The Five Eyes Alliance has published a rare call to action for organizations facing AI threats This article has been indexed from www.infosecurity-magazine.com Read the original article: Five Eyes Group Issues Urgent Call to Tackle Frontier AI Threats
Category: EN
Critical FFmpeg Vulnerability Lets Hackers Execute Remote Code via Malicious Media Files
A critical memory corruption vulnerability in FFmpeg has been disclosed, allowing for remote code execution through specially crafted media files. This flaw, tracked as CVE-2026-8461 and named “PixelSmash,” affects the MagicYUV decoder within FFmpeg’s libavcodec library and has a CVSS…
Cybercriminals Abuse TDS Infrastructure to Bypass Firewalls and Hide Malicious Destinations
Cybercriminals are increasingly abusing traffic distribution systems (TDSs) to evade defenses, conceal malicious destinations, and funnel victims into phishing, fraud, and malware campaigns. Once considered a legitimate marketing tool to route visitors to different content or offers, TDS infrastructure is…
ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity and Access Management
This is the part 3 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1). ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity…
Phishing hides in routine Microsoft 365 workflows
Attackers are abusing Outlook Groups and Microsoft 365 collaboration features to make phishing campaigns appear routine, according to Fortra. “The technique shifts malicious intent away from a single phishing email into a trusted productivity workflow. A user may see what…
Meta Pauses Employee Mouse-Tracking AI Training Program After Internal Data Exposure
Meta has paused its Model Capability Initiative (MCI), an internal program that tracks employee mouse movements, clicks, and keystrokes to train AI models. Thank you for being a Ghacks reader. The post Meta Pauses Employee Mouse-Tracking AI Training Program After…
UK Information Commissioner Resigns After Workplace Probe
Information commissioner John Edwards resigns from role after four years, following independent workplace investigation This article has been indexed from Silicon UK Read the original article: UK Information Commissioner Resigns After Workplace Probe
Apple Supplier Plans HK Listing To Fund Robotics Expansion
Apple iPhone component supplier Lingyi iTech plans second listing as it expands into humanoid robotics, AI servers This article has been indexed from Silicon UK Read the original article: Apple Supplier Plans HK Listing To Fund Robotics Expansion
Squidbleed: 29-Year-Old Squid Bug Leaks User Credentials
Squidbleed is a 29-year-old Squid Proxy flaw that can leak credentials, tokens, and other users’ HTTP data through a memory overread. Researchers at Calif.io have disclosed CVE-2026-47729, a memory leak vulnerability in Squid Proxy that was introduced in 1997 and…
Plans Filed For Second Major Northumberland Data Centre
New application seeks to build campus less than two miles from site of QTS data centre complex at former Blyth Power Station This article has been indexed from Silicon UK Read the original article: Plans Filed For Second Major Northumberland…
FlutterShell Malware Uses C2-Delivered JavaScript Payloads to Evade Sandbox Detection
Targeted macOS endpoint monitoring, the CL-CRI-1089 cluster tied to Operation FlutterBridge repurposes the Flutter framework to deliver a novel macOS malware family dubbed FlutterShell. Rather than rehashing prior campaign reporting, this piece treats recovered artifacts as a technical detection case…
OpenAI takes on Mythos, Klue hits security shops, Five Eyes has eyes on AI
OpenAI takes on Anthropic’s Mythos Klue hack hits security shops Five Eyes has eyes on AI models Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-takes-on-mythos-klue-hits-security-shops-five-eyes-has-eyes-on-ai/ Huge thanks to our episode sponsor, Guardsquare Your backend is only as secure as your frontend. Research…
WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software. Per findings from Kaspersky, the active campaign is targeting users of…
Two Men Plead Guilty To TfL Hack
Two men admit to hacking Transport for London in summer 2024 incident that caused months of chaos, following arrests last year This article has been indexed from Silicon UK Read the original article: Two Men Plead Guilty To TfL Hack
WhatsApp Boss To Step Down After Seven Years
Will Cathcart to move to another role at Meta, with WhatsApp top spot to be taken over by Indian start-up founder Kunal Shah This article has been indexed from Silicon UK Read the original article: WhatsApp Boss To Step Down…
CodeStorm Phishing Campaign Targets M365 Tenants With Token Reuse and Replay Attacks
A multi-organization phishing campaign attributed to the CodeStorm family is actively targeting Microsoft 365 tenants with a tenant-aware AiTM (adversary-in-the-middle) phishing kit that combines rotating frontends and backend replay behavior under a stable controller path, /google.php. The human recipient rarely…
Xsolis Data Breach Affects 1.4 Million Individuals
Threat actors gained access to personal and protected health information that Xsolis received from its clients. The post Xsolis Data Breach Affects 1.4 Million Individuals appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article:…
FortiBleed Campaign Uses FortigateSniffer to Harvest 110 Million Credentials From Fortinet Firewalls
A large-scale credential harvesting campaign called “FortiBleed” has been uncovered, revealing how threat actors are exploiting Fortinet FortiGate firewalls to capture authentication data on an unprecedented scale. Research from the SOCRadar Threat Research Unit (STRU) indicates that this operation has…
Two Scattered Spider Hackers Convicted Over Transport for London Cyber Attack
Two alleged members of the notorious Scattered Spider cybercrime collective have pleaded guilty to orchestrating a disruptive cyber attack against Transport for London (TfL). This marks a significant law enforcement victory against a group known for targeting large enterprises and…
A $1,400 experiment in AI security auditing outperformed OpenAI’s Codex Security
A research team has built a system that teaches AI agents to hunt for software bugs by writing the audit method down as plain text. The system, called EVOHUNT, keeps the underlying AI model fixed and improves only an external…