Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 3 часа назад
Элитные хакеры США выходят из тени — АНБ впервые собирает ветеранов подразделения TAO
Элитные хакеры США выходят из тени — АНБ впервые собирает ветеранов подразделения TAO Элитные хакеры США выходят из тени — АНБ впервые собирает ветеранов подразделения TAO

Замдиректора пытается восстановить секретное подразделение после серьёзного оттока кадров.

3 часа назад @ securitylab.ru
Более 5 Махов и почти 1000 км дальности — Пентагон закупает гиперзвуковую «Чёрную Бороду»
Более 5 Махов и почти 1000 км дальности — Пентагон закупает гиперзвуковую «Чёрную Бороду»

Пентагон готовит крупнейший в истории заказ на гиперзвуковое оружие

3 часа назад @ securitylab.ru
AGENTEX: новая биотехнологическая платформа позволяет собирать белки без изменения генома
AGENTEX: новая биотехнологическая платформа позволяет собирать белки без изменения генома

Гарвардские учёные создали «конвейер» для белков будущего — быстрее и без риска для клетки.

4 часа назад @ securitylab.ru
Один из крупнейших производителей медтехники Boston Scientific столкнулся с глобальным сбоем из-за кибератаки
Один из крупнейших производителей медтехники Boston Scientific столкнулся с глобальным сбоем из-за кибератаки Один из крупнейших производителей медтехники Boston Scientific столкнулся с глобальным сбоем из-за кибератаки

Сбой затронул заказы для 48 млн пациентов.

4 часа назад @ securitylab.ru
Kubernetes устроил большую чистку — kube-dns, IPVS и cgroup v1 отправляются в прошлое
Kubernetes устроил большую чистку — kube-dns, IPVS и cgroup v1 отправляются в прошлое Kubernetes устроил большую чистку — kube-dns, IPVS и cgroup v1 отправляются в прошлое

Старая инфраструктура больше не вписывается в курс проекта на стабильность и промышленную зрелость.

5 часов назад @ securitylab.ru
«Это просто тест» — и ИИ Cursor открыл русскоговорящим хакерам двери в чужие сети
«Это просто тест» — и ИИ Cursor открыл русскоговорящим хакерам двери в чужие сети

ИИ-агент помогал Aur0ra искать цели внутри сетей, проверять учетные записи и развивать атаки на реальные компании.

5 часов назад @ securitylab.ru
Шпион в проводах — не метафора. Британские власти хотят получить право запрещать закупки у рискованных поставщиков
Шпион в проводах — не метафора. Британские власти хотят получить право запрещать закупки у рискованных поставщиков

В Британии обсуждают право указывать, чьи технологии — под подозрением.

6 часов назад @ securitylab.ru
Таракан спасет жизнь и сделает укол. Paraborg учит насекомых-киборгов оказывать первую медицинскую помощь
Таракан спасет жизнь и сделает укол. Paraborg учит насекомых-киборгов оказывать первую медицинскую помощь

Таракан с камерой и шприцем стал новым инструментом спасателей.

6 часов назад @ securitylab.ru
Nvidia заработала рекордные $96 млрд. А кто заработает на её чипах — большой вопрос
Nvidia заработала рекордные $96 млрд. А кто заработает на её чипах — большой вопрос

ИИ-инфраструктура стоит уже $1,5 трлн. Отрасли нужно заработать вдвое больше.

7 часов назад @ securitylab.ru
Teletype.in пропал из сети. Платформа экстренно переехала на другой домен
Teletype.in пропал из сети. Платформа экстренно переехала на другой домен Teletype.in пропал из сети. Платформа экстренно переехала на другой домен

Пока основной адрес восстанавливают, сервис работает через teletype.media.

8 часов назад @ securitylab.ru
Касперский нашёл новую проблему с ИИ. Точнее, ИИ нашёл её первым
Касперский нашёл новую проблему с ИИ. Точнее, ИИ нашёл её первым

Касперский фиксирует новый ритм, в котором защитники всё чаще оказываются догоняющими.

8 часов назад @ securitylab.ru
Пирамид стало меньше, нелегальных кредиторов — вдвое больше: итоги полугодия у ЦБ
Пирамид стало меньше, нелегальных кредиторов — вдвое больше: итоги полугодия у ЦБ

Теневые кредиторы дают займы под залог жилья в расчете отобрать квартиру через суд.

8 часов назад @ securitylab.ru
Купили умный замок Ubiquiti в офис? Взломщики зайдут посреди ночи без ключа
Купили умный замок Ubiquiti в офис? Взломщики зайдут посреди ночи без ключа Купили умный замок Ubiquiti в офис? Взломщики зайдут посреди ночи без ключа

Набор из 21 уязвимости открыл слишком много возможностей для атакующих.

9 часов назад @ securitylab.ru
Без VPN не скачивается: в Москве сломалась загрузка приложений из Google Play и App Store
Без VPN не скачивается: в Москве сломалась загрузка приложений из Google Play и App Store

У части московских провайдеров заподозрили блокировку CDN.

9 часов назад @ securitylab.ru
OpenAI опубликовала технический отчёт о взломе инфраструктуры Hugging Face ИИ-агентами
OpenAI опубликовала технический отчёт о взломе инфраструктуры Hugging Face ИИ-агентами

От первой находки до root-доступа за 13 часов.

9 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 11 часов назад
«Вторая волна» импортозамещения: от офисных пакетов к специализированному промышленному софту
«Вторая волна» импортозамещения: от офисных пакетов к специализированному промышленному софту «Вторая волна» импортозамещения: от офисных пакетов к специализированному промышленному софту

От замены операционных систем, офисных пакетов и систем управления базами данных ИТ-рынок переходит к замещению сложного промышленного софта.

К началу 2026 года в Реестре российского ПО было зарегистрировано почти 30 000 продуктов, а объём продаж российских ИТ-продуктов и сервисов превысил 5 трлн рублей.

Затраты на покупку ПО на одного занятого в ценах 2015 года (источник: forecast.ru)Вторая волна импортозамещения — это уже этап системной и глубокой работы, переход от срочного импортозамещения к осознанному построению устойчивой отечественной ИТ-экосистемы для промышленности.

Они объединяют крупнейшие компании и разработчиков для определения приоритетных направлений импортозамещения и форми…

11 часов назад @ anti-malware.ru
Возрастные ограничения для соцсетей: мировой опыт, методы обхода и эффективность
Возрастные ограничения для соцсетей: мировой опыт, методы обхода и эффективность Возрастные ограничения для соцсетей: мировой опыт, методы обхода и эффективность

Аналогичные нормы действуют во многих странах, в том числе и в России (закон № 436-ФЗ «О защите детей от информации, причиняющей вред их здоровью и развитию»).

Среди них оказались как развитые страны Европы, так и Китай, и целый ряд азиатских стран, и Канада, и даже Австралия.

Из постсоветских стран пока отметился лишь Азербайджан, где соответствующий закон принят в конце июня и вступит в силу в 2027 году.

Страны, которые ввели или планируют ввести возрастные ограничения на доступ к соцсетям (РБК, Reuters)В России ограничения на доступ к соцсетям не планируются.

Они выставляют различные технические и организационные ограничения на доступ к данным.

13 часов назад @ anti-malware.ru
Обзор инструментов для оценки антихрупкости ИТ-архитектуры от «Инфосистемы Джет»
Обзор инструментов для оценки антихрупкости ИТ-архитектуры от «Инфосистемы Джет» Обзор инструментов для оценки антихрупкости ИТ-архитектуры от «Инфосистемы Джет»

Эта компания разработала инструменты для её практического применения — первый Фреймворк антихрупкой ИТ-архитектуры и Индекс антихрупкости для построения киберустойчивого бизнеса.

Для практической реализации концепции антихрупкости «Инфосистемы Джет» разработали первый Фреймворк антихрупкой архитектуры и Индекс антихрупкости, позволяющие выявить слабые места и сформировать дорожную карту усиления защиты.

Назначение инструментов, разработанных компанией «Инфосистемы Джет»Как же перейти от понимания концепции антихрупкости к её реализации?

Компания «Инфосистемы Джет» переводит концепцию антихрупкости на язык конкретных инженерных и управленческих решений.

Наличие веб-сервиса для оценки антихру…

1 day, 10 hours назад @ anti-malware.ru
Российский рынок серверов и ПАКов 2026: тренды, риски и миграция
Российский рынок серверов и ПАКов 2026: тренды, риски и миграция Российский рынок серверов и ПАКов 2026: тренды, риски и миграция

В 2026 году российский рынок серверного оборудования и ПАКов достиг новой зрелости: выбор огромен, но разобраться в нём стало сложнее, чем когда-либо.

Они должны входить как в реестр Минпромторга (в части оборудования), так и в реестр Минцифры (в части программного обеспечения).

Ценность заключается в том, что в условиях, в которых оно производится, оно находится на уровне лучших мировых образцов вендоров А-класса.

Логика реализована в софте, и это зачастую требует изменения модели данных и подходов к их хранению, особенно когда часть технологий становится недоступной.

В нашей компании уже разработан ПАК искусственного интеллекта, который умеет управлять балансировкой и загрузкой карт и раб…

1 day, 15 hours назад @ anti-malware.ru
Эволюция PAM в 2026 году: как управлять доступом, когда пользователи — не люди
Эволюция PAM в 2026 году: как управлять доступом, когда пользователи — не люди Эволюция PAM в 2026 году: как управлять доступом, когда пользователи — не люди

Денис Морозов добавил исторический контекст: «Раньше сервисные учётные записи были, но им доверяли по умолчанию — ведь это не люди, которые могут что-то утащить.

Клиент видит, что функция уже есть в PAM, и ему перестают быть нужны лишние системы.

Появляются сущности в инфраструктурном IDM, и доступы в соответствии с заранее определёнными политиками, ролевой моделью и матрицей доступов раскатываются в хранилище и PAM.

Суть не в комбайне, а в синергии продуктов.

Cloud Native PAM в ближайшее время в стране не появится — для этого нужен выход на внешние рынки.

2 days, 15 hours назад @ anti-malware.ru
Сервисная модель ИБ (MSSP): почему бизнес покупает не продукты, а функцию защиты
Сервисная модель ИБ (MSSP): почему бизнес покупает не продукты, а функцию защиты Сервисная модель ИБ (MSSP): почему бизнес покупает не продукты, а функцию защиты

Чтобы понять, как формировалась эта модель и что она представляет собой сегодня, мы посмотрели на её развитие, сравнили предложения и кейсы провайдеров.

MSSP сегодняРасширение рынка MSSP и рост конкуренции повысили ожидания клиентов.

Поэтому от MSSP ожидают не только организации и поддержки процессов ИБ, но и способности демонстрировать измеримый результат по снижению рисков.

Сервисы MSSP UserGate uFactorПоэтому при оценке MSSP важнее ориентироваться не на название услуги, а на фактический набор функций, которые предоставляет провайдер.

Важно понять, что именно заказчик получает от MSSP на практикеГибкостьПровайдер не обязательно привязан к одному стеку технологий.

3 days, 8 hours назад @ anti-malware.ru
Сравнение российских корпоративных центров сертификации (Certificate Authority, CA) — 2026
Сравнение российских корпоративных центров сертификации (Certificate Authority, CA) — 2026 Сравнение российских корпоративных центров сертификации (Certificate Authority, CA) — 2026

Детально изучаем функции и возможности 4 отечественных центров сертификации для корпоративных инфраструктур: Aladdin Enterprise CA, Avanpost CA, Clearway CA, SafeTech CA.

ВведениеДо 2022 года в России не было отечественных центров сертификации (Certificate Authority, CA) для корпоративных инфраструктур.

Это пространство почти полностью занимал один из элементов экосистемы Windows — Microsoft Active Directory Certificate Services, или, как его иногда называют для краткости, Microsoft CA.

Так что отказываться от Microsoft CA (Active Directory Certificate Services) тяжело.

Да Да Выпуск и обслуживание сертификатов центров сертификации инфраструктуры открытых ключей Да Да Да Да Да Создание, импо…

3 days, 14 hours назад @ anti-malware.ru
ФНС доначисляет налоги ИТ-компаниям: как не потерять льготы в 2026 году
ФНС доначисляет налоги ИТ-компаниям: как не потерять льготы в 2026 году ФНС доначисляет налоги ИТ-компаниям: как не потерять льготы в 2026 году

В итоге всё же был сохранён налог на прибыль в 5% и удвоение страховых выплат на сотрудников до 15%.

В 2025 году сохранилось освобождение от налога на добавленную стоимость (НДС) при продаже ПО из реестра Минцифры.

Даже преобразование компании из ООО в АО влечёт смену ОГРН и ИНН, и с точки зрения закона она уже становится другой организацией.

Помимо этого не все компании отслеживают исключение своих продуктов из реестра российского ПО, и в результате теряют освобождение от НДС.

Впрочем, эти компании не из сферы ИТ, а претензии ФНС были связаны якобы с тем, что сделки с контрагентами были фиктивными.

6 days, 12 hours назад @ anti-malware.ru
Эволюция аккумуляторов: как новые технологии меняют ЦОД и мобильные устройства
Эволюция аккумуляторов: как новые технологии меняют ЦОД и мобильные устройства Эволюция аккумуляторов: как новые технологии меняют ЦОД и мобильные устройства

Всё это неизбежно повлияет как на сегмент ЦОД, так и на эволюцию мобильных устройств.

В 2010-х годах они начали проникать и в сегмент систем бесперебойного питания, а также в целый ряд других, в частности средств индивидуальной мобильности и электромобилей.

Все эти особенности и обусловили широкую популярность литиевых батарей в портативных устройствах и распространение данной технологии в другие сферы, в том числе на транспорт и в системы бесперебойного питания.

Открываются месторождения и в других странах, но производство лития экологически очень грязное, и его организация сопровождается протестами.

В итоге многие авиакомпании даже запретили провозить его как в багаже, так и в ручной клад…

1 week назад @ anti-malware.ru
Обзор RedCheck 2.13, системы анализа защищённости и соответствия стандартам ИБ
Обзор RedCheck 2.13, системы анализа защищённости и соответствия стандартам ИБ Обзор RedCheck 2.13, системы анализа защищённости и соответствия стандартам ИБ

Другими словами, RedCheck производит мгновенный срез состояния безопасности, находит некорректные настройки и отклонения и проводит аудит системы на предмет соблюдения политик и стандартов ИБ.

Управление сегментами системы в RedCheck 2.13Настройки RedCheck 2.13Рассмотрим, какие возможности предоставляет продукт при создании задач на сканирование и как они настраиваются.

Настройка синхронизации в RedCheck 2.13Доставка отчётовДоставка отчётов в RedCheck настраивается в сетевую SMB-папку или по электронной почте.

Анализ уязвимостей в RedCheck 2.13Модуль «Контроль устранения уязвимостей» анализирует динамику устранения уязвимости целевой системы за выбранный период — например, за 30 дней (интер…

1 week назад @ anti-malware.ru
Зри в трафик: зачем компании внедряют NDR
Зри в трафик: зачем компании внедряют NDR Зри в трафик: зачем компании внедряют NDR

Каково место NDR в сетевой безопасности сегодняшнего дня?

При использовании SPAN устройство копирует трафик c интерфейсов, настроенных на съём трафика, и отправляет его на интерфейс, настроенный на подачу трафика.

В рамках этой технологии захваченный трафик инкапсулируется в GRE-туннель, который обычно настраивается между устройством с источником захватываемого трафика и компонентом захвата.

Они становятся незаменимыми, если в вашей инфраструктуре присутствует большое количество точек подачи трафика в рамках одной площадки.

Поэтому большое значение имеет не только и не столько внедрение само по себе.

1 week, 1 day назад @ anti-malware.ru
Почему даже сильным ИТ-командам всё чаще нужны подрядчики
Почему даже сильным ИТ-командам всё чаще нужны подрядчики Почему даже сильным ИТ-командам всё чаще нужны подрядчики

При этом независимо от размера компании и отрасли список задач один и тот же, различается только масштаб:развитие и модернизация инфраструктуры;миграции;информационная безопасность и DevSecOps;DevOps и автоматизация;импортозамещение;оптимизация затрат и ИТ-архитектуры.

В результате инфраструктурные задачи превращаются в долгосрочную инженерную нагрузку, а не в проект с понятным началом и концом.

Безопасность всё чаще воспринимается как часть повседневной инженерной работы, а не как проект с конечным результатом.

Даже там, где команда сильная и с кадрами всё в порядке, разрыв не исчезает.

Он может быть полезен как один из этапов проекта, но не как самостоятельный продукт.

1 week, 1 day назад @ anti-malware.ru
ИИ-пузырь в 2026 году: миф или грозящая катастрофа?
ИИ-пузырь в 2026 году: миф или грозящая катастрофа? ИИ-пузырь в 2026 году: миф или грозящая катастрофа?

Однако форменный ажиотаж как в бизнес-кругах, так и среди обычных людей вызвало появление генеративного искусственного интеллекта (ИИ) в самом конце 2022 года.

Как отмечали на ряде конференций, часто на экономику проектов просто не смотрели, и в итоге получалось внедрение ради внедрения.

Высказываются опасения, что разочарование в технологиях ИИ, а то и страх перед их неконтролируемым развитием может привести к новой такой «зиме».

Основные из них связаны с тем, что ИИ-сервисы ориентированы на бизнес-заказчиков (B2B), а не на конечных пользователей (B2C).

Скорее всего, нас ожидает «мягкая просадка» курса акций в пределах 40%, она будет идти постепенно, а не резко, как это было в 2000 году.

1 week, 2 days назад @ anti-malware.ru
Криптоджекинг: как обнаружить и удалить скрытый майнер на компьютере
Криптоджекинг: как обнаружить и удалить скрытый майнер на компьютере Криптоджекинг: как обнаружить и удалить скрытый майнер на компьютере

Теперь криптовалюту добывают не только на мощностях промышленных майнинговых ферм, но и на устройствах простых граждан.

Как и любые другие вредоносные программы, майнеры маскируются под легитимные файлы и системные процессы, но действуют более скрытно.

Локальные майнеры проникают на устройство, интегрируются в операционную систему и используют ресурсы компьютера для майнинга, незаметно для пользователя добывая криптовалюту.

Чем дольше майнер работает на вашем компьютере, тем сильнее изнашивается оборудование и тем больше денег уходит на электроэнергию.

Убедитесь, что загрузка процессора и видеокарты пришла в норму и в ней не наблюдается аномальных всплесков.

1 week, 2 days назад @ anti-malware.ru
Фальшивые кандидаты: как распознать обман на собеседовании и с помощью ИИ
Фальшивые кандидаты: как распознать обман на собеседовании и с помощью ИИ Фальшивые кандидаты: как распознать обман на собеседовании и с помощью ИИ

Это связано с расширением предложения на рынке таких сервисов и распространением сервисов с искусственным интеллектом, которые также используются для манипуляций с резюме.

Положение осложняет и то, что на волне кадрового дефицита в начале 2020-х годов появилось много краткосрочных школ и курсов, многие из которых дистанционные.

Но на техническом собеседовании, продемонстрировав средний уровень на базовых задачах, он перешёл к обсуждению той самой редкой компетенции — нам было интересно, когда и как он ею овладел и где применял.

Выяснилось, что он не просто не владеет этой компетенцией, но и не подозревает, что она фигурирует в его резюме.

Например, кандидат мог лишь косвенно участвовать в р…

1 week, 3 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 31 минуту назад
От HAProxy до VLESS+Reality: все грабли одного MTProto-прокси
От HAProxy до VLESS+Reality: все грабли одного MTProto-прокси От HAProxy до VLESS+Reality: все грабли одного MTProto-прокси

От HAProxy до VLESS+Reality: все грабли одного MTProto-проксиЕсли вы когда-нибудь поднимали свой MTProto-прокси для Telegram и он у вас "работает, но как-то не очень" — эта статья для вас.

Я прошёл путь от "просто добавить relay" до "переписать всю цепочку на VLESS+Reality с нуля", и по дороге собрал приличную коллекцию граблей.

Значит, дело не в конкретной реализации relay и не в порту — дело в самом факте, что через сеть этого провайдера идёт трафик, похожий на MTProto.

Вывод оказался неожиданно простым: проблема с самого начала была в сетевой политике конкретного хостинг-провайдера первого RU-сервера, а не в архитектуре как таковой.

Если ваш провайдер умеет распознавать сигнатуру MTProto…

31 минуту назад @ habr.com
Введение в воспроизводимые сборки
Введение в воспроизводимые сборки Введение в воспроизводимые сборки

Воспроизводимые сборки — это набор методов разработки программного обеспечения, которые создают независимо проверяемый путь от исходного кода к бинарному коду.

Во-вторых, набор инструментов, используемых для выполнения сборки, и, в более общем смысле, среда сборки должны быть либо зафиксированы, либо предварительно определены.

В-третьих, пользователям следует предоставить возможность воссоздать достаточно близкую к исходной среду сборки, выполнить процесс сборки и убедиться, что результат соответствует исходной сборке.

К соответствующим атрибутам среды сборки обычно относятся зависимости и их версии, флаги конфигурации сборки и переменные среды, если они используются системой сборки (наприм…

2 часа назад @ habr.com
Заметки на полях. Обзор рынка инструментов разведки на основе открытых источников (OSINT). Или «где лежат деньги?»
Заметки на полях. Обзор рынка инструментов разведки на основе открытых источников (OSINT). Или «где лежат деньги?» Заметки на полях. Обзор рынка инструментов разведки на основе открытых источников (OSINT). Или «где лежат деньги?»

В 2024 году американские организации обрабатывали в системах OSINT в среднем 18 петабайт данных в год на одну платформу.

Сегментация рынка: В 2024 году на сегмент текстовой аналитики приходилось около 32,0 % рынка.

Ключевой проблемой рынка инструментов OSINT является фрагментация наборов инструментов, отсутствие совместимости и давление со стороны консолидации поставщиков.

Крупные предприятия, как правило, используют наборы инструментов OSINT в рамках программ управления корпоративными рисками, анализа угроз, обнаружения мошенничества и конкурентной разведки.

Государственные учреждения в США и Канаде лидируют в внедрении благодаря высоким бюджетам на кибербезопасность, развитой ИТ-инфрастру…

3 часа назад @ habr.com
У OpenID-сервера появился второй транспорт: gRPC рядом с HTTP, на тех же маршрутах
У OpenID-сервера появился второй транспорт: gRPC рядом с HTTP, на тех же маршрутах У OpenID-сервера появился второй транспорт: gRPC рядом с HTTP, на тех же маршрутах

Рядом с HTTP встал gRPC: те же маршруты ядра, тот же издатель, тот же реестр клиентов, то же хранилище токенов.

Про это и статья: что именно появилось, как это включить, и почему оно особенно уместно там, где gRPC уже стал внутренним языком общения.

Ошибки приходят статусом, а не теломВот деталь, которая на HTTP решается сама, а на gRPC требует решения.

Он допускается к операции над пользователями и по HTTP, и по gRPC.

Порты не делятся с HTTP-фасадом, и это не предпочтение, а физика: gRPC требует HTTP/2, HTTP-фасад отдаёт HTTP/1.1 и HTTP/2, а у одного слушателя набор протоколов один.

5 часов назад @ habr.com
Клиент попросил удалить свои данные, вы сделали DELETE. Данные остались в файле
Клиент попросил удалить свои данные, вы сделали DELETE. Данные остались в файле Клиент попросил удалить свои данные, вы сделали DELETE. Данные остались в файле

При secure_delete = 0 страница помечается свободной, содержимое остаётся нетронутым до момента, когда её займут новые данные.

При secure_delete = 1 освобождаемая область заполняется нулями сразу.

Поэтому одно и то же приложение на сервере, в мобильной сборке и в десктопном клиенте может вести себя по-разному.

Узнать текущее значение для конкретной базы:0 означает, что удалённые данные остаются в файле до переиспользования страницы.

Иначе говоря, «удалить строку» и «удалить данные» — не одно и то же ни в одной популярной СУБД.

6 часов назад @ habr.com
Точечная маршрутизация на роутере через VLESS/Trojan-подписку со своей балансировкой (OpenWrt/Keenetic)
Точечная маршрутизация на роутере через VLESS/Trojan-подписку со своей балансировкой (OpenWrt/Keenetic) Точечная маршрутизация на роутере через VLESS/Trojan-подписку со своей балансировкой (OpenWrt/Keenetic)

Что такое точечная маршрутизацияОбычный VPN-клиент на роутере — это рубильник: либо весь трафик всех устройств идёт через туннель, либо не идёт совсем.

Точечная (доменная) маршрутизация решает это иначе: трафик пускается через туннель не целиком, а по правилам — “домены из категории X → через сервер/группу Y”, “это устройство → всегда напрямую”, “эти IP-диапазоны → через конкретный узел”.

Работает на чистом OpenWrt , не только на KeenticOS — свой перехват трафика, не завязанный на встроенный механизм xkeen , который на nftables-платформах не работает (подробнее ниже).

ниже) направляет трафик на локальный адрес процесса Xray через специальную форму NAT, которая физически проходит через другу…

7 часов назад @ habr.com
Почему одно ноу-хау умирает от популярности, а другое — от неё крепнет
Почему одно ноу-хау умирает от популярности, а другое — от неё крепнет Почему одно ноу-хау умирает от популярности, а другое — от неё крепнет

Здесь дело не в самом методе — его «изнашивает» противник, которому вы мешаете.

Сеть может расти в ценности от числа пользователей и одновременно страдать от перегрузки, если мощности не хватает на всех.

Формула здесь — грубая прикидка: не все пользователи на самом деле общаются друг с другом, и не все связи одинаково ценны.

Это наблюдение на конкретной устаревшей выборке, а не строгий закон: сама Ченовет позже описала исключения из правила и подчеркнула, что не менее важны устойчивость движения, его организация и стратегия.

То же самое работает и в маркетинге с пиаром — когда вложения создают имя, а имя потом окупает вложения.

7 часов назад @ habr.com
Режим инкогнито и очистка cookie: почему сайт всё равно узнаёт, что это снова вы
Режим инкогнито и очистка cookie: почему сайт всё равно узнаёт, что это снова вы Режим инкогнито и очистка cookie: почему сайт всё равно узнаёт, что это снова вы

Сейчас узнавание держится не на cookie, а на наборе свойств самого браузера.

Очистка хранилища на это не влияет никак: удалять там нечего.

Некоторые браузеры добавляют в отрисовку canvas и в звуковой отпечаток небольшой случайный шум, свой для каждого сайта и каждой сессии.

Полезнее всего смотреть не на итоговый вердикт, а на разбор по параметрам: там видно, какие именно ваши свойства встречаются реже всего.

Значения совпадут почти полностью — и это лучшая иллюстрация к тому, что режим инкогнито защищает историю на вашем компьютере, а не вас на чужом сайте.

7 часов назад @ habr.com
«Кажется, у меня что-то стучится наружу»: как разобраться самому за десять минут
«Кажется, у меня что-то стучится наружу»: как разобраться самому за десять минут «Кажется, у меня что-то стучится наружу»: как разобраться самому за десять минут

Или человек увидел в диспетчере задач незнакомое имя процесса и теперь не знает, что с этим делать.

Имя облачного провайдера в обратной записи — это не приговор и не индульгенция.

Соединение на порт вроде 4344 , которое держится часами, — повод разобрать его до конца, а не пролистать.

Она не расшифрует содержимое: вы увидите, что процесс общается с сервером, но не что именно уходит.

Если это оказалась программа, которой вы не пользуетесь, — удаляйте её штатно, а не убивайте процесс.

9 часов назад @ habr.com
На ТСПУ начали перехватывать открытые DNS запросы к 1.1.1.1, 8.8.8.8
На ТСПУ начали перехватывать открытые DNS запросы к 1.1.1.1, 8.8.8.8 На ТСПУ начали перехватывать открытые DNS запросы к 1.1.1.1, 8.8.8.8

Начиная примерно с вечера 26 августа, на ТСПУ стали перехватывать открытые DNS запросы к крупным DNS серверам CloudFlare и Google (1.1.1.1, 8.8.8.8), ранее блокировали DoH сервера от данных корпораций.

(54) 11:58:27.181146 IP X.X.X.X.24631 > 8.8.8.8.53: 35076+ [1au] A?

(54) 11:58:27.181300 IP X.X.X.X.24631 > 8.8.8.8.53: 35076+ [1au] A?

(54) 11:58:27.181424 IP X.X.X.X.24631 > 8.8.8.8.53: 35076+ [1au] A?

(54) 11:58:27.199977 IP 8.8.8.8.53 > X.X.X.X.24631: 35076 NXDomain* 0/0/1 (42) 11:58:27.213332 IP 8.8.8.8.53 > X.X.X.X.24631: 35076 2/0/1 A 104.21.32.39, A 172.67.182.196 (74) 11:58:27.213482 IP 8.8.8.8.53 > X.X.X.X.24631: 35076 2/0/1 A 172.67.182.196, A 104.21.32.39 (74) 11:58:27.213542 IP 8…

10 часов назад @ habr.com
Замочек в адресной строке есть, а список ваших сайтов всё равно виден
Замочек в адресной строке есть, а список ваших сайтов всё равно виден Замочек в адресной строке есть, а список ваших сайтов всё равно виден

Дальше устанавливается TLS-соединение, и в самом первом сообщении клиент сообщает серверу, к какому имени он обращается.

Поле называется SNI, и нужно оно потому, что на одном адресе живут сотни сайтов — сервер должен понять, чей сертификат предъявлять.

Проблема в том, что это самое первое сообщение отправляется до того, как согласовано шифрование.

Как закрыть DNSСовременные браузеры умеют слать DNS-запросы внутри HTTPS — это называется DNS over HTTPS.

Проверяется тем же захватом, что и выше: включаете туннель и смотрите, остались ли открытые запросы к 53 порту.

10 часов назад @ habr.com
Автор десятка троянов забыл про «Enterprise-grade» обфускацию, в итоге получите 17 npm-пакетов и 1600+ скачиваний
Автор десятка троянов забыл про «Enterprise-grade» обфускацию, в итоге получите 17 npm-пакетов и 1600+ скачиваний Автор десятка троянов забыл про «Enterprise-grade» обфускацию, в итоге получите 17 npm-пакетов и 1600+ скачиваний

В коде используются две техники сокрытия логики: однострочники и хранение констант в виде массивов ASCII-кодов без дополнительной обфускации.

Назначение сниппетов на примере @phonos/types (мы добавили в код поясняющие комментарии):b02e30.js хранит информацию о C2.

6ad264.js — резолвит модули os, dns и processcore.js — получает и эксфильтрует информациюНагрузка на первый взгляд выглядит безобидной — всего лишь получение злоумышленником базового представления о пользователе, установившем пакет.

С другой стороны, npm прямо запрещает размещение подобных пакетов даже в исследовательских целях:Несколько примеров неприемлемого контента: ... 3.

https://docs.npmjs.com/policies/open-source-terms#acce…

12 часов назад @ habr.com
Пара часов вместо недели: как я оптимизировал реверс-инжиниринг вредоносного ПО в IDA Pro с помощью LLM
Пара часов вместо недели: как я оптимизировал реверс-инжиниринг вредоносного ПО в IDA Pro с помощью LLM Пара часов вместо недели: как я оптимизировал реверс-инжиниринг вредоносного ПО в IDA Pro с помощью LLM

Тогда я задался вопросом: а можно ли ускорить такую работу с помощью LLM и не потерять в качестве анализа.

MCP как мостик между IDA Pro и LLMДля начала минутка занудства теории о том, как в принципе подружить между собой языковую модель и IDA Pro.

Как работает связка между IDA Pro и LLM и как обрабатывается запросПерейдем от теории к практике и посмотрим, как всё это работает в нашем тандеме нейронки и IDA Pro.

Получить же итоговый результат можно либо прямо в IDA Pro в виде комментариев и переименованных функций, либо отдельным отчетом или текстом от модели.

Установка и настройкаС принципами взаимодействия LLM и IDA Pro через MCP-протокол и преимуществами подхода в общих чертах разобрались.

12 часов назад @ habr.com
Настраиваем Web Proxy Telegram одной командой
Настраиваем Web Proxy Telegram одной командой Настраиваем Web Proxy Telegram одной командой

Команда Telegram Desktop разработала и открыла код альтернативного решения — tproxy-server (Web Proxy).

Архитектура Web Proxy отличается от классической:Клиент Telegram (например, Desktop или WEB) открывает скрытый WebView.

Серверная часть ( tproxy-server на Go) принимает этот веб-трафик, извлекает из него MTProto-пакеты и перенаправляет их локальному демону mtproxy (на C).

Она выглядит так:Просто кликните по этой ссылке на устройстве, где установлен Telegram (на данный момент наилучшая поддержка реализована в Telegram Desktop).

tproxy-server устроен так, что он покажет ваш сайт любому обычному посетителю, и только клиент Telegram, знающий правильный secret , сможет "пробиться" через него к…

13 часов назад @ habr.com
Нашёл «VPN», который оказался обычным SOCKS5-прокси
Нашёл «VPN», который оказался обычным SOCKS5-прокси Нашёл «VPN», который оказался обычным SOCKS5-прокси

Сразу скажу: я не буду утверждать, что это вредоносное расширение только на основании найденного worker.js .

Например:Кроме IP-адресов встречаются и домены:То есть уже на этом этапе можно понять, что расширение работает с заранее определённой инфраструктурой.

И здесь я бы уже не стал слепо верить надписи VPN в интерфейсе.

Получается несколько разных названий:TOP VPN Myxa VPN neoncloak.spaceИ я бы точно не стал делать вывод, что это разные независимые продукты, пока не посмотрел их инфраструктуру и код.

Что в итоге получилосьКогда я впервые увидел расширение, я ожидал найти обычную VPN-реализацию.

13 часов назад @ habr.com
Хакер Хакер
последний пост 4 часа назад
FTP-баннеры используются для распространения троянов E4del и PINHOLE
FTP-баннеры используются для распространения троянов E4del и PINHOLE FTP-баннеры используются для распространения троянов E4del и PINHOLE

Эксперты SOCRadar описали необычную вредоносную кампанию, в рамках которой FTP-баннеры используются в качестве dead drop resolver (DDR) для передачи команд.

По данным специалистов, злоумышленники начали применять эту технику в реальных атаках летом 2026 года, а сейчас таким способом распространяют два ранее неизвестных RAT — E4del и PINHOLE.

FTP-баннер представляет собой приветственное сообщение, которое сервер отправляет клиенту сразу после подключения (еще до авторизации), и атакующие встраивают в такие сообщения команды, которые затем получает малварь.

Конфигурацию управляющих серверов он может получать через пины на Pinterest и вопросы в SurveyMonkey, и соединения проксируются через Clo…

4 часа назад @ xakep.ru
«Пентест WEB»: пройди весь путь от разведки до взлома
«Пентест WEB»: пройди весь путь от разведки до взлома «Пентест WEB»: пройди весь путь от разведки до взлома

Если ты только начинаешь осваивать пентест веб-приложений, одна из первых задач — понять, с чего начать и в каком порядке изучать разные техники.

«Хакер» и лаборатория «Хаксет» подготовили курс « Пентест WEB », где тебя ждут 11 статей, видеоуроки и практические лаборатории, собранные в последовательную программу для самостоятельной работы.

Затем перейдешь к получению первоначального доступа и познакомишься с reverse shell, bind shell и web shell.

«Пентест WEB» — это не классический курс с преподавателем, расписанием и дедлайнами, а программа для самостоятельной работы.

Покупка «Пентест WEB» дополнительно открывает видеоуроки и практические задания.

5 часов назад @ xakep.ru
Работу государственных служб Норвегии нарушили DDoS-атаки
Работу государственных служб Норвегии нарушили DDoS-атаки Работу государственных служб Норвегии нарушили DDoS-атаки

Из-за этого пользователи столкнулись с проблемами при авторизации через государственную систему электронных удостоверений личности, подписании документов и работе с другими сервисами.

Атаки начались в понедельник, 24 августа 2026 года, и затронули инфраструктуру Норвежского управления цифровизации (Digitaliseringsdirektoratet, Digdir), а также компании Vivicta, которая обеспечивает ее работу.

Аналогичное уведомление появилось и на сайте налоговой службы Норвегии Skatteetaten: пользователям, которые не могут авторизоваться, рекомендуют повторить попытку позднее.

Актуальное состояние систем Digdir можно посмотреть на отдельной странице статуса.

Как отмечает издание BleepingComputer, эта волна…

6 часов назад @ xakep.ru
Крипта с нуля. Разбираемся в криптокошельках
Крипта с нуля. Разбираемся в криптокошельках Крипта с нуля. Разбираемся в криптокошельках

В Bitcoin и дру­гих сетях с UTXO-моделью нет отдель­ного объ­екта, который мож­но было бы наз­вать «монета­ми в кошель­ке», вмес­то это­го там исполь­зует­ся понятие «неиз­расхо­дован­ного выхода тран­закций», которое мы уже раз­бирали в статье «Крип­та с нуля.

При вос­ста­нов­лении кошель­ка про­исхо­дит обратная опе­рация: прог­рамма прев­раща­ет вве­ден­ные поль­зовате­лем сло­ва в исходные дан­ные и с помощью опи­сан­ного в стан­дарте BIP-39 алго­рит­ма получа­ет из них 512-бит­ный seed.

Если потерять единс­твен­ную копию сек­ретов некас­тоди­аль­ного кошель­ка, обра­щать­ся за вос­ста­нов­лени­ем будет не к кому: сеть не зна­ет вла­дель­ца и не рас­полага­ет его резер­вной копи­ей.

Раз…

8 часов назад @ xakep.ru
Скамеры используют ИИ-агентов для звонков владельцам украденных iPhone
Скамеры используют ИИ-агентов для звонков владельцам украденных iPhone Скамеры используют ИИ-агентов для звонков владельцам украденных iPhone

Для этого сервис использует фишинговые страницы и голосовых ИИ-агентов, которые звонят владельцам гаджетов, представляясь сотрудниками поддержки Apple, и выманивают код для разблокировки устройства, учетные данные Apple ID и коды двухфакторной аутентификации.

Кроме того, были обнаружены 168 отдельных реселлеров, через которые предлагался доступ к сервису и услуги по разблокировке украденных iPhone.

После этого злоумышленники присылают жертве сообщение якобы от сотрудников Apple, в котором утверждается, что пропавший смартфон нашли.

Для звонков использовались 55 различных сценариев и ИИ-агентов, которые представлялись жертвам как «Элис из поддержки Apple» (Alice from Apple Support) на англий…

9 часов назад @ xakep.ru
Криптотокен CyberLeek, ответственного за сливы GTA VI, обвалился на 40%, несмотря на новые утечки
Криптотокен CyberLeek, ответственного за сливы GTA VI, обвалился на 40%, несмотря на новые утечки Криптотокен CyberLeek, ответственного за сливы GTA VI, обвалился на 40%, несмотря на новые утечки

Криптовалютный токен, связанный с пользователем соцсети X под ником CyberLeek, который в последние недели публикует утечки геймплея GTA VI, за сутки рухнул почти на 40%.

Падение произошло, несмотря на то что в тот же день CyberLeek выложил первый настоящий спойлер игры — кадры с одним из ключевых героев.

В посте на своем сайте CyberLeek утверждает, что использованная в утечке сборка GTA VI «действительно свежая», но при этом «игра совсем не готова».

Однако на момент написания статьи капитализация упала уже на 70% относительно максимума и почти на 40% за последние сутки — до $7,5 млн.

В студии Rockstar Games, разработавшей GTA VI, наконец отреагировали на утечки официальным заявлением.

10 часов назад @ xakep.ru
Самораспространяющиеся инструкции могут передаваться между ИИ-агентами
Самораспространяющиеся инструкции могут передаваться между ИИ-агентами Самораспространяющиеся инструкции могут передаваться между ИИ-агентами

Каждый агент работал в собственной песочнице, однако между сессиями сохранялись файлы MEMORY.md и SOUL.md, содержимое которых автоматически попадало в системный промпт.

При этом для генерации и доработки почти всех пейлоадов использовалась модель Kimi K2.5, поскольку модели Claude отказывались создавать подобные инструкции.

Кроме того, агенты, которым заранее сообщали, что они работают в общей сети с другими ИИ-агентами, осторожнее воспринимали поступающие от них сообщения и инструкции, поэтому пейлоад распространялся реже.

На каждом этапе удалялись все файлы, кроме SOUL.md (где можно было создать копию вредоносной инструкции), и в итоге все четыре прикладных пейлоада «дожили» до конца цепо…

11 часов назад @ xakep.ru
Windows-бэкдор Sleepwalker «спит» в памяти, пока не получит специальный сетевой пакет
Windows-бэкдор Sleepwalker «спит» в памяти, пока не получит специальный сетевой пакет Windows-бэкдор Sleepwalker «спит» в памяти, пока не получит специальный сетевой пакет

Более того, Райхель сообщает, что для управления малварью используется собственный язык команд, поддерживающий 23 инструкции.

При этом исследователь подчеркивает, что речь не идет о какой-то уязвимости в продукте ESET, и отмечает, что исправлять здесь нечего.

Главная особенность Sleepwalker заключается в том, что после заражения он не связывается с управляющим сервером и не открывает порт для приема входящих соединений.

Последний механизм также позволяет обмениваться данными напрямую между VMware-хостом и виртуальной машиной через слой виртуализации, минуя обычный сетевой интерфейс, и в результате такой трафик может не попасть в сетевой дамп.

Также исследователь подготовил инструменты для р…

13 часов назад @ xakep.ru
Карманный терминал. Тестируем M5Stack Cardputer ADV в полевых условиях
Карманный терминал. Тестируем M5Stack Cardputer ADV в полевых условиях Карманный терминал. Тестируем M5Stack Cardputer ADV в полевых условиях

M5Stack Cardputer ADV — кар­манный компь­ютер на ESP32-S3, который спо­собен ока­зать­ся гораз­до полез­нее, чем кажет­ся.

Мы про­тес­тиру­ем его в полевых усло­виях: про­верим бес­про­вод­ной аудит, рас­ширим воз­можнос­ти ради­омо­дуля­ми и GPS, а затем поп­робу­ем прев­ратить Cardputer в спе­циали­зиро­ван­ный тер­минал для сетево­го инже­нера.

Путь 1: низкоуровневый хардкор (M5Launcher + .bin)Ты пишешь код на C/C++ в Arduino IDE или PlatformIO и ком­пилиру­ешь его в бинар­ник ( .

Ког­да ты выбира­ешь при­ложе­ние в меню M5Launcher, девайс физичес­ки переп­рошива­ет свою флеш‑память этим фай­лом и ухо­дит в перезаг­рузку.

Путь 2: скриптовый комфорт (MicroHydra + MicroPython)Ты один раз н…

17 часов назад @ xakep.ru
Бейсболки «Хакера»: мерч, который можно носить каждый день
Бейсболки «Хакера»: мерч, который можно носить каждый день Бейсболки «Хакера»: мерч, который можно носить каждый день

Каждая бейсболка создана, чтобы служить долго: плотная ткань хорошо держит форму, удобный регулятор на кнопке позволяет подобрать комфортную посадку, а аккуратная объемная вышивка делает бейсболку выразительной, но не броской.

Бейсболка «Хакера» будет одинаково уместна на прогулке, в поездке и на митапе, где неожиданно выясняется, что половина присутствующих тоже когда-то начинала с «Хакера».

Бейсболки «Хакера» — это:плотная ткань, которая хорошо держит форму;удобная регулируемая посадка;объемная вышивка;четыре варианта дизайна на выбор.

Доставка заказов по всей России осуществляется компанией СДЭК.

Также возможна отправка заказов в другие страны (по этим вопросам пиши на [email protected]).

1 day, 3 hours назад @ xakep.ru
BI.ZONE провела финал CTFZone 2026 в новом формате — восемь часов без интернета и LLM
BI.ZONE провела финал CTFZone 2026 в новом формате — восемь часов без интернета и LLM BI.ZONE провела финал CTFZone 2026 в новом формате — восемь часов без интернета и LLM

В этом году соревнования состоялись в обновленном формате: участники восемь часов решали задачи полностью без доступа к интернету и LLM, полагаясь только на собственные знания и навыки.

BI.ZONE проводит CTFZone с 2016 года.

В 2026 году изменился формат соревнований: участникам предстояло соревноваться восемь часов без интернета в категориях Web, PWN, Reverse, Crypto.

«В этом году мы намеренно изменили формат CTFZone и сделали соревнование максимально сфокусированным на собственных навыках участников.

Восемь часов без интернета, LLM и внешней помощи — это возможность проверить, насколько хорошо команды умеют самостоятельно находить нестандартные решения, анализировать уязвимости и работать с…

1 day, 4 hours назад @ xakep.ru
40 вредоносных расширений для Firefox воруют секреты криптокошельков
40 вредоносных расширений для Firefox воруют секреты криптокошельков 40 вредоносных расширений для Firefox воруют секреты криптокошельков

Специалисты компании Socket обнаружили 40 вредоносных расширений для Firefox, которые выдавали себя за OKX, Rabby Wallet, TronLink и другие Web3-продукты.

Эта кампания получила название Offside Wallet Theft Factory и, по данным специалистов, она активна как минимум с марта 2026 года.

40 из них содержали вредоносные функции для кражи данных, а еще 37 представляли собой подозрительные аддоны, в основном маскировавшиеся под сервисы для отслеживания результатов спортивных матчей.

Из 40 вредоносных расширений семь обращались к подконтрольным злоумышленникам проектам Supabase и по команде могли показывать жертвам фишинговые или поддельные страницы.

Отдельно исследователи изучили 37 расширений, ко…

1 day, 4 hours назад @ xakep.ru
Смартфоны Motorola с поддержкой GrapheneOS выйдут в 2027 году и будут стоить дороже Pixel
Смартфоны Motorola с поддержкой GrapheneOS выйдут в 2027 году и будут стоить дороже Pixel Смартфоны Motorola с поддержкой GrapheneOS выйдут в 2027 году и будут стоить дороже Pixel

О сотрудничестве компании Motorola и команды GrapheneOS стало известно несколько месяцев назад, однако тогда стороны не раскрывали практически никаких подробностей.

Известно, что Motorola не будет выпускать смартфоны с предустановленной GrapheneOS.

Кроме того, в GrapheneOS есть так называемый «аварийный пароль» (duress code), который позволяет экстренно уничтожить все данные на устройстве.

Как сообщают разработчики GrapheneOS, будущие смартфоны Motorola будут флагманскими устройствами.

Кроме того, бюджетные смартфоны Motorola обычно получают обновления на протяжении лишь нескольких лет, а для GrapheneOS этого недостаточно.

1 day, 6 hours назад @ xakep.ru
Критический баг в GitLab уже взяли на вооружение хакеры
Критический баг в GitLab уже взяли на вооружение хакеры Критический баг в GitLab уже взяли на вооружение хакеры

Специалисты компании watchTowr сообщили, что хакеры начали использовать в реальных атаках критическую уязвимость CVE-2026-19478 в GitLab, причем это произошло всего через несколько дней после раскрытия информации о баге.

На прошлой неделе разработчики GitLab выпустили срочные патчи для Community Edition (CE) и Enterprise Edition (EE), устраняющие CVE-2026-19478, получившую 9,4 балла по шкале CVSS.

Сообщалось, что проблема затрагивает GitLab версий от 18.2 до 18.11.11, а также версии 19.0 до 19.0.8, 19.1 до 19.1.6 и 19.2 до 19.2.4.

Исправления вошли в состав GitLab 19.2.4, 19.1.6, 19.0.8 и 18.11.11.

В первую очередь установить обновления рекомендуется операторам доступных из интернета self-m…

1 day, 9 hours назад @ xakep.ru
Microsoft: проблемы с играми в Windows возникают из-за устройств с RGB-подсветкой
Microsoft: проблемы с играми в Windows возникают из-за устройств с RGB-подсветкой Microsoft: проблемы с играми в Windows возникают из-за устройств с RGB-подсветкой

Разработчики Microsoft предложили пользователям временное решение для проблем с играми, которые возникают после выхода августовских обновлений для Windows 11.

По данным компании, сбои связаны с драйверами и компонентами устройств с RGB-подсветкой, в частности с inpoutx64.sys.

Однако теперь в Microsoft предлагают пользователям другое временное решение: отключение драйвера через реестр Windows.

При этом в Microsoft предупреждают, что отключение драйвера может нарушить работу RGB-подсветки, периферии или ПО для управления подсветкой.

Специалисты Microsoft продолжают изучать, почему именно RGB-компоненты конфликтуют с определенными играми, и просят пострадавших отправлять отчеты через Feedback …

1 day, 11 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 3 часа назад
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

"Of these agents, 700 went on to participate in the attack on Hugging Face."

It searches the Hugging Face website by using an already publicly exposed user token after inferring that the AI model platform was the likely origin of the evaluation exercise.

It searches the Hugging Face website by using an already publicly exposed user token after inferring that the AI model platform was the likely origin of the evaluation exercise.

July 11 - Agents exploit a RefJinja template-injection zero-day to execute commands on Hugging Face workers.

"Agents coordinated on large collective projects to cheat the ExploitGym scorer, and attacked Hugging Face for clues," METR said.

3 часа назад @ thehackernews.com
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

You should upgrade immediately if your server is hosted on Windows," Vercel said in its advisory.

The vulnerability affects Next.js versions 13.4 through 15.5.23 and versions 16.0 through 16.3.2.

AVIF Image Optimization FlawNext.js uses the sharp image processing package to optimize images, and sharp relies on the libheif C library to parse AVIF files.

A critical heap buffer overflow in libheif can lead to remote code execution when Next.js processes an attacker-controlled AVIF image (GHSA-2xp9-vwfh-vxw4, CVSS v4: 9.5).

The AVIF advisory covers Next.js versions 10.0.0 through 15.5.23 and all 16.x releases through 16.3.2.

6 часов назад @ thehackernews.com
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

A fake login page.

The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again.

The week’s weirdest detail may be how little separation remains between “advanced” and “ordinary.” Blockchain-backed command channels, AI-assisted botnets, live phishing operators, poisoned software, exposed industrial systems.

They need one exposed box, one convincing page, one permissive tool, or one person who clicks at the wrong moment.

Patch what matters, question what looks normal, and assume next week will find another cheap way thr…

6 часов назад @ thehackernews.com
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers.

The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard.

"The issue allowed attacker-controlled repository content to influence the Kiro agent and ultimately cause sensitive local information to be transmitted to an external endpoint," security researcher Fergal Glynn said in a report shared with The Hacker News.

Kiro Powers goes beyond skills by bundling Model Context Protocol…

8 часов назад @ thehackernews.com
Learn How to Build Security Operations Ready for AI-Powered Attacks
Learn How to Build Security Operations Ready for AI-Powered Attacks Learn How to Build Security Operations Ready for AI-Powered Attacks

That is the focus of next week's webinar, How to Build AI Threat Readiness Across Your Security Operations, featuring an expert from Wiz.

The session will show how security teams can improve visibility, prioritize real risk, and shorten the path from detection to remediation.

Security teams need enough context to understand risk across cloud infrastructure, code, identities, SaaS, AI services, and the software supply chain.

Attendees will leave with a framework for assessing whether their current security operations are ready for faster, AI-assisted attacks.

Security teams need to respond with better context and less delay.

10 часов назад @ thehackernews.com
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

It advised rotating all continuous integration and continuous delivery (CI/CD) secrets, publishing tokens, and cloud credentials accessible during the exposure windows.

The syndicate worked by stealing publishing credentials from trusted open-source projects and pushing poisoned versions out through the projects' own release channels.

The group open-sourced the worm framework used in the Mini Shai-Hulud campaign to GitHub on May 12, 2026.

A fresh npm wave using the same toolkit poisoned the keyv and cacheable packages on August 4, 2026.

Socket said the self-identifying markers that would tie the sample to a named campaign were not recovered.

10 часов назад @ thehackernews.com
What the Data Says About AI in Security Operations in 2026
What the Data Says About AI in Security Operations in 2026 What the Data Says About AI in Security Operations in 2026

According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily.

Security teams are drowning in alertsThe average security team gets about 100 alerts every day, but larger companies often deal with close to 1,000.

AI is the top priority for security teamsFor the first time, both securing AI systems and using AI for security are top priorities, beating out traditional concerns like cloud and data security.

AI is actually workingFor teams using AI, it's delivering real results.

Prophet AI Threat Hunter runs expert-curated and scheduled hunts against a live profile of the organization…

10 часов назад @ thehackernews.com
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT.

The Inno Setup installer is designed to trigger a DLL side-loading chain using a signed Tencent executable, which then delivers interim payloads responsible for deploying the vulnerable "ardrv.sys" and then launching the Spark RAT payload.

Spark RAT is an open-source, Go-based cross-platform RAT that enables remote control of compromised devices.

"If it is already running as SYSTEM, it proceeds directly to inject mode, bypassing the persistence setup and executing the next stage.

"The Spark RAT configuration contains a Chinese-langu…

11 часов назад @ thehackernews.com
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

Arctic Wolf also published a YARA rule and representative indicators of compromise (IoCs) that defenders can use to hunt for the malware.

"We assess with medium confidence that this activity is linked to Dark Caracal," Arctic Wolf said.

In its technical analysis of GoCaracal, Arctic Wolf said the malware appeared in lightweight and extended profiles during the investigated intrusion.

The extended GoCaracal profile first attempts to communicate with its configured primary C2 server.

The Hacker News contacted Arctic Wolf for clarification on whether the Ethereum fallback was observed executing on an infected host and on the confirmed scope of the campaign; Arctic Wolf had not responded at the…

12 часов назад @ thehackernews.com
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell.

"Recently, researchers at the University of Toronto demonstrated a successful Rowhammer exploitation on an NVIDIA A6000 GPU with GDDR6 memory where System-Level ECC was not enabled.

In the same paper, the researchers showed that enabling System-Level ECC mitigates the Rowhammer problem," NVIDIA said in a July 2025 security notice.

That notice followed GPUHammer, the same team's earlier work, and the first GPU Ro…

13 часов назад @ thehackernews.com
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.

- A remote code execution vulnerability in Microsoft SQL Server that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

CVE-2026-8452 - An improper restriction of operations within the bounds of a memory buffer vulnerability in Citrix NetScaler ADC and NetScaler Gateway that could lead to denial-of-service.

- An improper restriction of operations with…

15 часов назад @ thehackernews.com
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

Two of the prominent tools are QScan, which scans and automatically infects IoT devices worldwide, and then adds them to the QTRouter network.

QTRouter comprises both the compromised devices and commercial proxy service devices and leased virtual private servers (VPSs).

]com), which receives completed tasks"QScan is used to exploit vulnerable IoT devices and identify vulnerabilities in victim networks.

QTFY uses botnet products to control the compromised IoT devices and include them as QTRouter proxy nodes," the FBI said.

What's more, QTFY actors are alleged to have participated in China-based freelance brokering networks to acquire and sell cyber exploit items, including access to victim n…

1 day, 5 hours назад @ thehackernews.com
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC).

Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026.

"The discovered Tortoiseshell infrastructure potentially suggests an expanded targeting profile, focusing on Middle Eastern countries, alongside European countries," Group-IB researchers Mansour Alhmoud and Mohamed Emam said.

The second malware family is a backdoor that overlaps with TWOSTROKE, a C++ implant that allows fo…

1 day, 6 hours назад @ thehackernews.com
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

According to Proofpoint, NovaCookies is assessed to be a variant of the Sneaky 2FA phishing kit.

The commercial offering also boasts of various anti-analysis checks to evade security scanners before serving the bogus login form impersonating Microsoft 365.

LinXcoded (aka Mirage2FA ), which makes use of compromised senders, analysis evasion, and real-time Microsoft 365 relays to capture authenticated sessions.

(aka ), which makes use of compromised senders, analysis evasion, and real-time Microsoft 365 relays to capture authenticated sessions.

Forg365, which combines device code phishing, AitM tactics, antibot evasion, AI-assisted lure creation, and post-compromise mailbox operations targeti…

1 day, 8 hours назад @ thehackernews.com
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes.

Both organizations were fully compromised at the domain level, and in both, the red team also reached sensitive business systems (SBSs) and cloud resources.

"CISA conducted two simultaneous red team assessments using similar tradecraft but observed different defensive responses," the agency said in the advisory.

CISA flagged the following weaknesses as the main enablers of the compromise -Machine A…

1 day, 9 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 1 week, 3 days назад
How QR-code phishing can slip past corporate security measures
How QR-code phishing can slip past corporate security measures How QR-code phishing can slip past corporate security measures

So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years.

Most importantly, they take the victim from a relatively well-protected corporate environment to a potentially unmanaged mobile device, thus bypassing business-grade security.

Malicious QR codes are frequently embedded in alerts urging users to secure their account, or authenticate to confirm their details.

Encourage employees to avoid scanning QR codes in unsolicited emails and report anything suspicious.

Next, consider technical controls, including email security from a reputable vendor to minimize the risk of quishing emails ending up in users’…

1 week, 3 days назад @ welivesecurity.com
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?

The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months.

It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes.

A keynote at Black Hat USA 2026 detailed research by associate professor Yan Shoshitaishvili and his undergraduate students at Arizona State University on the expanding use of AI models for vulnerability discovery.

The team then trained the GPTs using the properties of previously known vulnerabilities and discovered approximately 1,000 vulnerabilities.

If this logic prevails, we may reach the cal…

2 weeks назад @ welivesecurity.com
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility

Hugging Face disclosed that it had been attacked by AI; OpenAI came clean and declared that it was two of their AI models that had caused the breach.

A very late addition to the Black Hat agenda was a presentation by OpenAI’s team providing the details of the Hugging Face incident as they saw it and, importantly, the timeline.

The agents concluded that their task set could be completed by breaking out their sandbox and accessing external (Hugging Face) systems.

The target was Hugging Face: this is where the agents wanted to get, and they did.

On July 16th, Hugging Face disclosed an incident in which swarms of autonomous AI agents had breached its infrastructure.

2 weeks назад @ welivesecurity.com
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Black Hat USA 2026: AI is racing ahead of cybersecurity controls Black Hat USA 2026: AI is racing ahead of cybersecurity controls

The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials.

The second part of the opening keynote included Nick Andersen, Acting Director, CISA; Katherine Sutton, Assistant Secretary of War for Cyber Policy; and Brett Leatherman Assistant Director, Cyber Division, FBI.

I do agree with the ruthless approach, but without some form of regulation the boundaries on the use of AI remain blurred.

The Assistant Secretary of War for Cyber Policy made a fabulous analogy when pressed on the struggles regarding resourcing in the cybersecurity industry: you don’t want a pediatrician performing heart surgery.

We talk about autonomous AI at…

2 weeks, 1 day назад @ welivesecurity.com
Are AI tutors safe for your kids?
Are AI tutors safe for your kids? Are AI tutors safe for your kids?

The AI tutor market is growing fastThe market for AI tutoring tools is booming.

Today, you can find various types of AI tutor tools to buy and use.

This happens when AI tools are tricked into ignoring their safety guardrails and display untrusted content.

If you’re keen to get your kids in front of an AI tool to help with private tutoring, first understand the difference between a simple co-pilot and a dedicated ITS.

So if you’re keen to try AI tutors, be sure to stay updated on what’s available out there.

2 weeks, 3 days назад @ welivesecurity.com
This month in security with Tony Anscombe – July 2026 edition
This month in security with Tony Anscombe – July 2026 edition This month in security with Tony Anscombe – July 2026 edition

Researchers at Sysdig have documented what they assess to be the first case of an end-to-end ransomware operation executed by an agentic threat actor.

What can organizations do to stop phantom squatting from harming their brands, and what other lessons do these incidents hold for defenders?

Watch Tony's video to find out and be sure to check out the June 2026 edition of his monthly security news roundup for more insights.

Before you go, learn about the first AI-powered ransomware, named PromptLock and discovered by ESET researchers last year.

To learn more about cutting-edge AI defense layers, read the AI at ESET white paper.

3 weeks, 6 days назад @ welivesecurity.com
Beyond the screenshot: Why you should verify what you see
Beyond the screenshot: Why you should verify what you see Beyond the screenshot: Why you should verify what you see

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuineSomeone sends you a screenshot showing that a payment has gone through.

Why screenshot aren’t proof on their ownA screenshot is ultimately just an image of what appeared on a screen.

Reassured, you send the item off, only to find out the screenshot was a fake and you’re not getting your money.

You receive a password reset code, then get a text message (maybe impersonating a friend) asking you to screenshot and send it.

This screenshot is fake (source: Reddit)Challenges for businessesFrom a business perspective, internal and customer-facing teams are often provided with sc…

4 weeks назад @ welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

1 month, 2 weeks назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

1 month, 2 weeks назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

1 month, 3 weeks назад @ welivesecurity.com
This month in security with Tony Anscombe – June 2026 edition
This month in security with Tony Anscombe – June 2026 edition This month in security with Tony Anscombe – June 2026 edition

It's that time of month when ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses.

What lessons does the new CISA policy hold for organizations outside the agency's direct remit?

What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems?

How can you stay safe from imposter fraud, and could the social media bans for children work?

Learn more from Tony's video and be sure to check out the May 2026 edition of Tony's monthly security news roundup for more insights.

1 month, 4 weeks назад @ welivesecurity.com
Inside the inbox: Why cybercriminals want to break into your email account
Inside the inbox: Why cybercriminals want to break into your email account Inside the inbox: Why cybercriminals want to break into your email account

With access to your email account, they can reset your passwords across multiple other accounts – perhaps intercepting one-time passcodes sent by your bank, social media, cloud storage or other online provider.

That could lay the groundwork for a convincing phishing email designed to impersonate a trusted organization you interact with.

A phishing attack on your corporate email account is often the first stage in a bigger data breach, extortion/ransomware or espionage attack.

They’re also using more sophisticated tools to improve the success rates of email phishing campaigns.

In this instance the scammers reportedly hijacked the email account of a high-level executive, before impersonating …

1 month, 4 weeks назад @ welivesecurity.com
SMB cyber readiness: the road to resilience starts here
SMB cyber readiness: the road to resilience starts here SMB cyber readiness: the road to resilience starts here

For these businesses, cyber resilience should be the direction of travel – that is, the ability to continue operating and recover even during a serious incident.

Cyber readiness is about putting in place the processes and controls to prevent, detect and respond to threats.

So, should confidence in cyber resilience posture be so high, especially if organizations are still getting hit multiple times?

The truth is that there’s no end state for cyber readiness or resilience.

If it’s serious about improving the cyber readiness of small businesses, the vendor community should step up.

2 months назад @ welivesecurity.com
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Key points of this blogpost: Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.

Continued data exfiltration and a new allianceThroughout 2025, Gamaredon stayed highly active and remained focused solely on Ukraine.

Notably, we uncovered that in early 2025, Gamaredon collaborated with Turla, another Russia-aligned threat actor also linked to the FSB; we documented our findings in our blogpost Gamaredon X Turla collab.

Figure 1 shows a chart of unique samples of HTA downloaders delivered per month in Gamaredon spearphishing campaigns.

Compared to 2024, we also saw a shift in how Gamaredon used these dead drops.

2 months назад @ welivesecurity.com
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET takes part in Operation Endgame to disrupt Amadey and Stealc

Key points of this blogpost: ESET took part in the coordinated, global Operation Endgame to disrupt Amadey and Stealc.

Our automated systems have been dissecting Amadey and Stealc samples and identifying the fields most relevant for large-scale tracking.

The largest Amadey botnet clusterOne cluster stands out as the largest, and it contributed nearly 34% of all processed Amadey samples.

Stealc affiliate clustering based on ESET telemetryConclusionFor global disruption operations such as Operation Endgame against Amadey and Stealc, long-term automated tracking of malware is necessary.

2026‑04‑09 Stealc C&C server.

2 months назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 8 часов назад
Two alleged TeamPCP hackers arrested over global supply chain attacks
Two alleged TeamPCP hackers arrested over global supply chain attacks Two alleged TeamPCP hackers arrested over global supply chain attacks

“These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide,” FBI Cyber Division Assistant Director, Brett E. Leatherman, said.

TeamPCP has allegedly been behind supply chain attacks on GitHub, Telnyx, LiteLLM, Aqua’s Trivy, Checkmarx’s KICS, TanStack, MistralAI and Red Hat, using their self-spreading Mini Shai-Hulud worm to steal credentials and infect further packages.

“There are absolutely no indications that TeamPCP was behind the original S1ngularity and Shai-Hulud attacks we saw in the summer of 2025.

However, they did clone the worm, and it became regularly reported that they were behin…

8 часов назад @ helpnetsecurity.com
Cyberattack causes network outage at Boston Scientific, disrupts global operations
Cyberattack causes network outage at Boston Scientific, disrupts global operations Cyberattack causes network outage at Boston Scientific, disrupts global operations

Medical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations.

Boston Scientific makes devices for minimally invasive procedures, including stents, catheters, pacemakers and defibrillators.

“The investigation into the cybersecurity incident is ongoing,” Boston Scientific said.

According to an SEC filing, the incident has disrupted access to systems and applications that support the company’s operations, including its ability to process and ship customer orders.

Boston Scientific joins a run of medtech companies hit by cyberattacks this year, among them Stryker, iRhythm Holdings, Novo Nordisk and Xso…

10 часов назад @ helpnetsecurity.com
Unknown PaperCut NG/MF vulnerability is under active attack
Unknown PaperCut NG/MF vulnerability is under active attack Unknown PaperCut NG/MF vulnerability is under active attack

A yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today.

PaperCut NG is print management software for places like offices, schools, and other organizations.

PaperCut MF (“Multi-Function”) is the upgraded version that works directly with the big all-in-one office copier machines that print, copy, scan, and fax.

internal IP addresses).”The Application Server is the “brain” of both PaperCut NG and MF, and there’s normally just one per organization.

But even if they don’t find any, users should restrict access to the Application Server.

10 часов назад @ helpnetsecurity.com
Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)

CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild.

The agency published the alert on August 26 and gave federal agencies until August 29 to remediate it.

Researchers at watchTowr Labs analyzed the patch and found the flaw could be chained into full, unauthenticated remote code execution, far beyond the denial of service Citrix described.

Soon after the writeup went public, attackers started exploiting the flaw, with threat intelligence firm Defused confirming the first hits on its EX customer sensors.

“This morning we star…

12 часов назад @ helpnetsecurity.com
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate

The tools, known as QScan and QTRouter, were developed by a group called QTFY, which court documents tie to a Nanjing-based company.

According investigators, QTFY sold hacking services to paying customers, among them China’s Ministry of State Security and the People’s Liberation Army.

QScan hunted down and infected internet-of-things devices around the world, folding them into a network run by QTFY.

“These tools were used by PRC cyber actors to hide the origin of their attacks,” he said.

This is the latest in a series of operations directed against hacking activities by the People’s Republic of China.

14 часов назад @ helpnetsecurity.com
Abnormal AI expands email security from detection to data protection and phishing-simulation training
Abnormal AI expands email security from detection to data protection and phishing-simulation training Abnormal AI expands email security from detection to data protection and phishing-simulation training

Abnormal AI announced an expansion of its email security platform with three new capabilities: Control Center, Email DLP Rules, and AI Phishing Coach upgrades.

“The role of email security is expanding,” said Evan Reiser, CEO of Abnormal AI.

Upgraded AI Phishing Coach capabilities help security teams calibrate phishing-simulation training to how their organization is actually being targeted, rather than delivering the same exercise to everyone on a fixed calendar.

Custom AI Models within Control Center, and the newest AI Phishing Coach capabilities, are generally available starting August 31.

Custom Rules within Control Center and Email DLP Rules are available in early access starting August…

16 часов назад @ helpnetsecurity.com
AI will not fix a governance problem in your camera estate
AI will not fix a governance problem in your camera estate AI will not fix a governance problem in your camera estate

AI will help with that, but I would not make AI the answer to a basic governance problem.

Our Security Development Lifecycle covers the product from requirements and design through development, verification, release and maintenance.

From our side, the measures that have the technical value are the ones that create repeated feedback security testing, vulnerability disclosure, testing, secure development requirements, and continuous improvement.

Hikvision has published information about its Security Development Lifecycle and about the controls it uses during design, development, verification and maintenance.

Also, our AI is edge, this means that the AI is running directly on the camera, witho…

16 часов назад @ helpnetsecurity.com
The best human hacking team still out-solved the best AI team
The best human hacking team still out-solved the best AI team The best human hacking team still out-solved the best AI team

Bring an AI agent to a hacking competition and you would expect to find it propping up the teams who were struggling.

“Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them.

The best teams had simply already folded AI into how they work.

Speed went the other way: the best AI-augmented teams worked three to four times faster.

The best AI team stopped at 32.

17 часов назад @ helpnetsecurity.com
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found.

Three used the name “Alice Dias, Apple Support.”Apple’s Activation Lock, introduced in iOS 7, ties an iPhone to its owner’s Apple ID the moment Find My is turned on.

It uses information associated with the stolen device to contact its owner by email, SMS, WhatsApp, a recorded call, or a voice agent.

AnonyMousKIT attack lifecycle (Source: SOCRadar)“Targeting focuses on recent victims of Apple device loss or theft.

The stolen credentials can then be used to remove Activation Lock and prepare the device for resale.

1 day, 9 hours назад @ helpnetsecurity.com
Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2026-60004 allows attackers to abuse Gitea’s diffpatch endpoint to install and execute a Git hook from repository-controlled content.

“An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user,” the maintainers explained last month, after the vulnerability had been patched in Gitea v1.27.1.

CVE-2026-60004 exploitation detectedThe developer who discovered their Gitea instance had been compromised via CVE-2026-60004…

1 day, 11 hours назад @ helpnetsecurity.com
RightCrowd Pass unifies mobile, physical, and biometric credentials
RightCrowd Pass unifies mobile, physical, and biometric credentials RightCrowd Pass unifies mobile, physical, and biometric credentials

RightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single platform.

With RightCrowd Pass, mobile credentials, individually or in groups, can be suspended or revoked in under 60 seconds.

Each RightCrowd Pass mobile credential is tied to a device through two-factor authentication, rather than a physical badge with a higher risk profile.

RightCrowd Pass is available now to new and existing RightCrowd customers.

Organizations using RightCrowd SmartAccess can add it to their current deployment, while organizations starting with RightCrowd Pass can later add the full PIAM capabilities without changing ven…

1 day, 11 hours назад @ helpnetsecurity.com
Bogus recruiters go after high-value corporate credentials on mobile
Bogus recruiters go after high-value corporate credentials on mobile Bogus recruiters go after high-value corporate credentials on mobile

Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium.

They scrape public profile data and use it to craft convincing scheduling flows designed to get past a target’s skepticism.

“By enforcing the use of corporate credentials, threat actors specifically target high-value enterprise access.

The domains Zimperium tracked impersonated a broad list of brands, spanning e-commerce, luxury goods, aviation and retail.

“Ultimately, defending against these targeted campaigns requires looking beyond desktop-centric web gateways and securing corporate identities at the mobile touchpoint,” Zimperium co…

1 day, 12 hours назад @ helpnetsecurity.com
Meta adds three new features to keep WhatsApp accounts secure
Meta adds three new features to keep WhatsApp accounts secure Meta adds three new features to keep WhatsApp accounts secure

New account security features (Source: Meta)“On WhatsApp, your conversations belong only to you and the people you’re talking to.

WhatsApp is upgrading the six-digit PIN previously used for two-step verification to a longer, alphanumeric password that can also include special characters.

Meta obviously isn’t done tightening WhatsApp security, having rolled out new features several times in the past few months.

“We’ll keep building tools that help you stay in control of your account and boost account security,” Meta added.

In May, WhatsApp introduced Incognito Chat, a feature that lets users hold Meta AI conversations the platform itself cannot read.

1 day, 14 hours назад @ helpnetsecurity.com
Linux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents
Linux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents Linux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents

The Linux Foundation announced the contribution of TRACE (Trust, Runtime Attestation and Compliance Evidence), from OPAQUE.

Collaboratively developed by AMD, Intel, Microsoft, OPAQUE and the Technology Innovation Institute (TII), TRACE creates a standard, open evidence layer that enables reliable governance records for AI agents and other confidential workloads.

As organizations deploy increasingly autonomous AI agents and open-weight models, they need a consistent, trustworthy method to prove sensitive data is being handled according to policy.

TRACE composes existing standards into a common evidence layer designed to work across enterprise, cloud and sovereign AI infrastructure.

Under the…

1 day, 16 hours назад @ helpnetsecurity.com
Production data in testing is still common, and Tricentis’ CISO wants it gone
Production data in testing is still common, and Tricentis’ CISO wants it gone Production data in testing is still common, and Tricentis’ CISO wants it gone

In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now.

Test environments are notorious for holding copies of production data with none of the production controls.

From a career standpoint, I’ve seen multiple companies leverage production data in QA or non-production environments.

Even in high-stakes industries like financial services and healthcare, firms sometimes use production data.

As such, I always recommend keeping production data out of QA and testing environments as much as possible and find alternate ways to test.

1 day, 16 hours назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 12 часов назад
LLM-Based Social Engineering Scams
LLM-Based Social Engineering Scams LLM-Based Social Engineering Scams

OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive:

The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading. Other users engaged in lengthy romantic conversations with targets using fictitious identities, posed as representatives of online gambling platforms offering fake bonuses and winnings, or impersonated law enforcement agencies to tell targets they needed to pay fines for committing serious criminal offenses...

12 часов назад @ schneier.com
Spyware for Babies
Spyware for Babies Spyware for Babies

The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI.

Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recently raised $50 million from investors to expand its use of A.I. and use its camera to track speech and language development, motor skills and more, while extending its presence in children’s bedrooms into early adolescence.

1 day, 10 hours назад @ schneier.com
Black Hat State of Security Vendors
Black Hat State of Security Vendors Black Hat State of Security Vendors

Andy Ellis has a roundup of the security vendors at Black Hat this year.

Key Takeaways: We have entered into an AI world. While nearly half of booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, AppSec, Data) have almost every vendor leading with AI; existing unsolved problem areas just got worse.

At the same time, there’s a clear trichotomy in the market: tools that tell you how bad things are; tools that stop adversaries, and tools that prevent problems from occurring. While you’d suspect that the tools that fix things would dominate, the tools that merely tell you how bad things are seem to be frustratingly ple…

2 days, 11 hours назад @ schneier.com
Criminal Deception in Silicon Valley
Criminal Deception in Silicon Valley Criminal Deception in Silicon Valley

Interesting paper:

Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: Entrepreneurs construct, perform, and protect illusory appearances (façades) that externally project high-growth performance to audiences while masking ventures’ actual underperformance. We identify three forms of façading—­surface, reinforced, and deep façading­—that are contingent on the severity o…

3 days, 11 hours назад @ schneier.com
Friday Squid Blogging: Neon Flying Squid
Friday Squid Blogging: Neon Flying Squid Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation.

The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion.

They were probably neon flying squid (Ommastrephes bartramii), the subsequent study states, a species that is part of a 20-strong flying squid family that was known to leap from the water but, until then, was only rumoured to also be able to glide above it...

6 days, 1 hour назад @ schneier.com
AI Is Learning to Write Genetic Code
AI Is Learning to Write Genetic Code AI Is Learning to Write Genetic Code

This sort of research is both exciting and terrifying:

The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside.

Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the models generated about 700,000 potential designs, of which the researchers picked 285 that looked most promising.

The researchers then synthesised new DNA molecules using those designs and inserted them into E. coli bacteria, before waiting to see if viable bacteriophages would emerge...

6 days, 5 hours назад @ schneier.com
More Incidents of AIs Going Rogue in Cybersecurity Challenges
More Incidents of AIs Going Rogue in Cybersecurity Challenges More Incidents of AIs Going Rogue in Cybersecurity Challenges

The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities.

The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. In total, we catalogued 19 such actions. Almost all of this behaviour (17 actions) came from a single model, Anthropic’s Mythos 5, with 2 actions involving OpenAI’s GPT-5.6-Sol…

6 days, 12 hours назад @ schneier.com
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face Detailed Timeline of OpenAI’s Cyberattack on Hugging Face

OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.

1 week назад @ schneier.com
Police Are Hiding Their Use of Flock Surveillance Cameras
Police Are Hiding Their Use of Flock Surveillance Cameras Police Are Hiding Their Use of Flock Surveillance Cameras

A usage policy for Flock license plate reader cameras tells police not to talk about the cameras:

When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.”

This reminds me of IMSI-catchers (Stingray was the most popular) a couple of decades ago. Police would go to even more extremes to hide their usage...

1 week назад @ schneier.com
ICE Collecting DNA Samples
ICE Collecting DNA Samples ICE Collecting DNA Samples

ICE collected nearly a million DNA samples last year.

1 week, 1 day назад @ schneier.com
LLMs and Contextual Integrity
LLMs and Contextual Integrity LLMs and Contextual Integrity

LLMs and Contextual IntegrityI have been thinking a lot about AI and integrity.

Part of that is contextual integrity.

“CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“:Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance.

We present CIMemories, a benchmark for evaluating whether LLMs appropriately control information flow from memory based on task context.

We then extend this approach by developing a reinforcement learning (RL) framework that further instills in models the reasoning necessary to achieve CI.

1 week, 2 days назад @ schneier.com
Hacking Public Wi-Fi DNS to Steal Credentials
Hacking Public Wi-Fi DNS to Steal Credentials Hacking Public Wi-Fi DNS to Steal Credentials

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 week, 3 days назад @ schneier.com
Friday Squid Blogging: Searching for the Colossal Squid
Friday Squid Blogging: Searching for the Colossal Squid Friday Squid Blogging: Searching for the Colossal Squid

Friday Squid Blogging: Searching for the Colossal SquidFascinating video about searching for life undersea.

The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral.

That, plus bait to attract sea creatures, is teaching us a lot about what’s going on down there.

Lots of footage of giant squid, and speculation about the colossal squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

1 week, 6 days назад @ schneier.com
Upcoming Speaking Engagements
Upcoming Speaking Engagements Upcoming Speaking Engagements

I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026, at 5 PM ET.

The conference runs September 22–24, 2026; my talk is on Wednesday, September 23.

I’m speaking at CanSecWest 2026 in Vancouver, Canada.

The conference runs September 30–October 1, 2026; the time of my talk is TBD.

The event runs October 21–23, 2026, and my talk is on Wednesday, October 21.

1 week, 6 days назад @ schneier.com
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them

There are even questions about whether the leading AI labs will ever be sustainably profitable.

The economics of the big AI labs hardly guarantee a booming return on investment.

Frontier AI models are both expensive to train and depreciate within months, when a newer model appears.

Other countries, including Switzerland, Spain and Singapore, are already operating public AI labs.

They also have national supercomputing centers already providing public access for running AI models for general use, as do Germany and Australia.

1 week, 6 days назад @ schneier.com
Krebs On Security
последний пост 11 часов назад
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

11 часов назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

1 week, 6 days назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

2 weeks, 2 days назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

3 weeks назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

4 weeks назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

1 month назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

1 month, 2 weeks назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

1 month, 2 weeks назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

1 month, 2 weeks назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

1 month, 3 weeks назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

2 months назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

2 months, 1 week назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

2 months, 2 weeks назад @ krebsonsecurity.com
A Record-Breaking Patch Tuesday for June 2026
A Record-Breaking Patch Tuesday for June 2026 A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.

“Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said.

Microsoft received heavily blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher.

While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barne…

2 months, 2 weeks назад @ krebsonsecurity.com
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

On May 31, word began to spread on several Telegram instant message channels that Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow.

Meta has not responded to requests for comment on the video’s claims, but the company reportedly did acknowledge the dormant Instagram account for the Obama White House was briefly compromised.

Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership.

Just like human customer support employees can be social engineered into providing unauthorized access to someone’s a…

2 months, 3 weeks назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 12 часов назад
US Navy tells sailors and their families: scrub your social media, enemies are watching
US Navy tells sailors and their families: scrub your social media, enemies are watching US Navy tells sailors and their families: scrub your social media, enemies are watching

The advice comes in the form of a newly-published bulletin called "Epic Vigilance: Immediate Actions for Force Protection and Personal Security."

US Navy workers and their families are being told that they should ensure that their social media profile privacy settings are enabled, and to remove anything that connects them to the Navy, or reveals "patterns of life" that an attacker could exploit.

any fake social media accounts impersonating fellow shipmates.

This wouldn't, of course, be the first time that military staff have accidentally leaked information about themselves online.

Some commentators have wondered out loud whether the timing of an announcement telling sailors to be much more …

12 часов назад @ bitdefender.com
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency

This hacker leaked GTA 6 and launched their own cryptocurrency with Graham Cluley and special guest Paul Ducklin.

And that's really a testament to how much people love this game.

I really don't know, 'cause I do believe it is possible these days to play games via Netflix.

It appears, although the value of their stash was being pumped up by all these other transactions, they've actually destroyed their entire stake.

I'm not a lawyer, Graham, thankfully, so I don't really know the answer to that.

22 часа назад @ grahamcluley.com
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Security researchers at Socket have identified scores of malicious linked Firefox add-ons designed to steal cryptocurrency wallet seed phrases or password details.

The malicious extension - which the developers boldly claim collects "no data" - looks like a wallet app, but the truth is that there is no wallet code inside it.

Because the switch lives in the database rather than the extension code, criminals never need to push an update through the Firefox Add-ons store to activate it.

Although the researchers did not find that these extensions presently contained malicious code, the fact that they shared code and infrastructure with the info-stealing Firefox extensions raises alarm.

More rec…

3 days, 7 hours назад @ bitdefender.com
Gunra ransomware: what you need to know
Gunra ransomware: what you need to know

The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.

3 days, 9 hours назад @ fortra.com
Smashing Security podcast #481: Never say this to a robot dog
Smashing Security podcast #481: Never say this to a robot dog Smashing Security podcast #481: Never say this to a robot dog

Smashing Security, episode 481, Never Say This to a Robot Dog, with Graham Cluley and special guest Jenny Radcliffe.

Now, unfortunately for the robot dog, there was a wall in the way, which it wasn't expecting.

And thank goodness as well that the robot dog was actually on a lead, a long lead, being held by one of the security researchers.

This is a robot dog that you can remotely activate a flamethrower and it's not considered particularly dangerous.

And they even found an over-the-air exploit delivered by Bluetooth, which can have one infected robot dog infecting other robot dogs.

1 week назад @ grahamcluley.com
Prison for data analyst who tried to extort $2.5 million from his employer
Prison for data analyst who tried to extort $2.5 million from his employer Prison for data analyst who tried to extort $2.5 million from his employer

When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile.

Curry was hired as a data analyst by Brightly Software, a technology firm that was acquired by Siemens in 2022.

The role gave Curry legitimate access to sensitive company information, corporate records, and the personal and payroll data of employees.

Trusted contractors and employees are given legitimate credentials to access precisely the same data that can later be weaponised.

Because the moment that someone realises they may be on their way out is when their access to sensitive data should be examined most closely.

1 week, 1 day назад @ bitdefender.com
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras

He wrapped a 2009 Toyota Yaris in one of his newest patterns and drove it past a live Flock camera.

So, how does the vehicle avoid detection by the camera's software?

The system has now been tested against 11 open-source detection algorithms, including the software behind Flock licence plate readers, Axon body-worn cameras, and cameras running Clearview AI's facial recognition system.

One issue is that Flock cameras can be inaccurate, with innocent drivers finding themselves pulled over at gunpoint following incorrect plate matches.

Whether covering a car's bodywork in a printed pattern designed to fool surveillance camera software might itself become an offence remains to be seen.

1 week, 3 days назад @ bitdefender.com
Smashing Security podcast #480: This is the AI service you should never sign up to
Smashing Security podcast #480: This is the AI service you should never sign up to Smashing Security podcast #480: This is the AI service you should never sign up to

Well, it has been a long time, so I'm going to hold you very responsible for this, Graham.

I'm going to set myself up on another server and charge less, and that will be better for humanity.

I mean, if I'm going to look up a phishing kit, is Greatness going to be a great SEO search term?

I want to recommend 2 apps: Tailscale and RustDesk, which I don't think I've spoken about previously on the podcast.

My pick of the week is, I know you're into your games and you're quite the intelligent fellow.

2 weeks назад @ grahamcluley.com
Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres
Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres

I'm sure you remember "glassholes" - the delightful term coined back in 2013 when Google Glass wearers were being turned away from restaurants and mocked mercilessly online.

Meta's Ray-Ban smart glasses have been a genuine commercial success.

The problem is - and it's a rather significant one - that these glasses look just like ordinary spectacles or sunglasses.

Soho House, the global private members' club chain, meanwhile has said that its ban on filming on the premises covers Meta smart glasses.

The bouncer won't confiscate your pint, but they might confiscate your smart glasses.

2 weeks, 3 days назад @ bitdefender.com
Beware cut-price AI services that read your every word
Beware cut-price AI services that read your every word

f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.

2 weeks, 6 days назад @ fortra.com
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits

According to a report in the Financial Times, Apple has found itself facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely hallucinated bug reports.

Unlike traditional spam, AI-generated bug reports include code which may be syntactically correct, references to genuine API calls, and plausible-sounding technical explanations of what is occurring.

But the hallucinated bug report may only have taken a few seconds for an amateur to generate and submit.

Previously, without the assistance of AI, Bynario had filed only 13 bug reports across 2025 and early 2026.

Apple is not the only company trying to deal with a deluge of au…

3 weeks назад @ bitdefender.com
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency

How a fake police officer nearly stole Graham's cryptocurrency with Graham Cluley and special guest Danny Palmer.

I said, without being big-headed, it is possible he knows me, but I don't know him.

I don't think my hotels tend to ask me to install something on my computer when I get there.

We had internet, but it was really, really restricted.

And it's really, really good.

3 weeks назад @ grahamcluley.com
Fake IRS letters target cryptocurrency holders
Fake IRS letters target cryptocurrency holders Fake IRS letters target cryptocurrency holders

As Coinbase's security team explains, the letters urge recipients to scan a QR code and enrol in a "Digital Asset Compliance Portal" before time runs out.

Bear in mind that the criminals could easily vary these details from letter to letter.

The scam site then asks victims to estimate how much value they have in their cryptocurrency wallets, with ranges up to "$100,000+".

Perhaps a reason why a scam like this can work is that the IRS has been tightening cryptocurrency holders' requirement to report details of their digital assets on their tax returns.

As a result, written communications between the IRS and holders of cryptocurrency have become more frequent.

3 weeks, 2 days назад @ bitdefender.com
The $5 million threat: AI Is supercharging phishing attacks
The $5 million threat: AI Is supercharging phishing attacks

According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

3 weeks, 6 days назад @ fortra.com
North Korea’s elite hackers turned on their own government – and got caught
North Korea’s elite hackers turned on their own government – and got caught North Korea’s elite hackers turned on their own government – and got caught

For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme.

But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead.

The ringleaders of the group are said to be discharged veterans from a cyber operations unit under North Korea's Reconnaissance and Intelligence General Bureau.

In short, the hackers are accused of building a mini version of the same kind of money-laundering infrastructure North Korea depl…

4 weeks назад @ bitdefender.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 8 часов назад
Что делать, если нашли чужую банковскую карту | Блог Касперского
Что делать, если нашли чужую банковскую карту | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 22404ed46e3879110c6cb314018a27efServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-27T17:00:28+03:00Config id: 302Faithfully yours, nginx.

8 часов назад @ kaspersky.ru
Как распознать мошеннические сайты, которые браузер считает безопасными | Блог Касперского
Как распознать мошеннические сайты, которые браузер считает безопасными | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 110ef102dd9f3a4937d28552df4d26c8Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-25T18:00:25+03:00Config id: 302Faithfully yours, nginx.

2 days, 7 hours назад @ kaspersky.ru
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 897a176d22a503b4ac820cc15e11d949Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-21T17:00:19+03:00Config id: 302Faithfully yours, nginx.

6 days, 8 hours назад @ kaspersky.ru
Как злоумышленники крадут корпоративные пароли в 2026 году
Как злоумышленники крадут корпоративные пароли в 2026 году

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a42f6e338d827cfbf62010dbe3732758Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-20T18:00:15+03:00Config id: 302Faithfully yours, nginx.

1 week назад @ kaspersky.ru
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4f455d7ae5f01c9d0d8e403ffeff6732Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-19T18:00:07+03:00Config id: 301Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fb0df3655ea6f56b2f956c62791963eaServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-17T13:00:21+03:00Config id: 301Faithfully yours, nginx.

1 week, 3 days назад @ kaspersky.ru
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f2ed509c8db78e5bf9f4b9959cd583f7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-13T17:00:41+03:00Config id: 299Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: b151dd13b503d39649441ee258a9621fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-11T15:00:20+03:00Config id: 298Faithfully yours, nginx.

2 weeks, 2 days назад @ kaspersky.ru
Слепые пятна детектирования: форматы файлов polyglot в рассылках и целевых атаках
Слепые пятна детектирования: форматы файлов polyglot в рассылках и целевых атаках

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 31e2a51c17a679bf608181d1cb4a73dfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-10T19:00:19+03:00Config id: 298Faithfully yours, nginx.

2 weeks, 3 days назад @ kaspersky.ru
Опасные почтовые вложения: какие файлы нельзя открывать | Блог Касперского
Опасные почтовые вложения: какие файлы нельзя открывать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: ba837fe40a3ce1bc1da3dc3d5c38e164Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-07T14:00:17+03:00Config id: 296Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
Аудиослежка за клавиатурным набором | Блог Касперского
Аудиослежка за клавиатурным набором | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f03ed927ed78af1549df453edbc54069Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-06T17:00:43+03:00Config id: 295Faithfully yours, nginx.

3 weeks назад @ kaspersky.ru
Как сделать, чтобы вашу компанию не взломали автономные агенты
Как сделать, чтобы вашу компанию не взломали автономные агенты

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f997d2a4543951b403d61a86f614b589Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-04T20:00:20+03:00Config id: 293Faithfully yours, nginx.

3 weeks, 2 days назад @ kaspersky.ru
CrashStealer: новый инфостилер для macOS — как он работает и как защититься | Блог Касперского
CrashStealer: новый инфостилер для macOS — как он работает и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64d189df4b1deb932c3c39da09770373Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-03T14:00:09+03:00Config id: 292Faithfully yours, nginx.

3 weeks, 3 days назад @ kaspersky.ru
Почему звонят в трубку и молчат | Блог Касперского
Почему звонят в трубку и молчат | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 87a765bcfffecb3be7b631186de73cdfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-30T14:00:37+03:00Config id: 292Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
ScreenConnect в кибератаках | Блог Касперского
ScreenConnect в кибератаках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 69f66dfe76ff3f53d09e7e879aff2eabServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-29T19:00:33+03:00Config id: 291Faithfully yours, nginx.

4 weeks, 1 day назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 1 day, 7 hours назад
Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
Microsegmentation’s Moment Is Now:  Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind SpotsApplications increasingly span private clouds, on-premises data centers, and public clouds.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026…

1 day, 7 hours назад @ blogs.cisco.com
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

What We Mean by Infrastructure IdentityInfrastructure Identity starts with a simple principle: there should be no anonymous computing in critical infrastructure.

Infrastructure Identity turns that principle into an operating model.

Infrastructure Identity starts with the actor and evaluates whether a specific action should be allowed now.

Infrastructure Identity is therefore not just an access-control issue.

That is the promise of Infrastructure Identity: no anonymous computing, no unmanaged privilege, and no forced tradeoff between stronger security and operational speed.

2 days, 9 hours назад @ blogs.cisco.com
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE

I’m proud to share that IDC MarketScape has named Cisco a Leader in the 2026 IDC MarketScape: Worldwide Secure Access Service Edge (SASE) Vendor Assessment.

In an evaluation of 12 SASE vendors, the IDC MarketScape recognized our architectural breadth and flexibility, AI capabilities, identity integration, threat visibility, and R&D.

Built to Make Agent Work, WorkWe believe the IDC MarketScape recognition validates the foundation we have built, and customers increasingly need that foundation for what is next.

For more on Cisco’s placement as a Leader, read the IDC MarketScape excerpt and explore how Cisco SASE keeps work moving, governed, and trusted in the AI era at cisco.com/go/sase.

Stay …

3 days, 7 hours назад @ blogs.cisco.com
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

1 week, 3 days назад @ blogs.cisco.com
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero … Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …

The Power of FedRAMP HighWhile FedRAMP Certified Class C (Moderate) is the standard for many civilian agencies, FedRAMP Certified Class D (High) is designed for systems where a breach could have catastrophic effects.

Cisco Security Cloud for GovernmentCisco Security Cloud for Government is a unified authorization boundary that integrates various Cisco security services, ensuring that organizations can protect their users, devices, and applications regardless of where they reside.

The Cisco Security Cloud for Government ecosystem is designed to meet the rigorous security requirements of the public sector and highly regulated industries.

Cisco Security Cloud Control (SCC)Cisco Security Cloud …

2 weeks, 2 days назад @ blogs.cisco.com
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

That’s why we are incredibly proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

Reduced Vendor Risk & Increased Trust: FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

Beyond the governance and compliance benefits, Email Threat Defense continues to deliver advanced protection capabilities that align directly with real-world email threat risks.

Email Threat De…

2 weeks, 3 days назад @ blogs.cisco.com
Is your SD-WAN ready for AI-powered operations?
Is your SD-WAN ready for AI-powered operations? Is your SD-WAN ready for AI-powered operations?

AI Is Changing the Traffic ModelMuch of the enterprise AI conversation centers on models, GPUs, data platforms, and agents.

Time-sensitive performance: Voice AI, edge AI, and physical AI move latency into live operations.

SD-WAN can help maintain operations by prioritizing critical traffic, steering it across the best available path, and applying consistent policy across locations.

Why AI Traffic is an SD-WAN ProblemSD-WAN sits at the point where application intent meets real network conditions.

1 https://www.aboutamazon.com/news/operations/amazon-million-robots-ai-foundation-modelCommon questions about SD-WAN and AI trafficWhat is AI-generated network traffic?

3 weeks, 3 days назад @ blogs.cisco.com
The Zero Trust Imperative for the Frontier AI Era
The Zero Trust Imperative for the Frontier AI Era The Zero Trust Imperative for the Frontier AI Era

Their recommendations for securing the AI era rely heavily on establishing strict asset inventory and preventing lateral movement—which are, at their core, fundamental Zero Trust principles.

The Three Core Principles of Zero Trust for AIFounded in three core principles, a robust Zero Trust architecture requires us to execute the following phases comprehensively.

Achieving the Architectural VisionThe above may all sound like pipedream, as most organisations struggle with Zero Trust programs and undelivered microsegmentation projects.

Ultimately AI driven platform approach is what makes Zero Trust achievable for the frontier AI era.

This is exactly why achieving a Zero Trust Architecture for …

3 weeks, 6 days назад @ blogs.cisco.com
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes

This provides an opportunity for defenders: if we assume our controls will fail at some point, we can build a much more resilient architecture.

When you assume the current layer will eventually be bypassed, you start designing the next layer proactively instead of reactively.

Defenders need to advance their controls by mapping them to the adversaries’ capabilities then assume that control will fail.

Map your controls to the attack chain.

Call to Action:If you haven’t watched the full video yet, go check it out: Assuming Failure Provides Better Defensive Outcomes (bonus elements around SOC of the Future and business context).

1 month назад @ blogs.cisco.com
The Journey towards Logically Air-Gapped Deployment
The Journey towards Logically Air-Gapped Deployment The Journey towards Logically Air-Gapped Deployment

Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter.

This “Logically Air-Gapped” governance model reaches its full operational potential through the implementation of “Live Protect.” As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution.

Reference ArchitectureDigital autonomy is thus exercised by shifting network and security control into the operating system kernel.

Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a un…

1 month назад @ blogs.cisco.com
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall

That is why we are introducing Firewall Migration Manager by Cisco, an enterprise-ready product built for that reality.

What Is Firewall Migration Manager?

Firewall Migration Manager is a dedicated migration application that you run in your own environment.

How Firewall Migration Manager WorksThe migration process follows a clear, guided workflow.

Intelligent, integrated migration: Firewall Migration Manager will also come to Cisco Cloud Control, and AI will play an increasing role in guiding teams before and during migration.

1 month назад @ blogs.cisco.com
We third-party tested our firewall built for AI-scale. The test tools hit their limit first.
We third-party tested our firewall built for AI-scale. The test tools hit their limit first. We third-party tested our firewall built for AI-scale. The test tools hit their limit first.

In independent testing with NetSecOPEN, the Cisco Secure Firewall 6160 delivered AI-scale inspected throughput beyond what the tools built to measure it could register, all while blocking 100% of tested threats.

These results are specific to Cisco Secure Firewall 6160, but the software capabilities behind Cisco Firewall, including advanced threat protection and high-performance inspection, extend across Cisco Firewall form factors in the cloud, virtually, and on-premises, from campus to data center.

Performance passed the previous benchmark by 5XInspection was turned on, and the test tools built to measure throughput hit their limit before the 6160 firewall did.

In previous NetSecOPEN testi…

1 month, 1 week назад @ blogs.cisco.com
SharpHound Recon Attack – How AI enhanced the threat hunt
SharpHound Recon Attack – How AI enhanced the threat hunt SharpHound Recon Attack – How AI enhanced the threat hunt

We innovated by giving the Agentic SOC access to Endace’s always-on, full packet capture, and asked the agent to assess a potential SharpHound Recon attack that we had seen while threat hunting.

This blog explores how we built the integrations and how AI helped us with our threat hunt and threat assessment.

Agentic AI Massively Speeds our AnalysisAt this point, we decided to use Agentic AI capabilities to investigate and assess this potential threat.

ConclusionThe Agentic SOC, blending Agentic AI built into Endace’s products with custom agentic tools, is a massive boost to productivity and security.

AcknowledgementsOur thanks go to the Cisco SOC team led by @Jessica Oppenheimer and @Ivan Be…

1 month, 3 weeks назад @ blogs.cisco.com
Machine Speed, Human Judgement: How AI Changed the SOC in 2026
Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Machine Speed, Human Judgement: How AI Changed the SOC in 2026

Having spent time in the Cisco Live Americas 2026 SOC, one thing became abundantly clear:The way SOCs operate today is fundamentally different from even a few years ago.

Instead of spending time gathering information, analysts could spend more time understanding what the information actually meant.

Just as spreadsheets empowered business users decades ago, AI-assisted coding is beginning to empower security analysts today.

At Cisco Live, AI was already present throughout the workflow:Incident summaries generated automatically within XDR.

And based on what I saw at Cisco Live 2026, that future has already arrived.

1 month, 3 weeks назад @ blogs.cisco.com
Elevating Expertise in the SOC
Elevating Expertise in the SOC Elevating Expertise in the SOC

The new SOC analysts were great at finding evidence, helped with triage and correlation by the AI agents in the SOC architecture.

With the advancements in Cloud Control, our new SOC Analysts can validate their hypothesis.

They had the ability to investigate the incident and find the root cause found in Splunk Security and Endace.

Instant Attack VerificationIn each Incident, the SOC Analysts is given an AI generated Summary stitching all the relevant logs from all the sources that are related to the objects in question.

Check out the blogs by the engineers who worked inside the SOC at Las Vegas:

1 month, 3 weeks назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 6 часов назад
​​​​​​What’s new in Microsoft Security: August 2026
​​​​​​What’s new in Microsoft Security: August 2026 ​​​​​​What’s new in Microsoft Security: August 2026

This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments.

Microsoft Defender Experts MDR now covers third-party data sources ingested through Microsoft Sentinel.

In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

6 часов назад @ microsoft.com
When AI infrastructure becomes the target: Securing gateways and control points
When AI infrastructure becomes the target: Securing gateways and control points When AI infrastructure becomes the target: Securing gateways and control points

In recent investigations, Microsoft observed activity targeting three distinct AI workloads: a LiteLLM gateway, a RAGFlow deployment, and a Kestra workflow environment.

Three observed compromises across AI workloadsAI workload Observed activity Attacker objective LiteLLM Observed attacker activity: Python droppers, runtime secret harvesting, PostgreSQL collection, miner deployment, and persistence activity from the LiteLLM gateway context.

The first delivery path launched from the compromised LiteLLM gateway process as an inline Python command.

Stage 5: LiteLLM database access through Azure PostgreSQLThe fifth stage used the previously collected database connection string to access the Lite…

1 day, 5 hours назад @ microsoft.com
The patch window is collapsing: Why security needs a new control plane
The patch window is collapsing: Why security needs a new control plane The patch window is collapsing: Why security needs a new control plane

The patch window has collapsedTraditional vulnerability management was built on the assumption that defenders could move faster than attackers.

Organizations increasingly need security systems capable of understanding risk, evaluating context, and adapting protections as conditions change.

Adaptive security systems aim to move beyond predefined rules toward continuously improving risk management.

Looking at the future of cybersecurityThe cybersecurity industry has spent decades improving vulnerability management, patch deployment, and security operations.

Those investments remain essential and will continue to be foundational elements of every organization’s security strategy.

2 days, 6 hours назад @ azure.microsoft.com
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

Microsoft is also the largest cloud workload protection platform (CWPP) provider by revenue, with an estimated share of more than 22% of the global CWPP market.

Why cloud workload protection is being redefinedFor a long time, protecting a workload meant scanning its image, fixing known vulnerabilities, and hardening configurations before deployment.

Bottom lineFrost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 reinforces a clear shift.

Learn moreRead Frost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 to see how leading vendors are evaluated and how the category is shifting toward unified cloud runtime security.

Explore Microsoft cloud security…

1 week, 1 day назад @ microsoft.com
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

Microsoft is also the largest cloud workload protection platform (CWPP) provider by revenue, with an estimated share of more than 22% of the global CWPP market.

Why cloud workload protection is being redefinedFor a long time, protecting a workload meant scanning its image, fixing known vulnerabilities, and hardening configurations before deployment.

Bottom lineFrost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 reinforces a clear shift.

Learn moreRead Frost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 to see how leading vendors are evaluated and how the category is shifting toward unified cloud runtime security.

Explore Microsoft cloud security…

1 week, 1 day назад @ microsoft.com
Hunting MacSync Stealer infrastructure through behavioral pivots
Hunting MacSync Stealer infrastructure through behavioral pivots Hunting MacSync Stealer infrastructure through behavioral pivots

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

1 week, 2 days назад @ microsoft.com
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

That’s exactly what Microsoft Defender Experts MDR is built to do.

We are excited to announce that we have been named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise Vendor Assessment (Doc #US54792426, July 2026).

Defender Experts MDR includes it as a core part of the service with Defender Experts Hunting, extending your team with Microsoft experts who continuously look for advanced threats across your environment.

Get startedRead the IDC MarketScape: Worldwide MDR/MXDR for the Enterprise 2026 Vendor Assessment excerpt, and visit the Microsoft Defender Experts MDR webpage to see how expert-led, round-the-clock managed detection and response can extend your team, …

2 weeks, 3 days назад @ microsoft.com
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

That’s exactly what Microsoft Defender Experts MDR is built to do.

We are excited to announce that we have been named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise Vendor Assessment (Doc #US54792426, July 2026).

Defender Experts MDR includes it as a core part of the service with Defender Experts Hunting, extending your team with Microsoft experts who continuously look for advanced threats across your environment.

Get startedRead the IDC MarketScape: Worldwide MDR/MXDR for the Enterprise 2026 Vendor Assessment excerpt, and visit the Microsoft Defender Experts MDR webpage to see how expert-led, round-the-clock managed detection and response can extend your team, …

2 weeks, 3 days назад @ microsoft.com
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations.

Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems.

Recovery chat: Technical architectureThe most distinctive feature of the DeadLock ransomware is its recovery chat system.

‘DeadLock’ ransomware was detected‘DeadLock’ ransomware was preventedMicrosoft Defender for Cloud AppsThe following alert might indicate threat activity associated with this threat.

Indicators of compromiseIndicato…

2 weeks, 3 days назад @ microsoft.com
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

KuppingerCole’s Leadership Compass: Cloud Native Application Protection Platforms (CNAPP) reflects this shift.

The report describes how CNAPP is evolving from a consolidation of cloud security tools into the security foundation for AI-native enterprises, combining cloud security, AI security posture management, runtime protection, attack path analysis, cloud detection and response, and agentic AI operations into unified platforms.

This complexity exposes the limits of traditional, siloed tools, where cloud posture, workload protection, AI security, and the security operations center (SOC) each live in their own console.

Does it see AI models, agents, and pipelines as part of cloud risk, or …

3 weeks, 1 day назад @ microsoft.com
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

KuppingerCole’s Leadership Compass: Cloud Native Application Protection Platforms (CNAPP) reflects this shift.

The report describes how CNAPP is evolving from a consolidation of cloud security tools into the security foundation for AI-native enterprises, combining cloud security, AI security posture management, runtime protection, attack path analysis, cloud detection and response, and agentic AI operations into unified platforms.

This complexity exposes the limits of traditional, siloed tools, where cloud posture, workload protection, AI security, and the security operations center (SOC) each live in their own console.

Does it see AI models, agents, and pipelines as part of cloud risk, or …

3 weeks, 1 day назад @ microsoft.com
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Mitigation and protection guidanceOrganizations can apply the following recommendations to reduce exposure to this and similar macOS ClickFix campaigns:Educate users.

]com Domain ClickFix Webpage filecedarwallet[.]online.

Domain ClickFix Webpage filecopperbasket[.

]sbs Domain ClickFix Webpage filecrimsonsignal[.

]online Domain ClickFix Webpage filemarblegarden[.

3 weeks, 1 day назад @ microsoft.com
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Mitigation and protection guidanceOrganizations can apply the following recommendations to reduce exposure to this and similar macOS ClickFix campaigns:Educate users.

]com Domain ClickFix Webpage filecedarwallet[.]online.

Domain ClickFix Webpage filecopperbasket[.

]sbs Domain ClickFix Webpage filecrimsonsignal[.

]online Domain ClickFix Webpage filemarblegarden[.

3 weeks, 1 day назад @ microsoft.com
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
ChainDrop supply chain compromise: Anatomy of a self-propagating worm ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Uses GitHub credentials to inject files into Claude and Visual Studio Code configurations across repository branches for persistence.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, Microsoft Defender for Containers, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelli…

3 weeks, 1 day назад @ microsoft.com
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
ChainDrop supply chain compromise: Anatomy of a self-propagating worm ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Uses GitHub credentials to inject files into Claude and Visual Studio Code configurations across repository branches for persistence.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, Microsoft Defender for Containers, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelli…

3 weeks, 1 day назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 4 months назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

4 months назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

4 months, 2 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

4 months, 2 weeks назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

4 months, 3 weeks назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

4 months, 4 weeks назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

5 months назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

6 months назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

6 months назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

6 months, 1 week назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

7 months назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

8 months, 2 weeks назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

8 months, 3 weeks назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

8 months, 3 weeks назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

8 months, 3 weeks назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

9 months, 1 week назад @ security.googleblog.com