🖋️ CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. Both organizations were fully compromised at the domain level, and in both, the red team also.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
The CERT Coordination Center CERTCC has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE202619913 and CVE202619912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a wellknown pattern an alert arrives a detection engine assigns a severity score. The issue then waits for a human to decide if it should escalate to an investigation. Given the volume of.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
❤1
🖋️ Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Aikido Security has published research that recreates the Australian gymbooking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a clientsideonly booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence AI tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts "were being used to promote the International Burke Institute IBI, a.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
An eightmonth INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks such as the Black Axe and other similar groups," INTERPOL said. "These groups are.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23instruction language of its own design. The sample is an unsigned 64bit Windows dynamiclink library DLL of 59,904 bytes, built to be sideloaded into.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE202660004 CVSS score 9.8, a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
🖋️ Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes 🖋️
📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
Cybersecurity researchers have disclosed details of a phishingasaservice PhaaS platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit STRU said the platform, which it tracks as AnonyMousKIT, is creditmetered and drives lures across.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity
📔 Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel 📔
📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
GroupIB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling tool.📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Infosecurity Magazine
Tortoiseshell Expands Toolset With New Backdoor, SSH Tunnel
Group-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling tool
📔 Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects 📔
📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Interpol operation leads to 58 arrests and identifies 263 suspects across 22 countries.📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Infosecurity Magazine
Interpol Operation Jackal IV Identifies 263 Cybercrime Suspects
Interpol operation leads to 58 arrests and identifies 263 suspects across 22 countries
📔 Four in Five AI Tools Run with No IT Oversight, New Research Finds 📔
📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Reco report reveals growing shadow AI problem and surge in vulnerability disclosures.📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Infosecurity Magazine
Four in Five AI Tools Run with No IT Oversight, Research Finds
Reco report reveals shadow AI and surge in vulnerability disclosures
📔 Average Cyber Insurance Losses Increase Despite Fewer Claims 📔
📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Chubb reported that growing privacy litigation has contributed to surging cyber claim costs in the US.📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Infosecurity Magazine
Average Cyber Insurance Losses Increase Despite Fewer Claims
Chubb reported that growing privacy litigation has contributed to surging cyber claim costs in the US
📔 Linux Foundation Introduces TRACE Standard for AI Runtime Evidence 📔
📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
This new open standard offers hardwareattested runtime and compliance evidence for AI agents.📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Infosecurity Magazine
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
This new open standard offers hardware-attested runtime and compliance evidence for AI agents
📔 DDoS Attack Hits Norwegian Government Services 📔
📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
A coordinated DDoS campaign has caused disruption among Norwegian government services.📖 Read more.
🔗 Via "Infosecurity Magazine"
----------
👁️ Seen on @cibsecurity
Infosecurity Magazine
DDoS Attack Hits Norwegian Government Services
A coordinated DDoS campaign has caused disruption among Norwegian government services
🌊 Arctic Wolf vs. Deepwatch for SIEM Management: Coverage, Pricing, and Data Ownership Compared 🌊
📖 Read more.
🔗 Via "UnderDefense"
----------
👁️ Seen on @cibsecurity
Compare Arctic Wolf vs Deepwatch for SIEM management on coverage, pricing, and data ownership. Discover which fits your team before you sign. The post Arctic Wolf vs. Deepwatch for SIEM Management Coverage, Pricing, and Data Ownership Compared appeared first on UnderDefense.📖 Read more.
🔗 Via "UnderDefense"
----------
👁️ Seen on @cibsecurity
UnderDefense
Arctic Wolf vs Deepwatch for SIEM Management: 8 Criteria That Decide
Compare Arctic Wolf vs Deepwatch for SIEM management on coverage, pricing, and data ownership. Discover which fits your team before you sign.
🌊 How an AiTM Phishing Attack Cleared SPF, DKIM, and MFA 🌊
📖 Read more.
🔗 Via "UnderDefense"
----------
👁️ Seen on @cibsecurity
Compare the 10 best AI SOC platforms that keep your own SIEM data lake. Evaluate data sovereignty, onprem options, and lockin. Explore the shortlist now. The post How an AiTM Phishing Attack Cleared SPF, DKIM, and MFA appeared first on UnderDefense.📖 Read more.
🔗 Via "UnderDefense"
----------
👁️ Seen on @cibsecurity
UnderDefense
How an AiTM Phishing Attack Cleared SPF, DKIM, and MFA
AiTM phishing: domain registered 12 min before delivery, SPF/DKIM passed, MFA relayed by live proxy. Full attack chain, business risk, and containment.
🕵️♂️ Red Flags That Expose Fake North Korean IT Workers 🕵️♂️
📖 Read more.
🔗 Via "Dark Reading"
----------
👁️ Seen on @cibsecurity
North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.📖 Read more.
🔗 Via "Dark Reading"
----------
👁️ Seen on @cibsecurity
Dark Reading
Red Flags That Expose Fake North Korean IT Workers
North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage.
🕵️♂️ Dark Caracal Adds New Malware to Cyber Espionage Arsenal 🕵️♂️
📖 Read more.
🔗 Via "Dark Reading"
----------
👁️ Seen on @cibsecurity
GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.📖 Read more.
🔗 Via "Dark Reading"
----------
👁️ Seen on @cibsecurity
Dark Reading
Dark Caracal Adds New Malware to Cyber Espionage Arsenal
GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.
❤2
📢 Everything we know about the Boston Scientific cyber attack so far 📢
📖 Read more.
🔗 Via "ITPro"
----------
👁️ Seen on @cibsecurity
Details remain limited, but Boston Scientific says it's lost access to some systems and is having problems processing orders.📖 Read more.
🔗 Via "ITPro"
----------
👁️ Seen on @cibsecurity
IT Pro
Everything we know about the Boston Scientific cyber attack so far
Details remain limited, but Boston Scientific says it's lost access to some systems and is having problems processing orders
🕵️♂️ Chinese Routers Sold Worldwide Contain Backdoors 🕵️♂️
📖 Read more.
🔗 Via "Dark Reading"
----------
👁️ Seen on @cibsecurity
An untold number of ZBT routers sold around the world as whitelabel products come with several implants built by the manufacturer.📖 Read more.
🔗 Via "Dark Reading"
----------
👁️ Seen on @cibsecurity
Dark Reading
Chinese Routers Sold Worldwide Contain Backdoors
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.