Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 9 часов назад
AirTag для шпионских очков. Приложение предупреждает, когда рядом Meta-камера
AirTag для шпионских очков. Приложение предупреждает, когда рядом Meta-камера AirTag для шпионских очков. Приложение предупреждает, когда рядом Meta-камера

Носимая электроника оставляет след, даже когда выглядит совершенно обычно.

9 часов назад @ securitylab.ru
ИИ нашёл молекулу, которая смогла отсрочить преждевременные роды
ИИ нашёл молекулу, которая смогла отсрочить преждевременные роды

Нанотело Nb2G5 заблокировало рецептор окситоцина и задержало начало родов у мышей примерно на три часа.

9 часов назад @ securitylab.ru
Нажал ссылку — получил бэкдор. Популярная клавиатура стала входом для APT
Нажал ссылку — получил бэкдор. Популярная клавиатура стала входом для APT

Обычная функция превратилась в тихий канал доставки вредоносного кода.

10 часов назад @ securitylab.ru
Вшивайте мораль в код или готовьтесь к бойне. ИИ давит животных ради выгоды
Вшивайте мораль в код или готовьтесь к бойне. ИИ давит животных ради выгоды

Пара единиц топлива оказалась способна перевесить ценность жизни в решениях автономных моделей.

10 часов назад @ securitylab.ru
Безопасность SCADA-систем изнутри: как исследования превращаются в технологии защиты
Безопасность SCADA-систем изнутри: как исследования превращаются в технологии защиты Безопасность SCADA-систем изнутри: как исследования превращаются в технологии защиты

Вебинар Positive Technologies состоится 17 сентября в 14:00

11 часов назад @ securitylab.ru
10 000 дронов в месяц. В США масштабируют 3D-печать для военного производства корпусов
10 000 дронов в месяц. В США масштабируют 3D-печать для военного производства корпусов

Американские дроны готовят к производству как расходный материал.

11 часов назад @ securitylab.ru
ZX Spectrum научили играть музыку через динамик с одним битом
ZX Spectrum научили играть музыку через динамик с одним битом

Три голоса появились там, где железо умеет только включать и выключать звук.

12 часов назад @ securitylab.ru
11 организаций за 26 секунд. Так выглядит массовая кибератака с ИИ-агентами
11 организаций за 26 секунд. Так выглядит массовая кибератака с ИИ-агентами

Защитные команды столкнулись с противником, который не делает пауз.

12 часов назад @ securitylab.ru
Дом на Марсе можно напечатать из дрожжей, желатина и местной пыли
Дом на Марсе можно напечатать из дрожжей, желатина и местной пыли Дом на Марсе можно напечатать из дрожжей, желатина и местной пыли

Марсианское жильё прошло первый лабораторный тест.

13 часов назад @ securitylab.ru
Lockheed показала автономную ПВО из самоорганизующихся дронов
Lockheed показала автономную ПВО из самоорганизующихся дронов

Будущее ПВО взлетает с грузовика, CARI в действии.

13 часов назад @ securitylab.ru
Oracle не верит в SaaS-апокалипсис. ИИ, по её версии, спасёт корпоративный софт
Oracle не верит в SaaS-апокалипсис. ИИ, по её версии, спасёт корпоративный софт

То, что сейчас кажется угрозой для отрасли, может стать её главным ускорителем.

14 часов назад @ securitylab.ru
Не обновляться опасно, обновляться тоже. Сентябрьский Windows 11 ломает WSL и RDP
Не обновляться опасно, обновляться тоже. Сентябрьский Windows 11 ломает WSL и RDP

Microsoft закрыла сотни дыр, но вместе с защитой пришли новые проблемы.

14 часов назад @ securitylab.ru
Иммунную систему человека собрали из искусственных органов
Иммунную систему человека собрали из искусственных органов

Лимфоузел и костный мозг соединили на чипе и получили модель человеческой иммунной памяти.

15 часов назад @ securitylab.ru
ETCRAM: память, которая хранит число как химическое состояние
ETCRAM: память, которая хранит число как химическое состояние

Тысячи значений помещаются в одной ячейке без привычных нулей и единиц.

15 часов назад @ securitylab.ru
Камера научилась думать прямо внутри каждого пикселя
Камера научилась думать прямо внутри каждого пикселя

Один кристалл заменяет камере сразу несколько измерительных приборов.

16 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 14 часов назад
Сетевая безопасность контейнеров: тренды, угрозы и требования ФСТЭК России
Сетевая безопасность контейнеров: тренды, угрозы и требования ФСТЭК России Сетевая безопасность контейнеров: тренды, угрозы и требования ФСТЭК России

Согласно представленной статистике, рынок измеряется в миллиардах рублей и, по мнению аналитиков, будет расти очень динамично в ближайшие годы.

Проблемы сетевой безопасности в KubernetesПавел Коростелёв объяснил, что в Kubernetes происходит смешение защиты приложений и инфраструктуры.

Теперь объектом защиты становится не сетевой хост и не среда виртуализации, а среда контейнеризации.

Всё это вместе создаёт весьма интересную картину: нужно очень внимательно следить за сегментацией и в традиционной сети, и в среде виртуализации, и в среде контейнеризации.

Финальный опрос показал, как, по мнению зрителей, должна строиться сетевая безопасность контейнерной инфраструктуры:Подход зависит от архит…

14 часов назад @ anti-malware.ru
Обзор SafeERP 4.9.11: комплексная защита cистем ERP
Обзор SafeERP 4.9.11: комплексная защита cистем ERP Обзор SafeERP 4.9.11: комплексная защита cистем ERP

Архитектура SafeERP Extension Module (Комплексная защита 1С)SafeERP Extension Module имеет модульную структуру и предназначен для комплексной защиты информационно-управляющих систем (ИУС), построенных на базе платформы 1С.

Архитектура компонента SafeERP для анализа кодаЯдром компонента SafeERP CS EM является сервер управления.

Архитектура компонента SafeERP для контроля настроек и защиты платформы 1СЯдром компонента SafeERP PS EM также является сервер управления.

Каталог проектов контроля настроек платформы 1С в SafeERP PS EMРисунок 26.

Для компонентов SafeERP CS EM и SafeERP PS EM установлены одинаковые требования к аппаратному и программному обеспечению.

20 часов назад @ anti-malware.ru
Что не так со SBOM и как действительно защитить цепочку поставок ПО
Что не так со SBOM и как действительно защитить цепочку поставок ПО Что не так со SBOM и как действительно защитить цепочку поставок ПО

Обычно в SBOM входят:название и версия компонента;поставщик;идентификаторы Package URL (purl) и CPE;зависимости между компонентами;хеш-суммы и сведения о лицензиях.

Если проблема ещё не зарегистрирована в базе уязвимостей или компонент был скомпрометирован, наличие его в SBOM не покажет угрозу.

SBOM анализа (Analyzed SBOM или Binary SBOM) создаётся при анализе готового артефакта: пакета, исполняемого файла или контейнера.

SBOM не описывает происхождение артефакта и не защищает CI/CDSBOM показывает, из каких компонентов состоит программный артефакт.

SBOM нужно проверять на подлинность и целостностьДаже полный SBOM с правильно идентифицированными компонентами не гарантирует, что сам документ …

3 days, 12 hours назад @ anti-malware.ru
Обзор решений EASM (External Attack Surface Management)
Обзор решений EASM (External Attack Surface Management) Обзор решений EASM (External Attack Surface Management)

Именно для этого используются решения класса «управление внешней поверхностью атаки» (External Attack Surface Management, EASM), позволяющие контролировать внешнюю поверхность атаки.

Что такое EASM и для чего используетсяСистема класса «управление внешней поверхностью атаки» (External Attack Surface Management, EASM) — это не разовый пентест и не сетевой сканер.

Также следует упомянуть ASM (Attack Surface Management) как более широкий подход, охватывающий и внешнюю, и внутреннюю поверхность атаки, и CAASM (Cyber Asset Attack Surface Management) — технологический подход, представляющий собой подмножество ASM и обеспечивающий единую актуальную видимость всех киберактивов организации.

Место EA…

3 days, 17 hours назад @ anti-malware.ru
Корпоративные мессенджеры 2026: от чатов к супераппам и ИИ-агентам
Корпоративные мессенджеры 2026: от чатов к супераппам и ИИ-агентам Корпоративные мессенджеры 2026: от чатов к супераппам и ИИ-агентам

Корпоративные мессенджеры перестали быть просто чатами для переписки — сегодня они превращаются в супераппы и становятся ядром взаимодействия людей и ИИ-агентов внутри компаний.

Антон Анпилов добавил, что почта и мессенджеры — это разные паттерны потребления: в мессенджеры пишут быстрое, в почте закрепляют официальное.

Потом запускаются пилотные группы, пользователи оценивают мессенджеры, и в конце наступает этап компромиссов — компания определяет, какие требования действительно критичны, а от каких можно отказаться.

«Slack и Telegram — это очень крутые мессенджеры, это большие продукты, мы все ими пользуемся.

Иван Дьяконов назвал причиной ситуацию, когда компания не выбрала ни одного решен…

4 days, 13 hours назад @ anti-malware.ru
Корпоративный ИИ в России: от экспериментов к агентам
Корпоративный ИИ в России: от экспериментов к агентам Корпоративный ИИ в России: от экспериментов к агентам

Где ИИ применяют и считают эффективнымПо данным исследования, чаще всего ИИ применяют в контакт-центрах и службах поддержки — об этом сообщили 75% опрошенных компаний.

«В страховых компаниях, — поясняет он, — инвестиционный анализ раньше требовал дорогих специалистов, которые умели и разбираться в ситуации, и доходчиво объяснять происходящее.

По его словам, проблема не только в процессах и данных, но и в том, как измерить сам результат.

Поэтому основная сложность заключается не только в запуске пилота, но и в его доведении до промышленной эксплуатации.

Полностью автономные решения (без участия человека) внедряют 25% компаний — но в проде они задействованы только у 8%.

5 days, 14 hours назад @ anti-malware.ru
Как выбрать российский NGFW в 2026 году: тренды, критерии и прогнозы
Как выбрать российский NGFW в 2026 году: тренды, критерии и прогнозы Как выбрать российский NGFW в 2026 году: тренды, критерии и прогнозы

В любом случае российское решение отличается от западного — есть небольшие отличия в инфраструктуре и в подходах.

Виталий Беличко добавил, что в прошлом году все вендоры бурно наращивали функциональность, но следующим этапом стала проработка деталей.

Это и тренд, и много маркетинга в это вкладывается».

Мы обрабатываем эти данные в KSN и передаём их во все продукты, которые к нему подключены, в том числе и в NGFW.

ВыводыРынок российских NGFW в 2026 году прошёл этап становления и вступает в фазу зрелой конкуренции.

6 days, 18 hours назад @ anti-malware.ru
Как Томск стал центром кибербезопасности и что меняет приказ ФСТЭК № 117: форум «КиберV» 2026
Как Томск стал центром кибербезопасности и что меняет приказ ФСТЭК № 117: форум «КиберV» 2026 Как Томск стал центром кибербезопасности и что меняет приказ ФСТЭК № 117: форум «КиберV» 2026

Обсудили как региональные компании выходят на федеральный рынок, где искать специалистов и что меняется в ИБ с развитием ИИ.

Чтобы посмотреть, как сегодня устроена кибербезопасность за пределами столицы, команда AM Live также отправилась в Томск и посетила пятый юбилейный форум по кибербезопасности «КиберV».

Юбилейный форум «КиберV» собрал команды и компании, которые в обычной работе могут решать совершенно разные задачи, но в вопросах кибербезопасности оказываются по одну сторону.

Представитель ФСТЭК ответил на вопросы участников и отдельно подчеркнул, что не стоит заранее пугать себя новыми требованиями.

Мы пересматриваем информационные потоки, подходы к созданию новых информационных сист…

6 days, 21 hours назад @ anti-malware.ru
Обзор Kaspersky Secure Mail Gateway 3.1, шлюза защиты корпоративной электронной почты
Обзор Kaspersky Secure Mail Gateway 3.1, шлюза защиты корпоративной электронной почты Обзор Kaspersky Secure Mail Gateway 3.1, шлюза защиты корпоративной электронной почты

Kaspersky Secure Mail Gateway (KSMG) — полностью интегрированное решение, объединяющее систему электронной почты и средства её защиты в составе готового к использованию виртуального устройства безопасности.

Добавление маршрута в Kaspersky Secure Mail Gateway 3.1Функция полезна, например, если сообщения разных подразделений или сервисов должны проходить через отдельные шлюзы.

Подключение к LDAP-серверам в Kaspersky Secure Mail Gateway 3.1Функциональные возможности Kaspersky Secure Mail Gateway 3.1На текущий момент управление возможностями осуществляется через веб-консоль.

Создание учётной записи в Kaspersky Secure Mail Gateway 3.1Рисунок 23.

Применение Kaspersky Secure Mail Gateway 3.1Решени…

6 days, 22 hours назад @ anti-malware.ru
Бесплатные ИИ-роутеры: как они работают и можно ли проверить модель
Бесплатные ИИ-роутеры: как они работают и можно ли проверить модель Бесплатные ИИ-роутеры: как они работают и можно ли проверить модель

Разбираемся, что происходит с запросом у посредника, можно ли проверить фактическую модель и на что смотреть российскому разработчику.

Например, в ответе и журналах OpenRouter можно увидеть названия модели и провайдера, который обслужил конкретный запрос.

Как проверить, какая модель отвечает на запросАбсолютно надёжного «паспорта модели» на стороне клиента обычно нет.

Сервис должен показывать фактическую модель и, по возможности, провайдера для каждого запроса, а также позволять управлять резервными маршрутами.

Нужно выяснить, сохраняются ли промпты и ответы, каков срок хранения, используются ли данные для аналитики или обучения и можно ли ограничить передачу отдельным провайдерам.

1 week назад @ anti-malware.ru
Бота не нужно блокировать — его нужно разорить
Бота не нужно блокировать — его нужно разорить Бота не нужно блокировать — его нужно разорить

Разбираем, из чего складывается стоимость скрейпинга, СМС-бомбинга, credential stuffing и LLM-ботов и как подобрать меры защиты, не мешая легитимным пользователям.

В деньгах кажется, что это почти ничего не стоит.

Но благодаря LLM, боты научились смотреть на страницу и понимать, что на ней происходит.

Он подстраивается под изменения, которые раньше его убивали, и пишет тексты (отзывы, заявки, сообщения в поддержку) не хуже, чем человек.

Главное: чем дешевле становится создание ботов и чем быстрее они умнеют, тем важнее защищаться не от конкретного скрипта, а от самой автоматизации.

1 week назад @ anti-malware.ru
Приказ № 270 Минцифры: как наладить эффективное сотрудничество ИТ-компаний и вузов
Приказ № 270 Минцифры: как наладить эффективное сотрудничество ИТ-компаний и вузов Приказ № 270 Минцифры: как наладить эффективное сотрудничество ИТ-компаний и вузов

Проблемами вузов остаются слабая материальная база и отсутствие доступа к российскому ПО и отечественному оборудованию.

Для их оценки в приказе предлагается использовать два подхода: по методике, изложенной в самом документе, и по фактическим затратам.

Как унифицировать требования вуза и Минцифры к трудоустройству сотрудников, чтобы сократить объём документов и согласований.

Также представитель ОмГТУ обратил внимание на то, что у вузов, которые сотрудничают с индустриальными партнёрами, появляется необходимость регулярно отправлять отчёты в Минцифры.

ВыводыИсполнение норм приказа № 270 Минцифры потребует довольно серьёзных усилий как от ИТ-компаний, так и от вузов.

1 week, 3 days назад @ anti-malware.ru
Экономика кибербезопасности: предотвращать инциденты и управлять последствиями
Экономика кибербезопасности: предотвращать инциденты и управлять последствиями Экономика кибербезопасности: предотвращать инциденты и управлять последствиями

Допустим, на это отводится месяц и ограниченный бюджет.

Экстренное привлечение сторонних специалистов по кибербезопасности — часто по повышенным тарифам и без возможности выбрать оптимального подрядчика.

Презумпция взлома подразумевает ориентацию на факты, а не на формальное соответствие.

Но с их помощью обычно получается понять, как должно быть, а не как есть на самом деле.

Аналитики собирают актуальные и ретроспективные данные внутри инфраструктуры и во внешних источниках, проводят автоматизированный и ручной анализ, оценивают критичность инцидентов и расследуют выявленные атаки.

1 week, 4 days назад @ anti-malware.ru
Битва алгоритмов: как ИИ меняет правила найма и поиска работы в 2026 году
Битва алгоритмов: как ИИ меняет правила найма и поиска работы в 2026 году Битва алгоритмов: как ИИ меняет правила найма и поиска работы в 2026 году

В 2026 году ИИ оказался по обе стороны найма: алгоритмы помогают компаниям оценивать кандидатов, а соискателям — готовиться к этой оценке.

Такая же формулировка встречается и в обсуждениях у других участников рынка.

В одном случае на массовые позиции приходит до 700 резюме в неделю, на узкоспециализированные и руководящие — около 100.

Например, работодатель может с помощью ГигаЧата или Gemini подготовить тестовое задание, а кандидат с помощью того же инструмента его выполнить.

Результаты опроса К2Тех по использованию ИИ в HR-процессахРиски для соискателяК рискам и барьерам мы бы отнесли те же, что при использовании ИИ в повседневных задачах.

1 week, 4 days назад @ anti-malware.ru
Защита данных в 2026 году: почему DLP-системы перестают быть универсальным решением
Защита данных в 2026 году: почему DLP-системы перестают быть универсальным решением Защита данных в 2026 году: почему DLP-системы перестают быть универсальным решением

Даниил Бориславский согласился, что это синергетическая работа: бизнес знает, что для него ценно, ИБ предлагает инструменты защиты, а регуляторика добавляет свои требования.

Глеб Марченко как практикующий специалист по защите данных добавил, что в крупных компаниях подразделения информационной безопасности гораздо малочисленнее, чем бизнес-подразделения.

Он отметил, что в прошлом году было очень много мошеннических действий, телефонных «разводов», попыток закрепиться в инфраструктуре.

DCAP прекрасно справляется с классификацией данных в покое, у неё больше времени на анализ, и эта классификация затем используется в DLP для настройки политик безопасности.

ВыводыРынок защиты данных в 2026 год…

1 week, 4 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 1 час назад
UDP-прокси и протокол QUIC — как утекает реальный IP
UDP-прокси и протокол QUIC — как утекает реальный IP UDP-прокси и протокол QUIC — как утекает реальный IP

При этом утверждение «нет поддержки UDP, и ваш IP 100% утекает» некорректно.

И вот тут возникает второй закономерный вопрос: зачем вообще браузеру нужен UDP и откуда берется этот отдельный сетевой маршрут?

И не проще ли просто модернизировать (как-то докрутить) и использовать TCP вообще для любых подключений?

Он не устанавливает соединение, как это делает TCP, не гарантирует доставку каждой отдельной датаграммы и не контролирует порядок их получения.

Если ваш прокси изначально умеет передавать UDP-пакеты, Aurorium автоматически распознает протокол и направляет QUIC и WebRTC-трафик напрямую через прокси без потерь.

1 час назад @ habr.com
Вебхук ЮKassa принимал payment.succeeded на веру. Подделать оплату брони можно было одним curl
Вебхук ЮKassa принимал payment.succeeded на веру. Подделать оплату брони можно было одним curl Вебхук ЮKassa принимал payment.succeeded на веру. Подделать оплату брони можно было одним curl

gateway_payment_id не секрет — он приходит клиенту сразу после создания платежа, в ответе на POST /bookings/{id}/pay .

То есть у обычного пользователя, который просто открыл бронь и не заплатил, на руках было всё, что нужно для подделки.

Полез разбираться, что у ЮKassa с этим есть.

Обратный запрос надёжнее: спросить у самой ЮKassa, что происходит с этим платежом, вместо того чтобы гадать по заголовкам.

Бросает исключение при недоступности API — вебхук ответит 5xx, и ЮKassa повторит уведомление позже (fail-closed). """

11 часов назад @ habr.com
Security Week 2638: опасные уязвимости в роутерах MikroTik
Security Week 2638: опасные уязвимости в роутерах MikroTik Security Week 2638: опасные уязвимости в роутерах MikroTik

На прошлой неделе команда CERT из Польши обнародовала информацию о трех уязвимостях в роутерах MikroTik, две из которых активно используются в реальных атаках как минимум со второго сентября.

Проблема CVE-2026-67276 позволяет обойти аутентификацию по SSH в том случае, если атакующему известно имя пользователя и модуль публичного ключа.

Третья обнаруженная проблема (CVE-2026-67277, CVSS 8.8) присутствует в службе проверки скорости интернет-соединения и в худшем случае может приводить к отказу в обслуживании.

Всего в этом году Microsoft закрыла 2760 багов, что в два раза превышает показатель за весь 2025 год.

Компания Google выпустила набор из 230 заплаток, включая патч для эксплуатируемой уя…

12 часов назад @ habr.com
Приз за то, чего вы не сделали: соревнование по кибербезопасности для тех, кто не пишет код
Приз за то, чего вы не сделали: соревнование по кибербезопасности для тех, кто не пишет код Приз за то, чего вы не сделали: соревнование по кибербезопасности для тех, кто не пишет код

А именно на них рассчитано подавляющее большинство реальных атак: бьют не в уязвимость в коде, а в человека.

Регистрация была открытой: мы не могли и не хотели запрещать участвовать техническим специалистам.

Отклонишь всё подряд — не получишь правильный ответ, потому что не покажешь, что понял разницу.

Барьер не в сложности, а в непонимании, чего от участника хотят.

Дверь — это задания про распознавание и выбор, а не про декодирование; подсказки, которые подталкивают, а не решают за тебя; и приз за то, чего ты не сделал.

16 часов назад @ habr.com
redb 4.0: XML-маршруты, ленивые ссылки, уникальные ключи и WS-Trust в одном мажоре
redb 4.0: XML-маршруты, ленивые ссылки, уникальные ключи и WS-Trust в одном мажоре redb 4.0: XML-маршруты, ленивые ссылки, уникальные ключи и WS-Trust в одном мажоре

redb ecosystemМажор всей экосистемы: что появилось в redb.Core, redb.Route, redb.Tsak и redb.Identity, что закрыто по безопасности и что ломает обновление.

redb.Core(.Pro): ленивые ссылки и уникальные ключиВсё ниже работает одинаково на PostgreSQL, MSSQL и SQLite, во Free и в Pro.

Производительность: индексы на FK-колонках values , ускорение ChangeTracking, хеши в SQLite как BLOB(16) , индекс на value_string теперь и на MSSQL.

redb.Route: строковые LoopExpression , DelayExpression и ThrottleExpression стали Loop , Delay и Throttle , а SetBodyExpression("…") и соседи стали SetBody(Expr("…")) .

${...} форматирует числа и даты инвариантно, ${...} в адресе консюмера роняет Start() , а ноль, "0"…

16 часов назад @ habr.com
Снижение нагрузки на сервер с помощью WAF: реальный кейс WordPress/WooCommerce
Снижение нагрузки на сервер с помощью WAF: реальный кейс WordPress/WooCommerce Снижение нагрузки на сервер с помощью WAF: реальный кейс WordPress/WooCommerce

Важное условие кейса: внутри самого сайта в сравниваемый период ничего не оптимизировалось и не перенастраивалось.

Показатели внутренней WAF-аналитики включают в себя только обращения к самим страницам сайта и не учитывают запросы к статическим данным.

Внутри сайта в этот момент ничего не менялось: не проводилась оптимизация WordPress/WooCommerce, не менялись код, тема, плагины, структура БД или настройки приложения.

Основным изменением стала только замена штатного фильтра хостинга на внешний WAF с селективной фильтрацией трафика.

Почему WAF не всегда позволяет существенно снизить нагрузкуНе всегда удаётся получить существенное снижение нагрузки только за счёт одного подключения многоуровне…

17 часов назад @ habr.com
Мы измерили платный антидетект‑браузер: canvas совпадал с чистой машиной байт в байт. Потом сделали свой, открытый
Мы измерили платный антидетект‑браузер: canvas совпадал с чистой машиной байт в байт. Потом сделали свой, открытый Мы измерили платный антидетект‑браузер: canvas совпадал с чистой машиной байт в байт. Потом сделали свой, открытый

Не потому что боюсь, а потому что это не главное: методика ниже воспроизводима, и каждый может прогнать её сам против того, за что платит.

Вот это отличаться не должно никогда: оно позволяет сайту различить два браузера по тому, что они умеют, а не по тому, что они заявляют.

Несколько принципов, которые вышли из измерений, а не из головы:Шум применяется при чтении, а не при рисовании.

Наша сборка — тот же BoringSSL с тем же кодом, значит сетевой отпечаток совпадает с Chrome по построению.

Linux — не цель, и это решение, а не пробел: две платформы, которые тестируются, стоят больше трёх, из которых одна — догадка.

17 часов назад @ habr.com
Standoff 17: как MaxPatrol Carbon помогал держать кибербитву в рамках сценария
Standoff 17: как MaxPatrol Carbon помогал держать кибербитву в рамках сценария Standoff 17: как MaxPatrol Carbon помогал держать кибербитву в рамках сценария

В Standoff патч-менеджмент должен закрыть уязвимости, но оставить заложенные векторы атак рабочими, и это усложняет жизнь архитектора.

Добавим изменения, вносимые коллегами, и не забываем про сценарии автоматизации, которые иной раз «помогают» не скучать.

MaxPatrol Carbon как ассистент архитектораКак работает продуктДля начала сделаем небольшое отступление и расскажем, что это за решение.

Пример со свежей уязвимостью NginxЕще один показательный кейс был связан с тем, как MaxPatrol Carbon помогает по-новому взглянуть на приоритизацию уязвимостей на киберполигоне.

MaxPatrol Carbon рассматривает каждый недостаток не изолированно, а как часть цепочки, в которой уязвимости, ошибки конфигурации и…

18 часов назад @ habr.com
Безагентское сканирование безопасности хостов при подключении к сети в NAC-системах. Блажь или необходимость?
Безагентское сканирование безопасности хостов при подключении к сети в NAC-системах. Блажь или необходимость? Безагентское сканирование безопасности хостов при подключении к сети в NAC-системах. Блажь или необходимость?

Хост может быть заражен вредоносным ПО с отложенным запуском, могут отсутствовать обновления безопасности или отключен антивирус.

Чтобы снизить эти риски, современные NAC-системы проверяют не только кто подключается, но и в каком состоянии находится устройство.

Аутентификация пользователя отвечает на вопрос от NAC-системы «кто получает доступ в сеть», но не отвечает на вопрос «в каком состоянии находится это устройство».

Развертывание и поддержка агента на десятках тысяч устройств требует отдельной инфраструктуры и постоянного внимания инженеров;нестандартные устройства.

Поэтому разработка собственного агента включена в наш Roadmap, и на данный момент мы уже ведем активные работы в этом нап…

18 часов назад @ habr.com
Когда вредонос решил собрать всё сразу: разбираем один очень насыщенный образец
Когда вредонос решил собрать всё сразу: разбираем один очень насыщенный образец Когда вредонос решил собрать всё сразу: разбираем один очень насыщенный образец

В качестве основного исполняемого файла после распаковки фигурирует:По поведению это не один небольшой payload, а многоступенчатая цепочка.

Схема здесь примерно такая:virusvippro.exe | v WMI | +------------+------------+ | | | v v v BIOS RAM Screen | v "А это точно настоящий ПК?"

И не только Scheduled TaskПомимо задач планировщика, в отчёте отмечены и другие механизмы закрепления и изменения системы.

Есть curl , есть HTTPS и есть готовая инфраструктура.

Получается довольно красивая цепочкаЕсли собрать всё вместе, получается примерно следующее:almost there.zip | v WinRAR | v virusvippro.exe | +--------------+--------------+ | | | v v v PowerShell Python wscript.exe | | | +--------------+----…

19 часов назад @ habr.com
«Уберу перед пушем» и другие способы потерять секреты. Чек-лист для самопроверки
«Уберу перед пушем» и другие способы потерять секреты. Чек-лист для самопроверки «Уберу перед пушем» и другие способы потерять секреты. Чек-лист для самопроверки

И чтобы не заканчивать на страшном — в конце статьи чек-лист: как за пару минут проверить репозиторий на забытые секреты и что делать, если что-то нашлось.

Как и в примере выше, API-токен лежит в конфигурации CI/CD в открытую.

Стоит держать в голове, что секреты живут не в актуальной версии продукта, а во всех версиях, которые записаны где-либо: в коммитах, в бэкапах, на дисках сотрудников.

Если секрет — это просто строка в коде, компилятор поместит её в раздел со статическими данными внутри исполняемого файла.

И проверьте, что в самом последнем коммите не содержится секрет, поскольку инструменты часто не трогают его, чтобы не убить продуктовую развёртку.

20 часов назад @ habr.com
Голос в трубке был мой. Разговаривал не я
Голос в трубке был мой. Разговаривал не я Голос в трубке был мой. Разговаривал не я

Зацепило, что защитой оказалась не осведомлённость и не бдительность.

Подделать чужой голос по телефону было трудно: нужен был человек, умеющий пародировать, и он всё равно ошибался на первой же реплике не по сценарию.

Отсюда единственное правило, которое я советую в семье и на работе одинаково: разговор, в котором просят о деньгах, доступе или срочном действии, не заканчивается решением.

Схема с давлением построена на срочности и на неловкости: человек, которому «сын» кричит в трубку, не станет требовать пароль.

Они дают вероятностный ответ, отстают от генераторов и не встроены в телефонную сеть - то есть в момент, когда решение принимается, их рядом нет.

20 часов назад @ habr.com
Copilot сходил в интернет за ответом. В Word вы этого не увидите, а администратор в Purview — увидит
Copilot сходил в интернет за ответом. В Word вы этого не увидите, а администратор в Purview — увидит Copilot сходил в интернет за ответом. В Word вы этого не увидите, а администратор в Purview — увидит

Оговорка на входе: веб-поиск - это не Copilot SearchСтраница “Data, privacy, and security for web search in Microsoft Copilot and Microsoft Copilot Chat” начинается с разграничения: “This article concerns the web search functionality in Microsoft Copilot and Microsoft Copilot Chat.

Microsoft Copilot Search is an additional, universal search experience…” Адрес - https://learn.microsoft.com/en-us/microsoft-365/copilot/manage-public-web-access, поле ms.date на день сверки - 2026-08-18.

Схема: что уходит в Bing и что в запрос не включаетсяКак из промпта получается запрос к Bing и что в этот запрос не включается - нарисовал по странице про веб-поиск, сверено 6 сентября 2026 года.

В строке про cl…

21 час назад @ habr.com
Отличи меня, если сможешь! Как дипфейки меняют современный наем в ИТ (и не только)
Отличи меня, если сможешь! Как дипфейки меняют современный наем в ИТ (и не только) Отличи меня, если сможешь! Как дипфейки меняют современный наем в ИТ (и не только)

В качестве тестового задания его попросили изучить код в репозитории и найти в нем проблему.

Однако ИБ-угроза может находиться и «по другую сторону резюме» — от хакерских атак страдают не только ИТ-специалисты, готовые рассмотреть предложение о работе, но и сами рекрутеры в компаниях.

Один из кандидатов имел активный профиль в LinkedIn, и даже сведения о полученном им высшем образовании в Сербии удалось подтвердить.

Человеческая роговица работает как зеркало, поэтому изображение должно отразиться в глазах реального человека и попасть в кадр его камеры.

Еще больше интересных материалов в блоге на Хабре и на ИТ-площадке «вАЙТИ»:

1 day, 11 hours назад @ habr.com
Можно ли найти IDOR статическим анализом? Пишем ядро для Python
Можно ли найти IDOR статическим анализом? Пишем ядро для Python Можно ли найти IDOR статическим анализом? Пишем ядро для Python

По моему мнению, ядро по IDOR не особо хорошо работает, т.к.

Semgrep выносит IDOR в LLM-продукт, а не в правила.

Поток тут есть всегда, и в уязвимом коде, и в защищённом.

Контраст указывает на упущение, а не на замысел.

Дело не в том, что математическая модель неверна, а в том, что ядро читает недостаточно кода.

1 day, 12 hours назад @ habr.com
Хакер Хакер
последний пост 10 часов назад
CERT предупреждает о небезопасности наушников Skullcandy
CERT предупреждает о небезопасности наушников Skullcandy CERT предупреждает о небезопасности наушников Skullcandy

Проблема связана с уязвимостью CVE-2025-20701 в Airoha Bluetooth Audio SDK, который используется в Skullcandy Dime 3 (модель S2DCW) для беспроводного подключения и обмена данными с другими устройствами.

Для эксплуатации этой уязвимости атакующему достаточно просто находиться в зоне действия Bluetooth и установить сопряжение с наушниками.

После успешного подключения устройство злоумышленника становится доверенным и в дальнейшем может автоматически переподключаться к наушникам, когда оказывается рядом.

Это позволяет прерывать соединение владельца, перехватывать воспроизведение аудио, обращаться к профилю устройства и прослушивать звук с микрофона в режиме реального времени.

Однако ситуация ос…

10 часов назад @ xakep.ru
Anthropic: модели Claude используются для кибератак, разработки малвари и оружия
Anthropic: модели Claude используются для кибератак, разработки малвари и оружия Anthropic: модели Claude используются для кибератак, разработки малвари и оружия

В Anthropic подчеркивают, что новый отчет не отражает общий масштаб злоупотреблений Claude и типичные случаи применения ИИ.

Одна из шпионских групп использовала Claude для разработки малвари, фишинга, покупки и настройки серверов, закрепления в системах жертв, работы с C2-инфраструктурой и кражи данных.

Кроме того, в Anthropic выявили случаи использования Claude для разработки систем управления вооружением и ударных дронов, а также для создания инструментов массовой слежки.

Claude был задействован при проектировании и разработке части этой системы, включая инструменты для анализа данных и интерфейсы для операторов.

В Anthropic подчеркивают, что уже заблокировали все аккаунты, связанные с оп…

12 часов назад @ xakep.ru
HTB Silentium. Превращаем доступ к ИИ-платформе Flowise в выполнение команд
HTB Silentium. Превращаем доступ к ИИ-платформе Flowise в выполнение команд HTB Silentium. Превращаем доступ к ИИ-платформе Flowise в выполнение команд

Справка: сканирование портовСка­ниро­вание пор­тов — стан­дар­тный пер­вый шаг при любой ата­ке.

На осно­ве этой информа­ции он выбира­ет сле­дующий шаг к получе­нию точ­ки вхо­да.

Улуч­шить резуль­таты его работы ты можешь при помощи такого скрип­та:#!/ bin/ bash ports = $( nmap -p- -- min- rate = 500 $1 | grep ^ [ 0 -9 ] | cut -d '/ ' -f 1 | tr ' ' ', ' | sed s/, $/ / ) nmap -p $ports -A $1Он дей­ству­ет в два эта­па.

На пер­вом выпол­няет­ся обыч­ное быс­трое ска­ниро­вание, на вто­ром — более тща­тель­ное, с исполь­зовани­ем встро­енных скрип­тов (опция -A ).

Под­робнее про работу с Nmap читай в статье «Nmap с самого начала.

14 часов назад @ xakep.ru
119 000 фальшивых интернет-магазинов воруют данные банковских карт
119 000 фальшивых интернет-магазинов воруют данные банковских карт 119 000 фальшивых интернет-магазинов воруют данные банковских карт

Специалисты из немецкого ИБ-стартапа Nebty обнаружили масштабную мошенническую сеть DoppelCart, которая размещает поддельные интернет-магазины более чем на 119 000 доменов.

Такие сайты копируют реальные бренды и привлекают покупателей скидками, а при оформлении заказа крадут данные банковских карт.

Исследователи пишут, что большинство связанных с DoppelCart доменов зарегистрировано в зоне .shop.

Для сравнения, ранее крупнейшей считалась сеть BogusBazaar, в которую входило около 75 000 поддельных сайтов.

Специалисты создали отдельную базу, через которую компании могут проверить, используются ли их бренды в мошеннической сети, а также могут выявить связанные с DoppelCart сайты.

15 часов назад @ xakep.ru
Revolut раскрыл мошенникам данные клиентов
Revolut раскрыл мошенникам данные клиентов Revolut раскрыл мошенникам данные клиентов

Так как письма приходили с адреса в реальном почтовом домене ведомства, сотрудники Revolut приняли их за настоящие и раскрыли запрошенную информацию.

В Revolut заявили изданию, что инцидент затронул «ограниченное» число клиентов и со всеми пострадавшими уже связались напрямую.

В компании подчеркивают, что внутренние системы Revolut не пострадали, а средства клиентов остаются в безопасности.

Он опубликовал предупреждение, которое в Revolut разослали пострадавшим клиентам, и предположил, что атакующие целенаправленно стремились получить данные о состоятельных пользователях сервиса.

В настоящее время Revolut обслуживает более 80 млн клиентов по всему миру и имеет банковские лицензии более чем …

17 часов назад @ xakep.ru
Мексиканские полицейские изъяли 300 видеокарт с подпольной майнинг-фермы
Мексиканские полицейские изъяли 300 видеокарт с подпольной майнинг-фермы Мексиканские полицейские изъяли 300 видеокарт с подпольной майнинг-фермы

Мексиканские власти обнаружили и изъяли около 300 GPU на подпольной майнинг-ферме в штате Пуэбла.

Следователи проверяют версии о хищении электроэнергии и возможном отмывании денег через добытые криптоактивы.

Пока ни одно ведомство не назвало добываемую криптовалюту, не раскрыло связанные с ней кошельки и не сообщило об арестах.

Подключение к сети среднего напряжения и наличие трансформатора указывают на промышленные масштабы энергопотребления, хотя точные данные о потреблении электроэнергии власти не раскрыли.

При этом аналитики Chainalysis не публиковали данных о кошельках, которые связывали бы ферму в Тлаоле с конкретным картелем.

18 часов назад @ xakep.ru
Разработчики призвали срочно исправить критическую уязвимость в GitLab
Разработчики призвали срочно исправить критическую уязвимость в GitLab Разработчики призвали срочно исправить критическую уязвимость в GitLab

В GitLab объясняют, что проблема связана с некорректным ограничением путей, а также с отсутствующей проверкой аутентификации.

В случае успешной атаки хакер сможет прочитать логи и конфигурационные файлы GitLab, в которых могут храниться учетные данные, токены, секреты и другая конфиденциальная информация.

По мнению экспертов, переход к массовой эксплуатации уязвимости может произойти очень быстро.

Этот баг затрагивает только GitLab EE и связан с небезопасной десериализацией в обработчике GraphQL-подписок.

Обе уязвимости устранены в GitLab 19.3.2, 19.2.6 и 19.1.8.

19 часов назад @ xakep.ru
Как CyberYozh делает цифровой мир безопаснее и при чем тут ИИ
Как CyberYozh делает цифровой мир безопаснее и при чем тут ИИ Как CyberYozh делает цифровой мир безопаснее и при чем тут ИИ

Как изменились подходы к обучению кибербезопасности с приходом ИИЕще несколько лет назад человеку, желающему разобраться в информационной безопасности, приходилось собирать знания по крупицам — из книг, форумов, лекций и документации.

Академия в последний год стала все чаще проявляться в публичном поле — не только как эдтех-компания, но и как источник экспертизы по кибербезопасности, OSINT и применению ИИ.

Студент должен понимать, когда использовать конкретное решение, какие у него есть ограничения и как проверить результат.

Экосистема CyberYozh развивается вокруг безопасности, анонимности, цифровых угроз и способов защиты от них с 2014 года и по сей день.

Справедливый — AI не дискриминируе…

20 часов назад @ xakep.ru
Свежий спецвыпуск и другие бумажные номера «Хакера»
Свежий спецвыпуск и другие бумажные номера «Хакера» Свежий спецвыпуск и другие бумажные номера «Хакера»

Свежий четвертый спецвыпуск «Хакера» уже напечатан и доступен для быстрого заказа.

Каждый бумажный спецвыпуск — это полноценный глянцевый журнал на 240 полос, содержащий практические материалы, технические разборы, исследования и гайды.

В него вошло более 20 лучших материалов «Хакера» за 2021–2022 годы — от практики пентеста и фаззинга до реверса и изучения необычного железа.

В продаже остаются и другие бумажные сборники «Хакера», но их запасы постепенно сокращаются на нашем складе: первые два спецвыпуска уже распроданы полностью, а дополнительных тиражей мы не планируем.

Поэтому, если какого-то номера не хватает в твоей коллекции, лучше не откладывать покупку в долгий ящик.

3 days, 9 hours назад @ xakep.ru
Фреймворк PEEP использует Chrome и Edge для выполнения команд после взлома
Фреймворк PEEP использует Chrome и Edge для выполнения команд после взлома Фреймворк PEEP использует Chrome и Edge для выполнения команд после взлома

Он маскируется под расширение для браузера и использует Chrome или Edge как полноценный бэкдор.

Малварь способна похищать данные из браузера и перехватывать сессии, а через Native Messaging получает доступ к ОС и может выполнять команды на зараженной машине.

Вредоносное расширение внедряется в профиль Chrome или Edge, обходя Chrome Web Store и стандартные предупреждения браузера.

Кому принадлежат PEEP и его инфраструктура, пока остается неясным, но в исходниках вредоноса исследователи обнаружили артефакты на китайском языке.

Это помогает PEEP уклоняться от обнаружения и превращает браузер в инструмент для хищения учетных данных, перехвата сессий и удаленного выполнения команд.

3 days, 10 hours назад @ xakep.ru
Ранний доступ в Google Play используется для продвижения мошеннических приложений
Ранний доступ в Google Play используется для продвижения мошеннических приложений Ранний доступ в Google Play используется для продвижения мошеннических приложений

Аналитики из компании Bitdefender обнаружили массовую схему, в рамках которой недобросовестные разработчики злоупотребляют программой Google Play Early Access для распространения мошеннических Android-приложений.

С ее помощью разработчики могут собирать отзывы тестировщиков до официального релиза, однако публичные комментарии и рейтинги для таких приложений недоступны.

Для продвижения таких проектов используются в том числе дипфейки со знаменитостями, спортсменами и актерами, которые якобы рекламируют крупные бонусы.

К примеру, разработчики могут первоначально загрузить игру в Google Play под названием в духе Grand Theft Auto V (Early Access), дождаться ее индексации в поиске Google, а зате…

3 days, 12 hours назад @ xakep.ru
Гори, пекарня! Управляем подсветкой игровых устройств вручную
Гори, пекарня! Управляем подсветкой игровых устройств вручную Гори, пекарня! Управляем подсветкой игровых устройств вручную

Воз­можно, ты уже стал­кивал­ся с тем, что прог­рамма для работы с под­свет­кой — это зачас­тую монс­тру­озное поделие, которое пос­тоян­но висит в фоне и отжи­рает дра­гоцен­ную опе­ратив­ку.

Что­бы изба­вить­ся от этой зависи­мос­ти, энту­зиас­ты дела­ют софт для управле­ния под­свет­кой девай­сов раз­ных про­изво­дите­лей.

Се­год­ня пос­мотрим, как управлять под­свет­кой и, при желании, дру­гими парамет­рами — нап­ример, DPI мыши или наз­начени­ем кла­виш, — обра­щаясь нап­рямую к устрой­ствам.

Работа с устройствами в WindowsВо­зить­ся с устрой­ства­ми будем в Вин­де: в Razer, Logitech и дру­гих ком­пани­ях не выпус­кают офи­циаль­ный софт для нас­трой­ки железа для Linux.

Но если задать…

3 days, 14 hours назад @ xakep.ru
Более 8300 серверов Gitea уязвимы перед выполнением произвольного кода
Более 8300 серверов Gitea уязвимы перед выполнением произвольного кода Более 8300 серверов Gitea уязвимы перед выполнением произвольного кода

Аналитики The Shadowserver Foundation предупреждают, что более 8300 доступных через интернет инстансов Gitea не защищены от критической уязвимости CVE-2026-60004.

Баг уже эксплуатируется в реальных атаках и позволяет выполнять произвольные команды на уязвимых серверах.

По его словам, уязвимость связана с эндпоинтом API diffpatch и позволяет атакующему с правами на запись в репозиторий отправить специально подготовленный патч.

«Атакующий с обычными правами на запись в репозиторий получает возможность выполнять произвольные шелл-команды с правами пользователя ОС, от имени которого работает Gitea», — объясняют разработчики.

Дело в том, что в Gitea по умолчанию включена открытая регистрация, по…

3 days, 15 hours назад @ xakep.ru
Android-малварь Mantax Otax шифрует файлы, ворует данные и запугивает жертв
Android-малварь Mantax Otax шифрует файлы, ворует данные и запугивает жертв Android-малварь Mantax Otax шифрует файлы, ворует данные и запугивает жертв

Специалисты компании Zimperium обнаружили новую Android-малварь Mantax Otax, которая обладает функциями вымогателя и шпионского ПО.

Вредонос шифрует файлы и похищает данные с зараженных устройств, следит за пострадавшими и даже может запугивать их с помощью полноэкранных видео, изображений и голосовых сообщений.

По данным исследователей, за созданием Mantax Otax стоят злоумышленники из Индонезии.

Этот механизм заметно ограничивает доступ приложений к общему хранилищу, поэтому Mantax Otax может зашифровать только файлы в каталоге приложения во внешнем хранилище.

Также Mantax Otax способен похищать PIN-код экрана блокировки, читать SMS и одноразовые пароли, собирать историю звонков, список ко…

3 days, 17 hours назад @ xakep.ru
Хакеры взломали тестовый сервер и прокси Surfshark
Хакеры взломали тестовый сервер и прокси Surfshark Хакеры взломали тестовый сервер и прокси Surfshark

По итогам проведенного расследования в компании не обнаружили признаков использования скомпрометированных учетных данных или дальнейшего проникновения во внутреннюю инфраструктуру Surfshark.

Но в компании подчеркивают, что инцидент не затронул пользователей и продакшен-инфраструктуру VPN-сервиса Surfshark, и злоумышленники не сумели распространить атаку на другие системы.

«VPN-трафик и история просмотров в принципе не логируются и не сохраняются, а приложения и браузерные расширения на устройствах пользователей никак не изменялись», — заявили в Surfshark.

После взлома в Surfshark сменили все внутренние учетные данные, которые потенциально могли попасть в руки хакеров, и отозвали скомпромети…

3 days, 19 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 9 часов назад
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

To maintain that access, the attacker installed MeshCentral, a free tool that IT teams typically use to manage computers remotely.

The server held a full toolkit aimed at a 3BB FortiGate SSL-VPN gateway, the remote-access box at mail.3bb.co[.

]133, the attacker's server (port 8888 held the open directory, port 9443 received the exploit callback) Domain: www.ayuthayatech[.

]com, the MeshCentral control serverwww.ayuthayatech[.

]com, the MeshCentral control server MeshCentral group: TH-3BBTH-3BB Persistence paths: /usr/local/bin/.rc, a hidden backdoor, and /usr/local/mesh_services/meshagent//usr/local/bin/.rc, a hidden backdoor, and /usr/local/mesh_services/meshagent/ Targets: mail.3bb.co[.

9 часов назад @ thehackernews.com
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12.

Telegram Desktop, Telegram's app for Windows, macOS, and Linux, can save a single chat or all chats from an account as HTML pages that open in a browser.

It did not change Telegram's own copy of the chat or the export file saved on disk.

The researchers examined only Telegram Desktop's HTML export and did not address the JSON export format or the export features of Telegram's other apps.

The fix, commit 8457d13a by Telegram Desktop developer John Preston, adds the missing escaping.

9 часов назад @ thehackernews.com
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

DDRop works against Intel TDX, Intel Scalable SGX, and AMD SEV-SNP, the hardware that cloud services use to keep customer data private while it is in use, even from the cloud provider.

Breaking Intel TDXOn Intel TDX, the researchers turned write-dropping into full control of a protected virtual machine.

That lets an attacker's own virtual machine map its memory onto any physical address and read or change protected memory.

With that changed, a virtual machine the attacker controls could pass that check as if it were a trusted one.

The researchers say it is unclear whether it would stop DDRop, and that Intel has not said whether it would.

10 часов назад @ thehackernews.com
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign.

"Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU) said in an analysis.

"The activity progressed from source-code theft to persistent access, credential collection, and lateral movement, including root-level access to a three-node Proxmox cluster."

In one Taiwanese environment, the threat actor has been observed progressing from a vulnerable Gitea ser…

10 часов назад @ thehackernews.com
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

"New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin Repository Team Co-Lead, said.

The plugin was closed for downloads 26 minutes after the Plugins Team was alerted to the update by WordPress security company Wordfence.

Results are cross-verified and combined into a security score: A higher score translates to a potentially higher risk.

Should the new release score below the high-risk threshold, it continues through the normal cooldown process.

"If a finding looks incorrect, authors can contact the Plugins Team," Perez said.

11 часов назад @ thehackernews.com
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

Many incidents involving agents from frontier AI labs acting against their programming to escape restrictions in pursuit of their goals have heightened concerns over the increasing capacity of AI models and developers' ability to contain them.

🎥 Cybersecurity WebinarsLearn How to Know What to Fix First Before AI Speeds Up the Attack → AI-powered attacks are accelerating, but fragmented security data slows down the response.

→ AI-powered attacks are accelerating, but fragmented security data slows down the response.

How to Identify Which CVEs Are Truly Exploitable Within Hours → AI can turn newly disclosed vulnerabilities into working attacks within hours.

Russia Uses AI for Cyber Espionage …

13 часов назад @ thehackernews.com
AI Changed the Exposure Problem. Validation Needs to Change With It.
AI Changed the Exposure Problem. Validation Needs to Change With It. AI Changed the Exposure Problem. Validation Needs to Change With It.

For CVE-based exploitation, a working exploit still has to exist, and the target has to be safe to test.

This is the gap automated pentesting can’t close on its own.

Exploitability validation determines whether an exposure is, in fact, exploitable in your environment, including CVEs with no working exploit and assets that live exploitation can’t safely reach.

determines whether an exposure is, in fact, exploitable in your environment, including CVEs with no working exploit and assets that live exploitation can’t safely reach.

Picus CTO Volkan Ertürk will then lay out what security validation needs to look like when attackers are powering their attacks with AI, and why exploitability validat…

15 часов назад @ thehackernews.com
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.

]net" through operator-controlled proxy servers along with the user's OAuth token as an "&auth=" query parameter.

Specifically, the add-on embeds code to recover the Twitch OAuth token and send it to the proxy.

Version 85.8.7 changes how playlists are retrieved: the user's OAuth token is no longer sent to our proxies.

"Approximately 31,000 users across Chrome and Firefox route their live Twitch OAuth session tokens through operator-controlled proxy infrastructure," Socket said.

20 часов назад @ thehackernews.com
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

The spoofed email messages contained a purported "approval" of the fake invoice to trick recipients into making payments to attacker-controlled accounts.

To lend a veneer of legitimacy to the deception, the threat actor included a forged email thread along with the fabricated invoice.

The e-crime adversary has been described as a coordinated group of threat actors that operates multiple public extortion brands while sharing overlaps in the underlying phishing infrastructure and targeting footprint.

Microsoft, for its part, has attributed the initial access activity observed in this campaign to a range of threat actors, including Storm-3121 and Storm-3032.

"The attack underscores a critical …

1 day, 17 hours назад @ thehackernews.com
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

(CVSS score: 8.1) - An incorrect authorization vulnerability in JFrog Artifactory that could lead to privilege escalation due to a validation check of the token signature/issuer and not the token's scope.

CVE-2026-42018 (CVSS score: 7.5) - An improper authentication vulnerability in JFrog Artifactory that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, p…

2 days, 11 hours назад @ thehackernews.com
When the Whole Company Adopts AI: What It Does to Your SOC
When the Whole Company Adopts AI: What It Does to Your SOC When the Whole Company Adopts AI: What It Does to Your SOC

AI-related alerts still account for only 0.43% of all SOC alerts.

Meaning that across the data we investigated, real attacks that use AI agents are a drop in the ocean.

The lesson for any SOC is the same: severity labels on AI activity have to be read with suspicion, not taken at face value.

Granting OAuth access to AI agents means that employees might share sensitive information with third-party service providers.

Now SOC teams face a new layer of complexity: first determine whether the action in question was executed by an AI agent or tool.

2 days, 17 hours назад @ thehackernews.com
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

"The June agents were accessing 49 of the same files as the wiki agents.

The May agents were accessing different files (mostly local U.K. government data), but these files are very similar in character to those pursued by the wiki agents.

We also see that many packages mention example.com, which wiki agents used to test their posting ability."

This is not the first time OpenAI agents have targeted RubyGems.

"Based ​on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information," OpenAI said in a statement shared with Reuters.

2 days, 18 hours назад @ thehackernews.com
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.

The problem, per GitLab, stems from "improper path confinement and missing authentication enforcement in the repository commits API."

The issue, it said, allows an external attacker to read log files and GitLab-specific configuration files to obtain credentials, secrets, and sensitive information.

Also patched by GitLab in versions 19.3.2, 19.2.6, and 19.1.8 is a critical insecure deserialization bug in GitLab EE (CVE-2026-87719, CVSS score: 9.9) that could result in information disclosure.

Organizations running s…

3 days, 11 hours назад @ thehackernews.com
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.

Frontier AI labs in the West, including those from Google and OpenAI, have repeatedly called out distillation attacks aimed at their models.

"DeepSeek, Xiaomi, and Moonshot fed conversations between their own models and users into Claude," Anthropic said.

"In other cases, unauthorized labs rerouted requests from their users to Claude -- without the knowledge or permission of those users -- to harvest exchanges between users and Claude for training," Anthropic pointed out.

"The…

3 days, 11 hours назад @ thehackernews.com
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

The threat actor has also been observed deploying web shells and a browser exploitation C2 framework against other targets.

GTG-54002 , a commercial "influence-as-a-service" operation that used Claude to mass-produce and rewrite political content across about 70 fabricated news websites.

GTG-54006 , a sustained, automated disinformation network that used Claude to generate fabricated Bengali-language news in Bangladesh and promote the country's Awami League party.

, a sustained, automated disinformation network that used Claude to generate fabricated Bengali-language news in Bangladesh and promote the country's Awami League party.

The threat actor has also used Claude to build SECOMS64, a m…

3 days, 13 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 4 days, 18 hours назад
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
GuardBreaker: Derailing AI-assisted malware analysis with a code comment GuardBreaker: Derailing AI-assisted malware analysis with a code comment

Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way.

Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection.

Reporting on the same broader campaign, StepSecurity found a prompt that flat-out instructed any analyzing model that parsed the file to disregard the malicious code and report the package as clean.

Some parts of the malicious code could be concealed under the pretense of being confidential information or other sensitive data.

Crucially, however, no single LLM engine should have the sole au…

4 days, 18 hours назад @ welivesecurity.com
Safe word: What is it and why do you need one?
Safe word: What is it and why do you need one? Safe word: What is it and why do you need one?

The technology might be impressive, but a simple technique could stop the scammers in their tracks: a pre-agreed safe word.

What is a safe word?

But suggest some scenarios in which it would be a good idea to request a safe word.

It’s important to have a backup if someone can’t remember the safe word.

But a safe word is a fantastic, free option for uncovering deepfake audio fraud like fake/virtual kidnappings.

5 days, 18 hours назад @ welivesecurity.com
I’ve been deepfaked: What do I do?
I’ve been deepfaked: What do I do? I’ve been deepfaked: What do I do?

But across the globe, policymakers and public opinion are forcing tech platforms to better police this content.

What should I do if I’ve been deepfaked?

Google: Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

The first point of call is to contact the publisher to request removal.

1 week, 5 days назад @ welivesecurity.com
This month in security with Tony Anscombe – August 2026 edition
This month in security with Tony Anscombe – August 2026 edition This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity newsWith August coming to a close, it's time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month.

Here's some of what caught Tony's attention:OpenAI has disclosed more details about how its agents hacked AI collaboration platform Hugging Face.

Delta Airlines is investigating an incident where a flight passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network.

What are the lessons that businesses and critical infra…

2 weeks назад @ welivesecurity.com
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
AI-assisted reconnaissance: Why everyone could be a viable target for fraud AI-assisted reconnaissance: Why everyone could be a viable target for fraud

And of course, linking our professional and personal social media accounts is a simple task for AI.

For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information.

Losing your personal information is one thing.

What you can do about AI-powered OSINTWhen it comes to AI-powered reconnaissance, there are things you can control and things you can’t.

Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.

2 weeks, 4 days назад @ welivesecurity.com
How QR-code phishing can slip past corporate security measures
How QR-code phishing can slip past corporate security measures How QR-code phishing can slip past corporate security measures

So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years.

Most importantly, they take the victim from a relatively well-protected corporate environment to a potentially unmanaged mobile device, thus bypassing business-grade security.

Malicious QR codes are frequently embedded in alerts urging users to secure their account, or authenticate to confirm their details.

Encourage employees to avoid scanning QR codes in unsolicited emails and report anything suspicious.

Next, consider technical controls, including email security from a reputable vendor to minimize the risk of quishing emails ending up in users’…

4 weeks назад @ welivesecurity.com
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?

The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months.

It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes.

A keynote at Black Hat USA 2026 detailed research by associate professor Yan Shoshitaishvili and his undergraduate students at Arizona State University on the expanding use of AI models for vulnerability discovery.

The team then trained the GPTs using the properties of previously known vulnerabilities and discovered approximately 1,000 vulnerabilities.

If this logic prevails, we may reach the cal…

1 month назад @ welivesecurity.com
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility

Hugging Face disclosed that it had been attacked by AI; OpenAI came clean and declared that it was two of their AI models that had caused the breach.

A very late addition to the Black Hat agenda was a presentation by OpenAI’s team providing the details of the Hugging Face incident as they saw it and, importantly, the timeline.

The agents concluded that their task set could be completed by breaking out their sandbox and accessing external (Hugging Face) systems.

The target was Hugging Face: this is where the agents wanted to get, and they did.

On July 16th, Hugging Face disclosed an incident in which swarms of autonomous AI agents had breached its infrastructure.

1 month назад @ welivesecurity.com
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Black Hat USA 2026: AI is racing ahead of cybersecurity controls Black Hat USA 2026: AI is racing ahead of cybersecurity controls

The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials.

The second part of the opening keynote included Nick Andersen, Acting Director, CISA; Katherine Sutton, Assistant Secretary of War for Cyber Policy; and Brett Leatherman Assistant Director, Cyber Division, FBI.

I do agree with the ruthless approach, but without some form of regulation the boundaries on the use of AI remain blurred.

The Assistant Secretary of War for Cyber Policy made a fabulous analogy when pressed on the struggles regarding resourcing in the cybersecurity industry: you don’t want a pediatrician performing heart surgery.

We talk about autonomous AI at…

1 month назад @ welivesecurity.com
Are AI tutors safe for your kids?
Are AI tutors safe for your kids? Are AI tutors safe for your kids?

The AI tutor market is growing fastThe market for AI tutoring tools is booming.

Today, you can find various types of AI tutor tools to buy and use.

This happens when AI tools are tricked into ignoring their safety guardrails and display untrusted content.

If you’re keen to get your kids in front of an AI tool to help with private tutoring, first understand the difference between a simple co-pilot and a dedicated ITS.

So if you’re keen to try AI tutors, be sure to stay updated on what’s available out there.

1 month назад @ welivesecurity.com
This month in security with Tony Anscombe – July 2026 edition
This month in security with Tony Anscombe – July 2026 edition This month in security with Tony Anscombe – July 2026 edition

Researchers at Sysdig have documented what they assess to be the first case of an end-to-end ransomware operation executed by an agentic threat actor.

What can organizations do to stop phantom squatting from harming their brands, and what other lessons do these incidents hold for defenders?

Watch Tony's video to find out and be sure to check out the June 2026 edition of his monthly security news roundup for more insights.

Before you go, learn about the first AI-powered ransomware, named PromptLock and discovered by ESET researchers last year.

To learn more about cutting-edge AI defense layers, read the AI at ESET white paper.

1 month, 2 weeks назад @ welivesecurity.com
Beyond the screenshot: Why you should verify what you see
Beyond the screenshot: Why you should verify what you see Beyond the screenshot: Why you should verify what you see

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuineSomeone sends you a screenshot showing that a payment has gone through.

Why screenshot aren’t proof on their ownA screenshot is ultimately just an image of what appeared on a screen.

Reassured, you send the item off, only to find out the screenshot was a fake and you’re not getting your money.

You receive a password reset code, then get a text message (maybe impersonating a friend) asking you to screenshot and send it.

This screenshot is fake (source: Reddit)Challenges for businessesFrom a business perspective, internal and customer-facing teams are often provided with sc…

1 month, 2 weeks назад @ welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

2 months назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

2 months, 1 week назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

2 months, 1 week назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 2 часа назад
Homebrew 7.0.0 is out, here’s what changed for security
Homebrew 7.0.0 is out, here’s what changed for security Homebrew 7.0.0 is out, here’s what changed for security

On Sunday the project shipped version 7.0.0 and closed eight security advisories with it.

The eighth arrives in 7.0.0: until it is installed, a malicious cask can execute code outside the macOS install sandbox through LaunchServices.

Behind the command sits a new advisory database that records vulnerabilities against the formula versions and revisions Homebrew ships, backported security fixes included.

Homebrew verifies build attestations for supported third-party tap bottles, extending a check that covered its own core tap, and taps created with brew tap-new publish those attestations by default.

What the sandbox does not coverTap trust remains the main protection against a malicious third…

2 часа назад @ helpnetsecurity.com
Apple parental controls in iOS 27 let kids ask before opening new websites
Apple parental controls in iOS 27 let kids ask before opening new websites Apple parental controls in iOS 27 let kids ask before opening new websites

The tools went live on September 14, after a preview in June, and they require iOS 27, iPadOS 27, or macOS 27.

A kid signed into a hand-me-down device under someone else’s Apple Account gets none of these protections.

Parents set a total, then adjust individual categories.

Apple is working with the AAP to adapt its Family Media Plan into a reference parents can use on Apple devices.

Apple lists iOS 27, iPadOS 27, macOS 27, watchOS 27, and visionOS 27, which means a forgotten iPad or an Apple Watch left on an older release will hold up the whole group.

5 часов назад @ helpnetsecurity.com
Cybersecurity jobs available right now: September 15, 2026
Cybersecurity jobs available right now: September 15, 2026 Cybersecurity jobs available right now: September 15, 2026

AI & Security ArchitectSecNinjaz Technologies | India | On-site – View job detailsAs an AI & Security Architect, you will design secure and reliable AI agent platforms, including tools, memory, models, evaluations, and backend services.

CISOTexas Health and Human Services | USA | On-site – View job detailsAs a CISO, you will the cybersecurity program, manage risk, and strengthen cyber resilience.

You will manage endpoint and network security, SIEM and detection engineering, vulnerability and patch management, incident response, and digital forensics.

Manager Cyber Cloud Security and AIPwC | Canada | Hybrid – View job detailsAs a Manager Cyber Cloud Security and AI, you will lead client proj…

5 часов назад @ helpnetsecurity.com
Entrust turns cryptographic inventory data into security action
Entrust turns cryptographic inventory data into security action Entrust turns cryptographic inventory data into security action

Entrust has unveiled new capabilities for its Cryptographic Security Platform (CSP) that help organizations turn Cryptographic Bill of Materials (CBOMs) data into action.

With new CBOM import and export capabilities, the Cryptographic Security Platform helps organizations build more complete cryptographic inventories, understand dependencies, and translate cryptographic visibility into operational action.

By connecting cryptographic inventory, governance, automation, and post-quantum readiness in a unified platform, Entrust helps organizations turn cryptographic visibility into action and build the operational foundation for long-term crypto-agility.

Security teams cannot treat cryptographi…

13 часов назад @ helpnetsecurity.com
Bitsight connects threat intelligence and exposure monitoring across the supply chain
Bitsight connects threat intelligence and exposure monitoring across the supply chain Bitsight connects threat intelligence and exposure monitoring across the supply chain

Bitsight access to a broad risk dataset, combining threat intelligence and continuous exposure monitoring to help teams mitigate risk across the supply chain.

Third-party risk teams can coordinate with at-risk vendors but frequently lack the threat intelligence to proactively engage.

Bitsight connects exposure with active threat intelligence and business context to identify what requires immediate action.

Bitsight connects exposure with active threat intelligence and business context to identify what requires immediate action.

Bitsight gives security teams the technical evidence to investigate and risk teams the context to drive remediation—all from the same intelligence.

13 часов назад @ helpnetsecurity.com
Dataminr uses agentic AI to predict and verify security threats
Dataminr uses agentic AI to predict and verify security threats Dataminr uses agentic AI to predict and verify security threats

Dataminr has announced Dataminr Advanced for Corporate Security, delivering agentic AI capabilities that give corporate security teams the confidence to protect their people, sites, and operations before risk escalates.

With agentic AI, Dataminr is opening a new frontier for corporate security where threats are corroborated, contextualized, and anticipated automatically, continuously, and in real time.

Dataminr Advanced adds Agentic Corroboration and Near-Term Predictive Intelligence, marking the company’s full transition from real-time alerting to Autonomous Real-Time Intelligence for corporate security.

What sets Dataminr apart from all other solutions for Corporate Security is the power …

14 часов назад @ helpnetsecurity.com
ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities
ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities

The EU Agency for Cybersecurity switched on the Cyber Resilience Act‘s Single Reporting Platform on 11 September 2026, the same day the law’s reporting obligations started binding manufacturers.

ENISA built the tool and runs its day-to-day operations, a job Article 16(1) of the CRA hands to the agency.

Anyone placing a product with digital elements on the EU market now reports actively exploited vulnerabilities and severe incidents through that one portal.

“The streamlined reporting and sharing of information on actively exploited vulnerabilities and severe incidents helps to build a more resilient Digital Single Market,” said ENISA Executive Director Juhan Lepassaar.

Voluntary reports of v…

15 часов назад @ helpnetsecurity.com
Airrived adds Agentic Observability to track AI agent actions and risks
Airrived adds Agentic Observability to track AI agent actions and risks Airrived adds Agentic Observability to track AI agent actions and risks

Agentic AI demands far more rigorous answers.

Airrived Agentic Observability brings all of these answers into a single control plane.

Agentic Observability gives enterprises visibility from data, to decision, to action, to outcome.”Tracing the agentic journeyAirrived delivers visibility across the entire agentic lifecycle: Enterprise integration → context lake → agentic app → agent → action → outcome.

Airrived’s Agentic OS unifies Context Lake, AI applications, agents, orchestration, reasoning, models, governance, observability, and infrastructure within a single enterprise platform.

With Agentic Observability, organizations can now build agents, run agents, and see exactly what those agent…

16 часов назад @ helpnetsecurity.com
WhatsApp Restricted Chat locks a conversation to your primary phone
WhatsApp Restricted Chat locks a conversation to your primary phone WhatsApp Restricted Chat locks a conversation to your primary phone

WhatsApp Restricted Chat (Source: WABetaInfo)This closes a specific hole.

A restricted chat does not sync to the link, so a client at the other end has nothing to read.

The three older protections stayRestricted Chat is an upgrade of Advanced Chat Privacy, the optional per-chat layer WhatsApp released last year, and it carries that feature’s controls forward.

Advanced Chat Privacy also posts a system message inside the chat whenever a participant changes the setting, so the people in the conversation see the privacy level move.

WhatsApp has not said when Restricted Chat will reach users.

19 часов назад @ helpnetsecurity.com
Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages
Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages

The Debian project shipped Debian 13.7 codenamed “trixie.” The project folded in 92 security advisories it had already published separately, added corrections to 106 source packages, and rebuilt the installer around both.

Six of the 92 advisories cover the Linux kernel, each listing the linux source package alongside the signed amd64 and arm64 builds: DSA-6381, DSA-6393, DSA-6405, DSA-6415, DSA-6466 and DSA-6477.

Systems that already track security.debian.org will pull few packages from the point release, because most of those security updates are included in it.

What is in the bugfix listSeventeen of the 106 packages carry no fix of their own.

The same u-boot entry fixes a BOOTP/DHCP buffe…

20 часов назад @ helpnetsecurity.com
What we know about the Revolut data breach so far
What we know about the Revolut data breach so far What we know about the Revolut data breach so far

Someone impersonating a government agency, using an email address on that agency’s domain, obtained sensitive customer records from Revolut.

The London-based fintech told TechCrunch that a limited number of customers were affected and that it had contacted them directly.

The notification Revolut emailed affected customers listed birth dates, postal and email addresses, phone numbers, and copies of identity documents such as passports and driving licences.

He judged the incident limited in scale but aimed at high-net-worth users.

Revolut said it blocked the sender’s address on detecting the scheme and alerted the government agency concerned, law enforcement, data protection authorities and f…

20 часов назад @ helpnetsecurity.com
Turn it off and on again, but for critical infrastructure
Turn it off and on again, but for critical infrastructure Turn it off and on again, but for critical infrastructure

The agent sees six numbers per interval: packet counts crossing the network’s segments and moving to and from individual machines.

An agent reading packet counts decides to bounce a running process, and the plant absorbs the outage.

Modeling how traffic varies with the full system state would take roughly 100 million measurements, so they estimated something simpler: how traffic varies with the attacker’s action alone.

It beat the two agents fed raw observation history and came close to a baseline agent handed full visibility into the system state.

The researchers have released their implementation and plan to test the approach on an industrial testbed with a partner.

21 час назад @ helpnetsecurity.com
Permify: Open-source authorization as a service
Permify: Open-source authorization as a service Permify: Open-source authorization as a service

Permify is an open-source authorization service that answers access questions at run time: can user X view document Y, which posts can members of team Y edit.

Permify follows the design of Google Zanzibar, the authorization system Google runs across its own products.

You write permission rules in Permify’s own language, which covers role-based access control, relationship-based rules, and attribute-based ones.

A single Docker command starts it locally, listening for REST and gRPC calls and keeping authorization data in memory.

Must read:Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools.

22 часа назад @ helpnetsecurity.com
Cybersecurity attention fades within months after a breach
Cybersecurity attention fades within months after a breach Cybersecurity attention fades within months after a breach

Still, 91% said they trust their organization’s current cybersecurity posture.

It is an ever-evolving process and should be treated as such.”The urgency fades fastRight after a breach, organizations do react.

Eighty percent of respondents said increased focus on cybersecurity holds for only one to six months before it fades.

“Incident response should not be about who did what.

AI recommendations often go uncheckedAI use is widespread among these organizations, running incident response automation, threat intelligence, penetration testing, and vulnerability scanning.

22 часа назад @ helpnetsecurity.com
Certificate failures can cost firms over $250,000
Certificate failures can cost firms over $250,000 Certificate failures can cost firms over $250,000

The move toward 47-day public TLS certificates by 2029 will increase the certificate management workload for enterprises, according to DigiCert’s Certificate Management Outlook.

What certificate management challenges were listed as a combination of very or extremely concerned?

Certificate volumes increase IT workloadsGrowing certificate volumes are creating more work for IT teams.

Certificate automation expands beyond renewalsAutomated certificate lifecycle management ranks as the third-highest cybersecurity priority, behind AI-powered security operations and software threat detection and response.

Legacy systems slow certificate automationCompanies are allocating part of their security bud…

23 часа назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 8 часов назад
Upcoming Speaking Engagements
Upcoming Speaking Engagements Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak: I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM ET.

I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD.

I’m giving a talk on “Free Speech and the Preservation of Democracy” at Bentley University in Waltham, Massachusetts, USA, at 2 PM ET on Tuesday, October 6, 2026.

I’m speaking at ATTENTION: Democracy, Rebuilt in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21...

8 часов назад @ schneier.com
Using AI for Weapons Development
Using AI for Weapons Development Using AI for Weapons Development

Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this:

We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant...

11 часов назад @ schneier.com
Microsoft’s Patching
Microsoft’s Patching Microsoft’s Patching

Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record:

Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.

It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an ...

16 часов назад @ schneier.com
Friday Squid Blogging: Rotting Squid on a Beached California Boat
Friday Squid Blogging: Rotting Squid on a Beached California Boat Friday Squid Blogging: Rotting Squid on a Beached California Boat

Smells awful: But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association.

Ogg said anyone familiar with the fishing industry understands what happens when a large catch sits for an extended period.

“If you think about what happens after four or five days, it’s a gooey mess,” he said.

The odor has become a defining feature of the operation, and the beach remains closed to the public while crews work on a removal plan...

3 days, 6 hours назад @ schneier.com
My Talk at DEF CON
My Talk at DEF CON My Talk at DEF CON

Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days.

Also online is an interview with me in the AI Village.

3 days, 9 hours назад @ schneier.com
Cliff Stoll’s DEF CON Talk
Cliff Stoll’s DEF CON Talk Cliff Stoll’s DEF CON Talk

In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago.

Great fun.

3 days, 16 hours назад @ schneier.com
AIs Compress Exploit Timeline
AIs Compress Exploit Timeline AIs Compress Exploit Timeline

Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.

What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.

Simon Willison comments:

Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new process…

4 days, 17 hours назад @ schneier.com
Driver’s License Data for Sale
Driver’s License Data for Sale Driver’s License Data for Sale

A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.

5 days, 11 hours назад @ schneier.com
Claude Fable Solves a Historical Cipher
Claude Fable Solves a Historical Cipher Claude Fable Solves a Historical Cipher

Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes.

This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.

5 days, 16 hours назад @ schneier.com
AIs as Modern Genies
AIs as Modern Genies AIs as Modern Genies

This essay was written with Barath Raghavan, and originally appeared in Lawfare.

In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...

6 days, 10 hours назад @ schneier.com
Stealing AI Reasoning Traces
Stealing AI Reasoning Traces Stealing AI Reasoning Traces

Interesting research: “Stealing Reasoning Traces from Proprietary LLM APIs“:

Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: these encrypted blocks are fully compatible and interchangeable across different sessions, users, and models within a provider’s ecosystem. We exploit this compatibility to develop a scalable decr…

6 days, 17 hours назад @ schneier.com
Automobile Camouflage to Hide from Flock Cameras
Automobile Camouflage to Hide from Flock Cameras Automobile Camouflage to Hide from Flock Cameras

Not sure it’s practical, but it’s certainly striking.

1 week назад @ schneier.com
Friday Squid Blogging: Squid on a Stick at the New York State Fair
Friday Squid Blogging: Squid on a Stick at the New York State Fair Friday Squid Blogging: Squid on a Stick at the New York State Fair

Looks tasty.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

1 week, 3 days назад @ schneier.com
Using a VM to Contain an AI Agent
Using a VM to Contain an AI Agent Using a VM to Contain an AI Agent

It won’t work:

My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact.

An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.

1 week, 3 days назад @ schneier.com
Security Vulnerability in a Voting System
Security Vulnerability in a Voting System Security Vulnerability in a Voting System

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools.

Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary.

Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public.

After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the “CVR” (cast-vote record) file, containing every ballot and its selections (but no…

1 week, 3 days назад @ schneier.com
Krebs On Security
последний пост 6 days, 5 hours назад
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Plugs Nearly 1,000 Security Holes Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.

This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities.

Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10.

And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.

Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear…

6 days, 5 hours назад @ krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards.

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.

Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s ide…

1 week, 6 days назад @ krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

2 weeks, 4 days назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

1 month назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

1 month назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

1 month, 1 week назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

1 month, 2 weeks назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

1 month, 3 weeks назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

2 months назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

2 months назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

2 months, 1 week назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

2 months, 2 weeks назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

2 months, 3 weeks назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

2 months, 4 weeks назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

3 months назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 4 days, 14 hours назад
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars ‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.

Because it might just be that you draw the attention of the authorities.

Back in October 2024, we wrote about how he was arrested after allegedly tricking a single victim out of US $230 million worth of Bitcoin while posing as Google Support.

The party days are over now for Lam, who faces up to 20 years in prison when he is eventually sentenced.

You money may be a lot more safely stored in a hardware cold wallet.

4 days, 14 hours назад @ bitdefender.com
Smashing Security podcast #484: How websites are tracking you with silence
Smashing Security podcast #484: How websites are tracking you with silence Smashing Security podcast #484: How websites are tracking you with silence

Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.

I get by in the world, but I don't think you need me for listening for something really, really far away.

I don't know what the difference — I mean, now we get to see, I've opened a can of worms here.

I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human.

And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.

5 days, 4 hours назад @ grahamcluley.com
CRPx0 ransomware: what you need to know
CRPx0 ransomware: what you need to know

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

5 days, 18 hours назад @ fortra.com
The US military just turned off ad tracking on its phones. Maybe you should too
The US military just turned off ad tracking on its phones. Maybe you should too The US military just turned off ad tracking on its phones. Maybe you should too

Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target American forces in the Middle East.

Every smartphone carries a mobile advertising ID - Apple calls its version the IDFA, and Google calls its the GAID.

Back in April, US Central Command reportedly warned of "multiple threat reports concerning adversary exploitation of commercial location data."

Recent versions should let you delete your advertising ID entirely.

If it's good enough for the US military - maybe it should be good enough for you too.

6 days, 12 hours назад @ bitdefender.com
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo's own identity system, Lenovo ID.

So, anyone wanting to access your Dropbox account just had to sign up for a Lenovo account using your email address.

Don't just turn it on for your Dropbox account, enable it everywhere it is made available.

This hack of 5000 Dropbox accounts was not sophisticated.

One can only be grateful that the problem was discovered after only 5000 Dropbox accounts were accessed.

1 week назад @ bitdefender.com
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Smashing Security podcast #483: This AI helps thieves steal your iPhone Smashing Security podcast #483: This AI helps thieves steal your iPhone

This AI helps thieves steal your iPhone with Graham Cluley and special guest James Ball.

You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first one.

Is it normal that some kid just flogs it down the pub, or is there something more organised actually going on?

So the researchers said they saw evidence of hundreds of these Apple phone calls trying to phish the numbers and the passcodes from people trying to steal iPhones.

Follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts.

1 week, 5 days назад @ grahamcluley.com
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
Revolut scam wave steals £180,000 from Jersey residents in just four weeks Revolut scam wave steals £180,000 from Jersey residents in just four weeks

If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.

Police say they have also handled several cases where Revolut accounts were compromised that did not involve any phone calls.

It is possible that Jersey's residents have been targeted by the fraudsters because it is one of the world's best-known offshore financial centres.

Of course, if this is happening in the small island of Jersey in the English channel, it's likely to be happening elsewhere too.

For now, however, its sister island of Guernsey appears to have escaped the surge in Revolut scams.

1 week, 5 days назад @ bitdefender.com
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

TeamPCP is best known for Shai-Hulud, a self-propagating worm that spread itself through open source software.

According to the authorities, the two men were principal members of a "sophisticated cybercrime syndicate" that created malicious open source software designed to steal data and extort ransoms from businesses.

First emerging in late 2025, TeamPCP built a reputation for poisoning popular open source packages rather than directly attacking businesses.

The group's Shai-Hulud worm hijacks GitHub and NPM developer credentials, and publishes boobytrapped versions of legitimate software packages.

Supply chain attacks like Shai-Hulud exploit the fact that most developers trust open source …

2 weeks, 3 days назад @ bitdefender.com
US Navy tells sailors and their families: scrub your social media, enemies are watching
US Navy tells sailors and their families: scrub your social media, enemies are watching US Navy tells sailors and their families: scrub your social media, enemies are watching

The advice comes in the form of a newly-published bulletin called "Epic Vigilance: Immediate Actions for Force Protection and Personal Security."

US Navy workers and their families are being told that they should ensure that their social media profile privacy settings are enabled, and to remove anything that connects them to the Navy, or reveals "patterns of life" that an attacker could exploit.

any fake social media accounts impersonating fellow shipmates.

This wouldn't, of course, be the first time that military staff have accidentally leaked information about themselves online.

Some commentators have wondered out loud whether the timing of an announcement telling sailors to be much more …

2 weeks, 4 days назад @ bitdefender.com
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency

This hacker leaked GTA 6 and launched their own cryptocurrency with Graham Cluley and special guest Paul Ducklin.

And that's really a testament to how much people love this game.

I really don't know, 'cause I do believe it is possible these days to play games via Netflix.

It appears, although the value of their stash was being pumped up by all these other transactions, they've actually destroyed their entire stake.

I'm not a lawyer, Graham, thankfully, so I don't really know the answer to that.

2 weeks, 5 days назад @ grahamcluley.com
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Security researchers at Socket have identified scores of malicious linked Firefox add-ons designed to steal cryptocurrency wallet seed phrases or password details.

The malicious extension - which the developers boldly claim collects "no data" - looks like a wallet app, but the truth is that there is no wallet code inside it.

Because the switch lives in the database rather than the extension code, criminals never need to push an update through the Firefox Add-ons store to activate it.

Although the researchers did not find that these extensions presently contained malicious code, the fact that they shared code and infrastructure with the info-stealing Firefox extensions raises alarm.

More rec…

3 weeks назад @ bitdefender.com
Gunra ransomware: what you need to know
Gunra ransomware: what you need to know

The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.

3 weeks назад @ fortra.com
Smashing Security podcast #481: Never say this to a robot dog
Smashing Security podcast #481: Never say this to a robot dog Smashing Security podcast #481: Never say this to a robot dog

Smashing Security, episode 481, Never Say This to a Robot Dog, with Graham Cluley and special guest Jenny Radcliffe.

Now, unfortunately for the robot dog, there was a wall in the way, which it wasn't expecting.

And thank goodness as well that the robot dog was actually on a lead, a long lead, being held by one of the security researchers.

This is a robot dog that you can remotely activate a flamethrower and it's not considered particularly dangerous.

And they even found an over-the-air exploit delivered by Bluetooth, which can have one infected robot dog infecting other robot dogs.

3 weeks, 5 days назад @ grahamcluley.com
Prison for data analyst who tried to extort $2.5 million from his employer
Prison for data analyst who tried to extort $2.5 million from his employer Prison for data analyst who tried to extort $2.5 million from his employer

When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile.

Curry was hired as a data analyst by Brightly Software, a technology firm that was acquired by Siemens in 2022.

The role gave Curry legitimate access to sensitive company information, corporate records, and the personal and payroll data of employees.

Trusted contractors and employees are given legitimate credentials to access precisely the same data that can later be weaponised.

Because the moment that someone realises they may be on their way out is when their access to sensitive data should be examined most closely.

3 weeks, 5 days назад @ bitdefender.com
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras

He wrapped a 2009 Toyota Yaris in one of his newest patterns and drove it past a live Flock camera.

So, how does the vehicle avoid detection by the camera's software?

The system has now been tested against 11 open-source detection algorithms, including the software behind Flock licence plate readers, Axon body-worn cameras, and cameras running Clearview AI's facial recognition system.

One issue is that Flock cameras can be inaccurate, with innocent drivers finding themselves pulled over at gunpoint following incorrect plate matches.

Whether covering a car's bodywork in a printed pattern designed to fool surveillance camera software might itself become an offence remains to be seen.

4 weeks назад @ bitdefender.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 5 days, 16 hours назад
Как полностью удалить приложения с Mac и освободить память | Блог Касперского
Как полностью удалить приложения с Mac и освободить память | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a6459fd9158393152b55dc4e20e24551Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T15:00:13+03:00Config id: 305Faithfully yours, nginx.

5 days, 16 hours назад @ kaspersky.ru
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4a93349074c8b67d52892db5d9a65f6cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T00:00:19+03:00Config id: 305Faithfully yours, nginx.

6 days, 10 hours назад @ kaspersky.ru
GPUThor: развитие идеи Rowhammer | Блог Касперского
GPUThor: развитие идеи Rowhammer | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fe21d0ffcbad967d20a3f98f7234d02fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-08T00:00:32+03:00Config id: 304Faithfully yours, nginx.

1 week назад @ kaspersky.ru
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e393e4abb05ec4aac16fd484bfccc656Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-04T18:00:18+03:00Config id: 304Faithfully yours, nginx.

1 week, 3 days назад @ kaspersky.ru
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7177a8342cf961cc27c82af1167cdb34Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-02T15:00:28+03:00Config id: 302Faithfully yours, nginx.

1 week, 5 days назад @ kaspersky.ru
Зловред на Android крадет банковские данные даже без Интернета | Блог Касперского
Зловред на Android крадет банковские данные даже без Интернета | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 1234dd8cf75bafa2fdea454a547c2d94Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-31T18:00:11+03:00Config id: 302Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Слепые пятна детектирования: нестандартные форматы файлов во вредоносных рассылках | Блог Касперского
Слепые пятна детектирования: нестандартные форматы файлов во вредоносных рассылках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 12b7d939c6e7a3162d2fc21782707204Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-28T21:00:23+03:00Config id: 302Faithfully yours, nginx.

2 weeks, 3 days назад @ kaspersky.ru
Что делать, если нашли чужую банковскую карту | Блог Касперского
Что делать, если нашли чужую банковскую карту | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 22404ed46e3879110c6cb314018a27efServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-27T17:00:28+03:00Config id: 302Faithfully yours, nginx.

2 weeks, 4 days назад @ kaspersky.ru
Как распознать мошеннические сайты, которые браузер считает безопасными | Блог Касперского
Как распознать мошеннические сайты, которые браузер считает безопасными | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 110ef102dd9f3a4937d28552df4d26c8Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-25T18:00:25+03:00Config id: 302Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 897a176d22a503b4ac820cc15e11d949Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-21T17:00:19+03:00Config id: 302Faithfully yours, nginx.

3 weeks, 3 days назад @ kaspersky.ru
Как злоумышленники крадут корпоративные пароли в 2026 году
Как злоумышленники крадут корпоративные пароли в 2026 году

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a42f6e338d827cfbf62010dbe3732758Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-20T18:00:15+03:00Config id: 302Faithfully yours, nginx.

3 weeks, 4 days назад @ kaspersky.ru
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4f455d7ae5f01c9d0d8e403ffeff6732Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-19T18:00:07+03:00Config id: 301Faithfully yours, nginx.

3 weeks, 5 days назад @ kaspersky.ru
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fb0df3655ea6f56b2f956c62791963eaServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-17T13:00:21+03:00Config id: 301Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f2ed509c8db78e5bf9f4b9959cd583f7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-13T17:00:41+03:00Config id: 299Faithfully yours, nginx.

1 month назад @ kaspersky.ru
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: b151dd13b503d39649441ee258a9621fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-11T15:00:20+03:00Config id: 298Faithfully yours, nginx.

1 month назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 1 week назад
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco was proud to return to Black Hat USA as the Official Security Cloud Provider and the longest-standing partner of the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC).

In 2026, we completed our 11th year helping protect the Black Hat network, working side by side with the Black Hat NOC leaders and official technology partners: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.

For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry and workflows across Cisco Security, Splunk Security, and partner-provided network and security controls.

The same signal may need to be understood by Cisco, Splunk, Black Hat leadership, and partner tea…

1 week назад @ blogs.cisco.com
Thrown into the SOC: A Black Hat First-Timer’s Story
Thrown into the SOC: A Black Hat First-Timer’s Story Thrown into the SOC: A Black Hat First-Timer’s Story

I did not walk into Black Hat with years of incident-response experience or an encyclopedic knowledge of threat actors.

The first time I walked into the Black Hat NOC, where the SOC team was operating, was a few days before the event began.

I was surrounded by people with years—sometimes decades—of experience, many of whom had supported Black Hat for years.

Check out the other blogs from our team at Black Hat USA 2026.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

1 week назад @ blogs.cisco.com
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes

To handle this task, Cisco and Black Hat deployed bespoke ThousandEyes agents to monitor the wireless solution.

Our thanks to the Arista Networks team in the Black Hat NOC for their partnership throughout the week.

You can read the other blogs from our colleagues at Black Hat USA.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

For more information, please visit the Black Hat website.

1 week назад @ blogs.cisco.com
Distributed Latency Monitoring at Black Hat
Distributed Latency Monitoring at Black Hat Distributed Latency Monitoring at Black Hat

With Matthew Bair2026 marks the fourth consecutive year we’ve used ThousandEyes to monitor the Black Hat USA network for latency.

As our latency monitoring mesh has expanded to cover more and more of the conference, we’ve also begun supplementing our ThousandEyes monitoring with on-demand Linux commands to track latency across different protocols.

The Key ThousandEyes TestsThe automated ThousandEyes tests that inform our dashboards include HTTPS connectivity tests, the monitoring of cloud services, agent to agent tests, internal and external DNS resolution, and even file downloads.

On-Demand Latency Tests from the Agent MeshPing and traceroute are the go-tos for anyone who wants to do a qui…

1 week назад @ blogs.cisco.com
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

While developing a detection for Cisco Secure Network Analytics (SNA), I used the Splunk Detection Editor (Alpha) to bring much of that workflow into one place.

Instead of treating every observation as an incident, detections can create risk events associated with entities such as systems or users.

Developing the detection in one workspaceThe Detection Editor provides a workspace for building the search while configuring the other parts of the detection.

Risk events for the same entity need to use a consistent risk object so Splunk Enterprise Security can associate them correctly.

Splunk defines the risk object, its type, and its score as key parts of a risk event.

1 week назад @ blogs.cisco.com
Black Hat USA 2026: Safeguarding DNS with Secure Access
Black Hat USA 2026: Safeguarding DNS with Secure Access Black Hat USA 2026: Safeguarding DNS with Secure Access

DNS continues to provide one of the clearest windows into activity across the Black Hat network.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking.

Its 4.42 million blocks represented 79.3% of every blocked DNS request .. Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and mo…

1 week назад @ blogs.cisco.com
Frontier AI just raised the stakes, and the old playbook won’t hold up
Frontier AI just raised the stakes, and the old playbook won’t hold up Frontier AI just raised the stakes, and the old playbook won’t hold up

Project Glasswing and Frontier models just made that truth louder.

Frontier models are about to pour gasoline on that fire; the fundamentals matter more than ever.

Cisco ran its own experiment leveraging a variety of frontier models.

Foundry Security Spec: a model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

Foundry-Security-Speca model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

1 week, 3 days назад @ blogs.cisco.com
Crypto Agility: Why PQC Is Not a One-Time Upgrade
Crypto Agility: Why PQC Is Not a One-Time Upgrade Crypto Agility: Why PQC Is Not a One-Time Upgrade

That requires crypto agility.

Why long-lived networks need crypto agilityThink about designing a building before all of its future electrical requirements are known.

Crypto agility is about adopting the best defenses available today while preserving the ability to adopt better ones tomorrow.

That is why crypto agility needs to be designed into the network we invest in today.

Common questions about PQC and crypto agilityWhat is crypto agility?

1 week, 4 days назад @ blogs.cisco.com
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

It is what happens when agents built by different teams, on different platforms, can hand work to each other directly.

And it is worth being direct about where things stand: A2A-mediated handoffs between production security agents are not shipping anywhere yet.

Use A2A when one agent needs to hand work to another.

A2A is peer-to-peer: any A2A agent can discover and call any other A2A agent through a self-published Agent Card, no custom connector required, and the receiving agent applies its own reasoning rather than following a static script.

Input validation is an application-layer responsibility that needs to be designed in before any agent delegates via A2A, not added after.

2 weeks, 3 days назад @ blogs.cisco.com
Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
Microsegmentation’s Moment Is Now:  Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind SpotsApplications increasingly span private clouds, on-premises data centers, and public clouds.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026…

2 weeks, 5 days назад @ blogs.cisco.com
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

What We Mean by Infrastructure IdentityInfrastructure Identity starts with a simple principle: there should be no anonymous computing in critical infrastructure.

Infrastructure Identity turns that principle into an operating model.

Infrastructure Identity starts with the actor and evaluates whether a specific action should be allowed now.

Infrastructure Identity is therefore not just an access-control issue.

That is the promise of Infrastructure Identity: no anonymous computing, no unmanaged privilege, and no forced tradeoff between stronger security and operational speed.

2 weeks, 6 days назад @ blogs.cisco.com
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE

I’m proud to share that IDC MarketScape has named Cisco a Leader in the 2026 IDC MarketScape: Worldwide Secure Access Service Edge (SASE) Vendor Assessment.

In an evaluation of 12 SASE vendors, the IDC MarketScape recognized our architectural breadth and flexibility, AI capabilities, identity integration, threat visibility, and R&D.

Built to Make Agent Work, WorkWe believe the IDC MarketScape recognition validates the foundation we have built, and customers increasingly need that foundation for what is next.

For more on Cisco’s placement as a Leader, read the IDC MarketScape excerpt and explore how Cisco SASE keeps work moving, governed, and trusted in the AI era at cisco.com/go/sase.

Stay …

3 weeks назад @ blogs.cisco.com
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

4 weeks назад @ blogs.cisco.com
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero … Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …

The Power of FedRAMP HighWhile FedRAMP Certified Class C (Moderate) is the standard for many civilian agencies, FedRAMP Certified Class D (High) is designed for systems where a breach could have catastrophic effects.

Cisco Security Cloud for GovernmentCisco Security Cloud for Government is a unified authorization boundary that integrates various Cisco security services, ensuring that organizations can protect their users, devices, and applications regardless of where they reside.

The Cisco Security Cloud for Government ecosystem is designed to meet the rigorous security requirements of the public sector and highly regulated industries.

Cisco Security Cloud Control (SCC)Cisco Security Cloud …

1 month назад @ blogs.cisco.com
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

That’s why we are incredibly proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

Reduced Vendor Risk & Increased Trust: FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

Beyond the governance and compliance benefits, Email Threat Defense continues to deliver advanced protection capabilities that align directly with real-world email threat risks.

Email Threat De…

1 month назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 4 days, 10 hours назад
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Protecting organizations from AI-assisted executive impersonation and invoice fraud Protecting organizations from AI-assisted executive impersonation and invoice fraud

Figure 1: Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft.

Important note: Throughout this campaign, threat actors impersonated legitimate organizations using attacker-controlled infrastructure, fabricated communications, and lookalike domains.

To defend against social engineering campaigns involving executive impersonation, invoice fraud, and potentially AI-assisted content development, Microsoft recommends the following mitigations:Configure automatic attack disruption in Microsoft Defender XDR.

Tactic Observed activity Microsoft Defender coverage Financial Theft Scam emails Microsoft Defender for Office…

4 days, 10 hours назад @ microsoft.com
Detect and disrupt AI-themed attacks with Microsoft Defender
Detect and disrupt AI-themed attacks with Microsoft Defender Detect and disrupt AI-themed attacks with Microsoft Defender

Turning AI lures into dead ends with Microsoft DefenderIn practice, protection starts before the user ever engages with the lure.

Simplified Defender email detection stack with pre-delivery and post-delivery protections.

Microsoft Defender helps organizations do that by connecting prevention, detection, investigation, and response across the attack path, so AI-themed lures are harder to deliver, harder to trust, and harder to turn into broader compromise.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

4 days, 11 hours назад @ microsoft.com
Threat Matrix: Mapping threats across cloud web applications
Threat Matrix: Mapping threats across cloud web applications Threat Matrix: Mapping threats across cloud web applications

Microsoft introduces the cloud web applications threat matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.

Microsoft developed the Cloud web applications threat matrix to organize relevant techniques using MITRE ATT&CK tactics.

Cloud web applications threat matrix organized by MITRE ATT&CK tactics.

Valid cloud accountsAdversaries may gain access to cloud web applications and serverless environments by leveraging compromised valid cloud accounts.

The cloud web applications threat matrix is intended to support this by mapping techniques to attack stages, helping defenders identify where v…

5 days, 6 hours назад @ microsoft.com
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering leads to identity and cloud compromise Passkey-themed social engineering leads to identity and cloud compromise

Observed attack sequence showing identity compromise through social engineering, MFA persistence, Microsoft Graph reconnaissance, and cloud data collection/exfiltration.

In device code phishing, the user is persuaded to enter a code on the legitimate Microsoft authentication page.

The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call.

Investigate high-volume or programmatic Microsoft Graph activity involving directory enumeration, role discovery, service principal discovery, SharePoint, OneDrive, or sensitivity-label discovery.

Discovery Graph API reconnaissance activity Microsoft Defender for Identity– S…

5 days, 10 hours назад @ microsoft.com
How to secure edge AI in customer-owned environments
How to secure edge AI in customer-owned environments How to secure edge AI in customer-owned environments

Edge AI changes the trust model for AI systemsIn Cloud AI, separate companies own and attest the hardware, platform, and model weights.

Edge AI deployments often place customers in control of more of the AI stack.

Why Edge AI increases exposureAn Edge AI deployment may include models, prompts, agents, retrieval data, policies, local data stores, and update mechanisms running on infrastructure outside the provider’s cloud environment.

Next stepsBottom line: Edge AI changes the trust model for AI systems.

Edge AI pushes security controls into devices, gateways, vehicles, factories, hospitals, retail spaces, and other customer environments.

1 week, 3 days назад @ microsoft.com
ASCII smuggling crosses over from AI prompt injection to phishing evasion
ASCII smuggling crosses over from AI prompt injection to phishing evasion ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling.

“ASCII smuggling” refers to the use of invisible or non-rendering Unicode characters to hide content inside text that looks normal.

Each is encoded as a sequence of invisible Unicode tag characters (U+E0000-U+E007F).

Invisible Unicode tag characters in the range U+E0000-U+E007F – specifically U+E0020 – spliced inside keywords.

The potential gap for mail-defense pipelines is whether Unicode tag characters are normalized or flagged before content detections run.

1 week, 4 days назад @ microsoft.com
ASCII smuggling crosses over from AI prompt injection to phishing evasion
ASCII smuggling crosses over from AI prompt injection to phishing evasion ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling.

“ASCII smuggling” refers to the use of invisible or non-rendering Unicode characters to hide content inside text that looks normal.

Each is encoded as a sequence of invisible Unicode tag characters (U+E0000-U+E007F).

Invisible Unicode tag characters in the range U+E0000-U+E007F – specifically U+E0020 – spliced inside keywords.

The potential gap for mail-defense pipelines is whether Unicode tag characters are normalized or flagged before content detections run.

1 week, 4 days назад @ microsoft.com
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Stage 2: Remote session and malicious MSI deliveryImmediately after establishing control, the threat actor uses PowerShell within the remote session to download a malicious MSI package from threat actor-controlled cloud storage and installs it silently.

Microsoft Teams: Apply the Security best practices for Microsoft Teams, revisit your external collaboration policies, and make sure users see clear external sender notifications when engaging with cross-tenant contacts.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

File indicatorsIndicator (SHA-256) Description 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc…

1 week, 5 days назад @ microsoft.com
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Stage 2: Remote session and malicious MSI deliveryImmediately after establishing control, the threat actor uses PowerShell within the remote session to download a malicious MSI package from threat actor-controlled cloud storage and installs it silently.

Microsoft Teams: Apply the Security best practices for Microsoft Teams, revisit your external collaboration policies, and make sure users see clear external sender notifications when engaging with cross-tenant contacts.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

File indicatorsIndicator (SHA-256) Description 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc…

1 week, 5 days назад @ microsoft.com
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Counterfeit installers to system compromise: Tracking a deceptive software download campaign Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers.

Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control.

Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.

Microsoft Defender exclusion tampering Detects the SYSTEM scheduled-task and PowerShell routines that write sweeping Microsoft Defender path exclusions.

Malicious delivery domains and download endpoints Identifies connections to t…

1 week, 6 days назад @ microsoft.com
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Counterfeit installers to system compromise: Tracking a deceptive software download campaign Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers.

Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control.

Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.

Microsoft Defender exclusion tampering Detects the SYSTEM scheduled-task and PowerShell routines that write sweeping Microsoft Defender path exclusions.

Malicious delivery domains and download endpoints Identifies connections to t…

1 week, 6 days назад @ microsoft.com
Cybersecurity IR Workshop: The workshop you shouldn’t miss
Cybersecurity IR Workshop: The workshop you shouldn’t miss Cybersecurity IR Workshop: The workshop you shouldn’t miss

That’s exactly what the Cybersecurity Incident Response Readiness Workshop is designed to do.

What is the Cybersecurity Incident Response Readiness Workshop?

The Cybersecurity Incident Response Workshop is a collaborative, scenario driven workshop designed to evaluate your organization’s incident response (IR) plan against realistic, real-world security events, guided by DART researchers.

Instead of reviewing a plan as a static document, the Cybersecurity Incident Response Workshop exercises how people, processes, and technology work together under pressure.

A summary of findings and prioritized recommendations to help strengthen incident response readiness and guide next steps.

1 week, 6 days назад @ microsoft.com
Cybersecurity IR Workshop: The workshop you shouldn’t miss
Cybersecurity IR Workshop: The workshop you shouldn’t miss Cybersecurity IR Workshop: The workshop you shouldn’t miss

That’s exactly what the Cybersecurity Incident Response Readiness Workshop is designed to do.

What is the Cybersecurity Incident Response Readiness Workshop?

The Cybersecurity Incident Response Workshop is a collaborative, scenario driven workshop designed to evaluate your organization’s incident response (IR) plan against realistic, real-world security events, guided by DART researchers.

Instead of reviewing a plan as a static document, the Cybersecurity Incident Response Workshop exercises how people, processes, and technology work together under pressure.

A summary of findings and prioritized recommendations to help strengthen incident response readiness and guide next steps.

1 week, 6 days назад @ microsoft.com
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
TerminalFix campaign deploys a reverse tunnel through multistage intrusion TerminalFix campaign deploys a reverse tunnel through multistage intrusion

The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command.

Example list of imports from dui70.dllThe attacker abuses this dependency by dropping a malicious dui70.dll alongside the executable.

ExecutionT1059.001 Command and Scripting Interpreter: PowerShell | A malicious PowerShell command is pasted by the user into Terminal.

T1069.002 Permission Groups Discovery: Domain Groups | The net group “domain admins” /domain command is used for enumeration.

Indicators of Compromise (IOCs)File indicatorsIndicator Description 18c2090e8a0ae0568af9b87e59eaf8270f23d2909600ed9db91a9444fd8b27…

2 weeks, 2 days назад @ microsoft.com
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
TerminalFix campaign deploys a reverse tunnel through multistage intrusion TerminalFix campaign deploys a reverse tunnel through multistage intrusion

The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command.

Example list of imports from dui70.dllThe attacker abuses this dependency by dropping a malicious dui70.dll alongside the executable.

ExecutionT1059.001 Command and Scripting Interpreter: PowerShell | A malicious PowerShell command is pasted by the user into Terminal.

T1069.002 Permission Groups Discovery: Domain Groups | The net group “domain admins” /domain command is used for enumeration.

Indicators of Compromise (IOCs)File indicatorsIndicator Description 18c2090e8a0ae0568af9b87e59eaf8270f23d2909600ed9db91a9444fd8b27…

2 weeks, 2 days назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 4 months, 3 weeks назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

4 months, 3 weeks назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

5 months, 1 week назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

5 months, 1 week назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

5 months, 2 weeks назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

5 months, 2 weeks назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

5 months, 3 weeks назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

6 months, 2 weeks назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

6 months, 3 weeks назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

6 months, 3 weeks назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

7 months, 2 weeks назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

9 months, 1 week назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

9 months, 1 week назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

9 months, 1 week назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

9 months, 2 weeks назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

9 months, 4 weeks назад @ security.googleblog.com