3VirusTotal Adds Scanning for Public IPv4 Space to Expose C2 Servers and Malware InfrastructureCisco Security AdvisoriesCyber Security NewsDark ReadingElastic Security LabsRapid7 BlogThe Hacker News+3VirusTotal has added daily scanning of the public IPv4 space, giving security teams a new way to find command-and-control (C2) servers and track malware infrastructure. Announced on October 8, 2026, the update records exposed services, port activity, banners, and server fingerprints alongside existing threat intelligence. The change helps researchers look beyond an IP address’s detection score. Earlier reports showed hosting details, passive DNS records, and files that contacted an address. The new data shows what a server exposes now, helping analysts find related hosts that have no malware…
5Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secretsBleeping ComputerCCCS Alerts & AdvisoriesThe Register SecurityGitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function. This is more of the same, with a twist. According to security researchers at Adversa AI, GitHub Copilot CLI suffers from the same vulnerability identified in Grok two months ago: Cryptographic Context Injection…
8Let’s Encrypt Cuts TLS Certificate Lifetimes From 90 to 64 Days Starting February 2027Ars Technica SecurityCyber Security NewsLet’s Encrypt will cut its default TLS certificate lifetime from 90 days to 64 days on February 10, 2027, giving website operators less time between renewals. The change applies to certificates issued or renewed from that date, while subscribers can still choose shorter certificate profiles offering 45 days or roughly six days. Let’s Encrypt Certificate Lifetime According to the October 7 announcement published by Let’s Encrypt , the nonprofit certificate authority confirmed the schedule. Existing certificates will remain valid until their normal expiry dates, and Let’s Encrypt will not…
10Citrix gives NetScaler admins another critical reason to patchSecurityWeekThe Register SecurityCVE-2026-107406 ↗Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. The affected configurations depend on the software version. Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration…
11MATCHBOIL Malware Uses Cloudflare-Hidden C2 Servers to Deliver Backdoor PayloadsCyber Security NewsThe Hacker NewsMATCHBOIL, a C# malware downloader linked to UAC-0099, uses command-and-control (C2) servers hidden behind Cloudflare to deliver backdoor payloads. Its changing code shows how the group has moved from a simple downloader toward repeated server contact, stronger code hiding, and checks designed to stop security researchers from studying infections. The observed victims were all in Ukraine. ESET recorded infections at transportation companies during July and August 2025, a manufacturing company in December 2025, and an energy company in June 2026. These findings show continued targeting across…
12Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML DeploymentsBleeping ComputerThe Hacker NewsCitrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability
14AWS launches open-source AI agent sandbox to prevent YOLO mode disastersDark ReadingThe Register SecurityAWS has offered multiple open-source strategies for holding AI agents accountable, and now it’s adding a full-on sandbox to this stack. Dubbed Strands Box, the new solution uses OS-level isolation and some of AWS’ other recent open-source AI control tools to, ostensibly, retain greater control over autonomous AI agents’ behavior. “Agents increasingly run in ‘YOLO mode,’ approving every action without human review,” the AWS team explained in its announcement. “The usual solution to this problem is a sandbox … but access is only part of what we want to control.” The problem with containers and…
15Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agentsBleeping ComputerTenable BlogCommunity-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed. Key takeaways Every Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code and threat model. Tenable security researchers then verify runtime behavior in a clean…
17Red Lion Controls N-Tron 700 SeriesCISA Alerts & AdvisoriesCISA ICS AdvisoriesView CSAF Summary Successful exploitation of these vulnerabilities could allow a malicious user to access the device and gain administrative access. This access would allow the user to view, edit, and upload configuration files. Further, a malicious user can cause the switch to reboot by navigating to a specific URL on the device. This action can be scripted on the malicious user's local machine to cause continuous rebooting of the switch. The following versions of Red Lion Controls N-Tron 700 Series are affected: 700 Series <=Firmware_3.11.0 (CVE-2026-32645, CVE-2026-39460, CVE-2026-28745…
18CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian productsRapid7 BlogSANS Internet Storm CenterwatchTowr LabsCVE-2026-21589 ↗Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration…
19FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device CredentialsCyberScoopThe Hacker NewsThe Register SecurityThe U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
Raheim Hamilton, 30, pleaded guilty earlier this year to a drug conspiracy charge and agreed to forfeit more than $100 million worth of Bitcoin and several properties in Virginia.
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow
Noteworthy stories that might have slipped under the radar: Tensorlake npm SDK compromised, Empire Market co-founder gets 40 years, exposed NVIDIA GPU monitors leak telemetry.
Comparitech observed 2627 claimed ransomware attacks in Q3, with critical sectors like finance, technology, education and healthcare experiencing significant increases
Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to…
Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. The affected configurations depend on the software version. Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration…
As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from…
As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The "Horizons of Identity Security" report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls, creating a
A Ukrainian-Russian dual citizen has pleaded guilty to running a massive money laundering operation that laundered millions for cybercriminals worldwide.
The customer data stolen from global fashion retailer ASOS includes more than just names and contact details, raising questions about its early reassurances. As we reported earlier this week, ASOS customers received a…
The customer data stolen from global fashion retailer ASOS includes more than just names and contact details, raising questions about its early reassurances. As we reported earlier this week, ASOS customers received a push notification through the ASOS app alleging that the company had been hacked. ASOS has confirmed that attackers accessed customer information after tricking an employee into handing over login credentials. While the retailer says payment card information and customer passwords were not accessed, reporting by the BBC shows the stolen information includes more than the “basic…
Microsoft says devices running unsupported versions of Windows will stop receiving security updates after next year's Windows Update certificate rotation.
MATCHBOIL, a C# malware downloader linked to UAC-0099, uses command-and-control (C2) servers hidden behind Cloudflare to deliver backdoor payloads. Its changing code shows how the group has moved from a simple…
MATCHBOIL, a C# malware downloader linked to UAC-0099, uses command-and-control (C2) servers hidden behind Cloudflare to deliver backdoor payloads. Its changing code shows how the group has moved from a simple downloader toward repeated server contact, stronger code hiding, and checks designed to stop security researchers from studying infections. The observed victims were all in Ukraine. ESET recorded infections at transportation companies during July and August 2025, a manufacturing company in December 2025, and an energy company in June 2026. These findings show continued targeting across…
A public proof of concept has exposed a flaw in Telegram Desktop that could let attackers steal local files and take over accounts after a user clicks a crafted external link. Tracked as CVE-2026-107181, the…
A public proof of concept has exposed a flaw in Telegram Desktop that could let attackers steal local files and take over accounts after a user clicks a crafted external link. Tracked as CVE-2026-107181, the vulnerability affects versions before 7.2.9 and carries a CVSS 4.0 severity rating of 8.6 (High). Researcher Beaksec published the technical write-up on October 3, 2026, and updated it on October 7. VulnCheck assigned the CVE that day. The reported attack reaches Telegram’s local session data, making account takeover possible when the victim has not enabled a local passcode. The weakness…
Every image scan returns hundreds of CVEs; the question is which ten your containers actually execute and which base image would zero the list entirely. We scored ten options with context and elimination weighted above…
Every image scan returns hundreds of CVEs; the question is which ten your containers actually execute and which base image would zero the list entirely. We scored ten options with context and elimination weighted above raw detection. Evaluating scanners alongside the Top 10 Best Container Security Tools in 2026 reveals that static vulnerability counts alone do not prevent attackers who compromise container hosts through misconfigurations. Aqua’s Trivy takes 1 as the free floor everyone should run; Sysdig and Wiz complete a podium built on making findings mean something. Key Takeaways • 1…
A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address…
A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site's .onion address using only public information, and then take that address over. Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the site's visitors to a copy of the site they control.
As AI adoption accelerates, ISACA is expanding its certification portfolio with a governance-focused credential designed to help professionals manage AI securely
Anthropic has introduced OSS Scanner, a free service that checks critical open-source repositories for security vulnerabilities and sends findings directly to project maintainers. The opt-in program uses the company’s…
Anthropic has introduced OSS Scanner, a free service that checks critical open-source repositories for security vulnerabilities and sends findings directly to project maintainers. The opt-in program uses the company’s strongest AI models to run repeated scans, giving developers a faster route to potential flaws without waiting for human review. According to Anthropic’s service overview, OSS Scanner builds on its work with Project Glasswing . The company says it had reviewed more than 6,000 vulnerability reports by October 2026 through its existing disclosure process. The new service offers a…
Researchers are testing your perimeter tonight whether you invited them or not bounty platforms decide whether that energy reaches your inbox or the dark web. Evaluating the offensive testing market alongside the best…
Researchers are testing your perimeter tonight whether you invited them or not bounty platforms decide whether that energy reaches your inbox or the dark web. Evaluating the offensive testing market alongside the best bug bounty platforms for white-hat hackers and modern penetration testing tools demonstrates that crowdsourced security has matured from an experimental gamble into an essential pillar of continuous threat validation. We scored ten platforms on crowd quality, triage, and jurisdiction fit, with status honesty where the roster demanded it. HackerOne takes 1 ; Bugcrowd and…
Let’s Encrypt will cut its default TLS certificate lifetime from 90 days to 64 days on February 10, 2027, giving website operators less time between renewals. The change applies to certificates issued or renewed from…
Let’s Encrypt will cut its default TLS certificate lifetime from 90 days to 64 days on February 10, 2027, giving website operators less time between renewals. The change applies to certificates issued or renewed from that date, while subscribers can still choose shorter certificate profiles offering 45 days or roughly six days. Let’s Encrypt Certificate Lifetime According to the October 7 announcement published by Let’s Encrypt , the nonprofit certificate authority confirmed the schedule. Existing certificates will remain valid until their normal expiry dates, and Let’s Encrypt will not…
Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.
The misconfiguration that breaches you in production was mergeable in review IaC security exists to catch it there. Evaluating the market alongside modern Infrastructure as Code (IaC) scanning tools demonstrates that…
The misconfiguration that breaches you in production was mergeable in review IaC security exists to catch it there. Evaluating the market alongside modern Infrastructure as Code (IaC) scanning tools demonstrates that static linting alone cannot protect dynamic, multi-tier architectures. We scored ten options with fix quality and cloud-context weighted highest, atop an OSS floor (Checkov, Trivy) every pipeline should already run. Wiz takes 1 for ranking findings by real exposure; Snyk IaC and Palo Alto’s Checkov complete the podium. Key Takeaways • 1 overall: Wiz the misconfig ranked by the…
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits…
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero
Microsoft is urging organizations to prepare their certificate systems for post-quantum authentication, warning that public key infrastructure (PKI), hardware security modules (HSMs), and security appliances need…
Microsoft is urging organizations to prepare their certificate systems for post-quantum authentication, warning that public key infrastructure (PKI), hardware security modules (HSMs), and security appliances need testing before deployment. Its October 8 guidance says the shift will affect applications, devices, certificate chains, and the processes that keep digital trust working. The message goes beyond protecting encrypted traffic. While many quantum security plans focus on attackers collecting data now to decrypt later, authentication depends on certificates and private keys being issued…
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions…
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability
VirusTotal has added daily scanning of the public IPv4 space, giving security teams a new way to find command-and-control (C2) servers and track malware infrastructure. Announced on October 8, 2026, the update records…
VirusTotal has added daily scanning of the public IPv4 space, giving security teams a new way to find command-and-control (C2) servers and track malware infrastructure. Announced on October 8, 2026, the update records exposed services, port activity, banners, and server fingerprints alongside existing threat intelligence. The change helps researchers look beyond an IP address’s detection score. Earlier reports showed hosting details, passive DNS records, and files that contacted an address. The new data shows what a server exposes now, helping analysts find related hosts that have no malware…
$1.2 million was paid out at Pwn2Own Ireland 2026 for exploits targeting phones, printers, smart speakers, smart home hubs, and AI infrastructure and coding tools.
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end…
The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon. To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure. The list of seized
Alleged internal chats from Silent Ransom Group suggest the criminals collected $206.95 million from 27 firms in roughly six months without encrypting victims’ files. The reported earnings point to the power of data…
Alleged internal chats from Silent Ransom Group suggest the criminals collected $206.95 million from 27 firms in roughly six months without encrypting victims’ files. The reported earnings point to the power of data extortion , where attackers steal sensitive records and demand payment to keep them private. However, the payment figures remain unverified, and the group denies breaching its systems or leaking its chats. DataBreaches reported the alleged leak on October 7. The material contains 5,692 messages covering August 27, 2025, through September 29, 2026. Discussions reportedly include…
The FBI announced that it has seized seven web domains linked to hacking tools allegedly operated by a Chinese security firm called Integrity Technology Group and used by Beijing-backed cyber operatives to scan a South…
The FBI announced that it has seized seven web domains linked to hacking tools allegedly operated by a Chinese security firm called Integrity Technology Group and used by Beijing-backed cyber operatives to scan a South Carolina power company's network and other critical infrastructure systems for vulnerabilities. In a subsequent advisory, the FBI and other government agencies in the US, UK, Australia, Canada, Japan, New Zealand, and Spain warned that Chinese government-linked attackers, enabled by Integrity Tech, are using botnets, malware, and other intrusion tools to target organizations…
The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other…
A 21-year-old from North Carolina who joined and helped establish 764 as an underage teenager and quickly emerged as the leader of the child sextortion group until his arrest last year pleaded guilty in federal court…
A 21-year-old from North Carolina who joined and helped establish 764 as an underage teenager and quickly emerged as the leader of the child sextortion group until his arrest last year pleaded guilty in federal court Thursday, the Justice Department said. Prasan Nepal pleaded guilty to conspiracy to commit sexual exploitation of a child as part of a plea agreement with prosecutors and faces at least 15 years and up to 30 years in prison upon sentencing. Nepal, also known as “Trippy,” ran the nihilistic violent extremist network for almost four years and played a crucial role facilitating the…
Anthropic announced a new program Thursday that will combine its AI tools with outside cybersecurity companies to find and fix cybersecurity vulnerabilities in critical infrastructure and open-source software…
Anthropic announced a new program Thursday that will combine its AI tools with outside cybersecurity companies to find and fix cybersecurity vulnerabilities in critical infrastructure and open-source software. Advertised as part of a new, “long-term commitment” to cybersecurity, the critical infrastructure defense program will pair Claude models, Anthropic engineers and threat research with the expertise of cybersecurity companies, including Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation…
Post-quantum cryptography (PQC) planning often focuses on protecting encrypted data, but authentication systems must also evolve. Certificates, trust anchors, PKI services, applications, devices, and hardware security…
Post-quantum cryptography (PQC) planning often focuses on protecting encrypted data, but authentication systems must also evolve. Certificates, trust anchors, PKI services, applications, devices, and hardware security modules may all be affected by new algorithms and larger certificate chains. Microsoft’s Post-Quantum Cryptography (PQC) Transport Layer Security (TLS) Pilot Program helps eligible certificate authorities evaluate interoperability and operational readiness in controlled environments. Organizations should begin now by inventorying certificate dependencies, assessing vendor…
The proposed sale would include about 100 million emails, 500 million Microsoft Teams messages, employment contracts, employee and timecard records and payroll and tax information, Rep. Steven Horsford (D-NV) said in a…
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part…
The Justice Department and FBI announced that they had seized two hacking tools connected to the Chinese government-linked group Flax Typhoon and a China-based company that the U.S. government has repeatedly taken…
The Justice Department and FBI announced that they had seized two hacking tools connected to the Chinese government-linked group Flax Typhoon and a China-based company that the U.S. government has repeatedly taken action against, including with a new multi-agency advisory Thursday. The domain name seizures were meant to deny hackers access to the vulnerability scanning tool Microscan and the spearphishing tool FishHub created by the Chinese firm Integrity Technology Group, which the United States sanctioned last year. The U.S. government in 2024 also made the company the focus of a takedown…
Threat actors are exploiting AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers. Update to 10.3.4 and restrict access now.
Let's Encrypt is continuing a push toward tighter security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting February 10, 2027. For administrators already implementing modern ACME clients…
Let's Encrypt is continuing a push toward tighter security by reducing free SSL/TLS certificate lifetimes from 90 days to 64 days, starting February 10, 2027. For administrators already implementing modern ACME clients that support ARI (ACME Renewal Information), the change should be seamless. For those still relying on hardcoded renewal schedules or manual processes, February will be the deadline to update before certificates start expiring unexpectedly. Starting on October 14, Let's Encrypt will begin testing the 64-day certificates, and interested users can opt in to test their setups…
Authorities accuse the owner of a so-called ransomware remediation company of swindling clients victimized by ransomware attacks into paying the company inflated fees under false pretenses. Zohar Pinhasi, owner and…
Authorities accuse the owner of a so-called ransomware remediation company of swindling clients victimized by ransomware attacks into paying the company inflated fees under false pretenses. Zohar Pinhasi, owner and operator of MonsterCloud, claimed he could decrypt and recover victims’ data with specialized, proprietary tools and avoid paying cybercriminals. Yet, no such tool existed, the Justice Department said Wednesday. Pinhasi allegedly used MonsterCloud clients’ fees to pay off cybercriminals and recover encrypted data without telling clients ransom payments were made on their behalf…
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad…
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.
The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed "widespread vulnerability scanning and, in some cases, intrusions" as part of the Flax Typhoon campaign.
The first cybercriminal to ever make the FBI's "10 Most Wanted Fugitives" list allegedly infused Tren de Aragua's violent criminal operations with cash.
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other…
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws using a tool containing more
Researchers found thousands of GPU servers exposing Nvidia's DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could let unauthenticated attackers crash the GPU monitoring…
Researchers found thousands of GPU servers exposing Nvidia's DCGM Exporter to the internet, with hundreds potentially vulnerable to a high-severity flaw that could let unauthenticated attackers crash the GPU monitoring service and disrupt AI workloads. DCGM Exporters read telemetry from the GPUs on a host, including its hardware, utilization, memory usage, power consumption, and error events. Each GPU has its own unique ID, or UUID, and all of these metrics are exposed in plaintext over HTTP. This exposure provides would-be attackers with detailed information useful for reconnaissance…
An Iowa man has kicked off controversy over religious freedom in the small town of Ottumwa, Iowa by opening a city council meeting with a prayer to Satan, which then kicked off a debate about the proper time in the…
An Iowa man has kicked off controversy over religious freedom in the small town of Ottumwa, Iowa by opening a city council meeting with a prayer to Satan, which then kicked off a debate about the proper time in the meeting agenda to undo the “curse.” On Tuesday night, Ottumwa resident, satanist, and former city council member Matt Dalbey took the podium to read an invocation to start a routine meeting of the council. “Thank you mayor, council. Let us pray,” Dalbey started. “Dear dark father, let us stand now unbowed and unfettered by arcane doctrines born of fearful minds and darkened times…
Welcome to this week’s edition of the Threat Source newsletter. My name is Pierre Cadieux, and I’ll be helping contribute to these newsletters. A little about me: I’ve been working in the cybersecurity industry in many…
Welcome to this week’s edition of the Threat Source newsletter. My name is Pierre Cadieux, and I’ll be helping contribute to these newsletters. A little about me: I’ve been working in the cybersecurity industry in many roles over the past 20+ years, first focusing on endpoint security, policies, and firewalls, then moving to risk management and compliance, disaster recovery, and investigations. I spent about 15 years as a consultant working across many well-known consultancy firms and eventually moved to Cisco where I spent time doing security operations center (SOC) design and assessments as…
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently…
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that
OpenAI disclosed Thursday it shut down two influence operations from Russia and Iran that used ChatGPT and other AI tools to create fake journalist personas and covert think tanks that successfully planted stories and…
OpenAI disclosed Thursday it shut down two influence operations from Russia and Iran that used ChatGPT and other AI tools to create fake journalist personas and covert think tanks that successfully planted stories and narratives in mainstream news publications. One cluster of accounts, which OpenAI calls “Dark Clark,” is attributed to Russian actors. The network focused on influencing Latin American politics and culture. Its name comes from Mia Clark, a fake AI persona the group presented as the leader of the Social Research Center, a supposed Latin American think tank used to seed propaganda…
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer.
The owner of a ransomware recovery firm was hit with wire fraud charges for allegedly making secret ransom payments while overcharging the victims of attacks.
The company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related…