Seventeen Iranians charged with carrying out hacks on thousands of academic, government and private groups around the world in long-running campaign
Tag: EN
Claude AI Finds SAML Security Flaws That Can Let Attackers Take Over Accounts
Security researchers have used Anthropic’s Claude AI to uncover serious flaws in Security Assertion Markup Language (SAML) implementations that could…
Critical GitLab Flaw Exploited Shortly After Disclosure
CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.
Tufin expands Unified Control Plane with AI intelligence and multi-vendor automation
Tufin has announced the availability of Tufin Orchestration Suite (TOS) 5.3, helping enterprises further simplify security operations and maintain…
StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check…
US charges 17 Iranian hackers over 31-terabyte academic data theft
The U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that stole data…
OpenAI rewrites safety rules, US charges 17 Iranian hackers, Defender crashes fixed
OpenAI rewrites safety rules after threshold warning US charges 17 in Iranian hacking campaign Microsoft fixes Windows Defender crash bug Get the show…
Hackers Using AI to Target Siemens PLCs in Critical US Sectors
A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.
HMRC Warns Crypto Holders Over Unpaid Tax
HMRC sends more than 81,000 warning messages to crypto holders suspected of failing to pay capital gains, amid ongoing crackdown
PwC Faces Scrutiny Over AI-Generated Errors in Research Reports
PwC has come under scrutiny over the use of artificial intelligence (AI) in its research publications after an investigation identified fabricated…
AI agent suggested installing a malware package. Engineer almost took its advice
Fortunately, the company had a policy of checking source code on GitHub first
Hackers Impersonate Claude, ChatGPT and Copilot to Deliver Infostealers and Backdoors
Threat actors are increasingly abusing the popularity of generative AI brands to distribute malware, turning trusted names such as Claude, ChatGPT and…
Critical Zimbra RCE Vulnerability Actively Exploited in the Wild
CERT Polska has warned that threat actors are actively exploiting a critical remote code execution vulnerability in Zimbra Collaboration Suite. Tracked as…
Microsoft Defender Update Crashes Virus Scans on Windows PCs
Microsoft Defender has been aborting Quick, Full, and Offline virus scans on Windows systems following a series of Security Intelligence updates released…
13 Malicious Rabby Firefox Extensions Steal Wallet Keyrings Before They Are Encrypted
A broad Firefox add-on campaign that includes 13 malicious Rabby Wallet impersonators engineered to exfiltrate wallet keyring data before the application…
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to…
Critical Citrix NetScaler Flaw Allows Attackers to Bypass Authentication
Cloud Software Group has issued a critical security bulletin regarding two vulnerabilities that affect customer-managed NetScaler ADC and NetScaler…
T-Mobile Physically Cuts Network Cable to Evict Chinese Salt Typhoon Hackers
In 2024, T-Mobile’s security team took an unusually direct approach to contain a cybersecurity threat: they physically cut a network cable to terminate…
Aeternum Operators Use Polygon Smart Contracts to Rotate Malware C2 Domains Dynamically
Aeternum operators are abusing Polygon smart contracts as a decentralized dead-drop resolver, allowing malware to retrieve and rotate command-and-control…
Critical Snowflake GitHub Actions Flaw Allows Attackers to Steal Internal Jira Credentials
A significant GitHub Actions injection vulnerability in Snowflake’s public snowflake-connector-net repository. This flaw could have allowed…