Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 2 часа назад
Свободных стоек почти нет. Цены в российских ЦОДах снова пошли вверх
Свободных стоек почти нет. Цены в российских ЦОДах снова пошли вверх

Дефицит мощностей оказался сильнее дорогих кредитов и затормозившего строительства.

2 часа назад @ securitylab.ru
Покажите Echo свой текст, и нейросеть попробует стать вами
Покажите Echo свой текст, и нейросеть попробует стать вами

Эксперимент показал, насколько близко машина уже подобралась к индивидуальному почерку.

2 часа назад @ securitylab.ru
7,9 млн клиентов и $400 тысяч выкупа. DataSuckers атаковала украинского ритейлера АТБ-Маркет
7,9 млн клиентов и $400 тысяч выкупа. DataSuckers атаковала украинского ритейлера АТБ-Маркет

Ритейлер подтверждает кибератаку, но категорически отрицает масштабную утечку.

3 часа назад @ securitylab.ru
Наконец-то не наоборот. Обновление Windows 11 сделало компьютер быстрее
Наконец-то не наоборот. Обновление Windows 11 сделало компьютер быстрее Наконец-то не наоборот. Обновление Windows 11 сделало компьютер быстрее

26H2 у части пользователей заметно снижает расход RAM и ускоряет запуск приложений, хотя Microsoft такого эффекта не обещала.

3 часа назад @ securitylab.ru
В ИБ без профильного диплома: куда реально берут и что проверяют на входе
В ИБ без профильного диплома: куда реально берут и что проверяют на входе

Где диплом обязателен, где его заменяют навыки и почему домашний стенд из виртуалок иногда весит больше, чем строчка о вузе в резюме.

3 часа назад @ securitylab.ru
Сначала роботы дрались друг с другом. Теперь в клетку пустили людей
Сначала роботы дрались друг с другом. Теперь в клетку пустили людей 4 часа назад @ securitylab.ru
После ДНК инженеры готовят ещё более странные молекулы для хранения данных
После ДНК инженеры готовят ещё более странные молекулы для хранения данных

Расширенный молекулярный алфавит может увеличить объём данных, записываемых в одной цепочке.

5 часов назад @ securitylab.ru
Ник. Имя. Работа. Друзья. Марк Цукерберг решил деанонимизировать планету
Ник. Имя. Работа. Друзья. Марк Цукерберг решил деанонимизировать планету

Новые документы показывают куда более системный механизм, чем считалось раньше.

5 часов назад @ securitylab.ru
Отсутствие взломов или «ИИ для всех»? Альтман объяснил, почему выбирает риск
Отсутствие взломов или «ИИ для всех»? Альтман объяснил, почему выбирает риск

OpenAI и Anthropic признают опасность мощных моделей, но проводят границу допустимого в разных местах.

6 часов назад @ securitylab.ru
Apple закрывает эпоху почти безграничного Full Disk Access из-за ИИ-агентов
Apple закрывает эпоху почти безграничного Full Disk Access из-за ИИ-агентов

Одного согласия пользователя для самых чувствительных данных скоро будет недостаточно.

6 часов назад @ securitylab.ru
Видели северное сияние? Вы видели только кусок. SMILE впервые за 18 лет снял его целиком — кольцом вокруг полюса
Видели северное сияние? Вы видели только кусок. SMILE впервые за 18 лет снял его целиком — кольцом вокруг полюса

Съёмка показала весь авроральный овал и дала учёным новый способ следить за магнитными бурями.

6 часов назад @ securitylab.ru
Reuters посчитал цену ИИ-гонки, миру может понадобиться свыше $30 трлн на дата-центры
Reuters посчитал цену ИИ-гонки, миру может понадобиться свыше $30 трлн на дата-центры

Счета приходят уже сейчас, а экономический эффект может задержаться на годы.

7 часов назад @ securitylab.ru
arXiv ставит ИИ-шлак на паузу. Учёным оставили всего две публикации в месяц
arXiv ставит ИИ-шлак на паузу. Учёным оставили всего две публикации в месяц

40000работ за сентябрь заставили крупнейший архив препринтов включить ограничитель.

8 часов назад @ securitylab.ru
12 случайных чисел до захвата сервера. ИИ от Anthropic нашёл критическую дыру в Rejetto HFS
12 случайных чисел до захвата сервера. ИИ от Anthropic нашёл критическую дыру в Rejetto HFS

После публикации технической цепочки уязвимость тут же начали использовать в реальных атаках.

8 часов назад @ securitylab.ru
Счётчики. Камеры. Сигнализации. Кассы. Минцифры хочет поставить на учёт всё, что звонит само
Счётчики. Камеры. Сигнализации. Кассы. Минцифры хочет поставить на учёт всё, что звонит само

«Антифрод 3.0» добрался до интернета вещей.

14 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 3 часа назад
Обзор AlphaSense Symbiote Space, ПО для поиска и эксплуатации уязвимостей
Обзор AlphaSense Symbiote Space, ПО для поиска и эксплуатации уязвимостей Обзор AlphaSense Symbiote Space, ПО для поиска и эксплуатации уязвимостей

Объединяет обнаружение и инвентаризацию ИТ-активов, поиск уязвимостей и ошибок конфигурации, активную проверку эксплуатации уязвимостей, приоритизацию и контроль устранения.

Информационная панель EASM в AlphaSense Symbiote SpaceС помощью фильтров задаются значения критериев отбора хостов и уязвимостей, отображаемых в блоке.

Реализуется полная поддержка системы CVSS версий 2, 3 и 4 для оценки критической значимости уязвимостей и их последующей приоритизации.

Платформа обнаруживает доступные извне активы и сервисы, связывает их с внутренней инвентаризацией и показывает открытые порты, версии ПО, уязвимости и реальную возможность эксплуатации.

ВыводыAlphaSense Symbiote Space объединяет обнаруж…

3 часа назад @ anti-malware.ru
ИИ-программисты сливают корпоративные ключи: новая угроза от нейросетевого кодинга
ИИ-программисты сливают корпоративные ключи: новая угроза от нейросетевого кодинга ИИ-программисты сливают корпоративные ключи: новая угроза от нейросетевого кодинга

Таким образом, доля изменений кода с обнаруженными секретами при использовании ИИ-инструментов оказалась более чем в два раза выше среднего показателя.

Hardcoded secrets — пароли и ключи, записанные непосредственно в тексте программы или её настройках, то есть доступ к ресурсу оказывается неотделим от самого кода.

Сами по себе такие секреты не всегда появляются в коде по вине ИИ: разработчики оставляли ключи и пароли в репозиториях и раньше.

Срок действия доступа ограничен, и по его истечении доступ автоматически прекращается.

Ключ необходимо отозвать и заменить, проверить журналы его использования и при необходимости очистить историю репозитория.

23 часа назад @ anti-malware.ru
Будущее строгой аутентификации: виртуальные смарт-карты и BYOD
Будущее строгой аутентификации: виртуальные смарт-карты и BYOD Будущее строгой аутентификации: виртуальные смарт-карты и BYOD

ВведениеФизическая смарт-карта или USB-токен защищает закрытый ключ и позволяют использовать его для аутентификации и других криптографических операций.

С 1 октября 2025 года действует ГОСТ Р 70262.2-2025, который устанавливает уровни доверия аутентификации и определяет требования к видам и средствам аутентификации для каждого из них.

При этом важно, чтобы закрытый ключ не передавался за пределы защищённого хранилища и не мог быть штатно экспортирован.

Ограничения: KeyBox не заменяет механизм строгой аутентификации, инфраструктуру открытых ключей (PKI) или систему контроля состояния устройства, а управляет средствами аутентификации и их жизненным циклом.

Когда выбирать: если нужно централиз…

1 day, 3 hours назад @ anti-malware.ru
Цифровой сотрудник — дешёвая замена человеку или новая статья расходов?
Цифровой сотрудник — дешёвая замена человеку или новая статья расходов? Цифровой сотрудник — дешёвая замена человеку или новая статья расходов?

Среднее базовое ДМС обходится в 2 000 рублей в месяц.

Среднемесячную заработную плату округлим до 56 000 рублей на руки.

Аренда мощностей может обходиться в 5 000 — 20 000 рублей (и выше) в месяц.

Другие расходы:LLM-токены: 0,5 — 2 рублей за ответ, при 900 диалогах — от 2 000 до 6 000 рублей в месяц.

Сообщения бесплатны, платный контур — хостинг прослойки, 1 000 — 3 000 рублей в месяц.

3 days, 22 hours назад @ anti-malware.ru
Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры
Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры

Отдельно обсудили, как выбирать облачного провайдера — на какие критерии смотреть и что влияет на надёжность его сервисов.

Заказчик не видит эти процессы изнутри и не может управлять ими так же, как собственной инфраструктурой.

Но, как советует Станислав Попов, внедрять ИИ сейчас стоит осознанно и с пониманием ожидаемого бизнес-эффекта.

Тестирование аварийного восстановления (disaster recovery, DR) позволяет эмулировать сбои, проверить работу собственной инфраструктуры и цепочки поставщиков.

Вместо самостоятельного создания инфраструктуры и найма специалистов они могут использовать облачную инфраструктуру, соответствие которой необходимым требованиям уже подтверждено.

5 days, 2 hours назад @ anti-malware.ru
Low-code и No-code в 2026 году: как создавать приложения без разработчиков
Low-code и No-code в 2026 году: как создавать приложения без разработчиков Low-code и No-code в 2026 году: как создавать приложения без разработчиков

Платформы Low-code и No-code позволяют создавать бизнес-приложения, автоматизировать процессы и интегрировать системы силами специалистов без профильного образования в области программирования.

Что такое Low-code и No-codeАнтон Симуни объяснил разницу между No-code и Low-code.

No-code — это для непрофессиональных программистов, может быть, даже вообще для тех, кто создаёт приложения без профильного ИТ-образования (т. н.

В первом опросе зрители рассказали, используют ли они платформы No-code / Low-code в своей компании:«Пилотируют» / только начинают внедрение — 28 %.

ВыводыРынок Low-code и No-code в 2026 году перестал быть нишевым явлением.

5 days, 22 hours назад @ anti-malware.ru
Миграция с Cisco: от пилота до замены инфраструктуры
Миграция с Cisco: от пилота до замены инфраструктуры Миграция с Cisco: от пилота до замены инфраструктуры

Вместе с Ideco мы обсудили, как подготовиться к переходу на российские решения, почему полностью бесшовной замены сегодня не бывает.

Причины отказа от CiscoПосле ухода Cisco из России вопрос перехода на другие решения для клиентов до сих пор никуда не исчез.

Совместимость IPsec Site-to-Site с Cisco подтверждена, поэтому площадки можно переносить поэтапно без потери связи между ними.

Илья Соболев, менеджер по продукту IdecoЗависимость от вендора и бесшовность миграцииПри переходе с Cisco на российское решение вопрос зависимости от вендора сохраняется.

Например, добавление поддержки EIGRP, протокола маршрутизации, было связано с тем, что многие компании строили инфраструктуру на Cisco.

6 days, 3 hours назад @ anti-malware.ru
Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке
Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке

ИИ-агенты и их влияние на рынокАндрей Галактионов считает, что истории о сбежавших из песочниц ИИ-агентах — это в первую очередь хайп.

«Красная» команда в 95 % случаев достигает целей, но если нет зрелости, результат будет тот же, что и от пентеста, только дороже.

Если по результатам пентеста нужно проверить инфраструктуру, а по результатам Red Teaming — перенастроить процессы, то внутренняя команда может быть эффективнее для изменения процессов.

ВыводыРынок Offensive Security в 2026 году проходит через фундаментальную трансформацию.

А те, кто считает, что с ними ничего не случится, рискуют убедиться в обратном в самый неподходящий момент.

6 days, 21 hours назад @ anti-malware.ru
Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA
Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA

SafeTech Lab встроила в SafeTech CA модуль CDM для доставки, установки и автоматического обновления технологических сертификатов.

Теперь заказчику больше не нужно искать отдельное решение, интегрировать его с CA и настраивать сложные схемы взаимодействия систем.

Новые расширенные возможности выводят SafeTech CA за рамки обычного центра сертификации — теперь это полноценная платформа управления цифровыми сертификатами.

SafeTech CA закрывает все самые востребованные задачи по контролю за сертификатами: от их выпуска до автоматического обновления на клиентских устройствах.

Модуль CDM расширяет возможности SafeTech CA за счёт агентской доставки, установки и автоматического перевыпуска сертифика…

1 week назад @ anti-malware.ru
ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок
ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок

Согласно отраслевым прогнозам, доля корпоративного ПО с агентным ИИ может возрасти с менее чем 1 % в 2024 году до 33 % к 2028 году.

Наблюдения специалистов по безопасности ИИ и открытые исследования подтверждают: злоумышленники уже сейчас тестируют методы обхода ограничений в промышленных системах.

Недостаточно добавить фильтры поверх уже созданной системы: принципы безопасности для агентов необходимо закладывать на этапе проектирования.

Инструментарий: что включить в конвейер обеспечения безопасности уже сейчасСредства защиты агентов перестают быть узкоспециализированными утилитами и интегрируются в классический конвейер (пайплайн) DevSecOps.

ВыводыОбеспечение безопасности автономных агент…

1 week назад @ anti-malware.ru
Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов
Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов

В Якутии хотят строить ЦОДы там, где мороз помогает охлаждать серверы, а газ можно превращать в электричество прямо у месторождений.

То, что десятилетиями делало стройку и жизнь в Якутии дороже и сложнее, теперь пытаются превратить в конкурентное преимущество: местный мороз должен помогать охлаждать серверы.

Новый проект правительства республики, КРДВ и «Ростелекома» хотят начать с 2,5 МВт — уже в пять раз больше нынешней инфраструктуры.

А заявленные 100 МВт означали бы рост относительно сегодняшнего уровня примерно в 200 раз и в 40 раз относительно старта.

И тогда уже важно, какой газ он потребляет, мог ли этот ресурс уйти другому покупателю и что происходит с локальным энергетическим бала…

1 week назад @ anti-malware.ru
Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты
Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты

Решение BI.ZONE Mail Security создано на основе системы BI.ZONE CESP и предназначено для защиты корпоративной почты от вредоносных и нежелательных сообщений.

Эти данные могут дополняться актуальной информацией из внешних систем: BI.ZONE Threat Intelligence, BI.ZONE Sandbox и платформы BI.ZONE Security Fitness.

BI.ZONE Mail Security также интегрируется с платформой BI.ZONE Security Fitness, что позволяет учитывать результаты учебных фишинговых рассылок при настройке политик безопасности.

Подключение модуля BI.ZONE SandboxВ on-prem-варианте BI.ZONE Mail Security также можно интегрировать с BI.ZONE Threat Intelligence, при этом сам портал располагается в облачной инфраструктуре BI.ZONE.

Компон…

1 week, 1 day назад @ anti-malware.ru
Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности
Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности

Использование macOS в dev-средах увеличивает риск горизонтального перемещенияКлассические техники горизонтального перемещения через Active Directory и SMB на macOS встречаются реже и хуже покрыты правилами детектирования.

Классическая подсистема аудита OpenBSM начиная с macOS 11 объявлена устаревшей, а в версиях начиная с macOS 14 она отключена по умолчанию.

Сейчас ситуация меняется: вендоры наращивают функциональность агентов под macOS и адаптируют их как к новым версиям ОС, так и к меняющемуся ландшафту угроз.

Политики безопасности исторически писались под Windows, и Mac-устройства во многих организациях так и не попали в контур мониторинга SOC.

Windows, Linux и macOS в ней сосуществуют, …

1 week, 3 days назад @ anti-malware.ru
Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки
Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки

Эксперты ведущих вендоров собрались в студии AM Live, чтобы обсудить, чем отличаются классы решений, как их выбирать и на что смотреть при пилотировании.

Какими бывают балансировщики нагрузкиДаниил Виняр предложил разделить решения на три класса:Global Server Load Balancing (GSLB) — решения на базе DNS, которые распределяют нагрузку между разными ЦОДами, будь то собственные площадки или облака.

ВыводыРоссийский рынок балансировщиков нагрузки и брокеров сетевых пакетов находится в фазе активного роста и уже не нуждается в доказательствах своей зрелости.

При этом удобство — это не только красивый интерфейс, но и логичность, понятность того, что можно сделать с устройством, и возможность не со…

1 week, 4 days назад @ anti-malware.ru
Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств
Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств

MaxPatrol Endpoint Security — это комплексное решение, которое объединило все возможности продуктов MaxPatrol EDR и MaxPatrol EPP.

Архитектура MaxPatrol Endpoint Security 10Порядок функционирования MaxPatrol Endpoint Security:Сервер агентов распространяет через агенты, установленные на конечных устройствах, исполняемые модули и их конфигурацию.

Взаимодействие компонентов MaxPatrol Endpoint Security 10 через портыУлучшенные функциональные возможности в MaxPatrol Endpoint Security 10Рассмотрим возможности MaxPatrol Endpoint Security 10-й версии.

MaxPatrol Endpoint Security поддерживает связку MaxPatrol EDR + MaxPatrol EPP, а также интеграции с MaxPatrol SIEM, MaxPatrol VM, PT Sandbox и PT NAD…

1 week, 5 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 35 минут назад
PKI-шторм: что делать, если Kubernetes одновременно запрашивает 100 тысяч сертификатов
PKI-шторм: что делать, если Kubernetes одновременно запрашивает 100 тысяч сертификатов PKI-шторм: что делать, если Kubernetes одновременно запрашивает 100 тысяч сертификатов

Когда таких потребителей тысячи, PKI работает уже не с отдельными сертификатами, а с массовым потоком запросов.

Представьте, что после аварии начинает восстанавливаться целый ЦОД, а вместе с ним одновременно поднимаются десятки тысяч pod'ов Kubernetes.

Если раньше 100 тысяч запросов упирались в ЦС, а теперь они идут в хранилище, не превратится ли уже оно в новый bottleneck?

Сертификат начинает «стареть» с момента выпуска, а не с момента выдачи сервису.

Какие выводы мы сделалиГлавный урок этой истории оказался не про конкретный центр сертификации и даже не про Kubernetes.

35 минут назад @ habr.com
В фокусе RVD: трендовые уязвимости сентября
В фокусе RVD: трендовые уязвимости сентября В фокусе RVD: трендовые уязвимости сентября

Как указано в описании уязвимости от Microsoft, злоумышленник отправляет на сервер специально сформированный запрос и выполняет на нём произвольный код.

Эксплуатации подвержены Windows 10 и Windows 11, а также серверные версии от Windows Server 2012 до Windows Server 2025.

Уязвимость затрагивает Windows 10 и Windows Server версий 2012, 2012 R2, 2016, 2019 и 2022.

Windows 11 и Windows Server 2025 вне угрозы эксплуатации.

11 сентября CISA добавила уязвимость в каталог KEV со сроком устранения до 14 сентября.

1 час назад @ habr.com
Публичный видеосервис на VPS: как не открыть дверь в домашнюю сеть
Публичный видеосервис на VPS: как не открыть дверь в домашнюю сеть Публичный видеосервис на VPS: как не открыть дверь в домашнюю сеть

Он сам устанавливает обратный SSH-туннель к VPS, а публичный Nginx передаёт запросы через этот туннель.

Эта статья — разбор того, как такое происходит и как публиковать домашний видеосервис, не превращая VPS в дверь в локальную сеть.

Самое главноеБезопасная схема держится не на одном пароле и не на одном firewall, а на нескольких независимых границах:Браузер не выбирает адрес внутреннего сервера.

Токен лучше передавать в заголовке или защищённой cookie, а не в query string: URL чаще попадают в историю браузера, журналы и аналитику.

Docker: Packet filtering and firewallsПосле запуска нужно проверять фактическое состояние, а не только конфигурационный файл:Get-NetTCPConnection -State Listen |…

1 час назад @ habr.com
Дайте нормально поработать или я сделаю это сам
Дайте нормально поработать или я сделаю это сам Дайте нормально поработать или я сделаю это сам

Причем насколько мне удалось понять, доступ организован по принципу черных списков — есть доступ ко всему, что не запрещено.

В итоге это было фиаско, и я забросил идею.

Тут я вернулся к исследованиям и нашел единственную разницу, почему мой тестовый сайт заблокирован, а новоиспеченный сервис открывается — я не прикрутил SSL‑сертификаты.

Но когда у тебя семья, работа и в целом жизнь бьет ключом, то неудивительны временные трудности и банальные затупы.

Дело за малым — понять, как я могу это использовать.

1 час назад @ habr.com
Рутокен с биометрией – не миф
Рутокен с биометрией – не миф Рутокен с биометрией – не миф

Основным плюсом однофакторной аутентификации с паролями является простота, а вот минусов куда больше:Пароли легко подобрать.

Что такое Рутокен БИОИтак, как вы уже могли догадаться, Рутокен БИО — это комплексный продукт, направленный на аппаратную поддержку биометрии по отпечатку пальца.

Рутокен ЭЦП 3.0 3250 БИО с аппаратной поддержкой биометрии — это привычный Рутокен ЭЦП 3.0, который можно использовать во всех уже внедренных сценариях.

Развитие экосистемы РутокенЛично мне, как непосредственному разработчику, хочется рассказать вам про Рутокен Логон для Linux 🤩Рутокен Логон — это программный комплекс для многофакторной аутентификации в отечественных линуксах.

Начиная с версии 4.12.0 в Руток…

2 часа назад @ habr.com
OpenCode против пентестера
OpenCode против пентестера OpenCode против пентестера

МетрикиНами оценивались следующие параметры:Количество подтвержденных уязвимостей – только с рабочим PoC, а не с оценками вида «вероятно, здесь SQLi».

Пять на Windows – включая карточки прямо в C:\Windows и в System32 .

К концу второго часа обе машины находились под полным контролем, как и в двух предыдущих прогонах.

Полезность человека в этом случае состояла не в знании конкретной уязвимости, а в способности увидеть необычную службу и задать проверяемую гипотезу.

OpenCode отличается от них характером работы:различные Nessus’ы и OpenVAS’ы сопоставляют версии с сигнатурами плагинов и часто выдают предположение о возможной уязвимости.

2 часа назад @ habr.com
Windows IR: системный подход. Часть 2 — изоляция, процессы, службы
Windows IR: системный подход. Часть 2 — изоляция, процессы, службы Windows IR: системный подход. Часть 2 — изоляция, процессы, службы

Все современные EDR поддерживают режим сетевой изоляции, и в то же время позволяют гибко настроить исключения в ней, если необходимо.

Еще один способ — изоляция на сетевых устройствах: Запретить трафик на межсетевом экране (на уровне L3) и на коммутаторе (на уровне L2).

Также видим, что в дереве два комплекта csrss / winlogon / explorer:Скрина терминала нет, поэтому вот скрин содержания транскрипта.

Остановленная служба не будет порождать процесс, и в тасклисте его видно не будет — а затем служба стартанет и запустит процесс.

Мысль здесь в том, что в «боевой» инфре таких артефактов будет много.

3 часа назад @ habr.com
Как мы собирали CTF-комьюнити в вузе с нуля до международного турнира
Как мы собирали CTF-комьюнити в вузе с нуля до международного турнира Как мы собирали CTF-комьюнити в вузе с нуля до международного турнира

Через два года после того, как мы сами начали играть, мы провели свой CTF, на который зарегистрировались 1280 команд из 51 страны.

Эта статья — про то, как формировалось комьюнити вокруг CTF в вузе, где потенциал был, но никто его не собирал воедино.

Мы начали играть в смешанных составах — мы с Александром(моим другом), остальные откуда придётся.

Мы с командой в 2025 году на Уральском форумеКомьюнити росло не потому, что мы кого-то агитировали.

Люди приходили, потому что видели, что это работает, это даёт скиллы, это помогает с трудоустройством.

4 часа назад @ habr.com
Маскирование ПДн для LLM: метрика, которую не считает никто, и шесть шлюзов против живого агента
Маскирование ПДн для LLM: метрика, которую не считает никто, и шесть шлюзов против живого агента Маскирование ПДн для LLM: метрика, которую не считает никто, и шесть шлюзов против живого агента

Команду можно повторить у себя: харнесс поднимает фальшивого провайдера, движок получает запросы по HTTP и не знает, что его измеряют.

Строка без единой ошибки печатает не «100%», а нижнюю границу подтверждаемого: 52/52 сертифицирует ≥94.4% по интервалу Клоппера-Пирсона.

100% на 52 случаях и 100% на 5 200 не одно и то же.

G6 : маскер, который ничего не делает, обязан пройти каждый случай: не пережившее passthrough значение значит сломанный случай, а не маскер.

Признак hard выводится из шаблона случая, а не из прогона детектора: отбор на сигналах измеряемой системы делает его непроваливаемым.

4 часа назад @ habr.com
Как я делаю защищенное файловое хранилище — 2: Ограничения и возможности
Как я делаю защищенное файловое хранилище — 2: Ограничения и возможности Как я делаю защищенное файловое хранилище — 2: Ограничения и возможности

Вот так, перемещаясь время от времени по городу и размышляя по дороге, я и продолжил работать над своим проектом.

Для начала пришлось посмотреть в лицо самому главному ограничению: у меня был только я и был я не дома.

Несмотря на то, что я не мог использовать аппаратные механизмы защиты, меня это не огорчило.

Что ж, если приложение должно работать на любом железе, то оно должно как можно меньше зависеть от этого самого железа.

В нем было все, что мне нужно и не было ничего лишнего.

4 часа назад @ habr.com
Как я подключил MAX и VK к Chatwoot: разбираем двусторонний мост
Как я подключил MAX и VK к Chatwoot: разбираем двусторонний мост Как я подключил MAX и VK к Chatwoot: разбираем двусторонний мост

После моей статьи о рабочем месте репетитора в Chatwoot в комментариях закономерно спросили не о календаре и не о Jitsi, а о детали, которую я тогда почти не показал: как именно сообщения из MAX и VK попадают в Chatwoot и как ответ возвращается обратно.

Обложка: MAX и VK сходятся в Chatwoot через собственный мостЧто именно я хотел получитьУ меня уже был Chatwoot как единое окно для переписки.

Он не читает мою личную переписку в MAX или VK и не пытается изображать браузер.

У входящего и исходящего направления разные инициаторы:MAX webhook ─┐ ├─> Node.js bridge ─> Chatwoot Application API VK Callback ─┘ Chatwoot message_created webhook ─> bridge ─┬─> MAX Bot API └─> VK APIАрхитектура двусторо…

5 часов назад @ habr.com
Security Week 2641: новая атака типа Spectre-v2
Security Week 2641: новая атака типа Spectre-v2 Security Week 2641: новая атака типа Spectre-v2

Свежая исследовательская работа вместо инъекции команд предлагает способ повторного использования информации в системе предсказания ветвлений.

Подходящее для атаки Branch Target Reuse состояние предсказателя ветвлений происходит в результате работы компилятора JIT, что ранее считалось непрактичным сценарием.

В опубликованном исследовании показано успешное извлечение секретной информации, когда особенности предсказания ветвлений комбинируются с работой JIT-компилятора cBPF, входящего в состав ядра Linux.

Что еще произошлоВ свежей публикации специалистов «Лаборатории Касперского» анализируются методы поиска следов атаки на серверы 1С.

Закрылась программа Google по вознаграждению за обнаружени…

7 часов назад @ habr.com
Используем ISD для защищенной персонализации Java Card апплета
Используем ISD для защищенной персонализации Java Card апплета Используем ISD для защищенной персонализации Java Card апплета

Исходники: ISD_secured_applet, FunGPСуть задачиПредставим, что на предприятии ввели систему СКУД и вход в здание только по картам, на которых хранится информация о сотруднике: ФИО, департамент, должность и срок действия карты.

Начнем описание с базовых элементов апплета и первым на очереди конструктор:public ISD_secured_applet() { person_info = new byte[_255]; }Несмотря на его лаконичность, именно на нем я столкнулся с очередным подвохом.

Затем был изнурительный гуглежь, который предложил инстанциировать супертяжей в отдельных функциях уже после инсталляции апплета, что и оказалось решением проблемы.

new ISD_secured_applet().register(buffer, offset, length); }Обратите внимание, что в метод …

17 часов назад @ habr.com
Спросить SIEM словами: подключаем LLM-ассистента к Wazuh
Спросить SIEM словами: подключаем LLM-ассистента к Wazuh Спросить SIEM словами: подключаем LLM-ассистента к Wazuh

Агент чатаВ окне чата общение происходит не с моделью, а с агентом.

Query Assist в DiscoverQuery Assist — строка в Discover, в которой вопрос словами превращается в запрос PPL.

В OpenSearch это делает плагин Alerting, но плагин Wazuh на это не способен, так что добавим кнопку в код плагина Wazuh и пересоберем его.

Правка общая для всех модулей: панель просмотра документа у Wazuh одна, и кнопка появится и в Threat Hunting, и в Vulnerability Detection, и во всех остальных разделах.

Чат оставьте для быстрых вопросов к данным и не забывайте смотреть на запрос под ответом.

23 часа назад @ habr.com
Карта профессий ИБ в эпоху ИИ: что автоматизируется, куда смещается спрос и чему учиться
Карта профессий ИБ в эпоху ИИ: что автоматизируется, куда смещается спрос и чему учиться Карта профессий ИБ в эпоху ИИ: что автоматизируется, куда смещается спрос и чему учиться

Однако сэкономленные часы не превращаются в праздное время: они перенаправляются на валидацию, разрешение краевых случаев и аудит цепочек рассуждения агентов.

Профессии в ИБ смещаются от механического исполнения регламентов к проектированию надёжных архитектур, контролю автоматизированных контуров и разрешению нестандартных инцидентов.

Карта трансформации 13 специализаций ИБОценивать изменения корректнее не по формальным названиям должностей, а по соотношению рутинных задач, цены ошибки и контекстной сложности работы.

Detection Engineer определяет, какие именно признаки атаки необходимо выявлять, на каких источниках данных и с каким порогом ложноположительных срабатываний.

Без понимания баз…

23 часа назад @ habr.com
Хакер Хакер
последний пост 47 минут назад
Репозитории на GitHub раскрывают более 543 000 учетных данных
Репозитории на GitHub раскрывают более 543 000 учетных данных Репозитории на GitHub раскрывают более 543 000 учетных данных

Исследователи из компании Truffle Security подсчитали, что в открытых репозиториях на GitHub опубликованы 543 699 уникальных и по-прежнему действующих учетных данных.

В общей сложности 543 699 уникальных секретов встречались более чем в 1,1 млн файлов и репозиториев, включая копии в форках.

В компании отдельно отметили, что в случае GitHub масштаб проблемы оказался в два раза больше, чем при аналогичном исследовании Hugging Face.

Отдельно исследователи оценили эффективность механизма GitHub Push Protection, который ищет в коде API-ключи, токены доступа и другие секреты, а затем блокирует их публикацию.

Однако исследователи установили, что, невзирая на работу GitHub Push Protection, 199 843 …

47 минут назад @ xakep.ru
СМИ: Минцифры снова рассматривает введение платы за международный трафик
СМИ: Минцифры снова рассматривает введение платы за международный трафик СМИ: Минцифры снова рассматривает введение платы за международный трафик

На этот раз с операторами обсуждается лимит в 50 Гбайт в месяц и только для сетей 5G.

Дело в том, что, по словам источников, у операторов связи попросту нет технического решения, нужного для реализации такого предложения.

Директор по продуктам Vigo Антон Прокопенко сообщил изданию, что в целом учитывать зарубежный трафик возможно, например, классифицируя его по IP-адресам.

Так, операторам придется классифицировать адреса и одновременно учитывать переключения абонента между 5G и LTE.

К примеру, в 2025 году частный абонент в среднем расходовал около 24 Гбайт всего мобильного трафика в месяц.

2 часа назад @ xakep.ru
В GitLab AI Gateway исправили критический баг на 9,9 балла
В GitLab AI Gateway исправили критический баг на 9,9 балла В GitLab AI Gateway исправили критический баг на 9,9 балла

AI Gateway представляет собой сервис, который связывает инстанс GitLab с ИИ-моделями и обеспечивает работу функций GitLab Duo.

Хотя в GitLab используют собственный облачный инстанс AI Gateway для GitLab.com, GitLab Self-Managed и GitLab Dedicated, пользователи также имеют возможность развертывать собственные установки в рамках GitLab Self-Managed посредством GitLab Duo Self-Hosted.

Подчеркивается, что пользователи AI Gateway, размещенного на серверах самой GitLab, уже защищены и им не нужно предпринимать никаких дополнительных действий.

В результате атакующий получал возможность выполнять произвольные команды непосредственно в AI Gateway.

Так как AI Gateway устанавливается отдельно, в виде …

17 часов назад @ xakep.ru
Near Intents идентифицировала атакующего и вернула похищенные $3,8 млн
Near Intents идентифицировала атакующего и вернула похищенные $3,8 млн Near Intents идентифицировала атакующего и вернула похищенные $3,8 млн

Команда кроссчейн-сервиса для обмена токенов NEAR Intents сообщила, что ей вернули 3,8 млн долларов, похищенных при взломе 1 октября.

Деньги вернулись всего через сутки после того, как команда заявила, что установила личность атакующего, и дала ему 48 часов на возврат средств.

В пятницу о возврате средств объявил генеральный менеджер NEAR Intents Алекс Шевченко в соцсети X. По его словам, все средства возвращены и команда прекращает расследование инцидента.

Уязвимость позволила злоумышленнику вывести средства, после чего работу NEAR Intents приостановили.

За два дня до атаки команда Near Intents заблокировала попытку обменять $50 млн, предпринятую хакером, стоящим за взломом биржи Bitget.

18 часов назад @ xakep.ru
Ботнет Carbonato использует ИИ для захвата незащищенных Docker-хостов
Ботнет Carbonato использует ИИ для захвата незащищенных Docker-хостов Ботнет Carbonato использует ИИ для захвата незащищенных Docker-хостов

После захвата машины малварь устанавливает в систему Hermes Agent — опенсорсный фреймворк для ИИ-агентов — и разворачивает в нем агента GH0ST, которым операторы управляют через Telegram.

Исследователи обнаружили Carbonato в публично доступном хранилище Docker-образов, которое не требовало аутентификации.

Обнаружив такую систему, малварь использует API и запускает привилегированный контейнер, с помощью которого получает доступ к самому хосту.

Обнаружив новую цель, Carbonato запускает ту же цепочку заражения, поэтому исследователи предупреждают, что малварь обладает потенциалом червя.

Для защиты от таких атак специалисты советуют не «светить» Docker API в интернете и обязательно использовать …

19 часов назад @ xakep.ru
Обход антивирусов на практике. Разбираем на пальцах сигнатурный движок YARA
Обход антивирусов на практике. Разбираем на пальцах сигнатурный движок YARA Обход антивирусов на практике. Разбираем на пальцах сигнатурный движок YARA

В статье мы раз­берем­ся, как устро­ены пра­вила и модули YARA, напишем собс­твен­ные сиг­натуры и при­меним их для поис­ка ано­маль­ных фай­лов.

Книга «Обход антивирусов на практике» Это пер­вая гла­ва из кни­ги «Об­ход анти­виру­сов на прак­тике».

Си­ла YARA — в гиб­кости опи­сания пат­тернов.

— любой байт целиком (от 00 до FF );— любой байт целиком (от до ); A?

Допус­тимые фор­мы:Син­таксис Рас­шифров­ка [ 4-6] От 4 до 6 байт [ 10-] От 10 байт до бес­конеч­ности [ -] От 0 байт до бес­конеч­ностиПе­рехо­ды кри­тичес­ки важ­ны в нес­коль­ких типич­ных сце­нари­ях.

21 час назад @ xakep.ru
Кастомные GPT используются для ClickFix-атак и распространения RAT
Кастомные GPT используются для ClickFix-атак и распространения RAT Кастомные GPT используются для ClickFix-атак и распространения RAT

ИБ-специалисты из компании Huntress обнаружили, что злоумышленники распространяют RAT через кастомные GPT в ChatGPT.

Исследователи объясняют, что злоумышленник злоупотребляет легитимной функцией OpenAI, которая позволяет создавать кастомные версии ChatGPT, адаптированные для конкретных задач, с соответствующими инструкциями, знаниями и навыками.

Для закрепления в системе малварь использовала сразу два механизма: добавляла запись в раздел Run реестра Windows и создавала задачу в планировщике.

Среди них были скрипт для закрепления в системе и финальная полезная нагрузка — RAT.

Перед подключением к своей управляющей инфраструктуре RAT собирал информацию о системе, а адрес управляющего сервера …

22 часа назад @ xakep.ru
Аккаунт Microsoft в соцсети X взломали для распространения криптовалютного скама
Аккаунт Microsoft в соцсети X взломали для распространения криптовалютного скама Аккаунт Microsoft в соцсети X взломали для распространения криптовалютного скама

Неизвестные злоумышленники «угнали» официальный аккаунт Microsoft в соцсети X, на который подписаны более 13 млн человек.

Кроме того, злоумышленники изменили аватар Microsoft на изображение скрепки.

В нем сообщалось, что компании известно о токене, который продвигают с использованием бренда Clippy и интеллектуальной собственности Microsoft без разрешения.

«Microsoft не санкционировала создание, продвижение или использование каких-либо криптовалютных токенов, связанных с Clippy, Microsoft или $MSFT, а также не спонсирует и не поддерживает их», — гласило сообщение.

Например, в июне 2024 года криптомошенники захватили профиль Microsoft India в соцсети X, на тот момент насчитывавший более 211 0…

1 day назад @ xakep.ru
Еще одного участника группы ShinyHunters могли арестовать в Иордании
Еще одного участника группы ShinyHunters могли арестовать в Иордании Еще одного участника группы ShinyHunters могли арестовать в Иордании

По данным информационного агентства Reuters, власти Иордании задержали предполагаемого участника группировки ShinyHunters, известного под ником Rey.

Источники журналистов утверждают, что теперь он сотрудничает с ФБР и помогает правоохранительным органам установить личности и местонахождение других участников группы.

В настоящее время Хадер якобы открыл следователям доступ к содержимому своих устройств и переписок, чтобы помочь идентифицировать своих предполагаемых сообщников.

Задержание Rey произошло на фоне конфликта между участниками ShinyHunters и ФБР.

В частности, в отчете сообщалось, что хак-группа преувеличивает масштабы своих атак, угрожает жертвам и их родственникам, занимается сват…

1 day, 2 hours назад @ xakep.ru
Новая атака снижает стойкость RSA и не требует факторизации
Новая атака снижает стойкость RSA и не требует факторизации Новая атака снижает стойкость RSA и не требует факторизации

Исследователи разработали новый метод атаки на RSA, который позволяет подделывать цифровые подписи без факторизации RSA-модуля и восстановления приватного ключа.

Для 1024-битного RSA такая атака уже практически реализуема, а стойкость ключей длиной 2048 и 4096 бит снижается до уровня, который считается недостаточным по современным стандартам.

До сих пор считалось, что для получения корректной RSA-подписи атакующему сначала придется разложить большое число на простые множители и восстановить приватный ключ, и стойкость RSA к таким атакам определяется сложностью факторизации больших чисел.

Эта работа показывает, что на практике RSA можно взломать, не взламывая сам ключ», — пояснил изданию Ars…

3 days, 17 hours назад @ xakep.ru
Из кадровой базы Пентагона утекли данные почти 3 млн человек
Из кадровой базы Пентагона утекли данные почти 3 млн человек Из кадровой базы Пентагона утекли данные почти 3 млн человек

Представители Пентагона заявили СМИ, что утечка затронула данные 2,76 млн живых людей и еще 294 000 умерших.

Для сравнения, по состоянию на март 2026 года в вооруженных силах США насчитывалось около 1,3 млн действующих военнослужащих.

Об инциденте стало известно из уведомления DMDC от 18 сентября 2026 года, которое один из получателей опубликовал на Reddit.

В общей сложности DMDC хранит более 60 млн записей о военных и гражданских сотрудниках, подрядчиках, членах их семей, пенсионерах и ветеранах.

Также центр отвечает за управление цифровыми идентификаторами и средствами доступа: учетными данными, паролями и смарт-картами, которые используются для входа в системы и на объекты Пентагона.

3 days, 19 hours назад @ xakep.ru
Девять жизней. Способы закрепления вредоносов в Linux
Девять жизней. Способы закрепления вредоносов в Linux Девять жизней. Способы закрепления вредоносов в Linux

h> # include < stdlib.

h> # include < unistd.

Соз­даем юнит‑файл в / etc/ systemd/ system/ , и systemd будет запус­кать наш бинарь при каж­дой заг­рузке как сис­темный сер­вис.

service systemctl daemon- reloadinit.dЕще до появ­ления systemd в Linux исполь­зовали сис­тему ини­циали­зации SysVinit .

d/ (в Debian они находят­ся пря­мо в / etc/ ).

3 days, 21 hours назад @ xakep.ru
16-летний исследователь обнаружил баг в системе аутентификации Microsoft Titan
16-летний исследователь обнаружил баг в системе аутентификации Microsoft Titan 16-летний исследователь обнаружил баг в системе аутентификации Microsoft Titan

16-летний ИБ-исследователь под ником Faav обнаружил серьезную ошибку аутентификации во внутренней аналитической платформе Microsoft Titan.

Так как система Titan предназначена для использования сотрудниками Microsoft, доступ к веб-интерфейсу платформы ограничен, но Faav вместе с самописным ИИ-ботом Antares обнаружил публичный API Titan на хосте Azure Cloud Services.

Faav рассказывает, что около десяти дней он вместе с Antares экспериментировал с аутентификацией, однако Titan отклоняла запросы.

То есть атакующий мог самостоятельно сформировать токен с нужными значениями, и Titan принимала его как настоящий.

Он подчеркивает, что в эту цифру, вероятно, входят старые, дублирующиеся и производные…

3 days, 22 hours назад @ xakep.ru
Компания MetaMask пострадала от киберинцидента, затронувшего часть инфраструктуры
Компания MetaMask пострадала от киберинцидента, затронувшего часть инфраструктуры Компания MetaMask пострадала от киберинцидента, затронувшего часть инфраструктуры

Представители MetaMask сообщили о компрометации части инфраструктуры и, чтобы снизить возможный ущерб, начали процедуру вывода затронутых валидаторов из стейкинга.

Для этого криптовалюту размещают в специальном депозите, а валидаторы проверяют новые блоки и подтверждают операции.

Причем сервис работает по некастодиальной модели: он обслуживает валидаторы, и в MetaMask подчеркивают, что не располагают ключами для вывода клиентских средств.

Также исследователь подсчитал, что MetaMask начала выводить примерно 17 000 валидаторов, за которыми закреплено около 523 000 ETH.

Согласно их заявлению, последние валидаторы MetaMask в протоколе Lido должны выйти из стейкинга к концу 7 октября.

4 days назад @ xakep.ru
США ввели санкции против семи TRON-адресов, связанных со взломами банкоматов
США ввели санкции против семи TRON-адресов, связанных со взломами банкоматов США ввели санкции против семи TRON-адресов, связанных со взломами банкоматов

Управление по контролю за иностранными активами Министерства финансов США (OFAC) внесло семь адресов в блокчейне TRON в санкционный список SDN.

Кроме того, в список попал один из лидеров группировки, которого в Минфине США обвиняют в незаконной добыче золота.

В TRM Labs рекомендуют криптосервисам и финансовым организациям проверить эти семь адресов и историю транзакций на связи с ними.

Санкции введены на основании указа 13224, поэтому иностранные финансовые учреждения, сознательно проводящие значимые операции в интересах фигурантов, рискуют попасть под вторичные санкции вплоть до ограничений на корреспондентские счета в США.

Основная работа по комплаенсу ложится на биржу, где размещены адре…

4 days, 1 hour назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 1 час назад
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software.

Neither the post nor the notice gives a date for accepting product vulnerability reports again.

Under the Cloud VRP rules, a flaw in an open source repository maintained by Google Cloud that affects Cloud products is rated at most IT3b.

Product vulnerability reports may still be accepted for some Google Cloud repositories that affect Google Cloud products, but the notice does not name them.

Under the Cloud VRP rules, a flaw in an open source repository maintained by Google Cloud that affects Cloud products is rated at most IT3b.

1 час назад @ thehackernews.com
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.

Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and listed a fixed version for each product.

Affected Products and Fixed VersionsThe flaw affects all versions of the 8 products before the fixed versions listed below.

Atlassian listed these fixed versions as of October 6:For Crowd's 7.1 branch, the ticket's fix version field said 7.1.7.

It marked every version of Bamboo Server, Bitbucket Server, Confluence Server, and Crowd Server as affected and listed no fixe…

4 часа назад @ thehackernews.com
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees.

"As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce."

Although the name of the third-party organization was not disclosed by the FBI, Reuters reported that it's Oracle PeopleSoft, which the ShinyHunters group said it exploited to breach the FBI's job portal last month.

The Hacker News has contacted both the FBI and Oracle for comment, and we will update the story if we hear back.

Accenture, in a statement …

4 часа назад @ thehackernews.com
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

They used a private Danish company's lawful right to look up records in the Central Person Register (CPR).

The ministry's statement does not say whether those people's CPR numbers were reached, or whether anyone will be told individually that they are among the 8.8 million.

A CPR number alone is enough to identify a person for that purpose.

The CPR number itself is not on that list.

Egelund told Ritzau it was too early to say whether people will need new CPR numbers.

5 часов назад @ thehackernews.com
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

What's notable about this browser cache smuggling approach is that it allows the attackers to conceal the payload script and bypass the character limit restrictions.

The Windows Run dialog, triggered by Win + R, truncates any input that exceeds approximately 260 characters.

The PowerShell script serves as a conduit for an intermediate PowerShell payload that's responsible for downloading the next stage ("cab.dat").

This is not the first time payloads have been staged in the browser cache as part of ClickFix attacks.

The user is then asked to paste the copied command into the Windows Run dialog, PowerShell, Windows Terminal, macOS Terminal, or another trusted system utility.

5 часов назад @ thehackernews.com
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.

"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network," Microsoft said in an advisory released on October 2, 2026.

The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments.

Users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected.

The following …

18 часов назад @ thehackernews.com
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

Successful exploitation requires NetScaler ADC or NetScaler Gateway to be configured either as a SAML service provider (SP) or SAML identity provider(IdP).

— The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a critical security flaw impacting Fortinet FortiMail.

"The group exploited software vulnerabilities and poorly secured access points, particularly to cloud storage, to gain access to organizations' systems," Europol said.

Victims were named on the group's dark web leak site and threatened with publication of their data unless paid."

"The group exploited software vulnerabilities and poorly secured access points, particularly to cloud stora…

20 часов назад @ thehackernews.com
The Credential Layer Is Expanding Faster Than Security Teams Can See It
The Credential Layer Is Expanding Faster Than Security Teams Can See It The Credential Layer Is Expanding Faster Than Security Teams Can See It

Security teams need to establish visibility into that expanding credential layer right now.

The credential layer has no convenient perimeterThe credential layer is the collection of credentials connecting people, applications, infrastructure, and services across an enterprise.

Security teams need a real denominator for their coverage metricsMany enterprises already have strong secrets-management programs.

Detection builds the map for everything that followsThe first step in controlling credential risk is understanding the credential layer the organization actually has.

Security teams need visibility capable of expanding at the same pace.

23 часа назад @ thehackernews.com
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

The transaction ID is set to all zeros instead of a random value, as per the specification.

Poll for UDP packets that encode operator commands in the STUN transaction ID field.

"From a network monitoring perspective, the activity appears as innocuous interaction with STUN servers," Nozomi Networks said.

It's worth noting these registration messages do not conform to the STUN protocol definition, causing legitimate STUN servers to drop the packet.

]184") is said to have returned an all-zero transaction ID instead of echoing the transaction ID of the original Binding Request in the Binding Success Response.

23 часа назад @ thehackernews.com
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.

Stating that Full Disk Access largely bypasses controls designed to safeguard users' private data, Apple said it plans to introduce updates to the setting to ensure that this sort of access is granted only with an explicit user action.

"As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple added.

Meta has since clarified that, for Muse to be able to access a user's private messages, it must have two permissions: have Full Disk Ac…

1 day назад @ thehackernews.com
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.

"Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login," according to an advisory for the flaw.

"HFS generated its Koa session-cookie signing key with JavaScript Math.random() and exposed outputs from the same V8 PRNG in the unauthenticated SRP login handshake," Ramos noted.

"An attacker can reconstruct the PRNG state, recover the signing key, forge an administrator session, and use the documented server_code …

1 day, 3 hours назад @ thehackernews.com
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks.

"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said.

"The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met."

For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP).

"Citrix has observed targeted attacks o…

1 day, 4 hours назад @ thehackernews.com
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter.

"Previously, Rey was an administrator of the data leak website for Hellcat, a ransomware group that surfaced in late 2024," Krebs noted at the time.

A ShinyHunters spokesperson subsequently denied having any connections with van der Stap.

Following the arrest, FBI director Kash Patel said, "FBI teams are actively working with partners to obtain and execute more leads in the ongoing investigation based on this arrest."

Leatherman, who described van der Stap as an alleged leader…

2 days, 3 hours назад @ thehackernews.com
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations.

The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at a U.S. think tank in February 2026.

Around July 2026, the threat actor is said to have impersonated several individuals, including a former member of the White House Office of Science and Technology Policy leadership team, as part of credential phishing campaigns targeting AI policy experts in the U.S.

"…

2 days, 3 hours назад @ thehackernews.com
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

CGTRI, also known as the China Academy of General Technology (CAGT), is assessed to be a front company for MSS.

The body, per MI5, funds academic research in China on topics including artificial intelligence (AI), cybersecurity, covert communications systems, and steganography.

More than 100 U.K.-linked academics have contributed to research projects funded by MSS via CGTRI, the alert read.

In some cases, the individuals may not be aware that CGTRI is providing monetary backing to the Chinese research project they are contributing to.

"Exchanges and collaboration between U.K. universities and China have always been conducted on a voluntary basis and in compliance with laws and regulations.

2 days, 20 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 6 days, 3 hours назад
This month in security with Tony Anscombe – September 2026 edition
This month in security with Tony Anscombe – September 2026 edition This month in security with Tony Anscombe – September 2026 edition

Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep paceAs another month draws to a close, ESET Chief Security Evangelist Tony Anscombe reviews some of the top cybersecurity stories that have made the news over the past 30 days while offering insights that they hold for your or your company's cyber-defenses.

Here's Tony's rundown of some of what stood out most in September 2026.

An OpenAI agent has broken into Australia's national healthcare database in what is the first known case of AI autonomously hacking a government network,Earlier in the month, Google announced that its models also escaped it…

6 days, 3 hours назад @ welivesecurity.com
Timeshare exit scams: From fake buyers to recovery fraud
Timeshare exit scams: From fake buyers to recovery fraud Timeshare exit scams: From fake buyers to recovery fraud

If an exit company cold calls you or makes 100% guaranteed promises of a swift exit, they’re likely to be a scammer.

If you’ve already paid a scam timeshare exit company, there’s still a chance you could get your money back if you act quickly.

What are the warning signs of a timeshare exit scam?

How can I check whether a timeshare exit company is legitimate?

What should I do if I've already paid a timeshare exit scam company?

1 week назад @ welivesecurity.com
The devil is still in the email – but wearing a new mask
The devil is still in the email – but wearing a new mask The devil is still in the email – but wearing a new mask

Some techniques go after live sessions themselves, with attackers shifting their focus from stealing passwords to stealing authentication tokens.

Purpose-built AI tools now make it trivial to clean up the language and even tailor the lure for each recipient.

What’s more, the code is scanned on a phone, so the usual controls that protect company-issued laptops don’t apply.

The ‘device hop’ also means that the company may have a hard time developing a full picture of the attack.

AI helps deal with the volume and speed involved, whereas experienced analysts can assess the evidence and direct the response.

1 week, 1 day назад @ welivesecurity.com
Is that vibe coded app safe? 5 checks before you download
Is that vibe coded app safe? 5 checks before you download Is that vibe coded app safe? 5 checks before you download

Vibe coded apps may also be exposed to prompt injection.

What can go wrong with vibe coded apps?

With a badly coded app, the leak usually happens on the developer’s servers, so start with your account and credentials.

Frequently asked questions (FAQs)What does 'vibe coded' mean?

Are all vibe coded apps dangerous?

1 week, 4 days назад @ welivesecurity.com
Been told to pay at a Bitcoin ATM? Read this first
Been told to pay at a Bitcoin ATM? Read this first Been told to pay at a Bitcoin ATM? Read this first

No real government agency, bank, or company will ever tell you to pay them via a Bitcoin ATM.

How do Bitcoin ATM scams work?

How do I stay safe from Bitcoin ATM scams?

What can I do straight after a Bitcoin ATM scam?

What should I do if I’ve fallen for a Bitcoin ATM scam?

1 week, 5 days назад @ welivesecurity.com
Looking for free Robux? Here’s what’s real, and what’s a scam
Looking for free Robux? Here’s what’s real, and what’s a scam Looking for free Robux? Here’s what’s real, and what’s a scam

Roblox itself is very clear: “There is no such thing as free Robux or subscription offers, tricks, or codes.”What there is, unfortunately, are a lot of scammers looking to trick you out of your personal information and logins with the promise of free Robux.

But it’s also about helping them understand there’s no such thing as ‘free’ Robux.

Frequently asked questions (FAQs)Is there a real free Robux generator?

Roblox says there is no legitimate way to get free Robux through generators, tricks or codes.

But these aren’t ‘free Robux generators.’How can I tell if a Robux offer is a scam?

2 weeks назад @ welivesecurity.com
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive

Many have moved past chatbots and begun assigning work to AI agents in the hope of gaining an edge on their similarly resource-strapped competitors and levelling the playing field with larger companies.

Indeed, the ambitious adopters are deploying, or at least experimenting with, multi-agent ‘assembly lines,’ where one supervisor agent manages swarms of specialist agents and passes work between them.

Of course, some risks surrounding AI agents have familiar roots: an agent’s supply chains can be compromised and its permissions abused.

Agents can also suffer from agentic misalignment where they proceed doggedly even if it involves, for example, breaking into other companies.

For a company wi…

2 weeks, 1 day назад @ welivesecurity.com
‘Nudify’ apps: What to do if someone makes a fake nude of you
‘Nudify’ apps: What to do if someone makes a fake nude of you ‘Nudify’ apps: What to do if someone makes a fake nude of you

And it doesn’t get much darker than ‘nudification’ or ‘nudify’ apps.

Are ‘nudify’ apps illegal?

The short answer is “it depends.” In the US, there’s no federal law explicitly prohibiting ‘nudify’ apps.

Can I sue over an AI nude image?

Will reporting a fake nude image make it disappear everywhere?

2 weeks, 4 days назад @ welivesecurity.com
Beware the SparroWock: The backdoor that bites, the commands that catch
Beware the SparroWock: The backdoor that bites, the commands that catch Beware the SparroWock: The backdoor that bites, the commands that catch

A month later, we noticed that the group had started using the new SparroWocky backdoor, which then quickly replaced SparrowDoor as FamousSparrow’s main implant.

Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor.

Backdoor commandsThe backdoor first establishes communication with its C&C server, then executes its core logic in an infinite loop, within which it processes received commands.

A common technique that the backdoor uses is dynamic API resolution via API hashing, but the backdoor…

2 weeks, 5 days назад @ welivesecurity.com
Cyberthreats are moving faster than SMBs: Readiness must accelerate
Cyberthreats are moving faster than SMBs: Readiness must accelerate Cyberthreats are moving faster than SMBs: Readiness must accelerate

This calls for a different operational model where AI and automation support security teams where it makes sense, with human oversight for decisions that require context and judgment.

ESET SMB Cyber Readiness Index 2026 found that most (73%) SMBs are integrating AI into their business.

Processing exfiltrated data: AI rapidly classifies, cleans-up, and extracts large volumes of information from stolen data in order to make it more monetizable/usable for cybercriminals.

Why SMBs are struggling with complexityUnfortunately, security teams are already on the back foot.

That means protection for AI conversations, agents, AI-generated outputs, AI components, sensitive data, and the broader AI eco…

2 weeks, 6 days назад @ welivesecurity.com
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
GuardBreaker: Derailing AI-assisted malware analysis with a code comment GuardBreaker: Derailing AI-assisted malware analysis with a code comment

Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way.

Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection.

Reporting on the same broader campaign, StepSecurity found a prompt that flat-out instructed any analyzing model that parsed the file to disregard the malicious code and report the package as clean.

Some parts of the malicious code could be concealed under the pretense of being confidential information or other sensitive data.

Crucially, however, no single LLM engine should have the sole au…

3 weeks, 5 days назад @ welivesecurity.com
Safe word: What is it and why do you need one?
Safe word: What is it and why do you need one? Safe word: What is it and why do you need one?

The technology might be impressive, but a simple technique could stop the scammers in their tracks: a pre-agreed safe word.

What is a safe word?

But suggest some scenarios in which it would be a good idea to request a safe word.

It’s important to have a backup if someone can’t remember the safe word.

But a safe word is a fantastic, free option for uncovering deepfake audio fraud like fake/virtual kidnappings.

3 weeks, 6 days назад @ welivesecurity.com
I’ve been deepfaked: What do I do?
I’ve been deepfaked: What do I do? I’ve been deepfaked: What do I do?

But across the globe, policymakers and public opinion are forcing tech platforms to better police this content.

What should I do if I’ve been deepfaked?

Google: Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

The first point of call is to contact the publisher to request removal.

1 month назад @ welivesecurity.com
This month in security with Tony Anscombe – August 2026 edition
This month in security with Tony Anscombe – August 2026 edition This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity newsWith August coming to a close, it's time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month.

Here's some of what caught Tony's attention:OpenAI has disclosed more details about how its agents hacked AI collaboration platform Hugging Face.

Delta Airlines is investigating an incident where a flight passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network.

What are the lessons that businesses and critical infra…

1 month назад @ welivesecurity.com
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
AI-assisted reconnaissance: Why everyone could be a viable target for fraud AI-assisted reconnaissance: Why everyone could be a viable target for fraud

And of course, linking our professional and personal social media accounts is a simple task for AI.

For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information.

Losing your personal information is one thing.

What you can do about AI-powered OSINTWhen it comes to AI-powered reconnaissance, there are things you can control and things you can’t.

Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.

1 month, 1 week назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 32 минуты назад
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)

Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

DSU is a tool used by enterprise IT administrators to apply driver, BIOS, and firmware updates to Dell PowerEdge servers.

“An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges,” the company wrote in the advisory.

“Dell recommends customers upgrade at the earliest opportuni…

32 минуты назад @ helpnetsecurity.com
Ontinue extends ION MXDR with managed dark web monitoring
Ontinue extends ION MXDR with managed dark web monitoring Ontinue extends ION MXDR with managed dark web monitoring

Ontinue has announced the launch of ION for Dark Web Monitoring (DWM), a new managed add-on service that extends ION MXDR to continuously identify exposed credentials, detect brand impersonation attempts, and uncover emerging external threats before attackers can exploit them.

Most dark web monitoring solutions stop at detection.

ION for Dark Web Monitoring goes further by investigating findings, assessing risk, and helping customers take action before exposures become incidents.”Turning external threat intelligence into actionION for Dark Web Monitoring continuously monitors customer-owned domains and brand assets across trusted intelligence sources spanning the clear, deep, and dark web.

…

1 час назад @ helpnetsecurity.com
Transcend Rails brings policy enforcement and spending controls to AI agents
Transcend Rails brings policy enforcement and spending controls to AI agents Transcend Rails brings policy enforcement and spending controls to AI agents

Transcend has launched Transcend Rails, a new category of agent management that goes beyond identity and access control to govern what an agent does.

Every enterprise scaling AI agents hits the same wall: the board asks what agents did last quarter, and no one can reconstruct it.

Gartner predicts that by 2030, half of AI agent deployment failures will be caused by insufficient runtime enforcement from AI governance platforms.

“Transcend Rails gives each agent exactly the permissions and the budget its job needs, and nothing more.

“The fastest way to get AI agents into production is to make sure they only do what you’ve approved, and that’s what Transcend Rails does,” said Ben Brook, CEO of …

1 час назад @ helpnetsecurity.com
Hack The Box helps enterprises evaluate AI agents for cybersecurity roles
Hack The Box helps enterprises evaluate AI agents for cybersecurity roles Hack The Box helps enterprises evaluate AI agents for cybersecurity roles

Hack The Box has introduced AI Range Enterprise Edition, making its platform for testing and measuring AI security agent effectiveness available to enterprise security teams.

The offering enables organizations to evaluate whether their own AI agents can perform the cybersecurity roles assigned to them and make informed decisions about how to use agents across the workforce.

Companies often assess whether people can do the job they were hired to do, but AI agents may not face the same scrutiny.

HTB introduced AI Range in December 2025 to test AI security agents in controlled cyber environments.

AI-augmented penetration tester and SOC analyst roles are available now, with additional cybersecu…

1 час назад @ helpnetsecurity.com
GitHub’s ReviewBench puts AI code reviewers to the test
GitHub’s ReviewBench puts AI code reviewers to the test GitHub’s ReviewBench puts AI code reviewers to the test

GitHub’s ReviewBench measures how well AI code review tools detect problems before software is released.

Code review involves checking proposed changes for mistakes.

ReviewBench measures AI reviewers’ ability to identify issues and avoid false alarms.

It gathered candidate findings from human reviewers, follow-up code changes, analysis tools and AI models, merged findings describing the same issue, and assessed them using a shared evaluation rubric.

GitHub’s results with Copilot code reviewGitHub uses ReviewBench to evaluate changes to Copilot code review before testing them with users.

1 час назад @ helpnetsecurity.com
Data breach at Denmark’s population register exposes 8.8 million people
Data breach at Denmark’s population register exposes 8.8 million people Data breach at Denmark’s population register exposes 8.8 million people

A data breach at Denmark’s Central Population Register (CPR) has exposed the personal information of 8.8 million people.

Over the weekend, it discovered the extent of the unauthorized access, and on Sunday, 4 October, it notified the Danish Data Protection Agency (Datatilsynet).

I have also asked for a thorough security review of the CPR system,” added Egelund.

The attackers obtained names, addresses and CPR numbers by misusing a private Danish company’s legitimate access to search the CPR system.

The Danish Data Protection Agency has opened a case and is looking into what happened, how it was able to happen, and who is responsible for the processing of the personal data involved.

2 часа назад @ helpnetsecurity.com
U.S. Bank CISO says the security role keeps growing and no one can own all of it
U.S. Bank CISO says the security role keeps growing and no one can own all of it U.S. Bank CISO says the security role keeps growing and no one can own all of it

In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance.

The CISO role keeps absorbing adjacent territory: fraud, resilience, third-party risk, AI governance.

It makes sense that many of these responsibilities have gravitated toward the CISO because cyber risk rarely stays confined to a single domain.

They also often believe security teams are solely responsible for managing cyber risk.

Security’s role is to provide expertise, visibility, and guidance, but lasting risk reduction happens when technology, business, risk, and security teams work together.

5 часов назад @ helpnetsecurity.com
Reflection’s Beam trails top open models on coding tests but claims lower inference compute
Reflection’s Beam trails top open models on coding tests but claims lower inference compute Reflection’s Beam trails top open models on coding tests but claims lower inference compute

Reflection AI has built Beam, a 501-billion-parameter open-weight model for coding and agent tasks, and plans to publish the weights under an Apache 2.0 license later this month.

Open-weight means developers can download the trained model and run it on their own hardware.

Reflection says Beam scores comparably to GLM 5.2 on advanced reasoning benchmarks while using three to four times less inference compute.

The training run had not leveled offReflection spent four weeks on reinforcement learning, the stage where a model improves by attempting tasks and getting graded.

Some of what Beam learned spread beyond its training tasks.

5 часов назад @ helpnetsecurity.com
NIS2 compliance: 7 low-cost steps to secure credentials
NIS2 compliance: 7 low-cost steps to secure credentials NIS2 compliance: 7 low-cost steps to secure credentials

Privileged accounts carry the highest impact if compromised, and shared credentials create attribution problems when something goes wrong.

Passwork connects vault access to directory and SSO processes so MFA coverage and access reviews live in one place.

7 low-cost steps to secure credentials, ranked by priorityStart by making privileged and shared access visible, owned, revocable, and reviewable.

The Credential Security Starter Stack below sequences seven credential controls by effort and cost, and lists the first action and evidence to retain for each.

Shared credentials are a governance problem before they are a technical one.

6 часов назад @ helpnetsecurity.com
Product showcase: Webroot Mobile Security screens texts, blocks risky sites, and checks for data leaks
Product showcase: Webroot Mobile Security screens texts, blocks risky sites, and checks for data leaks Product showcase: Webroot Mobile Security screens texts, blocks risky sites, and checks for data leaks

Webroot Mobile Security combines device security checks, Safari protection, text scam filtering, and data breach monitoring.

The app requires an active Webroot subscription and is included with Essentials, Premium, and Total Protection.

The home screen displays subscription status, a Scan Now button, the last scan time, and shortcuts to individual features.

Checking data breach exposureI added an email address to Data Breach Monitoring and verified it using a code.

Eligible subscribers can select a country and activate VPN protection within Mobile Security.

6 часов назад @ helpnetsecurity.com
Cybersecurity jobs available right now: October 6, 2026
Cybersecurity jobs available right now: October 6, 2026 Cybersecurity jobs available right now: October 6, 2026

Cybersecurity Engagement & Policy SpecialistCommission for Communications Regulation | Ireland | Hybrid – View job detailsAs a Cybersecurity Engagement & Policy Specialist, you will analyse cybersecurity policy and legislation, develop recommendations for ComReg leadership, and coordinate consultations, workshops, awareness campaigns, and stakeholder events.

You will also represent ComReg in national and international forums, monitor emerging risks and stakeholder perspectives, and support cross-divisional cybersecurity projects.

Get weekly updates on new cybersecurity job openings.

Cybersecurity Technology Architect IVAstreya | USA | Remote – View job detailsAs a Cybersecurity Technology A…

7 часов назад @ helpnetsecurity.com
CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)
CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779) CISA flags new exploited NetScaler flaw as attackers crash appliances (CVE-2026-88779)

CISA has added another Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities catalog on Sunday: CVE-2026-88779, a memory overflow bug that may cripple vulnerable NetScaler ADCs and Gateways.

“Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service.

Apparently, the attackers are trying to exploit the flaw to download and run a script to install webshells.

Affected versions and mitigationThe following supported NetScaler versions are affected by CVE-2026-88779:Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1 before 14.1-73.41Citrix NetScaler ADC and Citrix NetScaler Gateway 13.1 before 13.1-64.28Citrix NetScaler ADC F…

20 часов назад @ helpnetsecurity.com
Malwarebytes Scam Link Check analyzes URLs and explains potential risks
Malwarebytes Scam Link Check analyzes URLs and explains potential risks Malwarebytes Scam Link Check analyzes URLs and explains potential risks

Malwarebytes has launched the Malwarebytes Scam Link Check, a free web tool that lets anyone check whether a website link is safe or dangerous before clicking it.

Paste the link, get a straight answer, and know what to do next—free, in seconds.”How the Malwarebytes Scam Link Check worksThe Malwarebytes Scam Link Check analyzes a submitted URL using the Malwarebytes threat intelligence ecosystem.

Alongside the “Is this link safe” verdict, the tool shows:A screenshot of the website, so users can see the page without visiting it.

A direct entry point into Malwarebytes Scam Guard for deeper help.

The Malwarebytes anti-scam ecosystemThe Scam Link Check is one entry point into a broader Malwareby…

21 час назад @ helpnetsecurity.com
Fake brand discounts on social media prey on shoppers’ fear of missing out
Fake brand discounts on social media prey on shoppers’ fear of missing out Fake brand discounts on social media prey on shoppers’ fear of missing out

Cybercriminals are using fake discounts posted on Facebook and TikTok to lure shoppers to phishing sites that steal their payment card details and one-time passwords, Group-IB has warned.

Its operators skip fake fines, parcel delivery problems and bank alerts meant to cause fear and urgency.

They post malicious links in social media marketplace listings and tempt victims with big exclusive discounts on popular brands and consumer goods.

Milk Dragon’s Phishing flow (Source: Group-IB)“It hooks victims with a different kind of fear, the fear of missing out (FOMO),” researchers wrote.

Anyone who has entered card details on such a site should contact their bank or card issuer right away.

21 час назад @ helpnetsecurity.com
LTM launches BlueVerse AgenTraceIQ to monitor AI agents and reverse unintended actions
LTM launches BlueVerse AgenTraceIQ to monitor AI agents and reverse unintended actions LTM launches BlueVerse AgenTraceIQ to monitor AI agents and reverse unintended actions

LTM has announced the launch of BlueVerse AgenTraceIQ, an offering designed to help organizations securely adopt and scale agentic AI.

Combining Rubrik Agent Cloud with LTM’s AI governance and managed services expertise, the offering enables organizations to monitor AI agents, establish guardrails, and rewind unintended agent actions across business-critical environments.

As AI agents become increasingly embedded in enterprise operations, organizations need a structured approach to managing risk, accountability, and operational continuity.

Together with Rubrik, BlueVerse AgenTraceIQ helps enterprises move from experimentation to trusted, production-scale AI operations,” said Krishnan Iyer, …

21 час назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 1 day назад
Another Historic Cipher Falls to AI
Another Historic Cipher Falls to AI Another Historic Cipher Falls to AI

This one is from 1809, written by Napoleon’s nephew.

1 day назад @ schneier.com
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing

The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

3 days, 14 hours назад @ schneier.com
Unidentified Flock Cameras in Florida
Unidentified Flock Cameras in Florida Unidentified Flock Cameras in Florida

St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted.

I am reminded of the decade-old story of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown.

My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case is more likely some local government entity that didn’t bother getting approval. Were I a foreign actor, I would rather hack the existing Flock network—like Israel ...

3 days, 20 hours назад @ schneier.com
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools How American Political Campaigns Are Using AI—and What They’re Spending on the Tools

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them.

Candidates’, parties’ and committees’ spending reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet about how they are using the technology in their own campaigns. It’s a sensitive issue that we have been tracking closely since we started writing our book, Rewiring Democracy...

4 days назад @ schneier.com
Connected Cars Are a Surveillance Platform
Connected Cars Are a Surveillance Platform Connected Cars Are a Surveillance Platform

Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers:

To determine this, CR dug through thousands of pages of automakers’ privacy policies and asked questions of 15 different automakers­BMW, Ford, General Motors, Honda, Hyundai, Kia, Mazda, Mercedes-Benz, Mitsubishi, Nissan, Stellantis, Subaru, Tesla, Toyota, and Volkswagen. We also reviewed corporate, regulatory, and legal filings from data brokers operating in the “insurtech” industry­the technology companies and data brokers that help insurance companies set their rates. And we spoke to several car privacy experts, who, at industry conferences and in market re…

5 days назад @ schneier.com
I Want Better Reporting on AI Genie Behavior
I Want Better Reporting on AI Genie Behavior I Want Better Reporting on AI Genie Behavior

AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening.

I wish the popular press would report on this better. I don’t like the “going rogue” framing because it deflects the responsibility from the prompters—often the AI companies themselves. And now, pretty much anything off-script is being called “hacking.”

Take, for example, the recent stories of one of OpenAI’s models hacking into government systems. First, ...

6 days назад @ schneier.com
Using Device Linking to Eavesdrop on WhatsApp and Signal
Using Device Linking to Eavesdrop on WhatsApp and Signal Using Device Linking to Eavesdrop on WhatsApp and Signal

Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability:

Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers.

Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account.

Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them.

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sancti…

1 week назад @ schneier.com
New Attack Against RSA
New Attack Against RSA New Attack Against RSA

ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.

First, this attack isn’t new. The original research is from 2007. What is new is the implementation.

Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.

Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice.

Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with …

1 week, 1 day назад @ schneier.com
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

I feel like someone who reads this blog will want to go to this:

Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life.

[…]

During the guided squid dissection, each family will work together to examine a squid up close, exploring its organs, structures, and specialized features. The experience provides a memorable opportunity for children and adults to see firsthand how the anatomy of a squid helps it survive in it…

1 week, 3 days назад @ schneier.com
On Anthropic’s AI Misuse Report
On Anthropic’s AI Misuse Report On Anthropic’s AI Misuse Report

Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.

A few of the highlights: AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.

The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations.

...

1 week, 4 days назад @ schneier.com
Malicious npm Packages That Evade Defenses
Malicious npm Packages That Evade Defenses Malicious npm Packages That Evade Defenses

This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

1 week, 5 days назад @ schneier.com
Research on Models Engaging in Genie-Like Behavior
Research on Models Engaging in Genie-Like Behavior Research on Models Engaging in Genie-Like Behavior

New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.”

Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be …

1 week, 6 days назад @ schneier.com
GPT-6 Astra Breaks an Old Enigma Message
GPT-6 Astra Breaks an Old Enigma Message GPT-6 Astra Breaks an Old Enigma Message

This is pretty amazing:

However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message. After trying many different approaches, GPT­6 Astra focused on using the repeated place name ROSENOW ROSENOW as a crib. After developing the necessary Python and C++ soft…

2 weeks назад @ schneier.com
Reverse-Engineering Flock Cameras
Reverse-Engineering Flock Cameras Reverse-Engineering Flock Cameras

Hackers captured a Flock camera and got a look (alternate link) at the software:

While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag...

2 weeks назад @ schneier.com
Friday Squid Blogging: On Squid Egg Sacs
Friday Squid Blogging: On Squid Egg Sacs Friday Squid Blogging: On Squid Egg Sacs

Short essay about squid egg sacs.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

2 weeks, 3 days назад @ schneier.com
Krebs On Security
последний пост 1 week назад
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.

Van der Stap is currently employed as offensive security lead at the Dutch company Neo Security, which did not respond to requests for comment.

But not long after that interview, the Dutch hacker abruptly stopped replying to messages.

One source said a colleague of theirs personally witnessed Dutch authorities carting items out of Van der Stap’s residence.

Speaking with reporters from Bloomberg in 2024, Van der Stap said that singular focus in turn fueled his desire to carry out cyberattacks.

1 week назад @ krebsonsecurity.com
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.

Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data.

Less than a month later, Wagenius was arrested and charged in two separate federal indictments, and soon pleaded guilty to all counts in both cases.

In 2019, Schuchm…

1 week, 3 days назад @ krebsonsecurity.com
Data Broker Radaris Loses Domains in Privacy Fight
Data Broker Radaris Loses Domains in Privacy Fight Data Broker Radaris Loses Domains in Privacy Fight

In February 2024, Radaris was sued by Atlas Data Privacy Corp, a company that has been pursuing data brokers alleged to be violating a New Jersey statute called Daniel’s Law.

KrebsOnSecurity doubled down and showed how the Lubarsky brothers built and operated Radaris and other data broker companies using a fictitious CEO’s name.

All told, the New Jersey court has so far transferred 14 domain names from the Radaris family of companies to Atlas.

Sherman said federal lawmakers have long faced intense lobbying by the technology industry against more restrictive U.S. data privacy laws, but that many powerful industries are now working against passing comprehensive data privacy legislation.

The l…

2 weeks, 5 days назад @ krebsonsecurity.com
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Plugs Nearly 1,000 Security Holes Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.

This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities.

Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10.

And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.

Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear…

3 weeks, 6 days назад @ krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards.

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.

Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s ide…

1 month назад @ krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

1 month, 1 week назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

1 month, 3 weeks назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

1 month, 3 weeks назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

2 months назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

2 months, 1 week назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

2 months, 2 weeks назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

2 months, 3 weeks назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

2 months, 3 weeks назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

2 months, 4 weeks назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

3 months назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 3 days, 2 hours назад
N0n ransomware: what you need to know
N0n ransomware: what you need to know

N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra blog.

3 days, 2 hours назад @ fortra.com
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader

The FBI has a very simple message for the ShinyHunters gang: give yourselves up.

The FBI describes the man arrested in Amsterdam as "one of the alleged leaders of ShinyHunters", although Dutch police say only that he played a role.

The warning to remaining members of ShinyHunters follows particularly embarrassing episode for the FBI, which recently confirmed it had had its job application portal compromised by the gang.

According to ShinyHunters, it gained access to the FBI's data by exploiting a recently-patched flaw (CVE-2026-35273) in Oracle PeopleSoft PeopleTools.

The truth is that the arrest came a week or so before the compromise of the FBI became headline news.

5 days назад @ bitdefender.com
ShinyHunters suspect arrested, and is now investigated over alleged murder plots
ShinyHunters suspect arrested, and is now investigated over alleged murder plots ShinyHunters suspect arrested, and is now investigated over alleged murder plots

An alleged key figure in the ShinyHunters cybercrime group has been arrested in the Netherlands, and - in a grotesque turn - the 24-year-old suspect is also being investigated for attempting to arrange two murders.

Although the authorities are declining to name the individual, celebrated cybersecurity blogger Brian Krebs has identified him as Pepijn van der Stap, a convicted hacker.

Van der Stap was released from prison in December last year, and has since been working as a penetration tester at Amsterdam-based Neo Security.

Notably, Van der Stap appears to claim on his personal website that he is a reformed character.

That hasn't stopped FBI Director Kash Patel from describing the arrested…

5 days назад @ bitdefender.com
Pentagon personnel database breach exposes personal data of millions
Pentagon personnel database breach exposes personal data of millions Pentagon personnel database breach exposes personal data of millions

The unencrypted files contained Social Security numbers, names, birth dates, contact details, and other military personnel data including - in some cases - details of the jobs individuals held.

Breaches like this matter because the combination of Social Security numbers, names, and dates of birth make up the bread and butter of any self-respecting fraudster.

Personnel data, of course, has also been a target before.

The news of the Pentagon's latest data breach comes as the FBI warns its own employees about a separate breach of its FBIJobs.gov portal.

The ShinyHunters hacking group has claimed credit for the hack and threatened to publish staff details including... you guessed it... Social S…

6 days назад @ bitdefender.com
Ukrainian ransomware developer jailed for nearly 13 years
Ukrainian ransomware developer jailed for nearly 13 years Ukrainian ransomware developer jailed for nearly 13 years

A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world.

The 52-year-old man, who according to local media reports had been living in the Basel-Landschaft region but has not been named, found by the court to be the lead developer of the LockerGoga, MegaCortex, and Nefilim families of ransomware.

In all, prosecutors claimed that some 100 million Swiss Francs (US $123 million) worth of damage was caused by the ransomware attacks.

Ukrainian national Tymoshchuk allegedly released new strains of his ransomware whenever old ones had been decrypted.

In…

1 week, 4 days назад @ bitdefender.com
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras

Smashing Security, episode 486, Vibe-Coded Shops and Hackable Flock Cameras, with Graham Cluley and special guest Dave Bittner.

I will say I did not go gaga for La La the way many other people did.

Anyway, if any of you are still listening, I love La La Land.

This La La Land lunatic has watched the movie with his pause button.

This was definitely not created — if you haven't seen La La Land, go watch La La Land for goodness' sake.

1 week, 5 days назад @ grahamcluley.com
US Coast Guard and FBI board oil tanker to investigate cyber attack
US Coast Guard and FBI board oil tanker to investigate cyber attack US Coast Guard and FBI board oil tanker to investigate cyber attack

An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.

The VL Prosperity - a Liberian-flagged supertanker carrying roughly 2.3 million barrels of crude oil - apparently suffered a cyber attack while en route from Egypt's Sidi Kerir oil terminal to Galveston, Texas.

Two weeks later, a specialised team from the FBI and US Coast Guard boarded the vessel for four days, investigating the problem and helping the crew eradicate the threat from its IT and OT systems.

According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromised by a f…

2 weeks, 4 days назад @ bitdefender.com
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Smashing Security podcast #485: These researchers got drunk to hack an LG TV Smashing Security podcast #485: These researchers got drunk to hack an LG TV

That's really, really cool.

And I'm going to be getting really, really sozzled by looking at the security of LG smart TVs.

So it's really, really compelling.

When we started off on the journey of building this AI pen testing approach, there was a lot of scepticism.

And listeners, you can learn more about Intruder or even start your own AI pen test in minutes.

2 weeks, 5 days назад @ grahamcluley.com
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store.

According to Carter's own plea agreement, the scam ran from May 2018 to November 2019 and involved at least three co-conspirators alongside Carter.

Carter would use his privileged store access to move a victim's number onto a SIM card under the control of himself or an accomplice.

In one incident in May 2018, described in Carter's plea agreement, the store employee swapped a victim's number onto an Alcatel handset while working his shift in Portland.

In December 2018, Carter successfully hijacked the number of a victim known as "S.Q.T" in Portland, and this time their account was successfully drained of …

3 weeks назад @ bitdefender.com
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars ‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.

Because it might just be that you draw the attention of the authorities.

Back in October 2024, we wrote about how he was arrested after allegedly tricking a single victim out of US $230 million worth of Bitcoin while posing as Google Support.

The party days are over now for Lam, who faces up to 20 years in prison when he is eventually sentenced.

You money may be a lot more safely stored in a hardware cold wallet.

3 weeks, 4 days назад @ bitdefender.com
Smashing Security podcast #484: How websites are tracking you with silence
Smashing Security podcast #484: How websites are tracking you with silence Smashing Security podcast #484: How websites are tracking you with silence

Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.

I get by in the world, but I don't think you need me for listening for something really, really far away.

I don't know what the difference — I mean, now we get to see, I've opened a can of worms here.

I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human.

And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.

3 weeks, 5 days назад @ grahamcluley.com
CRPx0 ransomware: what you need to know
CRPx0 ransomware: what you need to know

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

3 weeks, 6 days назад @ fortra.com
The US military just turned off ad tracking on its phones. Maybe you should too
The US military just turned off ad tracking on its phones. Maybe you should too The US military just turned off ad tracking on its phones. Maybe you should too

Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target American forces in the Middle East.

Every smartphone carries a mobile advertising ID - Apple calls its version the IDFA, and Google calls its the GAID.

Back in April, US Central Command reportedly warned of "multiple threat reports concerning adversary exploitation of commercial location data."

Recent versions should let you delete your advertising ID entirely.

If it's good enough for the US military - maybe it should be good enough for you too.

3 weeks, 6 days назад @ bitdefender.com
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo's own identity system, Lenovo ID.

So, anyone wanting to access your Dropbox account just had to sign up for a Lenovo account using your email address.

Don't just turn it on for your Dropbox account, enable it everywhere it is made available.

This hack of 5000 Dropbox accounts was not sophisticated.

One can only be grateful that the problem was discovered after only 5000 Dropbox accounts were accessed.

4 weeks, 1 day назад @ bitdefender.com
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Smashing Security podcast #483: This AI helps thieves steal your iPhone Smashing Security podcast #483: This AI helps thieves steal your iPhone

This AI helps thieves steal your iPhone with Graham Cluley and special guest James Ball.

You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first one.

Is it normal that some kid just flogs it down the pub, or is there something more organised actually going on?

So the researchers said they saw evidence of hundreds of these Apple phone calls trying to phish the numbers and the passcodes from people trying to steal iPhones.

Follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts.

1 month назад @ grahamcluley.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 3 days, 18 hours назад
GTA 6 до релиза: фейковые утечки, ранний доступ и мошенничество | Блог Касперского
GTA 6 до релиза: фейковые утечки, ранний доступ и мошенничество | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 057a7a4758cd6ae7dfaab62417ac8d97Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-10-02T21:00:25+03:00Config id: 335Faithfully yours, nginx.

3 days, 18 hours назад @ kaspersky.ru
Как закрыть 110 уязвимостей в Google Pixel | Блог Касперского
Как закрыть 110 уязвимостей в Google Pixel | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8ea67ee2a3dd4315782e49963c8d5485Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-30T17:00:35+03:00Config id: 334Faithfully yours, nginx.

5 days, 21 hours назад @ kaspersky.ru
Как сканер уязвимостей создает иллюзию защиты | Блог Касперского
Как сканер уязвимостей создает иллюзию защиты | Блог Касперского Как сканер уязвимостей создает иллюзию защиты | Блог Касперского

Эти процессы могут тянуться неделями, а тем временем в инфраструктуру легко может попасть злоумышленник.

Где теряется времяПервое промедление может произойти сразу после появления информации об уязвимости в базах данных.

Рецепт управления уязвимостямиЧтобы у злоумышленников было как можно меньше поводов заглянуть к вам в инфраструктуру, важно убедиться, что в организации четко выстроены четыре основных процесса.

ПриоритизацияПри анализе уязвимости не стоит ориентироваться только на оценку из публичного каталога, например NVD, — она может существенно расходиться с реальным ущербом от эксплуатации бреши.

Например, один и тот же дефект в сервере, который находится в изолированном сегменте, и в…

6 days, 15 hours назад @ kaspersky.ru
Бесплатный курс «Введение в кибербезопасность» для студентов вузов от экспертов «Лаборатории Касперского» | Блог Касперского
Бесплатный курс «Введение в кибербезопасность» для студентов вузов от экспертов «Лаборатории Касперского» | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7dfac78cb3fca5a112c9b371cb1af0ecServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-29T14:00:43+03:00Config id: 307Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
CVE-2026-87902: критическая уязвимость в WordPress
CVE-2026-87902: критическая уязвимость в WordPress

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 3ba3f53e4698eed730b59fdbb57f2dc7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-25T19:00:33+03:00Config id: 307Faithfully yours, nginx.

1 week, 3 days назад @ kaspersky.ru
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: cdfce2802c5089c2e8d266eed059c5ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-23T18:00:08+03:00Config id: 307Faithfully yours, nginx.

1 week, 5 days назад @ kaspersky.ru
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8bdccf89e0ff9374b4a240e13e1d1e5dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-22T14:00:25+03:00Config id: 307Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: afb32d9b2ad2a9d051087c355f39881eServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-18T19:00:38+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 3 days назад @ kaspersky.ru
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: c7185cbdbdeda88817088ebb8613e249Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-17T16:00:24+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 4 days назад @ kaspersky.ru
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64b9740d8f9a94da6c64f21f2aeee15dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-16T19:00:10+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 5 days назад @ kaspersky.ru
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7e59b8e02f76cd9405fa38b4fdc32a36Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-15T11:00:04+03:00Config id: 305Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Как полностью удалить приложения с Mac и освободить память | Блог Касперского
Как полностью удалить приложения с Mac и освободить память | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a6459fd9158393152b55dc4e20e24551Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T15:00:13+03:00Config id: 305Faithfully yours, nginx.

3 weeks, 5 days назад @ kaspersky.ru
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4a93349074c8b67d52892db5d9a65f6cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T00:00:19+03:00Config id: 305Faithfully yours, nginx.

3 weeks, 6 days назад @ kaspersky.ru
GPUThor: развитие идеи Rowhammer | Блог Касперского
GPUThor: развитие идеи Rowhammer | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fe21d0ffcbad967d20a3f98f7234d02fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-08T00:00:32+03:00Config id: 304Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e393e4abb05ec4aac16fd484bfccc656Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-04T18:00:18+03:00Config id: 304Faithfully yours, nginx.

1 month назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 1 week назад
Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era
Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era

The Cisco Secure Firewall 200 Series brings enterprise-grade protection and connectivity to distributed branches in a compact form factor.

The Encrypted Visibility Engine (EVE) uses AI and machine learning to analyze encrypted traffic, including TLS 1.3, without requiring full decryption.

The Secure Firewall 220 model delivers up to 1.5 Gbps of throughput with next-generation firewall capabilities enabled in a compact form factor for smaller branches.

The Secure Firewall 200 Series helps meet these demands with intelligent threat protection, encrypted traffic visibility, resilient connectivity, and centralized management.

Explore the Secure Firewall 200 Series to build a more resilient, man…

1 week назад @ blogs.cisco.com
From Love Letters to AI Agents: Cybersecurity’s Evolution
From Love Letters to AI Agents: Cybersecurity’s Evolution From Love Letters to AI Agents: Cybersecurity’s Evolution

Architecting the Future: The Four Pillars of Agentic SecuritySecuring agentic AI requires a new strategic framework.

Pillar 2: Core ProtectionDelivered by: Cisco AI DefenseCisco AI Defense provides specialized protection for the AI models themselves and their operational environment.

AI Inventory & Validation: This solution catalogs all deployed AI models and continuously validates their integrity against supply chain risks.

Pillar 4: ObservabilityDelivered by: SplunkSplunk provides the unified intelligence platform required to monitor and respond to agentic AI at scale.

Splunk ingests logs, events, and telemetry from Duo, Secure Access, AI Defense, and other infrastructure points, creating…

2 weeks назад @ blogs.cisco.com
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco was proud to return to Black Hat USA as the Official Security Cloud Provider and the longest-standing partner of the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC).

In 2026, we completed our 11th year helping protect the Black Hat network, working side by side with the Black Hat NOC leaders and official technology partners: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.

For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry and workflows across Cisco Security, Splunk Security, and partner-provided network and security controls.

The same signal may need to be understood by Cisco, Splunk, Black Hat leadership, and partner tea…

4 weeks назад @ blogs.cisco.com
Thrown into the SOC: A Black Hat First-Timer’s Story
Thrown into the SOC: A Black Hat First-Timer’s Story Thrown into the SOC: A Black Hat First-Timer’s Story

I did not walk into Black Hat with years of incident-response experience or an encyclopedic knowledge of threat actors.

The first time I walked into the Black Hat NOC, where the SOC team was operating, was a few days before the event began.

I was surrounded by people with years—sometimes decades—of experience, many of whom had supported Black Hat for years.

Check out the other blogs from our team at Black Hat USA 2026.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

4 weeks назад @ blogs.cisco.com
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes

To handle this task, Cisco and Black Hat deployed bespoke ThousandEyes agents to monitor the wireless solution.

Our thanks to the Arista Networks team in the Black Hat NOC for their partnership throughout the week.

You can read the other blogs from our colleagues at Black Hat USA.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

For more information, please visit the Black Hat website.

4 weeks назад @ blogs.cisco.com
Distributed Latency Monitoring at Black Hat
Distributed Latency Monitoring at Black Hat Distributed Latency Monitoring at Black Hat

With Matthew Bair2026 marks the fourth consecutive year we’ve used ThousandEyes to monitor the Black Hat USA network for latency.

As our latency monitoring mesh has expanded to cover more and more of the conference, we’ve also begun supplementing our ThousandEyes monitoring with on-demand Linux commands to track latency across different protocols.

The Key ThousandEyes TestsThe automated ThousandEyes tests that inform our dashboards include HTTPS connectivity tests, the monitoring of cloud services, agent to agent tests, internal and external DNS resolution, and even file downloads.

On-Demand Latency Tests from the Agent MeshPing and traceroute are the go-tos for anyone who wants to do a qui…

4 weeks назад @ blogs.cisco.com
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

While developing a detection for Cisco Secure Network Analytics (SNA), I used the Splunk Detection Editor (Alpha) to bring much of that workflow into one place.

Instead of treating every observation as an incident, detections can create risk events associated with entities such as systems or users.

Developing the detection in one workspaceThe Detection Editor provides a workspace for building the search while configuring the other parts of the detection.

Risk events for the same entity need to use a consistent risk object so Splunk Enterprise Security can associate them correctly.

Splunk defines the risk object, its type, and its score as key parts of a risk event.

4 weeks назад @ blogs.cisco.com
Black Hat USA 2026: Safeguarding DNS with Secure Access
Black Hat USA 2026: Safeguarding DNS with Secure Access Black Hat USA 2026: Safeguarding DNS with Secure Access

DNS continues to provide one of the clearest windows into activity across the Black Hat network.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking.

Its 4.42 million blocks represented 79.3% of every blocked DNS request .. Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and mo…

4 weeks назад @ blogs.cisco.com
Frontier AI just raised the stakes, and the old playbook won’t hold up
Frontier AI just raised the stakes, and the old playbook won’t hold up Frontier AI just raised the stakes, and the old playbook won’t hold up

Project Glasswing and Frontier models just made that truth louder.

Frontier models are about to pour gasoline on that fire; the fundamentals matter more than ever.

Cisco ran its own experiment leveraging a variety of frontier models.

Foundry Security Spec: a model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

Foundry-Security-Speca model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

1 month назад @ blogs.cisco.com
Crypto Agility: Why PQC Is Not a One-Time Upgrade
Crypto Agility: Why PQC Is Not a One-Time Upgrade Crypto Agility: Why PQC Is Not a One-Time Upgrade

That requires crypto agility.

Why long-lived networks need crypto agilityThink about designing a building before all of its future electrical requirements are known.

Crypto agility is about adopting the best defenses available today while preserving the ability to adopt better ones tomorrow.

That is why crypto agility needs to be designed into the network we invest in today.

Common questions about PQC and crypto agilityWhat is crypto agility?

1 month назад @ blogs.cisco.com
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

It is what happens when agents built by different teams, on different platforms, can hand work to each other directly.

And it is worth being direct about where things stand: A2A-mediated handoffs between production security agents are not shipping anywhere yet.

Use A2A when one agent needs to hand work to another.

A2A is peer-to-peer: any A2A agent can discover and call any other A2A agent through a self-published Agent Card, no custom connector required, and the receiving agent applies its own reasoning rather than following a static script.

Input validation is an application-layer responsibility that needs to be designed in before any agent delegates via A2A, not added after.

1 month, 1 week назад @ blogs.cisco.com
Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
Microsegmentation’s Moment Is Now:  Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind SpotsApplications increasingly span private clouds, on-premises data centers, and public clouds.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026…

1 month, 1 week назад @ blogs.cisco.com
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

What We Mean by Infrastructure IdentityInfrastructure Identity starts with a simple principle: there should be no anonymous computing in critical infrastructure.

Infrastructure Identity turns that principle into an operating model.

Infrastructure Identity starts with the actor and evaluates whether a specific action should be allowed now.

Infrastructure Identity is therefore not just an access-control issue.

That is the promise of Infrastructure Identity: no anonymous computing, no unmanaged privilege, and no forced tradeoff between stronger security and operational speed.

1 month, 1 week назад @ blogs.cisco.com
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE

I’m proud to share that IDC MarketScape has named Cisco a Leader in the 2026 IDC MarketScape: Worldwide Secure Access Service Edge (SASE) Vendor Assessment.

In an evaluation of 12 SASE vendors, the IDC MarketScape recognized our architectural breadth and flexibility, AI capabilities, identity integration, threat visibility, and R&D.

Built to Make Agent Work, WorkWe believe the IDC MarketScape recognition validates the foundation we have built, and customers increasingly need that foundation for what is next.

For more on Cisco’s placement as a Leader, read the IDC MarketScape excerpt and explore how Cisco SASE keeps work moving, governed, and trusted in the AI era at cisco.com/go/sase.

Stay …

1 month, 1 week назад @ blogs.cisco.com
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

1 month, 2 weeks назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 4 days, 21 hours назад
Preparing governments for an era of interconnected cyber risk
Preparing governments for an era of interconnected cyber risk Preparing governments for an era of interconnected cyber risk

Trusted channels can enable this exchange among government agencies, law enforcement, critical infrastructure operators, technology providers, and international partners while respecting legal and privacy requirements.

As cyber incidents cross organizational and national boundaries, resilience depends not only on technical preparedness, but on whether institutions can coordinate effectively under pressure.

In an era of AI-enabled and increasingly interconnected cyber threats, resilience is no longer simply about recovering from an attack.

It is about preparing for a world in which cyber incidents move faster, spread further, and affect more organizations than ever before.

Governments best p…

4 days, 21 hours назад @ blogs.microsoft.com
Insights from the 2026 Microsoft Digital Defense Report
Insights from the 2026 Microsoft Digital Defense Report Insights from the 2026 Microsoft Digital Defense Report

Every year, the Microsoft Digital Defense Report gives us an opportunity to step back from individual threats and look broadly at what Microsoft’s security and threat intelligence teams are seeing.

These developments can change the speed and scale of security activity even as the underlying security fundamentals remain familiar.

People, identities, exposed systems, and trusted access continue to feature prominently in the threat activity Microsoft observes.

The 2026 Microsoft Digital Defense Report looks across the threat landscape, cybercrime, resilience, and the relationships among technologies, identities, systems, and people.

Read the 2026 Digital Defense Report for the full findings, d…

4 days, 21 hours назад @ microsoft.com
​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 ​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026

Join fellow customers and Microsoft Security leaders for a night designed to make meaningful connections.

Partners and the Microsoft Intelligent Security AssociationMicrosoft Intelligent Security Association (MISA) members have a full week ahead at Microsoft Ignite.

Sessions to watch forWhen AI acts, security has to answer: Microsoft Security for AI , the platform view of securing agentic AI.

Strengthen and Manage Data Security Posture with Microsoft Purview , on data security posture management in practice.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

5 days, 15 hours назад @ microsoft.com
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

The operators first validated command execution using lightweight out-of-band probes to unique subdomains hosted on public interaction and collaborator services, including oast[.

When a service-state change triggers health monitoring, swatchdog incorporates the attacker-controlled value into a snmptrap shell invocation, enabling command execution.

Exploitation of the Zimbra vulnerability provided attackers with direct command execution as the zimbra service account.

Attackers also used the initial command execution to download and execute content directly through wget or curl, launch background processes, and establish interactive reverse shells.

Command and controlThe actor used HTTP and H…

5 days, 21 hours назад @ microsoft.com
Phishing Abuses RMM Tools for Persistent Access
Phishing Abuses RMM Tools for Persistent Access Phishing Abuses RMM Tools for Persistent Access

Attack chain showing phishing delivering a masqueraded MSP360 RMM installer that deploys ScreenConnect for persistent remote access and follow-on activity.

Initial Access: Phishing Campaign Delivering Masqueraded MSP360 RMM InstallerMicrosoft observed multiple phishing campaigns that used a multi-stage delivery chain to distribute legitimate, digitally signed MSP360 RMM software (v2.5.0.67).

Analysis of downloaded samples showed that many ultimately contained the same MSP360 RMM installer package despite appearing as different files to the victim.

Command and ControlT1219 Remote Access Software | The threat actor abused legitimate remote administration software including MSP360 RMM and Conn…

6 days, 13 hours назад @ microsoft.com
​​Beyond source code: A path to the keys to the kingdom
​​Beyond source code: A path to the keys to the kingdom ​​Beyond source code: A path to the keys to the kingdom

By mapping trusted deployment paths and connected resources, the threat actor was able to identify opportunities to expand beyond the initial compromise.

In addition to deploying a kube agent, the threat actor modified pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility.

The threat actor added seven stolen kubeconfig files to a repository, providing the credentials needed to access targeted Kubernetes clusters.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

6 days, 19 hours назад @ microsoft.com
Star Blizzard refines phishing and malware delivery with the RedFlick technique
Star Blizzard refines phishing and malware delivery with the RedFlick technique Star Blizzard refines phishing and malware delivery with the RedFlick technique

In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns.

June 2026 RedFlick campaign follow-up email with the subject line “Invitation to the Chatham House London Conference 2026”Figure 3.

Persistence through multiple scheduled tasksIn April 2026, Microsoft observed Star Blizzard changing persistence tactics to include RedFlick scheduled tasks.

Defending against Star Blizzard and RedFlick-related activityMicrosoft Threat Intelligence advises organizations that are most likely at risk—primarily those in government, NGOs, or think tanks adjacent to Ukraine policy or support—to implement the followin…

6 days, 20 hours назад @ microsoft.com
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.

Microsoft has observed additional NeedyMantis activity beyond Storm-3069’s activity in the DAEMON Tools campaign, indicating that the malware might be used by more than one operator.

Indicators of compromiseIndicator Type Description First seen Last seen e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e SHA-256 First-stage loader WinSparkle.dll 2026-05-21 2026-05-21 9cb68f986043a576e19d32184…

1 week назад @ microsoft.com
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Storm-3168: Agentic-driven cloud attacks using compromised service principals Storm-3168: Agentic-driven cloud attacks using compromised service principals

About 90 minutes after the first compromised service principal started enumeration, the second compromised service principal enumerated virtual machines and resource groups across two subscriptions in five seconds.

16 hours later, the second service principal successfully enumerated Azure App Service configuration stores, possibly looking for exposed credentials.

This compromised service principal then attempted 150+ destructive or credential collection related operations in 35 minutes.

T1078.004 Valid Accounts: Cloud Accounts | Compromised service principals were used for Azure resource discovery and destruction.

To hear stories and insights from the Microsoft Threat Intelligence community…

1 week, 3 days назад @ microsoft.com
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Storm-3168: Agentic-driven cloud attacks using compromised service principals Storm-3168: Agentic-driven cloud attacks using compromised service principals

About 90 minutes after the first compromised service principal started enumeration, the second compromised service principal enumerated virtual machines and resource groups across two subscriptions in five seconds.

16 hours later, the second service principal successfully enumerated Azure App Service configuration stores, possibly looking for exposed credentials.

This compromised service principal then attempted 150+ destructive or credential collection related operations in 35 minutes.

T1078.004 Valid Accounts: Cloud Accounts | Compromised service principals were used for Azure resource discovery and destruction.

To hear stories and insights from the Microsoft Threat Intelligence community…

1 week, 3 days назад @ microsoft.com
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.

As a result, organizations could encounter the same actor, tools, and intrusion methods despite different ransomware payloads being deployed.

Storm-2570 uses a diverse set of remote access tools rather than relying on a single capability.

This type of tunnel can help bypass inbound firewall restrictions and provide covert remote access for follow-on activity.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat …

1 week, 4 days назад @ microsoft.com
​​​​​​​​What’s new in Microsoft Security: September 2026​​
​​​​​​​​What’s new in Microsoft Security: September 2026​​ ​​​​​​​​What’s new in Microsoft Security: September 2026​​

Here’s what’s new:Extend protection and support investigations with Microsoft DefenderBring more context into email investigation and hunting with Microsoft Security CopilotAvailable for organizations using both Microsoft Defender and Microsoft Security Copilot, a new email detonation summary delivers AI-generated explanations of URL and file sandboxing results, helping SOC teams investigate faster by reducing the manual effort required to correlate detonation evidence and contextual signals.

Protect sensitive data in motion with Microsoft Purview and Microsoft EntraStop sensitive data from reaching shadow AI over the networkNow generally available, Microsoft Purview and Microsoft Entra Glo…

1 week, 4 days назад @ microsoft.com
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.

As a result, organizations could encounter the same actor, tools, and intrusion methods despite different ransomware payloads being deployed.

Storm-2570 uses a diverse set of remote access tools rather than relying on a single capability.

This type of tunnel can help bypass inbound firewall restrictions and provide covert remote access for follow-on activity.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat …

1 week, 4 days назад @ microsoft.com
Reimagining the SOC for the agentic era in Microsoft Defender
Reimagining the SOC for the agentic era in Microsoft Defender Reimagining the SOC for the agentic era in Microsoft Defender

So must the security operations center (SOC).

For agentic security to work, the industry needs a different model.

Today we are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for security information and event management (SIEM) and threat protection together.

The result is an integrated protection loop that continuously turns what defenders learn into stronger pre-breach protection.

Integrated security operations center (ISOC) in Microsoft Defender is available in preview today.

1 week, 5 days назад @ microsoft.com
Unmasking EvilTokens: Getting to the root of device code phishing
Unmasking EvilTokens: Getting to the root of device code phishing Unmasking EvilTokens: Getting to the root of device code phishing

What is device code phishing?

Device code phishing occurs when threat actors insert themselves into this process.

Tactic Observed activity Microsoft Defender coverage Initial access Device code authentication Microsoft Defender for Identity– Anomalous OAuth device code authentication activity Credential access Token theft following device code authentication Microsoft Defender for Identity– Anomalous token exchange following device code authenticationMicrosoft Defender XDR– User account compromise via OAuth device code phishing– Suspicious Azure authentication through possible device code phishing Persistence Device registration following anomalous device code authentication Microsoft Defen…

1 week, 6 days назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 5 months, 2 weeks назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

5 months, 2 weeks назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

5 months, 4 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

5 months, 4 weeks назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

6 months назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

6 months, 1 week назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

6 months, 2 weeks назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

7 months, 1 week назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

7 months, 1 week назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

7 months, 2 weeks назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

8 months, 1 week назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

9 months, 4 weeks назад @ security.googleblog.com