🖋️ Growing Up The Hard Way 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral. Then,.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Cybersecurity researchers have called attention to an active "widespread emaildriven phishing campaign" that employs adversaryinthemiddle AitM techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious signins as ordinary consumer traffic,.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
A useafterfree bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP reachable should update.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
PortSwigger says HTTP Terminator, an artificial intelligence AIassisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate humanguided discovery cascade also exposed a zeroday in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation NAT connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Entra ID researcher Dirkjan Mollema demonstrated that malware already running in a signedin Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longerterm cloud access, register a device it controls, obtain a Primary Refresh Token PRT, and add further authentication methods where tenant policies.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Cybersecurity researchers have called attention to an active "widespread emaildriven phishing campaign" that employs adversaryinthemiddle AitM techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious signins as ordinary consumer traffic,.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own codingagent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
PortSwigger says HTTP Terminator, an artificial intelligence AIassisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate humanguided discovery cascade also exposed a zeroday in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internetfacing infrastructure for years before training their sights on the software supply chain. "The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastructure,.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Entra ID researcher Dirkjan Mollema demonstrated that malware already running in a signedin Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The attacker can then establish longerterm cloud access, register a device it controls, obtain a Primary Refresh Token PRT, and add further authentication methods where tenant policies.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine VM to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE202664561 and affects KVMx86's shadow memory management unit MMU, which manages shadow page.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own codingagent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor's agent in the configuration that the vendor ships by default, and presented the work at Black Hat USA on August 5.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SDWAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SDWAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. "These vulnerabilities were found.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
📔 Healthcare and Victim Support Charities Affected by Beacon Cyber Incident 📔
📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor.📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Infosecurity Magazine
Healthcare and Victim Support Charities Affected by Beacon Cyber Incid
Beacon has informed around 1500 customer charities that its CRM databases were accessed and likely exfiltrated by an unauthorized actor
🌊 CrowdStrike OverWatch vs. Dedicated AI SOC: When Endpoint-Layer MDR Is No Longer Enough 🌊
📖 Read more.
🔗 Via "UnderDefense"
----------
👁️ Seen on @cibsecurity
Compare CrowdStrike OverWatch vs a dedicated AI SOC and see when endpoint MDR stops covering identity and cloud. Evaluate your options today. The post CrowdStrike OverWatch vs. Dedicated AI SOC When EndpointLayer MDR Is No Longer Enough appeared first on UnderDefense.📖 Read more.
🔗 Via "UnderDefense"
----------
👁️ Seen on @cibsecurity
UnderDefense
CrowdStrike OverWatch vs Dedicated AI SOC: Endpoint Isn't Enough Anymore
Compare CrowdStrike OverWatch vs a dedicated AI SOC and see when endpoint MDR stops covering identity and cloud. Evaluate your options today.
📔 Google Links Redact Extortion Group to BlackFile Rebrand 📔
📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns.📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Infosecurity Magazine
Google Links Redact Extortion Group to BlackFile Rebrand
BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns
🌊 10 Best AI SOC Platforms with Slack and Teams Verification: ChatOps Feature Comparison for SOC Buyers 🌊
📖 Read more.
🔗 Via "UnderDefense"
----------
👁️ Seen on @cibsecurity
Explore how ChatOps verification separates real AI SOC platforms from noisy alert forwarders. Built for CTOs and security operations leaders in 2026 The post 10 Best AI SOC Platforms with Slack and Teams Verification ChatOps Feature Comparison for SOC Buyers appeared first on UnderDefense.📖 Read more.
🔗 Via "UnderDefense"
----------
👁️ Seen on @cibsecurity
UnderDefense
10 Best AI SOC Platforms with Slack and Teams Verification: ChatOps Feature Comparison for SOC Buyers
Explore how ChatOps verification separates real AI SOC platforms from noisy alert forwarders. Built for CTOs and security operations leaders in 2026
📔 Ransomware Surges in July After Q2 Lull 📔
📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech.📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Infosecurity Magazine
Ransomware Surges in July After Q2 Lull
Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech
🦅 Ransomware Threats in Europe H1 2026: A Deep Dive into Regional Attack Patterns and Dominant Threat Actors 🦅
📖 Read more.
🔗 Via "CYBLE"
----------
👁️ Seen on @cibsecurity
Europe faced a ransomware onslaught in the first half of 2026 that sets a troubling precedent for the remainder of the year. According to Cyble Research and Intelligence Labs CRIL, the region experienced 866 documented ransomware attacks, 51 confirmed data breach incidents, and 7 initial access sales between January and June 2026. These figures represent not just a volume problem, but a fundamental shift in how threat actors are organizing, targeting, and monetizing their operations within European territory. What distinguishes the ransomware threats in Europe from other global regions is the concentration of power among a small number of highly sophisticated threat actors. While the threat ecosystem encompasses dozens of groups, five dominant ransomware operators account for approx...📖 Read more.
🔗 Via "CYBLE"
----------
👁️ Seen on @cibsecurity
Cyble
Ransomware Threats In Europe H1 2026: A Deep Dive
Ransomware threats in Europe have escalated in 2026. Know the patterns and dominant actors behind it through Cyble's Research and Intelligences Labs' findings.
📔 Toolkit Hidden Inside Oracle Database Evades Endpoint Tools 📔
📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Attackers used SQL injection to compile a postexploitation toolkit inside an Oracle database.📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Infosecurity Magazine
Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
Attackers used SQL injection to compile a post-exploitation toolkit inside an Oracle database