Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 1 час назад
До года на восстановление. «Яндекс» рассказал о последствиях удара по ЦОДу
До года на восстановление. «Яндекс» рассказал о последствиях удара по ЦОДу

Ремонт может оказаться лишь частью гораздо более дорогой проблемы.

1 час назад @ securitylab.ru
IBM сворачивает VMware-бизнес. Сотен корпоративных клиентов передали другой компании
IBM сворачивает VMware-бизнес. Сотен корпоративных клиентов передали другой компании

У бизнеса остаётся всё меньше времени, чтобы подготовиться к новым условиям.

2 часа назад @ securitylab.ru
Серверы с NVIDIA для российского ИИ подорожали до миллиона долларов
Серверы с NVIDIA для российского ИИ подорожали до миллиона долларов

Зарубежные ограничения и мировой дефицит ударили по самым дорогим вычислениям.

2 часа назад @ securitylab.ru
Гигабит в каждый дом. Минцифры готовит новый минимум для домашнего интернета
Гигабит в каждый дом. Минцифры готовит новый минимум для домашнего интернета

Вместе со скоростным порогом ведомство предлагает радикально пересмотреть правила работы операторов.

3 часа назад @ securitylab.ru
Детектор сказал «не ИИ». Почему верить ему нельзя
Детектор сказал «не ИИ». Почему верить ему нельзя

Полный обзор способов проверки файлов на ИИ через OpenAI Verify, Claude, Gemini, SynthID, C2PA, Midjourney, Meta и ElevenLabs.

3 часа назад @ securitylab.ru
Microsoft Teams начнёт ловить дипфейки прямо во время созвона
Microsoft Teams начнёт ловить дипфейки прямо во время созвона

Голос и видео проверят внешние детекторы, а предупреждение появится непосредственно в интерфейсе.

3 часа назад @ securitylab.ru
Хакер вынес $53 млн из Uranium Finance. Суд догнал его пять лет спустя
Хакер вынес $53 млн из Uranium Finance. Суд догнал его пять лет спустя Хакер вынес $53 млн из Uranium Finance. Суд догнал его пять лет спустя

Хакер вынес $53 млн из Uranium Finance.

7 октября присяжные в Нью-Йорке признали 36-летнего Джонатана Спаллетту виновным в компьютерном мошенничестве и отмывании денег после двух взломов Uranium Finance в апреле 2021 года.

Uranium Finance работала как децентрализованная биржа с пулами ликвидности, где обмены выполняли смарт-контракты.

После мартовского обвинения материалы дела связали псевдонимы «Cthulhon» и «Jspalletta» с атаками на Uranium Finance.

Uranium Finance прекратила работу ещё в 2021 году, а уголовное дело дошло до обвинительного вердикта спустя пять лет.

3 часа назад @ securitylab.ru
Два дня, два удара. Теперь беспилотники добрались до серверов «Яндекса» в Калуге
Два дня, два удара. Теперь беспилотники добрались до серверов «Яндекса» в Калуге

Несколько серверных модулей предположительно выведены из строя.

4 часа назад @ securitylab.ru
Rabby и OKX подменили прямо в браузере. 16 расширений Firefox охотились за криптокошельками
Rabby и OKX подменили прямо в браузере. 16 расширений Firefox охотились за криптокошельками

Пользователи сами передавали главный секрет, даже не подозревая о ловушке.

4 часа назад @ securitylab.ru
Кожаные мешки, у нас проблемы: Anthropic признала за Claude право на душевную боль
Кожаные мешки, у нас проблемы: Anthropic признала за Claude право на душевную боль

Anthropic ввела запрет на жестокость к ИИ.

4 часа назад @ securitylab.ru
Марс заставил физиков переписать правила рождения облаков
Марс заставил физиков переписать правила рождения облаков

Водяной пар, похоже, способен превращаться в лед без пыли и других частиц-зародышей.

5 часов назад @ securitylab.ru
Поэзия – новая угроза безопасности для ИИ. Вредонос PoeLLM заразил более 3000 серверов
Поэзия – новая угроза безопасности для ИИ. Вредонос PoeLLM заразил более 3000 серверов

Хакеры превратили обычное произведение на GitHub в ключ к управлению ботнетом.

6 часов назад @ securitylab.ru
ФБР разгромило скам-центр в Гане. Среди 130 задержанных оказались жертвы торговли людьми
ФБР разгромило скам-центр в Гане. Среди 130 задержанных оказались жертвы торговли людьми

Почти 90 пострадавших потеряли миллионы, но следствие пока не знает полного масштаба схемы.

6 часов назад @ securitylab.ru
Вдвое меньше памяти, больше событий: MaxPatrol SIEM 28.0 выжимает максимум из того же сервера
Вдвое меньше памяти, больше событий: MaxPatrol SIEM 28.0 выжимает максимум из того же сервера

Организации смогут дольше наращивать нагрузку без обязательного расширения инфраструктуры.

6 часов назад @ securitylab.ru
В старом советском реактиве нашли ключ к терагерцовой памяти без паразитных полей
В старом советском реактиве нашли ключ к терагерцовой памяти без паразитных полей

Перестройка решётки резко меняет движение электронов и усиливает эффект Холла.

7 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 2 часа назад
Обзор АПК ЗАСТАВЫ 9, профессиональной защиты каналов связи и удалённого доступа
Обзор АПК ЗАСТАВЫ 9, профессиональной защиты каналов связи и удалённого доступа Обзор АПК ЗАСТАВЫ 9, профессиональной защиты каналов связи и удалённого доступа

Такой опыт позволил последовательно развивать продукт и накапливать экспертизу не в отдельных технологиях, а в самой функции защиты сетевого трафика.

Функциональные возможности «ЗАСТАВЫ 9»«ЗАСТАВА 9» обеспечивает комплексную защиту устройств пользователей, сетей и каналов связи от внутренних и внешних угроз.

Расположение элементов также оптимизировали для экранов с небольшим разрешением: они не перекрывают друг друга и остаются удобными для работы.

Веб-интерфейс «ЗАСТАВЫ-Офис»Возможности управления системой через веб-браузер, доступные в восьмой версии, сохранились и в девятой.

Главное окно ключевого центраСравнение возможностей девятой и восьмой версийВендор развивает поддержку протоколов …

2 часа назад @ anti-malware.ru
Регулирование ИИ в России: закон № 243-ФЗ, риски и перспективы развития
Регулирование ИИ в России: закон № 243-ФЗ, риски и перспективы развития Регулирование ИИ в России: закон № 243-ФЗ, риски и перспективы развития

Но есть и обратная сторона: проявились риски, связанные как с несовершенством технологий, так и с тем, что ИИ осваивают атакующие.

Однако в последний год использование ИИ стало обходиться дорого, и в итоге многие компании даже начали массово возвращать людей, уволенных после его внедрения.

При этом автономные поезда, в том числе метро, или трамваи — далеко не редкость, в том числе и в российских городах.

Такой вывод был сделан по итогам предвыборной кампании и по наличию разных аспектов, связанных с использованием ИИ, в повестках думских партий.

Мы работаем над новыми требованиями, но в большей степени в привязке к рискам и угрозам от ИИ, а не к регламентированию конкретных моделей.

20 часов назад @ anti-malware.ru
ИИ в облаке: кто отвечает за безопасность
ИИ в облаке: кто отвечает за безопасность ИИ в облаке: кто отвечает за безопасность

ВведениеПо данным рыночных исследований, 24% российских компаний уже используют ИИ в облаке, ещё 18% планируют начать в ближайший год.

При работе с ИИ в облаке сохраняется привычная схема: провайдер отвечает за инфраструктуру, а клиент — за развёрнутые поверх неё системы.

В случае с готовой моделью, предоставляемой как облачный сервис, провайдер отвечает за инфраструктуру и безопасность предоставляемой модели.

Провайдер отвечает за инфраструктуру и управляемые им компоненты, а на стороне клиента остаются данные, права доступа, собственные модели и решения о том, как использовать ответы и действия ИИ-систем.

Задача CISO — встроить ИИ в существующие процессы безопасности: учитывать его в моде…

1 day, 2 hours назад @ anti-malware.ru
Закрытый контур: 4 неочевидные причины настроить его уже сейчас
Закрытый контур: 4 неочевидные причины настроить его уже сейчас Закрытый контур: 4 неочевидные причины настроить его уже сейчас

Новые проблемы ИБ, вроде загрузки рабочих документов в ChatGPT или Qwen, сливаются с ростом угроз и ответственности за инциденты.

При этом само по себе единое рабочее пространство ещё не превращает среду в закрытый контур.

Такой подход позволяет контролировать не только место хранения информации, но и то, кто, откуда и при каких условиях получает к ней доступ.

Компрометация учётной записи сотрудника, вредоносная программа на его устройстве, избыточные права или подключённое стороннее приложение могут дать злоумышленнику доступ и к корпоративной среде.

Именно поэтому сегодня закрытый контур — уже не вопрос зрелости ИБ, а инструмент управления бизнес-рисками.

1 day, 22 hours назад @ anti-malware.ru
Усиление безопасности ГИС и ИСПДн в 2026 году: как использовать возможности защищённого облака
Усиление безопасности ГИС и ИСПДн в 2026 году: как использовать возможности защищённого облака Усиление безопасности ГИС и ИСПДн в 2026 году: как использовать возможности защищённого облака

Какие задачи можно передать провайдеруВ интервью подробно обсуждалось распределение ответственности между оператором инфраструктуры и оператором информационной системы.

Максим Куртин объяснил, что в классической модели ответственности всё, что находится ниже среды виртуализации, относится к зоне ответственности оператора инфраструктуры.

Сколько времени занимает подготовка к аттестацииОтдельно в интервью обсуждались сроки создания инфраструктуры и подготовки к аттестации.

Виктор Коноплёв пояснил, что в отношении продуктов, предоставляемых в качестве сервиса, провайдер может следить за их обновлением и работоспособностью.

Особенности размещения инфраструктуры в защищённом облакеВ интервью так…

2 days, 4 hours назад @ anti-malware.ru
Автономный SOC в 2026 году: где заканчивается автоматизация и начинается реальная автономность
Автономный SOC в 2026 году: где заканчивается автоматизация и начинается реальная автономность Автономный SOC в 2026 году: где заканчивается автоматизация и начинается реальная автономность

Эксперты ведущих российских вендоров и провайдеров услуг обсудили, где заканчивается автоматизация SOC и начинается реальная автономность.

Дальше можно идти туда, где риск минимален: если автоматизации можно доверить остановку служб и изменение конфигурационных файлов и это не остановит бизнес, то почему бы нет?

Михаил Карпенко считает, что в автоматизацию следует выводить те процессы, в которых уже есть уверенность, что их можно передать.

То, что вы составили первым и что кажется вам максимально понятным и управляемым, и нужно автоматизировать в первую очередь».

Автономность сегодня доходит до этапа вынесения первичного вердикта и, в ограниченном наборе типовых случаев, до локализации и пе…

2 days, 21 hours назад @ anti-malware.ru
Обзор AlphaSense Symbiote Space, ПО для поиска и эксплуатации уязвимостей
Обзор AlphaSense Symbiote Space, ПО для поиска и эксплуатации уязвимостей Обзор AlphaSense Symbiote Space, ПО для поиска и эксплуатации уязвимостей

Объединяет обнаружение и инвентаризацию ИТ-активов, поиск уязвимостей и ошибок конфигурации, активную проверку эксплуатации уязвимостей, приоритизацию и контроль устранения.

Информационная панель EASM в AlphaSense Symbiote SpaceС помощью фильтров задаются значения критериев отбора хостов и уязвимостей, отображаемых в блоке.

Реализуется полная поддержка системы CVSS версий 2, 3 и 4 для оценки критической значимости уязвимостей и их последующей приоритизации.

Платформа обнаруживает доступные извне активы и сервисы, связывает их с внутренней инвентаризацией и показывает открытые порты, версии ПО, уязвимости и реальную возможность эксплуатации.

ВыводыAlphaSense Symbiote Space объединяет обнаруж…

3 days, 3 hours назад @ anti-malware.ru
ИИ-программисты сливают корпоративные ключи: новая угроза от нейросетевого кодинга
ИИ-программисты сливают корпоративные ключи: новая угроза от нейросетевого кодинга ИИ-программисты сливают корпоративные ключи: новая угроза от нейросетевого кодинга

Таким образом, доля изменений кода с обнаруженными секретами при использовании ИИ-инструментов оказалась более чем в два раза выше среднего показателя.

Hardcoded secrets — пароли и ключи, записанные непосредственно в тексте программы или её настройках, то есть доступ к ресурсу оказывается неотделим от самого кода.

Сами по себе такие секреты не всегда появляются в коде по вине ИИ: разработчики оставляли ключи и пароли в репозиториях и раньше.

Срок действия доступа ограничен, и по его истечении доступ автоматически прекращается.

Ключ необходимо отозвать и заменить, проверить журналы его использования и при необходимости очистить историю репозитория.

3 days, 23 hours назад @ anti-malware.ru
Будущее строгой аутентификации: виртуальные смарт-карты и BYOD
Будущее строгой аутентификации: виртуальные смарт-карты и BYOD Будущее строгой аутентификации: виртуальные смарт-карты и BYOD

ВведениеФизическая смарт-карта или USB-токен защищает закрытый ключ и позволяют использовать его для аутентификации и других криптографических операций.

С 1 октября 2025 года действует ГОСТ Р 70262.2-2025, который устанавливает уровни доверия аутентификации и определяет требования к видам и средствам аутентификации для каждого из них.

При этом важно, чтобы закрытый ключ не передавался за пределы защищённого хранилища и не мог быть штатно экспортирован.

Ограничения: KeyBox не заменяет механизм строгой аутентификации, инфраструктуру открытых ключей (PKI) или систему контроля состояния устройства, а управляет средствами аутентификации и их жизненным циклом.

Когда выбирать: если нужно централиз…

4 days, 3 hours назад @ anti-malware.ru
Цифровой сотрудник — дешёвая замена человеку или новая статья расходов?
Цифровой сотрудник — дешёвая замена человеку или новая статья расходов? Цифровой сотрудник — дешёвая замена человеку или новая статья расходов?

Среднее базовое ДМС обходится в 2 000 рублей в месяц.

Среднемесячную заработную плату округлим до 56 000 рублей на руки.

Аренда мощностей может обходиться в 5 000 — 20 000 рублей (и выше) в месяц.

Другие расходы:LLM-токены: 0,5 — 2 рублей за ответ, при 900 диалогах — от 2 000 до 6 000 рублей в месяц.

Сообщения бесплатны, платный контур — хостинг прослойки, 1 000 — 3 000 рублей в месяц.

6 days, 22 hours назад @ anti-malware.ru
Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры
Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры

Отдельно обсудили, как выбирать облачного провайдера — на какие критерии смотреть и что влияет на надёжность его сервисов.

Заказчик не видит эти процессы изнутри и не может управлять ими так же, как собственной инфраструктурой.

Но, как советует Станислав Попов, внедрять ИИ сейчас стоит осознанно и с пониманием ожидаемого бизнес-эффекта.

Тестирование аварийного восстановления (disaster recovery, DR) позволяет эмулировать сбои, проверить работу собственной инфраструктуры и цепочки поставщиков.

Вместо самостоятельного создания инфраструктуры и найма специалистов они могут использовать облачную инфраструктуру, соответствие которой необходимым требованиям уже подтверждено.

1 week, 1 day назад @ anti-malware.ru
Low-code и No-code в 2026 году: как создавать приложения без разработчиков
Low-code и No-code в 2026 году: как создавать приложения без разработчиков Low-code и No-code в 2026 году: как создавать приложения без разработчиков

Платформы Low-code и No-code позволяют создавать бизнес-приложения, автоматизировать процессы и интегрировать системы силами специалистов без профильного образования в области программирования.

Что такое Low-code и No-codeАнтон Симуни объяснил разницу между No-code и Low-code.

No-code — это для непрофессиональных программистов, может быть, даже вообще для тех, кто создаёт приложения без профильного ИТ-образования (т. н.

В первом опросе зрители рассказали, используют ли они платформы No-code / Low-code в своей компании:«Пилотируют» / только начинают внедрение — 28 %.

ВыводыРынок Low-code и No-code в 2026 году перестал быть нишевым явлением.

1 week, 1 day назад @ anti-malware.ru
Миграция с Cisco: от пилота до замены инфраструктуры
Миграция с Cisco: от пилота до замены инфраструктуры Миграция с Cisco: от пилота до замены инфраструктуры

Вместе с Ideco мы обсудили, как подготовиться к переходу на российские решения, почему полностью бесшовной замены сегодня не бывает.

Причины отказа от CiscoПосле ухода Cisco из России вопрос перехода на другие решения для клиентов до сих пор никуда не исчез.

Совместимость IPsec Site-to-Site с Cisco подтверждена, поэтому площадки можно переносить поэтапно без потери связи между ними.

Илья Соболев, менеджер по продукту IdecoЗависимость от вендора и бесшовность миграцииПри переходе с Cisco на российское решение вопрос зависимости от вендора сохраняется.

Например, добавление поддержки EIGRP, протокола маршрутизации, было связано с тем, что многие компании строили инфраструктуру на Cisco.

1 week, 2 days назад @ anti-malware.ru
Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке
Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке

ИИ-агенты и их влияние на рынокАндрей Галактионов считает, что истории о сбежавших из песочниц ИИ-агентах — это в первую очередь хайп.

«Красная» команда в 95 % случаев достигает целей, но если нет зрелости, результат будет тот же, что и от пентеста, только дороже.

Если по результатам пентеста нужно проверить инфраструктуру, а по результатам Red Teaming — перенастроить процессы, то внутренняя команда может быть эффективнее для изменения процессов.

ВыводыРынок Offensive Security в 2026 году проходит через фундаментальную трансформацию.

А те, кто считает, что с ними ничего не случится, рискуют убедиться в обратном в самый неподходящий момент.

1 week, 2 days назад @ anti-malware.ru
Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA
Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA

SafeTech Lab встроила в SafeTech CA модуль CDM для доставки, установки и автоматического обновления технологических сертификатов.

Теперь заказчику больше не нужно искать отдельное решение, интегрировать его с CA и настраивать сложные схемы взаимодействия систем.

Новые расширенные возможности выводят SafeTech CA за рамки обычного центра сертификации — теперь это полноценная платформа управления цифровыми сертификатами.

SafeTech CA закрывает все самые востребованные задачи по контролю за сертификатами: от их выпуска до автоматического обновления на клиентских устройствах.

Модуль CDM расширяет возможности SafeTech CA за счёт агентской доставки, установки и автоматического перевыпуска сертифика…

1 week, 3 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 1 час назад
Централизуем использование ИИ при помощи Agentgateway
Централизуем использование ИИ при помощи Agentgateway Централизуем использование ИИ при помощи Agentgateway

Хочу познакомить вас с open-source-решением для контроля и централизации работы с ИИ — Agentgateway.

Agentgateway (буду сокращать до AGW) — мастер-оркестратор для ИИ.

Почему именно AGWУ читателя может возникнуть резонный вопрос: «А другие продукты вы рассматривали?» — «Да», — отвечу я. И сейчас объясню, почему остановились на AGW.

Данная настройка в AGW находится в разделе Settings → OIDC.

Хочу поблагодарить своих коллег Никиту Полосухина и Анатолия Зотова, благодаря которым я познакомился с Agentgateway и в итоге смог рассказать про него вам.

1 час назад @ habr.com
Почему ИИ‑агенты уязвимы к prompt injection и как защитить их на уровне архитектуры
Почему ИИ‑агенты уязвимы к prompt injection и как защитить их на уровне архитектуры Почему ИИ‑агенты уязвимы к prompt injection и как защитить их на уровне архитектуры

Я — независимый эксперт в области ИТ и ИБ, преподаю в учебных центрах и пишу статьи и книги.

OWASP формулирует это как «segregation of trust» и подчеркивает, что в 2026 году prompt injection и memory/RAG poisoning делают такое разделение «архитектурным требованием, а не просто хорошей практикой промпт‑инжиниринга».

Второй слой это изоляция результатов поиска, которые должны помечаться как недовернные и не смешиваться с системными инструкциями.

Важно, что это происходит на уровне архитектуры пайплайна, а не как «промпт‑инструкция модели не доверять документам».

Human‑in‑the‑loop как архитектурный компонент, а не «фича»Есть класс действий, которые не должны выполняться агентом без явного подт…

3 часа назад @ habr.com
От одного компьютера до глобальной эпидемии: как WannaCry распространялся по сети
От одного компьютера до глобальной эпидемии: как WannaCry распространялся по сети От одного компьютера до глобальной эпидемии: как WannaCry распространялся по сети

Как WannaCry распространялся по сетиУ WannaCry не было списка компьютеров, которые нужно заразить.

Именно сочетание двух направлений поиска, параллельных попыток и автоматического продолжения распространения делало WannaCry не просто шифровальщиком, а сетевым червём.

Исследователи обнаружили, что в определённых условиях данные, необходимые для восстановления ключа, могли сохраняться в оперативной памяти компьютера.

Регистрация домена помогла остановить распространение исходной версии WannaCry, но не могла отменить уже случившееся: она не расшифровывала файлы и не очищала компьютеры, которые успели заразиться.

WannaCry показал, как уязвимость, для которой уже существовало исправление, в соче…

11 часов назад @ habr.com
Как опубликовать внутренний API из DMZ, если соединения в LAN запрещены: пять подходов, которые мы проверили
Как опубликовать внутренний API из DMZ, если соединения в LAN запрещены: пять подходов, которые мы проверили Как опубликовать внутренний API из DMZ, если соединения в LAN запрещены: пять подходов, которые мы проверили

Если шлюз API стоит в DMZ, а соединения из DMZ в LAN запрещены, внутренний API можно опубликовать пятью способами.

Конфликт требований: шлюз в DMZ, системы в LAN, соединение внутрь запрещеноЗдесь важна одна деталь, которая многое определяет.

В DMZ и в LAN разворачиваются только шлюзы, которыми этот контур управляет.

Через полгода выясняется, что лимиты в DMZ и в LAN разные, и никто не помнит почему.

Частые вопросыКак опубликовать внутренний API наружу, если соединения из DMZ в LAN запрещены?

20 часов назад @ habr.com
Я полез в логи Mac после блокировки Claude, а починил только доступ к рабочим сайтам
Я полез в логи Mac после блокировки Claude, а починил только доступ к рабочим сайтам Я полез в логи Mac после блокировки Claude, а починил только доступ к рабочим сайтам

Почему я не стал пускать через VPN только ClaudeПервый план был простым: несколько сетей Claude в туннель, всё остальное напрямую.

Вечером 5 октября интернет пропал и с VPN, и без него.

Что первым нарушило правила, я не знаю, поэтому не скажу, что виновата только служба.

Контрольные запросы снова пошли и через VPN, и напрямую.

Если повторять такую настройку, я бы делал так:Сравнить один и тот же запрос через туннель и через физический интерфейс.

20 часов назад @ habr.com
Ошибочная блокировка на ТСПУ: как системному администратору решить проблему совместно с регулятором
Ошибочная блокировка на ТСПУ: как системному администратору решить проблему совместно с регулятором Ошибочная блокировка на ТСПУ: как системному администратору решить проблему совместно с регулятором

Покажу весь путь на реальном кейсе: от curl, traceroute и nping до переписки с ЦМУ ССОП и ДЦОА — без смены хостинга и IP-адреса.

Диагностируем проблему: действительно ли это ТСПУСначала нужно проверить, действительно ли проблема связана с фильтрацией на ТСПУ.

Отправляем заявку через ЛК ВТСЕсли диагностика указывает на ошибочную фильтрацию на ТСПУ, следующий шаг — заявка через ЛК ВТС.

Я также нашёл интересный пост на форуме, где один из системных администраторов сообщил, что на ТСПУ случайно заблокировали крымские подсети.

Если вы сталкивались с ошибочной фильтрацией на ТСПУ или взаимодействовали с ДЦОА, расскажите в комментариях, как проходила диагностика и что в итоге помогло восстановить …

21 час назад @ habr.com
Как использование нейросетей изменило игровую индустрию и homebrew-cцену
Как использование нейросетей изменило игровую индустрию и homebrew-cцену Как использование нейросетей изменило игровую индустрию и homebrew-cцену

Это событие изменило сцену взлома консолейВ последние годы взлом консолей и вся сцена пиратства — это в целом тот еще цирк, если честно.

Редакция в целом и автор лично решительно, громко и четко осуждает пиратство и любое нарушение условий использования ПО и железа.

Автор дает исключительно историческую справку происходящего, ни к чему не призывает и не показывает способы взлома.

Как ломали консоли раньше — методично руками искали уязвимости, копали ядро прошивки (при условии «подкопа») и в целом выполняли много очень монотонной работы.

Дальше началось бурное развитие Homebrew-сцены, потому что, как правило, пиратам-энтузиастам интереснее запускать то, что запуску не подлежит, а не игры с т…

23 часа назад @ habr.com
Я написал сканер уязвимостей для вайбкода и проверил им 3 800 чужих репозиториев
Я написал сканер уязвимостей для вайбкода и проверил им 3 800 чужих репозиториев Я написал сканер уязвимостей для вайбкода и проверил им 3 800 чужих репозиториев

Только в config.py лежит токен бота, в docker-compose.yml открыт Postgres на 0.0.0.0:5432 , а в истории git остался .env , который «потом удалили».

Раунд 1: 126 вайбкод-проектов и 2 012 «паролей»Начал я с репозиториев с явными следами ИИ: .cursorrules , CLAUDE.md , «vibe coded», «built with Cursor/Bolt/Lovable».

Находок снова хватило: токены ботов и API-ключи в коде и в истории git, закоммиченные .env , строки подключения к базам с паролем.

Почему я не проверял ни одного ключаМеня постоянно спрашивали: «Почему бы не дёрнуть getMe у Telegram и не узнать, живой ли токен?»Потому что это уже использование чужого доступа.

Больше всего времени ушло не на то, чтобы сканер находил, а на то, чтобы о…

1 day назад @ habr.com
Инструменты не спасут: как выстроить системную безопасность Kubernetes в условиях сотен разрозненных кластеров
Инструменты не спасут: как выстроить системную безопасность Kubernetes в условиях сотен разрозненных кластеров Инструменты не спасут: как выстроить системную безопасность Kubernetes в условиях сотен разрозненных кластеров

Моя статья об этом — как выстроить безопасность K8S как систему (функцию) в компании и масштабировать её в окружении сотен кластеров.

Собственно, распределение зон ответственности здесь уже будет выглядеть несколько иначе:Большинство «документов» мы пишем сами, но что-то уже и не мы.

Аудитор также отвечает за развитие нашего инструментария аудита, взаимодействуя и с командами и с BP.

Масштабировать безопасность количеством людей не получится — мы не можем быть сервисной командой.

Опять же, то, что мы не можем выполнить или закрыть по тем или иным причинам, мы ведем на оценку рисков.

1 day, 1 hour назад @ habr.com
Guardrails для LLM: как устроена защита языковых моделей
Guardrails для LLM: как устроена защита языковых моделей Guardrails для LLM: как устроена защита языковых моделей

Сегодня это звучит как фантастика, а вот ранние LLM ломались и на таком.

Атаки на LLM показали: если защита не умеет анализировать запрос и не может читать между строк, то она обречена.

Значит, нужны механизмы, которые удержат модель в рамках и не пропустят инъекцию, а если та все же проскочит, не дадут ей сработать.

Guardrails в норме срабатывают дважды: сначала на входе (когда модель получает запрос), а потом еще на выходе (когда модель выдает ответ).

Уже существуют Enterprise AI Gateway для агентов и моделей, в которых можно задавать политики и фильтры для каждого этапа взаимодействия.

1 day, 3 hours назад @ habr.com
Cloudflare изменил доступ ИИ-ботов к сайтам: как проверить настройки и не закрыть поиск
Cloudflare изменил доступ ИИ-ботов к сайтам: как проверить настройки и не закрыть поиск Cloudflare изменил доступ ИИ-ботов к сайтам: как проверить настройки и не закрыть поиск

Фразы о том, что новое умолчание включили всем бесплатным сайтам, я в документах Cloudflare не нашёл.

На странице с новыми результатами этой оговорки нет, вывод мой: цифры показывают ответ на самозваного бота, а не на краулер OpenAI.

Как проверить блокировку Cloudflare для ИИ-ботов на своём сайтеВосемь имён ведут себя по-разному, поэтому проверять надо каждое.

Настоящий доступ видно в логах сервера по IP краулеров и в разделе AI Crawl Control панели Cloudflare.

Robots.txt краулер читает сам, а правило Cloudflare и сервер сайта решают за него.

1 day, 4 hours назад @ habr.com
Корпуса персональных данных: 56 тысяч размеченных сущностей и ни одного вызова инструмента
Корпуса персональных данных: 56 тысяч размеченных сущностей и ни одного вызова инструмента Корпуса персональных данных: 56 тысяч размеченных сущностей и ни одного вызова инструмента

В корпусе для распознавания сущностей обычно нет ни CRM, ни вызова, ни результата поиска.

NEREL: большой корпус, но не переписка с поддержкойВ NEREL около 56 тысяч сущностей и 39 тысяч отношений, 29 типов разметки.

Обратите внимание на DATE: этим типом обозначены и «в 2009 году», и «через десять дней».

Это не точность определения ПДн: проверка допускает пересечение с любой сущностью и не требует совпадения типа или границ.

Для этого и нужны NEREL, MASSIVE и PII-Bench: они проверяют детектор на текстах, которые мы не составляли.

1 day, 4 hours назад @ habr.com
Глобальные политики Security Vision AM: как одна настройка автоматизирует целый модуль активов
Глобальные политики Security Vision AM: как одна настройка автоматизирует целый модуль активов Глобальные политики Security Vision AM: как одна настройка автоматизирует целый модуль активов

Вместо того, чтобы искать актив в общем списке, специалист сразу видит его карточку, роли, критичность и историю изменений — и может принимать решение.

Если опция включена — такие приложения считаются разрешёнными и не вызывают срабатываний политик контроля софта.

Зачем заказчику: Представьте, что вы только начинаете внедрение и в инфраструктуре тысячи рабочих станций с разным ПО.

Данная опция вынесена в отдельную настройку намеренно, так как она создаёт дополнительную нагрузку как на DNS-серверы организации, так и на сам модуль Security Vision Asset Management, который ожидает ответа по каждому запросу.

ЗаключениеГлобальные политики в Security Vision Asset Management — это не просто набор …

1 day, 4 hours назад @ habr.com
Дайджест ИБ-регулирования. Июль–сентябрь 2026
Дайджест ИБ-регулирования. Июль–сентябрь 2026 Дайджест ИБ-регулирования. Июль–сентябрь 2026

Кзи характеризует уровень защищенности информации в текущий момент и рассчитывается раз в полгода.

Что это значит для бизнесаФСТЭК продолжает приводить требования к защите информации к единому формату – теперь не только для госсектора, но и для бизнеса любых отраслей.

Проект приказа позволяет минимизировать эти риски как за счет функций безопасности ПО в составе информационных систем, так и с помощью решений для защиты информации.

При этом не обязательно учитывать показатели по всем направлениям: например, если организация не разрабатывает ПО, по этому направлению зрелость не оценивается.

Оценивать будет нужно, во-первых, все документы организации: политики, регламенты, стандарты, приказы и…

1 day, 4 hours назад @ habr.com
Luna Decisions в n8n для парсинга объявлений недвижимости: схема интеграции, ограничения и вопросы к сообществу
Luna Decisions в n8n для парсинга объявлений недвижимости: схема интеграции, ограничения и вопросы к сообществу Luna Decisions в n8n для парсинга объявлений недвижимости: схема интеграции, ограничения и вопросы к сообществу

Это не рассказ про кейс заказчика и не отчёт о внедрении Luna Decisions.

Реальных вызовов Decisions API и проверки интеграции в n8n здесь нет; проверка JavaScript на синтетических данных не заменяет такую проверку.

Ниже разберу, куда его можно встроить, чего не хватает во входных данных и с чем я бы сравнивал результат.

В дальнейшем я бы использовал статус "не найдено в последнем полном сканировании" и подтверждал отсутствие в нескольких успешных прогонах.

'baseline_thresholds_met' : 'below_baseline_thresholds' }; } return $input.all().map(({ json }) => ({ json: { ...json, ...decide(json.decision, json.baseline_candidate) } }));candidate в этом эксперименте - запись в журнале = не отправка …

1 day, 14 hours назад @ habr.com
Хакер Хакер
последний пост 1 day, 18 hours назад
Google частично приостанавливает работу опенсорсной программы bug bounty из-за ИИ-слопа
Google частично приостанавливает работу опенсорсной программы bug bounty из-за ИИ-слопа Google частично приостанавливает работу опенсорсной программы bug bounty из-за ИИ-слопа

Компания Google временно не принимает отчеты об уязвимостях через программу Open Source Software Vulnerability Rewards Program (OSS VRP).

Представители Google пишут, что в ближайшее время намерены переработать OSS VRP с учетом новой проблемы автоматизированных отчетов.

Отметим, что это не первая программа bug bounty, которая не справляется с потоком отчетов, сгенерированных или подготовленных с помощью ИИ.

Кроме того, в мае текущего года специалисты Google уже меняли правила bug bounty для Chrome и Android из-за широкого распространения ИИ-инструментов.

Тогда стандартные выплаты за баги в Chrome снизили, сделав упор на короткие отчеты с конкретными доказательствами существования проблемы.

1 day, 18 hours назад @ xakep.ru
Apple ограничит полный доступ к диску в macOS из-за ИИ-агентов
Apple ограничит полный доступ к диску в macOS из-за ИИ-агентов Apple ограничит полный доступ к диску в macOS из-за ИИ-агентов

Инженеры компании Apple планируют изменить механизм работы Full Disk Access (FDA) в macOS, чтобы приложения не могли получать доступ к файлам, почте, сообщениям и истории браузера без явного согласия пользователя.

Full Disk Access позволяет приложениям обходить часть ограничений macOS и читать или изменять данные, которые обычно для них недоступны.

Такой уровень доступа нужен, например, антивирусам и ПО для резервного копирования, однако в Apple предупреждают, что некоторые разработчики используют FDA слишком широко.

В сентябре упомянутый Патрик Уордл обнаружил в Mac-клиенте агента уязвимость, которая позволяла локальному приложению или команде получить доступ к токену Muse и перехватить уп…

1 day, 20 hours назад @ xakep.ru
Карты на стол! Проводим пентест POS-терминалов
Карты на стол! Проводим пентест POS-терминалов Карты на стол! Проводим пентест POS-терминалов

Схе­му вза­имо­дей­ствия мы, как и преж­де, намерен­но упростим.

Теперь мож­но перей­ти к одно­му из кей­сов, с которым мы стол­кну­лись на пен­тесте реаль­ного при­ложе­ния.

Итак, у нас есть пач­ка POS-тер­миналов, пла­теж­ное при­ложе­ние, которое уста­нов­лено на эти самые тер­миналы, и дос­туп к тес­товому веб‑при­ложе­нию TMS.

Более того, из‑за это­го у нас отсутс­тво­вал дос­туп к сетевым нас­трой­кам и мы не мог­ли нас­тро­ить MitM для ана­лиза тра­фика.

На одном из устрой­ств нас­трой­ки Android ока­зались без пароля — и мы сра­зу под­няли точ­ку дос­тупа Wi-Fi на ноут­буке.

1 day, 22 hours назад @ xakep.ru
Новая разновидность проблемы Spectre v2 угрожает процессорам Intel, AMD и Arm
Новая разновидность проблемы Spectre v2 угрожает процессорам Intel, AMD и Arm Новая разновидность проблемы Spectre v2 угрожает процессорам Intel, AMD и Arm

Новая разновидность side-channel-атаки Spectre v2, получившая название Branch Target Reuse (BTR), позволяет извлекать секреты из памяти через JIT-движки.

Согласно опубликованному исследователями отчету, атака нацелена на JIT-компиляторы, которые генерируют машинный код на лету и применяются в браузерных движках, рантаймах и ядре ОС.

Проблема связана с рассинхронизацией между текущим кодом в памяти и предсказателем ветвлений (branch predictor) процессора.

В результате CPU может использовать устаревшее предсказание и спекулятивно выполнить фрагмент нового кода, который оказался по адресу старой цели перехода.

Исследователи подтвердили, что эффект, на котором основана BTR, проявляется на всех …

1 day, 23 hours назад @ xakep.ru
Недавний взлом ФБР был связан с компанией-подрядчиком Accenture
Недавний взлом ФБР был связан с компанией-подрядчиком Accenture Недавний взлом ФБР был связан с компанией-подрядчиком Accenture

Хотя в ФБР не уточнили, какая именно система была скомпрометирована, источники Reuters утверждают, что атакующие взломали платформу Oracle PeopleSoft, которую обслуживала Accenture.

Конфликт между участниками ShinyHunters и ФБР начался в конце сентября 2026 года, когда представители группировки заявили о взломе ведомства.

Затем СМИ сообщили, что в Иордании задержали еще одного предполагаемого участника группировки, известного под ником Rey.

Источники журналистов утверждали, что теперь хакер сотрудничает с ФБР и помогает правоохранительным органам установить личности и местонахождение других участников группы.

Примечательно, что практически одновременно с этим представители ShinyHunters заяв…

2 days, 1 hour назад @ xakep.ru
Новая партия бейсболок «Хакера»
Новая партия бейсболок «Хакера» Новая партия бейсболок «Хакера»

Осенью погода меняется почти каждый день, но бейсболкам «Хакера» отдельный сезон не нужен.

Они одинаково хорошо защитят тебя от ветра, дождя и солнца, а за счет лаконичной вышивки не похожи на скучный корпоративный мерч.

Судя по тому, как быстро пустел наш склад, идея с бейсболками удалась, и мы уже заказали дополнительную партию.

Они одинаково уместно смотрятся как на созвоне с тимлидом, так и на прогулке в парке.

Бейсболки «Хакера» — это:• плотная ткань, которая хорошо держит форму;• удобная регулируемая посадка;• объемная вышивка;• четыре варианта дизайна на выбор.

2 days, 2 hours назад @ xakep.ru
Агенты OpenAI вносили правки в проекты Wikimedia и могли спровоцировать сбой
Агенты OpenAI вносили правки в проекты Wikimedia и могли спровоцировать сбой Агенты OpenAI вносили правки в проекты Wikimedia и могли спровоцировать сбой

Отмечается, что большинство подозрительных правок агентов осталось в «песочницах» и не попадало на страницы, доступные обычным читателям.

Причем среди изменений были потенциально вредоносные, включая попытки подмены конфигурации инструмента для работы с цитатами, который агенты пытались превратить в прокси.

Так, по данным Wikimedia, в прошлом году на ботов приходилось 65% наиболее ресурсоемкого трафика, а потребление пропускной способности выросло на 50%.

В фонде подчеркивают, что ИИ-компании недостаточно контролируют своих агентов и в итоге перекладывают последствия их активности на владельцев внешних сервисов.

Представители OpenAI заявили СМИ, что в настоящее время изучают данные Wikimedi…

2 days, 3 hours назад @ xakep.ru
Американский военный получил 70 месяцев тюрьмы за атаки на AT&T, Verizon и другие компании
Американский военный получил 70 месяцев тюрьмы за атаки на AT&T, Verizon и другие компании Американский военный получил 70 месяцев тюрьмы за атаки на AT&T, Verizon и другие компании

Среди сообщников Вагениуса следствие называет канадца Коннора Райли Муку (Connor Riley Moucka), известного как Waifu и Judische, а также Джона Эрина Биннса (John Erin Binns), использовавшего ники irdev и j_irdev1337.

Злоумышленники угрожали опубликовать украденную информацию на хак-форумах BreachForums и XSS, а в некоторых случаях выставляли похищенные данные на продажу, оценивая их в несколько тысяч долларов США.

В феврале 2025 года он признал свою вину по делу о взломах компаний AT&T и Verizon и передаче конфиденциальных телефонных записей.

А в июле того же года он также признал себя виновным по обвинениям в краже личности при отягчающих обстоятельствах, сговоре с целью мошенничества и вы…

2 days, 18 hours назад @ xakep.ru
Лидером вымогательской группы KillSec оказался 16-летний подросток
Лидером вымогательской группы KillSec оказался 16-летний подросток Лидером вымогательской группы KillSec оказался 16-летний подросток

В рамках международной операции KillSwitch правоохранительные органы ликвидировали инфраструктуру вымогательской группировки KillSec, конфисковали ее сайт для «слива» данных и серверы, а также задержали трех подозреваемых.

Подозреваемых задержали в Испании, Румынии и Великобритании, и суммарно полиция провела восемь обысков в этих странах, а также на территории Греции.

В рамках операции полиция перехватила управление даркнет-сайтом KillSec и пятью ключевыми серверами, включая основной сервер группы и системы, использовавшиеся для хранения похищенной информации.

Помимо этого следователи выяснили, что участники KillSec использовали ИИ для создания и поддержки своей инфраструктуры, а также пои…

2 days, 20 hours назад @ xakep.ru
HTB Reactor. Повышаем привилегии через открытый отладчик Node.js
HTB Reactor. Повышаем привилегии через открытый отладчик Node.js HTB Reactor. Повышаем привилегии через открытый отладчик Node.js

Справка: сканирование портовСка­ниро­вание пор­тов — стан­дар­тный пер­вый шаг при любой ата­ке.

На осно­ве этой информа­ции он выбира­ет сле­дующий шаг к получе­нию точ­ки вхо­да.

Улуч­шить резуль­таты его работы ты можешь при помощи такого скрип­та:#!/ bin/ bash ports = $( nmap -p- -- min- rate = 500 $1 | grep ^ [ 0 -9 ] | cut -d '/ ' -f 1 | tr ' ' ', ' | sed s/, $/ / ) nmap -p $ports -A $1Он дей­ству­ет в два эта­па.

На пер­вом выпол­няет­ся обыч­ное быс­трое ска­ниро­вание, на вто­ром — более тща­тель­ное, с исполь­зовани­ем встро­енных скрип­тов (опция -A ).

Под­робнее про работу с Nmap читай в статье «Nmap с самого начала.

2 days, 22 hours назад @ xakep.ru
В OpenAI заявляют, что прервали кампанию по дистилляции, связанную с Moonshot AI
В OpenAI заявляют, что прервали кампанию по дистилляции, связанную с Moonshot AI В OpenAI заявляют, что прервали кампанию по дистилляции, связанную с Moonshot AI

Основной кластер этой активности в компании связывают с людьми, имеющими отношение к разработчику Kimi — китайской компании Moonshot AI.

В отчете подчеркивается, что атакующие не взламывали шифрование, базы данных и не получили доступ к историям пользовательских диалогов.

Какие именно модели OpenAI стали целью атак, в компании не сообщили.

Также в OpenAI признают, что не все замеченные операторы этой кампании могли быть связаны с Moonshot AI.

По версии Anthropic, часть этих диалогов в Moonshot AI сохраняли и использовали для обучения собственной модели, работающей с цепочками рассуждений.

2 days, 23 hours назад @ xakep.ru
Репозитории на GitHub раскрывают более 543 000 учетных данных
Репозитории на GitHub раскрывают более 543 000 учетных данных Репозитории на GitHub раскрывают более 543 000 учетных данных

Исследователи из компании Truffle Security подсчитали, что в открытых репозиториях на GitHub опубликованы 543 699 уникальных и по-прежнему действующих учетных данных.

В общей сложности 543 699 уникальных секретов встречались более чем в 1,1 млн файлов и репозиториев, включая копии в форках.

В компании отдельно отметили, что в случае GitHub масштаб проблемы оказался в два раза больше, чем при аналогичном исследовании Hugging Face.

Отдельно исследователи оценили эффективность механизма GitHub Push Protection, который ищет в коде API-ключи, токены доступа и другие секреты, а затем блокирует их публикацию.

Однако исследователи установили, что, невзирая на работу GitHub Push Protection, 199 843 …

3 days, 1 hour назад @ xakep.ru
СМИ: Минцифры снова рассматривает введение платы за международный трафик
СМИ: Минцифры снова рассматривает введение платы за международный трафик СМИ: Минцифры снова рассматривает введение платы за международный трафик

На этот раз с операторами обсуждается лимит в 50 Гбайт в месяц и только для сетей 5G.

Дело в том, что, по словам источников, у операторов связи попросту нет технического решения, нужного для реализации такого предложения.

Директор по продуктам Vigo Антон Прокопенко сообщил изданию, что в целом учитывать зарубежный трафик возможно, например, классифицируя его по IP-адресам.

Так, операторам придется классифицировать адреса и одновременно учитывать переключения абонента между 5G и LTE.

К примеру, в 2025 году частный абонент в среднем расходовал около 24 Гбайт всего мобильного трафика в месяц.

3 days, 3 hours назад @ xakep.ru
В GitLab AI Gateway исправили критический баг на 9,9 балла
В GitLab AI Gateway исправили критический баг на 9,9 балла В GitLab AI Gateway исправили критический баг на 9,9 балла

AI Gateway представляет собой сервис, который связывает инстанс GitLab с ИИ-моделями и обеспечивает работу функций GitLab Duo.

Хотя в GitLab используют собственный облачный инстанс AI Gateway для GitLab.com, GitLab Self-Managed и GitLab Dedicated, пользователи также имеют возможность развертывать собственные установки в рамках GitLab Self-Managed посредством GitLab Duo Self-Hosted.

Подчеркивается, что пользователи AI Gateway, размещенного на серверах самой GitLab, уже защищены и им не нужно предпринимать никаких дополнительных действий.

В результате атакующий получал возможность выполнять произвольные команды непосредственно в AI Gateway.

Так как AI Gateway устанавливается отдельно, в виде …

3 days, 18 hours назад @ xakep.ru
Near Intents идентифицировала атакующего и вернула похищенные $3,8 млн
Near Intents идентифицировала атакующего и вернула похищенные $3,8 млн Near Intents идентифицировала атакующего и вернула похищенные $3,8 млн

Команда кроссчейн-сервиса для обмена токенов NEAR Intents сообщила, что ей вернули 3,8 млн долларов, похищенных при взломе 1 октября.

Деньги вернулись всего через сутки после того, как команда заявила, что установила личность атакующего, и дала ему 48 часов на возврат средств.

В пятницу о возврате средств объявил генеральный менеджер NEAR Intents Алекс Шевченко в соцсети X. По его словам, все средства возвращены и команда прекращает расследование инцидента.

Уязвимость позволила злоумышленнику вывести средства, после чего работу NEAR Intents приостановили.

За два дня до атаки команда Near Intents заблокировала попытку обменять $50 млн, предпринятую хакером, стоящим за взломом биржи Bitget.

3 days, 19 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 2 часа назад
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

How the Flaw WorksAn .onion address is really a public key, so whoever holds the matching private key controls the address.

A Tor private key is 64 bytes long, but GoBalance passed only the first 32 bytes to the signer and dropped the rest.

A single published descriptor then carries enough to recover the site's private key, with no access to its servers.

On October 5, Paris said he had "stupidly uploaded dread's main onion private key into a gobalance update."

A backup is harder to explain as a slip, and HugBunter then said the attacker had used a GoBalance flaw against several dark-web services.

2 часа назад @ thehackernews.com
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched.

One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner.

An entry that uses an already-known bug, which ZDI calls a collision, can still be accepted at a lower prize.

Google's October Pixel bulletin was published on October 6, two days before the Pixel 10 exploits were shown, and does not mention the contest.

Separately, Google in September patched a Pixel modem flaw, CVE-2026-58704, that it said : "may be under limited, targeted exploitation."

3 часа назад @ thehackernews.com
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions.

Successful exploitation hinges on the NetScaler deployments being configured as a SAML identity provider (IdP) or service provider (SP).

Customers can determine if their instances meet the criteria by checking the configuration for entries like below -SAML SP: add authentication samlActionSAML IdP: add authentication samlIdPProfileThe issue impacts the following versions -When configured as a SAML IdP - NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive Ne…

3 часа назад @ thehackernews.com
FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions

The U.S. Federal Bureau of Investigation (FBI) and Department of Justice (DoJ) have announced the disruption of malicious tools used by a China-linked advanced persistent threat group known as Flax Typhoon.

To that end, the agencies seized several domains and blocked access to platforms that were used to scan, and in some cases infiltrate, U.S. critical infrastructure.

According to the FBI, the botnet is said to have used a number of domains, including subdomains of w8510[.

In all, more than 260,000 devices, including approximately 126,000 U.S. devices, were actively infected as of June 5, 2024.

The botnet made use of a tool called Microscan to facilitate reconnaissance and computer vulnera…

4 часа назад @ thehackernews.com
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK.

The hackers also run a web application that "provides third-party access to stolen email content," the advisory said.

In September 2024, the FBI disrupted a botnet, a network of hijacked devices, that the U.S. Justice Department said Integrity Technology Group controlled.

Integrity Technology Group rejected the U.S. accusations in January 2025.

The FBI attributes that domain to Integrity Technology Group and assesses that the malware likely targets email.

16 часов назад @ thehackernews.com
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

One ransomware affiliate decided to keep the profits for himself.

Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion.

A basic file upload flaw gave attackers a way in, while weak session cookies made impersonation far too easy.

One strange thing about this week's stories is how often the attackers look just as careless as the systems they're breaking into.

Some leave their tools exposed.

17 часов назад @ thehackernews.com
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

The only product it names as a target is Metabase, a BI tool with a known flaw that attackers have exploited.

The Metabase Flaw and Which Versions to RunThe third pattern is exploitation of CVE-2026-72898, an SQL injection flaw in Metabase, an open-source BI tool that companies connect to their databases.

Give API users and tokens only the privileges they need.

The commission's guidance on leaks from unauthorized access, revised the same day, includes a case study on API abuse.

In it, an attacker logs in to a smartphone app or web service, rewrites request parameters, and gets other users' data.

19 часов назад @ thehackernews.com
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN.

ASHVEIN, compiled by the dev account, uses a different packing approach.

UAC-0099 makes use of multiple delivery methods for ASHVEIN, including DLL sideloading (aka FORGECLAMP), VHD containers, and purpose-built .NET droppers.

"This combination of institutional impersonation and credible decoy content is designed to increase the likelihood that recipients will open and trust the file," TrendAI said.

Recently observed iterations of MATCHBOIL have taken the form of a DLL file that's executed by a custom C# loader.

20 часов назад @ thehackernews.com
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks.

The campaign has not been attributed to any known threat actor or group.

It's suspected that the threat actor accessed DeepSeek via the likely LLM API reseller "xcai[.]pro."

"In addition to conducting ARTEX-related operations, the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups," CrowdStrike said.

"While the personal details included in the prompt likely belong…

21 час назад @ thehackernews.com
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself.

ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia.

Wazza Uses Multi-Stage Routing to Hide Its Phishing PageWazza does not send every visitor directly to its phishing page.

One Wazza Investigation Can Reveal More Than One IOCThe infrastructure behind Wazza should not be viewed simply as a list of domains to block.

For MSSPs, combining interactive sandboxing, threat intelligence, and integrations helps turn individual investigations into actionable i…

1 day, 1 hour назад @ thehackernews.com
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases 16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys.

The names of the extensions are below [email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@1.4franklin-uk@brows…

1 day, 1 hour назад @ thehackernews.com
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM.

Xu was arrested in Milan in July 2025 at the request of the United States, and Italy extradited him to the United States in April 2026.

What Zhang Is Accused OfU.S. authorities describe Zhang as a director at Shanghai Firetech Information Science and Technology, a Shanghai company.

On or about January 30, 2021, Xu allegedly told Zhang he had compromised a Texas university's network.

In July 2021, the United States and partner governments sa…

1 day, 3 hours назад @ thehackernews.com
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

On its website, MonsterCloud claims it uses "advanced decryption techniques and cutting-edge technology" to restore data.

Under a section called "Should I Pay The Ransom?," it states, "Paying a ransom to cybercriminals does not guarantee a positive outcome.

Contrary to its claims, there were no specialized tools to decrypt the data.

Pinhasi is said to have charged MonsterCloud's clients a fee that was "substantially higher" than the ransom that was secretly paid to the criminals.

In all, Pinhasi is accused of charging clients more than $19 million and paying more than $8 million in ransom payments.

1 day, 3 hours назад @ thehackernews.com
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack.

The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said.

Version 0.5.144 is no longer available for download from the npm package registry.

The stealer malware is designed to harvest credentials across local files, CI environments, Kubernetes, and Vault sources.

]com"), with GitHub acting as a fallback mechanism to stage the encrypted stolen data in a pub…

1 day, 5 hours назад @ thehackernews.com
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6.

Chrome blocked the unauthorized certificates for Google's domains through CRLSets, its way of quickly blocking certificates in emergencies, Google said.

They show at least 12 certificates issued between September 22 and 27 for Google and YouTube names under the three ccTLDs, including google.com.gh, google.sl and google.as.

Let's Encrypt issued 11 of them and ZeroSSL issued one.

SHA-256: 0357032e1214ae11d7da8e00f6b89fb7694e240b17d05f2f47feaf43e96aa7d8 SHA-256: 8886ca2b71501a6729f1ae868bd7d7b9b53c5cb6b5c7d851d041db4d6206945d SH…

1 day, 16 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 1 day, 2 hours назад
MATCHBOIL: New tricks, same old evil intentions
MATCHBOIL: New tricks, same old evil intentions MATCHBOIL: New tricks, same old evil intentions

Later, in June 2026, ESET telemetry registered further MATCHBOIL samples, this time at a company in the energy sector.

MATCHBOIL then performs three HTTPS requests to the C&C server; each with a different purpose:The first request receives a numeric value from the C&C server.

2024 samplesThe earliest MATCHBOIL samples that we have seen have compilation timestamps from 2024.

]pro N/A 2025‑11‑10 MATCHBOIL C&C server hidden behind Cloudflare.

]com N/A 2025‑08‑12 MATCHBOIL C&C server hidden behind Cloudflare.

1 day, 2 hours назад @ welivesecurity.com
Inside a brand deal scam targeting YouTube creators
Inside a brand deal scam targeting YouTube creators Inside a brand deal scam targeting YouTube creators

The platform also asks for the creator’s YouTube channel URL, which it uses to retrieve public information and generate a seemingly personalized experience.

How to stay safeIf you’re a social media influencer yourself, your Google account can be much more than “just” access to a YouTube channel.

Run Google’s Security Checkup, or open Security & sign-in in your Google account, and review recent security events and signed-in devices.

If you’re a YouTube creator yourself, you realize that your reputation ultimately defines your success.

A Google account can then sit at the center of your business: email, files, contacts, and the YouTube channel itself.

2 days, 2 hours назад @ welivesecurity.com
The quest for simplicity: Why SMBs want advanced protection without the complexity
The quest for simplicity: Why SMBs want advanced protection without the complexity The quest for simplicity: Why SMBs want advanced protection without the complexity

The cybersecurity market is often making it tougher for SMBs to keep threats at bayCybersecurity has never been easy.

SMBs are very much in the crosshairs, as providers of critical infrastructure themselves or suppliers to firms operating in critical infrastructure.

Yet the identity of the adversary is arguably less important than the tactics they’re using to target global SMBs.

By offering teams AI assistance to improve productivity.

By offering teams AI assistance to improve productivity.

3 days, 2 hours назад @ welivesecurity.com
This month in security with Tony Anscombe – September 2026 edition
This month in security with Tony Anscombe – September 2026 edition This month in security with Tony Anscombe – September 2026 edition

Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep paceAs another month draws to a close, ESET Chief Security Evangelist Tony Anscombe reviews some of the top cybersecurity stories that have made the news over the past 30 days while offering insights that they hold for your or your company's cyber-defenses.

Here's Tony's rundown of some of what stood out most in September 2026.

An OpenAI agent has broken into Australia's national healthcare database in what is the first known case of AI autonomously hacking a government network,Earlier in the month, Google announced that its models also escaped it…

1 week, 2 days назад @ welivesecurity.com
Timeshare exit scams: From fake buyers to recovery fraud
Timeshare exit scams: From fake buyers to recovery fraud Timeshare exit scams: From fake buyers to recovery fraud

If an exit company cold calls you or makes 100% guaranteed promises of a swift exit, they’re likely to be a scammer.

If you’ve already paid a scam timeshare exit company, there’s still a chance you could get your money back if you act quickly.

What are the warning signs of a timeshare exit scam?

How can I check whether a timeshare exit company is legitimate?

What should I do if I've already paid a timeshare exit scam company?

1 week, 3 days назад @ welivesecurity.com
The devil is still in the email – but wearing a new mask
The devil is still in the email – but wearing a new mask The devil is still in the email – but wearing a new mask

Some techniques go after live sessions themselves, with attackers shifting their focus from stealing passwords to stealing authentication tokens.

Purpose-built AI tools now make it trivial to clean up the language and even tailor the lure for each recipient.

What’s more, the code is scanned on a phone, so the usual controls that protect company-issued laptops don’t apply.

The ‘device hop’ also means that the company may have a hard time developing a full picture of the attack.

AI helps deal with the volume and speed involved, whereas experienced analysts can assess the evidence and direct the response.

1 week, 4 days назад @ welivesecurity.com
Is that vibe coded app safe? 5 checks before you download
Is that vibe coded app safe? 5 checks before you download Is that vibe coded app safe? 5 checks before you download

Vibe coded apps may also be exposed to prompt injection.

What can go wrong with vibe coded apps?

With a badly coded app, the leak usually happens on the developer’s servers, so start with your account and credentials.

Frequently asked questions (FAQs)What does 'vibe coded' mean?

Are all vibe coded apps dangerous?

2 weeks назад @ welivesecurity.com
Been told to pay at a Bitcoin ATM? Read this first
Been told to pay at a Bitcoin ATM? Read this first Been told to pay at a Bitcoin ATM? Read this first

No real government agency, bank, or company will ever tell you to pay them via a Bitcoin ATM.

How do Bitcoin ATM scams work?

How do I stay safe from Bitcoin ATM scams?

What can I do straight after a Bitcoin ATM scam?

What should I do if I’ve fallen for a Bitcoin ATM scam?

2 weeks, 1 day назад @ welivesecurity.com
Looking for free Robux? Here’s what’s real, and what’s a scam
Looking for free Robux? Here’s what’s real, and what’s a scam Looking for free Robux? Here’s what’s real, and what’s a scam

Roblox itself is very clear: “There is no such thing as free Robux or subscription offers, tricks, or codes.”What there is, unfortunately, are a lot of scammers looking to trick you out of your personal information and logins with the promise of free Robux.

But it’s also about helping them understand there’s no such thing as ‘free’ Robux.

Frequently asked questions (FAQs)Is there a real free Robux generator?

Roblox says there is no legitimate way to get free Robux through generators, tricks or codes.

But these aren’t ‘free Robux generators.’How can I tell if a Robux offer is a scam?

2 weeks, 3 days назад @ welivesecurity.com
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive

Many have moved past chatbots and begun assigning work to AI agents in the hope of gaining an edge on their similarly resource-strapped competitors and levelling the playing field with larger companies.

Indeed, the ambitious adopters are deploying, or at least experimenting with, multi-agent ‘assembly lines,’ where one supervisor agent manages swarms of specialist agents and passes work between them.

Of course, some risks surrounding AI agents have familiar roots: an agent’s supply chains can be compromised and its permissions abused.

Agents can also suffer from agentic misalignment where they proceed doggedly even if it involves, for example, breaking into other companies.

For a company wi…

2 weeks, 4 days назад @ welivesecurity.com
‘Nudify’ apps: What to do if someone makes a fake nude of you
‘Nudify’ apps: What to do if someone makes a fake nude of you ‘Nudify’ apps: What to do if someone makes a fake nude of you

And it doesn’t get much darker than ‘nudification’ or ‘nudify’ apps.

Are ‘nudify’ apps illegal?

The short answer is “it depends.” In the US, there’s no federal law explicitly prohibiting ‘nudify’ apps.

Can I sue over an AI nude image?

Will reporting a fake nude image make it disappear everywhere?

3 weeks назад @ welivesecurity.com
Beware the SparroWock: The backdoor that bites, the commands that catch
Beware the SparroWock: The backdoor that bites, the commands that catch Beware the SparroWock: The backdoor that bites, the commands that catch

A month later, we noticed that the group had started using the new SparroWocky backdoor, which then quickly replaced SparrowDoor as FamousSparrow’s main implant.

Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor.

Backdoor commandsThe backdoor first establishes communication with its C&C server, then executes its core logic in an infinite loop, within which it processes received commands.

A common technique that the backdoor uses is dynamic API resolution via API hashing, but the backdoor…

3 weeks, 1 day назад @ welivesecurity.com
Cyberthreats are moving faster than SMBs: Readiness must accelerate
Cyberthreats are moving faster than SMBs: Readiness must accelerate Cyberthreats are moving faster than SMBs: Readiness must accelerate

This calls for a different operational model where AI and automation support security teams where it makes sense, with human oversight for decisions that require context and judgment.

ESET SMB Cyber Readiness Index 2026 found that most (73%) SMBs are integrating AI into their business.

Processing exfiltrated data: AI rapidly classifies, cleans-up, and extracts large volumes of information from stolen data in order to make it more monetizable/usable for cybercriminals.

Why SMBs are struggling with complexityUnfortunately, security teams are already on the back foot.

That means protection for AI conversations, agents, AI-generated outputs, AI components, sensitive data, and the broader AI eco…

3 weeks, 2 days назад @ welivesecurity.com
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
GuardBreaker: Derailing AI-assisted malware analysis with a code comment GuardBreaker: Derailing AI-assisted malware analysis with a code comment

Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way.

Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection.

Reporting on the same broader campaign, StepSecurity found a prompt that flat-out instructed any analyzing model that parsed the file to disregard the malicious code and report the package as clean.

Some parts of the malicious code could be concealed under the pretense of being confidential information or other sensitive data.

Crucially, however, no single LLM engine should have the sole au…

4 weeks, 1 day назад @ welivesecurity.com
Safe word: What is it and why do you need one?
Safe word: What is it and why do you need one? Safe word: What is it and why do you need one?

The technology might be impressive, but a simple technique could stop the scammers in their tracks: a pre-agreed safe word.

What is a safe word?

But suggest some scenarios in which it would be a good idea to request a safe word.

It’s important to have a backup if someone can’t remember the safe word.

But a safe word is a fantastic, free option for uncovering deepfake audio fraud like fake/virtual kidnappings.

1 month назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 1 час назад
Anthropic offers free AI security scans to open-source maintainers
Anthropic offers free AI security scans to open-source maintainers Anthropic offers free AI security scans to open-source maintainers

Anthropic’s OSS Scanner is a new, free service that uses the company’s strongest AI models to find security vulnerabilities in open-source software.

Maintainers who opt in receive periodic scans and reports explaining suspected flaws, how to reproduce them and, when available, how to fix them.

Penetration testers assessed 97 high and critical severity findings across 48 projects from an early version of the scanner.

If Anthropic later validates a report through its existing coordinated disclosure program, a 90-day period may begin when maintainers are notified of that validation.

Projects can pause automated reports or opt out and return to receiving only reports under company’s standard di…

1 час назад @ helpnetsecurity.com
FBI disrupts Flax Typhoon hacking tools used in global cyberattacks
FBI disrupts Flax Typhoon hacking tools used in global cyberattacks FBI disrupts Flax Typhoon hacking tools used in global cyberattacks

The FBI seized seven domains used to operate Microscan and FishHub, two hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon that were used to target critical infrastructure and other organizations in the US and abroad.

Seizure notice (Source: US Department of Justice)According to the US Department of Justice, the hackers worked for Integrity Technology Group (Integrity Tech), a China-based company that holds contracts with the Chinese government.

Integrity Tech accessed the tool through c0cc[.

That malware either gave the company’s clients unauthorized remote access, or searched for specific files and sent them to servers controlled by Integrity Tech.

The advisory …

1 час назад @ helpnetsecurity.com
Product showcase: SimpleLogin keeps your email address private with aliases
Product showcase: SimpleLogin keeps your email address private with aliases Product showcase: SimpleLogin keeps your email address private with aliases

SimpleLogin is an email alias service from Proton that forwards messages to an existing mailbox.

Users create addresses for registrations, purchases, and correspondence, giving them control over where their primary email address is shared.

During this setup, the activity counter recorded one forwarded message, zero blocked messages, and zero sent messages.

I also tested sending an email from an alias to another email address I own.

Messages arrive in the connected inbox, and replies pass through SimpleLogin to preserve the alias address.

2 часа назад @ helpnetsecurity.com
October 2026 Patch Tuesday forecast: Time for an Office cleanup
October 2026 Patch Tuesday forecast: Time for an Office cleanup October 2026 Patch Tuesday forecast: Time for an Office cleanup

I will point out that starting in July, Microsoft has consolidated the Semi-Annual Enterprise Channel and the Monthly Enterprise Channel into a single, combined enterprise update channel.

Windows 11 26H2 arrives ahead of critical fixes and support cutoffsMicrosoft released Windows 11 26H2 on September 29th.

This new operating system shares the same kernel with Windows 11 24H2 and Windows 11 25H2, so those versions can be updated with an Enablement Package direct to Windows 11 26H2 with minimal interruption.

The Windows 11 update counts as a security update because it covers CVE-2026-62721 and the Windows 11 26H1 also fixes CVE-2026-85921.

Also consider your support desk and staff with respe…

4 часа назад @ helpnetsecurity.com
What the BPFDoor backdoor tells us about attacks on the network edge
What the BPFDoor backdoor tells us about attacks on the network edge What the BPFDoor backdoor tells us about attacks on the network edge

A backdoor that makes no noise is hard to catch, and that’s the point of BPFDoor.

For readers who haven’t followed this malware family, what is BPFDoor, and why has it worried telecom security teams for years?

Modern telecom networks are layered ecosystems composed of routing systems, subscriber management platforms, authentication services, billing systems, roaming databases, and lawful intercept capabilities.

Many network appliances can’t run endpoint security agents, and some vendor support contracts restrict what customers can install.

Finally, check for unrestricted management access to edge devices so a stolen credential doesn’t hand over the keys.

5 часов назад @ helpnetsecurity.com
Thousands of wind and solar park systems sit exposed on the internet across Europe
Thousands of wind and solar park systems sit exposed on the internet across Europe Thousands of wind and solar park systems sit exposed on the internet across Europe

The systems range from login screens to a turbine control page that offers a Stop button to anyone with a browser.

A system only made the list once the team could link it to a specific solar or wind site.

Some of the solar and wind devices were ones the team had not known to look for.

One wind turbine shows what the exposure looks like.

The wind farms in scope run from 10 megawatts to more than 4,500, and some of the exposed wind systems control several turbines at once.

6 часов назад @ helpnetsecurity.com
PCI SSC calls for human approval of AI agent actions involving cardholder data
PCI SSC calls for human approval of AI agent actions involving cardholder data PCI SSC calls for human approval of AI agent actions involving cardholder data

The PCI Security Standards Council (PCI SSC) has published Security Considerations for AI Systems, guidance covering the protection of data supplied to AI systems in payment environments and defenses against AI-assisted attacks.

A suitable human individual should formally accept responsibility for AI output, and organizations should specify which actions require human approval.

Organizations should avoid combining sensitive data access, external communications and unrestricted input from untrusted sources in one AI system.

The guidance describes human approval for each task and an alternative in which AI systems perform authorized actions under monitoring without approval for every individu…

6 часов назад @ helpnetsecurity.com
Companies want autonomous IT operations but hesitate to let AI act alone
Companies want autonomous IT operations but hesitate to let AI act alone Companies want autonomous IT operations but hesitate to let AI act alone

Yet 77 percent say their own organization hesitates to let AI make an operational decision without a human approving it.

Only 41 percent say their IT environment is prepared for autonomous operations, and 19 percent of their IT operations are automated.

Most respondents say consolidating tools would cut operational friction, yet most also say sprawl has increased their need to integrate systems.

The service desk is already changingAlmost all respondents expect AI to change what frontline IT and service desk teams can do within two years.

A third of companies say their IT team is already extremely effective at using AI to catch and fix problems before employees notice.

7 часов назад @ helpnetsecurity.com
Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls
Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls

The FBI and French law enforcement have seized two websites that sold hacked and stolen sexually explicit images and videos of young women and girls, and arrested their suspected administrator in northern France.

Although the site posted warnings against child sexual abuse material (CSAM), investigators found that it also sold sexually explicit images and videos of children.

The suspected administrator, a 25-year-old man, and his 21-year-old brother were arrested by French police during the operation.

French authorities put the number of victims at more than 17,000 women worldwide.

Both the FBI and French authorities have asked victims of the platform to come forward.

22 часа назад @ helpnetsecurity.com
YouTubers targeted with fake sponsorships and “channel verification” phishing
YouTubers targeted with fake sponsorships and “channel verification” phishing YouTubers targeted with fake sponsorships and “channel verification” phishing

Scammers are going after YouTube creators’ Google accounts by posing as a brand looking for sponsorship partners.

Spotting the scamThe name, look and domains hosting the fake collaboration platform are changed regularly.

How creators can protect themselvesESET’s advice to creators who receive a sponsorship offer is to verify it independently before going any further.

“Then inspect the permissions list – for example, a site that only needs to verify your channel has no reason to manage it.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats.

22 часа назад @ helpnetsecurity.com
Anthropic’s new budget model gets much better at ignoring hidden commands
Anthropic’s new budget model gets much better at ignoring hidden commands Anthropic’s new budget model gets much better at ignoring hidden commands

Anthropic’s Claude Haiku 5.5 model, designed for quick, repetitive workloads and speed-sensitive tasks, is now better at finding vulnerabilities and writing exploits than its predecessor.

In a test involving known flaws in Chrome’s V8 engine, Haiku 5.5 achieved arbitrary code execution in four of 410 runs.

Claude Haiku 5.5 outperformed Claude Sonnet 5 on ExploitGym but remained well below theother Claude 5.5-family models.

Anthropic says Haiku 5.5 is its most resistant Haiku model yet to prompt injection.

Anthropic is halving the price of cache reads for Sonnet 5.5, reducing the cost of reusing previously processed input.

1 day назад @ helpnetsecurity.com
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers

Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs.

When a vulnerable server turned up, an exploit server sent it a crafted POST request instructing it to download a file from the C2 server.

The four numbers make up the IPv4 address of the current C2 server.

In one earlier version of the poem, the words “driver,” “diode,” “decryption” and “string” translated to 92, 119, 165 and 74, which gave the C2 address 92.119.165.74.

Black Lotus Labs says it has blocked traffic to and from the PoeLLM C2 servers and will keep monitoring for new traffic.

1 day, 1 hour назад @ helpnetsecurity.com
GitHub adds AI to catch passwords before a code push
GitHub adds AI to catch passwords before a code push GitHub adds AI to catch passwords before a code push

GitHub has announced an AI detector, developed with Microsoft Applied Sciences, to help prevent developers from uploading passwords and other credentials to code repositories.

The ModernBERT-based classifier will expand GitHub’s push protection, which checks code for secrets and can block a push before a credential enters repository history.

GitHub says the classifier evaluates batches of possible secrets in under two milliseconds and could more than double the number of secrets that push protection can prevent.

Manual revocation takes around 40 days on average, with roughly one in five exposed secrets taking more than 90 days.

GitHub plans to make it available later in October to organizat…

1 day, 2 hours назад @ helpnetsecurity.com
What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor
What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor

ESET researchers traced almost two years of changes to MATCHBOIL, a downloader that the Russia-aligned group UAC-0099 uses to plant a second program on Windows machines in Ukraine.

The program MATCHBOIL installs is a spying tool, and the access it creates may be useful to other groups.

What MATCHBOIL installs“We have seen in ESET telemetry that MATCHBOIL downloads a payload known as MATCHWOK, a C# backdoor with capabilities for espionage on the victim’s machine.

The malware fingerprints the machine using its CPU ID and BIOS serial number, then makes three HTTPS requests to the group’s server.

By late 2025 MATCHBOIL ran on a two-minute timer, so a failed first contact with the server no long…

1 day, 2 hours назад @ helpnetsecurity.com
Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims
Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims

The owner of Florida-based ransomware remediation company MonsterCloud has been charged with fraud for allegedly paying ransomware gangs behind his clients’ backs and billing them far more than the ransom.

According to the indictment, Pinhasi told prospective clients that MonsterCloud offered a principled alternative to paying ransomware attackers.

“Pinhasi typically charged MonsterCloud’s clients a fee that was substantially higher than the ransom that MonsterCloud secretly paid.

“Monstercloud doesn’t hold any Proprietary technology [to] decrypt the ransomware data,” he allegedly replied.

Pinhasi is charged with two counts of wire fraud and one count of wire fraud conspiracy.

1 day, 3 hours назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 1 day назад
How Technology Empowers—and Imperils—Dictators
How Technology Empowers—and Imperils—Dictators How Technology Empowers—and Imperils—Dictators

This essay was written with Seva Gunitsky, and originally appeared in Foreign Affairs.

Two weeks after Moscow’s full-scale invasion of Ukraine in March 2022, the Russian TV Channel One editor Marina Ovsyannikova burst onto the set of the evening newscast. She held up a hand-drawn sign behind the anchor’s head that read: “Stop the war. Don’t believe propaganda. They’re lying to you!” She shouted, “No to war!” until she was dragged away.

No one has protested the war on Russian television since then, partly as a result of tighter security and a general climate of fear. But in October 2024, Margarita Simonyan, one of Russia’s chief propagandists, gave another explanation. A growing number of th…

1 day назад @ schneier.com
Apple’s Verified Photography System
Apple’s Verified Photography System Apple’s Verified Photography System

Apple just released a system called “Reference Image.” It can verify the image is exactly as taken by an iPhone—new models only—without tying it to a specific iPhone or photographer. It can also verify that multiple images came from the same iPhone.

Other industry solutions require a photographer or institution to vouch for an image using their own credentials. We are concerned this puts some photographers, such as those operating in conflict zones, in a difficult position; it should not be necessary to forgo anonymity in order to prove image authenticity. We built Apple Reference Image to avoid using an explicit, public credential for photographers, and to avoid even implicit public associ…

2 days назад @ schneier.com
Possible Vulnerability in Apple’s Automatic Reboot
Possible Vulnerability in Apple’s Automatic Reboot Possible Vulnerability in Apple’s Automatic Reboot

404Media is reporting (alternate link) that a cyber-weapons arms manufacturer is exploiting a vulnerability in iOS to bypass its automatic reboot security feature. This is the feature that automatically puts an iPhone into a more secure state if it hasn’t been used for 72 hours.

The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, a popular tool sold to law enforcement agencies that allows them to unlock and access data stored in iPhones and Android smartphones. Magnet has developed a new device called GrayKey Preserve and a feature for its regular GrayKey devices called Evidence Preservation Mode, according to the video...

3 days назад @ schneier.com
Another Historic Cipher Falls to AI
Another Historic Cipher Falls to AI Another Historic Cipher Falls to AI

This one is from 1809, written by Napoleon’s nephew.

4 days назад @ schneier.com
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing

The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

6 days, 14 hours назад @ schneier.com
Unidentified Flock Cameras in Florida
Unidentified Flock Cameras in Florida Unidentified Flock Cameras in Florida

St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted.

I am reminded of the decade-old story of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown.

My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case is more likely some local government entity that didn’t bother getting approval. Were I a foreign actor, I would rather hack the existing Flock network—like Israel ...

6 days, 20 hours назад @ schneier.com
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools How American Political Campaigns Are Using AI—and What They’re Spending on the Tools

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them.

Candidates’, parties’ and committees’ spending reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet about how they are using the technology in their own campaigns. It’s a sensitive issue that we have been tracking closely since we started writing our book, Rewiring Democracy...

1 week назад @ schneier.com
Connected Cars Are a Surveillance Platform
Connected Cars Are a Surveillance Platform Connected Cars Are a Surveillance Platform

Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers:

To determine this, CR dug through thousands of pages of automakers’ privacy policies and asked questions of 15 different automakers­BMW, Ford, General Motors, Honda, Hyundai, Kia, Mazda, Mercedes-Benz, Mitsubishi, Nissan, Stellantis, Subaru, Tesla, Toyota, and Volkswagen. We also reviewed corporate, regulatory, and legal filings from data brokers operating in the “insurtech” industry­the technology companies and data brokers that help insurance companies set their rates. And we spoke to several car privacy experts, who, at industry conferences and in market re…

1 week, 1 day назад @ schneier.com
I Want Better Reporting on AI Genie Behavior
I Want Better Reporting on AI Genie Behavior I Want Better Reporting on AI Genie Behavior

AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening.

I wish the popular press would report on this better. I don’t like the “going rogue” framing because it deflects the responsibility from the prompters—often the AI companies themselves. And now, pretty much anything off-script is being called “hacking.”

Take, for example, the recent stories of one of OpenAI’s models hacking into government systems. First, ...

1 week, 2 days назад @ schneier.com
Using Device Linking to Eavesdrop on WhatsApp and Signal
Using Device Linking to Eavesdrop on WhatsApp and Signal Using Device Linking to Eavesdrop on WhatsApp and Signal

Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability:

Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers.

Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account.

Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them.

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sancti…

1 week, 3 days назад @ schneier.com
New Attack Against RSA
New Attack Against RSA New Attack Against RSA

ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.

First, this attack isn’t new. The original research is from 2007. What is new is the implementation.

Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.

Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice.

Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with …

1 week, 4 days назад @ schneier.com
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

I feel like someone who reads this blog will want to go to this:

Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life.

[…]

During the guided squid dissection, each family will work together to examine a squid up close, exploring its organs, structures, and specialized features. The experience provides a memorable opportunity for children and adults to see firsthand how the anatomy of a squid helps it survive in it…

1 week, 6 days назад @ schneier.com
On Anthropic’s AI Misuse Report
On Anthropic’s AI Misuse Report On Anthropic’s AI Misuse Report

Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.

A few of the highlights: AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.

The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations.

...

2 weeks назад @ schneier.com
Malicious npm Packages That Evade Defenses
Malicious npm Packages That Evade Defenses Malicious npm Packages That Evade Defenses

This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

2 weeks, 1 day назад @ schneier.com
Research on Models Engaging in Genie-Like Behavior
Research on Models Engaging in Genie-Like Behavior Research on Models Engaging in Genie-Like Behavior

New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.”

Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be …

2 weeks, 2 days назад @ schneier.com
Krebs On Security
последний пост 1 day, 21 hours назад
ShinyHunters Extorted Boeing Spin-off Prior to Arrests
ShinyHunters Extorted Boeing Spin-off Prior to Arrests ShinyHunters Extorted Boeing Spin-off Prior to Arrests

The Dutch daily RTL reported on Sept. 29 that investigators suspect Van der Stap tried to orchestrate at least two murders.

According to RTL, the murders were allegedly to be committed abroad, and there are indications Van der Stap gave the order for these attacks.

In an interview with KrebsOnSecurity on September 9, Van der Stap described his new role as “offensive security lead” at the Dutch cybersecurity company Neo Security, saying the job involved probing client networks for security vulnerabilities.

Korper said Dutch forensic investigators visited his office on September 15, the night Van der ⁠Stap was arrested in a dramatic police raid that reportedly involved flash bang grenades.

“Y…

1 day, 21 hours назад @ krebsonsecurity.com
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.

Van der Stap is currently employed as offensive security lead at the Dutch company Neo Security, which did not respond to requests for comment.

But not long after that interview, the Dutch hacker abruptly stopped replying to messages.

One source said a colleague of theirs personally witnessed Dutch authorities carting items out of Van der Stap’s residence.

Speaking with reporters from Bloomberg in 2024, Van der Stap said that singular focus in turn fueled his desire to carry out cyberattacks.

1 week, 3 days назад @ krebsonsecurity.com
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.

Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data.

Less than a month later, Wagenius was arrested and charged in two separate federal indictments, and soon pleaded guilty to all counts in both cases.

In 2019, Schuchm…

1 week, 6 days назад @ krebsonsecurity.com
Data Broker Radaris Loses Domains in Privacy Fight
Data Broker Radaris Loses Domains in Privacy Fight Data Broker Radaris Loses Domains in Privacy Fight

In February 2024, Radaris was sued by Atlas Data Privacy Corp, a company that has been pursuing data brokers alleged to be violating a New Jersey statute called Daniel’s Law.

KrebsOnSecurity doubled down and showed how the Lubarsky brothers built and operated Radaris and other data broker companies using a fictitious CEO’s name.

All told, the New Jersey court has so far transferred 14 domain names from the Radaris family of companies to Atlas.

Sherman said federal lawmakers have long faced intense lobbying by the technology industry against more restrictive U.S. data privacy laws, but that many powerful industries are now working against passing comprehensive data privacy legislation.

The l…

3 weeks, 1 day назад @ krebsonsecurity.com
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Plugs Nearly 1,000 Security Holes Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.

This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities.

Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10.

And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.

Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear…

1 month назад @ krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards.

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.

Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s ide…

1 month, 1 week назад @ krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

1 month, 1 week назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

1 month, 3 weeks назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

1 month, 4 weeks назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

2 months назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

2 months, 1 week назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

2 months, 2 weeks назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

2 months, 3 weeks назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

2 months, 3 weeks назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

3 months назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 1 day, 12 hours назад
Smashing Security podcast #487: Clippy’s crypto comeback
Smashing Security podcast #487: Clippy’s crypto comeback Smashing Security podcast #487: Clippy’s crypto comeback

But do you actually know whether both of them can do the job?

Now, I don't know how good a swimmer you are, Danny.

I don't know about you, but I'm having 3 or 4 calls a day from an unknown number.

And I would imagine a company like Hack The Box has got great visibility as to what is actually going on out there.

And so I think that's the unique part here is it truly does have a pressure-tested element to it.

1 day, 12 hours назад @ grahamcluley.com
N0n ransomware: what you need to know
N0n ransomware: what you need to know

N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra blog.

6 days, 3 hours назад @ fortra.com
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader

The FBI has a very simple message for the ShinyHunters gang: give yourselves up.

The FBI describes the man arrested in Amsterdam as "one of the alleged leaders of ShinyHunters", although Dutch police say only that he played a role.

The warning to remaining members of ShinyHunters follows particularly embarrassing episode for the FBI, which recently confirmed it had had its job application portal compromised by the gang.

According to ShinyHunters, it gained access to the FBI's data by exploiting a recently-patched flaw (CVE-2026-35273) in Oracle PeopleSoft PeopleTools.

The truth is that the arrest came a week or so before the compromise of the FBI became headline news.

1 week, 1 day назад @ bitdefender.com
ShinyHunters suspect arrested, and is now investigated over alleged murder plots
ShinyHunters suspect arrested, and is now investigated over alleged murder plots ShinyHunters suspect arrested, and is now investigated over alleged murder plots

An alleged key figure in the ShinyHunters cybercrime group has been arrested in the Netherlands, and - in a grotesque turn - the 24-year-old suspect is also being investigated for attempting to arrange two murders.

Although the authorities are declining to name the individual, celebrated cybersecurity blogger Brian Krebs has identified him as Pepijn van der Stap, a convicted hacker.

Van der Stap was released from prison in December last year, and has since been working as a penetration tester at Amsterdam-based Neo Security.

Notably, Van der Stap appears to claim on his personal website that he is a reformed character.

That hasn't stopped FBI Director Kash Patel from describing the arrested…

1 week, 1 day назад @ bitdefender.com
Pentagon personnel database breach exposes personal data of millions
Pentagon personnel database breach exposes personal data of millions Pentagon personnel database breach exposes personal data of millions

The unencrypted files contained Social Security numbers, names, birth dates, contact details, and other military personnel data including - in some cases - details of the jobs individuals held.

Breaches like this matter because the combination of Social Security numbers, names, and dates of birth make up the bread and butter of any self-respecting fraudster.

Personnel data, of course, has also been a target before.

The news of the Pentagon's latest data breach comes as the FBI warns its own employees about a separate breach of its FBIJobs.gov portal.

The ShinyHunters hacking group has claimed credit for the hack and threatened to publish staff details including... you guessed it... Social S…

1 week, 2 days назад @ bitdefender.com
Ukrainian ransomware developer jailed for nearly 13 years
Ukrainian ransomware developer jailed for nearly 13 years Ukrainian ransomware developer jailed for nearly 13 years

A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world.

The 52-year-old man, who according to local media reports had been living in the Basel-Landschaft region but has not been named, found by the court to be the lead developer of the LockerGoga, MegaCortex, and Nefilim families of ransomware.

In all, prosecutors claimed that some 100 million Swiss Francs (US $123 million) worth of damage was caused by the ransomware attacks.

Ukrainian national Tymoshchuk allegedly released new strains of his ransomware whenever old ones had been decrypted.

In…

2 weeks назад @ bitdefender.com
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras

Smashing Security, episode 486, Vibe-Coded Shops and Hackable Flock Cameras, with Graham Cluley and special guest Dave Bittner.

I will say I did not go gaga for La La the way many other people did.

Anyway, if any of you are still listening, I love La La Land.

This La La Land lunatic has watched the movie with his pause button.

This was definitely not created — if you haven't seen La La Land, go watch La La Land for goodness' sake.

2 weeks, 1 day назад @ grahamcluley.com
US Coast Guard and FBI board oil tanker to investigate cyber attack
US Coast Guard and FBI board oil tanker to investigate cyber attack US Coast Guard and FBI board oil tanker to investigate cyber attack

An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.

The VL Prosperity - a Liberian-flagged supertanker carrying roughly 2.3 million barrels of crude oil - apparently suffered a cyber attack while en route from Egypt's Sidi Kerir oil terminal to Galveston, Texas.

Two weeks later, a specialised team from the FBI and US Coast Guard boarded the vessel for four days, investigating the problem and helping the crew eradicate the threat from its IT and OT systems.

According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromised by a f…

3 weeks назад @ bitdefender.com
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Smashing Security podcast #485: These researchers got drunk to hack an LG TV Smashing Security podcast #485: These researchers got drunk to hack an LG TV

That's really, really cool.

And I'm going to be getting really, really sozzled by looking at the security of LG smart TVs.

So it's really, really compelling.

When we started off on the journey of building this AI pen testing approach, there was a lot of scepticism.

And listeners, you can learn more about Intruder or even start your own AI pen test in minutes.

3 weeks, 1 day назад @ grahamcluley.com
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store.

According to Carter's own plea agreement, the scam ran from May 2018 to November 2019 and involved at least three co-conspirators alongside Carter.

Carter would use his privileged store access to move a victim's number onto a SIM card under the control of himself or an accomplice.

In one incident in May 2018, described in Carter's plea agreement, the store employee swapped a victim's number onto an Alcatel handset while working his shift in Portland.

In December 2018, Carter successfully hijacked the number of a victim known as "S.Q.T" in Portland, and this time their account was successfully drained of …

3 weeks, 3 days назад @ bitdefender.com
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars ‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.

Because it might just be that you draw the attention of the authorities.

Back in October 2024, we wrote about how he was arrested after allegedly tricking a single victim out of US $230 million worth of Bitcoin while posing as Google Support.

The party days are over now for Lam, who faces up to 20 years in prison when he is eventually sentenced.

You money may be a lot more safely stored in a hardware cold wallet.

4 weeks назад @ bitdefender.com
Smashing Security podcast #484: How websites are tracking you with silence
Smashing Security podcast #484: How websites are tracking you with silence Smashing Security podcast #484: How websites are tracking you with silence

Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.

I get by in the world, but I don't think you need me for listening for something really, really far away.

I don't know what the difference — I mean, now we get to see, I've opened a can of worms here.

I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human.

And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.

4 weeks, 1 day назад @ grahamcluley.com
CRPx0 ransomware: what you need to know
CRPx0 ransomware: what you need to know

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

1 month назад @ fortra.com
The US military just turned off ad tracking on its phones. Maybe you should too
The US military just turned off ad tracking on its phones. Maybe you should too The US military just turned off ad tracking on its phones. Maybe you should too

Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target American forces in the Middle East.

Every smartphone carries a mobile advertising ID - Apple calls its version the IDFA, and Google calls its the GAID.

Back in April, US Central Command reportedly warned of "multiple threat reports concerning adversary exploitation of commercial location data."

Recent versions should let you delete your advertising ID entirely.

If it's good enough for the US military - maybe it should be good enough for you too.

1 month назад @ bitdefender.com
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo's own identity system, Lenovo ID.

So, anyone wanting to access your Dropbox account just had to sign up for a Lenovo account using your email address.

Don't just turn it on for your Dropbox account, enable it everywhere it is made available.

This hack of 5000 Dropbox accounts was not sophisticated.

One can only be grateful that the problem was discovered after only 5000 Dropbox accounts were accessed.

1 month назад @ bitdefender.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 20 часов назад
Как найти пропавшего питомца с помощью технологий | Блог Касперского
Как найти пропавшего питомца с помощью технологий | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 61f641b9443f60bfa61c035e9925aff2Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-10-08T19:00:43+03:00Config id: 335Faithfully yours, nginx.

20 часов назад @ kaspersky.ru
Токеномика ИБ: атаки Denial of Wallet и стоимость работы SOC | Блог Касперского
Токеномика ИБ: атаки Denial of Wallet и стоимость работы SOC | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: db7c9e9b3ec5fc4fb9e02c8670f482a9Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-10-07T23:00:38+03:00Config id: 335Faithfully yours, nginx.

1 day, 16 hours назад @ kaspersky.ru
GTA 6 до релиза: фейковые утечки, ранний доступ и мошенничество | Блог Касперского
GTA 6 до релиза: фейковые утечки, ранний доступ и мошенничество | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 057a7a4758cd6ae7dfaab62417ac8d97Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-10-02T21:00:25+03:00Config id: 335Faithfully yours, nginx.

6 days, 18 hours назад @ kaspersky.ru
Как закрыть 110 уязвимостей в Google Pixel | Блог Касперского
Как закрыть 110 уязвимостей в Google Pixel | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8ea67ee2a3dd4315782e49963c8d5485Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-30T17:00:35+03:00Config id: 334Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
Как сканер уязвимостей создает иллюзию защиты | Блог Касперского
Как сканер уязвимостей создает иллюзию защиты | Блог Касперского Как сканер уязвимостей создает иллюзию защиты | Блог Касперского

Эти процессы могут тянуться неделями, а тем временем в инфраструктуру легко может попасть злоумышленник.

Где теряется времяПервое промедление может произойти сразу после появления информации об уязвимости в базах данных.

Рецепт управления уязвимостямиЧтобы у злоумышленников было как можно меньше поводов заглянуть к вам в инфраструктуру, важно убедиться, что в организации четко выстроены четыре основных процесса.

ПриоритизацияПри анализе уязвимости не стоит ориентироваться только на оценку из публичного каталога, например NVD, — она может существенно расходиться с реальным ущербом от эксплуатации бреши.

Например, один и тот же дефект в сервере, который находится в изолированном сегменте, и в…

1 week, 2 days назад @ kaspersky.ru
Бесплатный курс «Введение в кибербезопасность» для студентов вузов от экспертов «Лаборатории Касперского» | Блог Касперского
Бесплатный курс «Введение в кибербезопасность» для студентов вузов от экспертов «Лаборатории Касперского» | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7dfac78cb3fca5a112c9b371cb1af0ecServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-29T14:00:43+03:00Config id: 307Faithfully yours, nginx.

1 week, 4 days назад @ kaspersky.ru
CVE-2026-87902: критическая уязвимость в WordPress
CVE-2026-87902: критическая уязвимость в WordPress

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 3ba3f53e4698eed730b59fdbb57f2dc7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-25T19:00:33+03:00Config id: 307Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: cdfce2802c5089c2e8d266eed059c5ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-23T18:00:08+03:00Config id: 307Faithfully yours, nginx.

2 weeks, 1 day назад @ kaspersky.ru
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8bdccf89e0ff9374b4a240e13e1d1e5dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-22T14:00:25+03:00Config id: 307Faithfully yours, nginx.

2 weeks, 3 days назад @ kaspersky.ru
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: afb32d9b2ad2a9d051087c355f39881eServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-18T19:00:38+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: c7185cbdbdeda88817088ebb8613e249Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-17T16:00:24+03:00Config id: 305Faithfully yours, nginx.

3 weeks назад @ kaspersky.ru
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64b9740d8f9a94da6c64f21f2aeee15dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-16T19:00:10+03:00Config id: 305Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7e59b8e02f76cd9405fa38b4fdc32a36Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-15T11:00:04+03:00Config id: 305Faithfully yours, nginx.

3 weeks, 4 days назад @ kaspersky.ru
Как полностью удалить приложения с Mac и освободить память | Блог Касперского
Как полностью удалить приложения с Mac и освободить память | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a6459fd9158393152b55dc4e20e24551Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T15:00:13+03:00Config id: 305Faithfully yours, nginx.

1 month назад @ kaspersky.ru
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4a93349074c8b67d52892db5d9a65f6cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T00:00:19+03:00Config id: 305Faithfully yours, nginx.

1 month назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 20 часов назад
Chasing AMMYY at Splunk .conf
Chasing AMMYY at Splunk .conf Chasing AMMYY at Splunk .conf

The Splunk .conf network brought a new detection that we hadn’t seen before: Flawed AMMYY.

There is also a Remote Access Tool (RAT) called Flawed AMMYY that was developed from leaked AMMYY source code, and is directly used as malware.

One of the key value propositions of EVE is that it can use granular session fingerprinting to differentiate between similar but distinct applications like AMMYY and Flawed AMMYY.

Let’s dig into the events we saw for Flawed AMMYY and some of the details that EVE had to look at.

Our EVE detections for Flawed AMMYY came in pairs with identical timestamps, as seen above, all from a single IP.

20 часов назад @ blogs.cisco.com
Admin in the Loop: Firewalls and the Agentic SOC
Admin in the Loop: Firewalls and the Agentic SOC Admin in the Loop: Firewalls and the Agentic SOC

The event Network Operations Center (NOC) managed the venue network, providing our SOC firewalls with dedicated SPAN feeds directly from their core switches.

Inside Cisco Cloud Control, that story comes together in Unified Events.

While Splunk drives active investigations in the SOC, administrators maintain firewall health directly within Cloud Control.

The Horizon: Cisco Cloud Control & AI CanvasSecurity is now natively built into Cisco Cloud Control, the unified operations platform that brings Networking, Security, Observability, and Cloud into one consistent environment.

Without replacing individual product controllers, Cisco Cloud Control unifies inventory, topology, actions, identity, …

20 часов назад @ blogs.cisco.com
The Zero-Day Blind Spot: Why Your Agentic SOC needs Retrospective Packet Replay
The Zero-Day Blind Spot: Why Your Agentic SOC needs Retrospective Packet Replay The Zero-Day Blind Spot: Why Your Agentic SOC needs Retrospective Packet Replay

However, assessing whether a zero-day vulnerability was exploited in the past essentially involves going back in time.

Relying on standard logs or “Conditional / Selective PCAP” systems during a zero-day investigation leaves the Security Operations Center (SOC) team blind.

There is also a secondary benefit: if a breach occurred using an newly disclosed zero-day vulnerability, the attacker is likely to have been very sophisticated.

Replay The Relevant Historical Traffic Against The New Intrusion RulesOn the Firewall Threat Defense (FTD), we configured a dedicated interface for the Endace traffic replays.

Rapid retrospective packet replay transforms zero-day triage by delivering direct forens…

20 часов назад @ blogs.cisco.com
One Cisco in Action: Inside the Agentic SOC at .conf26
One Cisco in Action: Inside the Agentic SOC at .conf26 One Cisco in Action: Inside the Agentic SOC at .conf26

The .conf26 Agentic SOC was not a simulated demo or a scripted lab.

Powered by the Cisco Cloud Control management platform, Splunk Enterprise Security (ES), Cisco Security telemetry, Cisco Talos Intelligence, and Endace continuous packet capture, our joint team of Cisco, Splunk, Endace, and Jamf engineers demonstrated what multi-agent threat detection, investigation, and response (TDIR) delivers at enterprise scale.

Watch it come to life in David Bombal’s Interview at the Agentic SOC.

“The Agentic SOC is not about replacing human defenders with autonomous black boxes.

AcknowledgementsOur thanks to the engineers who built the Agentic SOC and the Humans who provided decision making expertise.

20 часов назад @ blogs.cisco.com
Splunk .conf26: Tracking the Triage Agent in the Agentic SOC
Splunk .conf26: Tracking the Triage Agent in the Agentic SOC Splunk .conf26: Tracking the Triage Agent in the Agentic SOC

Splunk .conf26 gave us the opportunity to operate a live Agentic Security Operations Center (SOC) in the middle of the Splunk community.

Splunk ES as the SOC data platformSplunk ES served as the primary analyst workspace and evidence system for the SOC.

Building the Triage Agent Dashboard in an AfternoonOnce the data was flowing and the agent was active, we built an operations dashboard in an afternoon.

The team preserved a path from telemetry to finding, from finding to agent analysis, and from agent analysis to an analyst decision.

Dashboard SnapshotThe following values are a snapshot from the displayed Triage Agent operations dashboard and should be read as event-environment observations…

20 часов назад @ blogs.cisco.com
Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era
Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era

The Cisco Secure Firewall 200 Series brings enterprise-grade protection and connectivity to distributed branches in a compact form factor.

The Encrypted Visibility Engine (EVE) uses AI and machine learning to analyze encrypted traffic, including TLS 1.3, without requiring full decryption.

The Secure Firewall 220 model delivers up to 1.5 Gbps of throughput with next-generation firewall capabilities enabled in a compact form factor for smaller branches.

The Secure Firewall 200 Series helps meet these demands with intelligent threat protection, encrypted traffic visibility, resilient connectivity, and centralized management.

Explore the Secure Firewall 200 Series to build a more resilient, man…

1 week, 3 days назад @ blogs.cisco.com
From Love Letters to AI Agents: Cybersecurity’s Evolution
From Love Letters to AI Agents: Cybersecurity’s Evolution From Love Letters to AI Agents: Cybersecurity’s Evolution

Architecting the Future: The Four Pillars of Agentic SecuritySecuring agentic AI requires a new strategic framework.

Pillar 2: Core ProtectionDelivered by: Cisco AI DefenseCisco AI Defense provides specialized protection for the AI models themselves and their operational environment.

AI Inventory & Validation: This solution catalogs all deployed AI models and continuously validates their integrity against supply chain risks.

Pillar 4: ObservabilityDelivered by: SplunkSplunk provides the unified intelligence platform required to monitor and respond to agentic AI at scale.

Splunk ingests logs, events, and telemetry from Duo, Secure Access, AI Defense, and other infrastructure points, creating…

2 weeks, 3 days назад @ blogs.cisco.com
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco was proud to return to Black Hat USA as the Official Security Cloud Provider and the longest-standing partner of the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC).

In 2026, we completed our 11th year helping protect the Black Hat network, working side by side with the Black Hat NOC leaders and official technology partners: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.

For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry and workflows across Cisco Security, Splunk Security, and partner-provided network and security controls.

The same signal may need to be understood by Cisco, Splunk, Black Hat leadership, and partner tea…

1 month назад @ blogs.cisco.com
Thrown into the SOC: A Black Hat First-Timer’s Story
Thrown into the SOC: A Black Hat First-Timer’s Story Thrown into the SOC: A Black Hat First-Timer’s Story

I did not walk into Black Hat with years of incident-response experience or an encyclopedic knowledge of threat actors.

The first time I walked into the Black Hat NOC, where the SOC team was operating, was a few days before the event began.

I was surrounded by people with years—sometimes decades—of experience, many of whom had supported Black Hat for years.

Check out the other blogs from our team at Black Hat USA 2026.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

1 month назад @ blogs.cisco.com
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes

To handle this task, Cisco and Black Hat deployed bespoke ThousandEyes agents to monitor the wireless solution.

Our thanks to the Arista Networks team in the Black Hat NOC for their partnership throughout the week.

You can read the other blogs from our colleagues at Black Hat USA.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

For more information, please visit the Black Hat website.

1 month назад @ blogs.cisco.com
Distributed Latency Monitoring at Black Hat
Distributed Latency Monitoring at Black Hat Distributed Latency Monitoring at Black Hat

With Matthew Bair2026 marks the fourth consecutive year we’ve used ThousandEyes to monitor the Black Hat USA network for latency.

As our latency monitoring mesh has expanded to cover more and more of the conference, we’ve also begun supplementing our ThousandEyes monitoring with on-demand Linux commands to track latency across different protocols.

The Key ThousandEyes TestsThe automated ThousandEyes tests that inform our dashboards include HTTPS connectivity tests, the monitoring of cloud services, agent to agent tests, internal and external DNS resolution, and even file downloads.

On-Demand Latency Tests from the Agent MeshPing and traceroute are the go-tos for anyone who wants to do a qui…

1 month назад @ blogs.cisco.com
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

While developing a detection for Cisco Secure Network Analytics (SNA), I used the Splunk Detection Editor (Alpha) to bring much of that workflow into one place.

Instead of treating every observation as an incident, detections can create risk events associated with entities such as systems or users.

Developing the detection in one workspaceThe Detection Editor provides a workspace for building the search while configuring the other parts of the detection.

Risk events for the same entity need to use a consistent risk object so Splunk Enterprise Security can associate them correctly.

Splunk defines the risk object, its type, and its score as key parts of a risk event.

1 month назад @ blogs.cisco.com
Black Hat USA 2026: Safeguarding DNS with Secure Access
Black Hat USA 2026: Safeguarding DNS with Secure Access Black Hat USA 2026: Safeguarding DNS with Secure Access

DNS continues to provide one of the clearest windows into activity across the Black Hat network.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking.

Its 4.42 million blocks represented 79.3% of every blocked DNS request .. Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and mo…

1 month назад @ blogs.cisco.com
Frontier AI just raised the stakes, and the old playbook won’t hold up
Frontier AI just raised the stakes, and the old playbook won’t hold up Frontier AI just raised the stakes, and the old playbook won’t hold up

Project Glasswing and Frontier models just made that truth louder.

Frontier models are about to pour gasoline on that fire; the fundamentals matter more than ever.

Cisco ran its own experiment leveraging a variety of frontier models.

Foundry Security Spec: a model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

Foundry-Security-Speca model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

1 month назад @ blogs.cisco.com
Crypto Agility: Why PQC Is Not a One-Time Upgrade
Crypto Agility: Why PQC Is Not a One-Time Upgrade Crypto Agility: Why PQC Is Not a One-Time Upgrade

That requires crypto agility.

Why long-lived networks need crypto agilityThink about designing a building before all of its future electrical requirements are known.

Crypto agility is about adopting the best defenses available today while preserving the ability to adopt better ones tomorrow.

That is why crypto agility needs to be designed into the network we invest in today.

Common questions about PQC and crypto agilityWhat is crypto agility?

1 month назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 14 часов назад
Post-quantum authentication: Why organizations should start testing certificate ecosystems now
Post-quantum authentication: Why organizations should start testing certificate ecosystems now Post-quantum authentication: Why organizations should start testing certificate ecosystems now

Early testing can surface compatibility and process gaps before post-quantum authentication is required at scale.

As the industry moves toward post-quantum authentication, security teams will need greater visibility into those dependencies.

Why organizations should begin preparing nowThe transition to post-quantum authentication is unlikely to be a single technology upgrade.

Testing the future certificate ecosystemTo help the ecosystem gain practical experience with post-quantum authentication, Microsoft launched the PQC TLS Pilot Program on August 27, 2026.

What organizations can do todayOrganizations do not need to wait for broad industry adoption to begin preparing for post-quantum authe…

14 часов назад @ microsoft.com
3 lessons from frontier AI vulnerability research
3 lessons from frontier AI vulnerability research 3 lessons from frontier AI vulnerability research

The mission of Microsoft Security’s Frontier Offensive Research & Generative Exploitation (FORGE) Lab is to advance the frontier of autonomous security engineering.

We’re building a team that enables AI-native vulnerability research at Microsoft, pushing the boundaries of finding and fixing zero-day vulnerabilities.

Three lessons follow, each marking a shift in how we approach vulnerability research:From frontier capability to scale.

Here, we focus on what those experiences teach us about operating vulnerability research at scale—across Windows and open-source projects.

FORGE has submitted nine Linux findings with internally assessed common vulnerability scoring system (CVSS) scores above 7…

1 day, 19 hours назад @ microsoft.com
CISO perspectives on managing vulnerability risks in the age of AI
CISO perspectives on managing vulnerability risks in the age of AI CISO perspectives on managing vulnerability risks in the age of AI

How do frontier AI models change vulnerability management for CISOs?

We use a ‘harness’ layer around AI models in vulnerability scanning for better results.

They should do so without delay, rather than wait for access to frontier AI models.

Extensive guidance can be found in a new Microsoft Security Exposure Management page with capabilities customers can use to act.

Final notesThe advent of frontier AI models to discover and exploit vulnerabilities creates both risks and opportunities.

2 days, 19 hours назад @ microsoft.com
CISO perspectives on managing vulnerability risks in the age of AI
CISO perspectives on managing vulnerability risks in the age of AI CISO perspectives on managing vulnerability risks in the age of AI

How do frontier AI models change vulnerability management for CISOs?

We use a ‘harness’ layer around AI models in vulnerability scanning for better results.

They should do so without delay, rather than wait for access to frontier AI models.

Extensive guidance can be found in a new Microsoft Security Exposure Management page with capabilities customers can use to act.

Final notesThe advent of frontier AI models to discover and exploit vulnerabilities creates both risks and opportunities.

2 days, 19 hours назад @ microsoft.com
Preparing governments for an era of interconnected cyber risk
Preparing governments for an era of interconnected cyber risk Preparing governments for an era of interconnected cyber risk

Trusted channels can enable this exchange among government agencies, law enforcement, critical infrastructure operators, technology providers, and international partners while respecting legal and privacy requirements.

As cyber incidents cross organizational and national boundaries, resilience depends not only on technical preparedness, but on whether institutions can coordinate effectively under pressure.

In an era of AI-enabled and increasingly interconnected cyber threats, resilience is no longer simply about recovering from an attack.

It is about preparing for a world in which cyber incidents move faster, spread further, and affect more organizations than ever before.

Governments best p…

1 week назад @ blogs.microsoft.com
Insights from the 2026 Microsoft Digital Defense Report
Insights from the 2026 Microsoft Digital Defense Report Insights from the 2026 Microsoft Digital Defense Report

Every year, the Microsoft Digital Defense Report gives us an opportunity to step back from individual threats and look broadly at what Microsoft’s security and threat intelligence teams are seeing.

These developments can change the speed and scale of security activity even as the underlying security fundamentals remain familiar.

People, identities, exposed systems, and trusted access continue to feature prominently in the threat activity Microsoft observes.

The 2026 Microsoft Digital Defense Report looks across the threat landscape, cybercrime, resilience, and the relationships among technologies, identities, systems, and people.

Read the 2026 Digital Defense Report for the full findings, d…

1 week назад @ microsoft.com
​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 ​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026

Join fellow customers and Microsoft Security leaders for a night designed to make meaningful connections.

Partners and the Microsoft Intelligent Security AssociationMicrosoft Intelligent Security Association (MISA) members have a full week ahead at Microsoft Ignite.

Sessions to watch forWhen AI acts, security has to answer: Microsoft Security for AI , the platform view of securing agentic AI.

Strengthen and Manage Data Security Posture with Microsoft Purview , on data security posture management in practice.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

1 week, 1 day назад @ microsoft.com
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

The operators first validated command execution using lightweight out-of-band probes to unique subdomains hosted on public interaction and collaborator services, including oast[.

When a service-state change triggers health monitoring, swatchdog incorporates the attacker-controlled value into a snmptrap shell invocation, enabling command execution.

Exploitation of the Zimbra vulnerability provided attackers with direct command execution as the zimbra service account.

Attackers also used the initial command execution to download and execute content directly through wget or curl, launch background processes, and establish interactive reverse shells.

Command and controlThe actor used HTTP and H…

1 week, 1 day назад @ microsoft.com
Phishing Abuses RMM Tools for Persistent Access
Phishing Abuses RMM Tools for Persistent Access Phishing Abuses RMM Tools for Persistent Access

Attack chain showing phishing delivering a masqueraded MSP360 RMM installer that deploys ScreenConnect for persistent remote access and follow-on activity.

Initial Access: Phishing Campaign Delivering Masqueraded MSP360 RMM InstallerMicrosoft observed multiple phishing campaigns that used a multi-stage delivery chain to distribute legitimate, digitally signed MSP360 RMM software (v2.5.0.67).

Analysis of downloaded samples showed that many ultimately contained the same MSP360 RMM installer package despite appearing as different files to the victim.

Command and ControlT1219 Remote Access Software | The threat actor abused legitimate remote administration software including MSP360 RMM and Conn…

1 week, 2 days назад @ microsoft.com
​​Beyond source code: A path to the keys to the kingdom
​​Beyond source code: A path to the keys to the kingdom ​​Beyond source code: A path to the keys to the kingdom

By mapping trusted deployment paths and connected resources, the threat actor was able to identify opportunities to expand beyond the initial compromise.

In addition to deploying a kube agent, the threat actor modified pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility.

The threat actor added seven stolen kubeconfig files to a repository, providing the credentials needed to access targeted Kubernetes clusters.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

1 week, 2 days назад @ microsoft.com
Star Blizzard refines phishing and malware delivery with the RedFlick technique
Star Blizzard refines phishing and malware delivery with the RedFlick technique Star Blizzard refines phishing and malware delivery with the RedFlick technique

In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns.

June 2026 RedFlick campaign follow-up email with the subject line “Invitation to the Chatham House London Conference 2026”Figure 3.

Persistence through multiple scheduled tasksIn April 2026, Microsoft observed Star Blizzard changing persistence tactics to include RedFlick scheduled tasks.

Defending against Star Blizzard and RedFlick-related activityMicrosoft Threat Intelligence advises organizations that are most likely at risk—primarily those in government, NGOs, or think tanks adjacent to Ukraine policy or support—to implement the followin…

1 week, 2 days назад @ microsoft.com
Star Blizzard refines phishing and malware delivery with the RedFlick technique
Star Blizzard refines phishing and malware delivery with the RedFlick technique Star Blizzard refines phishing and malware delivery with the RedFlick technique

In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns.

June 2026 RedFlick campaign follow-up email with the subject line “Invitation to the Chatham House London Conference 2026”Figure 3.

Persistence through multiple scheduled tasksIn April 2026, Microsoft observed Star Blizzard changing persistence tactics to include RedFlick scheduled tasks.

Defending against Star Blizzard and RedFlick-related activityMicrosoft Threat Intelligence advises organizations that are most likely at risk—primarily those in government, NGOs, or think tanks adjacent to Ukraine policy or support—to implement the followin…

1 week, 2 days назад @ microsoft.com
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.

Microsoft has observed additional NeedyMantis activity beyond Storm-3069’s activity in the DAEMON Tools campaign, indicating that the malware might be used by more than one operator.

Indicators of compromiseIndicator Type Description First seen Last seen e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e SHA-256 First-stage loader WinSparkle.dll 2026-05-21 2026-05-21 9cb68f986043a576e19d32184…

1 week, 3 days назад @ microsoft.com
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Storm-3168: Agentic-driven cloud attacks using compromised service principals Storm-3168: Agentic-driven cloud attacks using compromised service principals

About 90 minutes after the first compromised service principal started enumeration, the second compromised service principal enumerated virtual machines and resource groups across two subscriptions in five seconds.

16 hours later, the second service principal successfully enumerated Azure App Service configuration stores, possibly looking for exposed credentials.

This compromised service principal then attempted 150+ destructive or credential collection related operations in 35 minutes.

T1078.004 Valid Accounts: Cloud Accounts | Compromised service principals were used for Azure resource discovery and destruction.

To hear stories and insights from the Microsoft Threat Intelligence community…

1 week, 6 days назад @ microsoft.com
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Storm-3168: Agentic-driven cloud attacks using compromised service principals Storm-3168: Agentic-driven cloud attacks using compromised service principals

About 90 minutes after the first compromised service principal started enumeration, the second compromised service principal enumerated virtual machines and resource groups across two subscriptions in five seconds.

16 hours later, the second service principal successfully enumerated Azure App Service configuration stores, possibly looking for exposed credentials.

This compromised service principal then attempted 150+ destructive or credential collection related operations in 35 minutes.

T1078.004 Valid Accounts: Cloud Accounts | Compromised service principals were used for Azure resource discovery and destruction.

To hear stories and insights from the Microsoft Threat Intelligence community…

1 week, 6 days назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 5 months, 2 weeks назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

5 months, 2 weeks назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

6 months назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

6 months назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

6 months, 1 week назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

6 months, 1 week назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

6 months, 2 weeks назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

7 months, 1 week назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

7 months, 2 weeks назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

7 months, 3 weeks назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

8 months, 2 weeks назад @ security.googleblog.com