Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 1 час назад
Посмотрели три фильма и посмели назвать себя киноманом? Интернет уже поставил вам диагноз
Посмотрели три фильма и посмели назвать себя киноманом? Интернет уже поставил вам диагноз Посмотрели три фильма и посмели назвать себя киноманом? Интернет уже поставил вам диагноз

Ларпером теперь может стать каждый. Достаточно слишком уверенно любить что-нибудь новое.

1 час назад @ securitylab.ru
Хакеры-роботы против живых защитников: Positive Technologies запускает киберполигон с ИИ-атаками, которые невозможно предугадать
Хакеры-роботы против живых защитников: Positive Technologies запускает киберполигон с ИИ-атаками, которые невозможно предугадать

SOC-команды будут тренироваться против многоагентного ИИ, который сам выбирает путь атаки.

2 часа назад @ securitylab.ru
От 2^128 до жалких 2^39: баг 12-летней давности в CryptoJS позволяет сбрутить сид-фразу на обычном ноуте
От 2^128 до жалких 2^39: баг 12-летней давности в CryptoJS позволяет сбрутить сид-фразу на обычном ноуте

Двенадцать лет разработчики держали дверь приоткрытой. Никто и не заметил.

2 часа назад @ securitylab.ru
«Анонимный» сервис Apple 'Private Relay' раскрывает реальные IP-адреса пользователей
«Анонимный» сервис Apple 'Private Relay' раскрывает реальные IP-адреса пользователей

Достаточно просто открыть страницу. Даже нажимать ничего не нужно.

3 часа назад @ securitylab.ru
Проверка ИИ превратилась в настоящую кибератаку: агент создал подставные личности и пошёл в наступление на GitHub
Проверка ИИ превратилась в настоящую кибератаку: агент создал подставные личности и пошёл в наступление на GitHub Проверка ИИ превратилась в настоящую кибератаку: агент создал подставные личности и пошёл в наступление на GitHub

Модель должна была взломать песочницу, но вместо этого начала атаковать реальных разработчиков.

3 часа назад @ securitylab.ru
От состояния гонки до деанонимизации: как баг в CPU-таймерах Linux позволил хакерам взламывать Tails
От состояния гонки до деанонимизации: как баг в CPU-таймерах Linux позволил хакерам взламывать Tails

Главная угроза пряталась там, где люди искали максимальную безопасность.

4 часа назад @ securitylab.ru
Эпоха Google Assistant закончилась: компания назначила дату его исчезновения с Android
Эпоха Google Assistant закончилась: компания назначила дату его исчезновения с Android

Миллионы устройств принудительно переведут на Gemini.

4 часа назад @ securitylab.ru
20 моделей роутеров годами слали данные на чужой сервер — производитель говорит, что так и задумано
20 моделей роутеров годами слали данные на чужой сервер — производитель говорит, что так и задумано

В роутерах китайского производителя Zbtlink нашли скрытое удалённое управление.

5 часов назад @ securitylab.ru
Российский интернет накрыл масштабный сбой: Ozon, Telegram и десятки сервисов работают нестабильно
Российский интернет накрыл масштабный сбой: Ozon, Telegram и десятки сервисов работают нестабильно Российский интернет накрыл масштабный сбой: Ozon, Telegram и десятки сервисов работают нестабильно

От маркетплейсов до банков: тысячи жалоб за час.

6 часов назад @ securitylab.ru
Meta выпустила ИИ-программиста, который не спит сутками: Muse Code пишет код, компилирует и сам проверяет результат
Meta выпустила ИИ-программиста, который не спит сутками: Muse Code пишет код, компилирует и сам проверяет результат

Новый агент Meta справился с задачей, которую боятся давать джунам.

6 часов назад @ securitylab.ru
Cybertruck вместо броневика. NASA меняет машину для эвакуации астронавтов
Cybertruck вместо броневика. NASA меняет машину для эвакуации астронавтов

Отзывали 11 раз, а теперь доверили экипаж Crew-13.

7 часов назад @ securitylab.ru
Усиленный киберобман и защита айдентити в Xello Prisma 6.0
Усиленный киберобман и защита айдентити в Xello Prisma 6.0

18 августа Xello расскажет, как выстроить защиту на опережение и раскроет новые возможности решений.

7 часов назад @ securitylab.ru
«Один токен — и аккаунт ваш навсегда»: хакеры продают взлом Google за $10 000
«Один токен — и аккаунт ваш навсегда»: хакеры продают взлом Google за $10 000 «Один токен — и аккаунт ваш навсегда»: хакеры продают взлом Google за $10 000

Новая атака на Gmail сохраняет доступ даже после выхода из всех устройств.

7 часов назад @ securitylab.ru
45% вредоносов работают без DNS. Хакеры снова вшивают IP-адреса в код и побеждают
45% вредоносов работают без DNS. Хакеры снова вшивают IP-адреса в код и побеждают

Злоумышленники активно жертвуют удобством, чтобы незаметно выкачивать пароли корпораций.

8 часов назад @ securitylab.ru
28,9 млн параметров и почти 10 токенов в секунду. Нейросеть запустили на микроконтроллере за $10
28,9 млн параметров и почти 10 токенов в секунду. Нейросеть запустили на микроконтроллере за $10

Большой ИИ не поместился. Маленький все равно пролез.

9 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 5 часов назад
Переход с Microsoft Office на альтернативное ПО: риски и их минимизация
Переход с Microsoft Office на альтернативное ПО: риски и их минимизация Переход с Microsoft Office на альтернативное ПО: риски и их минимизация

Переход с Microsoft Office на альтернативные офисные пакеты — это не только установка нового ПО, но и риск столкнуться с несовместимостью документов, макросов и шаблонов.

Такие проблемы массово возникали при обновлении с Microsoft Office 7/95 на Microsoft Office 97.

А именно так обстоит дело в «МойОфис» и «Р7-Офис» (как и в его основе с открытым кодом OnlyOffice).

В Microsoft Office для создания формул применяется шрифт Cambria Math, и при подстановке его аналога для других платформ всё должно нормализоваться.

Наиболее часто проблема проявляется в Linux, но нередко имеет место и в Windows, и в Android.

5 часов назад @ anti-malware.ru
Обзор защищённых платформ и накладных средств безопасности больших данных
Обзор защищённых платформ и накладных средств безопасности больших данных Обзор защищённых платформ и накладных средств безопасности больших данных

Специфика защиты больших данных: проблемы и угрозыГоворя о защите Big Data, стоит начать с расшифровки понятия больших данных и их отличия от обычных массивов информации.

Прогноз увеличения рынка Big Data Security (источник: thebusinessresearchcompany.com)Лидеры рынка Big Data Security: IBM, Microsoft, Oracle, Broadcom (Symantec), AWS.

Машина больших данных «Скала^р МБД.Х»Программно-аппаратный комплекс «Скала^р МБД.Х» — отечественная платформа класса Data Lakehouse для хранения, обработки и анализа больших данных.

Защита систем хранения данных и дата-центров от KasperskyКомпания «Лаборатория Касперского» предлагает комплекс услуг и сервисов для защиты больших данных и дата-центров.

Как выбр…

8 часов назад @ anti-malware.ru
Почему обучение информационной безопасности не работает: 6 главных причин
Почему обучение информационной безопасности не работает: 6 главных причин Почему обучение информационной безопасности не работает: 6 главных причин

Значит ли это, что обучение не работает, или проблема в самом подходе к нему?

Выделили шесть возможных причин, по которым обучение ИБ не работает так, как ожидается.

Как понять, что обучение не даёт результатыМожно выделить следующие критерии неэффективного обучения:Сотрудник регулярно совершает одни и те же ошибки.

Такие ситуации возникают потому, что знания не были связаны с реальными рабочими процессами и не стали частью повседневных действий.

ВыводыПричины, по которым обучение информационной безопасности не работает, имеют не методический, а организационный характер.

1 day, 5 hours назад @ anti-malware.ru
Как измерить кибербезопасность: KPI, KRI и ключевые метрики эффективности защиты
Как измерить кибербезопасность: KPI, KRI и ключевые метрики эффективности защиты Как измерить кибербезопасность: KPI, KRI и ключевые метрики эффективности защиты

KPI, KRI и метрики: в чём разницаПри обсуждении информационной безопасности термины KPI и KRI часто путают, хотя они решают разные задачи.

При этом и KPI, и KRI рассчитываются на основе технических и бизнес-метрик, которые собирают системы мониторинга, средства защиты и другие источники данных.

Этот показатель отражает период от компрометации до обнаружения злоумышленника и не является MTTD, однако показывает, сколько времени атакующий может оставаться незамеченным.

Patch SLA = (Количество уязвимостей, устранённых в срок / Общее количество уязвимостей) × 100 %Метрика показывает эффективность процесса управления обновлениями.

Например, для уязвимостей с максимальным приоритетом SLA может сос…

1 day, 8 hours назад @ anti-malware.ru
Как меняются проекты внедрения ИИ в российских компаниях
Как меняются проекты внедрения ИИ в российских компаниях Как меняются проекты внедрения ИИ в российских компаниях

Тем не менее проекты внедрения ИИ в российских компаниях продолжаются.

Как и в целом с ИТ-проектами, они стали более точечными и с упором на максимальную эффективность.

Уровень проникновения ИИ в российских компаниях по ряду отраслейОднако внедрение ИИ далеко не всегда было экономически оправданным.

Влияло и то, что в ряде отраслей, в частности в медицине, это прямо сказывалось на показателях эффективности руководителей учреждений и глав региональных министерств здравоохранения.

ВыводыФокус во внедрении ИИ в российских компаниях всё больше смещается в сторону не новых, а хорошо отработанных и при этом относительно недорогих технологий классической аналитики и традиционного машинного обучени…

2 days, 6 hours назад @ anti-malware.ru
Нужен ли мессенджеру Telegram госконтроль
Нужен ли мессенджеру Telegram госконтроль Нужен ли мессенджеру Telegram госконтроль

Проблема состоит не в их участии, а в том, в какой степени они готовы вмешиваться в их работу.

Ссылки на каналы МИА «Россия сегодня» («Россия сегодня», 2026)Запрет использования Telegram на УкраинеПротиворечия вокруг Telegram особенно ярко проявились на фоне продолжающегося конфликта между Россией и Украиной и ограничений на трафик Telegram в России.

Популярные мессенджеры в Украине в 2026 году (WMTips, 2026)Ограничения работы Telegram в РоссииОфициальные причины введения ограничений на работу Telegram в России так и не были названы.

Впрочем, реальная картина сложнее и касается работы Telegram не только в России, но и в глобальном масштабе.

Самое сложное заключается даже не в самом выборе, …

3 days, 3 hours назад @ anti-malware.ru
Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть II
Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть II Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть II

Да Возможность расшифрования протокола TLS 1.3 Да Да Да Да Нет(планируется в будущих версиях, 2027 г.)

Нет Встроенная песочница Нет Нет Нет Нет Нет(планируется в будущих версиях, 2027 г.)

Нет(интеграция с «Гарда DLP») Режим блокировки для DLP Нет Нет Нет Нет Нет Нет Режим логирования для DLP Нет Нет Нет Нет Нет Нет Возможность блокировки передачи определенных типов файлов Нет Нет Нет Нет Нет(планируется в будущих версиях, 2027 г.)

Нет(в разработке) Свой клиент для IPsec VPN Нет Нет Нет Нет Нет Нет(в разработке) Поддержка OpenVPN Да Да Нет Да Нет(планируется в ближайшей версии — до конца 2026 года) Нет(поддержка WireGuard) Поддержка OpenVPN ГОСТ Да Нет Нет Нет Нет Нет Поддержка IKEv2 Да Да Н…

3 days, 8 hours назад @ anti-malware.ru
Геополитика и безопасность: почему Telegram и Alibaba под прицелом государства
Геополитика и безопасность: почему Telegram и Alibaba под прицелом государства Геополитика и безопасность: почему Telegram и Alibaba под прицелом государства

Но на них действуют законы, которые нередко принимались без понимания специфики новой среды.

Джек Ма, китайский миллиардерВ 1995 году муниципальный совет Ханчжоу направляет Джека Ма на годовую стажировку в США по студенческому обмену.

Предав наследие наших предков, мы встали на путь саморазрушения — морального, интеллектуального, экономического и, в конечном итоге, биологического.

Но что реально происходит «под капотом» и в какую сторону склонится чаша весов «независимости» — для большинства стран это риски ИБ.

Выход из них далеко не всегда способствует достижению общих целей — технологического и инновационного развития с соблюдением регуляторных и конституционных требований.

6 days, 5 hours назад @ anti-malware.ru
Secure Enterprise Browser: новый стандарт безопасности бизнеса
Secure Enterprise Browser: новый стандарт безопасности бизнеса Secure Enterprise Browser: новый стандарт безопасности бизнеса

Браузер — один из значимых векторов атакБыло бы преувеличением сказать, что количество атак на браузер и через него выросло в последние годы.

Другими словами, корпоративный браузер позволяет контролировать все потоки данных, которые через него проходят.

Крупнейшие игроки:Google Chrome Enterprise — самый известный корпоративный браузер.

Глобальные лидеры (специализированные решения):Island — стартап из США, создавший полноценный корпоративный браузер на основе Chromium.

Через пять лет фраза «используйте корпоративный браузер» будет звучать так же естественно, как сегодня «используйте корпоративную почту».

6 days, 10 hours назад @ anti-malware.ru
ROI ИБ-проектов: почему инвестиции в информационную безопасность окупаются
ROI ИБ-проектов: почему инвестиции в информационную безопасность окупаются ROI ИБ-проектов: почему инвестиции в информационную безопасность окупаются

В нынешних условиях даже если бюджет на ИТ и ИБ формально не снижается, но и не растёт, это означает его фактическое снижение.

Так, на одной из сессий конференции IT IS conf, которая прошла совсем недавно, провели блиц-опрос посетителей, в ходе которого лишь один участник заявил, что в их компании расходы на ИБ в 2026 году выросли.

Возможно, влияет и то, что в ИБ только идёт процесс перехода управления от технических специалистов к менеджерам.

ИБ как часть общей системы защиты«В информационную безопасность действительно приходится вкладываться, защищаясь от того, что, возможно, никогда не произойдёт.

В целом же, по его мнению, инвестиции в ИБ являются расходами на поддержание устойчивости б…

1 week назад @ anti-malware.ru
Обзор «Аттестованного публичного облака NGENIX»
Обзор «Аттестованного публичного облака NGENIX» Обзор «Аттестованного публичного облака NGENIX»

Мы уже рассказывали читателям о возможностях «Публичного облака NGENIX», а в этом обзоре рассмотрим «Аттестованное публичное облако NGENIX» — аттестованную распределённую облачную платформу для защиты от DDoS и бот-атак.

Архитектура «Аттестованного публичного облака NGENIX»«Аттестованное публичное облако NGENIX» построено на концепции встроенной безопасности: реализация всех требований ИБ заложена на этапе проектирования (Security by Design).

Администрирование «Аттестованного публичного облака NGENIX» и управление пользователями осуществляется в клиентском портале NGENIX EdgeSec Multidesk, доступном через веб-интерфейс.

Подключение и техподдержкаТарифы «Аттестованного публичного облака» раз…

1 week назад @ anti-malware.ru
Kaspersky VM: как меняется подход к управлению уязвимостями (Vulnerability Management)
Kaspersky VM: как меняется подход к управлению уязвимостями (Vulnerability Management) Kaspersky VM: как меняется подход к управлению уязвимостями (Vulnerability Management)

Среди российских решений можно назвать как экосистемные, так и самостоятельные продукты: MaxPatrol VM от Positive Technologies, R-Vision VM, ScanFactory VM, Vulns.io VM и др.

Первый вывод для Kaspersky VM – это желание снизить остроту проблем от хаотичности развития ИТ-инфраструктуры российских предприятий.

Отсутствие упоминания Kaspersky Security Center Web Console, скорее всего, объясняется ограничением первой версии Kaspersky VM.

Она может применяться как для Defensive, так и для Offensive Security.

Kaspersky VM и ИИНо вернёмся к теме Vulnerability Management и Kaspersky VM.

1 week, 1 day назад @ anti-malware.ru
Как выстроить резервное копирование, которое не зависит от человека
Как выстроить резервное копирование, которое не зависит от человека Как выстроить резервное копирование, которое не зависит от человека

Делимся лучшими практиками построения резервного копирования, которое работает предсказуемо и не зависит от человека.

Причина обычно заключается не в отсутствии технологий, а в том, что процесс построен так, что ошибки становятся заметны только в момент восстановления.

Почему ручной процесс подводитПока резервное копирование держится на действиях конкретного человека, результат зависит от его занятости, внимательности и приоритетов.

В конце встраивается проверка восстановления — не как разовое мероприятие, а как часть регулярного расписания.

Вместе это и есть процесс, который держится на системе, а не на человеке.

1 week, 1 day назад @ anti-malware.ru
Обзор Frisbee, платформы коммуникаций для бизнеса
Обзор Frisbee, платформы коммуникаций для бизнеса Обзор Frisbee, платформы коммуникаций для бизнеса

Её разработчик — российская компания «Клауд Атлас», которая создаёт технологические решения для бизнеса и государственных организаций, разрабатывая решения для бизнеса и государственных организаций, включая средства защиты информации и корпоративных коммуникаций.

Благодаря широким возможностям Frisbee является не только заменой WhatsApp и Telegram для бизнеса, но и может использоваться как альтернатива Slack и Microsoft Teams.

Возможности использования платформыРассмотрим основные функциональные возможности платформы Frisbee в корпоративной среде.

Для удобства разделим их на две части: инструменты для пользователей (интересные большинству сотрудников) и инструменты для администраторов (наст…

1 week, 1 day назад @ anti-malware.ru
Как Gartner меняет подход к управлению внешними угрозами
Как Gartner меняет подход к управлению внешними угрозами Как Gartner меняет подход к управлению внешними угрозами

Новый квадрант Gartner показывает, что подход к киберразведке смещается от аналитического к операционализированному.

На первый план выходят единые платформы, автоматизация и работа с внешними угрозами в общем контексте, а не разрозненные средства защиты.

Так, архитектура решений раннего предупреждения кибератак компании BI.ZONE объединяет портал BI.ZONE Threat Intelligence, платформы BI.ZONE Digital Risk Protection и BI.ZONE External Attack Surface Management.

Такой подход к управлению внешними угрозами соответствует требованиям, которые Gartner считает ключевыми для нового поколения CTI-решений.

Подход включает тесное взаимодействие команд BI.ZONE Digital Risk Protection, BI.ZONE Threat In…

1 week, 2 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 3 часа назад
Когда нейросеть слушает не вас — про промпт-инъекцию без жаргона
Когда нейросеть слушает не вас — про промпт-инъекцию без жаргона Когда нейросеть слушает не вас — про промпт-инъекцию без жаргона

Ниже разберу, что происходит, почему это касается обычных команд и что можно сделать, не ожидая волшебной кнопки.

Проблема в том, что для модели нет жёсткой границы между это приказ разработчика и это просто данные.

Модель не видит, где заканчивается доверие.

OpenAI в 2026 году запустил режим Lockdown и честно сказал, что в AI-браузерах эту дыру могут не закрыть полностью никогда.

Права на действия задавайте в коде, не в промпте.

3 часа назад @ habr.com
50 оттенков NGFW, часть первая
50 оттенков NGFW, часть первая 50 оттенков NGFW, часть первая

Как и обещали — вторая часть истории про то, как мы строим InfoWatch ARMA Стена (NGFW) в текущих реалиях.

Сегодня про:ИИ и нейросетимиграциюотечественное железопочему NGFW, а не data diodeцены и пилотированиеИИ сейчас почти из каждого утюга.

Как нормально мигрировать на новое решение и не потерять ничего по пути?

Почему NGFW, а не data diode?

NGFW можно настроить как логическую блокировку обратного канала (аналог data diode), а вот data diode в полноценный NGFW превратить, увы, нельзя.

4 часа назад @ habr.com
Как внедрять MLSecOps: пять этапов практического road-map
Как внедрять MLSecOps: пять этапов практического road-map Как внедрять MLSecOps: пять этапов практического road-map

Он делает безопасность измеримой, воспроизводимой и встроенной в разработку и эксплуатацию, а не «прикрученной» в конце.

Поставить промпт-шаблоны под версионный контроль и заводить на их правки такое же ревью, как на код.

Тестирование необходимо проводить после каждого дообучения модели и смены промпт-шаблонов, а не «по настроению».

Начать с инструмента, а не с инвентаризации.

Просто купленный сканер закрывает 5% поверхности, о которой вы знали, и не увидит 95%, о которой не знали.

5 часов назад @ habr.com
Ваш firewall пропускает атаку по правилам
Ваш firewall пропускает атаку по правилам Ваш firewall пропускает атаку по правилам

Для схемы выше это значит, что закрытые слои — прошивка NIC, management-движок, виртуальное устройство гипервизора — не «безопаснее по умолчанию», а всего лишь хуже освещены: там меньше публичных CVE, а не меньше ошибок.

Следующего хопа просто нет: у шлюза нет маршрута в доверенный сегмент, нет его адресов и нет права инициировать соединение; сессию всегда открывает исполнитель изнутри и сам забирает задачи.

Остаточный риск: клиентский код исполнителяНоля здесь нет, и делать вид, что он есть, — маркетинг, от которого я и пытаюсь отгородиться.

Сам по себе разрыв контролирует форму обмена, а не смысл содержимого: SQL-инъекция, укладывающаяся в схему моста, будет доставлена и выполнена.

Но ФЛК…

5 часов назад @ habr.com
Как хаос в службах каталогов подвергает риску вашу ИТ-инфраструктуру
Как хаос в службах каталогов подвергает риску вашу ИТ-инфраструктуру Как хаос в службах каталогов подвергает риску вашу ИТ-инфраструктуру

«Мусор» в службах каталогов тормозит работу инфраструктурыСлужбы каталогов, такие как Active Directory, ALD Pro, РЕД АДМ и Альт Домен, могут работать с миллионами объектов.

Однако большое количество устаревших учетных записей, избыточные права доступа и сложная структура каталога создают целый комплекс технических проблем.

Проблема была даже не в поиске отдельных учетных записей, а в том, что вручную уже невозможно было получить целостную картину прав доступа.

Проходит время после очередной «ручной» очистки, и в службе каталогов снова начинают накапливаться устаревшие учетные записи, неактуальные разрешения и другие артефакты.

Поделитесь, пожалуйста, в комментариях, как вы наводите порядок …

5 часов назад @ habr.com
Новый абсолютный рекорд по числу DDoS-атак и другая статистика за Q2 2026
Новый абсолютный рекорд по числу DDoS-атак и другая статистика за Q2 2026 Новый абсолютный рекорд по числу DDoS-атак и другая статистика за Q2 2026

Если коротко — мало хорошего, как, в принципе, видно по новостям, и в мире DDoS ситуация зеркальная.

Интересно, что на уровне L3-L4 наблюдается резкий перевес (в 2-3 раза по числу инцидентов) в сторону четверга и субботы как любимых дней злоумышленников для DDoS-атак.

У нас нет однозначного ответа, почему именно так резко выросло число атак в июне и связано ли с это с не менее резким ростом числа сверхдолгих атак.

На 30% выросло количество атак на новостные сайты, которые начали было выпадать из трендов DDoS в первом квартале 2026.

Уже сейчас заметен рост числа атак на новостные ресурсы, HR-платформы и IT-порталы, и во второй половине года эта тенденция может усилиться.

8 часов назад @ habr.com
Задаём UserGate неудобные вопросы
Задаём UserGate неудобные вопросы Задаём UserGate неудобные вопросы

Сразу оговорюсь: речь не о поиске уязвимостей в самом UserGate и не об оценке всей защищённости NGFW.

Так появилась идея утилиты, которая не меняет конфигурацию и не пытается принимать решения вместо администратора.

При этом часть данных хранится не в самом правиле, а в отдельных справочниках.

Данные существовали — просто не рядом и не в формате, который удобен для массового анализа.

Следствие ведёт ExcelНа выходе хотелось получить не JSON и не ещё один сервис, который нужно разворачивать и поддерживать.

9 часов назад @ habr.com
VPN с российским IP: что о вашем адресе видно на самом деле
VPN с российским IP: что о вашем адресе видно на самом деле VPN с российским IP: что о вашем адресе видно на самом деле

Я собрал их у себя и посмотрел не на описания, а на то, что о вашем адресе реально видно снаружи.

Границы замера, чтобы числа не соврали: адрес брался из анонсируемого диапазона хостера, а не из пула, куда попадают конкретные клиентские машины.

Практический вывод для диагностики: если сайт российский, а через каскад уходит не туда, смотрите не на геолокацию его адреса, а на то, кому выдан диапазон.

Границу назову честно: я проверил, что в статистике распределения этот диапазон числится за испанской организацией и что в зоне его нет.

Systemd поднял демон обратно за несколько секунд, так что я смотрел на окно перезапуска, а не на отказ.

12 часов назад @ habr.com
От чего защищает Certificate Transparency?
От чего защищает Certificate Transparency? От чего защищает Certificate Transparency?

Certificate TransparencyВ этом контексте активно обсуждается механизм certificate transparency, который должен защитить пользователей от атак man-in-the-middle, осуществляемых с помощью сертификатов, выпущенных без ведома владельца домена.

Мы же вообще говорим, что хотим защититься от атак, производимых на государственном уровне с использованием административного давления и инструментов спецслужб.

Я и через VPN пробовал, и через прокси, ошибка на сервере, бесполезно пытаться ее обойти.

Разница есть только в байтах публичного ключа и в fingerprint.

С помощью ct-логов можно заметить, если какой-то злоумышленник обманет добросовестный УЦ и сумеет получить от него сертификат без ведома владельц…

13 часов назад @ habr.com
Step-Up Authentication vs 2FA: зачем нужен второй фактор внутри активной сессии
Step-Up Authentication vs 2FA: зачем нужен второй фактор внутри активной сессии Step-Up Authentication vs 2FA: зачем нужен второй фактор внутри активной сессии

Что такое Step-Up Authentication и когда она необходимаВ отличие от классической двухфакторной аутентификации (2FA), Step-Up Authentication запрашивает дополнительное подтверждение личности не в момент входа в систему, а при попытке выполнить действие, требующее повышенного уровня доверия.

Поэтому мы выбрали другой подход – разработали отдельный сервис PIN-кодов, который отвечает за Step-Up Authentication независимо от механизма основной аутентификации.

Архитектура решенияВместо того чтобы выполнять дополнительную проверку непосредственно в Identity Provider, мы вынесли Step-Up Authentication в отдельный gateway-микросервис (gateway-2fa).

Как Step-Up Authentication выглядит для пользователя…

15 часов назад @ habr.com
Как измерить собственный обход блокировок: восемь механизмов, которые не выполнялись ни разу
Как измерить собственный обход блокировок: восемь механизмов, которые не выполнялись ни разу Как измерить собственный обход блокировок: восемь механизмов, которые не выполнялись ни разу

Это не «Молдова активно пользуется», это чей-то VPN или отдельный тяжёлый клиент.

Теперь reload на пуш-хосте планируется как операция с последствиями, а не как безобидная перечитка конфига, каковой он является для всего остального.

Мы не видим ничего за релеем, и не должны: релей стоит между нами и человеком ради этого.

Самый важный класс пользователей (те, у кого не сработало вообще) в лог не попадает никогда, потому что до лога не доехал.

И честно про сам вывод: восемь механизмов, которые не выполнялись, мы нашли за двое суток вовсе не потому, что стали умнее.

16 часов назад @ habr.com
Я написал мессенджер в одиночку … Разбор 149-ФЗ
Я написал мессенджер в одиночку … Разбор 149-ФЗ Я написал мессенджер в одиночку … Разбор 149-ФЗ

Официальная краткая формулировка такая у определения мессенджера:"сервис обмена мгновенными сообщениями"Но мой "мессенджер" может работать оффлайн, мгновенная доставка не гарантируется.

Обязанности не распространяются на «граждан (физических лиц), осуществляющих указанную деятельность для личных, семейных и домашних нужд».

( она только на устройствах пользователей ) Хранить содержимое полгода ( формально да, но там шифрованный мусор )Если вы не в юрисдикции РФ, то можете поднять узел и тогда всё будет законно.

Кстати локально крутятся такие же нодыПри этом шифруется у меня не всё, на сервере видно, кто, куда и когда пишет.

Для пользователя это незаметно, но крутить ботов становиться экономи…

1 day, 2 hours назад @ habr.com
DLL Sideloading через version.dll в WinSCP: порядок поиска DLL, прокси на Rust и перехват payload
DLL Sideloading через version.dll в WinSCP: порядок поиска DLL, прокси на Rust и перехват payload DLL Sideloading через version.dll в WinSCP: порядок поиска DLL, прокси на Rust и перехват payload

Такой же прием недавно использовали и при атаке на Filezilla, поэтому материал будет полезен тем, кто изучает подмену DLL в целевых программах.

Статический анализ: Import TableОтправной точкой стала таблица импортов WinSCP.exe - это перечень DLL и функций, с которыми программа связывается напрямую при запуске.

Здесь важен и список Known DLLs: библиотеки из него загрузчик забирает только из системного каталога и в папку приложения не заглядывает.

[allow(non_snake_case)] #[no_mangle] pub unsafe extern "system" fn GetFileVersionInfoA() {} #[no_mangle] pub unsafe extern "system" fn GetFileVersionInfoByHandle() {} #[no_mangle] pub unsafe extern "system" fn GetFileVersionInfoExA() {} #[no_mangle]…

1 day, 4 hours назад @ habr.com
Как PVS-Studio улучшает качество embedded-проектов
Как PVS-Studio улучшает качество embedded-проектов Как PVS-Studio улучшает качество embedded-проектов

Особенности встраиваемых системEmbedded-разработка на языках C и C++ затрагивает множество сфер нашей жизни: от электрического чайника и зубной щетки до критических систем, таких как медицинское оборудование и управление самолётами.

Visual Studio CodeИспользование мониторинга компиляции также возможно с помощью плагина PVS-Studio для Visual Studio Code.

Такие ошибки обходятся очень дорого как в финансовом, так и в репутационном плане.

Авторы тщательно проработали международные стандарты C и C++ и выписали все возможные способы допустить ошибку.

Попробуйте PVS-Studio на своём проекте бесплатно, узнайте цену на полную версию анализатора и получите поэтапный алгоритм внедрения в команду разраб…

1 day, 4 hours назад @ habr.com
Свет, камера, IDKFA!: как мы снимали первый российский фильм о реверс-инжиниринге
Свет, камера, IDKFA!: как мы снимали первый российский фильм о реверс-инжиниринге Свет, камера, IDKFA!: как мы снимали первый российский фильм о реверс-инжиниринге

Проблема была не в нехватке фактуры, а в отсутствии карты, по которой ее читать.

И дальше сборка пошла уже по смыслам, а не по наитию.

Принцип режиссер формулировал так — работаем не с логикой сюжета, а с ощущением, которое возникает рядом с человеком.

Аршинин вспоминает, что на встречах он смотрел на него почти не моргая, «будто на монитор с бегущей строкой».

Решение пришло случайно: однажды режиссер заметил на своем экране пиксель, который раздражающе моргал ровно в центре и, как и пристальный взгляд Леши, приковывал к себе внимание.

1 day, 5 hours назад @ habr.com
Хакер Хакер
последний пост 59 минут назад
В Ruby on Rails устранили критическую RCE-уязвимость
В Ruby on Rails устранили критическую RCE-уязвимость В Ruby on Rails устранили критическую RCE-уязвимость

Разработчики Ruby on Rails исправили критическую уязвимость в Active Storage.

Уязвимость затрагивает Ruby on Rails версий от 7.0.0 до 7.2.3.1, от 8.0.0 до 8.0.5 и от 8.1.0 до 8.1.3.

Исправления уже вошли в состав Ruby on Rails 7.2.3.2, 8.0.5.1 и 8.1.3.1.

Active Storage передает его библиотеке libvips, обрабатывает HDF5-контейнер, обращается к указанному в нем файлу на удаленно сервере и считывает его содержимое.

В частности, рекомендуется заменить secret_key_base, мастер-ключ, пароли баз данных, ключи Active Storage и сторонние токены.

59 минут назад @ xakep.ru
Google Chrome сможет блокировать расширения, подменяющие страницу новой вкладки
Google Chrome сможет блокировать расширения, подменяющие страницу новой вкладки Google Chrome сможет блокировать расширения, подменяющие страницу новой вкладки

Такие расширения подменяют поисковые системы, захватывают страницу новой вкладки и перенаправляют запросы на сомнительные ресурсы.

В настоящее время организации могут использовать корпоративные политики Chrome, чтобы принудительно устанавливать расширения и управлять настройками браузера.

К примеру, вредонос может без разрешения пользователя добавить локальные ключи политик в Chrome, установить расширение, сменить поисковую систему или страницу новой вкладки.

Если ранее управляемый компьютер потеряет доверенный статус, но в системе останутся локальные ключи политик, Chrome автоматически удалит расширения, подменяющие поисковик или страницу новой вкладки.

Также в Chrome добавят специальные м…

2 часа назад @ xakep.ru
LD_PRELOAD Reloaded. Закрепляемся в Linux — от перехвата функций до руткита BEURK
LD_PRELOAD Reloaded. Закрепляемся в Linux — от перехвата функций до руткита BEURK LD_PRELOAD Reloaded. Закрепляемся в Linux — от перехвата функций до руткита BEURK

Пос­ле сбор­ки исполня­емые фай­лы попада­ют в bin/ , а раз­деля­емые биб­лиоте­ки — в lib/ .

so bin lib : mkdir -p $@ clean : rm -rf bin lib .

Если сиг­натуры разой­дут­ся, ком­понов­щик не свя­жет нашу фун­кцию с вызовом sleep в прог­рамме и перех­вата не про­изой­дет.

soДаль­ше наша задача — зафик­сировать три сос­тояния GOT для фун­кции sleep :В самом начале, до того, как ком­понов­щик начал заг­ружать биб­лиоте­ки.

На самом деле _start находит­ся не в нашей прог­рамме, а в динами­чес­ком ком­понов­щике ld-linux-x86-64.

4 часа назад @ xakep.ru
Google случайно заблокировала сотни сайтов на платформе Blogger
Google случайно заблокировала сотни сайтов на платформе Blogger Google случайно заблокировала сотни сайтов на платформе Blogger

Автоматическая модерация Google заблокировала сотни легитимных сайтов на платформе Blogger, ошибочно обвинив их владельцев в распространении малвари.

Другие пользователи пишут, что столкнулись с иным поведением системы: после подачи апелляции их сайты восстанавливали, однако позже снова удаляли.

При этом автоматическое уведомление предупреждает, что Google может окончательно удалить блог в течение трех месяцев, если его владелец не подаст апелляцию.

Представители Google сообщили изданию, что им уже известно о проблеме и в компании работают над ее исправлением:«Нам известно об ошибке, из-за которой некоторые размещенные на платформе Blogger сайты, ошибочно помечались как вредоносные.

В Googl…

5 часов назад @ xakep.ru
Модели OpenAI и Anthropic атаковали реальных людей и проекты
Модели OpenAI и Anthropic атаковали реальных людей и проекты Модели OpenAI и Anthropic атаковали реальных людей и проекты

Хотя агентам было разрешено атаковать только киберполигон, им не объясняли, как они могут использовать доступ в интернет, и не предупредили, что следует избегать взаимодействия с реальными людьми и системами.

Более того, агент создал второй аккаунт и от его имени заявил, что якобы проверил код и не нашел в нем проблем.

Дело в том, что первый агент оставил в README инструкции для совместной работы и рекомендации по использованию созданных им аккаунтов и артефактов.

Аналитики AISI пишут, что не могут с точностью утверждать, понимал ли Mythos 5, что атакует реальных людей.

В компании подчеркнули, что агент не эксплуатировал 0-day-уязвимости и не совершал побег из песочницы.

7 часов назад @ xakep.ru
СМИ: более 60% сессий в мобильных сетях ЦФО проходили с ограничениями
СМИ: более 60% сессий в мобильных сетях ЦФО проходили с ограничениями СМИ: более 60% сессий в мобильных сетях ЦФО проходили с ограничениями

В остальных случаях абонентам были доступны лишь ресурсы из «белого списка» Минцифры, а в приграничных регионах доля ограниченных подключений приблизилась к 90%.

Специалисты Vigo изучили около 1 млрд пользовательских сессий и подсчитали, что с января по июль количество подключений в режиме «белого списка» в Центральном федеральном округе выросло в среднем на 31%.

В Москве и Московской области интернет работал без ограничений примерно в 49% случаев, тогда как остальные 51% подключений проходили по «белым спискам».

В Санкт-Петербурге доля сессий без ограничений составила 43,9%, а в Ленинградской области — 58,9%.

Директор по продуктам Vigo Антон Прокопенко сообщает, что доля сессий без огранич…

9 часов назад @ xakep.ru
Samsung банит ТВ-приложения, которые могут превращать устройства прокси
Samsung банит ТВ-приложения, которые могут превращать устройства прокси Samsung банит ТВ-приложения, которые могут превращать устройства прокси

Специалисты норвежской ИБ-компании Mnemonic обнаружили в популярных приложениях для телевизоров Samsung код, который позволяет превращать устройства в прокси и пропускать через них чужой трафик.

После публикации этого исследования представители Samsung сообщили, что уже запретили регистрацию новых приложений с прокси-функциями.

Также в компании готовят новые правила, прямо запрещающие использование SDK резидентных прокси, и намерены удалить из магазина все приложения с подобными компонентами.

В случае подтверждения телевизор начинал работать как выходной узел прокси (в фоновом режиме), вплоть до удаления приложения.

Следует отметить, что в прошлом месяце аналогичное решение приняли в компан…

1 day назад @ xakep.ru
Автомобили с системами безопасности KARR и SWDS можно взломать через Bluetooth
Автомобили с системами безопасности KARR и SWDS можно взломать через Bluetooth Автомобили с системами безопасности KARR и SWDS можно взломать через Bluetooth

Исследователи Калифорнийского университета в Сан-Диего (University of California San Diego, UCSD) обнаружили серьезную уязвимость в автомобильных охранных системах KARR и SWDS.

Оказалось, что как минимум 2,2 млн машин можно открыть через Bluetooth, находясь в непосредственной близости от автомобиля.

Дело в том, что несколько лет назад команда UCSD исследовала скиммеры и в ходе тестов заметила незнакомые Bluetooth-сигнатуры.

Устройства KARR и SWDS устанавливают в автомобили в дилерских центрах.

«Описанная в исследовании уязвимость отличается высокой сложностью и в реальных условиях представляет низкий риск для клиентов.

1 day, 2 hours назад @ xakep.ru
Преступное закрытие. Расследуем, как пошла на дно биржа BitMart
Преступное закрытие. Расследуем, как пошла на дно биржа BitMart Преступное закрытие. Расследуем, как пошла на дно биржа BitMart

Кит (имя изме­нено в целях кон­фиден­циаль­нос­ти) поль­зовал­ся BitMart уже два года и никог­да не стал­кивал­ся с проб­лемами в работе плат­формы.

«Я начал вывод средств 26 июля в 8:34 утра, и на момент написа­ния статьи заяв­ки так и не обра­бота­ны.

Но это не помог­ло.

Под­дер­жка не отве­чала на его обра­щения, и средс­тва так и не пос­тупили на его кошель­ки.

Бир­жа рекомен­довала кли­ентам отправ­лять все зап­росы на вывод средств до 05:00 UTC 26 августа 2026 года.

1 day, 4 hours назад @ xakep.ru
Червь ChainDrop заразил более 1300 пакетов npm
Червь ChainDrop заразил более 1300 пакетов npm Червь ChainDrop заразил более 1300 пакетов npm

Самораспространяющийся вредонос ChainDrop скомпрометировал более 1300 пакетов в реестре npm, на которые суммарно приходится около 2 млрд установок в месяц.

Сразу несколько ИБ-компаний сообщают, что за этой кампанией стоит червь под названием ChainDrop, основанный на исходном коде Shai-Hulud, а общее количество скомпрометированных пакетов уже превышает 1300 и продолжает расти.

Загрузчик скачивал официальный рантайм Bun с GitHub, запускал с его помощью инфостилер, а затем удалял временную директорию.

Кроме того, червь ищет в зараженных системах и CI/CD-раннерах учетные данные, открывающие доступ к другим репозиториям и пакетам npm.

Списки скомпрометированных пакетов и индикаторы компрометации…

1 day, 5 hours назад @ xakep.ru
Книги «Хакеры.RU» и «Белый хакер» еще можно заказать в печатном виде
Книги «Хакеры.RU» и «Белый хакер» еще можно заказать в печатном виде Книги «Хакеры.RU» и «Белый хакер» еще можно заказать в печатном виде

В нашем магазине по-прежнему доступны печатные версии романов Валентина Холмогорова «Хакеры.RU» и «Белый хакер» с черно-белыми иллюстрациями.

Книга «Хакеры.RU» рассказывает о двух парнях из небольшого города, которые по разным причинам погружаются в хакинг и постепенно обнаруживают, как код, человеческие ошибки и случайные встречи меняют их судьбы.

Валентин Холмогоров не только ведущий редактор «Хакера», но и писатель, журналист, публицист и автор более 40 учебников и 8 романов.

Он участвовал в межавторском цикле «Пограничье» Сергея Лукьяненко, а одна из книг в этом цикле была написана в соавторстве с ним самим.

Если ты еще не знаком с этой историей, первые главы романов можно прочитать на …

1 day, 6 hours назад @ xakep.ru
Павел Дуров объяснил, почему Telegram удалили из App Store
Павел Дуров объяснил, почему Telegram удалили из App Store Павел Дуров объяснил, почему Telegram удалили из App Store

Apple на короткое время исключила Telegram из App Store по всему миру.

Вечером 3 августа 2026 года пользователи заметили, что Telegram исчез из поисковой выдачи App Store по всему миру, а прямая ссылка на страницу мессенджера отображала ошибку.

«Прошлой ночью Apple ненадолго удалила Telegram из App Store, потому что один пользователь подбросил незаконный порнографический контент в публичный групповой чат», — пишет Дуров в своем Telegram-канале.

Из-за давней даты публикации сообщения участники чата не заметили произошедшего и не смогли вовремя отреагировать и пожать жалобу.

По его словам, Telegram удалили из App Store еще до того, как представители компании связались с разработчиками.

1 day, 7 hours назад @ xakep.ru
Кошельки хакера Coldcard превратились в доску объявлений
Кошельки хакера Coldcard превратились в доску объявлений Кошельки хакера Coldcard превратились в доску объявлений

Адреса, на которых осели украденные в результате крупной атаки биткоины, неожиданно стали публичной доской объявлений: жертвы взлома и предприимчивые пользователи платят небольшие суммы, чтобы оставить хакеру сообщение прямо в блокчейне.

Речь идет об адресе злоумышленника, стоящего за масштабной атакой на аппаратные кошельки Coldcard, которая началась 30 июля 2026 года.

Однако ничто не мешает обычным пользователям использовать ее и для личных посланий.

Именно поэтому люди, потерявшие деньги из-за взлома, отправляют на адрес хакера символические суммы в биткоинах с сопроводительными сообщениями в надежде, что хотя бы часть средств вернется.

Другое сообщение вообще не связано с атакой на Cold…

1 day, 8 hours назад @ xakep.ru
ИИ-модель Mythos обнаружила недостаток в постквантовом алгоритме HAWK
ИИ-модель Mythos обнаружила недостаток в постквантовом алгоритме HAWK ИИ-модель Mythos обнаружила недостаток в постквантовом алгоритме HAWK

Разработчики постквантового алгоритма HAWK отозвали его из программы стандартизации NIST после того, как модель Claude Mythos Preview помогла разработать более эффективную атаку на алгоритм.

Кроме того, модель Anthropic ускорила известную атаку на сокращенную версию AES-128 в 200–800 раз.

В компании пишут, что на исследование ушло около 60 часов работы модели и примерно 100 000 долларов США на использование API.

Авторы HAWK уже подтвердили выводы Anthropic и сообщили, что приняли решение выйти из программы стандартизации NIST: простые меры защиты, включая удвоение параметров, сделали бы алгоритм неконкурентоспособным.

С учетом дополнительных вычислений это ускоряет атаку в 200–800 раз.

1 day, 9 hours назад @ xakep.ru
Данные полиции и госслужащих Великобритании попали в даркнет
Данные полиции и госслужащих Великобритании попали в даркнет Данные полиции и госслужащих Великобритании попали в даркнет

Имена, рабочие email-адреса сотрудников полиции, госслужащих и других пользователей сервиса уже опубликованы в даркнете.

PNLD предоставляет полиции и другим организациям, работающим в системе уголовного правосудия, юридические материалы и справочную информацию.

В PNLD подчеркивают, что пароли и другие учетные данные, судя по имеющейся информации, в ходе атаки не пострадали.

Также представители организации напомнили, что PNLD не связана с Police National Computer или Police National Database, не используется для регистрации преступлений и не хранит конфиденциальные сведения о жертвах, свидетелях и преступниках.

Злоумышленники требуют выкуп, а в противном случае угрожают обнародовать всю похи…

2 days назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 2 часа назад
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

AMD published a bulletin on August 6, AMD-SB-7061, titled "Safe RET Interrupt Vulnerability," naming Zen 1 through Zen 4 processors as affected.

According to the paper the researchers shared with The Hacker News, Intel does not consider a mitigation necessary.

The Hacker News has contacted AMD, Intel, and Arm for comment and will update this story with any response.

Intel does it on kernel entry, with eIBRS and, depending on the processor, either a branch history buffer clearing loop or the BHI_DIS_S control.

Blocking interrupts for the length of the window would carry a performance cost the paper does not quantify.

2 часа назад @ thehackernews.com
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.

This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.

Just ordinary systems trusting slightly too much, slightly too early.

It is that trust keeps accumulating in quiet places: package managers, project files, assistants, provisioning tools, remote access software, and forgotten systems nobody planned to revisit.

Somewhere between “trusted” and “probably fine.” That gap is where this week lived, and it will be there next week too.

3 часа назад @ thehackernews.com
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities.

Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised.

That figure counts exposed controllers, not water utilities or confirmed victims.

Forescout found more than 70% of the US-based exposed controllers on large mobile carrier networks.

Forescout said 19 of the 22 controllers in affected cities ran firmware susceptible to CVE-2017-16740 (Rockwell CVSS score: 8.6).

6 часов назад @ thehackernews.com
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases.

Bexo Wallet , which Coinspect says has been fixed in version 20.1.0, although the updated builds had not yet been uploaded.

A recovery phrase generated by an affected version remains guessable wherever it is imported, including into a hardware wallet.

Apple's App Store listed version 18.3.5 as the current iPhone release, while Google Play showed an Android update on May 20 but no public version number.

Version 1.3.0 includes a tool to generate a new seed and move the funds.

6 часов назад @ thehackernews.com
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Cybersecurity researchers have disclosed a security issue with Apple's iCloud Private Relay tool that can expose a user's real IP address.

"The same leaks also affect Apple's iCloud Private Relay."

]app" has been made available for anyone to check if their real IP address leaks, even when Private Relay is on.

This is not the first time security issues have been discovered in iCloud Private Relay.

Shortly after the feature was released in 2021, FingerprintJS highlighted a WebRTC-based mechanism that leaked a client's real IP address.

6 часов назад @ thehackernews.com
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

Download the free AI Memory Poisoning Defense Cheat Sheet (PDF): DOM monitoring patterns, memory audit prompts, and remediation steps.

Memory poisoning Security vendor Competitor TL;DR "Create TLDR of [URL].

SEO generators: Free tools build customized "Ask AI" buttons across all major platforms, pitching memory retention instructions as standard practice.

Reflectiz monitors this layer continuously, automatically flagging "Ask AI" links carrying memory instructions before anyone has the chance to click.

[Download the AI Memory Poisoning Defense Cheat Sheet (PDF)]

6 часов назад @ thehackernews.com
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk.

They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine.

The flaw sat in the application, where an autocomplete search field passed unvalidated input to the database over a Java Database Connectivity (JDBC) connection.

Finding the toolkit means hunting: search the Oracle installation for object names beginning Khunt, and SQL logs for KHUNT%.

Those indicators are specific to this toolkit, so no search for Khu…

9 часов назад @ thehackernews.com
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them.

Immediately above the check sits a narrower branch that restores a tool-use message the agent stored before an interrupt, rather than taking whatever sits in the latest message.

Authorize at execution time: Bind each tool invocation to the exact model event, tool name, arguments, session, and authorization state that produced it.

Bind each tool invocation to the exact model event, tool name, arguments, session, and authorization state that produced it.

There is no probabilistic model to fool…

9 часов назад @ thehackernews.com
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.

"ENDLESSDOORS, at its core, is a small tool called rctl (remote control linux)," Jacob Baines, VulnCheck Chief Technology Officer, said.

"That is a live interactive root shell."

"The vocabulary of this protocol is two phrases: run this as root, and give me a root shell.

]125)As of writing, users visiting the firmware downloads page on Zbtlink's website are displayed the below message -We have detected firmware security vulnerabilities affecting selected router firmware releases.

10 часов назад @ thehackernews.com
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021.

Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department.

Accounts of when Ransom Cartel began have never lined up: prosecutors date the operation to May 2021, while Palo Alto Networks' Unit 42 did not observe it until mid-January 2022.

Silnikau ran the operation under another name from May 2021, renamed it "Ransom Cartel" in late 2021, then tried to publicize it…

11 часов назад @ thehackernews.com
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

"JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol," CISA said.

The exact impact varies depending on the privileges granted to the TeamCity server process.

A successful attack can expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines, per JetBrains.

Per Bi…

11 часов назад @ thehackernews.com
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts.

The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people.

Moucka also re-extorted at least one victim, prosecutors said, threatening further disclosure using the stolen data of a government officer and members of a then-former government officer's immediate family.

Victim companies suffered more than $9.5 million in actual losses, a figure that excludes losses to their own customers.

Snowflake has enforced MFA by default for human …

12 часов назад @ thehackernews.com
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.

The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download.

The attack still requires the user to copy and run an obfuscated command in Terminal.

That command retrieves scripts and launches an infostealer targeting credentials, browser data, authentication stores, cryptocurrency wallets, and sensitive files.

A request resembling a genuine Mac in the expected context recei…

23 часа назад @ thehackernews.com
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes.

To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive ties to scam compounds and human trafficking in the past.

"The operation illustrates an important reality about modern scam networks: organized criminal groups rarely restrict themselves to a single type of scam," OpenAI said.

Some accounts in the network generated content that is consistent with hum…

23 часа назад @ thehackernews.com
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.

Poison Claude accepts payments in cryptocurrencies.

Once a customer completes a payment, they are provisioned an API key for an Anthropic-compatible API and instructed to set certain environment variables to ensure that their development environment (i.e, Claude Code) uses the Poison Claude API instead of Anthropic's.

The main domain for Poison Claude, poison-claude.bitsender[.

These services offer API relay or proxy platforms that allow local developers in China to access the models.

1 day, 2 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 6 days, 4 hours назад
This month in security with Tony Anscombe – July 2026 edition
This month in security with Tony Anscombe – July 2026 edition This month in security with Tony Anscombe – July 2026 edition

Researchers at Sysdig have documented what they assess to be the first case of an end-to-end ransomware operation executed by an agentic threat actor.

What can organizations do to stop phantom squatting from harming their brands, and what other lessons do these incidents hold for defenders?

Watch Tony's video to find out and be sure to check out the June 2026 edition of his monthly security news roundup for more insights.

Before you go, learn about the first AI-powered ransomware, named PromptLock and discovered by ESET researchers last year.

To learn more about cutting-edge AI defense layers, read the AI at ESET white paper.

6 days, 4 hours назад @ welivesecurity.com
Beyond the screenshot: Why you should verify what you see
Beyond the screenshot: Why you should verify what you see Beyond the screenshot: Why you should verify what you see

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuineSomeone sends you a screenshot showing that a payment has gone through.

Why screenshot aren’t proof on their ownA screenshot is ultimately just an image of what appeared on a screen.

Reassured, you send the item off, only to find out the screenshot was a fake and you’re not getting your money.

You receive a password reset code, then get a text message (maybe impersonating a friend) asking you to screenshot and send it.

This screenshot is fake (source: Reddit)Challenges for businessesFrom a business perspective, internal and customer-facing teams are often provided with sc…

1 week назад @ welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

3 weeks, 2 days назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

4 weeks, 1 day назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

1 month назад @ welivesecurity.com
This month in security with Tony Anscombe – June 2026 edition
This month in security with Tony Anscombe – June 2026 edition This month in security with Tony Anscombe – June 2026 edition

It's that time of month when ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses.

What lessons does the new CISA policy hold for organizations outside the agency's direct remit?

What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems?

How can you stay safe from imposter fraud, and could the social media bans for children work?

Learn more from Tony's video and be sure to check out the May 2026 edition of Tony's monthly security news roundup for more insights.

1 month, 1 week назад @ welivesecurity.com
Inside the inbox: Why cybercriminals want to break into your email account
Inside the inbox: Why cybercriminals want to break into your email account Inside the inbox: Why cybercriminals want to break into your email account

With access to your email account, they can reset your passwords across multiple other accounts – perhaps intercepting one-time passcodes sent by your bank, social media, cloud storage or other online provider.

That could lay the groundwork for a convincing phishing email designed to impersonate a trusted organization you interact with.

A phishing attack on your corporate email account is often the first stage in a bigger data breach, extortion/ransomware or espionage attack.

They’re also using more sophisticated tools to improve the success rates of email phishing campaigns.

In this instance the scammers reportedly hijacked the email account of a high-level executive, before impersonating …

1 month, 1 week назад @ welivesecurity.com
SMB cyber readiness: the road to resilience starts here
SMB cyber readiness: the road to resilience starts here SMB cyber readiness: the road to resilience starts here

For these businesses, cyber resilience should be the direction of travel – that is, the ability to continue operating and recover even during a serious incident.

Cyber readiness is about putting in place the processes and controls to prevent, detect and respond to threats.

So, should confidence in cyber resilience posture be so high, especially if organizations are still getting hit multiple times?

The truth is that there’s no end state for cyber readiness or resilience.

If it’s serious about improving the cyber readiness of small businesses, the vendor community should step up.

1 month, 1 week назад @ welivesecurity.com
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Key points of this blogpost: Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.

Continued data exfiltration and a new allianceThroughout 2025, Gamaredon stayed highly active and remained focused solely on Ukraine.

Notably, we uncovered that in early 2025, Gamaredon collaborated with Turla, another Russia-aligned threat actor also linked to the FSB; we documented our findings in our blogpost Gamaredon X Turla collab.

Figure 1 shows a chart of unique samples of HTA downloaders delivered per month in Gamaredon spearphishing campaigns.

Compared to 2024, we also saw a shift in how Gamaredon used these dead drops.

1 month, 1 week назад @ welivesecurity.com
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET takes part in Operation Endgame to disrupt Amadey and Stealc

Key points of this blogpost: ESET took part in the coordinated, global Operation Endgame to disrupt Amadey and Stealc.

Our automated systems have been dissecting Amadey and Stealc samples and identifying the fields most relevant for large-scale tracking.

The largest Amadey botnet clusterOne cluster stands out as the largest, and it contributed nearly 34% of all processed Amadey samples.

Stealc affiliate clustering based on ESET telemetryConclusionFor global disruption operations such as Operation Endgame against Amadey and Stealc, long-term automated tracking of malware is necessary.

2026‑04‑09 Stealc C&C server.

1 month, 1 week назад @ welivesecurity.com
Killing me gently: Inside Gentlemen’s EDR killer framework
Killing me gently: Inside Gentlemen’s EDR killer framework Killing me gently: Inside Gentlemen’s EDR killer framework

The group distinguishes itself through a mature, operator-maintained set of endpoint detection and response (EDR) killers, i.e., tools for disrupting security software.

In this blogpost, we share our findings on Gentlemen’s suite of EDR killers gained through extensive research and corroborated by the recent leak.

Third‑party EDR killers (HexKiller, ThrottleBlood, and HavocKiller) are operationally integrated.

Rather than relying on affiliates to source their own EDR killers, Gentlemen operators actively develop and maintain a portfolio of EDR killers for affiliates.

It allows the Gentlemen operators to integrate abused drivers into their toolset very soon after an EDR killer PoC is disclos…

1 month, 2 weeks назад @ welivesecurity.com
Protecting legacy OT systems against modern cyberthreats
Protecting legacy OT systems against modern cyberthreats Protecting legacy OT systems against modern cyberthreats

Of course, connecting production systems to enterprise networks delivers tangible benefits, but the security implications – that systems once safe were suddenly no longer so – arrived more quietly.

Start by mapping which systems in an environment are connected and have no security coverage, where IT and OT networks intersect, which segments are unmonitored, and which production systems have fallen outside any vendor support agreement.

Meanwhile, off-the-peg security tools often don’t efficiently meet the enterprise requirements in legacy OT systems that run on older hardware and outdated operating system versions.

The production systems running that version continue to operate for years, ac…

1 month, 2 weeks назад @ welivesecurity.com
FishMonger’s arsenal upgraded: SprySOCKS for Windows
FishMonger’s arsenal upgraded: SprySOCKS for Windows FishMonger’s arsenal upgraded: SprySOCKS for Windows

Key points of this blogpost: We discovered two previously undocumented Windows variants of FishMonger’s SprySOCKS backdoor.

Technical analysisIn this section, we provide a technical analysis of these new, Windows variants of FishMonger’s SprySOCKS backdoor.

Figure 3. klelam00007.bat setting up persistence for the SprySOCKS backdoor (newlines added for readability)Figure 4 depicts the execution chain of the SprySOCKS WIN_DRV variant.

It contained the SprySOCKS backdoor and the SprySOCKS loader.

6490B8E4AADE25A3EE2D A9A47F312DB2122470BC X1B5206BDC1 743DD.dat Win64/SprySOCKS.A Encrypted container of the encrypted WIN_DRV variant of SprySOCKS backdoor, encrypted SprySOCKS RawWNPF and SprySOCKS …

1 month, 3 weeks назад @ welivesecurity.com
EvilTokens: A phishing attack that doesn’t steal your password
EvilTokens: A phishing attack that doesn’t steal your password EvilTokens: A phishing attack that doesn’t steal your password

Instead, attackers get the victim to complete a legitimate authentication process – including two-factor authentication (2FA) – on a real Microsoft login page.

What makes EvilTokens dangerousThe OAuth device code flow was designed for devices that may be awkward to sign into directly, such as smart TVs or printers.

No document, invoice, email, or another platform should ask for a device code without a clear reason.

A real Microsoft page doesn’t automatically make a request safe.

Sometimes the attacker could ask them to enter a real code on a real page – but for the wrong device.

1 month, 3 weeks назад @ welivesecurity.com
OceanLotus: From external espionage to domestic targeting
OceanLotus: From external espionage to domestic targeting OceanLotus: From external espionage to domestic targeting

During this period, the Vietnam-aligned OceanLotus adopted a more selective approach to external operations while placing increasing emphasis on domestic espionage.

We identified two distinct campaigns involving the SPECTRALVIPER backdoor: a supply-chain attack targeting stock investors in Vietnam and a prolonged espionage operation against a Vietnamese infrastructure and transport construction company.

The domain resolved to the genuine IP address of the FireAnt update server, suggesting a supply-chain compromise scenario.

LTD 2025‑09‑20 SPECTRALVIPER C&C server.

]com IRT‑CHOOPALLC‑AP 2025‑09‑20 SPECTRALVIPER C&C server.

1 month, 3 weeks назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 39 минут назад
Photos: Black Hat USA 2026, part two
Photos: Black Hat USA 2026, part two Photos: Black Hat USA 2026, part two

Round two from Black Hat USA 2026.

This set covers the parts of the show floor that did not make the first gallery.

Scroll through below.

Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security,Featured speaker: Kate Silverstein (Mozilla) discussing crowd-sourcing protection against real-world LLM attacks.

39 минут назад @ helpnetsecurity.com
Novel-reading apps used users’ phones to generate fake ad traffic
Novel-reading apps used users’ phones to generate fake ad traffic Novel-reading apps used users’ phones to generate fake ad traffic

A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab.

“Papyrus is built around BootNova, an orchestration layer that controls hidden browser activity inside the app.

Papyrus automates hidden browsingPapyrus drives the hidden browser windows two ways.

“A hidden page load can create invalid traffic,” the researchers warned.

“A hidden page load combined with automated clicks and scrolling can distort performance reporting and attention-based evaluation, leading to misinformed campaign optimization strategies.”That’s the part that reaches past wasted ad spend.

4 часа назад @ helpnetsecurity.com
Photos: Black Hat USA 2026
Photos: Black Hat USA 2026 Photos: Black Hat USA 2026

Help Net Security newsletters : Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.

4 часа назад @ helpnetsecurity.com
Three in four AI-generated vulnerability patches leave something broken
Three in four AI-generated vulnerability patches leave something broken Three in four AI-generated vulnerability patches leave something broken

Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix.

The models fix the example, not the bugHand a model a reproducer that demonstrates one malicious input and it patches that input’s code path.

Kernel maintainers closed it separately, in a commit of its own.

The only patches that closed it came from runs the researchers had already thrown out for copying the official fix.

The models patch the bug in the ticket, and nothing else, even when the something else is in front of them.

5 часов назад @ helpnetsecurity.com
Snowflake hacker pleads guilty, faces up to 32 years in prison
Snowflake hacker pleads guilty, faces up to 32 years in prison Snowflake hacker pleads guilty, faces up to 32 years in prison

A Canadian man is facing decades in prison for hacking customer accounts at cloud storage provider Snowflake and stealing data from more than 165 organizations.

He is due to be sentenced on October 27 and faces up to 32 years in prison.

In one case, Moucka attempted to extort a victim a second time by threatening to disclose additional stolen data.

The group also advertised stolen data for sale on BreachForums, Exploit.in, XSS.is, and Telegram.

Organizations publicly linked to the Snowflake campaign include AT&T, Ticketmaster, Santander, Advance Auto Parts, LendingTree, Neiman Marcus, Pure Storage, and Bausch Health.

5 часов назад @ helpnetsecurity.com
Discounted Claude access bought on the gray market may expose every prompt you send
Discounted Claude access bought on the gray market may expose every prompt you send Discounted Claude access bought on the gray market may expose every prompt you send

Poison ClaudeOne such site, Poison Claude, claims to offer access to four Anthropic models: Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6.

Advertisements for Poison Claude (Source: Okta)Advertisements for Poison Claude describe how the service keeps token prices low.

Poison Claude takes payment in several cryptocurrencies, including Tether, USD Coin, Ethereum, Litecoin, and Bitcoin.

The main domain for Poison Claude, poison-claude.bitsender[.

Like Poison Claude, Ecomagent left an unauthenticated API route exposed, showing total and active user counts, both under 1,000.

7 часов назад @ helpnetsecurity.com
Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200) Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)

Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface.

Customers are urged to upgrade devices running affected IOS XE or Catalyst SD-WAN releases to the fixed releases listed in each advisory.

Cisco also fixed CVE-2026-20200, a vulnerability in Cisco Integrated Management Controller (Cisco IMC), the system that data center technicians and admins use to manage Cisco UCS C-Series rack servers and S-Series storage servers (even when their OS is not responding).

CVE-2026-20200 affects the web-based management interface of Cisco IMC, and is due to improper va…

7 часов назад @ helpnetsecurity.com
Microsoft extends zero trust deeper into enterprise AI
Microsoft extends zero trust deeper into enterprise AI Microsoft extends zero trust deeper into enterprise AI

Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop.

The additions help organizations assess security posture, prioritize remediation, and apply zero trust principles to AI agents and AI-assisted software development.

Zero Trust Assessment adds AI pillarZero Trust Assessment is a free tool that automatically evaluates an organization’s Microsoft security configuration against zero trust best practices, identifies weaknesses, and recommends improvements before they can be exploited.

The AI pillar introduces zero trust checks that help organizations evaluate the controls required for secure AI adoption.

Microsoft also pu…

9 часов назад @ helpnetsecurity.com
Photos: Black Hat USA 2026 Arsenal
Photos: Black Hat USA 2026 Arsenal Photos: Black Hat USA 2026 Arsenal

This week Help Net Security is at the Mandalay Bay, where Arsenal is running alongside the Briefings.

If you’ve never been, it’s the corner of Black Hat that feels least like a conference and most like a workshop: a room full of stations where the people who wrote the tools stand behind laptops and show you what they do.

Everything on display is open source, and nearly all of it is available to download the moment you walk away.

The Black Hat Arsenal entranceMakoto “Mr.

Rabbit” Sugita presenting Azazel-EdgeA view of Lab 01Pınar Sadioğlu presenting LoRaCraftLive demo: Attack operationMike Hunhoff presenting CapaLab 04Vikram Narayan presenting PrecoglyWide view of the Black Hat ArsenalRyan Ma…

10 часов назад @ helpnetsecurity.com
OWASP 2026 LLM Top 10: “The model will be fooled”
OWASP 2026 LLM Top 10: “The model will be fooled” OWASP 2026 LLM Top 10: “The model will be fooled”

The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents.

Incorrect, incomplete, unsupported, or misleading output may sound believable to humans and agents, the project leads explained.

Know the limitsOne idea runs through all ten entries, and the leads open with it: “Stop trying to build a model that cannot be fooled.

The OWASP Top 10 for LLM Applications 2026 edition is also unusually clear about its own boundary: it outlines and orders risks related to models as a component inside an application.

“The moment that model becomes an actor, with tools it can call, memory it carr…

12 часов назад @ helpnetsecurity.com
Browser security is where software, data, and AI meet
Browser security is where software, data, and AI meet Browser security is where software, data, and AI meet

It’s where proprietary application logic, third-party software, customer data, and increasingly AI all come together during every customer interaction.

It’s about ensuring that software, data, and AI behave as intended throughout every customer interaction.

The biggest assumption that will prove wrong is that browser security is solely an application security initiative.

Increasingly, software supply chain security, data privacy, AI governance, fraud prevention, compliance, and digital trust all converge in the browser because that’s where software executes, data is created, and AI operates.

Browser security will increasingly become a shared business initiative, not because the browser chan…

12 часов назад @ helpnetsecurity.com
Suppliers, logins, and AI tools are all becoming attack paths
Suppliers, logins, and AI tools are all becoming attack paths Suppliers, logins, and AI tools are all becoming attack paths

AI speeds up attacksThreat actors are using LLMs to generate malware, phishing emails, reconnaissance commands, and scripts after compromising systems.

“AI is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend,” said Adam Meyers, head of counter adversary operations at CrowdStrike.

Cloud credentials under attackCloud-focused cybercrime activity increased 171% over the past year, driven by credential theft, cryptocurrency mining, AI service abuse, and attempts to steal digital assets.

Attackers are targeting cloud credentials, API keys, and secrets stored in cloud services to gain access to cryptocurrency wallets and other valu…

13 часов назад @ helpnetsecurity.com
Non-human identities are 91% of everything active in production
Non-human identities are 91% of everything active in production Non-human identities are 91% of everything active in production

Only 20% of non-human activity in production falls inside standard business hours, which puts a rogue API call at 3 a.m. in the middle of normal traffic.

Machines own the accountNine in ten active identities in production belong to something other than a person.

ClearVector puts the figure at 91% in its 2026 Identity Intelligence Report, drawn from the AWS and Google Cloud environments it monitors, counting service accounts, execution roles, managed identities, and vendor credentials.

Delete and terminate calls account for 3% of non-human activity, with privileged create-and-modify operations adding a few points on top.

The top four vendor identities each reached across the entire productio…

13 часов назад @ helpnetsecurity.com
Cloudflare OS goes open source with a record of everything its agents read
Cloudflare OS goes open source with a record of everything its agents read Cloudflare OS goes open source with a record of everything its agents read

Cloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May.

Two repositories went up on GitHub: a core, and a starter deployment modeled on how Cloudflare runs the thing internally.

The credential never reaches the agentEvery agent and app inside Cloudflare OS starts with access to nothing.

Server code runs in a Dynamic Worker with outbound networking switched off.

Every resource an agent reads gets recorded, and the record stays attached to the agent and to whatever it produced.

14 часов назад @ helpnetsecurity.com
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies, and its internal surface answers to strangers.

They presented it today at Black Hat USA 2026 in a briefing on pre-auth remote code execution in enterprise Java.

The internal surface takes basic auth and feeds whatever it receives to XStream, a library that turns XML into live Java objects.

Tomcat strips the semicolon, treats the remainder as a step up the directory tree, and routes the request onto the internal surface.

What Bonita and OFBiz did nextNovee reported every finding to the affected projects and worked with them before publication.

23 часа назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 7 часов назад
Adversarial Clothing Designed to Fool Facial Recognition Systems
Adversarial Clothing Designed to Fool Facial Recognition Systems Adversarial Clothing Designed to Fool Facial Recognition Systems

There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems.

It’s a cool idea, but I worry that it’s mostly security theater:“Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,” he said.

Bell, however, said “none of these products are tried and tested, and a lot of these surveillance technologies can deal with a little resistance … [but] even if the designs don’t necessarily work perfectly, fashion is also a visible sign of resistance.

“This is consumers collectively coming together to make a visible statement.”

7 часов назад @ schneier.com
Vulnerabilities in Car Anti-Theft Device
Vulnerabilities in Car Anti-Theft Device Vulnerabilities in Car Anti-Theft Device

This is disturbing:…a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.

1 day, 8 hours назад @ schneier.com
Iran Cyberattacks Against Minnesota Water Systems
Iran Cyberattacks Against Minnesota Water Systems Iran Cyberattacks Against Minnesota Water Systems

Iran Cyberattacks Against Minnesota Water SystemsAttribution is preliminary, and so far it seems no real damage.

And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself.

“I would blame it on Minnesota and the governor, the corrupt governor of Minnesota.

They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky.

Iran’s got bigger problems than worrying about Minnesota.”No word on whether he believes the other six states have hacked themselves as well.

1 day, 23 hours назад @ schneier.com
Some Claude Chats Are Searchable on Google
Some Claude Chats Are Searchable on Google Some Claude Chats Are Searchable on Google

Some Claude Chats Are Searchable on GoogleAnd it’s personal information (alternate link):The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data.

Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses.

What seems to be the issue is a user setting about data sharing.

“These shareable links are not guessable or discoverable unless people choose to share them themselves.

When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archive…

2 days, 8 hours назад @ schneier.com
More on the OpenAI Agent’s Attack on Hugging Face
More on the OpenAI Agent’s Attack on Hugging Face More on the OpenAI Agent’s Attack on Hugging Face

From the summary:The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities.

OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment.

The campaign, as we were able to reconstruct it, had two stages:Stage 1: reaching a launchpad by chaining through other parties’ infrastructure.

From that external launchpad, the agent abused our dataset-processing pipeline via two injection vectors, both targeting the same config-driven data loader within our product…

3 days, 1 hour назад @ schneier.com
The OpenAI Hack Shows the Genie Is Out of the Bottle
The OpenAI Hack Shows the Genie Is Out of the Bottle The OpenAI Hack Shows the Genie Is Out of the Bottle

OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6.

Modern AI models exhibit genie behavior: They can do what you ask in ways that you don’t expect or want.

There’s nothing magic about OpenAI’s frontier models; lots of models could have done the same thing.

Even if the U.S. frontier AI companies had some technical advantage, it’s now only a few months’ worth.

Even worse, U.S. companies limit access to their most sophisticated models, fearing being banned by the government if they do not do so.

3 days, 7 hours назад @ schneier.com
Friday Squid Blogging: Squid Helps Discover New Marine Species
Friday Squid Blogging: Squid Helps Discover New Marine Species Friday Squid Blogging: Squid Helps Discover New Marine Species

We could see cells interacting with each other, exchanging material and building skeletons.

And we could do that live on the ship, when usually it takes a couple of weeks of staining and mounting to see anything,” Osborn said.

The expedition discovered thirty-one new marine species in two weeks.

The article doesn’t say if any of them were new species of squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

5 days, 21 hours назад @ schneier.com
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection Anthropic’s Opus 5 Is Better at Resisting Prompt Injection

On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt.

It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated.

The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate.

The other GPT 5.6 variants are less robust, at 30.4% (Terra) and 43.9% (Luna).

A single attempt against GPT 5.6 Sol succeeded 3.1% of the time, higher than the 2.0% an attacker achieved against Opus 5 after fifteen attempts.

6 days, 1 hour назад @ schneier.com
Facial Recognition at Madison Square Garden
Facial Recognition at Madison Square Garden Facial Recognition at Madison Square Garden

Facial Recognition at Madison Square GardenLast month, the story broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition.

Turns out that the system was shut off for Taylor Swift’s wedding.

Evan Greer—one of the people that MSG alerts on—comments:Ironically, Swift herself has reportedly used facial recognition at her own concerts to identify stalkers.

Whatever privacy measures Swift had in place for the wedding seems to have worked.

Posted on July 31, 2026 at 7:08 AM • 0 Comments

6 days, 7 hours назад @ schneier.com
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials

He’s being prosecuted for giving border officials a code that wiped his phone:The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices.

Tunick’s attorneys confirmed GrapheneOS was running on his phone.

The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user’s unlock passcode.

Tunick’s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.

1 week назад @ schneier.com
Should You Use AI for a Task? Here’s a Simple Way to Decide
Should You Use AI for a Task? Here’s a Simple Way to Decide Should You Use AI for a Task? Here’s a Simple Way to Decide

And it will come as no surprise to you that my students regularly use AI to complete their writing assignments.

But if their entire career is going to include AI writing assistants, why shouldn’t they embrace their future?

The writing assignments I give my students are gym tasks, not work tasks.

We hired one regardless of whether we needed work writing or gym writing.

I know fiction writers who supported that poorly paying career with lucrative technical writing work.

1 week назад @ schneier.com
Measuring the Tendency of AI Agents to Go Rogue
Measuring the Tendency of AI Agents to Go Rogue Measuring the Tendency of AI Agents to Go Rogue

In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked.

OpenAI was running the unreleased AI model through a benchmark that tests how well AI can successfully hack systems.

So it chained together stolen credentials and further unknown security exploits to hack the company’s network.

For example, the Chinese lab Moonshot recently warned that its latest AI model may have “excessive proactiveness” and “make unexpected decisions on the user’s behalf”.

The UK’s AI Security Institute has started tracking “cheating behavior in frontier model evaluations”.

1 week, 1 day назад @ schneier.com
Long-Lived Vulnerability in Microsoft Secure Boot
Long-Lived Vulnerability in Microsoft Secure Boot Long-Lived Vulnerability in Microsoft Secure Boot

Microsoft’s Secure Boot has had a serious vulnerability for most of its existence.

An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence.

The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway.

The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software.

The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly availa…

1 week, 1 day назад @ schneier.com
Measuring LLMs’ Ability to Perform Cryptanalysis
Measuring LLMs’ Ability to Perform Cryptanalysis Measuring LLMs’ Ability to Perform Cryptanalysis

There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis.

The benchmark: “CryptanalysisBench: Can LLMs do Cryptanalysis?” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks against a series of historical algorithms.

Abstract: Cryptanalysis—the task of finding attacks against cryptographic schemes—its at the intersection of mathematical reasoning and cybersecurity, two areas where LLMs have advanced fastest.

Cryptanalysis represents both a clean testbed for frontier reasoning (as practical attacks can be automatically verified) and a domain with unusually high stakes, since the primitives under study underpin our digital …

1 week, 1 day назад @ schneier.com
Axon Is Another License Plate Surveillance Company
Axon Is Another License Plate Surveillance Company Axon Is Another License Plate Surveillance Company

Governments are switching, but I’m not sure it makes a difference:…some municipalities, including Denver, Colorado, are ditching their Flock arrays.

But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon, it’s like a gambling addict trying to kick the habit by switching from FanDuel to DraftKings.

[…]Despite what you may read on the Flock website, Axon cameras are pretty effective when it comes to hoovering up personal details that can go far beyond your license plate numbers.

That means a municipality that opts for Axon cameras instead of Flock units won’t necessarily reduce the amount privacy its citizens lose through their use.

1 week, 2 days назад @ schneier.com
Krebs On Security
последний пост 1 час назад
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

1 час назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

1 week назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

2 weeks, 1 day назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

3 weeks, 1 day назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

3 weeks, 3 days назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

4 weeks, 1 day назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

1 month назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

1 month, 2 weeks назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

1 month, 2 weeks назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

1 month, 3 weeks назад @ krebsonsecurity.com
A Record-Breaking Patch Tuesday for June 2026
A Record-Breaking Patch Tuesday for June 2026 A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.

“Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said.

Microsoft received heavily blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher.

While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barne…

1 month, 3 weeks назад @ krebsonsecurity.com
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

On May 31, word began to spread on several Telegram instant message channels that Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow.

Meta has not responded to requests for comment on the video’s claims, but the company reportedly did acknowledge the dormant Instagram account for the Obama White House was briefly compromised.

Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership.

Just like human customer support employees can be social engineered into providing unauthorized access to someone’s a…

2 months назад @ krebsonsecurity.com
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

But as KrebsOnSecurity observed in September 2025, those sanctions failed to target Stark’s remaining connection to the Internet — an Internet service provider based in the Netherlands called MIRhosting.

MIRhosting is operated by Andrey Nesterenko, a 39-year-old Russian native who runs the business out of the Netherlands.

And as our September 2025 report showed, WorkTitans was controlled by Nesterenko and a 57-year-old from Amsterdam named Youssef Zinad.

On top of that, WorkTitans was getting connectivity to the larger Internet solely through MIRhosting, where Zinad had worked previously.

“The transition to the.hosting was not intended to evade sanctions,” Nesterenko wrote.

2 months, 1 week назад @ krebsonsecurity.com
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers Demand Answers as CISA Tries to Contain Data Leak Lawmakers Demand Answers as CISA Tries to Contain Data Leak

The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.

Experts who reviewed the exposed secrets said the commit logs for the code repository showed the CISA contractor disabled GitHub’s built-in protection against publishing sensitive credentials in public repos.

CISA acknowledged the leak but has not responded to questions about the duration of the data exposure.

TruffleHog does this by monitoring a live feed that GitHub publishes which includes a record of all commits and changes to public code repositories.

In practical terms, it is likely that cybercrime groups or foreign adversaries also noticed the publication of these CISA secrets, …

2 months, 2 weeks назад @ krebsonsecurity.com
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

A criminal complaint unsealed today in an Alaska district court charges Jacob Butler, a.k.a.

“Dort,” of Ottawa, Canada with operating the Kimwolf DDoS botnet.

“KimWolf was tied to DDoS attacks which were measured at nearly 30 Terabits per second, a record in recorded DDoS attack volume,” the Justice Department statement reads.

Synthient was among many technology companies thanked by the Justice Department today, and Synthient’s founder Ben Brundage told KrebsOnSecurity he’s relieved Butler is in custody.

The DOJ said at least one of those services collaborated with Butler’s Kimwolf botnet.

2 months, 2 weeks назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 8 часов назад
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits

According to a report in the Financial Times, Apple has found itself facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely hallucinated bug reports.

Unlike traditional spam, AI-generated bug reports include code which may be syntactically correct, references to genuine API calls, and plausible-sounding technical explanations of what is occurring.

But the hallucinated bug report may only have taken a few seconds for an amateur to generate and submit.

Previously, without the assistance of AI, Bynario had filed only 13 bug reports across 2025 and early 2026.

Apple is not the only company trying to deal with a deluge of au…

8 часов назад @ bitdefender.com
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency

How a fake police officer nearly stole Graham's cryptocurrency with Graham Cluley and special guest Danny Palmer.

I said, without being big-headed, it is possible he knows me, but I don't know him.

I don't think my hotels tend to ask me to install something on my computer when I get there.

We had internet, but it was really, really restricted.

And it's really, really good.

19 часов назад @ grahamcluley.com
Fake IRS letters target cryptocurrency holders
Fake IRS letters target cryptocurrency holders Fake IRS letters target cryptocurrency holders

As Coinbase's security team explains, the letters urge recipients to scan a QR code and enrol in a "Digital Asset Compliance Portal" before time runs out.

Bear in mind that the criminals could easily vary these details from letter to letter.

The scam site then asks victims to estimate how much value they have in their cryptocurrency wallets, with ranges up to "$100,000+".

Perhaps a reason why a scam like this can work is that the IRS has been tightening cryptocurrency holders' requirement to report details of their digital assets on their tax returns.

As a result, written communications between the IRS and holders of cryptocurrency have become more frequent.

2 days, 9 hours назад @ bitdefender.com
The $5 million threat: AI Is supercharging phishing attacks
The $5 million threat: AI Is supercharging phishing attacks

According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

6 days, 6 hours назад @ fortra.com
North Korea’s elite hackers turned on their own government – and got caught
North Korea’s elite hackers turned on their own government – and got caught North Korea’s elite hackers turned on their own government – and got caught

For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme.

But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead.

The ringleaders of the group are said to be discharged veterans from a cyber operations unit under North Korea's Reconnaissance and Intelligence General Bureau.

In short, the hackers are accused of building a mini version of the same kind of money-laundering infrastructure North Korea depl…

1 week назад @ bitdefender.com
Smashing Security podcast #478: This job interview could destroy your company
Smashing Security podcast #478: This job interview could destroy your company Smashing Security podcast #478: This job interview could destroy your company

Smashing Security, Episode 478: This Job Interview Could Destroy Your Company, with Graham Cluley and special guest Paul Ducklin.

And all the time you're going through this process, bad news, they really were recording video of you.

Obviously, you can understand that CAR want to know, does your car actually have one of these in all likelihood?

And give it to them and then they tell you whether they think you're at risk.

I don't know.

1 week назад @ grahamcluley.com
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know

The AI models involved were OpenAI's GPT-5.6 Sol and a more capable, as-yet-unreleased model.

The intention of OpenAI's researchers was to get a clear picture of what the AI models were capable of achieving if not constrained.

American AI safety guardrails forced a US company to turn to a Chinese AI model for help.

Hugging Face's CEO Clément Delangue is quoted in OpenAI's blog post, calling on the AI industry to work more collaboratively.

It is clear that advanced AI models are remarkably capable of discovering and exploiting ways to attack real-world systems.

2 weeks назад @ bitdefender.com
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

How 14 orders of Chicken McNuggets helped nail a suspected Russian hacker with Graham Cluley and special guest James Ball.

I had a vindaloo, Graham Cluley, and I don't think it ever touched capsicum.

Yeah, I think you're right.

If you use Suno music, people say, you know, you're killing music.

I don't know much about Shai Hulud.

2 weeks назад @ grahamcluley.com
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Ukraine's computer emergency response team, CERT-UA, has warned that Russian hackers are using fake CAPTCHA checks to trick people into compromising their own PCs.

The Kremlin-backed Sandworm hacking group is reportedly leveraging fake CAPTCHA checks on compromised websites that persuade users to execute a PowerShell command on their computers - tricking them into running malicious code.

The latest attacks begin when a user visits a compromised webpage, where they're greeted by a fake CAPTCHA claiming they need to complete an extra step to prove that they are human.

Instead, the fake CAPTCHA instructs the user to copy and paste a PowerShell command into their Windows computer.

They are a pr…

2 weeks, 2 days назад @ bitdefender.com
Google’s Gemini lets strangers send messages from your locked Android phone
Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini lets strangers send messages from your locked Android phone

Someone gets hold of your locked Android phone and, despite not knowing your security PIN, they can send messages via SMS or WhatsApp pretending to come from you.

It is clear that Google has patched Gemini lock screen issues before, but security researchers keep finding new ways through.

The latest vulnerability is different from the previous similar Gemini-based Android lock screen bypass bugs that have been plaguing the operating system since September 2025.

To do that:Open the Gemini app, tap your profile picture, go to Settings, and select "Gemini on lock screen."

Every new capability Gemini is given at the lock screen is also a new potential attack surface.

2 weeks, 5 days назад @ bitdefender.com
Anubis ransomware: what you need to know
Anubis ransomware: what you need to know

The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.

2 weeks, 6 days назад @ fortra.com
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

That is a really, really busy street potentially.

I don't know what the difference is between a tuk-tuk and a rickshaw.

I don't know.

Yeah, it's got to be a Bluetooth transmitter from the battery, and within the battery there's an operating system or something that'll need updating.

It's really, really great.

3 weeks назад @ grahamcluley.com
The ransomware negotiator who was working for the other side
The ransomware negotiator who was working for the other side The ransomware negotiator who was working for the other side

When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help.

Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf.

41-year-old Martino worked as a ransomware negotiator for DigitalMint, an incident response company based in Chicago.

The ransomware victim, a hospitality company, ultimately paid out nearly US $16.5 million.

The company has since changed the way its negotiators communicate with ransomware gangs, and is working with the Department of Homeland Security to establish a registry for the currently highly-unregulated world of ransomware negotiation.

3 weeks, 2 days назад @ bitdefender.com
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk

Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role?

Security experts have uncovered a phishing campaign which impersonates over 30 well-known brands in fake job interviews designed to steal Google account passwords.

When victims click on "Continue with Google," a pop-up appears that looks like a legitimate Google authentication dialog.

In the past the FBI has warned the public about scammers using fake job ads to steal money and personal information from applicants.

Earlier this year, Hot for Security published a guide explaining how many fake recruiter scams work, and how to avoid them.

4 weeks назад @ bitdefender.com
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself

These stories appear different, but they're actually telling the same story.

I'm going to flag, I'm going to flag the point that I made earlier is that operational security isn't always there.

I know how to do this because it's done it for me, but I don't actually know how to apply it logically.

And when the technology you're relying on to protect you, and in some people's case it is protecting their life, and you're not doing it to the best of your ability, that's, that's really, really disappointing.

But I guess for now, all eyes are on Apple and how they're going to respond to this, albeit 13 months later.

4 weeks назад @ grahamcluley.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 5 часов назад
Аудиослежка за клавиатурным набором | Блог Касперского
Аудиослежка за клавиатурным набором | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f03ed927ed78af1549df453edbc54069Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-06T17:00:43+03:00Config id: 295Faithfully yours, nginx.

5 часов назад @ kaspersky.ru
Как сделать, чтобы вашу компанию не взломали автономные агенты
Как сделать, чтобы вашу компанию не взломали автономные агенты

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f997d2a4543951b403d61a86f614b589Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-04T20:00:20+03:00Config id: 293Faithfully yours, nginx.

2 days, 2 hours назад @ kaspersky.ru
CrashStealer: новый инфостилер для macOS — как он работает и как защититься | Блог Касперского
CrashStealer: новый инфостилер для macOS — как он работает и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64d189df4b1deb932c3c39da09770373Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-03T14:00:09+03:00Config id: 292Faithfully yours, nginx.

3 days, 7 hours назад @ kaspersky.ru
Почему звонят в трубку и молчат | Блог Касперского
Почему звонят в трубку и молчат | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 87a765bcfffecb3be7b631186de73cdfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-30T14:00:37+03:00Config id: 292Faithfully yours, nginx.

1 week назад @ kaspersky.ru
ScreenConnect в кибератаках | Блог Касперского
ScreenConnect в кибератаках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 69f66dfe76ff3f53d09e7e879aff2eabServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-29T19:00:33+03:00Config id: 291Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e1896b8624f52547d7aa4a3bebd90c3cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-27T16:00:28+03:00Config id: 291Faithfully yours, nginx.

1 week, 3 days назад @ kaspersky.ru
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 30ce39da164ccbcb4068b4e06c4c1e60Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-24T19:00:11+03:00Config id: 291Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Инциденты с атаками на ИИ-агентов в бизнесе | Блог Касперского
Инциденты с атаками на ИИ-агентов в бизнесе | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: abb2f672b0aebacf96a83f072ddf5be5Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-23T15:00:29+03:00Config id: 290Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 29288682927681f45f4ebe45b92c4f9dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-22T15:00:12+03:00Config id: 290Faithfully yours, nginx.

2 weeks, 1 day назад @ kaspersky.ru
ConsentFix: новая вариация ClickFix
ConsentFix: новая вариация ClickFix

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 92f538b35cc9db0cd8268f0e9c690524Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-21T12:00:10+03:00Config id: 290Faithfully yours, nginx.

2 weeks, 2 days назад @ kaspersky.ru
Как защитить свои данные после расставания | Блог Касперского
Как защитить свои данные после расставания | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7c4859afeb6714d16332cd516cc382ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-20T13:00:34+03:00Config id: 290Faithfully yours, nginx.

2 weeks, 3 days назад @ kaspersky.ru
Кража почты через OAuth | Блог Касперского
Кража почты через OAuth | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 89a6c1c61d71bc406a42bd2d91dc48b6Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-17T15:00:29+03:00Config id: 290Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
Промпт-атаки на умного помощника Gemini и ИИ-ассистента Gemini Workspace | Блог Касперского
Промпт-атаки на умного помощника Gemini и ИИ-ассистента Gemini Workspace | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 9e57da73febcf1364991851b3ffd4607Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-16T15:00:15+03:00Config id: 290Faithfully yours, nginx.

3 weeks назад @ kaspersky.ru
Ключевые уязвимости Microsoft Patch Tuesday за июль 2026 | Блог Касперского
Ключевые уязвимости Microsoft Patch Tuesday за июль 2026 | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: ad5fb1fb73f446dedef7d1ec45313d70Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-15T17:00:41+03:00Config id: 289Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Meta* включила и тут же отключила функцию генерации ИИ-изображений на основе пользовательского контента в Instagram** | Блог Касперского
Meta* включила и тут же отключила функцию генерации ИИ-изображений на основе пользовательского контента в Instagram** | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: d28ecbce6fae6b24393f114511aa53c1Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-14T15:00:39+03:00Config id: 282Faithfully yours, nginx.

3 weeks, 2 days назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 3 days, 3 hours назад
Is your SD-WAN ready for AI-powered operations?
Is your SD-WAN ready for AI-powered operations? Is your SD-WAN ready for AI-powered operations?

AI Is Changing the Traffic ModelMuch of the enterprise AI conversation centers on models, GPUs, data platforms, and agents.

Time-sensitive performance: Voice AI, edge AI, and physical AI move latency into live operations.

SD-WAN can help maintain operations by prioritizing critical traffic, steering it across the best available path, and applying consistent policy across locations.

Why AI Traffic is an SD-WAN ProblemSD-WAN sits at the point where application intent meets real network conditions.

1 https://www.aboutamazon.com/news/operations/amazon-million-robots-ai-foundation-modelCommon questions about SD-WAN and AI trafficWhat is AI-generated network traffic?

3 days, 3 hours назад @ blogs.cisco.com
The Zero Trust Imperative for the Frontier AI Era
The Zero Trust Imperative for the Frontier AI Era The Zero Trust Imperative for the Frontier AI Era

Their recommendations for securing the AI era rely heavily on establishing strict asset inventory and preventing lateral movement—which are, at their core, fundamental Zero Trust principles.

The Three Core Principles of Zero Trust for AIFounded in three core principles, a robust Zero Trust architecture requires us to execute the following phases comprehensively.

Achieving the Architectural VisionThe above may all sound like pipedream, as most organisations struggle with Zero Trust programs and undelivered microsegmentation projects.

Ultimately AI driven platform approach is what makes Zero Trust achievable for the frontier AI era.

This is exactly why achieving a Zero Trust Architecture for …

6 days, 3 hours назад @ blogs.cisco.com
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes

This provides an opportunity for defenders: if we assume our controls will fail at some point, we can build a much more resilient architecture.

When you assume the current layer will eventually be bypassed, you start designing the next layer proactively instead of reactively.

Defenders need to advance their controls by mapping them to the adversaries’ capabilities then assume that control will fail.

Map your controls to the attack chain.

Call to Action:If you haven’t watched the full video yet, go check it out: Assuming Failure Provides Better Defensive Outcomes (bonus elements around SOC of the Future and business context).

1 week, 3 days назад @ blogs.cisco.com
The Journey towards Logically Air-Gapped Deployment
The Journey towards Logically Air-Gapped Deployment The Journey towards Logically Air-Gapped Deployment

Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter.

This “Logically Air-Gapped” governance model reaches its full operational potential through the implementation of “Live Protect.” As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution.

Reference ArchitectureDigital autonomy is thus exercised by shifting network and security control into the operating system kernel.

Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a un…

1 week, 6 days назад @ blogs.cisco.com
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall

That is why we are introducing Firewall Migration Manager by Cisco, an enterprise-ready product built for that reality.

What Is Firewall Migration Manager?

Firewall Migration Manager is a dedicated migration application that you run in your own environment.

How Firewall Migration Manager WorksThe migration process follows a clear, guided workflow.

Intelligent, integrated migration: Firewall Migration Manager will also come to Cisco Cloud Control, and AI will play an increasing role in guiding teams before and during migration.

2 weeks назад @ blogs.cisco.com
We third-party tested our firewall built for AI-scale. The test tools hit their limit first.
We third-party tested our firewall built for AI-scale. The test tools hit their limit first. We third-party tested our firewall built for AI-scale. The test tools hit their limit first.

In independent testing with NetSecOPEN, the Cisco Secure Firewall 6160 delivered AI-scale inspected throughput beyond what the tools built to measure it could register, all while blocking 100% of tested threats.

These results are specific to Cisco Secure Firewall 6160, but the software capabilities behind Cisco Firewall, including advanced threat protection and high-performance inspection, extend across Cisco Firewall form factors in the cloud, virtually, and on-premises, from campus to data center.

Performance passed the previous benchmark by 5XInspection was turned on, and the test tools built to measure throughput hit their limit before the 6160 firewall did.

In previous NetSecOPEN testi…

3 weeks, 1 day назад @ blogs.cisco.com
SharpHound Recon Attack – How AI enhanced the threat hunt
SharpHound Recon Attack – How AI enhanced the threat hunt SharpHound Recon Attack – How AI enhanced the threat hunt

We innovated by giving the Agentic SOC access to Endace’s always-on, full packet capture, and asked the agent to assess a potential SharpHound Recon attack that we had seen while threat hunting.

This blog explores how we built the integrations and how AI helped us with our threat hunt and threat assessment.

Agentic AI Massively Speeds our AnalysisAt this point, we decided to use Agentic AI capabilities to investigate and assess this potential threat.

ConclusionThe Agentic SOC, blending Agentic AI built into Endace’s products with custom agentic tools, is a massive boost to productivity and security.

AcknowledgementsOur thanks go to the Cisco SOC team led by @Jessica Oppenheimer and @Ivan Be…

1 month назад @ blogs.cisco.com
Machine Speed, Human Judgement: How AI Changed the SOC in 2026
Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Machine Speed, Human Judgement: How AI Changed the SOC in 2026

Having spent time in the Cisco Live Americas 2026 SOC, one thing became abundantly clear:The way SOCs operate today is fundamentally different from even a few years ago.

Instead of spending time gathering information, analysts could spend more time understanding what the information actually meant.

Just as spreadsheets empowered business users decades ago, AI-assisted coding is beginning to empower security analysts today.

At Cisco Live, AI was already present throughout the workflow:Incident summaries generated automatically within XDR.

And based on what I saw at Cisco Live 2026, that future has already arrived.

1 month назад @ blogs.cisco.com
Elevating Expertise in the SOC
Elevating Expertise in the SOC Elevating Expertise in the SOC

The new SOC analysts were great at finding evidence, helped with triage and correlation by the AI agents in the SOC architecture.

With the advancements in Cloud Control, our new SOC Analysts can validate their hypothesis.

They had the ability to investigate the incident and find the root cause found in Splunk Security and Endace.

Instant Attack VerificationIn each Incident, the SOC Analysts is given an AI generated Summary stitching all the relevant logs from all the sources that are related to the objects in question.

Check out the blogs by the engineers who worked inside the SOC at Las Vegas:

1 month назад @ blogs.cisco.com
Educate at Event Speed: Cisco Live Security Operations Center
Educate at Event Speed: Cisco Live Security Operations Center Educate at Event Speed: Cisco Live Security Operations Center

At Cisco Live AMER 2026 in Las Vegas, my work with the Cisco Event SOC centered on one outcome that makes these deployments valuable beyond the event itself: Education.

The SOC protects the conference, but it also turns live operations into a learning environment through SOC tours, Cisco Live sessions, training inside the SOC, and conversations in the World of Solutions.

Bringing live SOC lessons into the classroomEducation also happened in the sessions I delivered at Cisco Live.

Cisco Live AMER 2026 reinforced that the SOC is one of the best classrooms we have because it teaches through real operations.

For a deeper look at the model behind these deployments, read the Cisco Event SOCs: A R…

1 month назад @ blogs.cisco.com
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

Inside the Cisco Live SOCAt Cisco Live AMER, the Security Operations Center (SOC) is more than a demo environment.

For a broader look at how the Cisco Live SOC operates, read this overview.

Another part was spent in the SOC, working real investigations with XDR, Splunk Enterprise Security, firewall events, DNS telemetry, packet data, and AI assistance.

AI can help a product manager become useful faster in a live SOC.

That is the bar I want us to continue building toward as we build Cisco XDR and Splunk Security.

1 month назад @ blogs.cisco.com
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC

As part of the Cisco XDR (Extended Detection and Response) product engineering group, a few of us got exactly that chance.

Every product had a part to play for a network as traffic-heavy as Cisco Live.

(PS : Flaunting the SOC T-shirts was fun)AcknowledgementsA heartfelt thank you to Cisco and the entire SOC team — you are all amazing.

To the Cisco XDR , Splunk , Secure Access , and Secure Firewall engineering teams.

Check out the other blogs from our team at the Cisco Live Americas 2026 SOC at Las Vegas:

1 month назад @ blogs.cisco.com
The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth
The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth

We built an Experience Score model on Cisco and Splunk infrastructure and watched it run against real traffic, at real scale, in real time.

The result was a working model for how leaders measure what customers feel, act before friction surfaces, and tie operational decisions to revenue and trust.

At Cisco Live, the Experience Score model organized that architecture around four questions business and technology leaders can answer together.

The composite Experience Score tells a leader whether the experience is healthy enough to protect the moments the business depends on.

From Cisco Live to LA28Cisco Live was a rehearsal for larger exposure surfaces, where digital experience, revenue, brand …

1 month назад @ blogs.cisco.com
AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026
AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026

And we kept thinking the same engineer thought: this flow is so consistent… could an agentic agent do the first 90%?

It was a great experiment — and a glimpse of a fully self-hosted agentic SOC — but for the event we pivoted to Claude Opus 4.8 running through Claude Code.

The division of labor we landed on: Tier-1 agentic SOC was already handled beautifully by the AI features in our own products — XDR’s Agentic Attack Storyboard and Splunk’s Triage Agent.

What does an agentic SOC actually need?

The MCP servers — an Endace MCP for packet capture/decode and a Splunk MCP for running queries.

1 month назад @ blogs.cisco.com
Building the Agentic SOC at Cisco Live Americas 2026
Building the Agentic SOC at Cisco Live Americas 2026 Building the Agentic SOC at Cisco Live Americas 2026

Building on the Cisco Live EMEA SOC, Cisco Live Americas placed the Security Operations Center (SOC) and Network Operations Center (NOC) at the center of the World of Solutions, demonstrating the power of Cisco in bringing Networking, Security and Observability together.

The Cisco Live Americas Agentic SOC architecture shows how a “One Cisco” approach brings different security tools together to eliminate data silos, in close partnership with the NOC.

The SOC at Cisco Live was set up in just two days, thanks to lessons learned and continuous evolution.

For Cisco Live AMER, we treated agentic AI as an auditable review layer across the SOC, not as a replacement for analysts.

Agentic SOC: Incid…

1 month назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 1 day, 2 hours назад
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

KuppingerCole’s Leadership Compass: Cloud Native Application Protection Platforms (CNAPP) reflects this shift.

The report describes how CNAPP is evolving from a consolidation of cloud security tools into the security foundation for AI-native enterprises, combining cloud security, AI security posture management, runtime protection, attack path analysis, cloud detection and response, and agentic AI operations into unified platforms.

This complexity exposes the limits of traditional, siloed tools, where cloud posture, workload protection, AI security, and the security operations center (SOC) each live in their own console.

Does it see AI models, agents, and pipelines as part of cloud risk, or …

1 day, 2 hours назад @ microsoft.com
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Mitigation and protection guidanceOrganizations can apply the following recommendations to reduce exposure to this and similar macOS ClickFix campaigns:Educate users.

]com Domain ClickFix Webpage filecedarwallet[.]online.

Domain ClickFix Webpage filecopperbasket[.

]sbs Domain ClickFix Webpage filecrimsonsignal[.

]online Domain ClickFix Webpage filemarblegarden[.

1 day, 2 hours назад @ microsoft.com
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
ChainDrop supply chain compromise: Anatomy of a self-propagating worm ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Uses GitHub credentials to inject files into Claude and Visual Studio Code configurations across repository branches for persistence.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, Microsoft Defender for Containers, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelli…

1 day, 18 hours назад @ microsoft.com
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

That’s why we are expanding the Zero Trust for AI strategy with two major additions: a new AI-focused Zero Trust Assessment experience and a new DevSecOps pillar in the Zero Trust Workshop.

Zero Trust Assessment tool updates: New set of assessment checks for AI, Security Operations (SecOps), and Infrastructure.

Zero Trust Workshop updates: New dedicated pillar focused on Developer Security (DevSecOps) and additional guidance for AI Memory.

How to run Zero Trust WorkshopThe Zero Trust Workshop follows a simple three-step motion: plan the right pillars and stakeholders, run the Zero Trust Assessment to establish a baseline, and use the facilitated workshop to turn findings into a 12- to 24-mo…

2 days назад @ microsoft.com
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints.

By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks.

Attack disruption instead uses AI-driven correlation and real-time analysis to identify multi-stage attacks by connecting signals across the environment before taking action.

The resultsTo summarize the results of the new device isolation response action:From first detection, Defender isolated the device in just 128 seconds.

Impact Mitigation (Defender response) – Device Isolation…

2 days назад @ microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence has also identified active traffic manipulation attacks leading to the delivery of malware on impacted systems.

Microsoft Threat Intelligence would like to thank our partners at Anthropic and OpenAI for their collaboration and support during this investigation.

Storm-2945 and Midnight BlizzardMicrosoft Threat Intelligence assesses that Storm-2945 is an operational sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps.

For additional details on Midnight Blizzard-related device code phishing techniques, see: Storm-2372 conducts device code phishing campaign.

To hear stories and insights from the Microsoft Threat Intelligence com…

5 days, 21 hours назад @ microsoft.com
​​​​What’s new in Microsoft Security: July 2026
​​​​What’s new in Microsoft Security: July 2026 ​​​​What’s new in Microsoft Security: July 2026

Microsoft Defender Experts services are also expanding: Microsoft Defender Experts Threat Intelligence delivers human-led, curated insight into the cyberthreats most relevant to each organization, and Microsoft Defender Experts MDR extends expert-run detection and response beyond the Microsoft estate into third-party and multicloud signals through Microsoft Sentinel.

Together, the Insider Risk Management alert experience and Data Security Triage Agent help security teams investigate faster and with greater confidence.

In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy.

To learn more about Microsoft Security solutio…

1 week назад @ microsoft.com
​​Better security starts with better questions
​​Better security starts with better questions ​​Better security starts with better questions

That starts with asking better questions—the kind that help organizations turn intelligence into action and trust into a foundation for progress.

But better security does not start with more information.

Understanding those connections is what allows security teams to use platforms, AI, and automation to make better decisions under real-world conditions.

Better analysis can surface more insights, but better decisions still depend on understanding what matters most and applying the right context.

Better security starts with better questions, and with the clarity to act on them.

1 week, 1 day назад @ microsoft.com
Rethinking security for the age of AI
Rethinking security for the age of AI Rethinking security for the age of AI

The approaches built for a world of human actors cannot keep pace with a world of AI, agents and machine-speed attacks.

Microsoft transforms its breadth of visibility, threat intelligence and security expertise into a security context that connects security data, knowledge and semantics across the digital estate.

By grounding every interaction in this rich security context, Project Perception improves the accuracy and consistency of reasoning while reducing the time, compute and cost required to operate at scale.

Our security researchers continuously assess models against real-world security workflows, enabling us to match each task with the model that delivers the best outcome.

Tags: AI, P…

1 week, 3 days назад @ blogs.microsoft.com
Enhancing AI security through global AI red teaming
Enhancing AI security through global AI red teaming Enhancing AI security through global AI red teaming

Microsoft’s AI Red Team has observed that meaningful testing of advanced AI systems- and models similarly requires broader participation from researchers and practitioners who operate outside traditional corporate security boundaries.

To address that gap, today we are announcing the External Red Team Alliance (EXTRA), a formalized global extension of Microsoft’s AI Red Team designed to support and encourage external expertise to advance AI safety and security testing.

Building a global allianceEXTRA is a two-part initiative focused on expanding AI safety research and strengthening external collaboration.

The first component supports a global academic network focused on advancing AI safety a…

1 week, 3 days назад @ microsoft.com
Enhancing AI security through global AI red teaming
Enhancing AI security through global AI red teaming Enhancing AI security through global AI red teaming

Microsoft’s AI Red Team has observed that meaningful testing of advanced AI systems- and models similarly requires broader participation from researchers and practitioners who operate outside traditional corporate security boundaries.

To address that gap, today we are announcing the External Red Team Alliance (EXTRA), a formalized global extension of Microsoft’s AI Red Team designed to support and encourage external expertise to advance AI safety and security testing.

Building a global allianceEXTRA is a two-part initiative focused on expanding AI safety research and strengthening external collaboration.

The first component supports a global academic network focused on advancing AI safety a…

1 week, 3 days назад @ microsoft.com
Email threat landscape: Q2 2026 trends and insights
Email threat landscape: Q2 2026 trends and insights Email threat landscape: Q2 2026 trends and insights

Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs.

Q2 AiTM token compromise April phishing campaign tactics, detections, and mitigations ›This blog provides a view of email threat activity across the second quarter of 2026, highlighting key trends in phishing techniques, payload delivery, and threat actor behavior observed by Microsoft Threat Intelligence.

email threat landscape Q1 trends that shaped Q2 activity ›Figure 1.

Trend of QR code phishing attacks by weekly volume (January 2026–June 2026)The delivery methods used in QR code attacks shifted notably during Q2.

To he…

2 weeks назад @ microsoft.com
Email threat landscape: Q2 2026 trends and insights
Email threat landscape: Q2 2026 trends and insights Email threat landscape: Q2 2026 trends and insights

Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs.

Q2 AiTM token compromise April phishing campaign tactics, detections, and mitigations ›This blog provides a view of email threat activity across the second quarter of 2026, highlighting key trends in phishing techniques, payload delivery, and threat actor behavior observed by Microsoft Threat Intelligence.

email threat landscape Q1 trends that shaped Q2 activity ›Figure 1.

Trend of QR code phishing attacks by weekly volume (January 2026–June 2026)The delivery methods used in QR code attacks shifted notably during Q2.

To he…

2 weeks назад @ microsoft.com
Real world incident response: Microsoft and AXA XL strengthen cyber resilience
Real world incident response: Microsoft and AXA XL strengthen cyber resilience Real world incident response: Microsoft and AXA XL strengthen cyber resilience

That experience continues to shape how we design Defender Experts Cybersecurity Incident Response—and how we work with partners like AXA XL.

Incident response must extend beyond technologyAs a global insurance provider, AXA XL plays a critical role in helping organizations navigate cyber risk and response.

AXA XL’s strategic partnerships with cyber incident response providers underscore our commitment to expertise, preparedness, and resilience.

Incident response engineered for high-stakes moments—and the readiness behind themWhat differentiates Microsoft Defender Experts Cybersecurity Incident Response is not only its deep technical expertise, but its direct connection to Microsoft engineer…

2 weeks, 1 day назад @ microsoft.com
Real world incident response: Microsoft and AXA XL strengthen cyber resilience
Real world incident response: Microsoft and AXA XL strengthen cyber resilience Real world incident response: Microsoft and AXA XL strengthen cyber resilience

That experience continues to shape how we design Defender Experts Cybersecurity Incident Response—and how we work with partners like AXA XL.

Incident response must extend beyond technologyAs a global insurance provider, AXA XL plays a critical role in helping organizations navigate cyber risk and response.

AXA XL’s strategic partnerships with cyber incident response providers underscore our commitment to expertise, preparedness, and resilience.

Incident response engineered for high-stakes moments—and the readiness behind themWhat differentiates Microsoft Defender Experts Cybersecurity Incident Response is not only its deep technical expertise, but its direct connection to Microsoft engineer…

2 weeks, 1 day назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 3 months, 2 weeks назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

3 months, 2 weeks назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

3 months, 4 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

3 months, 4 weeks назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

4 months назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

4 months, 1 week назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

4 months, 2 weeks назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

5 months, 1 week назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

5 months, 1 week назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

5 months, 2 weeks назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

6 months, 1 week назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

7 months, 4 weeks назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

8 months назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

8 months назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

8 months назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

8 months, 2 weeks назад @ security.googleblog.com