Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking Active Directory domain trust on some enterprise computers,…
Tag: EN
AI agents can modify themselves without humans telling them to do so
This is a test – it is only a test
Revolut gave customer IDs and financial data to a government impostor
The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.
Architecting a secure landing zone in the AWS European Sovereign Cloud
The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within…
Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick
Security teams are turning to AI as they struggle to investigate the volume of alerts coming into the SOC, according to new research from Prophet…
LNK Metadata
I ran across this Ctrl-Alt-Intel blog post today, which discusses RustGate v2, and noticed that for all of what was addressed in the blog, there wasn’t a…
BambooToken: The Malware That Speaks MQTT to Stay Under the Radar
Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new…
CISA decides weekly vulnerability bulletin isn’t necessary anymore
Agency’s shift from static CVSS scores to risk-based prioritization sends the old format packing September 28
Microsoft’s Patching
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record : Microsoft’s patch for September is a doozy, with a…
Revolut Confirms Data Breach Through Fake Government Requests
An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data
Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe
An analysis of 160 deepfake websites reveals politicians in 22 countries appear on them. Nearly all of them are women.
Museum heists turn violent: new Europol report on cultural property theft tactics
The spotlight features some key findings:Increasing violence: Museum thefts are becoming more aggressive, with offenders using tools like sledgehammers,…
Hackers Exploit Maximum Severity Flaw in GitLab
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0
China’s Answer to AI Safety: More Controls, Not Slower Development
China is emphasizing technical controls for AI agents as U.S. leaders debate slowing frontier AI, raising new questions for businesses deploying…
Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.
Scans Targeting Hospitality Applications, (Wed, Sep 16th)
Earlier today, I noted an odd request showing up in our “First Seen” report:
Agents of Chaos: A New $100K Agentic Security Challenge
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Agents of Chaos: A New $100K Agentic Security Challenge
UK.gov begins killing off passwords for 23 million users
Passkeys promise fewer phishing headaches – and £600 a day off Whitehall’s SMS bill
OpenSSL 3.0 End of Life
The OpenSSL 3.0 series has reached its End of Life (EOL). As such it will no longer receive publicly available security fixes.
Zero trust is the future. But enterprises still need their VPNs.
Zero trust shouldn’t mean sacrificing the stability and flexibility enterprises still depend on.
