Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.
Tag: EN
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium…
Google Just Patched a Chrome Security Flaw That Hackers Were Already Exploiting
Before getting into the specifics, it helps to understand what makes this kind of vulnerability different from a regular software bug. A “zero-day” is a…
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and…
Anthropic Researcher Resigns With Warning About the Dangers of AI Development
Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns.
How AI anxieties dominated the summer’s big cybersecurity conference
From the CVE Program to autonomous hacks, everyone is worried about the technology’s next evolution.
Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster
Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox.
ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolen
The ID checking company said the data breach included people’s full names and driver’s licenses and other government-issued identity documents.
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active…
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated…
Syrian migrant smugglers arrested in coordinated strike in Germany and Serbia
This follows several years of intensive and extensive investigations led by the German Federal Police under the direction of three Bavarian Public…
Essential AI agent security questions
AI agents are outpacing legacy IAM. Discover the 3 questions every CISO must ask to secure them.
Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation
Join the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT…
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities
Stealing AI Reasoning Traces
Interesting research: “ Stealing Reasoning Traces from Proprietary LLM APIs “: Abstract: Leading large language model providers now conceal their models’…
Secure AI Coding: Governing every agent, artifact, and identity
Enterprises are seeing an unprecedented surge in AI coding adoption with spend on AI coding tools projected to top $13 billion in this calendar year1,…
36K Plex servers unpatched against recent flaws
More than 36,000 Plex Media Server installations accessible from the internet have not been patched against recently disclosed security vulnerabilities,…
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware…
Trezor Supply Chain Breach Now Impacts 81,000 Customers
Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought
Drug trafficking investigation leads to some of the world’s biggest underground bankers
The investigation, led by the Spanish National Police (Policía Nacional) and supported by Europol, has resulted in the arrest of 21 suspects for offences…