ποΈ Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an opensource artificial intelligence AI agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39line prompt directs it to execute tasks received through.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
The U.S. Cybersecurity and Infrastructure Security Agency CISA on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities KEV catalog, following reports of active exploitation. The vulnerabilities are listed below CVE202688771 CVSS score 9.5 An improper input validation vulnerability that could allow an unauthenticated attacker to.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π¨ Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway π¨
π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.π Read more.
π Via "UK NCSC"
----------
ποΈ Seen on @cibsecurity
National Cyber Security Centre
Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
π Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Bitget has restarted Bitcoin withdrawals after a 387.5m breach of its hot and warm wallets.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Bitget Restarts Bitcoin Withdrawals Following $387.5m Wallet Breach
Bitget has restarted Bitcoin withdrawals after a $387.5m breach of its hot and warm wallets
π NVIDIA Launches Open Platform to Secure Autonomous AI Agents π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
NVIDIA has launched a platform pairing runtime controls with hardware monitoring for AI agents.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
NVIDIA Launches Open Platform to Secure Autonomous AI Agents
NVIDIA has launched a platform pairing runtime controls with hardware monitoring for AI agents
π Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A quarter of victims of deepfake attacks have lost over 1m. CISOs worry that boardrooms dont understand the threat.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns
A quarter of victims of deepfake attacks have lost over $1m. CISOs worry that boardrooms donβt understand the threat
π MCP Is Creating Major Governance Gaps, Researchers Warn π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Ox Security found security shortcomings in analysis of over 15,000 MCP servers.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
MCP Is Creating Major Governance Gaps, Researchers Warn
Ox Security found security shortcomings in analysis of over 15,000 MCP servers
π Citrix Patches Critical Zero Days Under Active Exploitation π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Citrix has confirmed exploitation of two critical zeroday RCE bugs.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Citrix Patches Critical Zero Days Under Active Exploitation
Citrix has confirmed exploitation of two critical zero-day RCE bugs
π1
π UnderDefense Launches MAXI Service Desk, Delivering Direct Native Support for Enterprise Security Teams π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
New capability embeds SOC analyst communication directly into the UnderDefense platform, replacing slow ticket queues with contextaware, auditready support Jacksonville, FL, September 18, 2026. UnderDefense, a cybersecurity company delivering Agentic AI SOC and Compliance AI to enterprise clients across the US and EU, today announced the launch of MAXI Service Desk. The new native capability The post UnderDefense Launches MAXI Service Desk, Delivering Direct Native Support for Enterprise Security Teams appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
UnderDefense Launches MAXI Service Desk for Enterprise SOCs
UnderDefense introduces MAXI Service Desk, embedding native SOC analyst communication into its platform to deliver direct, context-aware enterprise support.
β€1
π¦
Attack Surface Management in 2026: Why Point-in-Time Scans Canβt Keep Up With Cloud Sprawl π¦
π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cloud infrastructure now changes by the hour, yet many security teams still map their external attack surface once a quarter or once a year. That mismatch creates blind spots that can last for months. A developer spins up a test environment on a Tuesday, an engineer opens a storage bucket for a partner on Wednesday, and a marketing team launches a campaign subdomain on Friday. If the next external assessment is scheduled for December, each of those assets sits exposed and unmonitored until then. For CISOs, security operations leads, and cloud security leads, the question is no longer whether the attack surface is growing. The question is whether visibility is keeping pace. In 2026, pointintime scanning is structurally unable to do that. Why Cloud Sprawl Breaks the Quarterly ...π Read more.
π Via "CYBLE"
----------
ποΈ Seen on @cibsecurity
Cyble
Attack Surface Management in 2026: Why Point-in-Time Scans Canβt Keep Up With Cloud Sprawl
Cloud assets change hourly, but most attack surface management run quarterly. See why continuous ASM with Cyble Odin closes the months-long exposure gaps.