ποΈ DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A new Russian loaderasaservice LaaS codenamed DOUBLECUP has been using ClickFix lures as a way to stage malwarelaced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. "The first stage drops a steganographic PNG image into the browser's cache, retrieves its hidden content, and executes the second.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA on Monday added a highseverity security flaw impacting Nable Ncentral to its Known Exploited Vulnerabilities KEV catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE202618577 CVSS score 8.2, is a case of incomplete patching for CVE202618556 CVSS score 8.2 that allows.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π WhatsApp Scam Hijacks Accounts via Linked Devices Feature π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
WhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwords.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
π Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks Across Multiple Sessions π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Talos read attacker prompt logs and found guardrails fell to task splitting and ownership claims.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
π1
π Cloud and SaaS Environments Now Top Targets for Attackers π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
π AI Accounts for Over Half of Cybercrime in Africa, Says Interpol π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Interpol claims AI is driving a surge in cybercrime in Africa, with related losses doubling.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
AI Accounts for Over Half of Cybercrime in Africa, Says Interpol
Interpol claims AI is driving a surge in cybercrime in Africa, with related losses doubling
π UKβs Police National Legal Database Reveals Data Breach π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
The UKs Police National Legal Database and Ask the Police service have been breached.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
UKβs Police National Legal Database Reveals Data Breach
The UKβs Police National Legal Database and Ask the Police service have been breached
π UnderDefense MAXI Notifications β Officially Published in the Slack Marketplace π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
The UnderDefense Notifications Slack app has completed Slacks full marketplace review. It is now publicly listed, verified, and searchable under the UnderDefense name. Security teams connecting their workspaces will no longer see an app not approved by Slack warning during setup. What Changed The app itself, the connection flow, and the underlying data handling are The post UnderDefense MAXI Notifications Officially Published in the Slack Marketplace appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
UnderDefense Is Now an Official Slack Marketplace App
The UnderDefense Notifications app is now officially reviewed and listed in the Slack Marketplace β with a public security profile and no setup warnings.
π MITRE ATT&CK Coverage Comparison: How to Score AI SOC Vendors on Technique Detection Before You Buy π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Discover how to prove AI SOC MITRE ATTCK cloud coverage with adversary emulation, confidence scoring, and onprem telemetry options for compliance. The post MITRE ATTCK Coverage Comparison How to Score AI SOC Vendors on Technique Detection Before You Buy appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
AI SOC MITRE ATT&CK Coverage: Score Cloud Vendors in 6 Steps
Discover how to prove AI SOC MITRE ATT&CK cloud coverage with adversary emulation, confidence scoring, and on-prem telemetry options for compliance.
π¨ NCSC statement in response to recent incidents resulting from frontier AI evaluations π¨
π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
National Cyber Security Centre
NCSC statement in response to recent incidents resulting from frontier AI evaluations
A statement from Ollie Whitehouse, Chief Technology Officer at the NCSC, on AI security following recent incidents.
π’ CMMC phase 2 Is suspended. The liability It created for MSPs isn't π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Why the CMMC regulation is not dead and what MSPs need to do about it.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
ChannelPro
CMMC phase 2 Is suspended. The liability it created for MSPs isn't
Why the CMMC regulation is not dead and what MSPs need to do about it
β€1
π’ Rubrik teams up with Wipro to launch 'enterprise resilience as a service' scheme π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The new joint service aims to sharpen enterprise cyber resilience and recovery capabilities.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Rubrik teams up with Wipro to launch 'enterprise resilience as a service' scheme
The new joint service aims to sharpen enterprise cyber resilience and recovery capabilities
π’ 'The easiest way into a company isn't always through a vulnerability anymore': Hackers are building a global insider threat recruitment network β and theyβre even offering referral bonuses π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Cyber criminals have professionalized the recruitment of company employees to gain access to sensitive information.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
'The easiest way into a company isn't always through a vulnerability anymore': Hackers are building a global insider threat recruitmentβ¦
Cyber criminals have professionalized the recruitment of company employees to gain access to sensitive information
π’ Why quantum-ready data protection belongs in the channel portfolio π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Quantumready, datacentric protection is the channels next major differentiator.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
ChannelPro
Why quantum-ready data protection belongs in the channel portfolio
Quantum-ready, data-centric protection is the channelβs next major differentiator
π’ Attacks on US water systems could be the tip of the iceberg, cyber experts warn π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Internetexposed programmable logic controllers are also found in electric utilities, manufacturing and transportation.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Attacks on US water systems could be the tip of the iceberg, cyber experts warn
Internet-exposed programmable logic controllers are also found in electric utilities, manufacturing and transportation
π’ Anthropicβs Mythos AI tried to dupe devs in social engineering attack, collaborated with other agents π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Interagent collaboration is a serious cause for concern, says security expert.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Anthropicβs Mythos AI tried to dupe devs in social engineering attack, collaborated with other agents
Inter-agent collaboration is a serious cause for concern, says security expert
π’ Cyber criminals are selling discount AI tokens on underground forums π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Sites such as Poison Claude and Ecomagent.in are taking advantage of genuine promo offers and reselling access.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Cyber criminals are selling discount AI tokens on underground forums
Sites such as Poison Claude and Ecomagent.in are taking advantage of genuine promo offers and reselling access
π’ βShai-Hulud: Here We Go Againβ: Thousands of npm packages compromised in βChaindropβ malware campaign where hackers taunt victims π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The Chaindrop infostealer is a variant of the notorious ShaiHulud malware strain.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
βShai-Hulud: Here We Go Againβ: Thousands of npm packages compromised in βChaindropβ malware campaign where hackers taunt victims
The Chaindrop infostealer is a variant of the notorious Shai-Hulud malware strain
π’ Cyber resilience 101: what it means and why Dell PowerProtect One is a vital piece of the puzzle π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Cyber resilience is now a boardlevel priority, and solutions like Dell PowerProtect One can help make all the difference.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
ITPro
Cyber resilience 101: what it means and why Dell PowerProtect One is a vital piece of the puzzle
Cyber resilience is now a board-level priority, and solutions like Dell PowerProtect One can help make all the difference
π’ Microsoft forks out record-breaking sums with expanded bug bounty program π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Hundreds of security researchers won a share of 20 million after the tech giant expanded its bug hunting scheme.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Microsoft forks out record-breaking sums with expanded bug bounty program
Hundreds of security researchers won a share of $20 million after the tech giant expanded its bug hunting scheme
π’ After OpenAI-Hugging Face, how do IT leaders need to change the way they think about AI? π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The OpenAIHugging Face incident and Anthropic admission soon after have opened up new conversations about controls around AI. How should IT leaders change their thinking about the technology?.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
After OpenAI-Hugging Face, how do IT leaders need to change the way they think about AI?
The OpenAI-Hugging Face incident and Anthropic admission soon after have opened up new conversations about controls around AI. How should IT leaders change their thinking about the technology?