access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 3
Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At…
-
Bitdefender finds preinstalled Android malware you can’t uninstall, seen in 150 countries
Bitdefender finds Midnight Mimosa, preinstalled Android malware on cheap MediaTek phones that fakes ad clicks, drops apps and builds a proxy botnet. Bitdefender researchers discovered a campaign called Midnight Mimosa involving preinstalled Android malware on low-cost phones from different brands that use MediaTek platforms. The malware is built into the device firmware and may be…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 118
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure UAC-0277: ClickFix on compromised websites to spread LUNEXSTEALER MALFEX A malicious npm postinstall no advisory has caught for fourteen months Canto incognito: tracking the PoeLLM malware […]…
-
Nippon Columbia malware incident exposes 8.6 million karaoke fan records
Daiichi Kosho, a major Japanese entertainment system maker, disclosed that a malware infection at its contractor, Nippon Columbia, exposed more than 8.7 million customer and employee records. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/nippon-columbia-malware-incident-exposes-86-million-karaoke-fan-records/ also interesting: FBI warns that end of life devices are being actively targeted by threat actors Unveiling 0bj3ctivityStealer’s Execution Chain:…
-
Security Affairs newsletter Round 599 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Anthropic Restricts Live Internet Access After Claude Evaluation Failures Silent Ransom Group Allegedly Extorted $207 Million Without…
-
KI-Modelle werden austauschbar – der Wettbewerbsvorteil liegt in der Architektur
KI-Modelle werden günstiger, doch Agenten treiben die Kosten. Warum Model Routing, AI Gateways und Governance über den KI-Erfolg entscheiden. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ki-modelle-werden-austauschbar-der-wettbewerbsvorteil-liegt-in-der-architektur/a46716/ also interesting: AI in the Enterprise: Key Findings from the ThreatLabz 2025 AI Security Report The Full Lifecycle Imperative: Why >>Shift Left<>Shift Right<< The cybercrime industry continues to…
-
U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The five vulnerabilities have been added to a broader list of flaws linked to cyber…
-
Week in review: FortiBleed is still active, Patch Tuesday forecast
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Three questions a hospital CISO should ask a healthcare fintech vendor In … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/11/week-in-review-fortibleed-is-still-active-patch-tuesday-forecast/ also interesting: Week in review: 10 must-read cybersecurity books, AnyDesk hack, Patch Tuesday forecast 5 things to know about…
-
‘You have a meeting’: the calendar phishing scam growing exponentially
Appointment or renewal reminder appears in victims’ calendar to lure them into logging in to fake Google, Microsoft or PayPal pageYou’re preparing for the week ahead and take a look at your Google calendar. There’s an entry for a meeting that you must have completely forgotten. The note that pops up when you click on…
-
Anthropic Restricts Live Internet Access After Claude Evaluation Failures
Anthropic’s models kept working around the rules on the live internet. The company published the cases. Anthropic released a report on unintended actions its Claude models took during evaluations and internal use. The cases involved real websites and real organizations outside the company. Anthropic says the impact was minimal, and it published them anyway. The…
-
Windows-Server im Mittelstand Lizenzmodelle, CALs und was die Kosten wirklich treibt
Tags: windowsDie Kostenfrage einer Windows-Server-Umgebung lässt sich an der Quelle nicht beantworten. Auf der Preisseite des Herstellers steht statt der Beträge der Platzhalter ‘VARIABLE”, dazu der Verweis auf den zuständigen Kundenbetreuer. Listenpreise weist der Hersteller dort also nicht aus. Für die Budgetplanung im Mittelstand bleibt der Weg über die Struktur, und die ist belegbar. Vier Größen…
-
ARTEX AI, Claude agents used in cyberattacks on South Korean banks
The cyberattacks that shook the South Korean financial sector earlier this month were launched by a Chinese hacker using the ARTEX AI penetration testing suite and Claude agents. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hacker-used-artex-ai-and-claude-agents-to-target-south-korean-banks/ also interesting: China-linked hackers target Japan’s national security and high-tech industries The 14 most valuable cybersecurity certifications What is…
-
Cyber exec arrested in case allegedly tied to ShinyHunters hackers
Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI’s ongoing crackdown on the ShinyHunters hacking group. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cyber-exec-arrested-in-case-allegedly-tied-to-shinyhunters-hackers/ also interesting: Cybersecurity Snapshot: AI Security Skills Drive Up Cyber Salaries, as Cyber Teams Grow Arsenal…
-
Cyber exec arrested in case allegedly tied to ShinyHunters hackers
Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI’s ongoing crackdown on the ShinyHunters hacking group. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cyber-exec-arrested-in-case-allegedly-tied-to-shinyhunters-hackers/ also interesting: Cybersecurity Snapshot: AI Security Skills Drive Up Cyber Salaries, as Cyber Teams Grow Arsenal…
-
Canadian cybersecurity executive arrested in federal extortion case
Details of the case align with the investigation into ShinyHunters’ attack on FBI IT systems. First seen on cyberscoop.com Jump to article: cyberscoop.com/edward-dubrovsky-cypfer-arrested-fbi-extortion-charges/ also interesting: Is the tide turning on macOS security? 8 Cyber Predictions for 2025: A CSO’s Perspective Two U.S. Cybersecurity Professionals Plead Guilty to Acting as ALPHV/BlackCat Affiliates Silent Ransom Group targets…
-
Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
Traditional attack surface management helps organizations discover exposed assets, but visibility alone is not enough to address threats. Criminal IP introduces AITEM, an AI-powered approach that connects exposure discovery with investigation, risk prioritization, and response. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/criminal-ip-introduces-aitem-as-the-next-evolution-of-attack-surface-management/ also interesting: Securing cloud-native applications: Why a comprehensive API security strategy is…
-
The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn’t
In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid them, but because an identity stack can only govern what authenticates through it, and most…
-
AI Is Getting Really Good at Messing With Cybercriminals
Anti-cybercrime initiatives are increasingly using AI to scam the scammers by tricking them into talking to lifelike bots that they think are real victims. First seen on wired.com Jump to article: www.wired.com/story/ai-is-getting-really-good-at-messing-with-cybercriminals/ also interesting: Top 12 ways hackers broke into your systems in 2024 Meet GhostGPT: The Malicious AI Chatbot Fueling Cybercrime and Scams Next…
-
FBI Arrests Ransomware Negotiation Firm Co-Founder in ShinyHunters Probe
Tags: ransomwareFBI arrests Cypfer co-founder Edward Dubrovsky, now associated with CyberSteward, in the ShinyHunters investigation into the FBI jobs… First seen on hackread.com Jump to article: hackread.com/fbi-arrests-ransomware-negotiation-founder-shinyhunters/ also interesting: Ermittler gelingt Schlag gegen LockBit-Bande The Notorious Lockbit Ransomware Gang Has Been Disrupted by Law Enforcement Sophos Ransomware in Retail Studie zeigt Einzelhandel massiv unter Druck MonsterCloud…
-
Strafjustiz: UN warnt vor Missbrauch von Neurotechnologie
Tags: unclassifiedUN-Generalsekretär Guterres warnt erstmals vor Neurotechnologie. Staaten könnten Gehirne auslesen und Grundrechte verletzen. First seen on golem.de Jump to article: www.golem.de/news/strafjustiz-un-warnt-vor-missbrauch-von-neurotechnologie-2610-213952.html also interesting: Datenschutz: Kabinett beschließt neue Regeln für IP-Auskunft … Beijing issues list of approved CPUs with no Intel or AMD IT-Security: Fachkräfte sind begehrt primär in diesem Bereich sticht der Bedarf heraus Certification…
-
Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws
Anthropic on Friday said it’s cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited misaligned behavior and targeted real websites.The AI company said it identified four broad categories of unintended model actions during evaluations and internal use of Claude –…
-
Security Threats Don’t Stop at the Office: Why Executives’ Families Need Training, Too
Those closest to executives must match their security postures because the weakest link in a family can become the entry point for attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/security-threats-don-t-stop-at-the-office-why-executives-families-need-training-too also interesting: Talent overlooked: embracing neurodiversity in cybersecurity Clément Domingo: “We are not using AI correctly to defend ourselves” Vaillant CISO: NIS2 complexity and…
-
Why websites need to assess the Wikimedia attack
An OpenAI bot overloaded Wikimedia, attacked a system at the foundation and attempted to change entries First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366652022/Why-websites-need-to-assess-the-Wikimedia-attack also interesting: Third-Party ChatGPT Plugins Could Lead to Account Takeovers AI programming copilots are worsening code security and leaking more secrets HackedGPT: Novel AI Vulnerabilities Open the Door for Private Data…
-
Asos Hackers Claim Breach of Snowflake-Connected Simon AI
Snowflake-Connected Marketing Tool Appears to Be Source of Customer Data Breach. Fast-fashion retailer Asos’ hacker claims to have stolen customer data by breaching a marketing tool called Simon AI, integrated with the victim’s Snowflake cloud-based data warehousing platform. By default, Simon AI doesn’t require multifactor authentication, a cybersecurity expert warned. First seen on govinfosecurity.com Jump…
-
Suspected ShinyHunters Extortion Hacker Arrested by FBI
FBI Vows to Dismantle Hacking Group After It Stole FBI Personnel Data. The FBI announced Friday the arrest of a suspected hacker behind the breach of a bureau HR system, marking the second recent detention of an alleged member of the ShunyHunters extortion group. The suspect, arrested earlier week in Pennsylvania, is a Canadian citizen.…
-
MonsterCloud CEO Zohar Pinhasi Accused of Paying Hackers, Defrauding Victims
The DOJ accuses MonsterCloud CEO Zohar Pinhasi of secretly paying ransomware gangs for decryption keys while charging victims… First seen on hackread.com Jump to article: hackread.com/monstercloud-ceo-zohar-pinhasi-ransomware-victims/ also interesting: UnitedHealth CEO Says Hackers Lurked in Network for Nine Days Before Ransomware Strike Starbucks operations hit after ransomware attack on supply chain software vendor DOJ charges ransomware…
-
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.”Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker’s infrastructure,” iVerify said in a new report published Thursday.The name…
-
Security Threats Don’t Stop at the Office: Why Executives’ Families Need Training Too
Those closest to executives must match their security postures because the weakest link in a family becomes the entry point for attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/security-threats-don-t-stop-at-the-office-why-executives-families-need-training-too also interesting: Security leaders top 10 takeaways for 2024 Cybersecurity Snapshot: What Looms on Cyberland’s Horizon? Here’s What Tenable Experts Predict for 2025 Blown the…
-
What We Missed: FBI Strikes Back at ShinyHunters
Tags: dataIn this video conversation, Dark Reading editors discuss some of the news they didn’t get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run data center. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/fbi-shinyhunters-claims-hack also interesting: FBI Warns: Threat Actors Impersonating BianLian Group to Target Corporate…
-
FBI arrests another suspected ShinyHunters hacker after agency breach
The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fbi-arrests-another-suspected-shinyhunters-hacker-after-agency-breach/ also interesting: New Great Morpheus Hacker Group Claims Hacking Into Arrotex Pharmaceuticals And PUS GmbH Hackers use Vishing to…
-
Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/ also interesting: 2025 Cybersecurity and AI Predictions What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical Infrastructure Attackers Exploit AhsayCBS Flaws to…
-
Germany arrests alleged core Qilin ransomware member after extradition
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/germany-arrests-alleged-core-qilin-ransomware-member-after-extradition/ also interesting: UkraineGermany operation targets Black Basta, Russian leader wanted Law enforcement tracks ransomware group blamed for massive financial losses Germany Doxes “UNKN,”…
-
FBI touts another ShinyHunters arrest in response to data breach
“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate,” FBI Director Kash Patel said. First seen on therecord.media Jump to article: therecord.media/shinyhunters-arrest-fbi-data-breach-investigation also interesting: Data breach reported by Universal Music Group CERT-EU blames Trivy supply chain attack for Europa.eu…
-
Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty
Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, was a principal of Your Mule Cashout, or “YMCO,” which from 2007 until 2014 set up a sophisticated network of mules in the U.S. and Europe. First seen on therecord.media Jump to article: therecord.media/leader-of-money-mule-operation-for-cybercriminals-pleads-guilty also interesting: Operation Endgame 2.0: DanaBusted Cybersecurity Snapshot: AI Data Security…
-
Hundreds of thousands impacted by data breach at biosensor firm iRhythm
A company known for wearable cardiac sensors, iRhythm, has begun notifying states of the impact of a data breach from the summer. First seen on therecord.media Jump to article: therecord.media/irhythm-data-breach-reports also interesting: 300,000 Impacted by Data Breach at Car Rental Firm Avis Estonia issues arrest warrant for Moroccan wanted for major pharmacy data breach Unbefugter…
-
The Cyber Express Weekly Roundup: US Puts $10 Million Bounty on Chinese Hacker, Japan Moves to Hunt Hidden Attackers and More
This weekly roundup covers a massive exposure of personal data from Denmark’s national population register, a U.S. bounty on a Chinese hacker accused of stealing COVID-19 research, Japan’s plan to actively search for attackers hiding in its critical infrastructure, a pair of breaches at Japanese publisher Nikkei, a call for AI-driven decision-making in security operations,…
-
$10 million bounty offered for Chinese Hafnium hacker accused of Microsoft Exchange Server mega-attack
The US State Department is offering up to US $10 million for information about the whereabouts of Zhang Yu, a 44-year-old Chinese national who is accused of being a key figure in China’s state-sponsored hacking group, Hafnium. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/10-million-bounty-chinese-hafnium-hacker-microsoft-exchange-server-mega-attack also interesting: State-Backed Hackers Exploiting Windows Zero-Day Since 2017 US…
-
Belarusian hacktivists admit to 2023 breach of Russian state healthcare network
The Belarusian Cyber Partisans concurred with Russian research that they indeed spent months inside the network for the Moscow Department of Health. First seen on therecord.media Jump to article: therecord.media/belarusian-cyber-partisans-claim-2023-russia-healthcare-hack also interesting: The most notorious and damaging ransomware of all time Rogues gallery: 15 worst ransomware groups active today The economics of ransomware 3.0 The…
-
5 Big Things To Know About Post-Quantum Security In 2026
Tags: dataThe need to prepare for the quantum paradigm shift”, and the first steps that are most necessary to take to get ready for the adoption of new forms of data encryption”, are coming clearly into focus, solution provider and vendor executives tell CRN. First seen on crn.com Jump to article: www.crn.com/news/security/2026/5-big-things-to-know-about-post-quantum-security-in-2026 also interesting: Acuity downplays…
-
FBI seizes domains linked to China-nexus botnet
The infrastructure supported an international hacking campaign that targeted critical infrastructure, including a South Carolina-based power company. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/fbi-seizes-domains-china-botnet-flax-typhoon/832611/ also interesting: International effort erases PlugX malware from thousands of Windows computers When Your Own Eyes Turn Against You: How Compromised Security Cameras and IoT/OT Devices Become Tools for Your…
-
FBI seizes domains linked to China-nexus botnet
The infrastructure supported an international hacking campaign that targeted critical infrastructure, including a South Carolina-based power company. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/fbi-seizes-domains-china-botnet-flax-typhoon/832611/ also interesting: International effort erases PlugX malware from thousands of Windows computers When Your Own Eyes Turn Against You: How Compromised Security Cameras and IoT/OT Devices Become Tools for Your…
-
Cyberangriffe auf Banken: Hacker nutzt KI und hinterlässt Accountdaten
Der Angreifer ist aufgeflogen, weil er offene und ungesicherte Webverzeichnisse auf seiner Server-Infrastruktur betrieb. First seen on golem.de Jump to article: www.golem.de/news/cyberangriffe-auf-banken-hacker-nutzt-ki-und-hinterlaesst-accountdaten-2610-213941.html also interesting: Attack Surface Management ein Kaufratgeber FortiGate firewall credentials being stolen after vulnerabilities discovered Wie KI die Cybersicherheit neu gestaltet Hacker legen Websites von Conceptnet-Kunden lahm
-
Cybersecurity Awareness Month 2026 – Awareness unter Pflicht- und KI-Druck
First seen on security-insider.de Jump to article: www.security-insider.de/phishing-schulungen-deepfakes-ki-awareness-nis2-a-84536d8c66eb0d54958809764f7beba4/ also interesting: 12 most innovative launches at RSA 2025 The devil of proposed SEC AI disclosure rule is in the details Gartner-Prognose: Die sechs wichtigsten Cybersicherheits-Trends für 2026 12 cyber industry trends revealed at RSAC 2026
-
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners.Details of the flaws are below – CVE-2026-105133 (CVSS v4 score: 5.5) – An improper authentication vulnerability in the checkSysPwd() function in the “com/ahsay/obs/api/ApiStructsAction.java” First seen on…
-
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI).”It’s an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing,” Anthropic said. “Projects that join will receive thorough, periodic security scans by our strongest models at no cost.” First…
-
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection.AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as “fixed a bug that could lead to a crash,” with no…
-
TP-Link Sued by Four More U.S. States Over Router Security and China Ties
Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it…
-
How to keep AI agents within their permissions
AI agents can use valid credentials to perform actions beyond their assigned permissions, creating risks that traditional access controls may not prevent. Token Security explains how organizations can enforce agent-specific policies without sacrificing autonomy. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-to-keep-ai-agents-within-their-permissions/ also interesting: Fraud Awareness Week: How to Effectively Protect Your Data and Combat…

