370 Vulnerabilities in Chrome 151
The new version of Chrome, 151, comes with 370 vulnerability patches, including for seven critical flaws
π NCSC Calls on Vendors to Embed βForensic Observabilityβ in Network Devices π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The UKs National Cyber Security Centre wants network device makers to improve forensic observability.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
NCSC Calls on Vendors to Embed βForensic Observabilityβ in Devices
The UKβs National Cyber Security Centre wants network device makers to improve forensic observability
π LogoKit Phishing Kit Screenshots Victim Sites in Real Time π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
LogoKit now builds pervictim phishing pages using live screenshots of the target's real website.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
LogoKit now builds per-victim phishing pages using live screenshots of the target's real website
π Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
TA488 returned with OWA halfclick exploit deploying OWAReaper implant that survived reimaging.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
RussianTA488 Returns With Persistent Outlook Web Access Attack
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
π Anthropic Reveals Claude Escaped Testing, Breaching Three Companies π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Anthropic has revealed that Claude AI models broke free of sandbox to compromise thirdparty organizations.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
π€2
π’ Anthropic joins OpenAI in admitting loss of control in cybersecurity tests π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The company found Claude AI had escaped containment three times and targeted other organizations.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Anthropic joins OpenAI in admitting loss of control in cybersecurity tests
The company found Claude AI had escaped containment three times and targeted other organizations
ποΈ Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denialofservice DoS attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
β€1
ποΈ 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Device code phishing the abuse of the OAuth 2.0 device authorization grant to steal access tokens has evolved from a niche redteam technique to an industrialscale threat in under six months. Designed for inputconstrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and usecases that it wasn't originally.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Palo Alto Networks' Unit 42 says a Chinesespeaking threat actor used DeepSeek through the opensource Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internetfacing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Anthropic on Thursday became the latest artificial intelligence AI company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a ".π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
AWS has linked North Korea to the axios campaign to other attacks on npm libraries.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
AWS Blames North Korean Group for npm Supply Chain Attacks
AWS has linked North Korea to the axios campaign to other attacks on npm libraries
ποΈ Cheap Android TV Boxes Pose as Phones and Turn Ownersβ Broadband Into Proxies ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π’ The OpenAI and Anthropic containment breaches are a bit spooky, but also quite silly π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
An AI leaving notes to future versions of itself is pure scifi forgetting to lock down an environment is prosaic.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
The OpenAI and Anthropic containment breaches are a bit spooky, but also quite silly
An AI leaving notes to future versions of itself is pure sci-fi; forgetting to lock down an environment is prosaic
ποΈ HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have shed light on a previously undocumented Gobased loader framework called HollowFrame and a Rustbased malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spearphishing message containing a link to an encrypted archive, which holds a Windows Shortcut LNK. Executing the file triggers a multistage chain that.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π¦Ώ Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Chrome 151 Patches 370 Vulnerabilities, 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now.
ποΈ Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A Chinesespeaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π AI SOC and Analyst Retention: Moving Senior Engineers Off Alert Triage and Onto Work Worth Keeping Them For π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Is SOAR dead? Discover why playbooks stall on investigation and how an AI SOC reasons per alert to cut noise. The post AI SOC and Analyst Retention Moving Senior Engineers Off Alert Triage and Onto Work Worth Keeping Them For appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
Benefits of having an AI SOC over a SOAR
Is SOAR dead? Discover why playbooks stall on investigation and how an AI SOC reasons per alert to cut noise.
π Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A Chinesespeaking threat actor has been using DeepSeeks AI models to orchestrate cyberattacks targeting Asian organizations.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability Exploits
A Chinese-speaking threat actor has been using DeepSeekβs AI models to orchestrate cyber-attacks targeting Asian organizations