Tag: EN

China-Linked Espionage Cluster Deploys Custom ASPX/ASHX Shells on IIS

A previously disclosed China-linked threat cluster, tracked as OP-512, has been observed deploying a purpose-built web shell framework to compromise Internet Information Services (IIS) servers. Identified by ReliaQuest, the espionage operation targeted a Windows Server 2016 environment running an end-of-life…

Crypto-Funded Chinese Peptide Labs Are Booming

Plus: Hackers use Meta’s AI bots to hack Instagram accounts, Anthropic helps NSA hackers, a decades-long GPS satellite mystery may have been solved, and more. This article has been indexed from Security Latest Read the original article: Crypto-Funded Chinese Peptide…

Malspam Campaign Abuses DoubleClick to Deploy Stealthy .NET Loader

A sophisticated new malspam campaign is actively exploiting Google’s DoubleClick ad-tracking infrastructure to bypass enterprise email security gateways. Discovered by researchers at Huntress, the attack utilizes highly personalized dynamic lures to initiate a complex, five-stage infection chain that actively dismantles…

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-28318 (CVSS score:…

Top 5 Best Tools for Simulated DDoS Attacks in 2026

Last year, a botnet hurled 31.4 Tbps of junk traffic at a single target—enough data to stream every Netflix movie at once. The record-shattering flood forced boards, regulators, and cloud teams to ask one question: are we sure our defenses…

CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical SolarWinds Serv-U vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that threat actors are actively exploiting the flaw in the wild. Tracked as CVE-2026-28318, the vulnerability affects…

Cybersecurity Today Month in Review: Microsoft Zero-Days, AI Deregulation

Host Jim Love and panelists David Shipley, Laura Payne, and Jeff Williams discuss a researcher (“Chaotic/Nightmare Eclipse”) publicly disclosing multiple Windows zero-days affecting components including Defender and BitLocker, frustration with Microsoft’s vulnerability disclosure process, and backlash to Microsoft’s initially threatening…

Researchers build autonomous AI worm that can reason and adapt

<p>University of Toronto researchers said they used open source technology to create an agentic AI worm that reasons and adapts — identifying each targeted device’s unique vulnerabilities and creating tailored attack strategies on the fly.</p> <p>Traditional worms are one-trick ponies…