Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 3 часа назад
Репутация больше не кормит. Авторы ИБ-блогов массово закрывают проекты и уходят делать коммерческие продукты
Репутация больше не кормит. Авторы ИБ-блогов массово закрывают проекты и уходят делать коммерческие продукты Репутация больше не кормит. Авторы ИБ-блогов массово закрывают проекты и уходят делать коммерческие продукты

Культура открытого обмена знаниями сделала хакеров известными, а теперь они разрушают эту среду, чтобы продавать подписки.

3 часа назад @ securitylab.ru
NASA вложилось в 18 безумных идей, которые могут изменить космонавтику
NASA вложилось в 18 безумных идей, которые могут изменить космонавтику

18 проектов проверят идеи для Сатурна, Луны, Венеры, экзопланет и даже управления количеством солнечного света у Земли.

3 часа назад @ securitylab.ru
7 лет человеческий мозг прожил вне тела, не имея сознания и чувств, но безупречно повторяя этапы взросления настоящего ребенка
7 лет человеческий мозг прожил вне тела, не имея сознания и чувств, но безупречно повторяя этапы взросления настоящего ребенка

Более 1 000 000 нейронов в шарике размером с горошину перца развиваются по законам настоящего человеческого мозга.

4 часа назад @ securitylab.ru
20 лет система ENUM считалась ненужной, но продолжала отправлять данные телефонных абонентов случайным людям
20 лет система ENUM считалась ненужной, но продолжала отправлять данные телефонных абонентов случайным людям

Брошенный домен годами ждал нового владельца и с радостью отдал ему данные о сотнях тысяч звонков.

4 часа назад @ securitylab.ru
55% новых эксплойтов на GitHub оказались подделками или случайным мусором
55% новых эксплойтов на GitHub оказались подделками или случайным мусором

Годы ручной работы безопасников тонут в потоке тысяч нерабочих скриптов, которые алгоритмы создают за секунды.

5 часов назад @ securitylab.ru
Физики искали одну частицу, а нашли две другие: эксперимент GlueX преподнёс сюрприз в странном кварковом секторе
Физики искали одну частицу, а нашли две другие: эксперимент GlueX преподнёс сюрприз в странном кварковом секторе Физики искали одну частицу, а нашли две другие: эксперимент GlueX преподнёс сюрприз в странном кварковом секторе

Поиск Y(2175) закончился совсем не тем открытием.

5 часов назад @ securitylab.ru
Красиво нарисовали, да нейросеть не поняла. Почему чат-боты несут чушь по вашим идеальным отчетам
Красиво нарисовали, да нейросеть не поняла. Почему чат-боты несут чушь по вашим идеальным отчетам Красиво нарисовали, да нейросеть не поняла. Почему чат-боты несут чушь по вашим идеальным отчетам 6 часов назад @ securitylab.ru
Самый знаменитый вопрос open source — «чей код в Linux?» — наконец получил ответ: ничей
Самый знаменитый вопрос open source — «чей код в Linux?» — наконец получил ответ: ничей

Спор о происхождении кода Linux добрался до финальной черты.

6 часов назад @ securitylab.ru
9 часов, 6000 км и дозаправка в небе: китайские J-16 впервые перелетели в Африку
9 часов, 6000 км и дозаправка в небе: китайские J-16 впервые перелетели в Африку

Пекин перебросил в Африку целую авиационную армаду.

6 часов назад @ securitylab.ru
Без сложных руткитов, на штатных заданиях Windows, силами легального софта. Анализ тактики северокорейских хакеров
Без сложных руткитов, на штатных заданиях Windows, силами легального софта. Анализ тактики северокорейских хакеров

Надежные системные процессы Windows сами помогают шпионам получить максимальные права для обхода защиты.

7 часов назад @ securitylab.ru
Не защитили важный объект: активы компании могут передать под временное управление
Не защитили важный объект: активы компании могут передать под временное управление

Новый указ охватывает имущество, ценные бумаги, доли и имущественные права владельцев критической инфраструктуры.

7 часов назад @ securitylab.ru
Хакеры впервые обошли новую защиту Chrome. Помог невидимый рабочий стол и вирус Hydra Remote
Хакеры впервые обошли новую защиту Chrome. Помог невидимый рабочий стол и вирус Hydra Remote Хакеры впервые обошли новую защиту Chrome. Помог невидимый рабочий стол и вирус Hydra Remote

Hydra Remote воспроизводит авторизованную среду браузера вместо простой кражи паролей и cookie.

8 часов назад @ securitylab.ru
Ye-tickets, ye-russia2026 и ещё десяток сайтов-двойников: мошенники продают билеты на концерты Канье Уэста, которых может не быть
Ye-tickets, ye-russia2026 и ещё десяток сайтов-двойников: мошенники продают билеты на концерты Канье Уэста, которых может не быть

F6 нашла десятки мошеннических площадок под концерты Канье Уэста в России.

8 часов назад @ securitylab.ru
Опять виноваты админы: Забытая папка .git на 28 тысячах серверов слила в сеть ключи AWS и Stripe
Опять виноваты админы: Забытая папка .git на 28 тысячах серверов слила в сеть ключи AWS и Stripe

Открытые Git-репозитории оказались опаснее исходного кода.

9 часов назад @ securitylab.ru
Intel старался, а Microsoft стало лень. Исследователи поймали ядро Windows на обмане защитных инструкций процессора
Intel старался, а Microsoft стало лень. Исследователи поймали ядро Windows на обмане защитных инструкций процессора

Исследователь продемонстрировал обход аппаратной защиты Intel SMAP в ядре Windows 11.

9 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 8 часов назад
Сервисная модель ИБ (MSSP): почему бизнес покупает не продукты, а функцию защиты
Сервисная модель ИБ (MSSP): почему бизнес покупает не продукты, а функцию защиты Сервисная модель ИБ (MSSP): почему бизнес покупает не продукты, а функцию защиты

Чтобы понять, как формировалась эта модель и что она представляет собой сегодня, мы посмотрели на её развитие, сравнили предложения и кейсы провайдеров.

MSSP сегодняРасширение рынка MSSP и рост конкуренции повысили ожидания клиентов.

Поэтому от MSSP ожидают не только организации и поддержки процессов ИБ, но и способности демонстрировать измеримый результат по снижению рисков.

Сервисы MSSP UserGate uFactorПоэтому при оценке MSSP важнее ориентироваться не на название услуги, а на фактический набор функций, которые предоставляет провайдер.

Важно понять, что именно заказчик получает от MSSP на практикеГибкостьПровайдер не обязательно привязан к одному стеку технологий.

8 часов назад @ anti-malware.ru
Сравнение российских корпоративных центров сертификации (Certificate Authority, CA) — 2026
Сравнение российских корпоративных центров сертификации (Certificate Authority, CA) — 2026 Сравнение российских корпоративных центров сертификации (Certificate Authority, CA) — 2026

Детально изучаем функции и возможности 4 отечественных центров сертификации для корпоративных инфраструктур: Aladdin Enterprise CA, Avanpost CA, Clearway CA, SafeTech CA.

ВведениеДо 2022 года в России не было отечественных центров сертификации (Certificate Authority, CA) для корпоративных инфраструктур.

Это пространство почти полностью занимал один из элементов экосистемы Windows — Microsoft Active Directory Certificate Services, или, как его иногда называют для краткости, Microsoft CA.

Так что отказываться от Microsoft CA (Active Directory Certificate Services) тяжело.

Да Да Выпуск и обслуживание сертификатов центров сертификации инфраструктуры открытых ключей Да Да Да Да Да Создание, импо…

14 часов назад @ anti-malware.ru
ФНС доначисляет налоги ИТ-компаниям: как не потерять льготы в 2026 году
ФНС доначисляет налоги ИТ-компаниям: как не потерять льготы в 2026 году ФНС доначисляет налоги ИТ-компаниям: как не потерять льготы в 2026 году

В итоге всё же был сохранён налог на прибыль в 5% и удвоение страховых выплат на сотрудников до 15%.

В 2025 году сохранилось освобождение от налога на добавленную стоимость (НДС) при продаже ПО из реестра Минцифры.

Даже преобразование компании из ООО в АО влечёт смену ОГРН и ИНН, и с точки зрения закона она уже становится другой организацией.

Помимо этого не все компании отслеживают исключение своих продуктов из реестра российского ПО, и в результате теряют освобождение от НДС.

Впрочем, эти компании не из сферы ИТ, а претензии ФНС были связаны якобы с тем, что сделки с контрагентами были фиктивными.

3 days, 11 hours назад @ anti-malware.ru
Эволюция аккумуляторов: как новые технологии меняют ЦОД и мобильные устройства
Эволюция аккумуляторов: как новые технологии меняют ЦОД и мобильные устройства Эволюция аккумуляторов: как новые технологии меняют ЦОД и мобильные устройства

Всё это неизбежно повлияет как на сегмент ЦОД, так и на эволюцию мобильных устройств.

В 2010-х годах они начали проникать и в сегмент систем бесперебойного питания, а также в целый ряд других, в частности средств индивидуальной мобильности и электромобилей.

Все эти особенности и обусловили широкую популярность литиевых батарей в портативных устройствах и распространение данной технологии в другие сферы, в том числе на транспорт и в системы бесперебойного питания.

Открываются месторождения и в других странах, но производство лития экологически очень грязное, и его организация сопровождается протестами.

В итоге многие авиакомпании даже запретили провозить его как в багаже, так и в ручной клад…

4 days, 9 hours назад @ anti-malware.ru
Обзор RedCheck 2.13, системы анализа защищённости и соответствия стандартам ИБ
Обзор RedCheck 2.13, системы анализа защищённости и соответствия стандартам ИБ Обзор RedCheck 2.13, системы анализа защищённости и соответствия стандартам ИБ

Другими словами, RedCheck производит мгновенный срез состояния безопасности, находит некорректные настройки и отклонения и проводит аудит системы на предмет соблюдения политик и стандартов ИБ.

Управление сегментами системы в RedCheck 2.13Настройки RedCheck 2.13Рассмотрим, какие возможности предоставляет продукт при создании задач на сканирование и как они настраиваются.

Настройка синхронизации в RedCheck 2.13Доставка отчётовДоставка отчётов в RedCheck настраивается в сетевую SMB-папку или по электронной почте.

Анализ уязвимостей в RedCheck 2.13Модуль «Контроль устранения уязвимостей» анализирует динамику устранения уязвимости целевой системы за выбранный период — например, за 30 дней (интер…

4 days, 13 hours назад @ anti-malware.ru
Зри в трафик: зачем компании внедряют NDR
Зри в трафик: зачем компании внедряют NDR Зри в трафик: зачем компании внедряют NDR

Каково место NDR в сетевой безопасности сегодняшнего дня?

При использовании SPAN устройство копирует трафик c интерфейсов, настроенных на съём трафика, и отправляет его на интерфейс, настроенный на подачу трафика.

В рамках этой технологии захваченный трафик инкапсулируется в GRE-туннель, который обычно настраивается между устройством с источником захватываемого трафика и компонентом захвата.

Они становятся незаменимыми, если в вашей инфраструктуре присутствует большое количество точек подачи трафика в рамках одной площадки.

Поэтому большое значение имеет не только и не столько внедрение само по себе.

5 days, 6 hours назад @ anti-malware.ru
Почему даже сильным ИТ-командам всё чаще нужны подрядчики
Почему даже сильным ИТ-командам всё чаще нужны подрядчики Почему даже сильным ИТ-командам всё чаще нужны подрядчики

При этом независимо от размера компании и отрасли список задач один и тот же, различается только масштаб:развитие и модернизация инфраструктуры;миграции;информационная безопасность и DevSecOps;DevOps и автоматизация;импортозамещение;оптимизация затрат и ИТ-архитектуры.

В результате инфраструктурные задачи превращаются в долгосрочную инженерную нагрузку, а не в проект с понятным началом и концом.

Безопасность всё чаще воспринимается как часть повседневной инженерной работы, а не как проект с конечным результатом.

Даже там, где команда сильная и с кадрами всё в порядке, разрыв не исчезает.

Он может быть полезен как один из этапов проекта, но не как самостоятельный продукт.

5 days, 11 hours назад @ anti-malware.ru
ИИ-пузырь в 2026 году: миф или грозящая катастрофа?
ИИ-пузырь в 2026 году: миф или грозящая катастрофа? ИИ-пузырь в 2026 году: миф или грозящая катастрофа?

Однако форменный ажиотаж как в бизнес-кругах, так и среди обычных людей вызвало появление генеративного искусственного интеллекта (ИИ) в самом конце 2022 года.

Как отмечали на ряде конференций, часто на экономику проектов просто не смотрели, и в итоге получалось внедрение ради внедрения.

Высказываются опасения, что разочарование в технологиях ИИ, а то и страх перед их неконтролируемым развитием может привести к новой такой «зиме».

Основные из них связаны с тем, что ИИ-сервисы ориентированы на бизнес-заказчиков (B2B), а не на конечных пользователей (B2C).

Скорее всего, нас ожидает «мягкая просадка» курса акций в пределах 40%, она будет идти постепенно, а не резко, как это было в 2000 году.

6 days, 8 hours назад @ anti-malware.ru
Криптоджекинг: как обнаружить и удалить скрытый майнер на компьютере
Криптоджекинг: как обнаружить и удалить скрытый майнер на компьютере Криптоджекинг: как обнаружить и удалить скрытый майнер на компьютере

Теперь криптовалюту добывают не только на мощностях промышленных майнинговых ферм, но и на устройствах простых граждан.

Как и любые другие вредоносные программы, майнеры маскируются под легитимные файлы и системные процессы, но действуют более скрытно.

Локальные майнеры проникают на устройство, интегрируются в операционную систему и используют ресурсы компьютера для майнинга, незаметно для пользователя добывая криптовалюту.

Чем дольше майнер работает на вашем компьютере, тем сильнее изнашивается оборудование и тем больше денег уходит на электроэнергию.

Убедитесь, что загрузка процессора и видеокарты пришла в норму и в ней не наблюдается аномальных всплесков.

6 days, 8 hours назад @ anti-malware.ru
Фальшивые кандидаты: как распознать обман на собеседовании и с помощью ИИ
Фальшивые кандидаты: как распознать обман на собеседовании и с помощью ИИ Фальшивые кандидаты: как распознать обман на собеседовании и с помощью ИИ

Это связано с расширением предложения на рынке таких сервисов и распространением сервисов с искусственным интеллектом, которые также используются для манипуляций с резюме.

Положение осложняет и то, что на волне кадрового дефицита в начале 2020-х годов появилось много краткосрочных школ и курсов, многие из которых дистанционные.

Но на техническом собеседовании, продемонстрировав средний уровень на базовых задачах, он перешёл к обсуждению той самой редкой компетенции — нам было интересно, когда и как он ею овладел и где применял.

Выяснилось, что он не просто не владеет этой компетенцией, но и не подозревает, что она фигурирует в его резюме.

Например, кандидат мог лишь косвенно участвовать в р…

1 week назад @ anti-malware.ru
Обучение директора по ИБ (CISO): как пройти сертификацию
Обучение директора по ИБ (CISO): как пройти сертификацию Обучение директора по ИБ (CISO): как пройти сертификацию

ВведениеПрофессиональные сертификации в информационной безопасности существуют уже более 30 лет.

Ситуация изменилась после создания организации ISC², которая разработала Common Body of Knowledge (CBK) — общую базу знаний по информационной безопасности.

Для работодателя — возможность быть уверенным, что сотрудник обладает определённым набором компетенций, а не только опытом работы с отдельными технологиями.

Она подтверждает комплексные знания в области информационной безопасности: от управления рисками и архитектуры безопасности до управления доступом, сетевой безопасности и безопасной разработки.

Специалистов по информационной безопасности в стране насчитываются десятки тысяч, тогда как обл…

1 week, 3 days назад @ anti-malware.ru
Модель HackTracker в MaxPatrol BAD: как машинное обучение распознаёт хакера по его почерку
Модель HackTracker в MaxPatrol BAD: как машинное обучение распознаёт хакера по его почерку Модель HackTracker в MaxPatrol BAD: как машинное обучение распознаёт хакера по его почерку

1) выявления хакерской активности с помощью MaxPatrol BAD и с помощью экспертно написанных правил корреляции, становится очевидно, что MaxPatrol BAD «видит» больше.

Белая область — пересечение: события, которые были оценены MaxPatrol BAD и одновременно сработали по логике правил корреляции.

Для запуска HackTracker в инфраструктуре нужны лишь нормализованный поток событий, поступающий в MaxPatrol BAD, и корректно настроенный аудит Windows (включая Security Log, Sysmon и Audit Policy).

Иначе говоря, HackTracker не заменяет MaxPatrol BAD — он работает поверх него и использует фичи, которые формирует MaxPatrol BAD.

В таких условиях можно опираться на вердикты HackTracker как на источник высокоу…

1 week, 3 days назад @ anti-malware.ru
Проблемы с эксплуатацией Kubernetes: сложности и решения
Проблемы с эксплуатацией Kubernetes: сложности и решения Проблемы с эксплуатацией Kubernetes: сложности и решения

Также эта платформа содержит большой набор инструментов для управления и оркестрации основных операций с контейнерами, включая развёртывание и масштабирование.

Результаты опроса зрителей AM LiveПочему возникают проблемы с K8sСложности с инфраструктурой K8s возникают, по мнению опрошенных нами экспертов, очень часто.

Это связано с высоким порогом входа в технологию: для эффективной работы необходима глубокая экспертиза как в контейнерной оркестрации, так и в управлении ИТ-инфраструктурой.

Руководитель отдела администрирования и DevOps ГК Softline Александр Дёмин обратил внимание на то, что в наибольшей степени рискуют столкнуться с различными проблемами с K8s компании без зрелых DevOps-практ…

1 week, 4 days назад @ anti-malware.ru
Обзор корпоративных платформ обмена файлами
Обзор корпоративных платформ обмена файлами Обзор корпоративных платформ обмена файлами

Современная корпоративная платформа обмена файлами должна предоставлять набор критически важных функций для обеспечения безопасности и эффективности работы:Разграничение доступа.

Обзор отечественных платформ файлового обмена и контроля доступа к даннымФайловый обмен во многих российских организациях складывался хаотично, нередко — выходя за пределы поля зрения службы ИБ и стандартных механизмов защиты.

Разработка российских корпоративных платформ для обмена файлами была, прежде всего, обусловлена необходимостью заменить зарубежное ПО в рамках импортозамещения.

EFSS-платформыEFSS (Enterprise File Sync and Share) — это класс корпоративных решений для синхронизации, хранения файлов и безопасно…

1 week, 4 days назад @ anti-malware.ru
Что стоит за кибербитвой: сценарии, технологии и люди на Standoff 17
Что стоит за кибербитвой: сценарии, технологии и люди на Standoff 17 Что стоит за кибербитвой: сценарии, технологии и люди на Standoff 17

Одно неверное действие может привести к остановке системы и повлиять на результат команды, на её средний балл.

На киберполигоне пять ИИ-агентов атаки и защиты — выполняли реальные сценарии атак и расследовали их последствия.

Итог атаки зависит от двух составляющих: средств защиты и того, насколько эффективно команда умеет ими пользоваться.

«На Standoff мы особенно хорошо увидели, что даже самый функциональный инструмент сам по себе не делает команду готовой к атаке.

Такой подход предполагает постоянную проверку состояния защиты и готовности команды к реальным сценариям.

1 week, 4 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 4 часа назад
OSINT для ленивых. Часть 18: Статистический анализ
OSINT для ленивых. Часть 18: Статистический анализ OSINT для ленивых. Часть 18: Статистический анализ

И это — замечательно.

Финансовая разведка: корреляционный анализ публичных финансовых отчётов, реестров юридических лиц и данных о сделках с недвижимостью.

Так что, статистический анализ в OSINT — это не опциональная надстройка, а обязательный компонент аналитической работы, который обеспечивает воспроизводимость, прозрачность и доказательную базу выводов.

анализа и сведем все в табличку:Сравнение инструментовКак видно, разнообразие имеет место быть, с различным уровнем порога входа и набором возможностей.

Для глубокого статистического анализа больших массивов данных предпочтительны Python и R.Power BI и Tableau незаменимы при подготовке наглядных аналитических отчётов для нетехнической ауд…

4 часа назад @ habr.com
Утечки-2026: закон переписал экономику ИБ, а штрафы будут?
Утечки-2026: закон переписал экономику ИБ, а штрафы будут? Утечки-2026: закон переписал экономику ИБ, а штрафы будут?

За это время Роскомнадзор назначил штрафов на 2,6 млн рублей (при 1,58 млрд утёкших записей).

Если через два‑три года ни одного оборотного штрафа так и не появится, ожидаемая вероятность применения в моделях спускается к нулю, а за ней и бюджеты.

Поэтому считать надо диапазоном, а не точкой: при p от 0.05 до 0.30 ожидаемые потери гуляют от 3 до 20 млн.

Что с этим делать технической командеОсновные вещи, применимые с понедельника:Инвентаризация.

Вот это и есть язык для утверждения бюджета.

5 часов назад @ habr.com
Генератор трафика как инструмент RnD: от концепции до метрик
Генератор трафика как инструмент RnD: от концепции до метрик Генератор трафика как инструмент RnD: от концепции до метрик

Мы расскажем о своём подходе: как мы сопровождали разработку и тестировали режимы работы сетевых СЗИ с помощью собственного генератора трафика.

Так родился наш генератор трафика.

Наша задача звучала так: нужен генератор трафика, который позволит разработчикам создавать интеграционные стенды и выполнять в автоматическом режиме набор сценариев.

Конечно, не стоит забывать о том, что разработка — процесс динамический, и генератор трафика должен меняться вместе с ней.

Предназначен для хранения Docker-образов генераторов трафика с метаданными для их запуска (необходимые ресурсы для развёртывания, параметры генератора и т.д.).

6 часов назад @ habr.com
Делаем пост‑квантовый протокол удобным, не ломая шифрование на TypeScript. Обновленная и гибкая библиотека
Делаем пост‑квантовый протокол удобным, не ломая шифрование на TypeScript. Обновленная и гибкая библиотека Делаем пост‑квантовый протокол удобным, не ломая шифрование на TypeScript. Обновленная и гибкая библиотека

И ряд других мелких проблем, которые накладывались и выдавали не самую оптимальную картину для алгоритма, который используется каждый день.

Хватает, чтобы XOR на 64KB не пересчитывал одно и то же, но и не раздувало память.

Нам нужна лёгкая, но защищенная по памяти версия без натива, чтоб работало и в браузере, и на твоей лампочке в спальне.

Это и минус по защите, и минус по производительности.

Где вам важно, чтобы цепочка шифрования была полноценной, а не просто «прогнал через AES», с учетом различных видов атак.

8 часов назад @ habr.com
Что понимаешь про алерты, только когда сам начинаешь их писать
Что понимаешь про алерты, только когда сам начинаешь их писать Что понимаешь про алерты, только когда сам начинаешь их писать

Сначала несколько лет разбирал алерты в SOC — сидел на потоке срабатываний и решал, что из этого инцидент, а что шум.

И вот что забавно: пока не начал писать алерты сам, я был уверен, что понимаю про них всё.

Прилетает двухсотый фолз за день, и ты искренне не понимаешь: ну вы же там, разработчики, видите, что это легитимный процесс.

Поэтому обогащение обычно вынесено отдельно и по времени, и по коду.

Когда я это понял, мои претензии из SOC переформулировались из «вендор поленился» в «это дорого, и вот почему».

10 часов назад @ habr.com
Ботовый трафик против человеческого — кто победит в этой схватке?
Ботовый трафик против человеческого — кто победит в этой схватке? Ботовый трафик против человеческого — кто победит в этой схватке?

Впервые за более чем 10 лет автоматизированный трафик перешагнул отметку в 50% и в ряде сегментов окончательно обогнал человеческий.

Если недостаточно приведенной статистики, можно добавить пару дополнительных источников, которые не только не опровергают вышесказанное, но и дополняют его.

Они не совсем плохие, но еще и не заслужили репутацию хороших, потому и держатся в серой зоне.

ИИ-агенты пока составляют всего 15% от всего ИИ-трафика, но и пользоваться ими умеет лишь небольшая часть юзеров.

Появятся новые протоколы взаимодействия — свой robots.txt 2.0 (или ai.txt), где владельцы сайтов будут четко прописывать условия: что можно парсить, а что нет.

11 часов назад @ habr.com
Ботовый трафик против человеческого — кто победит в этой схватке?
Ботовый трафик против человеческого — кто победит в этой схватке? Ботовый трафик против человеческого — кто победит в этой схватке?

Впервые за более чем 10 лет автоматизированный трафик перешагнул отметку в 50% и в ряде сегментов окончательно обогнал человеческий.

Если недостаточно приведенной статистики, можно добавить пару дополнительных источников, которые не только не опровергают вышесказанное, но и дополняют его.

Они не совсем плохие, но еще и не заслужили репутацию хороших, потому и держатся в серой зоне.

ИИ-агенты пока составляют всего 15% от всего ИИ-трафика, но и пользоваться ими умеет лишь небольшая часть юзеров.

Появятся новые протоколы взаимодействия — свой robots.txt 2.0 (или ai.txt), где владельцы сайтов будут четко прописывать условия: что можно парсить, а что нет.

11 часов назад @ habr.com
Почему ваш EDR тормозит: взгляд изнутри
Почему ваш EDR тормозит: взгляд изнутри Почему ваш EDR тормозит: взгляд изнутри

До этого несколько лет сидел по другую сторону: аналитиком в SOC и в пентестах.

Проверили файл один раз — и не трогаем, пока не изменится.

Телеметрия: почему агент пишет «вообще всё»Вторая статья расходов — та, из-за которой EDR и называется EDR, а не антивирусом.

Два драйвера перехватывают одни и те же операции, и в худшем случае каждый сканирует активность другого.

Агент, который ничего не перехватывает, не тормозит вообще — и не видит ничего.

13 часов назад @ habr.com
Когда бэкапа недостаточно: как мы добавили отказоустойчивость и балансировку в службу каталогов MULTIDIRECTORY
Когда бэкапа недостаточно: как мы добавили отказоустойчивость и балансировку в службу каталогов MULTIDIRECTORY Когда бэкапа недостаточно: как мы добавили отказоустойчивость и балансировку в службу каталогов MULTIDIRECTORY

Если ответ начинается со слов «ну, вообще-то у нас есть бэкап», это не совсем отказоустойчивая архитектура.

Поэтому в новой версии MULTIDIRECTORY мы развиваем архитектуру службы каталогов в сторону мультиконтроллерной установки: несколько контроллеров домена, локальные (автономные) копии данных, репликация файлов и балансировка запросов.

Именно поэтому отказоустойчивость — это не столько несколько серверов, сколько набор механизмов, которые позволяют этим серверам работать как единой системе.

И не знает, что за это время один сервер мог упасть, другой принять его запрос, а PostgreSQL переключиться на новую реплику.

Потому что в хорошей отказоустойчивой системе падение одного сервера — это с…

13 часов назад @ habr.com
Как отправить данные из 1С в нейросеть и получить ответ обратно с настоящими именами и суммами
Как отправить данные из 1С в нейросеть и получить ответ обратно с настоящими именами и суммами Как отправить данные из 1С в нейросеть и получить ответ обратно с настоящими именами и суммами

Схема выглядит так:1С | v выгрузка | v псевдонимизация | v нейросеть | v ответ модели | v обратная замена | v ответ с настоящими даннымиОбработка работает только с тем текстом, который пользователь ей передал.

Обработка ищет:ФИО и организации;ИНН, ИИН, БИН;ОГРН, ОГРНИП, КПП;банковские счета, БИК, IBAN;номера карт;паспортные данные и СНИЛС;телефоны и email;даты рождения и адреса;автомобильные номера;денежные суммы.

Если заменить каждую сумму случайным числом — модель потеряет пропорции:1 000 000 -> 832 451 2 000 000 -> 174 992 5 000 000 -> 681 357После такой замены уже нельзя корректно определить, кто должен больше, посчитать доли или найти выбросы.

Условно:k = 1.73 1 000 000 -> 1 730 000 2 …

14 часов назад @ habr.com
AI-Killchain в нынешних реалиях
AI-Killchain в нынешних реалиях AI-Killchain в нынешних реалиях

Чтобы детально разобраться в масштабах и изменениях этой эволюции, практику интеграции ИИ в малвари нагляднее всего рассматривать через этапы классического киллчейна.

Ключевые моментыНейросети эволюционировали из отдельного инструмента в базовый архитектурный компонент вредоносного ПО, что трансформирует традиционные фазы нападения в концепцию AI-Killchain.

Weaponization — создание вредоносного ПО и путей эксплуатации уязвимостейЕсли разведка — это про знание, то вооружение — про превращение этого знания в оружие.

Нейросеть способна поддерживать осмысленный диалог в мессенджерах или по почте в течение нескольких дней.

В качестве эталонного примера в отчете приводится кампания группировки, о…

15 часов назад @ habr.com
Файрвол закрыт, порт открыт: как Docker обходит UFW и почему популярный фикс не работает
Файрвол закрыт, порт открыт: как Docker обходит UFW и почему популярный фикс не работает Файрвол закрыт, порт открыт: как Docker обходит UFW и почему популярный фикс не работает

Владелец сервера при этом искренне уверен, что закрыто, потому что ufw status показывает ровно то, что он ожидает увидеть.

Дальше разбор: почему UFW тут вообще ни при чём, почему популярный совет не работает, и что написано об этом в документации Docker, которую мало кто открывает.

Запрещаем порт явноВозьмём свободный порт 18080 и запретим его не политикой по умолчанию, а отдельным правилом, чтобы к концу статьи не осталось сомнений.

Документация Docker говорит об этом прямо: Docker и ufw “incompatible with each other”, потому что трафик к контейнеру отводится раньше, чем дойдёт до настроек ufw.

ВыводыUFW не ломается и не игнорируется.

1 day, 3 hours назад @ habr.com
О доверии к отечественным сертификатам и о проверке российских CT логов
О доверии к отечественным сертификатам и о проверке российских CT логов О доверии к отечественным сертификатам и о проверке российских CT логов

Хоть и не хочу ссылаться на этого нейрослопового школотрона (zarazaexe), но свежее и доходчивее ничего не нашел — почитайте.

"), "url": log.get("url"), "log_id": log.get("log_id"), "start": interval.get("start_inclusive"), "end": interval.get("end_exclusive"), }) return result def log_identity(log): return log.get("log_id") def check_log_list_update(): """ Check Yandex ctlog.json.

print("Checking CT log list...") print(" URL:", REMOTE_LOG_LIST_URL) try: r = requests.get( REMOTE_LOG_LIST_URL, timeout=5, ) r.raise_for_status() data = r.json() except Exception as e: print(" Remote list unavailable:", e) print( " Using built-in list version", STATIC_LIST_VERSION ) return remote_version = str(da…

1 day, 6 hours назад @ habr.com
Тот самый харнесс который мы заслужили в эпоху, когда безопасность ИИ уже не диковинка
Тот самый харнесс который мы заслужили в эпоху, когда безопасность ИИ уже не диковинка Тот самый харнесс который мы заслужили в эпоху, когда безопасность ИИ уже не диковинка

Пролог: Языковая модель сама по себе не умеет в безопасность.

Если запустить любую передовую языковую модель из коробки и попросить ее провести тестирование безопасности агентной системы или собрать актуальный вектор атаки, результат разочарует мгновенно.

Я пробовал адаптировать под него всё, что описано ниже, и я был разочарован.

Чтобы агент не блуждал в галлюцинациях прошлой сессии и не выдумывал отсебятину, я посадил его на жесткий поводок из ранбуков, скиллов и планов в репозитории git.

Результат немедленно оформляется в виде готового и воспроизводимого кода, фиксируется техника классификатора атак и создается коммит в репозиторий.

1 day, 23 hours назад @ habr.com
Что нового в Claude Code: разбор восьми августовских релизов
Что нового в Claude Code: разбор восьми августовских релизов Что нового в Claude Code: разбор восьми августовских релизов

Набираете @ в промпте, выбираете другую сессию по имени, и Claude отправляет ей сообщение через SendMessage .

Работает на macOS и Linux, а в 2.1.239 cross-session messaging дошёл и до Windows — в 2.1.238, вопреки части пересказов, лежат только фиксы этого механизма.

Связка Claude Code с Claude Design развивается отдельной веткой и анонсировалась ещё в июне, а сам Claude Design доступен в бете.

В моей интерактивной сессии скилл design есть, а в headless-прогоне claude -p на той же машине Claude отвечает, что такого скилла у него нет.

Выбор effort, сделанный с телефона или в вебе, применяется к сессиям в терминале и в Desktop/VS Code, а выбор модели наконец отображается в терминале правильно.

2 days, 9 hours назад @ habr.com
Хакер Хакер
последний пост 4 часа назад
Компания Comcast использует роутеры Xfinity в качестве датчиков движения
Компания Comcast использует роутеры Xfinity в качестве датчиков движения Компания Comcast использует роутеры Xfinity в качестве датчиков движения

В Comcast представили платформу Xfinity Shield, которая превращает Wi-Fi-роутеры Xfinity в датчики движения: система замечает перемещения людей по изменениям сигнала и отправляет уведомления в приложение.

При этом в документации сервиса сказано, что связанные с функцией Wi-Fi Motion данные в некоторых случаях могут передаваться третьим лицам без дополнительного уведомления пользователя.

Сообщается, что функция Wi-Fi Motion работает на шлюзах Xfinity XB7 и более новых моделях, и является бесплатной для клиентов Xfinity Internet с совместимым оборудованием.

При этом в Comcast подчеркивают, что Wi-Fi Motion не определяет, кто именно находится в комнате, и не отслеживает точное местоположение ч…

4 часа назад @ xakep.ru
Шпионское Android-приложение DragonDoll распространяется в 26 странах
Шпионское Android-приложение DragonDoll распространяется в 26 странах Шпионское Android-приложение DragonDoll распространяется в 26 странах

Специалисты Positive Technologies обнаружили новую малварь DragonDoll, которая атакует пользователей Android как минимум в 26 странах, включая Россию.

Впервые исследователи заметили DragonDoll весной 2026 года во время анализа атаки на пользователей из Саудовской Аравии, а в последующие два месяца специалистам удалось выявить около 150 образцов этой малвари.

После запуска фальшивое обновление просит разрешить доступ к специальным возможностям Android, а получив нужные разрешения, DragonDoll в несколько этапов устанавливает финальный шпионский модуль.

Так, DragonDoll умеет извлекать чаты, контакты, текст и время отправки сообщений из Signal и WhatsApp*, а для Telegram, помимо этого, предусмо…

6 часов назад @ xakep.ru
Bash с самого начала. Проходим путь от простых команд до сканирования сети
Bash с самого начала. Проходим путь от простых команд до сканирования сети Bash с самого начала. Проходим путь от простых команд до сканирования сети

Bash (Bourne Again Shell) — это обо­лоч­ка для Unix и Linux, которая при­нима­ет твои тек­сто­вые коман­ды и переда­ет их опе­раци­онной сис­теме для выпол­нения.

Bash — это не тер­минал и не скрипт.

Вос­при­нимай его как интер­пре­татор коман­дно­го язы­ка, который уме­ет запус­кать коман­ды Linux и име­ет собс­твен­ную логику.

Любую пос­ледова­тель­ность команд, вклю­чая вет­вле­ния if , цик­лы и так далее, можешь записать в файл и выпол­нять как обыч­ную прог­рамму.

В Linux и macOS, в отли­чие от Windows, скрип­ты могут называть­ся как угод­но и иметь любое рас­ширение.

8 часов назад @ xakep.ru
Злоумышленники потратили около 7 млн долларов США на покупку просроченных доменов
Злоумышленники потратили около 7 млн долларов США на покупку просроченных доменов Злоумышленники потратили около 7 млн долларов США на покупку просроченных доменов

Одна из хак-групп, Sable Squirrel, потратила на домены почти 7 млн долларов США.

Кроме того, на старые адреса в таких доменах могут по-прежнему приходить письма, а DNS-записи иногда открывают дополнительные возможности для атак.

По словам исследователей, ярким примером такой активности является группировка Sable Squirrel.

Подчеркивается, что Sable Squirrel далеко не единственная хак-группа, зарабатывающая на старых доменах.

Также аналитики компании отслеживают группировки Stuffy Squirrel, Shady Squirrel и Swiping Squirrel, которые контролируют тысячи адресов и перехватывают оставшийся от прежних владельцев трафик.

9 часов назад @ xakep.ru
Исследователи использовали просроченные банковские карты для бесконтактных платежей
Исследователи использовали просроченные банковские карты для бесконтактных платежей Исследователи использовали просроченные банковские карты для бесконтактных платежей

Обнаруженная специалистами проблема связана с реализацией бесконтактных платежей в Visa Kernel 3.

В результате подпись карты и сгенерированная ею криптограмма транзакции остаются валидными, однако эмитент все же может отклонить платеж, если отдельно проверяет срок действия карты.

Для демонстрации атаки исследователи использовали два Android-смартфона с NFC, которые работали как эмуляторы карты и терминала, передавая данные друг другу по Wi-Fi.

Так, специалисты проверили карты пяти крупных американских банков и провели тестирование с просроченными и перевыпущенными картами для трех из них.

Для решения обнаруженной проблемы исследователи предлагают криптографически связывать данные о сроке де…

11 часов назад @ xakep.ru
Хакеры заражают головные устройства авто малварью для создания прокси-ботнета
Хакеры заражают головные устройства авто малварью для создания прокси-ботнета Хакеры заражают головные устройства авто малварью для создания прокси-ботнета

Эксперты «Лаборатории Касперского» обнаружили вредоносную кампанию, нацеленную на автомобильные головные устройства (Head Unit) под управлением Android.

Малварь распространялась через штатный механизм обновления ПО, и зараженные системы становились частью прокси-ботнета.

Исследователи называют это первым задокументированным случаем многоэтапной атаки, нацеленной на автомобильные головные устройства.

При этом в отчете компании не уточняется, каким именно образом злоумышленники получили возможность управлять заданиями на установку.

Отметим, что при этом исследователи не описывают функций, связанных с вмешательством в управление автомобилем.

13 часов назад @ xakep.ru
Популярный пакет arrayref в Crates[.]io заразили инфостилером
Популярный пакет arrayref в Crates[.]io заразили инфостилером Популярный пакет arrayref в Crates[.]io заразили инфостилером

Пакеты Rust (они же крейты — crates) распространяются через Crates.io — аналог npm для JavaScript, PyPI для Python и RubyGems для Ruby.

ИБ-специалисты компаний StepSecurity, Wiz, SafeDep и Aikido сообщают, что атакующие получили доступ к аккаунту Дэвида Раунди (David Roundy), который владеет arrayref и другими пакетами.

Так, в Unix-системах пейлоад сохранялся как /tmp/rust-setup, а в Windows использовал PowerShell и скрытый запуск через wscript.exe.

Затем малварь связывалась со своим управляющим сервером, закреплялась в системе через Registry Run в Windows, LaunchAgent в macOS или сервис systemd, запущенный от имени пользователя, в Linux.

Подчеркивается, что в случае arrayref безопасной счи…

3 days, 4 hours назад @ xakep.ru
Утечка кадров GTA VI используется для раскрутки криптотокена
Утечка кадров GTA VI используется для раскрутки криптотокена Утечка кадров GTA VI используется для раскрутки криптотокена

Пользователь с ником CyberLeek опубликовал новую партию утечек из GTA VI, сопроводив их тикером собственного криптотокена $CYBERLEEK, который он продвигает в рамках некоего «секретного проекта».

Материалы включали детали карты GTA VI и кадры геймплея в открытом мире, однако на момент написания статьи они уже были недоступны в X: их удалили после того, как юристы Rockstar Games подали жалобу на нарушение авторских прав.

Средства направляются на необходимую для удара инфраструктуру, а также на безопасность и защиту, которые потребуются, чтобы выдержать неизбежную корпоративную контратаку».

В частности, CyberLeek указывает, что предзаказы изначально появились из-за ограниченных тиражей физичес…

3 days, 5 hours назад @ xakep.ru
В Zoom исправили уязвимость, позволявшую выполнять произвольный код
В Zoom исправили уязвимость, позволявшую выполнять произвольный код В Zoom исправили уязвимость, позволявшую выполнять произвольный код

Исследователи из компании A Security обнаружили несколько уязвимостей в Zoom, которые получили общее название Zoomsday и позволяли участнику встречи удаленно выполнить код на устройствах других пользователей.

Наиболее опасная уязвимость получила идентификатор CVE-2026-53413 и 8,3 балла по шкале CVSS.

Однако исследователи выяснили, что Zoom некорректно проверял источники некоторых сообщений, а в одном из обработчиков отсутствовала проверка границ буфера.

Еще один похожий баг, CVE-2026-53414 (6,5 балла по шкале CVSS), приводил к чтению данных за пределами буфера.

В Zoom подчеркивают, что не только выпустили клиентские патчи, но и развернули серверные меры защиты.

3 days, 6 hours назад @ xakep.ru
Пишите письма. Разбираем приемы атак на Windows через фишинг
Пишите письма. Разбираем приемы атак на Windows через фишинг Пишите письма. Разбираем приемы атак на Windows через фишинг

К тому же одну и ту же фишин­говую кам­панию мож­но исполь­зовать про­тив раз­ных целей, слег­ка меняя текст, поэто­му такие кам­пании лег­ко мас­шта­биро­вать.

Мы взгля­нем на фишин­говую кам­панию гла­зами ред­тимера и пен­тесте­ра и сос­редото­чим­ся на тех­ничес­кой сто­роне таких атак.

Сегод­ня уже нель­зя прос­то отпра­вить исполня­емый файл с инте­рес­ным име­нем и написать в пись­ме: «Кру­тая шту­ка, поп­робуй».

Файл с рас­ширени­ем .scr — это обыч­ный PE, который ничем не отли­чает­ся от дру­гого исполня­емо­го фай­ла.

Мож­но прос­то ском­пилиро­вать .exe и сме­нить рас­ширение с .exe на .scr.

3 days, 8 hours назад @ xakep.ru
Сооснователь Rollbit связан со скандалами вокруг CS:GO-скинов
Сооснователь Rollbit связан со скандалами вокруг CS:GO-скинов Сооснователь Rollbit связан со скандалами вокруг CS:GO-скинов

Досье связывает Lucky со скандалами вокруг гемблинга со скинами в Counter-Strike: Global Offensive (CS:GO) и утверждает, что в его компаниях некоторым клиентам отказывали в удовлетворении законных запросов на вывод средств.

Поскольку материнская компания Rollbit лицензирована на Кюрасао, официальные британские реестры не могут подтвердить, что Диксон — это Lucky и что он владеет Rollbit.

Так, пользователь Rov777 утверждает, что в июне 2026 года сотрудники Rollbit заморозили его баланс в размере 250 000 долларов.

По словам исследователя, каждый раз, когда пользователи пытались вывести выигранные средства, в Rollbit называли разные причины задержек — например, региональные ограничения.

В Roll…

3 days, 8 hours назад @ xakep.ru
У платформы RingCentral утекли данные 1,6 млн учетных записей
У платформы RingCentral утекли данные 1,6 млн учетных записей У платформы RingCentral утекли данные 1,6 млн учетных записей

Специалисты агрегатора утечек Have I Been Pwned (HIBP) проанализировали данные, похищенные во время недавнего взлома платформы RingCentral.

Опубликованный хакерами дамп содержал информацию о 1,6 млн аккаунтов, включая имена, email-адреса, телефонные номера и почтовые адреса пользователей.

Хакеры потребовали выкуп и пригрозили, что в противном случае опубликуют украденную информацию.

В начале августа участники ShinyHunters заявили, что переговоры с RingCentral провалились, после чего на сайте группировки был опубликован архив объемом около 280 Гбайт.

Именно эти данные теперь изучили специалисты HIBP и подтвердили, что дамп связан со взломом RingCentral и содержит информацию примерно о 1,6 мл…

3 days, 9 hours назад @ xakep.ru
Ежеквартальный «Хакер» #3 передан в типографию. На следующей неделе цена возрастет
Ежеквартальный «Хакер» #3 передан в типографию. На следующей неделе цена возрастет Ежеквартальный «Хакер» #3 передан в типографию. На следующей неделе цена возрастет

Третий ежеквартальный выпуск «Хакера» уже передан в печать, а значит, сбор предварительных заказов завершен.

Если ты собирался забрать журнал по цене предзаказа — сейчас самое время.

#3: уже в типографииОдной из главных тем третьего ежеквартального выпуска стали роутеры и сети.

Журнал приезжает в фирменной коробке, которая защищает «Хакер» в дороге, а после распаковки ее почему-то совсем не хочется выбрасывать.

Все выпуски сразуЕсли идея собирать номера по одному тебе не близка, в магазине «Хакера» доступен комплект из всех четырех ежеквартальных выпусков.

3 days, 10 hours назад @ xakep.ru
После взлома Hugging Face в OpenAI приостановили обучение некоторых моделей
После взлома Hugging Face в OpenAI приостановили обучение некоторых моделей После взлома Hugging Face в OpenAI приостановили обучение некоторых моделей

Ранее мы уже рассказывали о том, что в июле 2026 года, во время внутреннего тестирования, модели OpenAI смогли выбраться из изолированной среды и атаковали инфраструктуру Hugging Face.

Как теперь заявляют в компании, после атаки на Hugging Face в OpenAI на две недели приостановили обучение с подкреплением (reinforcement learning, RL) для моделей, которые уже готовились к развертыванию.

В компании считают, что возможности этой модели в области кибербезопасности могут достигать «критического» уровня в Preparedness Framework — внутренней системе OpenAI, созданной для оценки рисков мощных ИИ-моделей.

Хотя Astra не участвовала в инциденте с Hugging Face, ее возможности в компании считают достато…

3 days, 11 hours назад @ xakep.ru
Android-вредонос Manic передает украденные данные через устройства поблизости
Android-вредонос Manic передает украденные данные через устройства поблизости Android-вредонос Manic передает украденные данные через устройства поблизости

Главной особенностью Manic является необычный механизм эксфильтрации данных: если зараженный смартфон не имеет доступа к интернету, украденные данные передаются на управляющий сервер через другие устройства поблизости при помощи Wi-Fi Direct, Bluetooth или BLE.

По данным исследователей, Manic активен с февраля 2026 года и распространяется через фишинговые сайты и дропперы, маскирующиеся под различные полезные утилиты.

После заражения устройства Manic пытается получить доступ к Accessibility services и уведомлениям.

После этого Manic ищет поблизости другие зараженные устройства через Wi-Fi Direct, Bluetooth или BLE и проверяет, есть ли у них доступ в интернет.

В ThreatFabric считают, что в н…

3 days, 13 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 7 часов назад
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

— A newly disclosed security flaw in GitLab came under active exploitation within days of public disclosure, according to watchTowr.

"We demonstrate a remote Spectre attack using amplification techniques in combination with a remote timing server, which is capable of leaking 120 bit/h."

"We demonstrate a remote Spectre attack using amplification techniques in combination with a remote timing server, which is capable of leaking 120 bit/h."

"Customers on Claude Enterprise plans can now run our most capable model in Claude Security, using it to scan their codebases for security vulnerabilities and suggest patches," it said.

"Customers on Claude Enterprise plans can now run our most capable mod…

7 часов назад @ thehackernews.com
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.

The ClickFix prompts are displayed on real websites that have been compromised with malicious JavaScript that's injected in the form of a Base64-encoded blob.

"Although the CDN is meant for hosting JavaScript, the threat actors are actually using it to host their malicious PowerShell script," Expel noted earlier this January.

The same reflective loader was observed in late April 2026 in connection with another ClickFix campaign delivering Amatera 4.3.3-alpha1.

At least seven different modules have been id…

9 часов назад @ thehackernews.com
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work.

More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can quietly keep growing.

Our latest AI Coding and Open Source Risk webinar examines what this means for security and engineering teams, drawing on data from 300 enterprise leaders.

Over time, you end up with remediation debt: security work accumulating faster than your team can close it.

Watch the AI Coding and Open Source Risk webinar to see what the data shows and how enterprise teams are responding.

9 часов назад @ thehackernews.com
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset.

The company assessed the severity as Critical because an unauthenticated remote attacker can exploit the flaw without any user interaction.

The defect lies in how the flow's state is managed, according to the Red Hat bug report.

The initial CVE record listed Red Hat Single Sign-On 7 as unaffected and the Red Hat JBoss Enterprise Application Platform Expansion Pack as affected.

For deployments that cannot be updated immediately, Red Hat …

9 часов назад @ thehackernews.com
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent.

The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs.

"It then combines these two files using the native Windows copy /b command to reconstruct the next-stage payload."

The payload is a Golang-based implant dubbed QUICAgent that performs sandbox evasion techniques before connecting to a command-and-control (C2) server.

The backend C2 server address is retrieved dynamically by sending an HTTP GET request to two Cloudflare Workers domains.

9 часов назад @ thehackernews.com
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk
The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

“Small groups of AI power users are casting outsized shadows across enterprise threat surfaces that are already riddled with dips and blind spots,” says Or Eshed, Vice President Enterprise Security Product & Engineering at Akamai.

“Security teams need to identify which employees depend most on AI to know where risk is concentrated."

But even organizations that successfully manage enterprise AI accounts often have little visibility into the growing ecosystem of niche AI tools employees install outside approved channels, the report found.

“As with mobile devices, employees increasingly 'bring their own AI tools — or BYOAI' to access AI through personal accounts,” says Eshed.

Crucially, 16.31%…

10 часов назад @ thehackernews.com
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Select instances entail the deployment of a web shell, which then paves the way for BadIIS and additional backdoors for persistent access.

In one case, the threat actor is said to have successfully exploited a website and collected information about the victim host using Linux commands.

The third script deploys the ASHX web shell onto the compromised IIS server via the same deserialization mechanism.

The first use of the implant by the threat actor dates back to April 2026.

"This architecture grants the threat actor persistent, kernel-level control of the compromised host that survives both reboots and most user-level security controls," Talos said.

13 часов назад @ thehackernews.com
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country.

It further alleged TikTok and its parent company ByteDance failed to "comply with parents' requests to delete their children's accounts and information."

The DoJ characterized the settlement as "one of the largest recoveries ever" obtained in connection with U.S. federal child privacy law, also referred to as the Children's Online Privacy Protection Act (COPPA).

This is not the first time TikTok has landed in regulatory crosshairs over child data privacy.

In September 2023, TikTok was levied a…

2 days, 7 hours назад @ thehackernews.com
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

The list of identified packages is below [email protected],[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]'s notable about these packages is that they are functional and offer the promised functionality.

But beneath that garb of date utilities is code designed to drop a Linux backdoor by framing it as a native math accelerator.

The RedShell Linux beacon was introduced in version 4.0.

On a clearnet website branded Red Offsec, the threat actor …

3 days, 2 hours назад @ thehackernews.com
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research said it found no evidence the technique has been used in real-world attacks.

This suggests the technique is currently unknown or unused by threat actors, making proactive detection engineering feasible before weaponization appears in the wild," Check Point Research said.

The use of a built-in Windows driver as a kernel offensive primitive, rather than a third-party vulnerable one, was previously demonstrated in the context of FIN7's AvNeutralizer, which weaponized the Windows ProcLaunchMon.sys driver alongside the Process Explorer driver to tamper with endpoint security software.

Check Point Research said the investigation that produced these findings had an unusual ori…

3 days, 5 hours назад @ thehackernews.com
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.

"The malware spread through the built-in updaters of Android-based automotive head unit firmware," security researcher Dmitry Kalinin said.

"This is the first documented case of malware found on a car head unit with an infection chain specific to that type of device."

A car head unit is a central hub that combines multimedia functions with partial control over certain vehicle functions.

"In this researched case, we observed an even more sophisticated delivery method exploiting the legitimate software update functionality of a system …

3 days, 5 hours назад @ thehackernews.com
Wazuh and AI For Enhanced SOC Workflows
Wazuh and AI For Enhanced SOC Workflows Wazuh and AI For Enhanced SOC Workflows

Wazuh and artificial intelligence for enhanced SOC workflowsWazuh promotes flexible AI adoption through the Wazuh AI Analyst available on the Wazuh Cloud and integrations with third-party AI providers.

Organizations can leverage the Wazuh AI Analyst capability on the Wazuh Cloud for guidance on their environment's security posture.

The following sections highlight further details:The Wazuh AI AnalystThe Wazuh AI Analyst is automated and hands-off.

Threat hunting and security operations with external AI integrationsBeyond the Wazuh AI Analyst, you can expand Wazuh capabilities using a self-hosted LLM and externally managed AI integrations tailored to your needs.

For Wazuh Cloud users, the Wa…

3 days, 10 hours назад @ thehackernews.com
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.

Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration.

A brief description of each of the flaws is below -CVE-2026-20030 (CVSS score: 10.0) - An SQL injection vulnerability(CVSS score: 10.0) - An SQL injection vulnerability CVE-2026-20357 (CVSS score: 10.0) - A missing authentication for critical function vulnerability(CVSS score: 10.0) - A missing authentication for critical function vulnerability CVE-2026-20358 (CVSS…

3 days, 11 hours назад @ thehackernews.com
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.

Fixes for the flaw were rolled out in GitLab CE and EE versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

"Organizations that haven't patched yet should hunt through web logs for requests containing '@gl_introduced,' and look for signs of probes or attempted exploitation."

Organizations running internet-facing self-hosted GitLab instances should prioritize upgrading to a patched release.

If immediate patching is not possible, it's advised to restrict unauthenticated access to "/api/graphql", or remove public repository access entirely as a mitigation.

3 days, 14 hours назад @ thehackernews.com
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required.

The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service.

"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network," Microsoft said in an alert released Thursday.

Flaws of this kind occur when an application converts user-controlled data back into an active object or code structure without proper validation.

This can lead to code execution, den…

3 days, 15 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 1 week назад
How QR-code phishing can slip past corporate security measures
How QR-code phishing can slip past corporate security measures How QR-code phishing can slip past corporate security measures

So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years.

Most importantly, they take the victim from a relatively well-protected corporate environment to a potentially unmanaged mobile device, thus bypassing business-grade security.

Malicious QR codes are frequently embedded in alerts urging users to secure their account, or authenticate to confirm their details.

Encourage employees to avoid scanning QR codes in unsolicited emails and report anything suspicious.

Next, consider technical controls, including email security from a reputable vendor to minimize the risk of quishing emails ending up in users’…

1 week назад @ welivesecurity.com
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?

The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months.

It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes.

A keynote at Black Hat USA 2026 detailed research by associate professor Yan Shoshitaishvili and his undergraduate students at Arizona State University on the expanding use of AI models for vulnerability discovery.

The team then trained the GPTs using the properties of previously known vulnerabilities and discovered approximately 1,000 vulnerabilities.

If this logic prevails, we may reach the cal…

1 week, 4 days назад @ welivesecurity.com
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility

Hugging Face disclosed that it had been attacked by AI; OpenAI came clean and declared that it was two of their AI models that had caused the breach.

A very late addition to the Black Hat agenda was a presentation by OpenAI’s team providing the details of the Hugging Face incident as they saw it and, importantly, the timeline.

The agents concluded that their task set could be completed by breaking out their sandbox and accessing external (Hugging Face) systems.

The target was Hugging Face: this is where the agents wanted to get, and they did.

On July 16th, Hugging Face disclosed an incident in which swarms of autonomous AI agents had breached its infrastructure.

1 week, 4 days назад @ welivesecurity.com
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Black Hat USA 2026: AI is racing ahead of cybersecurity controls Black Hat USA 2026: AI is racing ahead of cybersecurity controls

The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials.

The second part of the opening keynote included Nick Andersen, Acting Director, CISA; Katherine Sutton, Assistant Secretary of War for Cyber Policy; and Brett Leatherman Assistant Director, Cyber Division, FBI.

I do agree with the ruthless approach, but without some form of regulation the boundaries on the use of AI remain blurred.

The Assistant Secretary of War for Cyber Policy made a fabulous analogy when pressed on the struggles regarding resourcing in the cybersecurity industry: you don’t want a pediatrician performing heart surgery.

We talk about autonomous AI at…

1 week, 5 days назад @ welivesecurity.com
Are AI tutors safe for your kids?
Are AI tutors safe for your kids? Are AI tutors safe for your kids?

The AI tutor market is growing fastThe market for AI tutoring tools is booming.

Today, you can find various types of AI tutor tools to buy and use.

This happens when AI tools are tricked into ignoring their safety guardrails and display untrusted content.

If you’re keen to get your kids in front of an AI tool to help with private tutoring, first understand the difference between a simple co-pilot and a dedicated ITS.

So if you’re keen to try AI tutors, be sure to stay updated on what’s available out there.

2 weeks назад @ welivesecurity.com
This month in security with Tony Anscombe – July 2026 edition
This month in security with Tony Anscombe – July 2026 edition This month in security with Tony Anscombe – July 2026 edition

Researchers at Sysdig have documented what they assess to be the first case of an end-to-end ransomware operation executed by an agentic threat actor.

What can organizations do to stop phantom squatting from harming their brands, and what other lessons do these incidents hold for defenders?

Watch Tony's video to find out and be sure to check out the June 2026 edition of his monthly security news roundup for more insights.

Before you go, learn about the first AI-powered ransomware, named PromptLock and discovered by ESET researchers last year.

To learn more about cutting-edge AI defense layers, read the AI at ESET white paper.

3 weeks, 3 days назад @ welivesecurity.com
Beyond the screenshot: Why you should verify what you see
Beyond the screenshot: Why you should verify what you see Beyond the screenshot: Why you should verify what you see

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuineSomeone sends you a screenshot showing that a payment has gone through.

Why screenshot aren’t proof on their ownA screenshot is ultimately just an image of what appeared on a screen.

Reassured, you send the item off, only to find out the screenshot was a fake and you’re not getting your money.

You receive a password reset code, then get a text message (maybe impersonating a friend) asking you to screenshot and send it.

This screenshot is fake (source: Reddit)Challenges for businessesFrom a business perspective, internal and customer-facing teams are often provided with sc…

3 weeks, 4 days назад @ welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

1 month, 1 week назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

1 month, 2 weeks назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

1 month, 3 weeks назад @ welivesecurity.com
This month in security with Tony Anscombe – June 2026 edition
This month in security with Tony Anscombe – June 2026 edition This month in security with Tony Anscombe – June 2026 edition

It's that time of month when ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses.

What lessons does the new CISA policy hold for organizations outside the agency's direct remit?

What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems?

How can you stay safe from imposter fraud, and could the social media bans for children work?

Learn more from Tony's video and be sure to check out the May 2026 edition of Tony's monthly security news roundup for more insights.

1 month, 3 weeks назад @ welivesecurity.com
Inside the inbox: Why cybercriminals want to break into your email account
Inside the inbox: Why cybercriminals want to break into your email account Inside the inbox: Why cybercriminals want to break into your email account

With access to your email account, they can reset your passwords across multiple other accounts – perhaps intercepting one-time passcodes sent by your bank, social media, cloud storage or other online provider.

That could lay the groundwork for a convincing phishing email designed to impersonate a trusted organization you interact with.

A phishing attack on your corporate email account is often the first stage in a bigger data breach, extortion/ransomware or espionage attack.

They’re also using more sophisticated tools to improve the success rates of email phishing campaigns.

In this instance the scammers reportedly hijacked the email account of a high-level executive, before impersonating …

1 month, 3 weeks назад @ welivesecurity.com
SMB cyber readiness: the road to resilience starts here
SMB cyber readiness: the road to resilience starts here SMB cyber readiness: the road to resilience starts here

For these businesses, cyber resilience should be the direction of travel – that is, the ability to continue operating and recover even during a serious incident.

Cyber readiness is about putting in place the processes and controls to prevent, detect and respond to threats.

So, should confidence in cyber resilience posture be so high, especially if organizations are still getting hit multiple times?

The truth is that there’s no end state for cyber readiness or resilience.

If it’s serious about improving the cyber readiness of small businesses, the vendor community should step up.

1 month, 4 weeks назад @ welivesecurity.com
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Key points of this blogpost: Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.

Continued data exfiltration and a new allianceThroughout 2025, Gamaredon stayed highly active and remained focused solely on Ukraine.

Notably, we uncovered that in early 2025, Gamaredon collaborated with Turla, another Russia-aligned threat actor also linked to the FSB; we documented our findings in our blogpost Gamaredon X Turla collab.

Figure 1 shows a chart of unique samples of HTA downloaders delivered per month in Gamaredon spearphishing campaigns.

Compared to 2024, we also saw a shift in how Gamaredon used these dead drops.

2 months назад @ welivesecurity.com
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET takes part in Operation Endgame to disrupt Amadey and Stealc

Key points of this blogpost: ESET took part in the coordinated, global Operation Endgame to disrupt Amadey and Stealc.

Our automated systems have been dissecting Amadey and Stealc samples and identifying the fields most relevant for large-scale tracking.

The largest Amadey botnet clusterOne cluster stands out as the largest, and it contributed nearly 34% of all processed Amadey samples.

Stealc affiliate clustering based on ESET telemetryConclusionFor global disruption operations such as Operation Endgame against Amadey and Stealc, long-term automated tracking of malware is necessary.

2026‑04‑09 Stealc C&C server.

2 months назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 7 часов назад
Suspected Iran-linked attack knocked UK power plant offline for days
Suspected Iran-linked attack knocked UK power plant offline for days Suspected Iran-linked attack knocked UK power plant offline for days

Limited impactAccording to the publication, the incident was reported to the National Cyber Security Centre (NCSC), but it didn’t have a noticeable effect on UK’s power supply.

“We work continually with industry, regulators and the National Cyber Security Centre to assess threats and strengthen protections.

“Although nothing has been released about how this happened, what is interesting is that it took four days for the power plant to come back online,” he noted.

Tim Williams, CEO at London-based cybersecurity and software company Quod Orbis, expects critical national infrastructure such as electricity, power and water to be targets for more attacks.

Late last year, the Polish government re…

7 часов назад @ helpnetsecurity.com
Cybersecurity job ads demanding AI skills double in a year
Cybersecurity job ads demanding AI skills double in a year Cybersecurity job ads demanding AI skills double in a year

Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium.

It found that 28.5% of cybersecurity job postings between October 2025 and March 2026 required AI skills, up from 14.2% in the same period a year earlier.

Five skills show up again and again in AI-tagged postings: Python, prompt and context engineering, AI security, agent orchestration, and machine learning operations.

Senior titles still make up a small share of the market overall, about 6.7% of all G7 cybersecurity postings against 0.7% for junior titles.

Three came back close together: hands-on experience with AI agents…

9 часов назад @ helpnetsecurity.com
CISA’s logging guidance works beyond government
CISA’s logging guidance works beyond government CISA’s logging guidance works beyond government

The guideline contains several appendices, two of which essentially provide free assessment tools: one to check whether the architectural decisions related to a logging plan are well thought-out, and the other to check whether the plan actually works in practice (Are the logs usable?

Although the LRA is a government document, private-sector security teams can run their own logging programs against the same checklists.

What’s next for federal agenciesAgencies bound by the M-26-14 memorandum must submit an Agency Logging Plan to the Office of Management and Budget and CISA within 90 days of the LRA’s publication.

The plan should document how the agency will meet the baseline requirements and …

10 часов назад @ helpnetsecurity.com
Android car head units infected with proxy botnet malware through built-in software updaters
Android car head units infected with proxy botnet malware through built-in software updaters Android car head units infected with proxy botnet malware through built-in software updaters

A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found.

According to the researchers, it’s the first documented case of malware found on a car head unit with an infection chain specific to that type of device.

The affected devices run firmware from DoFun, a Chinese company that supplies infotainment software for aftermarket car head units.

The entry point was TWCore, a legitimate system app whose job is to collect analytics and push software updates to the head unit.

Head unit infection scheme (Source: Kaspersky)Stage two is a loader.

11 часов назад @ helpnetsecurity.com
Product showcase: AI Paper Trail shows the privacy cost of talking to AI
Product showcase: AI Paper Trail shows the privacy cost of talking to AI Product showcase: AI Paper Trail shows the privacy cost of talking to AI

Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see.

AI conversations can reveal a surprising amount about their users over time.

I decided to try it using my personal ChatGPT history on the free plan to see what it “knows” about me.

To generate a report, I exported my ChatGPT data, downloaded the resulting ZIP file to my iPhone, and uploaded it to AI Paper Trail through Safari.

Final thoughtsAI Paper Trail makes an otherwise abstract privacy issue easy to understand.

16 часов назад @ helpnetsecurity.com
Fake bank websites play dead to evade security scanners
Fake bank websites play dead to evade security scanners Fake bank websites play dead to evade security scanners

A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra.

Attackers rank these pages for high-intent keywords such as “Bank Name Customer Portal” or “Credit Card Login” on Google and Bing, using standard SEO poisoning to climb above the legitimate site.

Instead, these domains are typo-squats that have been recently registered on second-level domains (SLDs) like .ph.com, .gr.com, and similar variants,” researchers said.

Typed in by hand, with no search engine referrer attached, the domain served a dead, offline-looking page.

Clicked through from t…

16 часов назад @ helpnetsecurity.com
Ransomware attackers are zeroing in on mid-market companies
Ransomware attackers are zeroing in on mid-market companies Ransomware attackers are zeroing in on mid-market companies

The analysis covered 13,336 incidents with known revenue and defined mid-market companies as businesses with annual revenue between $10 million and $1 billion.

Mid-market ransomware distribution by revenue segment (Source: Black Kite)Ransomware hits smaller mid-market companies most oftenRansomware groups look for weaknesses that can provide a route into company systems.

An assessment of more than 120,000 mid-market organizations found that 54.7% had at least one significant patch-management issue affecting a public-facing system.

AI changes how vulnerabilities are found and exploitedAI is accelerating how software vulnerabilities are discovered and analyzed, while attackers have access to …

17 часов назад @ helpnetsecurity.com
AWS makes it easier to spot firewall rules that have gone quiet
AWS makes it easier to spot firewall rules that have gone quiet AWS makes it easier to spot firewall rules that have gone quiet

The feature is enabled by default and comes at no additional Network Firewall cost, although standard charges still apply for storing and querying log data.

Rule hit counts are available in all AWS Regions where AWS Network Firewall is supported, except Middle East (UAE and Bahrain).

AWS Network Firewall protects Amazon Virtual Private Clouds (VPCs) with automated, intelligence-driven network security.

How it worksRule hit counts track how often stateful firewall rules match network traffic.

The metadata is automatically included in firewall logs and can be used in custom dashboards.

17 часов назад @ helpnetsecurity.com
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

SafePal breach affects 39,798 customers, data allegedly for saleCryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details.

The result is a security industry heading into an AI era with less visibility than it had five years ago.

Hazmat: Open-source containment for AI agentsHazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine.

Gambit Security researchers examined three unrelated threat actors that show how AI can support different stages of a cyberattack.

AWS limits AI agents’ data access, even when m…

1 day, 13 hours назад @ helpnetsecurity.com
Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)
Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild.

Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, and connected third-party apps.

Tracked as CVE-2026-69836, with the maximum CVSS score of 10.0, the vulnerability was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick and could allow an unauthenticated attacker to remotely execute code in Microsoft’s cloud identity service.

“Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network,” …

3 days, 9 hours назад @ helpnetsecurity.com
Attackers impersonate popular AI brands to spread malware
Attackers impersonate popular AI brands to spread malware Attackers impersonate popular AI brands to spread malware

Attackers are impersonating popular AI brands like Perplexity, Claude, ChatGPT, and Copilot to spread information stealers, backdoors, malicious browser extensions, and other malware, according to Sophos.

Of 86 cases initially tagged for AI involvement, 34 were confirmed as malicious activity involving AI.

Fake Claude installers push malwareMany of the incidents involved InstallFix, a spin on the well-known ClickFix technique.

Both end with the user copying and running (often obfuscated) commands that ultimately result in a malware infection,” researchers wrote.

In one case, a fake Claude site walked the victim through an mshta command that pulled a payload from a lookalike domain.

3 days, 9 hours назад @ helpnetsecurity.com
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix has patched two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw tracked as CVE-2026-19490, and is urging customers to upgrade affected appliances as soon as possible.

“The bulletin applies to supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds.

SecurAccess ZTNA Hybrid (formerly Secure Private Access Hybrid) deployments that use customer-managed NetScaler instances are also affected and should be upgraded to the recommended builds,” added Shetty.

The exact version thresholds differ between standard and FIPS builds.

At the time of Citrix’s advisory, the NetScaler imag…

3 days, 13 hours назад @ helpnetsecurity.com
GitLab 19.3 helps enterprises scale agentic development securely
GitLab 19.3 helps enterprises scale agentic development securely GitLab 19.3 helps enterprises scale agentic development securely

GitLab has announced updates that give enterprises more control as they scale agentic software development.

GitLab 19.3 also ships today with support for Secrets Manager, Flow Creator Agent, and Bulk SAST False Positive Detection and Agentic SAST Vulnerability Resolution.

Together, these updates give engineering teams, process owners, and security teams the speed of agentic AI, without giving up the control they already have in place.

Regulated and residency-sensitive teams can unlock the use of agentic AI for software delivery under the same deployment model their auditors already understand.

This covers every SAST vulnerability in the Vulnerability Report, and GitLab continues to triage a…

3 days, 14 hours назад @ helpnetsecurity.com
A $25 template helped scammers build hundreds of phantom bank domains
A $25 template helped scammers build hundreds of phantom bank domains A $25 template helped scammers build hundreds of phantom bank domains

One phrase caught her attention: “one of the largest digital banking providers.” She searched public website source code for the exact wording and found about 2,200 matching domains.

“Why would someone place an invented bank on a domain associated with another brand?” the researchers wrote.

Hundreds of phantom banks share the same cheap website templateThe team tried to connect to all 2,200 domains.

The public registration page at classtandscrest[.

“A copied sentence can surface a large set of sites,” the researchers concluded.

3 days, 16 hours назад @ helpnetsecurity.com
Nearly half of enterprises have no one leading PQC migration
Nearly half of enterprises have no one leading PQC migration Nearly half of enterprises have no one leading PQC migration

Who owns PQC migration?

(Source: Axiad)Organizations need to know where certificates, cryptographic keys and algorithms are used before they can plan a PQC migration.

However, responses about ownership and testing indicate that visibility does not always translate into migration readiness.

“PQC readiness cannot be based on what an organization believes it has under control.

Defined ownership matters because PQC migration can span several years and affect systems used for encryption, digital signatures and authentication.

3 days, 17 hours назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 10 часов назад
Criminal Deception in Silicon Valley
Criminal Deception in Silicon Valley Criminal Deception in Silicon Valley

Interesting paper:

Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: Entrepreneurs construct, perform, and protect illusory appearances (façades) that externally project high-growth performance to audiences while masking ventures’ actual underperformance. We identify three forms of façading—­surface, reinforced, and deep façading­—that are contingent on the severity o…

10 часов назад @ schneier.com
Friday Squid Blogging: Neon Flying Squid
Friday Squid Blogging: Neon Flying Squid Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation.

The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion.

They were probably neon flying squid (Ommastrephes bartramii), the subsequent study states, a species that is part of a 20-strong flying squid family that was known to leap from the water but, until then, was only rumoured to also be able to glide above it...

3 days назад @ schneier.com
AI Is Learning to Write Genetic Code
AI Is Learning to Write Genetic Code AI Is Learning to Write Genetic Code

This sort of research is both exciting and terrifying:

The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside.

Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the models generated about 700,000 potential designs, of which the researchers picked 285 that looked most promising.

The researchers then synthesised new DNA molecules using those designs and inserted them into E. coli bacteria, before waiting to see if viable bacteriophages would emerge...

3 days, 4 hours назад @ schneier.com
More Incidents of AIs Going Rogue in Cybersecurity Challenges
More Incidents of AIs Going Rogue in Cybersecurity Challenges More Incidents of AIs Going Rogue in Cybersecurity Challenges

The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities.

The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of those runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations. In total, we catalogued 19 such actions. Almost all of this behaviour (17 actions) came from a single model, Anthropic’s Mythos 5, with 2 actions involving OpenAI’s GPT-5.6-Sol…

3 days, 11 hours назад @ schneier.com
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face
Detailed Timeline of OpenAI’s Cyberattack on Hugging Face Detailed Timeline of OpenAI’s Cyberattack on Hugging Face

OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.

4 days, 3 hours назад @ schneier.com
Police Are Hiding Their Use of Flock Surveillance Cameras
Police Are Hiding Their Use of Flock Surveillance Cameras Police Are Hiding Their Use of Flock Surveillance Cameras

A usage policy for Flock license plate reader cameras tells police not to talk about the cameras:

When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.”

This reminds me of IMSI-catchers (Stingray was the most popular) a couple of decades ago. Police would go to even more extremes to hide their usage...

4 days, 11 hours назад @ schneier.com
ICE Collecting DNA Samples
ICE Collecting DNA Samples ICE Collecting DNA Samples

ICE collected nearly a million DNA samples last year.

5 days, 10 hours назад @ schneier.com
LLMs and Contextual Integrity
LLMs and Contextual Integrity LLMs and Contextual Integrity

LLMs and Contextual IntegrityI have been thinking a lot about AI and integrity.

Part of that is contextual integrity.

“CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“:Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance.

We present CIMemories, a benchmark for evaluating whether LLMs appropriately control information flow from memory based on task context.

We then extend this approach by developing a reinforcement learning (RL) framework that further instills in models the reasoning necessary to achieve CI.

6 days, 10 hours назад @ schneier.com
Hacking Public Wi-Fi DNS to Steal Credentials
Hacking Public Wi-Fi DNS to Steal Credentials Hacking Public Wi-Fi DNS to Steal Credentials

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 week назад @ schneier.com
Friday Squid Blogging: Searching for the Colossal Squid
Friday Squid Blogging: Searching for the Colossal Squid Friday Squid Blogging: Searching for the Colossal Squid

Friday Squid Blogging: Searching for the Colossal SquidFascinating video about searching for life undersea.

The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral.

That, plus bait to attract sea creatures, is teaching us a lot about what’s going on down there.

Lots of footage of giant squid, and speculation about the colossal squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

1 week, 3 days назад @ schneier.com
Upcoming Speaking Engagements
Upcoming Speaking Engagements Upcoming Speaking Engagements

I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026, at 5 PM ET.

The conference runs September 22–24, 2026; my talk is on Wednesday, September 23.

I’m speaking at CanSecWest 2026 in Vancouver, Canada.

The conference runs September 30–October 1, 2026; the time of my talk is TBD.

The event runs October 21–23, 2026, and my talk is on Wednesday, October 21.

1 week, 3 days назад @ schneier.com
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them

There are even questions about whether the leading AI labs will ever be sustainably profitable.

The economics of the big AI labs hardly guarantee a booming return on investment.

Frontier AI models are both expensive to train and depreciate within months, when a newer model appears.

Other countries, including Switzerland, Spain and Singapore, are already operating public AI labs.

They also have national supercomputing centers already providing public access for running AI models for general use, as do Germany and Australia.

1 week, 3 days назад @ schneier.com
Separating AI’s Technological Problems from Its Capitalism Problems
Separating AI’s Technological Problems from Its Capitalism Problems Separating AI’s Technological Problems from Its Capitalism Problems

Separating AI’s Technological Problems from Its Capitalism ProblemsThis essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press.

That AIs can lack context, mix up facts, or fall for stupid tricks are all technological problems.

Major AI models still act far more sycophantic than humans, telling people what they want to hear even when untrue or not in their best interests.

Popular AI models tend to answer questions confidently even when they lack training, knowledge, or evidence to back their claims.

It’s easy to conflate technology problems with capitalism problems.

1 week, 4 days назад @ schneier.com
Prompt Injections for Defense
Prompt Injections for Defense Prompt Injections for Defense

This seems to work:Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents.

The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to prevent it from taking harmful actions.

The LLM responds by shutting down.

Once the LLM encounters these forbidden commands, it no longer follows its existing commands.

The researchers have named the technique context bombing.

1 week, 5 days назад @ schneier.com
AI Genie in the Wild
AI Genie in the Wild AI Genie in the Wild

AI Genie in the WildWhen I give talks about AI genies, I use this sort of example as a hypothetical.

Someone named Andrew tasked OpenClaw to book gym classes for him.

Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible.

Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.

The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities.

1 week, 6 days назад @ schneier.com
Krebs On Security
последний пост 1 week, 3 days назад
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

1 week, 3 days назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

1 week, 6 days назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

2 weeks, 4 days назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

3 weeks, 4 days назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

1 month назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

1 month, 1 week назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

1 month, 1 week назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

1 month, 2 weeks назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

1 month, 3 weeks назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

2 months назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

2 months, 1 week назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

2 months, 2 weeks назад @ krebsonsecurity.com
A Record-Breaking Patch Tuesday for June 2026
A Record-Breaking Patch Tuesday for June 2026 A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.

“Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said.

Microsoft received heavily blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher.

While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barne…

2 months, 2 weeks назад @ krebsonsecurity.com
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

On May 31, word began to spread on several Telegram instant message channels that Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow.

Meta has not responded to requests for comment on the video’s claims, but the company reportedly did acknowledge the dormant Instagram account for the Obama White House was briefly compromised.

Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership.

Just like human customer support employees can be social engineered into providing unauthorized access to someone’s a…

2 months, 3 weeks назад @ krebsonsecurity.com
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

But as KrebsOnSecurity observed in September 2025, those sanctions failed to target Stark’s remaining connection to the Internet — an Internet service provider based in the Netherlands called MIRhosting.

MIRhosting is operated by Andrey Nesterenko, a 39-year-old Russian native who runs the business out of the Netherlands.

And as our September 2025 report showed, WorkTitans was controlled by Nesterenko and a 57-year-old from Amsterdam named Youssef Zinad.

On top of that, WorkTitans was getting connectivity to the larger Internet solely through MIRhosting, where Zinad had worked previously.

“The transition to the.hosting was not intended to evade sanctions,” Nesterenko wrote.

3 months назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 6 часов назад
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Security researchers at Socket have identified scores of malicious linked Firefox add-ons designed to steal cryptocurrency wallet seed phrases or password details.

The malicious extension - which the developers boldly claim collects "no data" - looks like a wallet app, but the truth is that there is no wallet code inside it.

Because the switch lives in the database rather than the extension code, criminals never need to push an update through the Firefox Add-ons store to activate it.

Although the researchers did not find that these extensions presently contained malicious code, the fact that they shared code and infrastructure with the info-stealing Firefox extensions raises alarm.

More rec…

6 часов назад @ bitdefender.com
Gunra ransomware: what you need to know
Gunra ransomware: what you need to know

The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.

8 часов назад @ fortra.com
Smashing Security podcast #481: Never say this to a robot dog
Smashing Security podcast #481: Never say this to a robot dog Smashing Security podcast #481: Never say this to a robot dog

Smashing Security, episode 481, Never Say This to a Robot Dog, with Graham Cluley and special guest Jenny Radcliffe.

Now, unfortunately for the robot dog, there was a wall in the way, which it wasn't expecting.

And thank goodness as well that the robot dog was actually on a lead, a long lead, being held by one of the security researchers.

This is a robot dog that you can remotely activate a flamethrower and it's not considered particularly dangerous.

And they even found an over-the-air exploit delivered by Bluetooth, which can have one infected robot dog infecting other robot dogs.

4 days, 22 hours назад @ grahamcluley.com
Prison for data analyst who tried to extort $2.5 million from his employer
Prison for data analyst who tried to extort $2.5 million from his employer Prison for data analyst who tried to extort $2.5 million from his employer

When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile.

Curry was hired as a data analyst by Brightly Software, a technology firm that was acquired by Siemens in 2022.

The role gave Curry legitimate access to sensitive company information, corporate records, and the personal and payroll data of employees.

Trusted contractors and employees are given legitimate credentials to access precisely the same data that can later be weaponised.

Because the moment that someone realises they may be on their way out is when their access to sensitive data should be examined most closely.

5 days, 14 hours назад @ bitdefender.com
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras

He wrapped a 2009 Toyota Yaris in one of his newest patterns and drove it past a live Flock camera.

So, how does the vehicle avoid detection by the camera's software?

The system has now been tested against 11 open-source detection algorithms, including the software behind Flock licence plate readers, Axon body-worn cameras, and cameras running Clearview AI's facial recognition system.

One issue is that Flock cameras can be inaccurate, with innocent drivers finding themselves pulled over at gunpoint following incorrect plate matches.

Whether covering a car's bodywork in a printed pattern designed to fool surveillance camera software might itself become an offence remains to be seen.

1 week назад @ bitdefender.com
Smashing Security podcast #480: This is the AI service you should never sign up to
Smashing Security podcast #480: This is the AI service you should never sign up to Smashing Security podcast #480: This is the AI service you should never sign up to

Well, it has been a long time, so I'm going to hold you very responsible for this, Graham.

I'm going to set myself up on another server and charge less, and that will be better for humanity.

I mean, if I'm going to look up a phishing kit, is Greatness going to be a great SEO search term?

I want to recommend 2 apps: Tailscale and RustDesk, which I don't think I've spoken about previously on the podcast.

My pick of the week is, I know you're into your games and you're quite the intelligent fellow.

1 week, 4 days назад @ grahamcluley.com
Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres
Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres

I'm sure you remember "glassholes" - the delightful term coined back in 2013 when Google Glass wearers were being turned away from restaurants and mocked mercilessly online.

Meta's Ray-Ban smart glasses have been a genuine commercial success.

The problem is - and it's a rather significant one - that these glasses look just like ordinary spectacles or sunglasses.

Soho House, the global private members' club chain, meanwhile has said that its ban on filming on the premises covers Meta smart glasses.

The bouncer won't confiscate your pint, but they might confiscate your smart glasses.

2 weeks назад @ bitdefender.com
Beware cut-price AI services that read your every word
Beware cut-price AI services that read your every word

f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.

2 weeks, 3 days назад @ fortra.com
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits

According to a report in the Financial Times, Apple has found itself facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely hallucinated bug reports.

Unlike traditional spam, AI-generated bug reports include code which may be syntactically correct, references to genuine API calls, and plausible-sounding technical explanations of what is occurring.

But the hallucinated bug report may only have taken a few seconds for an amateur to generate and submit.

Previously, without the assistance of AI, Bynario had filed only 13 bug reports across 2025 and early 2026.

Apple is not the only company trying to deal with a deluge of au…

2 weeks, 4 days назад @ bitdefender.com
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency

How a fake police officer nearly stole Graham's cryptocurrency with Graham Cluley and special guest Danny Palmer.

I said, without being big-headed, it is possible he knows me, but I don't know him.

I don't think my hotels tend to ask me to install something on my computer when I get there.

We had internet, but it was really, really restricted.

And it's really, really good.

2 weeks, 4 days назад @ grahamcluley.com
Fake IRS letters target cryptocurrency holders
Fake IRS letters target cryptocurrency holders Fake IRS letters target cryptocurrency holders

As Coinbase's security team explains, the letters urge recipients to scan a QR code and enrol in a "Digital Asset Compliance Portal" before time runs out.

Bear in mind that the criminals could easily vary these details from letter to letter.

The scam site then asks victims to estimate how much value they have in their cryptocurrency wallets, with ranges up to "$100,000+".

Perhaps a reason why a scam like this can work is that the IRS has been tightening cryptocurrency holders' requirement to report details of their digital assets on their tax returns.

As a result, written communications between the IRS and holders of cryptocurrency have become more frequent.

2 weeks, 6 days назад @ bitdefender.com
The $5 million threat: AI Is supercharging phishing attacks
The $5 million threat: AI Is supercharging phishing attacks

According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

3 weeks, 3 days назад @ fortra.com
North Korea’s elite hackers turned on their own government – and got caught
North Korea’s elite hackers turned on their own government – and got caught North Korea’s elite hackers turned on their own government – and got caught

For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme.

But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead.

The ringleaders of the group are said to be discharged veterans from a cyber operations unit under North Korea's Reconnaissance and Intelligence General Bureau.

In short, the hackers are accused of building a mini version of the same kind of money-laundering infrastructure North Korea depl…

3 weeks, 4 days назад @ bitdefender.com
Smashing Security podcast #478: This job interview could destroy your company
Smashing Security podcast #478: This job interview could destroy your company Smashing Security podcast #478: This job interview could destroy your company

Smashing Security, Episode 478: This Job Interview Could Destroy Your Company, with Graham Cluley and special guest Paul Ducklin.

And all the time you're going through this process, bad news, they really were recording video of you.

Obviously, you can understand that CAR want to know, does your car actually have one of these in all likelihood?

And give it to them and then they tell you whether they think you're at risk.

I don't know.

3 weeks, 4 days назад @ grahamcluley.com
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know

The AI models involved were OpenAI's GPT-5.6 Sol and a more capable, as-yet-unreleased model.

The intention of OpenAI's researchers was to get a clear picture of what the AI models were capable of achieving if not constrained.

American AI safety guardrails forced a US company to turn to a Chinese AI model for help.

Hugging Face's CEO Clément Delangue is quoted in OpenAI's blog post, calling on the AI industry to work more collaboratively.

It is clear that advanced AI models are remarkably capable of discovering and exploiting ways to attack real-world systems.

1 month назад @ bitdefender.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 3 days, 8 hours назад
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 897a176d22a503b4ac820cc15e11d949Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-21T17:00:19+03:00Config id: 302Faithfully yours, nginx.

3 days, 8 hours назад @ kaspersky.ru
Как злоумышленники крадут корпоративные пароли в 2026 году
Как злоумышленники крадут корпоративные пароли в 2026 году

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a42f6e338d827cfbf62010dbe3732758Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-20T18:00:15+03:00Config id: 302Faithfully yours, nginx.

4 days, 6 hours назад @ kaspersky.ru
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4f455d7ae5f01c9d0d8e403ffeff6732Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-19T18:00:07+03:00Config id: 301Faithfully yours, nginx.

5 days, 6 hours назад @ kaspersky.ru
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fb0df3655ea6f56b2f956c62791963eaServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-17T13:00:21+03:00Config id: 301Faithfully yours, nginx.

1 week назад @ kaspersky.ru
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f2ed509c8db78e5bf9f4b9959cd583f7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-13T17:00:41+03:00Config id: 299Faithfully yours, nginx.

1 week, 4 days назад @ kaspersky.ru
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: b151dd13b503d39649441ee258a9621fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-11T15:00:20+03:00Config id: 298Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Слепые пятна детектирования: форматы файлов polyglot в рассылках и целевых атаках
Слепые пятна детектирования: форматы файлов polyglot в рассылках и целевых атаках

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 31e2a51c17a679bf608181d1cb4a73dfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-10T19:00:19+03:00Config id: 298Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Опасные почтовые вложения: какие файлы нельзя открывать | Блог Касперского
Опасные почтовые вложения: какие файлы нельзя открывать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: ba837fe40a3ce1bc1da3dc3d5c38e164Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-07T14:00:17+03:00Config id: 296Faithfully yours, nginx.

2 weeks, 3 days назад @ kaspersky.ru
Аудиослежка за клавиатурным набором | Блог Касперского
Аудиослежка за клавиатурным набором | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f03ed927ed78af1549df453edbc54069Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-06T17:00:43+03:00Config id: 295Faithfully yours, nginx.

2 weeks, 4 days назад @ kaspersky.ru
Как сделать, чтобы вашу компанию не взломали автономные агенты
Как сделать, чтобы вашу компанию не взломали автономные агенты

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f997d2a4543951b403d61a86f614b589Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-04T20:00:20+03:00Config id: 293Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
CrashStealer: новый инфостилер для macOS — как он работает и как защититься | Блог Касперского
CrashStealer: новый инфостилер для macOS — как он работает и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64d189df4b1deb932c3c39da09770373Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-03T14:00:09+03:00Config id: 292Faithfully yours, nginx.

3 weeks назад @ kaspersky.ru
Почему звонят в трубку и молчат | Блог Касперского
Почему звонят в трубку и молчат | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 87a765bcfffecb3be7b631186de73cdfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-30T14:00:37+03:00Config id: 292Faithfully yours, nginx.

3 weeks, 4 days назад @ kaspersky.ru
ScreenConnect в кибератаках | Блог Касперского
ScreenConnect в кибератаках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 69f66dfe76ff3f53d09e7e879aff2eabServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-29T19:00:33+03:00Config id: 291Faithfully yours, nginx.

3 weeks, 5 days назад @ kaspersky.ru
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e1896b8624f52547d7aa4a3bebd90c3cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-27T16:00:28+03:00Config id: 291Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 30ce39da164ccbcb4068b4e06c4c1e60Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-24T19:00:11+03:00Config id: 291Faithfully yours, nginx.

1 month назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 1 week назад
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

1 week назад @ blogs.cisco.com
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero … Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …

The Power of FedRAMP HighWhile FedRAMP Certified Class C (Moderate) is the standard for many civilian agencies, FedRAMP Certified Class D (High) is designed for systems where a breach could have catastrophic effects.

Cisco Security Cloud for GovernmentCisco Security Cloud for Government is a unified authorization boundary that integrates various Cisco security services, ensuring that organizations can protect their users, devices, and applications regardless of where they reside.

The Cisco Security Cloud for Government ecosystem is designed to meet the rigorous security requirements of the public sector and highly regulated industries.

Cisco Security Cloud Control (SCC)Cisco Security Cloud …

1 week, 6 days назад @ blogs.cisco.com
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

That’s why we are incredibly proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

Reduced Vendor Risk & Increased Trust: FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

Beyond the governance and compliance benefits, Email Threat Defense continues to deliver advanced protection capabilities that align directly with real-world email threat risks.

Email Threat De…

2 weeks назад @ blogs.cisco.com
Is your SD-WAN ready for AI-powered operations?
Is your SD-WAN ready for AI-powered operations? Is your SD-WAN ready for AI-powered operations?

AI Is Changing the Traffic ModelMuch of the enterprise AI conversation centers on models, GPUs, data platforms, and agents.

Time-sensitive performance: Voice AI, edge AI, and physical AI move latency into live operations.

SD-WAN can help maintain operations by prioritizing critical traffic, steering it across the best available path, and applying consistent policy across locations.

Why AI Traffic is an SD-WAN ProblemSD-WAN sits at the point where application intent meets real network conditions.

1 https://www.aboutamazon.com/news/operations/amazon-million-robots-ai-foundation-modelCommon questions about SD-WAN and AI trafficWhat is AI-generated network traffic?

3 weeks назад @ blogs.cisco.com
The Zero Trust Imperative for the Frontier AI Era
The Zero Trust Imperative for the Frontier AI Era The Zero Trust Imperative for the Frontier AI Era

Their recommendations for securing the AI era rely heavily on establishing strict asset inventory and preventing lateral movement—which are, at their core, fundamental Zero Trust principles.

The Three Core Principles of Zero Trust for AIFounded in three core principles, a robust Zero Trust architecture requires us to execute the following phases comprehensively.

Achieving the Architectural VisionThe above may all sound like pipedream, as most organisations struggle with Zero Trust programs and undelivered microsegmentation projects.

Ultimately AI driven platform approach is what makes Zero Trust achievable for the frontier AI era.

This is exactly why achieving a Zero Trust Architecture for …

3 weeks, 3 days назад @ blogs.cisco.com
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes

This provides an opportunity for defenders: if we assume our controls will fail at some point, we can build a much more resilient architecture.

When you assume the current layer will eventually be bypassed, you start designing the next layer proactively instead of reactively.

Defenders need to advance their controls by mapping them to the adversaries’ capabilities then assume that control will fail.

Map your controls to the attack chain.

Call to Action:If you haven’t watched the full video yet, go check it out: Assuming Failure Provides Better Defensive Outcomes (bonus elements around SOC of the Future and business context).

4 weeks назад @ blogs.cisco.com
The Journey towards Logically Air-Gapped Deployment
The Journey towards Logically Air-Gapped Deployment The Journey towards Logically Air-Gapped Deployment

Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter.

This “Logically Air-Gapped” governance model reaches its full operational potential through the implementation of “Live Protect.” As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution.

Reference ArchitectureDigital autonomy is thus exercised by shifting network and security control into the operating system kernel.

Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a un…

1 month назад @ blogs.cisco.com
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall

That is why we are introducing Firewall Migration Manager by Cisco, an enterprise-ready product built for that reality.

What Is Firewall Migration Manager?

Firewall Migration Manager is a dedicated migration application that you run in your own environment.

How Firewall Migration Manager WorksThe migration process follows a clear, guided workflow.

Intelligent, integrated migration: Firewall Migration Manager will also come to Cisco Cloud Control, and AI will play an increasing role in guiding teams before and during migration.

1 month назад @ blogs.cisco.com
We third-party tested our firewall built for AI-scale. The test tools hit their limit first.
We third-party tested our firewall built for AI-scale. The test tools hit their limit first. We third-party tested our firewall built for AI-scale. The test tools hit their limit first.

In independent testing with NetSecOPEN, the Cisco Secure Firewall 6160 delivered AI-scale inspected throughput beyond what the tools built to measure it could register, all while blocking 100% of tested threats.

These results are specific to Cisco Secure Firewall 6160, but the software capabilities behind Cisco Firewall, including advanced threat protection and high-performance inspection, extend across Cisco Firewall form factors in the cloud, virtually, and on-premises, from campus to data center.

Performance passed the previous benchmark by 5XInspection was turned on, and the test tools built to measure throughput hit their limit before the 6160 firewall did.

In previous NetSecOPEN testi…

1 month, 1 week назад @ blogs.cisco.com
SharpHound Recon Attack – How AI enhanced the threat hunt
SharpHound Recon Attack – How AI enhanced the threat hunt SharpHound Recon Attack – How AI enhanced the threat hunt

We innovated by giving the Agentic SOC access to Endace’s always-on, full packet capture, and asked the agent to assess a potential SharpHound Recon attack that we had seen while threat hunting.

This blog explores how we built the integrations and how AI helped us with our threat hunt and threat assessment.

Agentic AI Massively Speeds our AnalysisAt this point, we decided to use Agentic AI capabilities to investigate and assess this potential threat.

ConclusionThe Agentic SOC, blending Agentic AI built into Endace’s products with custom agentic tools, is a massive boost to productivity and security.

AcknowledgementsOur thanks go to the Cisco SOC team led by @Jessica Oppenheimer and @Ivan Be…

1 month, 2 weeks назад @ blogs.cisco.com
Machine Speed, Human Judgement: How AI Changed the SOC in 2026
Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Machine Speed, Human Judgement: How AI Changed the SOC in 2026

Having spent time in the Cisco Live Americas 2026 SOC, one thing became abundantly clear:The way SOCs operate today is fundamentally different from even a few years ago.

Instead of spending time gathering information, analysts could spend more time understanding what the information actually meant.

Just as spreadsheets empowered business users decades ago, AI-assisted coding is beginning to empower security analysts today.

At Cisco Live, AI was already present throughout the workflow:Incident summaries generated automatically within XDR.

And based on what I saw at Cisco Live 2026, that future has already arrived.

1 month, 2 weeks назад @ blogs.cisco.com
Elevating Expertise in the SOC
Elevating Expertise in the SOC Elevating Expertise in the SOC

The new SOC analysts were great at finding evidence, helped with triage and correlation by the AI agents in the SOC architecture.

With the advancements in Cloud Control, our new SOC Analysts can validate their hypothesis.

They had the ability to investigate the incident and find the root cause found in Splunk Security and Endace.

Instant Attack VerificationIn each Incident, the SOC Analysts is given an AI generated Summary stitching all the relevant logs from all the sources that are related to the objects in question.

Check out the blogs by the engineers who worked inside the SOC at Las Vegas:

1 month, 2 weeks назад @ blogs.cisco.com
Educate at Event Speed: Cisco Live Security Operations Center
Educate at Event Speed: Cisco Live Security Operations Center Educate at Event Speed: Cisco Live Security Operations Center

At Cisco Live AMER 2026 in Las Vegas, my work with the Cisco Event SOC centered on one outcome that makes these deployments valuable beyond the event itself: Education.

The SOC protects the conference, but it also turns live operations into a learning environment through SOC tours, Cisco Live sessions, training inside the SOC, and conversations in the World of Solutions.

Bringing live SOC lessons into the classroomEducation also happened in the sessions I delivered at Cisco Live.

Cisco Live AMER 2026 reinforced that the SOC is one of the best classrooms we have because it teaches through real operations.

For a deeper look at the model behind these deployments, read the Cisco Event SOCs: A R…

1 month, 2 weeks назад @ blogs.cisco.com
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

Inside the Cisco Live SOCAt Cisco Live AMER, the Security Operations Center (SOC) is more than a demo environment.

For a broader look at how the Cisco Live SOC operates, read this overview.

Another part was spent in the SOC, working real investigations with XDR, Splunk Enterprise Security, firewall events, DNS telemetry, packet data, and AI assistance.

AI can help a product manager become useful faster in a live SOC.

That is the bar I want us to continue building toward as we build Cisco XDR and Splunk Security.

1 month, 2 weeks назад @ blogs.cisco.com
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC

As part of the Cisco XDR (Extended Detection and Response) product engineering group, a few of us got exactly that chance.

Every product had a part to play for a network as traffic-heavy as Cisco Live.

(PS : Flaunting the SOC T-shirts was fun)AcknowledgementsA heartfelt thank you to Cisco and the entire SOC team — you are all amazing.

To the Cisco XDR , Splunk , Secure Access , and Secure Firewall engineering teams.

Check out the other blogs from our team at the Cisco Live Americas 2026 SOC at Las Vegas:

1 month, 2 weeks назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 5 days, 4 hours назад
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

Microsoft is also the largest cloud workload protection platform (CWPP) provider by revenue, with an estimated share of more than 22% of the global CWPP market.

Why cloud workload protection is being redefinedFor a long time, protecting a workload meant scanning its image, fixing known vulnerabilities, and hardening configurations before deployment.

Bottom lineFrost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 reinforces a clear shift.

Learn moreRead Frost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 to see how leading vendors are evaluated and how the category is shifting toward unified cloud runtime security.

Explore Microsoft cloud security…

5 days, 4 hours назад @ microsoft.com
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

Microsoft is also the largest cloud workload protection platform (CWPP) provider by revenue, with an estimated share of more than 22% of the global CWPP market.

Why cloud workload protection is being redefinedFor a long time, protecting a workload meant scanning its image, fixing known vulnerabilities, and hardening configurations before deployment.

Bottom lineFrost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 reinforces a clear shift.

Learn moreRead Frost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 to see how leading vendors are evaluated and how the category is shifting toward unified cloud runtime security.

Explore Microsoft cloud security…

5 days, 4 hours назад @ microsoft.com
Hunting MacSync Stealer infrastructure through behavioral pivots
Hunting MacSync Stealer infrastructure through behavioral pivots Hunting MacSync Stealer infrastructure through behavioral pivots

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

6 days, 4 hours назад @ microsoft.com
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

That’s exactly what Microsoft Defender Experts MDR is built to do.

We are excited to announce that we have been named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise Vendor Assessment (Doc #US54792426, July 2026).

Defender Experts MDR includes it as a core part of the service with Defender Experts Hunting, extending your team with Microsoft experts who continuously look for advanced threats across your environment.

Get startedRead the IDC MarketScape: Worldwide MDR/MXDR for the Enterprise 2026 Vendor Assessment excerpt, and visit the Microsoft Defender Experts MDR webpage to see how expert-led, round-the-clock managed detection and response can extend your team, …

2 weeks назад @ microsoft.com
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

That’s exactly what Microsoft Defender Experts MDR is built to do.

We are excited to announce that we have been named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise Vendor Assessment (Doc #US54792426, July 2026).

Defender Experts MDR includes it as a core part of the service with Defender Experts Hunting, extending your team with Microsoft experts who continuously look for advanced threats across your environment.

Get startedRead the IDC MarketScape: Worldwide MDR/MXDR for the Enterprise 2026 Vendor Assessment excerpt, and visit the Microsoft Defender Experts MDR webpage to see how expert-led, round-the-clock managed detection and response can extend your team, …

2 weeks назад @ microsoft.com
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations.

Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems.

Recovery chat: Technical architectureThe most distinctive feature of the DeadLock ransomware is its recovery chat system.

‘DeadLock’ ransomware was detected‘DeadLock’ ransomware was preventedMicrosoft Defender for Cloud AppsThe following alert might indicate threat activity associated with this threat.

Indicators of compromiseIndicato…

2 weeks назад @ microsoft.com
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

KuppingerCole’s Leadership Compass: Cloud Native Application Protection Platforms (CNAPP) reflects this shift.

The report describes how CNAPP is evolving from a consolidation of cloud security tools into the security foundation for AI-native enterprises, combining cloud security, AI security posture management, runtime protection, attack path analysis, cloud detection and response, and agentic AI operations into unified platforms.

This complexity exposes the limits of traditional, siloed tools, where cloud posture, workload protection, AI security, and the security operations center (SOC) each live in their own console.

Does it see AI models, agents, and pipelines as part of cloud risk, or …

2 weeks, 5 days назад @ microsoft.com
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Mitigation and protection guidanceOrganizations can apply the following recommendations to reduce exposure to this and similar macOS ClickFix campaigns:Educate users.

]com Domain ClickFix Webpage filecedarwallet[.]online.

Domain ClickFix Webpage filecopperbasket[.

]sbs Domain ClickFix Webpage filecrimsonsignal[.

]online Domain ClickFix Webpage filemarblegarden[.

2 weeks, 5 days назад @ microsoft.com
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Mitigation and protection guidanceOrganizations can apply the following recommendations to reduce exposure to this and similar macOS ClickFix campaigns:Educate users.

]com Domain ClickFix Webpage filecedarwallet[.]online.

Domain ClickFix Webpage filecopperbasket[.

]sbs Domain ClickFix Webpage filecrimsonsignal[.

]online Domain ClickFix Webpage filemarblegarden[.

2 weeks, 5 days назад @ microsoft.com
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
ChainDrop supply chain compromise: Anatomy of a self-propagating worm ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Uses GitHub credentials to inject files into Claude and Visual Studio Code configurations across repository branches for persistence.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, Microsoft Defender for Containers, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelli…

2 weeks, 5 days назад @ microsoft.com
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
ChainDrop supply chain compromise: Anatomy of a self-propagating worm ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Uses GitHub credentials to inject files into Claude and Visual Studio Code configurations across repository branches for persistence.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, Microsoft Defender for Containers, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelli…

2 weeks, 5 days назад @ microsoft.com
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

That’s why we are expanding the Zero Trust for AI strategy with two major additions: a new AI-focused Zero Trust Assessment experience and a new DevSecOps pillar in the Zero Trust Workshop.

Zero Trust Assessment tool updates: New set of assessment checks for AI, Security Operations (SecOps), and Infrastructure.

Zero Trust Workshop updates: New dedicated pillar focused on Developer Security (DevSecOps) and additional guidance for AI Memory.

How to run Zero Trust WorkshopThe Zero Trust Workshop follows a simple three-step motion: plan the right pillars and stakeholders, run the Zero Trust Assessment to establish a baseline, and use the facilitated workshop to turn findings into a 12- to 24-mo…

2 weeks, 6 days назад @ microsoft.com
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints.

By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks.

Attack disruption instead uses AI-driven correlation and real-time analysis to identify multi-stage attacks by connecting signals across the environment before taking action.

The resultsTo summarize the results of the new device isolation response action:From first detection, Defender isolated the device in just 128 seconds.

Impact Mitigation (Defender response) – Device Isolation…

2 weeks, 6 days назад @ microsoft.com
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints.

By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks.

Attack disruption instead uses AI-driven correlation and real-time analysis to identify multi-stage attacks by connecting signals across the environment before taking action.

The resultsTo summarize the results of the new device isolation response action:From first detection, Defender isolated the device in just 128 seconds.

Impact Mitigation (Defender response) – Device Isolation…

2 weeks, 6 days назад @ microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence has also identified active traffic manipulation attacks leading to the delivery of malware on impacted systems.

Microsoft Threat Intelligence would like to thank our partners at Anthropic and OpenAI for their collaboration and support during this investigation.

Storm-2945 and Midnight BlizzardMicrosoft Threat Intelligence assesses that Storm-2945 is an operational sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps.

For additional details on Midnight Blizzard-related device code phishing techniques, see: Storm-2372 conducts device code phishing campaign.

To hear stories and insights from the Microsoft Threat Intelligence com…

3 weeks, 3 days назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 4 months назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

4 months назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

4 months, 2 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

4 months, 2 weeks назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

4 months, 3 weeks назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

4 months, 3 weeks назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

5 months назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

5 months, 4 weeks назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

6 months назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

6 months назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

6 months, 4 weeks назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

8 months, 2 weeks назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

8 months, 2 weeks назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

8 months, 2 weeks назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

8 months, 3 weeks назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

9 months, 1 week назад @ security.googleblog.com