no alarms and no surprises please..
-
TR-26-0086 (KNOWHY İleri Teknoloji – EduAsist Güvenlik Bildirimi)
TR-26-0086 (KNOWHY İleri Teknoloji – EduAsist Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0085 (Signum Teknoloji – windesk.fm Güvenlik Bildirimi)
TR-26-0085 (Signum Teknoloji – windesk.fm Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0084 (Dayneks Yazılım – E-Ticaret Sistemleri Güvenlik Bildirimi)
TR-26-0084 (Dayneks Yazılım – E-Ticaret Sistemleri Güvenlik Bildirimi) Go to usom.gov
-
Pentagon Designates Anthropic Supply Chain Risk Over AI Military Dispute
Pentagon Designates Anthropic Supply Chain Risk Over AI Military Dispute Anthropic on Friday hit back after U.S. Secretary of Defense Pete Hegseth directed the Pentagon to designate the artificial intelligence (AI) upstart as a “supply chain risk.” “This action follows months of negotiations that reached an impasse over two exceptions we requested to the lawful…
-
DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams
DoJ Seizes $61 Million in Tether Linked to Pig Butchering Crypto Scams The U.S. Department of Justice (DoJ) this week announced the seizure of $61 million worth of Tether that were allegedly associated with bogus cryptocurrency schemes known as pig butchering. The confiscated funds were traced to cryptocurrency addresses used for the laundering of criminally…
-
900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks
900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks The Shadowserver Foundation has revealed that over 900 Sangoma FreePBX instances still remain infected with web shells as part of attacks that exploited a command injection vulnerability starting in December 2025. Of these, 401 instances are located in the U.S., followed by 51 in Brazil,…
-
Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor
Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor Cybersecurity researchers have disclosed details of a malicious Go module that’s designed to harvest passwords, create persistent access via SSH, and deliver a Linux backdoor named Rekoobe. The Go module, github[.]com/xinfeisoft/crypto, impersonates the legitimate “golang.org/x/crypto” codebase, but injects malicious code that’s responsible for exfiltrating secrets entered…
-
ScarCruft Uses Zoho WorkDrive and USB Malware to Breach Air-Gapped Networks
ScarCruft Uses Zoho WorkDrive and USB Malware to Breach Air-Gapped Networks The North Korean threat actor known as ScarCruft has been attributed to a fresh set of tools, including a backdoor that uses Zoho WorkDrive for command-and-control (C2) communications to fetch more payloads and an implant that uses removable media to relay commands and breach…
-
Cisco SD-WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775) in active exploitation
Cisco SD-WAN vulnerabilities (CVE-2026-20127, CVE-2022-20775) in active exploitation Categories: Threat Research Tags: advisory, vulnerability, SD-WAN Go to sophos
-
Friday Squid Blogging: Squid Fishing in Peru
Friday Squid Blogging: Squid Fishing in Peru Peru has increased its squid catch limit. The article says “giant squid,” but they can’t possibly mean that. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce…
-
Why Tehran’s Two-Tiered Internet Is So Dangerous
Why Tehran’s Two-Tiered Internet Is So Dangerous Iran is slowly emerging from the most severe communications blackout in its history and one of the longest in the world. Triggered as part of January’s government crackdown against citizen protests nationwide, the regime implemented an internet shutdown that transcends the standard definition of internet censorship. This was…
-
Phishing Attacks Against People Seeking Programming Jobs
Phishing Attacks Against People Seeking Programming Jobs This is new. North Korean hackers are posing as company recruiters, enticing job candidates to participate in coding challenges. When they run the code they are supposed to work on, it installs malware on their system. News article. Bruce Schneier Go to bruce schneier
-
Fake Fedex Email Delivers Donuts!, (Fri, Feb 27th)
Fake Fedex Email Delivers Donuts!, (Fri, Feb 27th) It’s Friday, let’s have a look at another simple piece of malware to close a busy week! I received a Fedex notification about a delivery. Usually, such emails are simple phishing attacks that redirect you to a fake login page to collect your credentials. Here, it was…
-
Life Mirrors Art: Ransomware Hits Hospitals on TV & IRL
Life Mirrors Art: Ransomware Hits Hospitals on TV & IRL HBO’s “The Pitt” is showing audiences what a real Mississippi healthcare system is going through this week, thanks to a ransomware attack. Nate Nelson Go to gbhackers.com
-
Cities Hosting Major Events Need More Focus on Wireless, Drone Defense
Cities Hosting Major Events Need More Focus on Wireless, Drone Defense Major events like the FIFA World Cup need to look beyond traditional physical and cyber security to active and passive wireless threats, say experts. Robert Lemos Go to gbhackers.com
-
The Case for Why Better Breach Transparency Matters
The Case for Why Better Breach Transparency Matters It’s become a standard practice for organizations to disclose the bare minimum about a data breach, or worse — not disclose the incident at all. Elizabeth Montalbano Go to gbhackers.com
-
Claude Code Security Shows Promise, Not Perfection
Claude Code Security Shows Promise, Not Perfection Claude Code’s introduction rippled across the stock market, but researchers and analysts say its impact was overstated, as they peel back the layers. Alexander Culafi Go to gbhackers.com
-
Critical Trend Micro Apex One Vulnerabilities Allow Remote Malicious Code Execution
Critical Trend Micro Apex One Vulnerabilities Allow Remote Malicious Code Execution Trend Micro has disclosed eight security vulnerabilities in its Apex One endpoint protection platform, including two critical-severity flaws that allow unauthenticated remote attackers to… Go to gbhackers.com
-
Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor in Developer Environments
Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor in Developer Environments Malicious actors are abusing Go’s open-source ecosystem by deploying a backdoored crypto module that steals passwords and installs a Rekoobe Linux backdoor on developer… Go to gbhackers.com
-
Infostealers Drive Massive Brute-Force Attacks on Corporate SSO Gateways with Stolen Credentials
Infostealers Drive Massive Brute-Force Attacks on Corporate SSO Gateways with Stolen Credentials The cybersecurity community is witnessing a rise in credential‑stuffing attacks targeting corporate Single Sign‑On (SSO) systems, with recent campaigns focusing on F5 BIG‑IP devices…. Go to gbhackers.com
-
1 Million Records from Dutch Telco Odido Leaked Online in Massive Data Breach
1 Million Records from Dutch Telco Odido Leaked Online in Massive Data Breach The Dutch telecommunications company Odido suffered a massive data breach that exposed the personal information of nearly 700,000 customers. The incident, which included an… Go to gbhackers.com
-
FreeBSD Vulnerabilities Enable Attackers to Crash Entire System
FreeBSD Vulnerabilities Enable Attackers to Crash Entire System The FreeBSD Project has disclosed a critical security vulnerability, tracked as CVE-2025-15576, which allows attackers to escape jail environments and gain unauthorized access to… Go to gbhackers.com
-
Previously harmless Google API keys now expose Gemini AI data
Previously harmless Google API keys now expose Gemini AI data Google API keys for services like Maps embedded in accessible client-side code could be used to authenticate to the Gemini AI assistant and access private data. […] Bill Toulas Go to bleepingcomputer
-
Trend Micro warns of critical Apex One code execution flaws
Trend Micro warns of critical Apex One code execution flaws Trend Micro has patched two critical Apex One vulnerabilities that allow attackers to gain remote code execution (RCE) on vulnerable Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
European DYI chain ManoMano data breach impacts 38 million customers
European DYI chain ManoMano data breach impacts 38 million customers DIY store chain ManoMano is notifying customers of a data breach personal data, which was caused by hackers compromising a third-party service provider. […] Bill Toulas Go to bleepingcomputer
-
Critical Juniper Networks PTX flaw allows full router takeover
Critical Juniper Networks PTX flaw allows full router takeover A critical vulnerability in the Junos OS Evolved network operating system running on PTX Series routers from Juniper Networks could allow an unauthenticated attacker to execute code remotely with root privileges. […] Bill Toulas Go to bleepingcomputer
-
Olympique Marseille confirms ‘attempted’ cyberattack after data leak
Olympique Marseille confirms ‘attempted’ cyberattack after data leak French professional football club Olympique de Marseille has confirmed a cyberattack after a threat actor claimed on Monday that it breached the club’s systems earlier this month. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Defender Uncovers Trojanized Gaming Utility Campaign Targeting Users with RATs and Remote Data Theft
Microsoft Defender Uncovers Trojanized Gaming Utility Campaign Targeting Users with RATs and Remote Data Theft Cybercriminals have found a new way to get past users’ defenses — by hiding malware inside gaming tools that look completely normal. Microsoft’s security team has uncovered an active campaign where attackers are distributing trojanized versions of popular gaming utilities…
-
North Korean APT37 Hackers Leverages Novel Malware to Infect Air‑Gapped Systems
North Korean APT37 Hackers Leverages Novel Malware to Infect Air‑Gapped Systems North Korea-linked threat group APT37 has launched a sophisticated new campaign using a fresh set of custom malware tools specifically designed to reach computers that are not connected to the internet — a type of system long considered among the most secure in the…
-
Claude Code Hacked to Achieve Full RCE and Hijacked Organization API keys
Claude Code Hacked to Achieve Full RCE and Hijacked Organization API keys Critical vulnerabilities in Anthropic’s Claude Code, an AI-powered command-line development tool. The flaws could allow attackers to achieve Remote Code Execution (RCE) and exfiltrate Anthropic API keys by exploiting project configuration files. The issues were reported by Check Point Research (CPR), and Anthropic…
-
1 Million Records from Dutch Telco Odido Published Online After Extortion Attempt
1 Million Records from Dutch Telco Odido Published Online After Extortion Attempt A major data breach has hit Odido, one of the Netherlands’ prominent telecommunications providers, with cybercriminals publishing over one million customer records online following a failed extortion attempt in February 2026. The threat actor group ShinyHunters is believed to be behind the attack,…
-
Google API Keys Expose Private Data Silently Through Gemini
Google API Keys Expose Private Data Silently Through Gemini A critical privilege escalation vulnerability affecting Google Cloud API keys specifically how legacy public-facing keys now silently grant unauthorized access to Google’s Gemini AI endpoints, exposing private files, cached data, and billable AI usage to attackers. For over a decade, Google explicitly instructed developers to embed…
-
TR-26-0083 (Dokuzsoft Teknoloji – E-Commerce Product Güvenlik Bildirimi)
TR-26-0083 (Dokuzsoft Teknoloji – E-Commerce Product Güvenlik Bildirimi) Go to usom.gov
-
Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown
Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown Cybersecurity researchers have disclosed details of a new botnet loader called Aeternum C2 that uses a blockchain-based command-and-control (C2) infrastructure to make it resilient to takedown efforts. “Instead of relying on traditional servers or domains for command-and-control, Aeternum stores its instructions on the…
-
UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoor
UAT-10027 Targets U.S. Education and Healthcare with Dohdoor Backdoor A previously undocumented threat activity cluster has been attributed to an ongoing malicious campaign targeting education and healthcare sectors in the U.S. since at least December 2025. The campaign is being tracked by Cisco Talos under the moniker UAT-10027. The end goal of the attacks is…
-
ThreatsDay Bulletin: Kali Linux + Claude, Chrome Crash Traps, WinRAR Flaws, LockBit & 15+ Stories
ThreatsDay Bulletin: Kali Linux + Claude, Chrome Crash Traps, WinRAR Flaws, LockBit & 15+ Stories Nothing here looks dramatic at first glance. That’s the point. Many of this week’s threats begin with something ordinary, like an ad, a meeting invite, or a software update. Behind the scenes, the tactics are sharper. Access happens faster. Control…
-
Expert Recommends: Prepare for PQC Right Now
Expert Recommends: Prepare for PQC Right Now Introduction: Steal It Today, Break It in a Decade Digital evolution is unstoppable, and though the pace may vary, things tend to fall into place sooner rather than later. That, of course, applies to adversaries as well. The rise of ransomware and cyber extortion generated funding for a…
-
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware A “coordinated developer-targeting campaign” is using malicious repositories disguised as legitimate Next.js projects and technical assessments to trick victims into executing them and establish persistent access to compromised machines. “The activity aligns with a broader cluster of threats that use job-themed lures to blend…
-
LLMs Generate Predictable Passwords
LLMs Generate Predictable Passwords LLMs are bad at generating passwords: There are strong noticeable patterns among these 50 passwords that can be seen easily: All of the passwords start with a letter, usually uppercase G, almost always followed by the digit 7. Character choices are highly uneven for example, L , 9, m, 2,…
-
ISC Stormcast For Friday, February 27th, 2026 https://isc.sans.edu/podcastdetail/9828, (Fri, Feb 27th)
ISC Stormcast For Friday, February 27th, 2026 https://isc.sans.edu/podcastdetail/9828, (Fri, Feb 27th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Your staff are your biggest security risk: AI is making it worse
Your staff are your biggest security risk: AI is making it worse A new report claims that the cost of insider security incidents has surged 20% in two years, reaching an average of US $19.5 million per organization annually, with no sign that the alarming figure is flattening. Read more in my article on the…
-
Notorious ransomware gang allegedly blackmailed by fake FSB officer
Notorious ransomware gang allegedly blackmailed by fake FSB officer There is a certain poetic justice in a cybersecurity-related story that has emerged from Moscow this week: A man has been accused of trying to extort money… from a notorious Russian ransomware gang. Read more in my article on the Hot for Security blog. Graham Cluley…
-
Marquis v. SonicWall Lawsuit Ups the Breach Blame Game
Marquis v. SonicWall Lawsuit Ups the Breach Blame Game When a company gets breached through a third-party security vendor, who should bear responsibility? For one FinTech company, the answer is the firewall provider. Nate Nelson Go to gbhackers.com
-
Cisco SD-WAN Zero-Day Under Exploitation for 3 Years
Cisco SD-WAN Zero-Day Under Exploitation for 3 Years The maximum-severity vulnerability CVE-2026-20127 was exploited by an unknown but sophisticated threat actor who left very little evidence behind. Rob Wright Go to gbhackers.com
-
ServiceNow AI Platform Vulnerability Allows Remote Code Execution
ServiceNow AI Platform Vulnerability Allows Remote Code Execution ServiceNow has disclosed a critical security vulnerability in its AI Platform that could allow unauthenticated attackers to remotely execute code within the ServiceNow Sandbox… Go to gbhackers.com
-
ResidentBat Android Malware Grants Belarusian KGB Ongoing Mobile Access
ResidentBat Android Malware Grants Belarusian KGB Ongoing Mobile Access ResidentBat is a custom Android spyware implant used by the Belarusian KGB to turn seized smartphones into long‑lived surveillance platforms against journalists and civil… Go to gbhackers.com
-
Government Data Stolen After Hacker Jailbreaks Claude AI to Write Malicious Exploit Code
Government Data Stolen After Hacker Jailbreaks Claude AI to Write Malicious Exploit Code A hacker successfully manipulated Anthropic’s Claude AI to launch a sophisticated month-long cyberattack against Mexican government agencies. Between December 2025 and January 2026, the… Go to gbhackers.com
-
New $300 Android RAT Boasts Automated Permission Bypass and Hidden Remote Control
New $300 Android RAT Boasts Automated Permission Bypass and Hidden Remote Control Every so often, a new piece of malware emerges that truly shifts the threat landscape. Oblivion, a newly discovered Android Remote Access Trojan (RAT), appears… Go to gbhackers.com
-
Hydra Saiga Espionage Campaign Targets Critical Utilities Using Telegram C2 for Data Theft
Hydra Saiga Espionage Campaign Targets Critical Utilities Using Telegram C2 for Data Theft Hydra Saiga is running a long-running espionage campaign that abuses Telegram as command-and-control (C2) to infiltrate critical utilities in Central Asia and exfiltrate sensitive… Go to gbhackers.com
-
Medical device maker UFP Technologies warns of data stolen in cyberattack
Medical device maker UFP Technologies warns of data stolen in cyberattack American manufacturer of medical devices, UFP Technologies, has disclosed that a cybersecurity incident has compromised its IT systems and data. […] Bill Toulas Go to bleepingcomputer
-
Fake Next.js job interview tests backdoor developer’s devices
Fake Next.js job interview tests backdoor developer’s devices The Microsoft Defender team has discovered a coordinated campaign targeting software developers through malicious repositories posing as legitimate Next.js projects and technical assessment materials, including recruiting coding tests. […] Bill Toulas Go to bleepingcomputer
-
Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023 Cisco is warning that a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN, tracked as CVE-2026-20127, was actively exploited in zero-day attacks that allowed remote attackers to compromise controllers and add malicious rogue peers to targeted networks. […] Lawrence Abrams Go to bleepingcomputer
-
Chinese cyberspies breached dozens of telecom firms, govt agencies
Chinese cyberspies breached dozens of telecom firms, govt agencies Google’s Threat Intelligence Group (GTIG), Mandiant, and partners disrupted a global espionage campaign attributed to a suspected Chinese threat actor that used SaaS API calls to hide malicious traffic in attacks targeting telecom and government networks. […] Bill Toulas Go to bleepingcomputer
-
Marquis sues SonicWall over backup breach that led to ransomware attack
Marquis sues SonicWall over backup breach that led to ransomware attack Marquis Software Solutions has filed a lawsuit against SonicWall, accusing the cybersecurity company of gross negligence and misrepresentation that allegedly led to a ransomware attack disrupting operations at 74 U.S. banks. […] Bill Toulas Go to bleepingcomputer
-
Firefox 148 Released With Sanitizer API to Disable XSS Attack
Firefox 148 Released With Sanitizer API to Disable XSS Attack Firefox 148 introduces the new standardized Sanitizer API, becoming the first browser to implement it. The update marks a major step forward for web security, giving developers a straightforward and effective way to prevent Cross-Site Scripting (XSS) attacks. XSS is one of the most common…
-
Critical Claude Code Vulnerabilities Enables Remote Code Execution Attacks
Critical Claude Code Vulnerabilities Enables Remote Code Execution Attacks A critical security flaw in Anthropic’s Claude Code demonstrates how threat actors can exploit repository configuration files to execute malicious code and steal sensitive API keys. The vulnerabilities, tracked as CVE-2025-59536 and CVE-2026-21852, highlight a significant shift in the software supply chain threat landscape as AI…
-
27 Years old Telnet Vulnerability Enables Attackers to Gain Root Access
27 Years old Telnet Vulnerability Enables Attackers to Gain Root Access A newly confirmed vulnerability in the telnet daemon (telnetd) in GNU Inetutils has revived a 27-year-old security flaw, allowing attackers to gain root access by exploiting improper sanitization of environment variables, with no authentication required. Tracked as CVE-2026-24061, the flaw exists in GNU Inetutils through…
-
PoC Released for Windows Vulnerability That Allows Attackers to Cause Unrecoverable BSOD Crashes
PoC Released for Windows Vulnerability That Allows Attackers to Cause Unrecoverable BSOD Crashes A proof-of-concept (PoC) exploit has been publicly released for CVE-2026-2636, a newly documented vulnerability in Windows’ Common Log File System (CLFS) driver that allows any low-privileged, unprivileged user to instantly crash a target system into an unrecoverable Blue Screen of Death (BSoD). The…
-
Google Disrupts Chinese Hackers Infrastructre which Breached 53 Telecom and Government Entities
Google Disrupts Chinese Hackers Infrastructre which Breached 53 Telecom and Government Entities A suspected Chinese state-linked hacking group has been caught running one of the most far-reaching cyber espionage operations ever uncovered — silently breaching telecom providers and government bodies across four continents for nearly a decade. Google has now stepped in to dismantle that…
-
TR-26-0082 (ePati Siber Güvenlik – Antikor Next Generation Firewall Güvenlik Bildirimi)
TR-26-0082 (ePati Siber Güvenlik – Antikor Next Generation Firewall Güvenlik Bildirimi) Go to usom.gov
-
Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access
Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access A newly disclosed maximum-severity security flaw in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Catalyst SD-WAN Manager (formerly vManage) has come under active exploitation in the wild as part of malicious activity that dates back to 2023. The vulnerability, tracked as CVE-2026-20127 (CVSS score: 10.0),…
-
Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries
Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries Google on Wednesday disclosed that it worked with industry partners to disrupt the infrastructure of a suspected China-nexus cyber espionage group tracked as UNC2814 that breached at least 53 organizations across 42 countries. “This prolific, elusive actor has a long history of targeting international…
-
Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration
Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration Cybersecurity researchers have disclosed multiple security vulnerabilities in Anthropic’s Claude Code, an artificial intelligence (AI)-powered coding assistant, that could result in remote code execution and theft of API credentials. “The vulnerabilities exploit various configuration mechanisms, including Hooks, Model Context Protocol (MCP) servers, and environment…
-
SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks
SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks The notorious cybercrime collective known as Scattered LAPSUS$ Hunters (SLH) has been observed offering financial incentives to recruit women to pull off social engineering attacks. The idea is to hire them for voice phishing campaigns targeting IT help desks, Dataminr said…
-
Top 5 Ways Broken Triage Increases Business Risk Instead of Reducing It
Top 5 Ways Broken Triage Increases Business Risk Instead of Reducing It Triage is supposed to make things simpler. In a lot of teams, it does the opposite. When you can’t reach a confident verdict early, alerts turn into repeat checks, back-and-forth, and “just escalate it” calls. That cost doesn’t stay inside the SOC; it…
-
Poisoning AI Training Data
Poisoning AI Training Data All it takes to poison AI training data is to create a website: I spent 20 minutes writing an article on my personal website titled “The best tech journalists at eating hot dogs.” Every word is a lie. I claimed (without evidence) that competitive hot-dog-eating is a popular hobby among tech…
-
Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance [Guest Diary], (Tue, Feb 24th)
Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance [Guest Diary], (Tue, Feb 24th) [This is a Guest Diary by Austin Bodolay, an ISC intern as part of the SANS.edu BACS program] Over the past several months, I have gained practical insight into the challenges of deploying and operating a honeypot,…
-
ISC Stormcast For Thursday, February 26th, 2026 https://isc.sans.edu/podcastdetail/9826, (Thu, Feb 26th)
ISC Stormcast For Thursday, February 26th, 2026 https://isc.sans.edu/podcastdetail/9826, (Thu, Feb 26th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies [Guest Diary], (Wed, Feb 25th)
The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies [Guest Diary], (Wed, Feb 25th) [This is a guest diary contributed by Claire Perry (LinkedIn)] The structural integrity of modern society is predicated upon a dense and often opaque network of interconnected systems. For decades, the modeling of these systems remained siloed…
-
Smashing Security podcast #456: How to lose friends and DDoS people
Smashing Security podcast #456: How to lose friends and DDoS people When the mysterious operator of an internet archiving-service decided to silence a curious Finnish blogger, they didn’t just send a stroppy email – they allegedly weaponised their own CAPTCHA page to launch a DDoS attack, threatened to invent an entirely new genre of AI…
-
$10,000 bounty offered if you can hack Ring cameras to stop them sharing your data with Amazon
$10,000 bounty offered if you can hack Ring cameras to stop them sharing your data with Amazon Amid a privacy backlash, a US $10,000 reward has been offered for anyone who can find a way to run Ring doorbell cameras locally, cutting off the flow of video data to Amazon’s servers. Read more in my…
-
Flaws in Claude Code Put Developers’ Machines at Risk
Flaws in Claude Code Put Developers’ Machines at Risk The vulnerabilities highlight a big drawback to integrating AI into software development workflows and the potential impact on supply chains. Jai Vijayan Go to gbhackers.com
-
RAMP Forum Seizure Fractures Ransomware Ecosystem
RAMP Forum Seizure Fractures Ransomware Ecosystem Researchers suggest defenders monitor how these malicious groups re-form and leverage the useful threat intel to guide their next moves. Alexander Culafi Go to gbhackers.com
-
Chinese Police Use ChatGPT to Smear Japan PM Takaichi
Chinese Police Use ChatGPT to Smear Japan PM Takaichi A Chinese keyboard warrior inadvertently leaked information about politically motivated influence operations through a ChatGPT account. Nate Nelson Go to gbhackers.com
-
Malicious Next.js Repos Target Developers Via Fake Job Interviews
Malicious Next.js Repos Target Developers Via Fake Job Interviews Linked to North Korean fake job-recruitment campaigns, the poisoned repositories are aimed at establishing persistent access to infected machines. Elizabeth Montalbano Go to gbhackers.com
-
Why ‘Call This Number’ TOAD Emails Beat Gateways
Why ‘Call This Number’ TOAD Emails Beat Gateways Attackers are bypassing email gateways through telephone-oriented attack delivery (TOAD), in which the only email payload is a phone number. Alexander Culafi Go to gbhackers.com
-
‘Richter Scale’ Model Measures Magnitude of OT Cyber Incidents
‘Richter Scale’ Model Measures Magnitude of OT Cyber Incidents ICS/OT experts have devised a scoring system for rating the severity and effects of cybersecurity events in operational technology environments. Kelly Jackson Higgins Go to gbhackers.com
-
Critical SolarWinds Serv-U Vulnerabilities Enable Remote Root Access
Critical SolarWinds Serv-U Vulnerabilities Enable Remote Root Access SolarWinds has released a critical security update for its Serv-U file transfer software, patching four vulnerabilities that could allow attackers to execute arbitrary code… Go to gbhackers.com
-
Cybercriminals Exploit Fake Avast Website to Steal Users Credit Card Information
Cybercriminals Exploit Fake Avast Website to Steal Users Credit Card Information Cybercriminals have launched a convincing phishing operation by building a fake Avast website designed to steal credit card information from unsuspecting visitors. The fraudulent… Go to gbhackers.com
-
Android RAT SURXRAT Grants Hackers Full Device Control and Data Exfiltration
Android RAT SURXRAT Grants Hackers Full Device Control and Data Exfiltration SURXRAT is an actively developed Android Remote Access Trojan (RAT) sold as a commercial malware-as-a-service (MaaS) on Telegram, giving attackers full device control and… Go to gbhackers.com
-
Threat Actors Exploit Apache ActiveMQ Vulnerability to Gain RDP Access, Deploy LockBit Ransomware
Threat Actors Exploit Apache ActiveMQ Vulnerability to Gain RDP Access, Deploy LockBit Ransomware Threat actors recently abused a critical Apache ActiveMQ vulnerability to gain deep access to a Windows environment, eventually deploying LockBit ransomware over RDP. The attack shows… Go to gbhackers.com
-
OAuth Vulnerabilities in Entra ID Could Exploit ChatGPT to Breach User Email Accounts
OAuth Vulnerabilities in Entra ID Could Exploit ChatGPT to Breach User Email Accounts OAuth consent attacks in Microsoft Entra ID are giving threat actors a stealthy path to cloud email, and even trusted apps like ChatGPT can… Go to gbhackers.com
-
Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker
Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker The former head of Trenchant, a specialized U.S. defense contractor unit, was sentenced Tuesday to more than seven years in federal prison for stealing and selling zero-day exploits to a Russian exploit broker whose clients include the Russian government. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5077241 update improves BitLocker, adds Sysmon tool
Windows 11 KB5077241 update improves BitLocker, adds Sysmon tool Microsoft has released the KB5077241 optional cumulative update for Windows 11, which comes with 29 changes, including improvements to BitLocker, a new network speed test tool, and native System Monitor (Sysmon) functionality. […] Sergiu Gatlan Go to bleepingcomputer
-
Phishing campaign targets freight and logistics orgs in the US, Europe
Phishing campaign targets freight and logistics orgs in the US, Europe A financially motivated threat group dubbed “Diesel Vortex” is stealing credentials from freight and logistics operators in the U.S. and Europe in phishing attacks using 52 domains. […] Bill Toulas Go to bleepingcomputer
-
Wynn Resorts confirms employee data breach after extortion threat
Wynn Resorts confirms employee data breach after extortion threat Wynn Resorts has confirmed that a hacker stole employee data from its systems after the company was listed on the ShinyHunters extortion gang’s data leak site. […] Lawrence Abrams Go to bleepingcomputer
-
1Campaign platform helps malicious Google ads evade detection
1Campaign platform helps malicious Google ads evade detection A newly identified cybercrime service known as 1Campaign is enabling threat actors to run malicious Google Ads that remain online for extended periods while evading scrutiny from security researchers. […] Bill Toulas Go to bleepingcomputer
-
Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft
Multiple Vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker Allow Root Access and Credential Theft Multiple vulnerabilities have been discovered in CryptoPro Secure Disk (CPSD) for BitLocker, a widely used encryption solution. These flaws could allow an attacker with physical access to a device to gain persistent root access and steal sensitive credentials. The issues…
-
Microsoft Warns of Hackers Attacking Developers with Malicious Next.js Repositories
Microsoft Warns of Hackers Attacking Developers with Malicious Next.js Repositories A coordinated attack campaign is actively targeting software developers through malicious repositories disguised as legitimate Next.js projects and technical assessment materials. The attackers rely on job-themed lures, presenting fake recruitment challenges that convince developers to clone and run poisoned code on their own machines. Once…
-
Microsoft Released Updates for Windows 11, Version 25H2 and 24H2 Systems
Microsoft Released Updates for Windows 11, Version 25H2 and 24H2 Systems An optional non-security update, KB5077241, has been released for Windows 11 versions 25H2 and 24H2, improving overall functionality, performance, and reliability without addressing security vulnerabilities. The release, which brings the OS builds to 26200.7922 and 26100.7922, includes enhancements to user interface elements and updates…
-
Threat Actors Exploit Apache ActiveMQ Server Vulnerability to Gain RDP Access and Deploy LockBit Ransomware
Threat Actors Exploit Apache ActiveMQ Server Vulnerability to Gain RDP Access and Deploy LockBit Ransomware A critical vulnerability in Apache ActiveMQ has been actively exploited by threat actors, leading to a full LockBit ransomware deployment across an enterprise network. Attackers leveraged CVE-2023-46604, a remote code execution flaw in the ActiveMQ messaging broker, to break into…
-
GitHub Copilot Exploited to Perform Full Repository Takeover via Passive Prompt Injection
GitHub Copilot Exploited to Perform Full Repository Takeover via Passive Prompt Injection A critical AI-driven vulnerability in GitHub Codespaces, dubbed RoguePilot, that enabled attackers to silently hijack a repository by embedding malicious instructions inside a GitHub Issue. The flaw, uncovered by researchers at the Orca Research Pod, exploits the seamless integration between GitHub Issues and…
-
Operation Red Card 2.0 Leads to 651 Arrests in Africa
Operation Red Card 2.0 Leads to 651 Arrests in Africa In the latest operation targeting cybercrime groups, African law enforcement agencies cooperated with Interpol and cybersecurity firms to recover more than USD 4.3 million. Robert Lemos Go to gbhackers.com
-
CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability
CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed vulnerability in FileZen to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-25108 (CVSS v4 score: 8.7), is a case of operating system (OS) command injection…
-
RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN
RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN A vulnerability in GitHub Codespaces could have been exploited by bad actors to seize control of repositories by injecting malicious Copilot instructions in a GitHub issue. The artificial intelligence (AI)-driven vulnerability has been codenamed RoguePilot by Orca Security. It has since been patched by Microsoft…
-
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware A Russia-aligned threat actor has been observed targeting a European financial institution as part of a social engineering attack to likely facilitate intelligence gathering or financial theft, signaling a possible expansion of the threat actor’s targeting beyond Ukraine and into entities supporting the war-torn…
-
Identity Prioritization isn’t a Backlog Problem – It’s a Risk Math Problem
Identity Prioritization isn’t a Backlog Problem – It’s a Risk Math Problem Most identity programs still prioritize work the way they prioritize IT tickets: by volume, loudness, or “what failed a control check.” That approach breaks the moment your environment stops being mostly-human and mostly-onboarded. In modern enterprises, identity risk is created by a compound…
-
Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks
Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the Middle East, according to a new report by the Symantec and Carbon Black Threat Hunter Team. Broadcom’s threat…
-
Nowhere, man: The 2026 Active Adversary Report
Nowhere, man: The 2026 Active Adversary Report <p>AI headline hype didn’t deliver a sea change for practical defense — but one below-the-radar development should</p> Categories: Security Operations, Threat Research Tags: Active Adversary, Active Adversary Report Go to sophos
-
Is AI Good for Democracy?
Is AI Good for Democracy? Politicians fixate on the global race for technological supremacy between US and China. They debate geopolitical implications of chip exports, latest model releases from each country, and military applications of AI. Someday, they believe, we might see advancements in AI tip the scales in a superpower conflict. But the most…