π New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic
π Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
CloudSEK linked GHAPPIER to a compromised npm package with valid trustedpublishing provenance.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
CloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenance
β€1
π ShinyHunters Claim Hack of Rival Ransomware Gang Clop π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data
π AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A new report by ISACA found that 71 of orgs have not run AI incident response exercises as teams face rising pressure.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds
ISACA found 71% of orgs have not run AI incident response exercises as teams face rising pressure
ποΈ AI Agents Are Rewriting the Rules of Lateral Movement ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π1
ποΈ New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Attackers are exploiting a new flaw in onpremises VeloCloud Orchestrator VCO, the server that manages the Edge devices in a VeloCloud SDWAN, Arista said on September 22. The flaw, tracked as CVE202693952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π North Korean Attackers Hit 30,000 Devices and Steal $10.7m π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets
π’ NCSC talks up agents for cyber defense β but there's an 'inconvenient truth' businesses need to accept π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Cyber defenders need to identify the lowestrisk actions that can be automated before making decisions about adoption.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
NCSC talks up agents for cyber defense β but there's an 'inconvenient truth' businesses need to accept
Cyber defenders need to identify the lowest-risk actions that can be automated before making decisions about adoption
ποΈ Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFixstyle Cloudflare verification checks is part of a wider malwareasaservice MaaS platform called Lunex. The new findings come from Ontinue, which described the activity as a fourstage attack chain aimed at targeting Ukrainianspeaking users. "The attack chain begins with a fake CAPTCHA page and.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π1
ποΈ Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunterslinked activity involves the weaponization of CVE202635273 CVSS score 9.8, a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zeroday.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π1
ποΈ Zero Trust for AI Agents Starts With Fixing Zero Visibility ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Details have emerged about a highseverity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The crosssite request forgery CSRF vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
β€1π₯1
ποΈ SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities KEV catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows CVE202665660 CVSS score 8.8 A code injection vulnerability in Microsoft Office SharePoint.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π₯1
ποΈ Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Kiteworks formerly Accellion is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
β€1π₯1
ποΈ Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Two new unpatched zeroday vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26. Citrix has not confirmed the flaws or published a fix. Some administrators say they have taken appliances offline rather than wait for one to be available. NetScaler ADC and.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π’ UK academic institutions are under assault by hackers π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
New data from SonicWall shows "relentless" ongoing activity by cyber criminals.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
UK academic institutions are under assault by hackers
New data from SonicWall shows "relentless" ongoing activity by cyber criminals
π΅οΈββοΈ AI Agents Are Privileged Users; Who Is Auditing Their Access? π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
AI Agents Are Privileged Users; Who Is Auditing Their Access?
Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges.
β€1
π΅οΈββοΈ Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
A purported adblocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval despite researcher warnings.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
A purported ad-blocker exfiltrates reams of sensitive information, and benefits from having Google's stamp of approval despite researcher warnings.
π΅οΈββοΈ JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack π΅οΈββοΈ
π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
The "agentic threat actor" may have used exposed credentials to access resources and delete cloudbased storage, applications, and databases.π Read more.
π Via "Dark Reading"
----------
ποΈ Seen on @cibsecurity
Dark Reading
JadePuffer AI Actor Compromises Azure in Destructive Cloud Attack
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
π¦Ώ Anthropic Declines Australian AI Hearing as OpenAI Agent Breach Faces Scrutiny π¦Ώ
π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
Anthropic declined an Australian Senate AI hearing as officials investigate an OpenAI agent breach and consider mandatory AI incident reporting. The post Anthropic Declines Australian AI Hearing as OpenAI Agent Breach Faces Scrutiny appeared first on TechRepublic.π Read more.
π Via "Tech Republic"
----------
ποΈ Seen on @cibsecurity
TechRepublic
Anthropic Declines Australia AI Hearing Amid OpenAI Probe
Anthropic declined an Australian Senate AI hearing as officials investigate an OpenAI agent breach and consider mandatory AI incident reporting.
βοΈ Dutch Police Arrest βReformedβ Hacker in Shiny Hunters Investigation βοΈ
π Read more.
π Via "Krebs on Security"
----------
ποΈ Seen on @cibsecurity
Authorities in the Netherlands have arrested a 23yearold convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.π Read more.
π Via "Krebs on Security"
----------
ποΈ Seen on @cibsecurity
Krebs on Security
Dutch Police Arrest βReformedβ Hacker in Shiny Hunters Investigation β Krebs on Security
Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspectβs arrest, remaining ShinyHuntersβ¦