Hackers recently abused a SQL injection flaw in a public-facing Java application to plant a post-exploitation toolkit called khunt directly inside an…
Tag: EN
Sysdig: Industry Highlights from Black Hat 2026
Sysdig is acknowledging the fact that CISOs don’t have time to click through a dashboard anymore. Conor Sherman, the company’s Global CISO, argues the…
AvePoint: Industry Highlights from Black Hat 2026
Most organizations think they’ve solved the data sensitivity problem. AvePoint’s research says otherwise. In the company’s third annual State of AI…
Rethinking Cyber Readiness In Our Current Threat Landscape
Cybersecurity leaders are dealing with a threat landscape where disruption spreads quickly across systems, vendors, and business operations. AI is…
Microsoft Windows 11 App Pushes Bing as Default Search in Chrome, Firefox and Brave
Microsoft has built a dedicated Windows 11 app that exists to put Bing in front of users who already chose another search engine. The utility, Microsoft…
The Cyber Resilience Imperative: Why CISOs Must Shift from Prevention to Business Survival
For decades, cybersecurity strategies have been built around a single objective: preventing attacks. Organizations invested heavily in perimeter defenses,…
UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks…
Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email…
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed…
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection
New Cryptographic Context Injection technique bypasses AI guardrails via AES-encrypted payloads, leaking full Grok chat histories zero-click Adversa AI…
ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries
ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda…
Ultra-Wealthy Turn to Premium Services to Erase Their Digital Footprints
For the ultra-wealthy, protecting personal information is increasingly becoming a premium service. High-net-worth individuals and corporations are paying…
Google Tightens Android Sideloading: Unverified Apps Now Face a 24-Hour Wait
Google’s new Android verification flow adds a 24-hour wait for apps from unverified developers as broader identity checks approach.
Syrian migrant smugglers arrested in coordinated strike in Germany and Serbia
This follows several years of intensive and extensive investigations led by the German Federal Police under the direction of three Bavarian Public…
Siemens S7 PLCs Face Emerging Threat From AI-Generated Exploit Scripts
A cyber threat targeting critical infrastructure has been reported by the U.S. government utilizing AI-generated exploit scripts aimed at Siemens…
Loud Phone Use is Becoming A New Battleground for Public-space Etiquette
For commuters, a journey on public transport can now come with an unexpected soundtrack: someone else’s smartphone. A passenger watching videos without…
Frontier AI labs still won’t say how they’d contain a rogue model
A new study finds leading AI labs have few publicly documented plans for containing rogue models, raising questions about preparedness as AI systems…
North Korean Hackers Target 1,640 Companies Across 57 Countries, Researcher Finds
North Korean hackers have been targeting the infrastructure and cryptocurrency wallets worldwide. Greek security expert Vangelis Stykas identified 1,640…
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company…
If you’re not using AI to attack your own systems, your adversaries will
Agents are also the new attack surface – cue defenders’ existential angst