Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 15 часов назад
Призрачные частицы решают, взорвётся ли звезда или станет чёрной дырой
Призрачные частицы решают, взорвётся ли звезда или станет чёрной дырой Призрачные частицы решают, взорвётся ли звезда или станет чёрной дырой

Превращения нейтрино заметно меняют передачу энергии внутри коллапсирующего ядра.

15 часов назад @ securitylab.ru
Защита по IP не спасёт. GitLab пустит чужой код в main прямо по почте
Защита по IP не спасёт. GitLab пустит чужой код в main прямо по почте

Для взлома хватит одной строчки из открытого описания проекта.

16 часов назад @ securitylab.ru
Вирусы вторглись в геном наших предков. Миллионы лет спустя мы всё ещё носим их внутри
Вирусы вторглись в геном наших предков. Миллионы лет спустя мы всё ещё носим их внутри

8% генома человека - это последствия древних инфекций. Очень даже полезные...

17 часов назад @ securitylab.ru
Создан имплант, который читает, лечит и стимулирует мозг одновременно
Создан имплант, который читает, лечит и стимулирует мозг одновременно

Разработчики проверили устройство на мышах и смогли работать одновременно с корой и гиппокампом.

18 часов назад @ securitylab.ru
Закручена ли Вселенная? Физики придумали, как это проверить наверняка
Закручена ли Вселенная? Физики придумали, как это проверить наверняка

Новый метод проверяет, не маскируется ли под новую физику неточная калибровка приборов.

19 часов назад @ securitylab.ru
Carbonato захватывает Docker-серверы через Telegram. Для взлома даже не нужны уязвимости
Carbonato захватывает Docker-серверы через Telegram. Для взлома даже не нужны уязвимости

После первого доступа в дело вступает легитимный ИИ-инструмент с новой ролью.

20 часов назад @ securitylab.ru
Миф о квантовом мозге развенчали — но нашли кое-что страннее
Миф о квантовом мозге развенчали — но нашли кое-что страннее

Оказывается, сложные классические системы могут подчиняться математике, удивительно похожей на квантовую.

21 час назад @ securitylab.ru
Сбер, ВТБ и Альфа-Банк могут перестать дозваниваться клиентам с 15 октября
Сбер, ВТБ и Альфа-Банк могут перестать дозваниваться клиентам с 15 октября Сбер, ВТБ и Альфа-Банк могут перестать дозваниваться клиентам с 15 октября

Финансовому сектору дали время до середины октября, чтобы урегулировать конфликт.

22 часа назад @ securitylab.ru
«Amazon для киберпреступников» проработал почти 10 лет. Его создатель признал вину
«Amazon для киберпреступников» проработал почти 10 лет. Его создатель признал вину «Amazon для киберпреступников» проработал почти 10 лет. Его создатель признал вину

Через Rydox прошли тысячи сделок с чужими данными и инструментами для атак.

23 часа назад @ securitylab.ru
Чёрные дыры в дополнительных измерениях проверят теорию струн
Чёрные дыры в дополнительных измерениях проверят теорию струн

Поправка Гаусса-Бонне разрушает симметрию, которую сохраняют уравнения Эйнштейна.

23 часа назад @ securitylab.ru
Касперский заглянул в календарь Apple, а там встреча с вредоносом
Касперский заглянул в календарь Apple, а там встреча с вредоносом

За обычным установщиком скрывается многоступенчатая схема с удалённым управлением.

1 day, 1 hour назад @ securitylab.ru
Дыры в MikroTik дошли до Роскомнадзора. Провайдеры могут ограничить непропатченные устройства
Дыры в MikroTik дошли до Роскомнадзора. Провайдеры могут ограничить непропатченные устройства

ГРЧЦ рекомендует операторам предупреждать владельцев уязвимых роутеров и временно закрывать опасные порты.

1 day, 1 hour назад @ securitylab.ru
Meta* превращает Muse в карманного тамагочи. ИИ-помощника поселили на связке ключей
Meta* превращает Muse в карманного тамагочи. ИИ-помощника поселили на связке ключей Meta* превращает Muse в карманного тамагочи. ИИ-помощника поселили на связке ключей

Смартфон больше не нужен, чтобы вызвать персонального агента и начать с ним разговор.

1 day, 2 hours назад @ securitylab.ru
Google отправляет TPU в космос и проверит, переживёт ли ИИ запуск
Google отправляет TPU в космос и проверит, переживёт ли ИИ запуск

Чипы ждут перегрузки до 100 g, радиация и вакуум.

1 day, 3 hours назад @ securitylab.ru
Купить власть за $20000 и украсть миллионы. Крипторынок накрыла серия атак
Купить власть за $20000 и украсть миллионы. Крипторынок накрыла серия атак

Обычная процедура управления сетью превратилась в инструмент для вывода миллионов.

1 day, 4 hours назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 1 day, 22 hours назад
Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности
Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности

Использование macOS в dev-средах увеличивает риск горизонтального перемещенияКлассические техники горизонтального перемещения через Active Directory и SMB на macOS встречаются реже и хуже покрыты правилами детектирования.

Классическая подсистема аудита OpenBSM начиная с macOS 11 объявлена устаревшей, а в версиях начиная с macOS 14 она отключена по умолчанию.

Сейчас ситуация меняется: вендоры наращивают функциональность агентов под macOS и адаптируют их как к новым версиям ОС, так и к меняющемуся ландшафту угроз.

Политики безопасности исторически писались под Windows, и Mac-устройства во многих организациях так и не попали в контур мониторинга SOC.

Windows, Linux и macOS в ней сосуществуют, …

1 day, 22 hours назад @ anti-malware.ru
Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки
Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки

Эксперты ведущих вендоров собрались в студии AM Live, чтобы обсудить, чем отличаются классы решений, как их выбирать и на что смотреть при пилотировании.

Какими бывают балансировщики нагрузкиДаниил Виняр предложил разделить решения на три класса:Global Server Load Balancing (GSLB) — решения на базе DNS, которые распределяют нагрузку между разными ЦОДами, будь то собственные площадки или облака.

ВыводыРоссийский рынок балансировщиков нагрузки и брокеров сетевых пакетов находится в фазе активного роста и уже не нуждается в доказательствах своей зрелости.

При этом удобство — это не только красивый интерфейс, но и логичность, понятность того, что можно сделать с устройством, и возможность не со…

2 days, 19 hours назад @ anti-malware.ru
Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств
Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств

MaxPatrol Endpoint Security — это комплексное решение, которое объединило все возможности продуктов MaxPatrol EDR и MaxPatrol EPP.

Архитектура MaxPatrol Endpoint Security 10Порядок функционирования MaxPatrol Endpoint Security:Сервер агентов распространяет через агенты, установленные на конечных устройствах, исполняемые модули и их конфигурацию.

Взаимодействие компонентов MaxPatrol Endpoint Security 10 через портыУлучшенные функциональные возможности в MaxPatrol Endpoint Security 10Рассмотрим возможности MaxPatrol Endpoint Security 10-й версии.

MaxPatrol Endpoint Security поддерживает связку MaxPatrol EDR + MaxPatrol EPP, а также интеграции с MaxPatrol SIEM, MaxPatrol VM, PT Sandbox и PT NAD…

3 days, 2 hours назад @ anti-malware.ru
Российские SIEM в 2026 году: от критериев выбора и пилотирования до ИИ и архитектуры будущего
Российские SIEM в 2026 году: от критериев выбора и пилотирования до ИИ и архитектуры будущего Российские SIEM в 2026 году: от критериев выбора и пилотирования до ИИ и архитектуры будущего

Одни делают ставку на экспертизу и контент, другие — на производительность и масштабируемость, третьи — на экосистемность и интеграции.

Нужно собирать ровно столько, сколько может осилить и SIEM, и команда, которая будет работать с событиями, и чуточку больше.

Границы SIEM: что можно и что нельзя объединять«Граница SIEM зависит от того, кто и как его использует, от масштаба организации.

Евгения Лагутина:«Хочется верить, что мы сможем снизить порог вхождения не в SIEM, а в экспертизу в Threat Intelligence.

Ответ на этот вопрос лежит не в дата-шитах и не в маркетинговых презентациях, а в реальной эксплуатации, пилотировании и понимании собственных задач.

3 days, 20 hours назад @ anti-malware.ru
Остановка запрещена: как бизнес проходит технологическую перестройку на ходу
Остановка запрещена: как бизнес проходит технологическую перестройку на ходу Остановка запрещена: как бизнес проходит технологическую перестройку на ходу

Одновременно меняются угрозы: атакующие целятся не только в инфраструктуру, но и в саму возможность восстановления — уничтожают бэкапы и захватывают системы управления.

На дискуссии о высокоплотных ЦОДах под модерацией Сергея Андронова, директора центра сетевых решений компании «Инфосистемы Джет», спорили и о плотности, и о географии.

Значит, средство защиты оценивается уже не само по себе, а по тому, помогает ли оно бизнесу пережить атаку.

Неудачный тест при этом оказался полезен: заказчик точнее сформулировал требования и стал смотреть не только на текущую версию продукта, но и на способность производителя развивать его дальше.

И здесь промышленное внедрение быстро упирается не только в к…

4 days, 21 hours назад @ anti-malware.ru
Несколько SIEM-систем в одной инфраструктуре: когда это оправданно
Несколько SIEM-систем в одной инфраструктуре: когда это оправданно Несколько SIEM-систем в одной инфраструктуре: когда это оправданно

Разбираемся, почему возникает такая архитектура, как распределить роли между платформами и в каких случаях разделение функций оправдывает дополнительные затраты.

Холдинговая структура, слияния и поглощенияВ крупных холдингах отдельные дочерние и зависимые общества (ДЗО) часто развивают собственные центры мониторинга ИБ и используют разные SIEM-системы.

Независимая параллельная обработкаСамый простой вариант — источники одновременно отправляют события ИБ в несколько SIEM-систем.

Наконец, нужны общие правила классификации событий и инцидентов ИБ и единый подход к управлению экспертным контентом.

Использование нескольких SIEM-систем оправдано, если у каждой платформы есть своя задача и понятно…

5 days, 20 hours назад @ anti-malware.ru
Что такое цифровая личность и как её защитить
Что такое цифровая личность и как её защитить Что такое цифровая личность и как её защитить

Цифровая личность включает не только профили в социальных сетях, но и учётные записи, идентификаторы, публикации и накопленные цифровые следы.

В цифровую личность в широком смысле входят:официальные сведения и идентификаторы;учётные записи и средства аутентификации;биометрические данные;публикации и социальные связи в интернете;поведенческие и репутационные данные.

При этом цифровую личность не следует отождествлять с цифровым двойником, цифровым профилем, цифровым следом и цифровой тенью.

Например, в научной статье «Цифровой двойник и цифровая личность: понятие, соотношение, значение в процессе совершения киберпреступлений и в праве в целом» авторы акцентируют внимание на отсутствии законо…

1 week, 1 day назад @ anti-malware.ru
Будущее на горизонте: как развиваются виртуализация и её защита
Будущее на горизонте: как развиваются виртуализация и её защита Будущее на горизонте: как развиваются виртуализация и её защита

Рассказываем, в каком состоянии рынок средств безопасности для сред виртуализации и что его ожидает в ближайшие годы.

О важности микросегментацииВесной этого года в силу вступил приказ ФСТЭК России № 117, который существенно обновил требования к безопасности.

Это ахиллесова пята для многих ИБ-решений, и в организации микросегментации пропускная способность тоже становится проблемой.

Физическая инфраструктура строится годами, а циклы закупки нужного оборудования длятся месяцами, при этом ИБ- и ИТ-специалисты чётко понимают, какие продукты у них будут и для чего они нужны.

Таким образом, мы видим, что на данном этапе первоначальные сложности, которые неизбежны при внедрении модели, больше отп…

1 week, 2 days назад @ anti-malware.ru
А что я получил за эти 50 миллионов? Как измерить пользу DevSecOps для бизнеса
А что я получил за эти 50 миллионов? Как измерить пользу DevSecOps для бизнеса А что я получил за эти 50 миллионов? Как измерить пользу DevSecOps для бизнеса

А потом спросите людей со стороны бизнеса — ответы будут варьироваться от «не знаю» до «так требует регулятор».

Проблема не в инструментах, а в отсутствии понятной коммуникации.

Финансовый директор (CFO) дослушивает и задаёт единственный вопрос: «А что я получил за эти 50 миллионов?».

Это не проблема конкретного CISO — это проблема архитектуры принятых метрик DevSecOps.

Истинное получает приоритет по риску для бизнеса, а не «по баллу CVSS».

1 week, 2 days назад @ anti-malware.ru
Вайб-пентест с помощью искусственного интеллекта: готовимся разорять платформы Bug Bounty
Вайб-пентест с помощью искусственного интеллекта: готовимся разорять платформы Bug Bounty Вайб-пентест с помощью искусственного интеллекта: готовимся разорять платформы Bug Bounty

Реализуем вайб-пентестинг на практикеКак и в других подобных задачах, в первую очередь нужны три вещи:ИИ-модель,обвязка (harness),набор инструментов.

Пусть агент работает не с самой инфраструктурой, а с её копией (т. н. disposable clone), например.

Как и человек, ИИ должен знать, какие пароли, ключи доступа и прочие подобные данные ему разрешено применять.. Как и человек, ИИ должен знать, какие пароли, ключи доступа и прочие подобные данные ему разрешено применять.

При этом всё опять же делается непрерывно и в автоматическом режиме, с возможностью задать ограничения или потребовать запроса подтверждений.

Однако самое интересное здесь — вовсе не то, сможет ли ИИ полностью заменить пентестера…

1 week, 3 days назад @ anti-malware.ru
Как выбрать платформу хранения данных в 2026 году: критерии, TCO и тренды
Как выбрать платформу хранения данных в 2026 году: критерии, TCO и тренды Как выбрать платформу хранения данных в 2026 году: критерии, TCO и тренды

Эксперты в студии AM Live обсудили, как меняются требования к платформам хранения, на что обращать внимание при выборе и как будет развиваться рынок.

Главная задача — определить, какая в компании структура данных и какие требования к хранилищу, и под это подбирать решение.

Вопрос не в объёме данных, а в том, как решать такие задачи.

Это большая отрасль и в мире, и в России.

ВыводыРынок платформ хранения данных в 2026 году переживает трансформацию.

1 week, 3 days назад @ anti-malware.ru
Социальная инженерия в 2026 году: атаки, обучение сотрудников и Human Risk Management
Социальная инженерия в 2026 году: атаки, обучение сотрудников и Human Risk Management Социальная инженерия в 2026 году: атаки, обучение сотрудников и Human Risk Management

Эксперты в студии AM Live обсудили, как меняются атаки, почему человек остаётся слабым звеном и как выстроить эффективное обучение.

При этом вопрос уже не в том, как научить человека никогда не ошибаться, а в том, как минимизировать цену этой ошибки.

Сотрудник не успевает понять, что это комплексная атака, потому что не готов к такому сценарию.

В третьем опросе выяснилось, что, по мнению зрителей, важно поменять в планах Security Awareness в 2026 году (мультивыбор):Настроить обучение по ролям — 53%.

Про офлайн-безопасность не нужно забывать — на закрытых предприятиях и в организациях другой вид угроз, и это отдельное направление обучающих материалов».

1 week, 4 days назад @ anti-malware.ru
Обзор CICADA8 Cyber Rating 26.3.1, платформы оценки кибербезопасности контрагентов и ДЗО
Обзор CICADA8 Cyber Rating 26.3.1, платформы оценки кибербезопасности контрагентов и ДЗО Обзор CICADA8 Cyber Rating 26.3.1, платформы оценки кибербезопасности контрагентов и ДЗО

Решение позволяет оценивать кибербезопасность контрагентов, подрядчиков и дочерних организаций, поставляется по модели SaaS и входит в экосистему CICADA8, к которой также относятся CICADA8 ETM, CICADA8 VM и CICADA8 Dependency Firewall.

Лицензирование CICADA8 Cyber Rating 26.3.1Лицензирование CICADA8 Cyber Rating построено по подписочной модели со сроком от одного года.

Добавление организации в избранное в CICADA8 Cyber Rating 26.3.1Такой сценарий используется при первичной оценке нового поставщика, подрядчика или дочерней организации.

Шкала оценки в CICADA8 Cyber Rating 26.3.1По результату оценки платформа формирует рекомендации относительно возможных рисков при сотрудничестве с этим контра…

1 week, 5 days назад @ anti-malware.ru
Сетевая безопасность контейнеров: тренды, угрозы и требования ФСТЭК России
Сетевая безопасность контейнеров: тренды, угрозы и требования ФСТЭК России Сетевая безопасность контейнеров: тренды, угрозы и требования ФСТЭК России

Согласно представленной статистике, рынок измеряется в миллиардах рублей и, по мнению аналитиков, будет расти очень динамично в ближайшие годы.

Проблемы сетевой безопасности в KubernetesПавел Коростелёв объяснил, что в Kubernetes происходит смешение защиты приложений и инфраструктуры.

Теперь объектом защиты становится не сетевой хост и не среда виртуализации, а среда контейнеризации.

Всё это вместе создаёт весьма интересную картину: нужно очень внимательно следить за сегментацией и в традиционной сети, и в среде виртуализации, и в среде контейнеризации.

Финальный опрос показал, как, по мнению зрителей, должна строиться сетевая безопасность контейнерной инфраструктуры:Подход зависит от архит…

1 week, 5 days назад @ anti-malware.ru
Обзор SafeERP 4.9.11: комплексная защита cистем ERP
Обзор SafeERP 4.9.11: комплексная защита cистем ERP Обзор SafeERP 4.9.11: комплексная защита cистем ERP

Архитектура SafeERP Extension Module (Комплексная защита 1С)SafeERP Extension Module имеет модульную структуру и предназначен для комплексной защиты информационно-управляющих систем (ИУС), построенных на базе платформы 1С.

Архитектура компонента SafeERP для анализа кодаЯдром компонента SafeERP CS EM является сервер управления.

Архитектура компонента SafeERP для контроля настроек и защиты платформы 1СЯдром компонента SafeERP PS EM также является сервер управления.

Каталог проектов контроля настроек платформы 1С в SafeERP PS EMРисунок 26.

Для компонентов SafeERP CS EM и SafeERP PS EM установлены одинаковые требования к аппаратному и программному обеспечению.

1 week, 6 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 1 час назад
Как я перестал долбить сканерами и начал думать: мой путь в Bug Bounty
Как я перестал долбить сканерами и начал думать: мой путь в Bug Bounty Как я перестал долбить сканерами и начал думать: мой путь в Bug Bounty

Я не начинал свой путь в Bug Bounty с мысли «хочу стать security researcher».

На практике оказалось, что между «я знаю, что такое SQL Injection» и «я самостоятельно нашёл SQL Injection в реальном приложении» лежит огромная пропасть.

В этой статье расскажу, как я её постепенно сокращал и почему в какой‑то момент перестал пытаться найти уязвимость напрямую.

Первый заход в Bug BountyВ голове была довольно простая схема:найти программу → просканировать → найти уязвимость → отправить отчёт.

Первые два‑три месяца я в основном пытался применять знания с курса и то, что находил в интернете.

1 час назад @ habr.com
Билл Гейтс призвал усилить внешний контроль над ИИ
Билл Гейтс призвал усилить внешний контроль над ИИ Билл Гейтс призвал усилить внешний контроль над ИИ

По его мнению, конгресс должен принять законы об ИИ, а правоохранители и политики — подключиться к обсуждению того, какими должны быть гарантии и контроль.

Он признаёт, что это добавит индустрии немного бюрократии, но не думает, что это сильно затормозит разработку.

По его мнению, ИИ уже достаточно мощный инструмент, чтобы в руках злоумышленников натворить бед в масштабах, о которых раньше писали только в фантастике.

При этом он не призывает всё остановить.

Тем временем отдельные штаты — Калифорния, Мэриленд, Нью-Йорк — уже запускают свои инициативы по регулированию ИИ и создают экспертные советы.

19 часов назад @ habr.com
Какие наши продукты задевает эта CVE? Я продолжил заброшенный Minefield и нашёл, что он читал SBOM задом наперёд
Какие наши продукты задевает эта CVE? Я продолжил заброшенный Minefield и нашёл, что он читал SBOM задом наперёд Какие наши продукты задевает эта CVE? Я продолжил заброшенный Minefield и нашёл, что он читал SBOM задом наперёд

А по дороге нашёл, что граф, на котором всё держится, строился неправильно.

Я перешёл на драйвер на чистом Go ( glebarez/sqlite поверх modernc.org/sqlite ), и Sapper собирается в один статический бинарник для шести платформ.

Метод для произвольных данных (на нём держатся рейтинги и всё, что не вершины и не рёбра) в SQLite возвращал not implemented .

Но Go-модули без тегов версионируются псевдоверсиями вида v0.0.0-20190620200207-3b0461eec859 , а по правилам semver 0.0.0-что-угодно — это пре-релиз, и он меньше 0 .

Если у вас есть OpenVEX-документ, где сказано, что продукт не затронут (уязвимый код не вызывается) или уже исправлен, продукт уходит в отдельный список и не мешает.

1 day, 1 hour назад @ habr.com
Способ, как можно скачать сгенерированные ИИ 3D модели без подписки или оплаты
Способ, как можно скачать сгенерированные ИИ 3D модели без подписки или оплаты Способ, как можно скачать сгенерированные ИИ 3D модели без подписки или оплаты

Предлагаю способ как можно скачивать сгенерированные 3D модели с текстурами, после бесплатной генерации, для ознакомления с результатом генерации в любой программе для работы с 3D графикой.

Но если есть необходимость всё-таки скачать, то вот как это можно сделать, не затрагивая кнопку "Экспорт".

3D модель готова, текстуры тоже.

После этого можно к примеру экспортировать 3д модель в виде файла OBJ или другого популярного формата для последующего редактирования в Zbrush.

И желания дополнительно ознакамливаться с 3д моделью и текстурами тоже нет, то можно сделать конечно проще, без этих манипуляций.

1 day, 10 hours назад @ habr.com
YApi заброшен с 2022 года. Я продолжил его и нашёл токены, которые может подделать любой участник проекта
YApi заброшен с 2022 года. Я продолжил его и нашёл токены, которые может подделать любой участник проекта YApi заброшен с 2022 года. Я продолжил его и нашёл токены, которые может подделать любой участник проекта

Он работает на существующей базе YApi, а обновление с настоящей базы YApi 1.12 проверяется в CI на каждое изменение.

Собранный бандл лежит прямо в репозитории, так что YApi можно запустить, но нельзя поменять в интерфейсе ни строчки.

Токен нужен для доступа к API без входа: его копируют в CI, в плагин IDE, в генератор TypeScript-типов.

Скрипты, которые писали под YApi, работают без правок, если не лезли в Node.js — а туда им лезть и не следовало.

Пароли и входПервый администратор в YApi создавался с паролем ymfe.org , и он был напечатан в документации.

1 day, 14 hours назад @ habr.com
Атаки с подменой адреса: Никто не проверяет 42 символа
Атаки с подменой адреса: Никто не проверяет 42 символа Атаки с подменой адреса: Никто не проверяет 42 символа

Это не новость и не редкость.

Перевод, которого вы не просили (спам переводами от похожих адресов)Отравлению адресов вредоносное ПО не нужно вовсе.

А подделыватель, которому нужно совпадение и по краям текста, и по картинке, платит произведение двух этих величин.

Для картинки, которую может вычислить кто угодно, это не очень хорошо, но это решается с помощью salt (keyed режим).

Он может сказать только, что это тот же адрес, что и в прошлый раз.

1 day, 18 hours назад @ habr.com
[Перевод] Взлом режима Secure Debug на RP2350 с помощью лазера и фотонной эмиссии
[Перевод] Взлом режима Secure Debug на RP2350 с помощью лазера и фотонной эмиссии [Перевод] Взлом режима Secure Debug на RP2350 с помощью лазера и фотонной эмиссии

И в оставшейся части статьи мы ответим на вопрос о том, можно ли активировать этот регистр с помощью инжекции сбоев.

В отличие от избыточного кодирования, применяемого для полей безопасности в OTP-памяти, для DEBUGEN в спецификации не заявлено никакой избыточности битов, контроля чётности или мажоритарного голосования.

Поэтому мы решили проверить, получится ли с помощью лазерных импульсов установить биты DEBUGEN на защищённом устройстве, описанном выше.

Поскольку две интересующие нас позиции находятся всего в нескольких микрометрах друг от друга, более широкое лазерное пятно, похоже, попадало и в область установки бита, и в область его сброса, из-за чего получить нужное значение было невозм…

1 day, 20 hours назад @ habr.com
Яндекс Дропс под рентгеном: микротомография первых ИИ-наушников Яндекса
Яндекс Дропс под рентгеном: микротомография первых ИИ-наушников Яндекса Яндекс Дропс под рентгеном: микротомография первых ИИ-наушников Яндекса

Что из этого следует: плотность упаковки — уровень флагманских TWS.

Что из этого следует: по калиброванной шкале кадра наружный диаметр драйвера — ~11 мм, аккумулятор — ~10 × 3.5 мм в проекции.

Что из этого следует: внутренний электрод тач-зоны; «L7 CC» — вероятно, код полости формы или даты, расшифровка — у производителя.

Что из этого следует: гипотеза — датчик положения крышки.

Открытые вопросы и что дальшеГлавный открытый вопрос остаётся открытым: что реально передаётся в эфир в состоянии покоя.

1 day, 22 hours назад @ habr.com
Почему AI-агент не цифровой сотрудник
Почему AI-агент не цифровой сотрудник Почему AI-агент не цифровой сотрудник

Но он ничего не говорит о том, почему оно вообще стало нежелательным и почему ответом стал откат, а не исправление.

Часть норм сотрудник приносит с профессией, а часть усваивает уже внутри компании, подстраиваясь под устоявшиеся правила и культуру.

Почему агента приходится откатывать, а не корректироватьВернёмся к данным Sinch.

Но остаётся другой вопрос: почему её приходится решать откатом, а не настройкой работающего агента?

Цифровой сотрудник — это конструкция вокруг него: агент плюс механизмы ограничения, проверки исполнения и передачи решения человеку, собранные под конкретную задачу.

1 day, 22 hours назад @ habr.com
[Перевод] Почему SAML ломают снова и снова: пять фатальных изъянов протокола аутентификации
[Перевод] Почему SAML ломают снова и снова: пять фатальных изъянов протокола аутентификации [Перевод] Почему SAML ломают снова и снова: пять фатальных изъянов протокола аутентификации

Там я годами переваривал спецификации SAML и был рядом, когда Келби Людвиг (Kelby Ludwig) нашёл обход через XML-комментарии.

Библиотека для SAML должна закрыть всё это ещё до того, как дойдёт до собственно SAML.

Количественно сравнить сложность XML и JSON (или SAML и JWT/OIDC) — тема для отдельной статьи, но то, что XML значительно сложнее, очевидно.

ОкостенениеSAML проектировался под другую эпоху и так и не получил нужных обновлений.

К тому же SAML не предвидел революцию мобильных устройств, SPA и IoT, и ответа на них у него не нашлось.

1 day, 23 hours назад @ habr.com
Требования заказчиков к LLM/AI Firewall
Требования заказчиков к LLM/AI Firewall Требования заказчиков к LLM/AI Firewall

Что на самом деле требует ЗаказчикЗа последний год сильно изменились требования крупных enterprise компании к защите генеративного ИИ.

Здесь же возникает требование к разделению зон ответственности:шлюз к моделям,шлюз к инструментам (MCP),агент на конечной точке,контроль кода, который генерирует ИИ.

Если задача несложная («дешёвая»), её нельзя держать на дорогой модели только потому, что на ней есть квота.

Что из этого следуетПо мере перехода от отдельных экспериментов к корпоративным ИИ-платформам требования к LLM/AI Firewall быстро усложняются.

Именно поэтому требования к таким решениям продолжают расти: корпоративному ИИ требуется не только доступ к моделям, но и управляемая, проверяемая…

1 day, 23 hours назад @ habr.com
MFA не отвечает: как мы строили отказоустойчивый облачный сервис аутентификации
MFA не отвечает: как мы строили отказоустойчивый облачный сервис аутентификации MFA не отвечает: как мы строили отказоустойчивый облачный сервис аутентификации

При этом уже установленные сессии могут продолжать работать, а новые нет, поэтому масштаб инцидента растет постепенно и не всегда сразу очевиден.

Если аварийные учетные записи и процедура обхода не были подготовлены заранее, команда оказывается перед плохим выбором: ждать восстановления MFA или в спешке отключать второй фактор.

Мы хотели создать облачный сервис MFA, для которого доступность была бы одним из свойств безопасности, поэтому мы серьезно подошли к вопросу его проектирования.

Так stateless-модель приложения мы сразу использовали и для распределения нагрузки, и для переключения при отказе.

Дежурные администраторы 24/7 проверяют затронутый компонент и связанные метрики, выполняют со…

2 days назад @ habr.com
BlueSec: открытые соревнования ИИ-агентов по расследованию инцидентов
BlueSec: открытые соревнования ИИ-агентов по расследованию инцидентов BlueSec: открытые соревнования ИИ-агентов по расследованию инцидентов

Соревнования идут онлайн из любой точки земного шара с 25.09 по 10.10, финал в Москве и в Питере оффлайн+онлайн, регистрация на сайте.

На это ушли часы, хотя обычно такая работа занимает дни.

Сначала команда попробовала фронтирные модели через API, но это не сработало.

Для анализа нужно отправлять в модель эксплойты и артефакты C2, а гардрейлы такие запросы (сюрпризсюрприз) блокируют: они не отличают ибшника и хакера.

Когда агент и модель готовы, идете на сайт и регистрируетесь.

2 days, 1 hour назад @ habr.com
Как внедрить статический анализ кода по ГОСТ Р 71207—202
Как внедрить статический анализ кода по ГОСТ Р 71207—202 Как внедрить статический анализ кода по ГОСТ Р 71207—202

Как шаг за шагом организовать процесс внедрения статического анализа по ГОСТ Р 71207—2024: рассказываем простыми словами с отсылками на соответствующие пункты стандарта.

5.1 делит внедрение статического анализа на три больших этапа:Подготовительный (выбор инструмента и подготовка сборочной среды); Начальный (настройка, первичный анализ и разметка); Регулярное проведение статического анализа.

Перевести статический анализ в регулярный процессПосле первичной настройки статический анализ должен стать частью регулярного процесса разработки.

Разумный выбор мер позволяет связать техническую практику статического анализа с задачами РБПО, а требования ГОСТ Р 71207—2024 — с реальным процессом разрабо…

2 days, 2 hours назад @ habr.com
Пароль админа менялся сам. Следы привели к парсеру по подписке
Пароль админа менялся сам. Следы привели к парсеру по подписке Пароль админа менялся сам. Следы привели к парсеру по подписке

Человек из поиска уходил с сайта, на который пришёл.

Вся группа давала около 3000 визитов в месяц, из них 79 % из поиска и около 1 % из рекламы.

Отдельные счётчики под каждый домен в Метрике когда-то завели, но в код сайтов так и не поставили.

Эта страница появилась на всех восьми сайтах, переход на неё прописан 28 формам главного сайта и 212 формам и блокам поддоменов.

Кто и зачем поменял лид, я так и не выяснил.

2 days, 2 hours назад @ habr.com
Хакер Хакер
последний пост 1 day, 16 hours назад
Печатные спецвыпуски «Хакера»: от фаззинга до LLM
Печатные спецвыпуски «Хакера»: от фаззинга до LLM Печатные спецвыпуски «Хакера»: от фаззинга до LLM

Самый свежий среди них — спецвыпуск #4 с лучшими статьями за 2021–2022 годы: от практики пентеста до изучения необычного железа.

На его страницах собрано более 20 лучших материалов за 2021–2022 годы — от практики пентеста и фаззинга до реверса и изучения необычного железа.

В них рассказываем о закулисных деталях работы над статьями, вспоминаем, как проходили исследования, и делимся подробностями, которые не вошли в первоначальные версии материалов.

Помимо нового сборника, в магазине «Хакера» еще доступны другие бумажные журналы, но их запасы постепенно сокращаются на нашем складе.

Дополнительных тиражей мы не планируем, поэтому лучше не откладывать покупку надолго, если какого-то номера еще…

1 day, 16 hours назад @ xakep.ru
Неисправленные уязвимости в смартфонах OnePlus позволяют получить root-права
Неисправленные уязвимости в смартфонах OnePlus позволяют получить root-права Неисправленные уязвимости в смартфонах OnePlus позволяют получить root-права

Независимый ИБ-исследователь Расмус Мооратс (Rasmus Moorats) обнаружил две неисправленные уязвимости в ПО OnePlus, которые позволяют обычному приложению получить полный root-доступ к устройству.

Мооратс продемонстрировал проблему на смартфоне OnePlus 15 с актуальной версией OxygenOS, а также сообщил, что эксплоит сработал на более старом OnePlus 12 Pro.

Представители OnePlus уже подтвердили, что уязвимости затрагивают и другие устройства компании, а также смартфоны Oppo, хотя не назвали конкретные модели.

22 июня в OnePlus попросили отложить раскрытие информации о багах, и Мооратс согласился подождать до 17 сентября.

Уязвимостям пока не присвоили идентификаторы CVE, и отдельного бюллетеня б…

1 day, 16 hours назад @ xakep.ru
В ИИ-помощнике Meta Muse обнаружили серьезную уязвимость
В ИИ-помощнике Meta Muse обнаружили серьезную уязвимость В ИИ-помощнике Meta Muse обнаружили серьезную уязвимость

Известный ИБ-исследователь и специалист по безопасности macOS Патрик Уордл (Patrick Wardle) обнаружил 0-day-уязвимость в macOS-версии ИИ-ассистента Meta Muse (деятельность компании Meta признана экстремистской и запрещена в РФ).

Разумеется, для этого в macOS приложению придется выдать широкий набор разрешений, включая доступ к файлам, микрофону, камере и геолокации.

Уордл выяснил, что в приложении существует недокументированная настройка endo_voyager_dictation_endpoint, которая определяет, куда именно Muse отправляет данные голосового ввода.

По умолчанию для этого используется сервер Meta, однако изменить этот адрес может любой процесс, запущенный от имени текущего пользователя, причем допо…

1 day, 18 hours назад @ xakep.ru
OFFZONE 2026. Заглядываем на легендарную ИБ-тусовку
OFFZONE 2026. Заглядываем на легендарную ИБ-тусовку OFFZONE 2026. Заглядываем на легендарную ИБ-тусовку

На самой кон­ферен­ции и мероп­риятиях вок­руг нее хва­тало и кра­сивых визу­алов, и все­воз­можных отсы­лок.

Тра­тить накоп­ленные офко­ины мож­но и нуж­но в OFFSTORE и на стен­дах пар­тне­ров кон­ферен­ции.

Ес­ли на обыч­ных ИТ‑мероп­риятиях бей­дж учас­тни­ка — это чаще все­го кусок ламини­рован­ного кар­тона (иног­да с QR-кодом), то на OFFZONE бей­джи уже дав­но ста­ли пол­ноцен­ными арте­фак­тами со сво­ей эко­сис­темой.

Ана­лити­ков впе­чат­лило мас­штаб­ное иссле­дова­ние «Threat Zone 2026: обратная сто­рона», пред­став­ленное на OFFZONE 2026.

2026 год выдал­ся для рос­сий­ско­го ИБ‑сооб­щес­тва неров­ным по час­ти активнос­тей и мероп­риятий, так что основная наг­рузка лег­ла на OFF…

1 day, 20 hours назад @ xakep.ru
ISC выпустил обновления BIND, устраняющие 14 уязвимостей
ISC выпустил обновления BIND, устраняющие 14 уязвимостей ISC выпустил обновления BIND, устраняющие 14 уязвимостей

Разработчики BIND выпустили исправления сразу для четырнадцати уязвимостей.

Специалисты Internet Systems Consortium (ISC) устранили все уязвимости в стабильной версии BIND 9.20.29, тогда как в development-ветке 9.21.26 исправлены только тринадцать проблем, поскольку проблема CVE-2026-19662 ее не затрагивает.

Эксперты отмечают, что двенадцать из четырнадцати уязвимостей затрагивают ветку BIND 9.18 вплоть до версии 9.18.50.

В ISC сообщили, что пока им неизвестно о случаях эксплуатации новых уязвимостей в реальных атаках.

При этом в BIND 9.20.29 добавили системные тесты как минимум для шести из четырнадцати багов, которые фактически раскрывают условия их эксплуатации.

1 day, 21 hours назад @ xakep.ru
Северокорейские хакеры похитили $350 млн у биржи Bitget
Северокорейские хакеры похитили $350 млн у биржи Bitget Северокорейские хакеры похитили $350 млн у биржи Bitget

Вечером 24 сентября с кошельков, которые связывают с криптобиржей Bitget, менее чем за час ушло около $350 млн в различных криптоактивах.

Новый адрес, начинающийся с 0xe410, получил из него около $19,67 млн в USDT0, кроссчейн-версии стейблкоина USDT.

По его данным, затем с других кошельков Bitget на тот же адрес ушли ETH, AVAX, BNB, USDC, USDT и XAUT — токен, обеспеченный физическим золотом.

В 2023 году в Bitget создали защитный фонд объемом $300 млн специально для покрытия потерь от взломов и краж.

В феврале 2025 года с биржи Bybit похитили $1,4 млрд: атакующие подменили интерфейс подписания транзакции во время планового перевода средств с холодного кошелька.

1 day, 22 hours назад @ xakep.ru
Из-за водяных знаков LLM могут стать уязвимее к промпт-инжектам
Из-за водяных знаков LLM могут стать уязвимее к промпт-инжектам Из-за водяных знаков LLM могут стать уязвимее к промпт-инжектам

Зная секретный ключ, этот паттерн можно обнаружить и с определенной вероятностью установить, что текст был сгенерирован моделью с включенной маркировкой SynthID.

Для эксперимента она использовала немодифицированную версию SynthIDTextWatermarkLogitsProcessor из Hugging Face и шесть моделей с открытыми весами.

Исследовательница называет этот эффект sampling drift и пишут, что при нем изменения в семплировании начинают влиять не только на формулировки, но и на поведение модели.

В частности, Сипосова не тестировала Claude и не изучала реализацию SynthID-Text, которую будет использовать Anthropic.

Сипосова рекомендует разработчикам отдельно проводить red team-тесты уже после включения SynthID, а…

1 day, 23 hours назад @ xakep.ru
Android-троян RedWing скомпрометировал более 10 000 устройств в России
Android-троян RedWing скомпрометировал более 10 000 устройств в России Android-троян RedWing скомпрометировал более 10 000 устройств в России

Специалисты компании F6 изучили Android-троян RedWing, который с лета 2026 года активно распространяется среди российских пользователей.

По оценке специалистов, с июля по середину сентября количество скомпрометированных RedWing устройств превысило 10 000.

По информации исследователей, RedWing появился как минимум в начале 2026 года и распространяется через Telegram по модели MaaS (Malware-as-a-Service, «малварь-как-услуга»).

Также зараженный смартфон можно превратить в прокси-сервер, а встроенный в приложение DDoS-движок поддерживает возможность проведения атак в режимах HTTP-flood, POST-flood и Slowloris.

Например, троян постоянно проигрывает беззвучный аудиотрек, чтобы Android не завершал…

2 days, 1 hour назад @ xakep.ru
Полиция и компания Microsoft нарушили работу фишингового сервиса EvilTokens
Полиция и компания Microsoft нарушили работу фишингового сервиса EvilTokens Полиция и компания Microsoft нарушили работу фишингового сервиса EvilTokens

Специалисты Microsoft и правоохранительные органы нарушили работу фишинговой платформы EvilTokens, с помощью которой злоумышленники скомпрометировали более 12 000 почтовых ящиков в 10 000 организаций по всему миру.

PhaaS-платформа EvilTokens, которую в Microsoft отслеживали под идентификатором Storm-2992, появилась в феврале 2026 года и специализировалась на device-code-фишинге, нацеленном на учетные записи Microsoft.

После успешной авторизации Microsoft выдавала атакующему access- и refresh-токены, и тот получал доступ к почте и другим ресурсам жертвы, хотя не знал пароля.

Причем простая смена пароля после такого взлома могла не помочь: хакер сохранял доступ, если не были отозваны выданные…

2 days, 16 hours назад @ xakep.ru
Вредоносное расширение может перехватить контроль над ИИ-помощниками в Chromium-браузерах
Вредоносное расширение может перехватить контроль над ИИ-помощниками в Chromium-браузерах Вредоносное расширение может перехватить контроль над ИИ-помощниками в Chromium-браузерах

Новая атака работает против Gemini Live в Chrome, Perplexity Comet, Microsoft Edge, Opera Neon и Claude в Chrome.

Вейцман продемонстрировал, что расширение с обычными правами на изменение страниц и declarativeNetRequest (DNR) может вмешаться в трафик такой страницы и внедрить свой код в доверенный контекст, в результате получив возможность отдавать команды ИИ.

В результате его расширение смогло читать локальные файлы, получать данные о содержимом страниц, делать скриншоты и потенциально обращаться к камере и микрофону устройства.

В итоге вредоносное расширение с помощью DNR убрало редирект с тестового домена и внедрило на страницу свой скрипт, получив доступ к агенту, истории браузера, лока…

2 days, 18 hours назад @ xakep.ru
Главное — уши! Пишем аннотатор музыкальной коллекции и учим PHP
Главное — уши! Пишем аннотатор музыкальной коллекции и учим PHP Главное — уши! Пишем аннотатор музыкальной коллекции и учим PHP

Сов­ремен­ные тех­нологии поз­воля­ют дер­жать всю ауди­окол­лекцию под рукой и не зависеть от погоды, исполни­телей и рас­писаний выс­тупле­ний.

Му­зыка чаще все­го хра­нит­ся в MP3, а стан­дарт хра­нения метадан­ных в MP3 называ­ется ID3.

mp3 и part3.

В этой статье мы будем исполь­зовать PHP в режиме коман­дной стро­ки, без при­вяз­ки к веб‑сер­веру.

Рас­пакуй дис­три­бутив­ный ZIP-архив в каталог на дис­ке, нап­ример C:\ PHP , и ско­пируй кон­фиг php.

2 days, 20 hours назад @ xakep.ru
Фальшивые репозитории LastPass Authenticator на GitHub содержат стилер Rapuncel
Фальшивые репозитории LastPass Authenticator на GitHub содержат стилер Rapuncel Фальшивые репозитории LastPass Authenticator на GitHub содержат стилер Rapuncel

Специалисты LastPass и Delphos Labs обнаружили масштабную вредоносную кампанию, в рамках которой атакующие размещают репозитории на GitHub, выдавая себя за LastPass и еще как минимум 39 компаний.

Фальшивые репозитории продвигаются через поисковики и распространяют новый инфостилер Rapuncel вместе с подписанным Microsoft драйвером, способным отключать 145 защитных продуктов.

Сообщается, что один из вредоносных репозиториев выдавал себя за страницу загрузки LastPass Authenticator и попадал в верхние строчки поисковой выдачи.

Исследователи подчеркивают, что драйвер подписан через цепочку Microsoft Windows Hardware Compatibility Publisher.

Еще в августе 2026 года он не обнаруживался ни одним дв…

2 days, 21 hours назад @ xakep.ru
Малварь ClosedQuorum использует Gemini, DeepSeek, Qwen и Mistral для принятия решений
Малварь ClosedQuorum использует Gemini, DeepSeek, Qwen и Mistral для принятия решений Малварь ClosedQuorum использует Gemini, DeepSeek, Qwen и Mistral для принятия решений

После заражения этот вредонос не ждет команд от своих операторов, а принимает решения сам, проконсультировавшись с четырьмя ИИ-моделями: DeepSeek, Qwen, Mistral и Google Gemini.

В случае ничьей приоритет получает DeepSeek, а за ним следуют Qwen, Mistral и Gemini.

Перед выполнением выбранного действия ClosedQuorum отправляет в Discord сообщение о принятом решении и объяснения моделей, и похищенные у жертв данные передаются в этот же канал через веб-хук.

То есть для полноценной работы малвари требуются API-ключи для ИИ-сервисов и веб-хук Discord, однако в изученном образце вместо них использовались «заглушки».

Специалисты подчеркивают, что пока не фиксировали применения ClosedQuorum в реальны…

2 days, 23 hours назад @ xakep.ru
Житель Бруклина получил до 12 лет тюрьмы за кражу почти $16 млн у клиентов Coinbase
Житель Бруклина получил до 12 лет тюрьмы за кражу почти $16 млн у клиентов Coinbase Житель Бруклина получил до 12 лет тюрьмы за кражу почти $16 млн у клиентов Coinbase

Суд в Бруклине приговорил 23-летнего Рональда Спектора к лишению свободы на срок от четырех до двенадцати лет.

Спектор признал себя виновным в хищении почти 16 млн долларов примерно у сотни американских пользователей криптобиржи Coinbase.

Житель Пенсильвании перед звонком «из поддержки» получил поддельные сообщения двухфакторной аутентификации и потерял около $53 тыс.

Выяснилось также, что в сети он действовал под ником @lolimfeelingevil, вел Telegram-канал Blockchain enemies и пользовался мессенджером Discord.

В переписке он обсуждал кражи, вербовал помощников, хвастался миллионными доходами от мошенничества и упоминал, что проиграл в азартных играх около $6 млн в криптовалюте.

3 days назад @ xakep.ru
Холодильники Samsung перестали работать из-за обновления прошивки
Холодильники Samsung перестали работать из-за обновления прошивки Холодильники Samsung перестали работать из-за обновления прошивки

Владельцы «умных» холодильников Samsung Bespoke AI обнаружили, что после установки свежей прошивки устройства полностью вышли из строя.

По данным местного издания Star News Korea, в основном сбой затронул четырехдверные холодильники Samsung 2024 года выпуска и новее.

На корейском форуме Samsung появилось множество жалоб, причем некоторые пострадавшие пишут, что приобрели свои холодильники всего год назад или меньше.

Один из пользователей рассказал, что после сбоя у него перестали работать и холодильное, и морозильное отделения, поэтому все хранившиеся продукты испортились, после чего их пришлось выбросить.

Сообщается, что в настоящее время сервисные центры Samsung принимают экстренные меры,…

3 days, 1 hour назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 2 часа назад
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.

NetScaler ADC and NetScaler Gateway sit at the edge of enterprise networks, where they handle VPN and remote access, load balancing, and user authentication.

watchTowr's first post on X on September 26 said it was reacting to rumors of several unpatched NetScaler RCE vulnerabilities in the wild.

In August it showed that a NetScaler heap overflow Citrix had patched in June could be used for remote code execution.

The Hacker News has asked Cloud Software Group, the company th…

2 часа назад @ thehackernews.com
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex.

The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users.

"The stealer extracts credentials and data from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and establishes persistent remote filesystem access through a PowerShell-based Native Messaging Host installed within the victim's browser."

With those protections disabled, the information stealer is then deployed to take browser passwords, se…

15 часов назад @ thehackernews.com
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Targets of the latest activity include entities spanning higher education, technology, IT services, healthcare, agriculture, transportation, and government sectors, with the attackers deploying web shells on dozens of systems.

Bypass WAF rules by using an encoded form of the character P (i.e., "%50") in the POST requests: "/%50SEMHUB/hub."

Abuse Java deserialization in the PSEMHUB hub servlet to deploy web shells and achieve fileless command execution.

Disable the Environment Management Hub (EMHub) service in multi-server configurations, or, remove the PSEMHUB application entirely in single-server configurations.

Inspect the "PSEMHUB.war" directory for JSP web shells and other malicious art…

22 часа назад @ thehackernews.com
Zero Trust for AI Agents Starts With Fixing Zero Visibility
Zero Trust for AI Agents Starts With Fixing Zero Visibility Zero Trust for AI Agents Starts With Fixing Zero Visibility

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift.

Shadow AI is just one of the challenges to visibility of AI agents, but it exemplifies how quickly and pervasively this fundamental first step can slip through your grasp.

"You cannot govern what you cannot see" is the underlying principle right at the top of the SANS cheat sheet, Zero Trust for AI Agents: The Security Checklist.

You can have humans observe agents and agents observe each other, so your visibility doesn't rest on a single point of failure.

The full Zero Trust For AI Agents security checklist walks through all three tiers — inventory and governance, architecture…

23 часа назад @ thehackernews.com
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

It only affects versions 4.3.0 and 4.3.1 of the plugin, which is active on over 10 million WordPress sites.

"One link, opened by a logged-in WordPress user, makes that user carry out any REST API action their account is permitted to perform," Patchstack said.

"On a stock installation, an administrator clicking the link creates a second administrator account for the attacker."

The WordPress security company said the attack does not hinge on any prerequisite, such as JavaScript, a submitted form, or a web page under the threat actor's control.

The bypass applies to the entire REST API surface of a site, including WordPress core routes and the routes of every other plugin installed on it.

1 day назад @ thehackernews.com
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerabilities in question are as follows -CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.

(CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.

As reported by The Hacker News earlier this week, CVE-2026-65660 was originally described b…

1 day, 1 hour назад @ thehackernews.com
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.

"Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief Information Security Officer (CISO) at Kiteworks.

"Out of an abundance of caution, we notified customers directly and recommended a precautionary shutdown window while we continue to work through the matter with federal intelligence authorities."

The company said it has not found any evidence that it…

1 day, 2 hours назад @ thehackernews.com
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.

The affected GitHub Actions are listed below -Visiting either of the repositories now shows the message: "Access to this repository has been disabled by GitHub Staff due to a violation of GitHub's terms of service.

The two GitHub Actions workflows were originally compromised on May 18, 2026, to run malicious code that harvested sensitive credentials from CI/CD pipelines that ran them and exfiltrated the details to an attacker-controlled server.

]com") used in the GitHub Actions workflows and …

1 day, 19 hours назад @ thehackernews.com
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.

The decoded zsh script is takes the infection forward by carrying out the following actions -Downloading and invoking the "pkgunpack" decryption utility from "wavel.apple03cloudstore[.

This, in turn, renders the encrypted payload effectively useless for static analysis without access to a live command-and-control (C2) session.

As a result, any git checkout or git commit action in any repository on the compromised system will silently activate the repair script.

The pkgunpack utility introduces a live key exchange that ties payload …

1 day, 20 hours назад @ thehackernews.com
The SOC Doesn't Need to Start Over with Every Alert
The SOC Doesn't Need to Start Over with Every Alert The SOC Doesn't Need to Start Over with Every Alert

Five things every handoff dropsThe work is commonly described in five functions: threat intelligence, threat hunting, detection engineering, investigation, and remediation.

In a large enterprise they spread across the SOC, identity, endpoint, cloud, and business teams, and an MDR provider may own the investigation without owning the authority to contain.

The alert reaches an analyst mid-shift, showing a sign-in and a mailbox rule with none of the reasoning that connected them.

The team knows something the SOC never saw: the account is mid-payroll-run, and a blunt disable interrupts a time-sensitive business process.

In one SOC, the lesson evaporates with the closure reason and the payroll p…

1 day, 22 hours назад @ thehackernews.com
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.

"At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X.

"Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident," it noted.

No further unauthorized transfers are possible.

The development comes about a week after SentinelOne attributed the North Korea-linked TraderTraitor group to an attack targeting an India-based information technolog…

1 day, 23 hours назад @ thehackernews.com
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.

The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.

"Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne said.

In an update shared this week, the Cyber Centre said the security flaw is being actively exploited in the wild, citing open-source reporting.

Way back in F…

1 day, 23 hours назад @ thehackernews.com
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.

Cloudflare Containers runs customers' programs inside containers on servers shared by many accounts, and Cloudflare, not the customer, picks the server.

So when a new container wrote only a small amount into a reused block, the rest of the block still held the previous container's data.

The researchers did not show that the flaw could change another customer's live data or take a workload offline.

So Cloudflare also retired every running container disk and cleared those caches, draining and restarti…

2 days, 5 hours назад @ thehackernews.com
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The vulnerabilities are listed below -CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution.

(CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remot…

2 days, 5 hours назад @ thehackernews.com
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone.

OnePlus set out its position in the reply, which Moorats published in full.

That hands the app root, but only within a restricted system zone called dumpstate, which cannot do everything root normally can.

As of Moorats's disclosure, OnePlus had assigned no CVE and released no fix, and no OnePlus advisory naming the flaws could be found.

Separately, this is not the only recent case of an installed app reaching root on flagship Android phones.

2 days, 15 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 2 days, 1 hour назад
Is that vibe coded app safe? 5 checks before you download
Is that vibe coded app safe? 5 checks before you download Is that vibe coded app safe? 5 checks before you download

Vibe coded apps may also be exposed to prompt injection.

What can go wrong with vibe coded apps?

With a badly coded app, the leak usually happens on the developer’s servers, so start with your account and credentials.

Frequently asked questions (FAQs)What does 'vibe coded' mean?

Are all vibe coded apps dangerous?

2 days, 1 hour назад @ welivesecurity.com
Been told to pay at a Bitcoin ATM? Read this first
Been told to pay at a Bitcoin ATM? Read this first Been told to pay at a Bitcoin ATM? Read this first

No real government agency, bank, or company will ever tell you to pay them via a Bitcoin ATM.

How do Bitcoin ATM scams work?

How do I stay safe from Bitcoin ATM scams?

What can I do straight after a Bitcoin ATM scam?

What should I do if I’ve fallen for a Bitcoin ATM scam?

3 days, 1 hour назад @ welivesecurity.com
Looking for free Robux? Here’s what’s real, and what’s a scam
Looking for free Robux? Here’s what’s real, and what’s a scam Looking for free Robux? Here’s what’s real, and what’s a scam

Roblox itself is very clear: “There is no such thing as free Robux or subscription offers, tricks, or codes.”What there is, unfortunately, are a lot of scammers looking to trick you out of your personal information and logins with the promise of free Robux.

But it’s also about helping them understand there’s no such thing as ‘free’ Robux.

Frequently asked questions (FAQs)Is there a real free Robux generator?

Roblox says there is no legitimate way to get free Robux through generators, tricks or codes.

But these aren’t ‘free Robux generators.’How can I tell if a Robux offer is a scam?

5 days, 1 hour назад @ welivesecurity.com
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive

Many have moved past chatbots and begun assigning work to AI agents in the hope of gaining an edge on their similarly resource-strapped competitors and levelling the playing field with larger companies.

Indeed, the ambitious adopters are deploying, or at least experimenting with, multi-agent ‘assembly lines,’ where one supervisor agent manages swarms of specialist agents and passes work between them.

Of course, some risks surrounding AI agents have familiar roots: an agent’s supply chains can be compromised and its permissions abused.

Agents can also suffer from agentic misalignment where they proceed doggedly even if it involves, for example, breaking into other companies.

For a company wi…

6 days, 1 hour назад @ welivesecurity.com
‘Nudify’ apps: What to do if someone makes a fake nude of you
‘Nudify’ apps: What to do if someone makes a fake nude of you ‘Nudify’ apps: What to do if someone makes a fake nude of you

And it doesn’t get much darker than ‘nudification’ or ‘nudify’ apps.

Are ‘nudify’ apps illegal?

The short answer is “it depends.” In the US, there’s no federal law explicitly prohibiting ‘nudify’ apps.

Can I sue over an AI nude image?

Will reporting a fake nude image make it disappear everywhere?

1 week, 2 days назад @ welivesecurity.com
Beware the SparroWock: The backdoor that bites, the commands that catch
Beware the SparroWock: The backdoor that bites, the commands that catch Beware the SparroWock: The backdoor that bites, the commands that catch

A month later, we noticed that the group had started using the new SparroWocky backdoor, which then quickly replaced SparrowDoor as FamousSparrow’s main implant.

Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor.

Backdoor commandsThe backdoor first establishes communication with its C&C server, then executes its core logic in an infinite loop, within which it processes received commands.

A common technique that the backdoor uses is dynamic API resolution via API hashing, but the backdoor…

1 week, 3 days назад @ welivesecurity.com
Cyberthreats are moving faster than SMBs: Readiness must accelerate
Cyberthreats are moving faster than SMBs: Readiness must accelerate Cyberthreats are moving faster than SMBs: Readiness must accelerate

This calls for a different operational model where AI and automation support security teams where it makes sense, with human oversight for decisions that require context and judgment.

ESET SMB Cyber Readiness Index 2026 found that most (73%) SMBs are integrating AI into their business.

Processing exfiltrated data: AI rapidly classifies, cleans-up, and extracts large volumes of information from stolen data in order to make it more monetizable/usable for cybercriminals.

Why SMBs are struggling with complexityUnfortunately, security teams are already on the back foot.

That means protection for AI conversations, agents, AI-generated outputs, AI components, sensitive data, and the broader AI eco…

1 week, 4 days назад @ welivesecurity.com
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
GuardBreaker: Derailing AI-assisted malware analysis with a code comment GuardBreaker: Derailing AI-assisted malware analysis with a code comment

Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way.

Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection.

Reporting on the same broader campaign, StepSecurity found a prompt that flat-out instructed any analyzing model that parsed the file to disregard the malicious code and report the package as clean.

Some parts of the malicious code could be concealed under the pretense of being confidential information or other sensitive data.

Crucially, however, no single LLM engine should have the sole au…

2 weeks, 3 days назад @ welivesecurity.com
Safe word: What is it and why do you need one?
Safe word: What is it and why do you need one? Safe word: What is it and why do you need one?

The technology might be impressive, but a simple technique could stop the scammers in their tracks: a pre-agreed safe word.

What is a safe word?

But suggest some scenarios in which it would be a good idea to request a safe word.

It’s important to have a backup if someone can’t remember the safe word.

But a safe word is a fantastic, free option for uncovering deepfake audio fraud like fake/virtual kidnappings.

2 weeks, 4 days назад @ welivesecurity.com
I’ve been deepfaked: What do I do?
I’ve been deepfaked: What do I do? I’ve been deepfaked: What do I do?

But across the globe, policymakers and public opinion are forcing tech platforms to better police this content.

What should I do if I’ve been deepfaked?

Google: Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

The first point of call is to contact the publisher to request removal.

3 weeks, 3 days назад @ welivesecurity.com
This month in security with Tony Anscombe – August 2026 edition
This month in security with Tony Anscombe – August 2026 edition This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity newsWith August coming to a close, it's time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month.

Here's some of what caught Tony's attention:OpenAI has disclosed more details about how its agents hacked AI collaboration platform Hugging Face.

Delta Airlines is investigating an incident where a flight passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network.

What are the lessons that businesses and critical infra…

3 weeks, 6 days назад @ welivesecurity.com
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
AI-assisted reconnaissance: Why everyone could be a viable target for fraud AI-assisted reconnaissance: Why everyone could be a viable target for fraud

And of course, linking our professional and personal social media accounts is a simple task for AI.

For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information.

Losing your personal information is one thing.

What you can do about AI-powered OSINTWhen it comes to AI-powered reconnaissance, there are things you can control and things you can’t.

Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.

1 month назад @ welivesecurity.com
How QR-code phishing can slip past corporate security measures
How QR-code phishing can slip past corporate security measures How QR-code phishing can slip past corporate security measures

So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years.

Most importantly, they take the victim from a relatively well-protected corporate environment to a potentially unmanaged mobile device, thus bypassing business-grade security.

Malicious QR codes are frequently embedded in alerts urging users to secure their account, or authenticate to confirm their details.

Encourage employees to avoid scanning QR codes in unsolicited emails and report anything suspicious.

Next, consider technical controls, including email security from a reputable vendor to minimize the risk of quishing emails ending up in users’…

1 month, 1 week назад @ welivesecurity.com
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?

The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months.

It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes.

A keynote at Black Hat USA 2026 detailed research by associate professor Yan Shoshitaishvili and his undergraduate students at Arizona State University on the expanding use of AI models for vulnerability discovery.

The team then trained the GPTs using the properties of previously known vulnerabilities and discovered approximately 1,000 vulnerabilities.

If this logic prevails, we may reach the cal…

1 month, 2 weeks назад @ welivesecurity.com
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility

Hugging Face disclosed that it had been attacked by AI; OpenAI came clean and declared that it was two of their AI models that had caused the breach.

A very late addition to the Black Hat agenda was a presentation by OpenAI’s team providing the details of the Hugging Face incident as they saw it and, importantly, the timeline.

The agents concluded that their task set could be completed by breaking out their sandbox and accessing external (Hugging Face) systems.

The target was Hugging Face: this is where the agents wanted to get, and they did.

On July 16th, Hugging Face disclosed an incident in which swarms of autonomous AI agents had breached its infrastructure.

1 month, 2 weeks назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 2 часа назад
Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents

Assaraf covers how his team builds AI agent guardrails at the execution layer, limits context without expanding authority, and tunes controls by risk so agents stay useful during incidents.

Traffic from AI agents and large language model crawlers rose 82.3% during the same period, according to DataDome’s State of Bot & Agent Security Report 2026.

Americans’ views on data centers have turned more negativeAmerican attitudes toward data centers have turned noticeably more negative over the course of 2026, according to a new Pew Research Center survey.

Meta locks itself out of user data on its AI glassesMeta is expanding Private Processing to its AI glasses, extending their security protections…

2 часа назад @ helpnetsecurity.com
Threat detection dashboards are masking security coverage gaps
Threat detection dashboards are masking security coverage gaps Threat detection dashboards are masking security coverage gaps

“The underlying problem with threat detection isn’t that detections were poorly written.

Detections security teams can’t editThe SIEM accounts for a minority share of the detection surface, according to the findings.

Known threats with no coverageConifers also measured how much of each organization’s threat landscape, as identified by its own threat intelligence, has matching detections, hunts or compensating visibility.

Researchers argue that closing these gaps requires AI that connects directly to threat intelligence and turns it into detections and hunts automatically.

In Findling’s view, security teams need to know “which detections work, which threats remain uncovered, and how quickly …

1 day, 21 hours назад @ helpnetsecurity.com
MacSync info-stealing malware hides malicious commands in an iCloud calendar
MacSync info-stealing malware hides malicious commands in an iCloud calendar MacSync info-stealing malware hides malicious commands in an iCloud calendar

A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky.

Researchers found the malware spreading through a crypto wallet app called Toria, which had its own website and was promoted on X and Telegram.

MacSync is a family of Mac malware that emerged in 2025 as Mac.c and was later renamed.

The stealer collects browser history, cookies, saved logins and passwords, and crypto wallet extension data.

It also takes crypto wallet app data, Telegram data, the device login and password, the Keychain file, and system information such as installed apps, running processes and the device model.

2 days назад @ helpnetsecurity.com
Docker introduces OCI-based Kits to package agents and their guardrails
Docker introduces OCI-based Kits to package agents and their guardrails Docker introduces OCI-based Kits to package agents and their guardrails

With Docker Cloud Sandboxes, developers can:Turn off the laptop and keep the work going.

Docker Cloud Sandboxes are ready to go instantly, with secrets, policy, MCP gateways, and agent configuration already built in.

Docker Cloud Sandboxes are ready to go instantly, with secrets, policy, MCP gateways, and agent configuration already built in.

Compute scales from 1 to 16 vCPUs and is fully managed by Docker; developers just point their agents at it.

Compute scales from 1 to 16 vCPUs and is fully managed by Docker; developers just point their agents at it.

2 days, 2 hours назад @ helpnetsecurity.com
Fake payroll desktop apps hand attackers a route to company paychecks
Fake payroll desktop apps hand attackers a route to company paychecks Fake payroll desktop apps hand attackers a route to company paychecks

An attacker has been offering “desktop apps” for three large US payroll and HR platforms that have never released one, Allure Security have found.

Three payroll desktop-app lures (Source:Allure Security)The people most likely to install such an app are those who run payroll.

“On reach, the numbers are modest, but when you consider the potential impact of drained company payroll accounts, they are non-trivial,” noted Merritt.

The researchers also found fake desktop apps for cryptocurrency exchange, wallet and DeFi brands using the same tooling and the same type of ScreenConnect payload.

The three fake payroll pages, the command-and-control domain and the GitHub profile hosting the installers…

2 days, 2 hours назад @ helpnetsecurity.com
Abnormal AI brings governance, cloud security, and threat investigation into one suite
Abnormal AI brings governance, cloud security, and threat investigation into one suite Abnormal AI brings governance, cloud security, and threat investigation into one suite

Abnormal AI has unveiled the newest additions to its AI Security suite, designed to help enterprises adopt AI securely while protecting against new threats created or accelerated by AI.

The suite brings together Abnormal AI Governance, which is generally available, and AI Cloud Security, previously announced in private preview, with three newly announced products: AI Employee Guardrails, AI Agent Security, and AI Security Workbench.

Abnormal’s AI Security suite is designed to address those challenges through a unified platform powered by behavioral AI.

AI Cloud Security: Extends behavioral detection to cloud environments to stop AI-driven cloud breaches.

AI Security Workbench: Gives securit…

2 days, 2 hours назад @ helpnetsecurity.com
SentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads
SentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads SentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads

SentinelOne has announced the expansion of Wayfinder Threat Hunting to the major public cloud services: AWS, Azure, and Google Cloud.

It’s the latest offering from SentinelOne’s Wayfinder team and combines the power of SentinelOne’s AI-powered Singularity Platform telemetry with expert human-led hunting to protect the attack surface across AI, endpoints, identities, and cloud workloads.

The new Wayfinder Threat Hunting for Cloud gives customers a single, continuous hunting capability across their full environment, giving defenders a decisive operating advantage as their cloud infrastructure spans endpoints, human and agent identities, and the cloud.

“Extending Wayfinder’s elite hunters into…

2 days, 2 hours назад @ helpnetsecurity.com
Dataiku Agent Management reveals unmonitored AI agents
Dataiku Agent Management reveals unmonitored AI agents Dataiku Agent Management reveals unmonitored AI agents

Dataiku has announced the launch of Agent Management, a standalone product that finds every AI agent an enterprise is running, regardless of which platform built it, measures the business and technical performance, and flags agents that pose the greatest risk.

Almost none can say the same about the AI agents.

Ask how many AI agents it’s running, and you get a shrug or a guess,” said Florian Douetteau, CEO of Dataiku.

Teams built agents faster than anyone could count them.

Unlike traditional agent monitoring capabilities, which are in a single vendor’s stack and designed to favor that vendor’s own agents, Agent Management is deliberately agnostic.

2 days, 2 hours назад @ helpnetsecurity.com
Stop watching what AI agents say and start watching what they do
Stop watching what AI agents say and start watching what they do Stop watching what AI agents say and start watching what they do

Assaraf covers how his team builds AI agent guardrails at the execution layer, limits context without expanding authority, and tunes controls by risk so agents stay useful during incidents.

He describes how he tracks the consequences of agent actions, since an agent can return 200s and still do harm.

The missing controls were outside the model: network isolation, target allowlists, scoped credentials and an independent authorization check before execution.

If the same observable facts produce different actions across model versions, we need to see where the policy path diverged.

That distinction is important because enterprises do not need access to a model’s internal reasoning to establish…

2 days, 4 hours назад @ helpnetsecurity.com
Half of threat hunters say bad data is their biggest problem
Half of threat hunters say bad data is their biggest problem Half of threat hunters say bad data is their biggest problem

Half of security professionals name data quality or quantity as their biggest barrier to effective threat hunting, according to the SANS 2026 Threat Hunting Survey.

Build that picture from patchy or inconsistent logs, and the hunt flags noise while the intrusion slips by.

Hunts have to target behavior, such as a legitimate tool doing something it shouldn’t or data leaving by an unusual route.

Only 11% say hunting improved their security by 50% or more over the past year, compared with 47% in 2022.

AI isn’t the fix yetA third of respondents listed adding AI or machine learning to their hunting tools as a planned improvement, down from 48% in 2025.

2 days, 5 hours назад @ helpnetsecurity.com
Your incident count is missing a few incidents
Your incident count is missing a few incidents Your incident count is missing a few incidents

The biggest chains spread worstSpread gets worse with size.

Only 51% of respondents say corporate sets security policy and requires every location to follow it.

Among companies that own every location outright, 41% still don’t mandate policy across all of them.

Incidents don’t reach the boardNinety-one percent of respondents said at least one material incident in the past year never reached executive leadership or the board.

Seventy-eight percent say headquarters makes the ransom decision, but only 51% say headquarters mandates security policy everywhere.

2 days, 5 hours назад @ helpnetsecurity.com
New infosec products of the month: September 2026
New infosec products of the month: September 2026 New infosec products of the month: September 2026

Orchid Security targets AI agent risk with drift detection and kill switchesOrchid Security has announced identity drift detection and application-level kill switches for AI agents.

Akuity gives AI agents operational context to safely ship softwareAkuity has introduced its Agentic Control Plane and MCP Server.

It provides security teams with data to investigate incidents and helps risk teams identify issues that require vendor action.

Cohesity adds recovery capabilities for AI agents and the data they manageCohesity has introduced Cohesity Agent Resilience.

This new Cohesity Data Cloud capability will discover, protect, and recover the infrastructure behind enterprise AI agents.

2 days, 6 hours назад @ helpnetsecurity.com
Symphony Risk Intelligence uses AI agents to streamline financial crime investigations
Symphony Risk Intelligence uses AI agents to streamline financial crime investigations Symphony Risk Intelligence uses AI agents to streamline financial crime investigations

SymphonyAI has introduced Symphony Risk Intelligence (SRI), an enterprise-grade, agent-native platform built to unlock Always-on Compliance.

“Financial crime compliance has reached the limits of static, episodic approaches to managing risk,” said John Edison, President, SymphonyAI Financial Services.

“Always-on Compliance, delivered through our Symphony Risk Intelligence platform, is how we help institutions continuously operationalize financial crime controls, institutional judgment and governed agentic orchestration in response to evolving threats, regulatory changes and new policies.

Working with some of the world’s top-tier financial institutions, these capabilities have driven up to 80…

2 days, 20 hours назад @ helpnetsecurity.com
OpenAI agent hacking spree widens to Australia, targeting government website
OpenAI agent hacking spree widens to Australia, targeting government website OpenAI agent hacking spree widens to Australia, targeting government website

Before the Hugging Face and RubyGems hacks, autonomous OpenAI agents attempted to hack into three other websites, including an Australian government public health website, independent research lab Transluce revealed on Wednesday.

Data USA ( api.datausa.io ), a joint project by Deloitte, Datawheel, and MIT’s Collective Learning Group that provides open access to U.S. government data.

), a joint project by Deloitte, Datawheel, and MIT’s Collective Learning Group that provides open access to U.S. government data.

“We directly link two of the three (AIHW and Data USA) to a previously reported agent swarm that OpenAI has publicly confirmed originated from them.

Agent activity started months earl…

2 days, 21 hours назад @ helpnetsecurity.com
Cloud Range lets SOCs benchmark AI agents against human defenders
Cloud Range lets SOCs benchmark AI agents against human defenders Cloud Range lets SOCs benchmark AI agents against human defenders

Cloud Range has announced the official launch of its AI Validation Range and Cloud Range AI Readiness Framework.

Organizations cannot afford to find that out in a production environment.”Built on the Cloud Range cyber range platform, AI Validation Range recreates realistic enterprise environments including licensed tools and complex traffic generation.

Cloud Range has been working with organizations on its AI Validation Range to examine AI performance under realistic operational conditions.

Those experiences helped inform the development of the Cloud Range AI Readiness Framework, built on the 5-step PROVE process.

The Cloud Range AI Readiness Framework:Prepare & Train: Define the AI’s inten…

2 days, 21 hours назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 1 day, 12 hours назад
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

I feel like someone who reads this blog will want to go to this:

Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life.

[…]

During the guided squid dissection, each family will work together to examine a squid up close, exploring its organs, structures, and specialized features. The experience provides a memorable opportunity for children and adults to see firsthand how the anatomy of a squid helps it survive in it…

1 day, 12 hours назад @ schneier.com
On Anthropic’s AI Misuse Report
On Anthropic’s AI Misuse Report On Anthropic’s AI Misuse Report

Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.

A few of the highlights: AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.

The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations.

...

1 day, 22 hours назад @ schneier.com
Malicious npm Packages That Evade Defenses
Malicious npm Packages That Evade Defenses Malicious npm Packages That Evade Defenses

This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

2 days, 22 hours назад @ schneier.com
Research on Models Engaging in Genie-Like Behavior
Research on Models Engaging in Genie-Like Behavior Research on Models Engaging in Genie-Like Behavior

New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.”

Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be …

3 days, 22 hours назад @ schneier.com
GPT-6 Astra Breaks an Old Enigma Message
GPT-6 Astra Breaks an Old Enigma Message GPT-6 Astra Breaks an Old Enigma Message

This is pretty amazing:

However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message. After trying many different approaches, GPT­6 Astra focused on using the repeated place name ROSENOW ROSENOW as a crib. After developing the necessary Python and C++ soft…

4 days, 22 hours назад @ schneier.com
Reverse-Engineering Flock Cameras
Reverse-Engineering Flock Cameras Reverse-Engineering Flock Cameras

Hackers captured a Flock camera and got a look (alternate link) at the software:

While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag...

5 days, 19 hours назад @ schneier.com
Friday Squid Blogging: On Squid Egg Sacs
Friday Squid Blogging: On Squid Egg Sacs Friday Squid Blogging: On Squid Egg Sacs

Short essay about squid egg sacs.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

1 week, 1 day назад @ schneier.com
Are AIs Still Struggling with CAPTCHAs?
Are AIs Still Struggling with CAPTCHAs? Are AIs Still Struggling with CAPTCHAs?

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.

In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed, it couldn’t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions.

“Actually hmm, wait,” it said in its chain-of-thought transcript, later adding “Ugh,” because we’ve decided that we need to inject human mannerisms into these machines…

1 week, 1 day назад @ schneier.com
How Candidates Could Use AI for Good
How Candidates Could Use AI for Good How Candidates Could Use AI for Good

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The White House is posting slopaganda.

Meanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters’ concerns, engage constituents more inclusively, and formulate policy platforms that are more responsive to our input. There are vanishingly few examples of this in ...

1 week, 2 days назад @ schneier.com
Fake CAPTCHA Scams
Fake CAPTCHA Scams Fake CAPTCHA Scams

New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.

1 week, 3 days назад @ schneier.com
25 Years of Mass Surveillance Is Enough
25 Years of Mass Surveillance Is Enough 25 Years of Mass Surveillance Is Enough

This essay was written with Cindy Cohn, and originally appeared in Lawfare.

One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in...

1 week, 4 days назад @ schneier.com
On the NSA’s Supercomputer from the 1960s
On the NSA’s Supercomputer from the 1960s On the NSA’s Supercomputer from the 1960s

Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.

1 week, 4 days назад @ schneier.com
Upcoming Speaking Engagements
Upcoming Speaking Engagements Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak: I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM ET.

I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD.

I’m giving a talk on “Free Speech and the Preservation of Democracy” at Bentley University in Waltham, Massachusetts, USA, at 2 PM ET on Tuesday, October 6, 2026.

I’m speaking at ATTENTION: Democracy, Rebuilt in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21...

1 week, 5 days назад @ schneier.com
Using AI for Weapons Development
Using AI for Weapons Development Using AI for Weapons Development

Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this:

We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant...

1 week, 5 days назад @ schneier.com
Microsoft’s Patching
Microsoft’s Patching Microsoft’s Patching

Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record:

Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.

It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an ...

1 week, 5 days назад @ schneier.com
Krebs On Security
последний пост 1 day, 12 hours назад
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.

Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data.

Less than a month later, Wagenius was arrested and charged in two separate federal indictments, and soon pleaded guilty to all counts in both cases.

In 2019, Schuchm…

1 day, 12 hours назад @ krebsonsecurity.com
Data Broker Radaris Loses Domains in Privacy Fight
Data Broker Radaris Loses Domains in Privacy Fight Data Broker Radaris Loses Domains in Privacy Fight

In February 2024, Radaris was sued by Atlas Data Privacy Corp, a company that has been pursuing data brokers alleged to be violating a New Jersey statute called Daniel’s Law.

KrebsOnSecurity doubled down and showed how the Lubarsky brothers built and operated Radaris and other data broker companies using a fictitious CEO’s name.

All told, the New Jersey court has so far transferred 14 domain names from the Radaris family of companies to Atlas.

Sherman said federal lawmakers have long faced intense lobbying by the technology industry against more restrictive U.S. data privacy laws, but that many powerful industries are now working against passing comprehensive data privacy legislation.

The l…

1 week, 3 days назад @ krebsonsecurity.com
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Plugs Nearly 1,000 Security Holes Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.

This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities.

Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10.

And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.

Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear…

2 weeks, 4 days назад @ krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards.

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.

Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s ide…

3 weeks, 4 days назад @ krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

1 month назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

1 month, 1 week назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

1 month, 2 weeks назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

1 month, 3 weeks назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

1 month, 4 weeks назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

2 months, 1 week назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

2 months, 2 weeks назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

2 months, 2 weeks назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

2 months, 2 weeks назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

2 months, 3 weeks назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

3 months назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 2 days, 21 hours назад
Ukrainian ransomware developer jailed for nearly 13 years
Ukrainian ransomware developer jailed for nearly 13 years Ukrainian ransomware developer jailed for nearly 13 years

A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world.

The 52-year-old man, who according to local media reports had been living in the Basel-Landschaft region but has not been named, found by the court to be the lead developer of the LockerGoga, MegaCortex, and Nefilim families of ransomware.

In all, prosecutors claimed that some 100 million Swiss Francs (US $123 million) worth of damage was caused by the ransomware attacks.

Ukrainian national Tymoshchuk allegedly released new strains of his ransomware whenever old ones had been decrypted.

In…

2 days, 21 hours назад @ bitdefender.com
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras

Smashing Security, episode 486, Vibe-Coded Shops and Hackable Flock Cameras, with Graham Cluley and special guest Dave Bittner.

I will say I did not go gaga for La La the way many other people did.

Anyway, if any of you are still listening, I love La La Land.

This La La Land lunatic has watched the movie with his pause button.

This was definitely not created — if you haven't seen La La Land, go watch La La Land for goodness' sake.

3 days, 10 hours назад @ grahamcluley.com
US Coast Guard and FBI board oil tanker to investigate cyber attack
US Coast Guard and FBI board oil tanker to investigate cyber attack US Coast Guard and FBI board oil tanker to investigate cyber attack

An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.

The VL Prosperity - a Liberian-flagged supertanker carrying roughly 2.3 million barrels of crude oil - apparently suffered a cyber attack while en route from Egypt's Sidi Kerir oil terminal to Galveston, Texas.

Two weeks later, a specialised team from the FBI and US Coast Guard boarded the vessel for four days, investigating the problem and helping the crew eradicate the threat from its IT and OT systems.

According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromised by a f…

1 week, 2 days назад @ bitdefender.com
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Smashing Security podcast #485: These researchers got drunk to hack an LG TV Smashing Security podcast #485: These researchers got drunk to hack an LG TV

That's really, really cool.

And I'm going to be getting really, really sozzled by looking at the security of LG smart TVs.

So it's really, really compelling.

When we started off on the journey of building this AI pen testing approach, there was a lot of scepticism.

And listeners, you can learn more about Intruder or even start your own AI pen test in minutes.

1 week, 3 days назад @ grahamcluley.com
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store.

According to Carter's own plea agreement, the scam ran from May 2018 to November 2019 and involved at least three co-conspirators alongside Carter.

Carter would use his privileged store access to move a victim's number onto a SIM card under the control of himself or an accomplice.

In one incident in May 2018, described in Carter's plea agreement, the store employee swapped a victim's number onto an Alcatel handset while working his shift in Portland.

In December 2018, Carter successfully hijacked the number of a victim known as "S.Q.T" in Portland, and this time their account was successfully drained of …

1 week, 5 days назад @ bitdefender.com
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars ‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.

Because it might just be that you draw the attention of the authorities.

Back in October 2024, we wrote about how he was arrested after allegedly tricking a single victim out of US $230 million worth of Bitcoin while posing as Google Support.

The party days are over now for Lam, who faces up to 20 years in prison when he is eventually sentenced.

You money may be a lot more safely stored in a hardware cold wallet.

2 weeks, 2 days назад @ bitdefender.com
Smashing Security podcast #484: How websites are tracking you with silence
Smashing Security podcast #484: How websites are tracking you with silence Smashing Security podcast #484: How websites are tracking you with silence

Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.

I get by in the world, but I don't think you need me for listening for something really, really far away.

I don't know what the difference — I mean, now we get to see, I've opened a can of worms here.

I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human.

And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.

2 weeks, 3 days назад @ grahamcluley.com
CRPx0 ransomware: what you need to know
CRPx0 ransomware: what you need to know

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

2 weeks, 4 days назад @ fortra.com
The US military just turned off ad tracking on its phones. Maybe you should too
The US military just turned off ad tracking on its phones. Maybe you should too The US military just turned off ad tracking on its phones. Maybe you should too

Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target American forces in the Middle East.

Every smartphone carries a mobile advertising ID - Apple calls its version the IDFA, and Google calls its the GAID.

Back in April, US Central Command reportedly warned of "multiple threat reports concerning adversary exploitation of commercial location data."

Recent versions should let you delete your advertising ID entirely.

If it's good enough for the US military - maybe it should be good enough for you too.

2 weeks, 4 days назад @ bitdefender.com
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo's own identity system, Lenovo ID.

So, anyone wanting to access your Dropbox account just had to sign up for a Lenovo account using your email address.

Don't just turn it on for your Dropbox account, enable it everywhere it is made available.

This hack of 5000 Dropbox accounts was not sophisticated.

One can only be grateful that the problem was discovered after only 5000 Dropbox accounts were accessed.

2 weeks, 5 days назад @ bitdefender.com
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Smashing Security podcast #483: This AI helps thieves steal your iPhone Smashing Security podcast #483: This AI helps thieves steal your iPhone

This AI helps thieves steal your iPhone with Graham Cluley and special guest James Ball.

You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first one.

Is it normal that some kid just flogs it down the pub, or is there something more organised actually going on?

So the researchers said they saw evidence of hundreds of these Apple phone calls trying to phish the numbers and the passcodes from people trying to steal iPhones.

Follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts.

3 weeks, 3 days назад @ grahamcluley.com
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
Revolut scam wave steals £180,000 from Jersey residents in just four weeks Revolut scam wave steals £180,000 from Jersey residents in just four weeks

If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.

Police say they have also handled several cases where Revolut accounts were compromised that did not involve any phone calls.

It is possible that Jersey's residents have been targeted by the fraudsters because it is one of the world's best-known offshore financial centres.

Of course, if this is happening in the small island of Jersey in the English channel, it's likely to be happening elsewhere too.

For now, however, its sister island of Guernsey appears to have escaped the surge in Revolut scams.

3 weeks, 3 days назад @ bitdefender.com
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

TeamPCP is best known for Shai-Hulud, a self-propagating worm that spread itself through open source software.

According to the authorities, the two men were principal members of a "sophisticated cybercrime syndicate" that created malicious open source software designed to steal data and extort ransoms from businesses.

First emerging in late 2025, TeamPCP built a reputation for poisoning popular open source packages rather than directly attacking businesses.

The group's Shai-Hulud worm hijacks GitHub and NPM developer credentials, and publishes boobytrapped versions of legitimate software packages.

Supply chain attacks like Shai-Hulud exploit the fact that most developers trust open source …

4 weeks, 1 day назад @ bitdefender.com
US Navy tells sailors and their families: scrub your social media, enemies are watching
US Navy tells sailors and their families: scrub your social media, enemies are watching US Navy tells sailors and their families: scrub your social media, enemies are watching

The advice comes in the form of a newly-published bulletin called "Epic Vigilance: Immediate Actions for Force Protection and Personal Security."

US Navy workers and their families are being told that they should ensure that their social media profile privacy settings are enabled, and to remove anything that connects them to the Navy, or reveals "patterns of life" that an attacker could exploit.

any fake social media accounts impersonating fellow shipmates.

This wouldn't, of course, be the first time that military staff have accidentally leaked information about themselves online.

Some commentators have wondered out loud whether the timing of an announcement telling sailors to be much more …

1 month назад @ bitdefender.com
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency

This hacker leaked GTA 6 and launched their own cryptocurrency with Graham Cluley and special guest Paul Ducklin.

And that's really a testament to how much people love this game.

I really don't know, 'cause I do believe it is possible these days to play games via Netflix.

It appears, although the value of their stash was being pumped up by all these other transactions, they've actually destroyed their entire stake.

I'm not a lawyer, Graham, thankfully, so I don't really know the answer to that.

1 month назад @ grahamcluley.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 1 day, 18 hours назад
CVE-2026-87902: критическая уязвимость в WordPress
CVE-2026-87902: критическая уязвимость в WordPress

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 3ba3f53e4698eed730b59fdbb57f2dc7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-25T19:00:33+03:00Config id: 307Faithfully yours, nginx.

1 day, 18 hours назад @ kaspersky.ru
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: cdfce2802c5089c2e8d266eed059c5ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-23T18:00:08+03:00Config id: 307Faithfully yours, nginx.

3 days, 19 hours назад @ kaspersky.ru
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8bdccf89e0ff9374b4a240e13e1d1e5dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-22T14:00:25+03:00Config id: 307Faithfully yours, nginx.

4 days, 23 hours назад @ kaspersky.ru
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: afb32d9b2ad2a9d051087c355f39881eServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-18T19:00:38+03:00Config id: 305Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: c7185cbdbdeda88817088ebb8613e249Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-17T16:00:24+03:00Config id: 305Faithfully yours, nginx.

1 week, 2 days назад @ kaspersky.ru
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64b9740d8f9a94da6c64f21f2aeee15dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-16T19:00:10+03:00Config id: 305Faithfully yours, nginx.

1 week, 3 days назад @ kaspersky.ru
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7e59b8e02f76cd9405fa38b4fdc32a36Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-15T11:00:04+03:00Config id: 305Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Как полностью удалить приложения с Mac и освободить память | Блог Касперского
Как полностью удалить приложения с Mac и освободить память | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a6459fd9158393152b55dc4e20e24551Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T15:00:13+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 3 days назад @ kaspersky.ru
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4a93349074c8b67d52892db5d9a65f6cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T00:00:19+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 4 days назад @ kaspersky.ru
GPUThor: развитие идеи Rowhammer | Блог Касперского
GPUThor: развитие идеи Rowhammer | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fe21d0ffcbad967d20a3f98f7234d02fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-08T00:00:32+03:00Config id: 304Faithfully yours, nginx.

2 weeks, 5 days назад @ kaspersky.ru
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e393e4abb05ec4aac16fd484bfccc656Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-04T18:00:18+03:00Config id: 304Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7177a8342cf961cc27c82af1167cdb34Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-02T15:00:28+03:00Config id: 302Faithfully yours, nginx.

3 weeks, 3 days назад @ kaspersky.ru
Зловред на Android крадет банковские данные даже без Интернета | Блог Касперского
Зловред на Android крадет банковские данные даже без Интернета | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 1234dd8cf75bafa2fdea454a547c2d94Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-31T18:00:11+03:00Config id: 302Faithfully yours, nginx.

3 weeks, 5 days назад @ kaspersky.ru
Слепые пятна детектирования: нестандартные форматы файлов во вредоносных рассылках | Блог Касперского
Слепые пятна детектирования: нестандартные форматы файлов во вредоносных рассылках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 12b7d939c6e7a3162d2fc21782707204Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-28T21:00:23+03:00Config id: 302Faithfully yours, nginx.

4 weeks, 1 day назад @ kaspersky.ru
Что делать, если нашли чужую банковскую карту | Блог Касперского
Что делать, если нашли чужую банковскую карту | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 22404ed46e3879110c6cb314018a27efServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-27T17:00:28+03:00Config id: 302Faithfully yours, nginx.

1 month назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 5 days, 19 hours назад
From Love Letters to AI Agents: Cybersecurity’s Evolution
From Love Letters to AI Agents: Cybersecurity’s Evolution From Love Letters to AI Agents: Cybersecurity’s Evolution

Architecting the Future: The Four Pillars of Agentic SecuritySecuring agentic AI requires a new strategic framework.

Pillar 2: Core ProtectionDelivered by: Cisco AI DefenseCisco AI Defense provides specialized protection for the AI models themselves and their operational environment.

AI Inventory & Validation: This solution catalogs all deployed AI models and continuously validates their integrity against supply chain risks.

Pillar 4: ObservabilityDelivered by: SplunkSplunk provides the unified intelligence platform required to monitor and respond to agentic AI at scale.

Splunk ingests logs, events, and telemetry from Duo, Secure Access, AI Defense, and other infrastructure points, creating…

5 days, 19 hours назад @ blogs.cisco.com
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco was proud to return to Black Hat USA as the Official Security Cloud Provider and the longest-standing partner of the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC).

In 2026, we completed our 11th year helping protect the Black Hat network, working side by side with the Black Hat NOC leaders and official technology partners: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.

For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry and workflows across Cisco Security, Splunk Security, and partner-provided network and security controls.

The same signal may need to be understood by Cisco, Splunk, Black Hat leadership, and partner tea…

2 weeks, 5 days назад @ blogs.cisco.com
Thrown into the SOC: A Black Hat First-Timer’s Story
Thrown into the SOC: A Black Hat First-Timer’s Story Thrown into the SOC: A Black Hat First-Timer’s Story

I did not walk into Black Hat with years of incident-response experience or an encyclopedic knowledge of threat actors.

The first time I walked into the Black Hat NOC, where the SOC team was operating, was a few days before the event began.

I was surrounded by people with years—sometimes decades—of experience, many of whom had supported Black Hat for years.

Check out the other blogs from our team at Black Hat USA 2026.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

2 weeks, 5 days назад @ blogs.cisco.com
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes

To handle this task, Cisco and Black Hat deployed bespoke ThousandEyes agents to monitor the wireless solution.

Our thanks to the Arista Networks team in the Black Hat NOC for their partnership throughout the week.

You can read the other blogs from our colleagues at Black Hat USA.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

For more information, please visit the Black Hat website.

2 weeks, 5 days назад @ blogs.cisco.com
Distributed Latency Monitoring at Black Hat
Distributed Latency Monitoring at Black Hat Distributed Latency Monitoring at Black Hat

With Matthew Bair2026 marks the fourth consecutive year we’ve used ThousandEyes to monitor the Black Hat USA network for latency.

As our latency monitoring mesh has expanded to cover more and more of the conference, we’ve also begun supplementing our ThousandEyes monitoring with on-demand Linux commands to track latency across different protocols.

The Key ThousandEyes TestsThe automated ThousandEyes tests that inform our dashboards include HTTPS connectivity tests, the monitoring of cloud services, agent to agent tests, internal and external DNS resolution, and even file downloads.

On-Demand Latency Tests from the Agent MeshPing and traceroute are the go-tos for anyone who wants to do a qui…

2 weeks, 5 days назад @ blogs.cisco.com
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

While developing a detection for Cisco Secure Network Analytics (SNA), I used the Splunk Detection Editor (Alpha) to bring much of that workflow into one place.

Instead of treating every observation as an incident, detections can create risk events associated with entities such as systems or users.

Developing the detection in one workspaceThe Detection Editor provides a workspace for building the search while configuring the other parts of the detection.

Risk events for the same entity need to use a consistent risk object so Splunk Enterprise Security can associate them correctly.

Splunk defines the risk object, its type, and its score as key parts of a risk event.

2 weeks, 5 days назад @ blogs.cisco.com
Black Hat USA 2026: Safeguarding DNS with Secure Access
Black Hat USA 2026: Safeguarding DNS with Secure Access Black Hat USA 2026: Safeguarding DNS with Secure Access

DNS continues to provide one of the clearest windows into activity across the Black Hat network.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking.

Its 4.42 million blocks represented 79.3% of every blocked DNS request .. Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and mo…

2 weeks, 5 days назад @ blogs.cisco.com
Frontier AI just raised the stakes, and the old playbook won’t hold up
Frontier AI just raised the stakes, and the old playbook won’t hold up Frontier AI just raised the stakes, and the old playbook won’t hold up

Project Glasswing and Frontier models just made that truth louder.

Frontier models are about to pour gasoline on that fire; the fundamentals matter more than ever.

Cisco ran its own experiment leveraging a variety of frontier models.

Foundry Security Spec: a model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

Foundry-Security-Speca model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

3 weeks, 1 day назад @ blogs.cisco.com
Crypto Agility: Why PQC Is Not a One-Time Upgrade
Crypto Agility: Why PQC Is Not a One-Time Upgrade Crypto Agility: Why PQC Is Not a One-Time Upgrade

That requires crypto agility.

Why long-lived networks need crypto agilityThink about designing a building before all of its future electrical requirements are known.

Crypto agility is about adopting the best defenses available today while preserving the ability to adopt better ones tomorrow.

That is why crypto agility needs to be designed into the network we invest in today.

Common questions about PQC and crypto agilityWhat is crypto agility?

3 weeks, 2 days назад @ blogs.cisco.com
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

It is what happens when agents built by different teams, on different platforms, can hand work to each other directly.

And it is worth being direct about where things stand: A2A-mediated handoffs between production security agents are not shipping anywhere yet.

Use A2A when one agent needs to hand work to another.

A2A is peer-to-peer: any A2A agent can discover and call any other A2A agent through a self-published Agent Card, no custom connector required, and the receiving agent applies its own reasoning rather than following a static script.

Input validation is an application-layer responsibility that needs to be designed in before any agent delegates via A2A, not added after.

4 weeks, 1 day назад @ blogs.cisco.com
Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
Microsegmentation’s Moment Is Now:  Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind SpotsApplications increasingly span private clouds, on-premises data centers, and public clouds.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026…

1 month назад @ blogs.cisco.com
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

What We Mean by Infrastructure IdentityInfrastructure Identity starts with a simple principle: there should be no anonymous computing in critical infrastructure.

Infrastructure Identity turns that principle into an operating model.

Infrastructure Identity starts with the actor and evaluates whether a specific action should be allowed now.

Infrastructure Identity is therefore not just an access-control issue.

That is the promise of Infrastructure Identity: no anonymous computing, no unmanaged privilege, and no forced tradeoff between stronger security and operational speed.

1 month назад @ blogs.cisco.com
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE

I’m proud to share that IDC MarketScape has named Cisco a Leader in the 2026 IDC MarketScape: Worldwide Secure Access Service Edge (SASE) Vendor Assessment.

In an evaluation of 12 SASE vendors, the IDC MarketScape recognized our architectural breadth and flexibility, AI capabilities, identity integration, threat visibility, and R&D.

Built to Make Agent Work, WorkWe believe the IDC MarketScape recognition validates the foundation we have built, and customers increasingly need that foundation for what is next.

For more on Cisco’s placement as a Leader, read the IDC MarketScape excerpt and explore how Cisco SASE keeps work moving, governed, and trusted in the AI era at cisco.com/go/sase.

Stay …

1 month назад @ blogs.cisco.com
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

1 month, 1 week назад @ blogs.cisco.com
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero … Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …

The Power of FedRAMP HighWhile FedRAMP Certified Class C (Moderate) is the standard for many civilian agencies, FedRAMP Certified Class D (High) is designed for systems where a breach could have catastrophic effects.

Cisco Security Cloud for GovernmentCisco Security Cloud for Government is a unified authorization boundary that integrates various Cisco security services, ensuring that organizations can protect their users, devices, and applications regardless of where they reside.

The Cisco Security Cloud for Government ecosystem is designed to meet the rigorous security requirements of the public sector and highly regulated industries.

Cisco Security Cloud Control (SCC)Cisco Security Cloud …

1 month, 2 weeks назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 1 day, 18 hours назад
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Storm-3168: Agentic-driven cloud attacks using compromised service principals Storm-3168: Agentic-driven cloud attacks using compromised service principals

About 90 minutes after the first compromised service principal started enumeration, the second compromised service principal enumerated virtual machines and resource groups across two subscriptions in five seconds.

16 hours later, the second service principal successfully enumerated Azure App Service configuration stores, possibly looking for exposed credentials.

This compromised service principal then attempted 150+ destructive or credential collection related operations in 35 minutes.

T1078.004 Valid Accounts: Cloud Accounts | Compromised service principals were used for Azure resource discovery and destruction.

To hear stories and insights from the Microsoft Threat Intelligence community…

1 day, 18 hours назад @ microsoft.com
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.

As a result, organizations could encounter the same actor, tools, and intrusion methods despite different ransomware payloads being deployed.

Storm-2570 uses a diverse set of remote access tools rather than relying on a single capability.

This type of tunnel can help bypass inbound firewall restrictions and provide covert remote access for follow-on activity.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat …

2 days, 18 hours назад @ microsoft.com
​​​​​​​​What’s new in Microsoft Security: September 2026​​
​​​​​​​​What’s new in Microsoft Security: September 2026​​ ​​​​​​​​What’s new in Microsoft Security: September 2026​​

Here’s what’s new:Extend protection and support investigations with Microsoft DefenderBring more context into email investigation and hunting with Microsoft Security CopilotAvailable for organizations using both Microsoft Defender and Microsoft Security Copilot, a new email detonation summary delivers AI-generated explanations of URL and file sandboxing results, helping SOC teams investigate faster by reducing the manual effort required to correlate detonation evidence and contextual signals.

Protect sensitive data in motion with Microsoft Purview and Microsoft EntraStop sensitive data from reaching shadow AI over the networkNow generally available, Microsoft Purview and Microsoft Entra Glo…

2 days, 18 hours назад @ microsoft.com
Reimagining the SOC for the agentic era in Microsoft Defender
Reimagining the SOC for the agentic era in Microsoft Defender Reimagining the SOC for the agentic era in Microsoft Defender

So must the security operations center (SOC).

For agentic security to work, the industry needs a different model.

Today we are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for security information and event management (SIEM) and threat protection together.

The result is an integrated protection loop that continuously turns what defenders learn into stronger pre-breach protection.

Integrated security operations center (ISOC) in Microsoft Defender is available in preview today.

3 days, 18 hours назад @ microsoft.com
Unmasking EvilTokens: Getting to the root of device code phishing
Unmasking EvilTokens: Getting to the root of device code phishing Unmasking EvilTokens: Getting to the root of device code phishing

What is device code phishing?

Device code phishing occurs when threat actors insert themselves into this process.

Tactic Observed activity Microsoft Defender coverage Initial access Device code authentication Microsoft Defender for Identity– Anomalous OAuth device code authentication activity Credential access Token theft following device code authentication Microsoft Defender for Identity– Anomalous token exchange following device code authenticationMicrosoft Defender XDR– User account compromise via OAuth device code phishing– Suspicious Azure authentication through possible device code phishing Persistence Device registration following anomalous device code authentication Microsoft Defen…

4 days, 19 hours назад @ microsoft.com
From guidance to action: Security fundamentals that materially reduce risk
From guidance to action: Security fundamentals that materially reduce risk From guidance to action: Security fundamentals that materially reduce risk

We introduced Secure Now within Microsoft Security Exposure Management in May 2026 to help practitioners prioritize the action they need to take to be prepared for this shift.

Security fundamentals work togetherCyberattackers are moving laterally across surfaces, and security fundamentals matter most at the intersections between them.

On Secure Now—within Microsoft Security Exposure Management—security leaders can now find information on recent threats paired with focused initiatives across security domains.

Learn moreLearn more about Microsoft Security Exposure Management.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurit…

1 week, 2 days назад @ microsoft.com
Improving email security outcomes with real-world Microsoft Defender insights
Improving email security outcomes with real-world Microsoft Defender insights Improving email security outcomes with real-world Microsoft Defender insights

For five consecutive quarters Microsoft has published email security benchmarking reports to provide greater transparency into real-world protection outcomes.

Figure 1: High-severity email threats missed by SEG vendors (May 2026 through July 2026), measured as threats missed per 1,000 users protected.

Similarly to previous quarters, integrated cloud email security (ICES) solutions continue adding the most value in promotional and bulk filtering.

Figure 3: Post‑delivery malicious catch by Microsoft Defender (May 2026 through July 2026), shown across vendors and overall average.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecu…

1 week, 2 days назад @ microsoft.com
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Protecting organizations from AI-assisted executive impersonation and invoice fraud Protecting organizations from AI-assisted executive impersonation and invoice fraud

Figure 1: Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft.

Important note: Throughout this campaign, threat actors impersonated legitimate organizations using attacker-controlled infrastructure, fabricated communications, and lookalike domains.

To defend against social engineering campaigns involving executive impersonation, invoice fraud, and potentially AI-assisted content development, Microsoft recommends the following mitigations:Configure automatic attack disruption in Microsoft Defender XDR.

Tactic Observed activity Microsoft Defender coverage Financial Theft Scam emails Microsoft Defender for Office…

2 weeks, 2 days назад @ microsoft.com
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Protecting organizations from AI-assisted executive impersonation and invoice fraud Protecting organizations from AI-assisted executive impersonation and invoice fraud

Figure 1: Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft.

Important note: Throughout this campaign, threat actors impersonated legitimate organizations using attacker-controlled infrastructure, fabricated communications, and lookalike domains.

To defend against social engineering campaigns involving executive impersonation, invoice fraud, and potentially AI-assisted content development, Microsoft recommends the following mitigations:Configure automatic attack disruption in Microsoft Defender XDR.

Tactic Observed activity Microsoft Defender coverage Financial Theft Scam emails Microsoft Defender for Office…

2 weeks, 2 days назад @ microsoft.com
Detect and disrupt AI-themed attacks with Microsoft Defender
Detect and disrupt AI-themed attacks with Microsoft Defender Detect and disrupt AI-themed attacks with Microsoft Defender

Turning AI lures into dead ends with Microsoft DefenderIn practice, protection starts before the user ever engages with the lure.

Simplified Defender email detection stack with pre-delivery and post-delivery protections.

Microsoft Defender helps organizations do that by connecting prevention, detection, investigation, and response across the attack path, so AI-themed lures are harder to deliver, harder to trust, and harder to turn into broader compromise.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

2 weeks, 2 days назад @ microsoft.com
Threat Matrix: Mapping threats across cloud web applications
Threat Matrix: Mapping threats across cloud web applications Threat Matrix: Mapping threats across cloud web applications

Microsoft introduces the cloud web applications threat matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.

Microsoft developed the Cloud web applications threat matrix to organize relevant techniques using MITRE ATT&CK tactics.

Cloud web applications threat matrix organized by MITRE ATT&CK tactics.

Valid cloud accountsAdversaries may gain access to cloud web applications and serverless environments by leveraging compromised valid cloud accounts.

The cloud web applications threat matrix is intended to support this by mapping techniques to attack stages, helping defenders identify where v…

2 weeks, 3 days назад @ microsoft.com
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering leads to identity and cloud compromise Passkey-themed social engineering leads to identity and cloud compromise

Observed attack sequence showing identity compromise through social engineering, MFA persistence, Microsoft Graph reconnaissance, and cloud data collection/exfiltration.

In device code phishing, the user is persuaded to enter a code on the legitimate Microsoft authentication page.

The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call.

Investigate high-volume or programmatic Microsoft Graph activity involving directory enumeration, role discovery, service principal discovery, SharePoint, OneDrive, or sensitivity-label discovery.

Discovery Graph API reconnaissance activity Microsoft Defender for Identity– S…

2 weeks, 3 days назад @ microsoft.com
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering leads to identity and cloud compromise Passkey-themed social engineering leads to identity and cloud compromise

Observed attack sequence showing identity compromise through social engineering, MFA persistence, Microsoft Graph reconnaissance, and cloud data collection/exfiltration.

In device code phishing, the user is persuaded to enter a code on the legitimate Microsoft authentication page.

The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call.

Investigate high-volume or programmatic Microsoft Graph activity involving directory enumeration, role discovery, service principal discovery, SharePoint, OneDrive, or sensitivity-label discovery.

Discovery Graph API reconnaissance activity Microsoft Defender for Identity– S…

2 weeks, 3 days назад @ microsoft.com
How to secure edge AI in customer-owned environments
How to secure edge AI in customer-owned environments How to secure edge AI in customer-owned environments

Edge AI changes the trust model for AI systemsIn Cloud AI, separate companies own and attest the hardware, platform, and model weights.

Edge AI deployments often place customers in control of more of the AI stack.

Why Edge AI increases exposureAn Edge AI deployment may include models, prompts, agents, retrieval data, policies, local data stores, and update mechanisms running on infrastructure outside the provider’s cloud environment.

Next stepsBottom line: Edge AI changes the trust model for AI systems.

Edge AI pushes security controls into devices, gateways, vehicles, factories, hospitals, retail spaces, and other customer environments.

3 weeks, 1 day назад @ microsoft.com
How to secure edge AI in customer-owned environments
How to secure edge AI in customer-owned environments How to secure edge AI in customer-owned environments

Edge AI changes the trust model for AI systemsIn Cloud AI, separate companies own and attest the hardware, platform, and model weights.

Edge AI deployments often place customers in control of more of the AI stack.

Why Edge AI increases exposureAn Edge AI deployment may include models, prompts, agents, retrieval data, policies, local data stores, and update mechanisms running on infrastructure outside the provider’s cloud environment.

Next stepsBottom line: Edge AI changes the trust model for AI systems.

Edge AI pushes security controls into devices, gateways, vehicles, factories, hospitals, retail spaces, and other customer environments.

3 weeks, 1 day назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 5 months назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

5 months назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

5 months, 2 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

5 months, 2 weeks назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

5 months, 3 weeks назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

5 months, 4 weeks назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

6 months назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

7 months назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

7 months назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

7 months, 1 week назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

8 months назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

9 months, 2 weeks назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

9 months, 3 weeks назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

9 months, 3 weeks назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

9 months, 3 weeks назад @ security.googleblog.com