GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution…
Tag: EN
Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Hackers are turning ordinary searches and gaming videos into malware traps. A long-running campaign used YouTube channels and search-engine manipulation…
Hackers Exploit Maximum Severity Flaw in GitLab
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0
Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Casbaneiro is targeting online banking users in Latin America through phishing messages that look like urgent invoices or legal notices. The campaign uses…
Telus Warns Customers of Account Breaches
Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.
Museum heists turn violent: new Europol report on cultural property theft tactics
The spotlight features some key findings:Increasing violence: Museum thefts are becoming more aggressive, with offenders using tools like sledgehammers,…
UK.gov begins killing off passwords for 23 million users
Passkeys promise fewer phishing headaches – and £600 a day off Whitehall’s SMS bill
Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator.
Zero trust is the future. But enterprises still need their VPNs.
Zero trust shouldn’t mean sacrificing the stability and flexibility enterprises still depend on.
Sandworm-Linked Cyclops Blink Returns With Network Scanning and Packet-Sniffing Capabilities
A newly identified Cyclops Blink variant has resurfaced on compromised Cisco Secure Firewall Management Center (FMC) appliances, adding active…
Security teams are adopting AI faster than they trust it
New survey data reveals a widening gap between AI adoption and AI trust.
OpenAI Agent Swarm Hacks RubyGems Package Manager
Researchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGems
WhatsApp Restricted Chat locks a conversation to your primary phone
WhatsApp is building a per-chat setting that keeps a conversation on a single phone. The setting, called Restricted Chat, sits in the Android beta…
Agents of Chaos: A New $100K Agentic Security Challenge
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: Agents of Chaos: A New $100K Agentic Security Challenge
China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for…
ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
The flaw allows attackers to send files and execute them without authorization through an active remote session.
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian…
UK Military Spends Millions On SpaceX Satellite Services
Defence ministry reportedly acknowledges spending tens of millions on SpaceX’s Starlink and Starshield satellite services
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Hackers are using a familiar Windows automation tool to hide AsyncRAT, a remote-access trojan, inside a trusted system process. The campaign starts with a…