Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 6 часов назад
Взятка полицейскому и компромат на миллиардера: чему учат в закрытом клубе Эндрю Тейта «Военная комната»
Взятка полицейскому и компромат на миллиардера: чему учат в закрытом клубе Эндрю Тейта «Военная комната» Взятка полицейскому и компромат на миллиардера: чему учат в закрытом клубе Эндрю Тейта «Военная комната»

В сеть попали курсы о подкупе чиновников, слежке и поиске слабостей богатых людей.

6 часов назад @ securitylab.ru
MeerKAT услышал водород, летевший к Земле пять миллиардов лет
MeerKAT услышал водород, летевший к Земле пять миллиардов лет

Радиотелескоп увидел невидимую карту Вселенной.

6 часов назад @ securitylab.ru
Что обязательно нужно проверить в Active Directory до первой атаки
Что обязательно нужно проверить в Active Directory до первой атаки 6 часов назад @ securitylab.ru
Все морозильники разом включили разморозку. Пентагон начал расследование сбоя холодильной системы
Все морозильники разом включили разморозку. Пентагон начал расследование сбоя холодильной системы

Версию кибератаки проверяют после массовых сбоев сразу в нескольких штатах.

7 часов назад @ securitylab.ru
Один аккаунт на всё правительство: США переходят на Login.gov
Один аккаунт на всё правительство: США переходят на Login.gov

Белый дом запускает двухлетний переход к единой аутентификации федеральных сервисов.

7 часов назад @ securitylab.ru
$600.000 улетели в трубу: ИИ-агент решил, что отдать хакеру секретный ключ — вполне разумная идея
$600.000 улетели в трубу: ИИ-агент решил, что отдать хакеру секретный ключ — вполне разумная идея

Авторизация тихо отключилась сама, пока исследователи списывали аномалии на плановые тесты.

8 часов назад @ securitylab.ru
Увидели тревогу от Защитника Windows? Расслабьтесь, просто Microsoft снова что-то сломала
Увидели тревогу от Защитника Windows? Расслабьтесь, просто Microsoft снова что-то сломала Увидели тревогу от Защитника Windows? Расслабьтесь, просто Microsoft снова что-то сломала

Разработчики подтвердили странное поведение системы, но дату починки назвать постеснялись.

8 часов назад @ securitylab.ru
Чёрный экран вместо фильма. Хакеры научились прятать трояны внутри «битых» MP4
Чёрный экран вместо фильма. Хакеры научились прятать трояны внутри «битых» MP4

Встроенная защита пропускает опасный контейнер, принимая его за обычное видео.

9 часов назад @ securitylab.ru
Один запрос — и сервер пуст. Хакеры нашли способ забирать ключи OpenAI и AWS у создателей ИИ-ботов
Один запрос — и сервер пуст. Хакеры нашли способ забирать ключи OpenAI и AWS у создателей ИИ-ботов Один запрос — и сервер пуст. Хакеры нашли способ забирать ключи OpenAI и AWS у создателей ИИ-ботов

Инцидент застал отрасль врасплох: спасительное обновление вышло, но ставить его никто не спешит.

9 часов назад @ securitylab.ru
Кубиты научились запутываться сами — их просто окружили правильным шумом
Кубиты научились запутываться сами — их просто окружили правильным шумом

Специально настроенная среда не разрушает запутанность, а помогает сохранять её.

10 часов назад @ securitylab.ru
Ноль совпадений по хешу. Сервер собирает новый троян под каждый клик
Ноль совпадений по хешу. Сервер собирает новый троян под каждый клик

Встроенный защитник Windows даже не понял причину собственной слепоты.

10 часов назад @ securitylab.ru
Друг просит денег на лечение детей, а ваши сбережения улетают хакерам. Работает новый благотворительный развод
Друг просит денег на лечение детей, а ваши сбережения улетают хакерам. Работает новый благотворительный развод

Доброе дело стало входным билетом к банковскому счету.

10 часов назад @ securitylab.ru
Указ №604: дата-центры в России получили новую головную боль — противодроновую защиту
Указ №604: дата-центры в России получили новую головную боль — противодроновую защиту

Серверы придется защищать уже не только от хакеров.

11 часов назад @ securitylab.ru
Миллиарды молекул за часы вместо месяцев. ИИ удешевил поиск лекарств в тысячу раз
Миллиарды молекул за часы вместо месяцев. ИИ удешевил поиск лекарств в тысячу раз Миллиарды молекул за часы вместо месяцев. ИИ удешевил поиск лекарств в тысячу раз

Новая платформа отсеивает миллиарды молекул и концентрируется на самых перспективных кандидатах.

11 часов назад @ securitylab.ru
От разведки до чужого пароля: как хакеры взламывают Active Directory — покажут на живом стенде
От разведки до чужого пароля: как хакеры взламывают Active Directory — покажут на живом стенде

Открытый онлайн-практикум 2 сентября.

11 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 8 часов назад
Как связка VM и SIEM помогает оценивать риски эксплуатации уязвимостей
Как связка VM и SIEM помогает оценивать риски эксплуатации уязвимостей Как связка VM и SIEM помогает оценивать риски эксплуатации уязвимостей

Разбираемся, как объединить данные VM, SIEM и CMDB, учесть EPSS и CISA KEV, настроить расчёт риска и расставить приоритеты устранения.

Уровни риска и сроки устранения уязвимостейКак работают вместе VM, SIEM и CMDBКаждый источник отвечает на отдельную группу вопросов.

Актив есть в VM, но не передаёт событияОбратная ситуация возникает, когда VM видит узел, а SIEM не получает от него событий.

Организовать обмен данными между VM, SIEM и CMDB.

ВыводыСвязка VM, SIEM и CMDB помогает оценивать уязвимости в контексте реальной инфраструктуры.

8 часов назад @ anti-malware.ru
Обзор встроенных СЗИ операционной системы Astra Linux
Обзор встроенных СЗИ операционной системы Astra Linux Обзор встроенных СЗИ операционной системы Astra Linux

Статистика роста количества уязвимостей в ОС Linux в 1998–2026 гг.

Профили настройки СЗИ в Astra LinuxДля настройки СЗИ в Astra Linux предусмотрены готовые профили, соответствующие требованиям регулятора.

Выбор профиля защиты системы в Astra LinuxАрхитектура СЗИ ОС Astra LinuxДля обеспечения безопасности использования Astra Linux команда разработчиков переработала архитектуру исходной операционной системы.

Трёхзвенная клиент-серверная архитектура ОС Astra LinuxСогласно сертификату № 2557 ОС Astra Linux соответствует требованиям документов: Требования доверия (1), Требования доверия (2), Требования к ОС, Профиль защиты ОС (А первого класса защиты.

Сценарии использования встроенных СЗИ Astra …

13 часов назад @ anti-malware.ru
Гонка за ИИ-инфраструктурой: кто победит в 2026 году
Гонка за ИИ-инфраструктурой: кто победит в 2026 году Гонка за ИИ-инфраструктурой: кто победит в 2026 году

Аннотация: В 2026 году преимущество получают не компании с самым большим числом ИИ-пилотов, а те, кто умеет превращать эксперименты в управляемые сервисы.

В 2026 году гораздо важнее другое: способна ли компания превратить удачный ИИ-пилот в эффективный сервис, которым безопасно пользуются сотни или тысячи сотрудников?

Гонка 2026 года в пяти цифрахМасштаб разрыва между интересом к ИИ и готовностью к его промышленной эксплуатации показывают результаты исследования Orion soft и данные проектов компании.

Эта оценка окупаемости инвестиций (ROI) не проходила независимый аудит, но показывает принцип расчёта: стоимость инфраструктуры нужно сопоставлять с изменением конкретного процесса, а не с коли…

1 day, 7 hours назад @ anti-malware.ru
Автоматизируем анализ защищённости в 2026 году: когда пентест уже не справляется
Автоматизируем анализ защищённости в 2026 году: когда пентест уже не справляется Автоматизируем анализ защищённости в 2026 году: когда пентест уже не справляется

Эксперты рынка обсудили, какие инструменты нужны для непрерывной оценки защищённости, как выстроить процессы и что ждёт отрасль в ближайшие годы.

Денис Гамаюнов указал, что не стоит безапелляционно отграничивать пентест от автоматизации.

Давид Ордян, генеральный директор METASCANМаксим Пятаков уточнил, что для внешнего периметра ограничений практически нет — любая компания может начать использовать ASM-решения.

Важно сначала оценить слабые места: возможно, проблема не в отсутствии какого-то инструмента, а в том, что у ИБ нет общего языка с ИТ-подразделениями.

При этом главная ценность автоматизации — не в количестве найденных уязвимостей, а в приоритизации: показать бизнесу не список пробле…

1 day, 10 hours назад @ anti-malware.ru
Обзор Deckhouse Virtualization Platform 1.10, системы для управления ВМ и контейнерами в одной среде
Обзор Deckhouse Virtualization Platform 1.10, системы для управления ВМ и контейнерами в одной среде Обзор Deckhouse Virtualization Platform 1.10, системы для управления ВМ и контейнерами в одной среде

Отдельные редакции позволяют запускать контейнеры вместе с ВМ в одной среде для запуска гибридных приложений.

Для решения задач виртуализации существует множество решений с открытым кодом, в том числе и для управления виртуальными машинами (ВМ) с помощью Kubernetes.

DevOps-инструменты и практики для ВМ: IaC, GitOps, Helm, Argo CD для управления жизненным циклом.

Централизованная наблюдаемость: мониторинг, события и журналы инфраструктуры, ВМ и приложений из одной точки.

Снимок ВМ включает в себя параметры ВМ и состояние всех её дисков; снимок диска сохраняет только данные выбранного диска.

2 days, 14 hours назад @ anti-malware.ru
Импортозамещение как иллюзия безопасности: почему смена вендора не решает проблем ИТ и ИБ
Импортозамещение как иллюзия безопасности: почему смена вендора не решает проблем ИТ и ИБ Импортозамещение как иллюзия безопасности: почему смена вендора не решает проблем ИТ и ИБ

Не хватает не только линейных инженеров и аналитиков, но и системных архитекторов, руководителей проектов, разработчиков безопасных интерфейсов и других специалистов, способных выстраивать комплексные процессы.

Организациям приходится «выращивать» такие кадры самостоятельно: профильные вузы не всегда успевают за темпами развития ИТ и ИБ и изменением требований к специалистам.

Импортозамещение должно рассматриваться не как конечная цель и не как перечень продуктов, которые необходимо заменить, а как часть более широкой системы управления технологическими рисками.

Приоритеты в области ИТ и ИБ должны определяться реальными рисками и потенциальным ущербом, а не только необходимостью соответство…

5 days, 12 hours назад @ anti-malware.ru
«Вторая волна» импортозамещения: от офисных пакетов к специализированному промышленному софту
«Вторая волна» импортозамещения: от офисных пакетов к специализированному промышленному софту «Вторая волна» импортозамещения: от офисных пакетов к специализированному промышленному софту

От замены операционных систем, офисных пакетов и систем управления базами данных ИТ-рынок переходит к замещению сложного промышленного софта.

К началу 2026 года в Реестре российского ПО было зарегистрировано почти 30 000 продуктов, а объём продаж российских ИТ-продуктов и сервисов превысил 5 трлн рублей.

Затраты на покупку ПО на одного занятого в ценах 2015 года (источник: forecast.ru)Вторая волна импортозамещения — это уже этап системной и глубокой работы, переход от срочного импортозамещения к осознанному построению устойчивой отечественной ИТ-экосистемы для промышленности.

Они объединяют крупнейшие компании и разработчиков для определения приоритетных направлений импортозамещения и форми…

6 days, 11 hours назад @ anti-malware.ru
Возрастные ограничения для соцсетей: мировой опыт, методы обхода и эффективность
Возрастные ограничения для соцсетей: мировой опыт, методы обхода и эффективность Возрастные ограничения для соцсетей: мировой опыт, методы обхода и эффективность

Аналогичные нормы действуют во многих странах, в том числе и в России (закон № 436-ФЗ «О защите детей от информации, причиняющей вред их здоровью и развитию»).

Среди них оказались как развитые страны Европы, так и Китай, и целый ряд азиатских стран, и Канада, и даже Австралия.

Из постсоветских стран пока отметился лишь Азербайджан, где соответствующий закон принят в конце июня и вступит в силу в 2027 году.

Страны, которые ввели или планируют ввести возрастные ограничения на доступ к соцсетям (РБК, Reuters)В России ограничения на доступ к соцсетям не планируются.

Они выставляют различные технические и организационные ограничения на доступ к данным.

6 days, 13 hours назад @ anti-malware.ru
Обзор инструментов для оценки антихрупкости ИТ-архитектуры от «Инфосистемы Джет»
Обзор инструментов для оценки антихрупкости ИТ-архитектуры от «Инфосистемы Джет» Обзор инструментов для оценки антихрупкости ИТ-архитектуры от «Инфосистемы Джет»

Эта компания разработала инструменты для её практического применения — первый Фреймворк антихрупкой ИТ-архитектуры и Индекс антихрупкости для построения киберустойчивого бизнеса.

Для практической реализации концепции антихрупкости «Инфосистемы Джет» разработали первый Фреймворк антихрупкой архитектуры и Индекс антихрупкости, позволяющие выявить слабые места и сформировать дорожную карту усиления защиты.

Назначение инструментов, разработанных компанией «Инфосистемы Джет»Как же перейти от понимания концепции антихрупкости к её реализации?

Компания «Инфосистемы Джет» переводит концепцию антихрупкости на язык конкретных инженерных и управленческих решений.

Наличие веб-сервиса для оценки антихру…

1 week назад @ anti-malware.ru
Российский рынок серверов и ПАКов 2026: тренды, риски и миграция
Российский рынок серверов и ПАКов 2026: тренды, риски и миграция Российский рынок серверов и ПАКов 2026: тренды, риски и миграция

В 2026 году российский рынок серверного оборудования и ПАКов достиг новой зрелости: выбор огромен, но разобраться в нём стало сложнее, чем когда-либо.

Они должны входить как в реестр Минпромторга (в части оборудования), так и в реестр Минцифры (в части программного обеспечения).

Ценность заключается в том, что в условиях, в которых оно производится, оно находится на уровне лучших мировых образцов вендоров А-класса.

Логика реализована в софте, и это зачастую требует изменения модели данных и подходов к их хранению, особенно когда часть технологий становится недоступной.

В нашей компании уже разработан ПАК искусственного интеллекта, который умеет управлять балансировкой и загрузкой карт и раб…

1 week назад @ anti-malware.ru
Эволюция PAM в 2026 году: как управлять доступом, когда пользователи — не люди
Эволюция PAM в 2026 году: как управлять доступом, когда пользователи — не люди Эволюция PAM в 2026 году: как управлять доступом, когда пользователи — не люди

Денис Морозов добавил исторический контекст: «Раньше сервисные учётные записи были, но им доверяли по умолчанию — ведь это не люди, которые могут что-то утащить.

Клиент видит, что функция уже есть в PAM, и ему перестают быть нужны лишние системы.

Появляются сущности в инфраструктурном IDM, и доступы в соответствии с заранее определёнными политиками, ролевой моделью и матрицей доступов раскатываются в хранилище и PAM.

Суть не в комбайне, а в синергии продуктов.

Cloud Native PAM в ближайшее время в стране не появится — для этого нужен выход на внешние рынки.

1 week, 1 day назад @ anti-malware.ru
Сервисная модель ИБ (MSSP): почему бизнес покупает не продукты, а функцию защиты
Сервисная модель ИБ (MSSP): почему бизнес покупает не продукты, а функцию защиты Сервисная модель ИБ (MSSP): почему бизнес покупает не продукты, а функцию защиты

Чтобы понять, как формировалась эта модель и что она представляет собой сегодня, мы посмотрели на её развитие, сравнили предложения и кейсы провайдеров.

MSSP сегодняРасширение рынка MSSP и рост конкуренции повысили ожидания клиентов.

Поэтому от MSSP ожидают не только организации и поддержки процессов ИБ, но и способности демонстрировать измеримый результат по снижению рисков.

Сервисы MSSP UserGate uFactorПоэтому при оценке MSSP важнее ориентироваться не на название услуги, а на фактический набор функций, которые предоставляет провайдер.

Важно понять, что именно заказчик получает от MSSP на практикеГибкостьПровайдер не обязательно привязан к одному стеку технологий.

1 week, 2 days назад @ anti-malware.ru
Сравнение российских корпоративных центров сертификации (Certificate Authority, CA) — 2026
Сравнение российских корпоративных центров сертификации (Certificate Authority, CA) — 2026 Сравнение российских корпоративных центров сертификации (Certificate Authority, CA) — 2026

Детально изучаем функции и возможности 4 отечественных центров сертификации для корпоративных инфраструктур: Aladdin Enterprise CA, Avanpost CA, Clearway CA, SafeTech CA.

ВведениеДо 2022 года в России не было отечественных центров сертификации (Certificate Authority, CA) для корпоративных инфраструктур.

Это пространство почти полностью занимал один из элементов экосистемы Windows — Microsoft Active Directory Certificate Services, или, как его иногда называют для краткости, Microsoft CA.

Так что отказываться от Microsoft CA (Active Directory Certificate Services) тяжело.

Да Да Выпуск и обслуживание сертификатов центров сертификации инфраструктуры открытых ключей Да Да Да Да Да Создание, импо…

1 week, 2 days назад @ anti-malware.ru
ФНС доначисляет налоги ИТ-компаниям: как не потерять льготы в 2026 году
ФНС доначисляет налоги ИТ-компаниям: как не потерять льготы в 2026 году ФНС доначисляет налоги ИТ-компаниям: как не потерять льготы в 2026 году

В итоге всё же был сохранён налог на прибыль в 5% и удвоение страховых выплат на сотрудников до 15%.

В 2025 году сохранилось освобождение от налога на добавленную стоимость (НДС) при продаже ПО из реестра Минцифры.

Даже преобразование компании из ООО в АО влечёт смену ОГРН и ИНН, и с точки зрения закона она уже становится другой организацией.

Помимо этого не все компании отслеживают исключение своих продуктов из реестра российского ПО, и в результате теряют освобождение от НДС.

Впрочем, эти компании не из сферы ИТ, а претензии ФНС были связаны якобы с тем, что сделки с контрагентами были фиктивными.

1 week, 5 days назад @ anti-malware.ru
Эволюция аккумуляторов: как новые технологии меняют ЦОД и мобильные устройства
Эволюция аккумуляторов: как новые технологии меняют ЦОД и мобильные устройства Эволюция аккумуляторов: как новые технологии меняют ЦОД и мобильные устройства

Всё это неизбежно повлияет как на сегмент ЦОД, так и на эволюцию мобильных устройств.

В 2010-х годах они начали проникать и в сегмент систем бесперебойного питания, а также в целый ряд других, в частности средств индивидуальной мобильности и электромобилей.

Все эти особенности и обусловили широкую популярность литиевых батарей в портативных устройствах и распространение данной технологии в другие сферы, в том числе на транспорт и в системы бесперебойного питания.

Открываются месторождения и в других странах, но производство лития экологически очень грязное, и его организация сопровождается протестами.

В итоге многие авиакомпании даже запретили провозить его как в багаже, так и в ручной клад…

1 week, 6 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 5 часов назад
Отучаем IoT от облака
Отучаем IoT от облака Отучаем IoT от облака

Я уже несколько лет методично выбирал устройства для умного дома, работающие по протоколу Zigbee, чтобы не зависеть от облака вендора.

Так что отказом от облака это назвать сложно.

Производители используют Wi-Fi контроллеры от Tuya (например WBR3) и готовую прошивку для них для подключения устройств к облаку.

В такой схеме, именуемой TuyaMCU, Wi-Fi контроллер подключается через вашу домашнюю сеть к облаку Tuya и регистрирует в нём устройство.

Очень удобноКонтроллеру лотка не хватило питания от того же UART адаптера, поэтому я подключил его чуть более напрямую и немного поперебирал имеющиеся UART адаптеры.

5 часов назад @ habr.com
Как создавался агрегатор ИБ-новостей: склейка сюжетов, семь признаков важности и порог по данным
Как создавался агрегатор ИБ-новостей: склейка сюжетов, семь признаков важности и порог по данным Как создавался агрегатор ИБ-новостей: склейка сюжетов, семь признаков важности и порог по данным

Решение «важно или нет» принимает уже формула из семи признаков с открытыми весами: каждый балл виден в журнале, и с ним можно спорить.

У нас, как и у Яндекса, ранжируется сюжет, склеенный из материалов об одном событии, и оценка считается один раз на сюжет.

Главный подход при этом совпал и со статьей – больше половины ошибок сводки у Яндекса давали дубли, и у нас возникла та же проблема.

Что и как писать про уязвимостиУязвимостей ежедневно выходят огромное количество, и агрегатор нужно обучить их правильно ранжировать.

Мне здесь непонятно как это реализовать, чтобы это принесло ценность для читателяВидео контент совсем не собирается и не публикуется.

5 часов назад @ habr.com
От Root CA до User Authorization в nginx+apache. Часть 4. Свой web-УЦ: выпуск из браузера, роли и аудит
От Root CA до User Authorization в nginx+apache. Часть 4. Свой web-УЦ: выпуск из браузера, роли и аудит От Root CA до User Authorization в nginx+apache. Часть 4. Свой web-УЦ: выпуск из браузера, роли и аудит

В этой части:Кнопка «получить сертификат»: ключ рождается в браузере и не покидает его — и почему такой кнопке нельзя доверять отличительное имя.

algorithm algorithm ALGORITHM.&id({IOSet})знач.

Содержит ровно один член — name.⚠️ Это корень иерархии: RsaKeyGenParams : Algorithm, EcKeyGenParams : Algorithm, EcdsaParams : Algorithm, RsaPssParams : Algorithm, AesGcmParams : Algorithm и так далее.

Четыре значения: сырые байты, SubjectPublicKeyInfo (DER), PKCS#8 (DER), JSON Web Key.⚠️ Всё строчными буквами: “spki”, а не “SPKI”; “pkcs8”, а не “PKCS8”.

Должна идти ДО любых -algorithm, -paramfile или -pkeyopt.⚠️ Двойное ограничение порядка: -genparam раньше -algorithm, а -algorithm раньше -pkeyopt.

6 часов назад @ habr.com
Вы скопировали команду с сайта. В буфер попало не то, что вы выделили
Вы скопировали команду с сайта. В буфер попало не то, что вы выделили Вы скопировали команду с сайта. В буфер попало не то, что вы выделили

Перед Enter посмотрел на строку — вставилось не то, что было в блоке.

Это умолчание в bash с readline 8.1, в zsh и в fish.

Почему терминал опаснее редактораДело не в видимости: скрытый фрагмент вставится и в редактор.

Как защититьсяВставлять в редактор, а не в терминал.

В редакторе с включённым показом непечатаемых символов видно ровно то, что скопировано, вместе с невидимыми переводами строк.

7 часов назад @ habr.com
Как мы переходили на ViPNet Prime: грабли, «осиротевшие» ключи и умножение времени на π
Как мы переходили на ViPNet Prime: грабли, «осиротевшие» ключи и умножение времени на π Как мы переходили на ViPNet Prime: грабли, «осиротевшие» ключи и умножение времени на π

Развернуть сеть заново на новой лицензии Prime и постепенно переносить туда клиентов.

Если в ЦУС загрузка лицензии проходит всегда (просто количество свободных уходит в минус, и можно перераспределить), то в Prime лицензия просто не загрузится и даже не покажет, что именно не так.

💡 Заложенное на всё время миграции умножайте на π. Это не шутка.

Сейчас, глядя на опыт, понимаю, что удаляли их неправильно и это не могло решить проблему.

В УКЦ он отображался со сроками выпуска и действия «неизвестно», и, судя по всему, именно он ломал логику утилиты миграции на стороне Prime.

8 часов назад @ habr.com
В России начали блокировать протоколы DoH и DoT
В России начали блокировать протоколы DoH и DoT В России начали блокировать протоколы DoH и DoT

Причём ложился он по-разному в зависимости от протокола, и это различие — самое интересное в истории.

Именно поэтому DoT ловится и глушится системно и стабильно — 853-й порт мало кто использует для чего-то ещё, и ущерба почти нет.

Нынешняя волна отличается сразу по нескольким признакам:Бьёт одновременно и по Google, и по Cloudflare — два независимых поставщика DNS, два разных набора IP-адресов, два разных протокола.

Затрагивает разных операторов независимо друг от друга — то есть похоже на централизованно распространённую сигнатуру/правило для оборудования ТСПУ, а не на локальную настройку одного оператора.

Точка разрыва — не IP-уровень, а TLS-хендшейк, что требует специфичного функционала …

10 часов назад @ habr.com
Внутренний DNS как контур управления: почему от резолвера зависит больше, чем кажется
Внутренний DNS как контур управления: почему от резолвера зависит больше, чем кажется Внутренний DNS как контур управления: почему от резолвера зависит больше, чем кажется

DNS в эти схемы часто так и не вошёл.

Вендор собрал публичный и внутренний DNS рядом с защитным резолвером и описал систему через три объекта – внутренние зоны, представления (views) и политики резолвера.

Это не новый стандарт DNS и не единственно возможная реализация.

Транспортом может быть обычный DNS, DNS over TLS или DNS over HTTPS.

Политика резолвера выбирает внутреннее представление, собственный вышестоящий DNS или публичную рекурсию.

10 часов назад @ habr.com
«CT-log» — это самый частый сценарий, почему имя остается в открытом доступе, даже если его нет в DNS
«CT-log» — это самый частый сценарий, почему имя остается в открытом доступе, даже если его нет в DNS «CT-log» — это самый частый сценарий, почему имя остается в открытом доступе, даже если его нет в DNS

Механика такая: Chrome с 30 апреля 2018 года требует, чтобы публично доверенный сертификат сопровождался SCT — подписанными отметками журналов о том, что сертификат в них принят.

Apple включила аналогичное требование в Safari осенью 2018-го, Firefox — только в 2025-м, в версии 135.

Именно это видно в выводе выше: наружу ушёл факт существования зоны int , а не список того, что в ней живёт.

Проверка тут простая: если сервис нельзя выставить в интернет под известным именем, то и под неизвестным нельзя — значит, вопрос не в имени, а в аутентификации и в сетевом доступе.

Найденное разделить на три части — то, что должно быть снаружи; то, что должно быть внутри и получило публичный сертификат по …

14 часов назад @ habr.com
Не конкурируй с ИИ — управляй им. Как специалисту по ИБ остаться востребованным в эпоху ИИ-агентов
Не конкурируй с ИИ — управляй им. Как специалисту по ИБ остаться востребованным в эпоху ИИ-агентов Не конкурируй с ИИ — управляй им. Как специалисту по ИБ остаться востребованным в эпоху ИИ-агентов

Как не остаться на свалке истории, а наоборот — вскочить на ступеньку этого поезда и использовать ИИ как инструмент, который усиливает, а не заменяет?

Ведь именно бизнес даёт деньги на безопасность: на багбаунти, на закупку средств защиты, на обучение сотрудников, на поездки на конференции.

Вы не получите денег и, что хуже, заработаете репутацию человека, который не понимает, что защищает.

И это не единичный случай — те же агенты справляются с моделированием угроз, расчётом рисков и даже с созданием персональных Security Awareness-программ.

Вопрос не в том, какой моделью пользоваться, а в том, как правильно её использовать.

15 часов назад @ habr.com
Что случилось с NVD и почему опираться на один источник уязвимостей больше нельзя
Что случилось с NVD и почему опираться на один источник уязвимостей больше нельзя Что случилось с NVD и почему опираться на один источник уязвимостей больше нельзя

На CVE опираются и NVD, и БДУ, и продукты вендоров.

Собственные исследователи компаний-вендоров находят уязвимости, в том числе в чужих и собственных продуктах, и вносят их в свои базы.

Что сломалось в мировой экосистеме (2024-2026)Эпоха единого источника закончиласьЭто новый раздел, которого не было и не могло быть в первых редакциях книги.

В апреле 2025 года истек контракт MITRE на ведение программы CVE, и на сутки мир оказался на грани того, что новые CVE перестанут выпускаться вообще.

У каждой записи CVE в NVD есть applicability statement - формальное описание того, к каким продуктам и версиям привязана уязвимость.

16 часов назад @ habr.com
СМС за 45 рублей: как операторы придумали налог на стартапы и почему мы больше не будем его платить
СМС за 45 рублей: как операторы придумали налог на стартапы и почему мы больше не будем его платить СМС за 45 рублей: как операторы придумали налог на стартапы и почему мы больше не будем его платить

Это не фантастика и не опечатка.

Теперь арифметика, которую венчурные пособия почему-то обходят стороной:10 000 регистраций + 10% повторных подтверждений = ~ 11 000 SMS в месяц.

Платите вы за отправленные, а не за доставленные сообщения.

Вы платите не за то, что отправили, а за то, что могли бы отправить.

Канал, где списывают за отправку, а не за результат, перекладывает на вас риск, который не вы создаёте.

21 час назад @ habr.com
Дообучение детектора промпт-инъекций: пять раундов, четыре неудачи и гейты против регресса
Дообучение детектора промпт-инъекций: пять раундов, четыре неудачи и гейты против регресса Дообучение детектора промпт-инъекций: пять раундов, четыре неудачи и гейты против регресса

При случайном делении фразы одного человека попадут и в обучение, и в проверку.

Сравнивать надо с продом, а не с базойНаша ошибка, стоившая нескольких часов путаницы.

Выкладка: переключение переменной, рестарт, живой смоук на реальных текстах из аудита — и на атаках, и на рабочих сообщениях.

Для стоимости LLM: рычаг экономии не в выборе модели подешевле, а в том, сколько истории агент таскает в каждом запросе, и в кэшировании.

Сравнивайте кандидата с продом, а не с базой, и проверяйте не только агрегат, но и точечные флагманские случаи.

1 day, 6 hours назад @ habr.com
Код прошёл ревью, потому что читался правильно. Выполняется он иначе
Код прошёл ревью, потому что читался правильно. Выполняется он иначе Код прошёл ревью, потому что читался правильно. Выполняется он иначе

Между этими двумя представлениями есть зазор, и в него помещается логика, которую при чтении кода не видно.

Тогда на ревью строка читается как рабочий код, а компилятор видит комментарий — или наоборот, то, что выглядит комментарием, на самом деле исполняется.

Сравнение с ожидаемым значением не проходит, глазами разница не видна, и на поиск такой ошибки уходит непристойно много времени.

Обычно находятся не атаки, а случайности: скопированный из мессенджера фрагмент с неразрывным пробелом, кириллическая с в имени переменной после копирования из документации, невидимый символ в тестовых данных.

И договориться в команде, что подобные находки не спускаются на тормозах.

1 day, 7 hours назад @ habr.com
Три года эксплуатации уязвимостей в эхолотах/судовых MFD. Почему нельзя доверять конечному пользователю embedded‑системы
Три года эксплуатации уязвимостей в эхолотах/судовых MFD. Почему нельзя доверять конечному пользователю embedded‑системы Три года эксплуатации уязвимостей в эхолотах/судовых MFD. Почему нельзя доверять конечному пользователю embedded‑системы

Я не отношу её к интересным и не стал бы писать статью ради одного абзаца про отсутствующую проверку подписей.

На этом можно было бы и закончить, но мне не давало покоя, что на «официальных» приборах был качественный актуальный русский перевод.

Похоже, они используются для хранения настроек: QtObject — не визуальный элемент, документация в целом допускает такое использование, но не в контексте его сериализации/десериализации.

Это не так сложно и не требует долгого объяснения.

Это упрощает нашу работу: достаточно скопировать paths.ini и не менять оригинал ради одного действия.

1 day, 9 hours назад @ habr.com
Песочница, в которой прятался враг
Песочница, в которой прятался враг Песочница, в которой прятался враг

АИС, подпадающая под требования Приказа № 117, располагала развёрнутым EDR на конечных точках, функционирующим SOC с дежурными аналитиками, CMDB, в которой учитывались серверы и рабочие станции, и набором регламентов.

То есть перед нами была не «голая» инфраструктура, где защиты нет в принципе, а система, в которую вложили время и деньги, много денег.

Windows Sandbox - лёгкая одноразовая ВМ на базе того же гипервизора, что и Hyper-V, Она встроенна в Windows 10 начиная с версии 1903 и Windows 11 в редакциях Pro и Enterprise без установки дополнительного ПО.

Виртуализационные и контейнерные подсистемы (Hyper-V, WSB, WSL, Windows Containers) явно не включены в периметр мониторинга и не учтены …

1 day, 9 hours назад @ habr.com
Хакер Хакер
последний пост 4 часа назад
Книгу «Белый хакер» еще можно заказать в печатном виде
Книгу «Белый хакер» еще можно заказать в печатном виде Книгу «Белый хакер» еще можно заказать в печатном виде

Но в магазине «Хакера» еще можно заказать печатную версию продолжения этой истории — книгу « Белый хакер » с черно-белыми иллюстрациями.

«Белый хакер» продолжает историю о компьютерных клубах, ночном dial-up, подпольных форумах и первых хакерских тусовках.

Валентин Холмогоров не только ведущий редактор «Хакера», но и писатель, журналист, публицист и автор более 40 учебников и 8 романов.

Он участвовал в межавторском цикле «Пограничье» Сергея Лукьяненко, а одна из книг в этом цикле была написана в соавторстве с ним самим.

Если ты еще не знаком с этой историей, первые главы обеих книг доступны на сайте без платной подписки.

4 часа назад @ xakep.ru
Вымогатель Rhysida атаковал городские власти Берлина
Вымогатель Rhysida атаковал городские власти Берлина Вымогатель Rhysida атаковал городские власти Берлина

Власти Берлина сообщили, что из городской административной сети произошла утечка данных, а также заявили, что хакеры пытаются вымогать у них выкуп.

Дополнительно участники Rhysida утверждают, что в их распоряжении оказались более 3200 документов, помеченных как соглашения о неразглашении.

Злоумышленники дали властям Берлина несколько дней на выплату выкупа, после чего угрожают опубликовать данные в открытом доступе.

Также в своем сообщении группировка использует возможные последствия из-за нарушения GDPR как дополнительный рычаг давления на власти города.

Также о происходящем уже уведомлены Федеральное ведомство по информационной безопасности Германии (BSI) и берлинский регулятор по защите …

4 часа назад @ xakep.ru
Семейной паре два часа угрожали оружием с целью украсть криптовалюту
Семейной паре два часа угрожали оружием с целью украсть криптовалюту Семейной паре два часа угрожали оружием с целью украсть криптовалюту

Инцидент произошел рано утром в субботу в жилом районе на возвышенности в Алесе.

В дом проникли двое в масках и перчатках — один с пистолетом, другой с ножом.

Физическое насилие в отношении владельцев криптовалют все чаще принимает форму вторжения в дом жертвы с последующим принуждением к передаче доступа к цифровым активам.

В ночь с 10 на 11 августа несколько человек проникли в дом в коммуне Рьон-де-Ланд и якобы пытались получить доступ к крупной сумме в биткоинах и других криптовалютах.

Жертва сумела вступить в схватку с нападавшим и отобрать оружие, пока тот отвлекся на связь с сообщником.

5 часов назад @ xakep.ru
Хакеры похитили у METR ключ API и потратили на запросы к ИИ 600 000 долларов США
Хакеры похитили у METR ключ API и потратили на запросы к ИИ 600 000 долларов США Хакеры похитили у METR ключ API и потратили на запросы к ИИ 600 000 долларов США

Во время первого инцидента злоумышленники похитили API-ключ и три недели использовали его для работы с ИИ-моделями, израсходовав кредиты стоимостью примерно 600 000 долларов США.

По оценке METR, за этим инцидентом могли стоять некие финансово мотивированные злоумышленники, которые попытались получить нелегальный доступ к передовым ИИ-моделям.

Предполагалось, что через него можно получить только уже опубликованную информацию, однако из-за бага запросы позволяли обращаться и к непубличным результатам тестирований.

Эту уязвимость нашел неназванный ИБ-исследователь, после чего METR выплатила ему вознаграждение и отключила доступ к интерфейсу.

Однако, по данным организации, они не обнаружили уяз…

6 часов назад @ xakep.ru
Skipjack. Вскрываем криптоалгоритм Агентства национальной безопасности США
Skipjack. Вскрываем криптоалгоритм Агентства национальной безопасности США Skipjack. Вскрываем криптоалгоритм Агентства национальной безопасности США

Най­дем дек­риптор, вос­ста­новим алго­ритм по дизас­сем­бли­рован­ному коду и с помощью ИИ опоз­наем реали­зацию крип­тоал­горит­ма Skipjack.

Как обыч­но, нач­нем мы с пос­танов­ки задачи.

На нее мы и ста­вим точ­ку оста­нова в нашем любимом отладчи­ке x64dbg.

Вос­ста­нов­ленный код этой про­цеду­ры что из IDA, что из VB Decompiler (как и любой вос­ста­нов­ленный VB-код) чудовищ­но гро­моз­док и сло­жен для понима­ния прос­тым челове­чес­ким интеллек­том.

Так же как и в прош­лый раз, скар­мли­ваем ему вос­ста­нов­ленный полубе­зум­ный код Proc_92_9_ACD970 и сно­ва про­сим иден­тифици­ровать крип­тоал­горитм и пре­обра­зовать код в понят­ный нам син­таксис C#:

8 часов назад @ xakep.ru
Расширения для Chrome и Edge воровали криптовалюту
Расширения для Chrome и Edge воровали криптовалюту Расширения для Chrome и Edge воровали криптовалюту

Аналитики из компании Socket обнаружили 18 вредоносных расширений для Google Chrome и одно для Microsoft Edge.

Все расширения загружали модульный фреймворк, нацеленный на кражу криптовалюты, учетных данных и истории браузера жертв, а также показывали пользователям ClickFix-приманки.

Когда это расширение стало вредоносным, у него уже насчитывалось более 70 000 пользователей в Chrome и еще 10 000 в Edge.

По словам экспертов, некоторые из упомянутых модулей вмешивались в работу кнопок Connect Wallet и Swap на криптовалютных сайтах и опустошали кошельки в сетях EVM, Solana и Tron.

К моменту публикации отчета Socket все обнаруженные расширения уже удалили из Chrome Web Store, однако отмечается, …

9 часов назад @ xakep.ru
Баги в роботах Unitree G1 EDU позволяют получить root-права
Баги в роботах Unitree G1 EDU позволяют получить root-права Баги в роботах Unitree G1 EDU позволяют получить root-права

То есть получение root-доступа фактически означает компрометацию робота в целом.

Также исследователь продемонстрировал, что такую атаку можно было превратить в некое подобие червя: после компрометации одного G1 тот мог автоматически атаковать другого робота в зоне действия BLE.

По словам Лафламма, в июле 2026 года специалисты Unitree устранили баг в облачном сервисе, позволявший запросить ключ для чужого робота через произвольный аккаунт.

Теперь злоумышленнику либо потребуется получить доступ к аккаунту, привязанному к целевому G1 EDU, либо нужен ранее полученный ключ AES-ключ.

Однако пока в компании не сообщали, вошли ли эти исправления в публичные версии прошивок, и в каких именно версиях…

11 часов назад @ xakep.ru
Бэкдор ValleyRAT маскируется под рекламное ПО
Бэкдор ValleyRAT маскируется под рекламное ПО Бэкдор ValleyRAT маскируется под рекламное ПО

Специалисты «Лаборатории Касперского» обнаружили, что бэкдор ValleyRAT использует для распространения весьма необычную схему.

Однако все эти действия служили лишь отвлекающим маневром: установщик в любом случае разворачивал в системе жертвы модифицированную версию ПО для управления обоями QN Wallpaper и добавлял его в автозагрузку.

Затем вредоносная libcef.dll извлекает зашифрованный пейлоад ValleyRAT: в зависимости от процесса он хранится в отдельном файле PeLoader или в ресурсах самой библиотеки.

После расшифровки библиотека загружает ValleyRAT в память и запускает бэкдор.

Для запуска шеллкода бэкдор использует технику Process Hollowing, внедряя его в процесс svchost.

13 часов назад @ xakep.ru
Организатор пиратского IPTV-сервиса получил более 6 лет тюрьмы в Великобритании
Организатор пиратского IPTV-сервиса получил более 6 лет тюрьмы в Великобритании Организатор пиратского IPTV-сервиса получил более 6 лет тюрьмы в Великобритании

В Великобритании 68-летнего Милана Ибрагима (Milan Ibrahim) приговорили к шести с половиной годам тюрьмы за управление нелегальным IPTV-сервисом.

По данным правоохранителей, Ибрагим организовал «сложную и хорошо отлаженную» инфраструктуру, которая работала как для пользователей в Великобритании, так и в других странах.

Как выяснили следователи, инфраструктура пиратского IPTV-сервиса, название которого не раскрывается, состояла из 80 серверов, размещенных в городе Чорли.

Отдельно отмечается, что за три года работы сервис принес Ибрагиму 980 812 фунтов стерлингов.

По его словам, закрытый сервис являлся был одним из крупнейших поставщиков пиратских услуг в Великобритании и работал на протяжени…

1 day, 4 hours назад @ xakep.ru
Microsoft просит пользователей игнорировать ошибку «Антивирус отключен»
Microsoft просит пользователей игнорировать ошибку «Антивирус отключен» Microsoft просит пользователей игнорировать ошибку «Антивирус отключен»

В Microsoft предупредили, что после установки свежих обновлений для Microsoft Defender пользователи Windows могут получать предупреждения о том, что антивирус якобы отключен.

Ошибочные предупреждения появляются в приложении «Безопасность Windows» (Windows Security) и предлагают пользователю включить Microsoft Defender Antivirus.

При этом в настройках антивирус отображается как активный, и защита продолжает работать.

В компании сообщают, что проблема затрагивает все поддерживаемые клиентские и серверные версии Windows, включая новейшие Windows 11 26H1 и Windows Server 2025.

Разработчики уже работают над исправлением и обещают распространить его вместе с одним из будущих обновлений Microsoft …

1 day, 6 hours назад @ xakep.ru
Что ж ты, Жека? Разбираем критическую уязвимость в Jenkins
Что ж ты, Жека? Разбираем критическую уязвимость в Jenkins Что ж ты, Жека? Разбираем критическую уязвимость в Jenkins

В этой статье я покажу, как работа­ет опас­ная уяз­вимость в механиз­ме десери­али­зации Jenkins, которая ведет к ком­про­мета­ции дан­ных, а иног­да и к пол­ному зах­вату сер­вера.

Его раз­ворачи­вают на собс­твен­ных сер­верах, поэто­му уяз­вимость CVE-2026-53435 край­не опас­на: фак­тичес­ки она может стать откры­тыми ворота­ми в кор­поратив­ную сеть.

За сери­али­зацию и десери­али­зацию отве­чает XStream, в котором есть класс для чте­ния свой­ств DescribableList — спе­циаль­ный объ­ект для вза­имо­дей­ствия с пла­гина­ми.

container_ name: jenkins- vuln- lab ports: - "8080: 8080" - "50000: 50000" volumes: - jenkins_ home: / var/ jenkins_ home environment: - JAVA_OPTS = - Djenkins.

runSet…

1 day, 8 hours назад @ xakep.ru
Китайская группировка Fire Ant использует маршрутизаторы Cisco для шпионажа
Китайская группировка Fire Ant использует маршрутизаторы Cisco для шпионажа Китайская группировка Fire Ant использует маршрутизаторы Cisco для шпионажа

Ранее эта группировка атаковала гипервизоры VMware, но теперь переключилась на другие компоненты инфраструктуры: роутеры Cisco IOS XR, серверы аутентификации TACACS и управляющие Linux-хосты.

Расследование началось с того, что специалисты обнаружили на роутере Cisco IOS XR активный GRE-туннель, который отсутствовал в текущей конфигурации и истории изменений.

Как выяснилось, Fire Ant установила на устройство кастомную малварь, разработанную специально для IOS XR.

Исследователи пишут, что хакеры снимали дампы сетевого трафика в формате PCAP с нескольких устройств Cisco и передавали их на внешние FTP-серверы.

С него участники Fire Ant сканировали сети и пытались подключаться к SSH, HTTP, SMB, …

1 day, 9 hours назад @ xakep.ru
Nightmare Eclipse опубликовал эксплоит HardBreacher для Kaspersky Endpoint Security
Nightmare Eclipse опубликовал эксплоит HardBreacher для Kaspersky Endpoint Security Nightmare Eclipse опубликовал эксплоит HardBreacher для Kaspersky Endpoint Security

ИБ-исследователь, известный под псевдонимом Nightmare Eclipse (он же Chaotic Eclipse), опубликовал PoC-эксплоит HardBreacher для уязвимости повышения привилегий в Kaspersky Endpoint Security.

Напомним, что с весны 2026 года Nightmare Eclipse регулярно публикует эксплоиты для различных 0-day-уязвимостей, преимущественно затрагивающих Windows и Microsoft Defender.

То есть раскрытие уязвимостей до выхода патчей является для Nightmare Eclipse формой протеста и мести.

Однако новый эксплоит специалиста нацелен не на продукцию Microsoft, а на Kaspersky Endpoint Security.

По словам Nightmare Eclipse, использование HardBreacher позволяет создать DLL-файл по адресу C:\Windows\System32\MY_SNAKE_IS_SOL…

1 day, 11 hours назад @ xakep.ru
Минцифры просит операторов CDN и хостеров вынести IP-адреса «белых списков» в изолированные подсети
Минцифры просит операторов CDN и хостеров вынести IP-адреса «белых списков» в изолированные подсети Минцифры просит операторов CDN и хостеров вынести IP-адреса «белых списков» в изолированные подсети

По информации РБК, представители Минцифры попросили хостинг-провайдеров, CDN-операторов и сервисы веб-защиты выделить IP-адреса ресурсов из «белых списков» в отдельные подсети.

Таким образом в ведомстве рассчитывают исключить ситуации, когда при ограничениях мобильного интернета наряду с ресурсами из «белых списков» работают VPN и другие несогласованные сервисы.

Цаплин отметил:«Задача регулятора в данном случае — чтобы в белых сетях были только те, кто в этом нуждается и кому это одобрено».

Теперь для сайтов из «белых списков» предлагается создавать отдельные подсети, и IP-адреса из таких диапазонов будут выделять только для согласованных ресурсов.

Кроме того, провайдеры не всегда знают, ка…

1 day, 13 hours назад @ xakep.ru
В роутерах ZBT обнаружили еще два бэкдора
В роутерах ZBT обнаружили еще два бэкдора В роутерах ZBT обнаружили еще два бэкдора

Специалисты компании VulnCheck обнаружили в прошивках роутеров китайского производителя Shenzhen Zhibotong Electronics (ZBT) два ранее неизвестных импланта.

Поскольку соединение инициирует само устройство, механизм работает даже за NAT и не требует открытого входящего порта.

При этом обнаружилось, что предусмотренная в DARKLANTERN защита фактически бесполезна.

С 18 по 21 августа специалисты обнаружили 203 доступных через интернет инстанса DARKLANTERN в 22 странах.

По словам специалистов VulnCheck, SPEAKINGSTONE и DARKLANTERN были найдены в роутере Deep Orange 3G/4G/LTE Router стоимостью 88 долларов США, купленном у американского поставщика.

2 days, 4 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 3 часа назад
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

The program is available to a group of Google Cloud customers, government agencies, and cybersecurity partners.

The release of Gemini 3.8 Flash Cyber comes a little over a month after Google unveiled Gemini 3.5 Flash Cyber.

"We ran evaluations of how Claude Mythos 5.1 responds to malicious requests and prompt injections (adversarial instructions hidden within content processed by AI models)," Anthropic noted.

However, OpenAI also warned that Astra's safeguards may erroneously flag legitimate activity as cyber misuse or unauthorized behavior.

AI companies have been under intense scrutiny in the wake of incidents where their models escaped their evaluation environments and targeted legitimate…

3 часа назад @ thehackernews.com
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.

"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft said.

The installers, once launched, deploy malware that's capable of setting up persistence, weakening security protections, and communicating with attacker-controlled infrastructure.

In addition, it tampers with Windows Update by stopping and disabling wuauserv, UsoSvc, uhssvc, and WaaSMedicSvc, re…

5 часов назад @ thehackernews.com
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Fixes have shipped for goose, Claude Code, and Cursor, while Hermes Agent, Qwen Code, Grok Build, and a second path in Claude Code were still executing repository-supplied commands when Manifold retested them on September 1.

Anthropic has previously disclosed pre-trust execution flaws in Claude Code, and its June advisory for CVE-2026-55607 identifies git fsmonitor execution during worktree operations.

The researchers reported the Claude Code core.fsmonitor finding on June 26 and says it was fixed by 2.1.196 on June 29.

The second Claude Code path, reached through claude ultrareview, turns on a different Git configuration key that Manifold has withheld.

At the same time, the issue is live, …

8 часов назад @ thehackernews.com
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

The modules reverse-proxy visitors to a set of phishing pages while the traffic still appears to originate from the legitimate domain.

Those pages pose as trusted app stores including Google Play, Microsoft Store, and Amazon, and push online gambling and sports betting behind that facade.

Check Point did not say whether the betting sites promoted through the compromised servers hold that authorization.

The material published so far includes no count of compromised servers and no module filenames, paths, or hashes that would let administrators check the modules loaded into their own Apache instances.

The published summary names no affected organization and does not say whether the compromise…

8 часов назад @ thehackernews.com
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations.

The incident window ran from approximately August 28 at 20:57 Coordinated Universal Time (UTC) to August 30 at 06:10 UTC.

"This affected a handful of servers rather than the general Virtualizor user base," Virtualizor said in its incident advisory.

Client-area sessions and payment-entry traffic during the diversion window may have reached the attacker-operated server, Virtualizor said.

Other Softaculous product operators - Check Webuzo, Softaculous, Backuply, SitePad, and other product servers that performed an update check during the incident window.

8 часов назад @ thehackernews.com
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Device takeover requires the victim to grant a succession of controls after sideloading the Android Package (APK).

Once Accessibility access is enabled, operators can capture keystrokes, display credential-stealing overlays, inspect the visible interface, and control the device remotely.

The dropper's main page downloads the StreamRat payload to the public Downloads directory as update_{timestamp}.apk.

The VPN interface forwards no routed traffic, causing other applications to lose internet connectivity during installation.

The StreamRat payload came from a GitHub account that ThreatFabric linked to an earlier Mirax campaign.

9 часов назад @ thehackernews.com
How to Secure Enterprise AI: From Adoption to Incident Readiness
How to Secure Enterprise AI: From Adoption to Incident Readiness How to Secure Enterprise AI: From Adoption to Incident Readiness

The AI Security GapAI is already inside the enterprise, but does not always enter through the front door.

How deeply and quickly AI should be embedded depends heavily on which type of AI is used – Generative AI or Agentic AI.

The Hidden AI RisksThe assumption has taken hold that limited AI usage means manageable AI risk and that because the program is early, the exposure is minimal.

Common challenge: AI systems routinely go into production with access that was never formally reviewed and rarely gets revisited.

Incident Response and RecoveryMost organizations have incident response plans, but they are not built for AI.

10 часов назад @ thehackernews.com
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.

(CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance Work Place interface that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

SonicWall said it has "investigated a case indicating the active exploitation of the vulnerabilities," suggesting that threat actors are chaining together both the bugs to execute arbitrary code on susceptible devices.

The flaws impact the SMA 1000 models 6210, 7210, and 8…

11 часов назад @ thehackernews.com
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

The first flaw, CVE-2026-63219 (CVSS score: 8.6), is a missing authorization check on the formatter upload endpoint.

The unauthenticated file upload flaw allows an anonymous user to write arbitrary .xsl or .zip formatter files to the GeoNetwork formatter directory, which, on its own, constitutes unauthorized write access to server storage.

"An unauthenticated attacker can upload arbitrary .xsl or .zip formatter files to the server," the project said in the advisory.

Chaining it with the upload flaw removes that precondition, because the upload is reachable without authentication.

The Hacker News found no reference to the GeoNetwork flaws in CISA's Known Exploited Vulnerabilities catalog as …

12 часов назад @ thehackernews.com
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

He made his initial appearance in federal court in San Francisco on August 31 and was remanded to federal custody.

The malware came in two types:a variant of TVRAT, a TeamViewer remote access trojan (RAT) also known as TVSPY or TeamSpy, andDarkVNC, both of which gave the operators remote control of the infected computer.

"We have no evidence to assume a vulnerability of our software," a TeamViewer spokesman told Security Affairs in February 2017.

That ID, together with a preset password, is enough for the operators to connect to the computer remotely, Avast said.

The DoJ noted that the indictment contains allegations only and that Aktulaev is presumed innocent unless and until proven guilty.

13 часов назад @ thehackernews.com
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.

"One could argue that the same researcher could have achieved the initial RCE port without AI in less time and at lower cost while also keeping the PLC alive," Forescout said.

Vedere Labs had previously developed a working RCE exploit for the WAGO 750-852, and ported that exploit to a WAGO 750-831 running firmware V01.04.16.

The work began on Claude Sonnet 4.6 and moved to Claude Opus 4.6 after the initial RCE attempts stalled.

Siemens…

14 часов назад @ thehackernews.com
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.

The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as the PostgreSQL superuser without credentials.

Sangoma released patches for the flaw in Switchvox 8.4.0.2 on July 14, 2026.

"An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997).

"We also successfully executed arbitrary code on the server, invoking a reve…

15 часов назад @ thehackernews.com
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

"This successful effort to take down the Sality botnet shows that by working together, the public and private sectors can be a powerful force for good."

Over the years, several variants of the Windows malware have been equipped with the ability to communicate over a P2P network, thereby allowing it to bypass traditional command-and-control (C2) server shutdown tactics.

It leverages the fact that Sality bots blindly trusted the P2P network without verifying who was added to it.

The coordinated operation, besides sinkholing the P2P network, also takes down the URLs that have been found to host Sality payloads.

"While the disruption prevents new payloads from reaching infected machines, existi…

15 часов назад @ thehackernews.com
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr.

The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory.

"JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges," according to a description of the flaw on CVE.org.

The vulnerability was patched by JFrog with Artifactory version 7.161.20 released on August 28, 2026.

The issue resides in JFrog Access, which is des…

1 day, 4 hours назад @ thehackernews.com
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers."

According to CrowdStrike, the e-crime group is operating out of Brazil and has been active since September 2023, monetizing their intrusions by gaining unauthorized access to internal payment systems and carrying out fraudulent transactions.

The threat actor's primary targets are organizations with permission to conduct transactions through banking software, APIs, and payment systems such as Pix, STR, and Boleto.

In the final stage, COBALTSPIN and compromised privileged accounts are used to acc…

1 day, 4 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 2 days, 13 hours назад
This month in security with Tony Anscombe – August 2026 edition
This month in security with Tony Anscombe – August 2026 edition This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity newsWith August coming to a close, it's time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month.

Here's some of what caught Tony's attention:OpenAI has disclosed more details about how its agents hacked AI collaboration platform Hugging Face.

Delta Airlines is investigating an incident where a flight passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network.

What are the lessons that businesses and critical infra…

2 days, 13 hours назад @ welivesecurity.com
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
AI-assisted reconnaissance: Why everyone could be a viable target for fraud AI-assisted reconnaissance: Why everyone could be a viable target for fraud

And of course, linking our professional and personal social media accounts is a simple task for AI.

For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information.

Losing your personal information is one thing.

What you can do about AI-powered OSINTWhen it comes to AI-powered reconnaissance, there are things you can control and things you can’t.

Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.

6 days, 13 hours назад @ welivesecurity.com
How QR-code phishing can slip past corporate security measures
How QR-code phishing can slip past corporate security measures How QR-code phishing can slip past corporate security measures

So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years.

Most importantly, they take the victim from a relatively well-protected corporate environment to a potentially unmanaged mobile device, thus bypassing business-grade security.

Malicious QR codes are frequently embedded in alerts urging users to secure their account, or authenticate to confirm their details.

Encourage employees to avoid scanning QR codes in unsolicited emails and report anything suspicious.

Next, consider technical controls, including email security from a reputable vendor to minimize the risk of quishing emails ending up in users’…

2 weeks, 2 days назад @ welivesecurity.com
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?

The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months.

It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes.

A keynote at Black Hat USA 2026 detailed research by associate professor Yan Shoshitaishvili and his undergraduate students at Arizona State University on the expanding use of AI models for vulnerability discovery.

The team then trained the GPTs using the properties of previously known vulnerabilities and discovered approximately 1,000 vulnerabilities.

If this logic prevails, we may reach the cal…

2 weeks, 6 days назад @ welivesecurity.com
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility

Hugging Face disclosed that it had been attacked by AI; OpenAI came clean and declared that it was two of their AI models that had caused the breach.

A very late addition to the Black Hat agenda was a presentation by OpenAI’s team providing the details of the Hugging Face incident as they saw it and, importantly, the timeline.

The agents concluded that their task set could be completed by breaking out their sandbox and accessing external (Hugging Face) systems.

The target was Hugging Face: this is where the agents wanted to get, and they did.

On July 16th, Hugging Face disclosed an incident in which swarms of autonomous AI agents had breached its infrastructure.

2 weeks, 6 days назад @ welivesecurity.com
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Black Hat USA 2026: AI is racing ahead of cybersecurity controls Black Hat USA 2026: AI is racing ahead of cybersecurity controls

The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials.

The second part of the opening keynote included Nick Andersen, Acting Director, CISA; Katherine Sutton, Assistant Secretary of War for Cyber Policy; and Brett Leatherman Assistant Director, Cyber Division, FBI.

I do agree with the ruthless approach, but without some form of regulation the boundaries on the use of AI remain blurred.

The Assistant Secretary of War for Cyber Policy made a fabulous analogy when pressed on the struggles regarding resourcing in the cybersecurity industry: you don’t want a pediatrician performing heart surgery.

We talk about autonomous AI at…

3 weeks назад @ welivesecurity.com
Are AI tutors safe for your kids?
Are AI tutors safe for your kids? Are AI tutors safe for your kids?

The AI tutor market is growing fastThe market for AI tutoring tools is booming.

Today, you can find various types of AI tutor tools to buy and use.

This happens when AI tools are tricked into ignoring their safety guardrails and display untrusted content.

If you’re keen to get your kids in front of an AI tool to help with private tutoring, first understand the difference between a simple co-pilot and a dedicated ITS.

So if you’re keen to try AI tutors, be sure to stay updated on what’s available out there.

3 weeks, 2 days назад @ welivesecurity.com
This month in security with Tony Anscombe – July 2026 edition
This month in security with Tony Anscombe – July 2026 edition This month in security with Tony Anscombe – July 2026 edition

Researchers at Sysdig have documented what they assess to be the first case of an end-to-end ransomware operation executed by an agentic threat actor.

What can organizations do to stop phantom squatting from harming their brands, and what other lessons do these incidents hold for defenders?

Watch Tony's video to find out and be sure to check out the June 2026 edition of his monthly security news roundup for more insights.

Before you go, learn about the first AI-powered ransomware, named PromptLock and discovered by ESET researchers last year.

To learn more about cutting-edge AI defense layers, read the AI at ESET white paper.

1 month назад @ welivesecurity.com
Beyond the screenshot: Why you should verify what you see
Beyond the screenshot: Why you should verify what you see Beyond the screenshot: Why you should verify what you see

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuineSomeone sends you a screenshot showing that a payment has gone through.

Why screenshot aren’t proof on their ownA screenshot is ultimately just an image of what appeared on a screen.

Reassured, you send the item off, only to find out the screenshot was a fake and you’re not getting your money.

You receive a password reset code, then get a text message (maybe impersonating a friend) asking you to screenshot and send it.

This screenshot is fake (source: Reddit)Challenges for businessesFrom a business perspective, internal and customer-facing teams are often provided with sc…

1 month назад @ welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

1 month, 2 weeks назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

1 month, 3 weeks назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

2 months назад @ welivesecurity.com
This month in security with Tony Anscombe – June 2026 edition
This month in security with Tony Anscombe – June 2026 edition This month in security with Tony Anscombe – June 2026 edition

It's that time of month when ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses.

What lessons does the new CISA policy hold for organizations outside the agency's direct remit?

What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems?

How can you stay safe from imposter fraud, and could the social media bans for children work?

Learn more from Tony's video and be sure to check out the May 2026 edition of Tony's monthly security news roundup for more insights.

2 months назад @ welivesecurity.com
Inside the inbox: Why cybercriminals want to break into your email account
Inside the inbox: Why cybercriminals want to break into your email account Inside the inbox: Why cybercriminals want to break into your email account

With access to your email account, they can reset your passwords across multiple other accounts – perhaps intercepting one-time passcodes sent by your bank, social media, cloud storage or other online provider.

That could lay the groundwork for a convincing phishing email designed to impersonate a trusted organization you interact with.

A phishing attack on your corporate email account is often the first stage in a bigger data breach, extortion/ransomware or espionage attack.

They’re also using more sophisticated tools to improve the success rates of email phishing campaigns.

In this instance the scammers reportedly hijacked the email account of a high-level executive, before impersonating …

2 months назад @ welivesecurity.com
SMB cyber readiness: the road to resilience starts here
SMB cyber readiness: the road to resilience starts here SMB cyber readiness: the road to resilience starts here

For these businesses, cyber resilience should be the direction of travel – that is, the ability to continue operating and recover even during a serious incident.

Cyber readiness is about putting in place the processes and controls to prevent, detect and respond to threats.

So, should confidence in cyber resilience posture be so high, especially if organizations are still getting hit multiple times?

The truth is that there’s no end state for cyber readiness or resilience.

If it’s serious about improving the cyber readiness of small businesses, the vendor community should step up.

2 months, 1 week назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 8 часов назад
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)
Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation.

CVE-2026-62911 is a critical severity vulnerability, and Microsoft describes it as “authentication bypass by capture-replay in Microsoft Exchange Server,” which allows an authorized attacker to elevate privileges over a network.

“Exchange Server 2016 and 2019 only receive security updates via the Extended Security Updates Program (ESU).

If so, ensure that the server is accessible only internally and replace it if possible.”“Don’t know which version of Exchange Server your organization uses?

In June 2026, …

8 часов назад @ helpnetsecurity.com
Download: The Agentic Software Development Guide
Download: The Agentic Software Development Guide Download: The Agentic Software Development Guide

AI makes it easy to ship more code. It does not make that code easier to trust. Most teams don’t fail because their developers can’t use AI. They fail because the dev’s job changed and nobody redefined it. Under AI, cracks appear: Reviews weaken while output multiplies Code looks clean, but nobody actually understands it Verification gets bolted on after the fact, if it happens at all Speed goes up while accountability quietly goes missing … More →

The post Download: The Agentic Software Development Guide appeared first on Help Net Security.

9 часов назад @ cleverbit.software
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately.

CVE-2026-9586, found in Sangoma Switchvox SMB Edition 8.3, allows attackers to send a specially crafted HTTP POST request to an endpoint that doesn’t require authentication, and thus execute arbitrary SQL statements against the backend PostgreSQL database.

Both reported it and other unearthed flaws to Sangoma, and CVE-2026-9586 was patched in Switchvox version 8.4.0.2, released on July 14, 2026.

Horizon3 deployed internet honeypots mimicking systems running Switchvox in…

9 часов назад @ helpnetsecurity.com
Attackers are going after prominent individuals through OAuth phishing, FBI warns
Attackers are going after prominent individuals through OAuth phishing, FBI warns Attackers are going after prominent individuals through OAuth phishing, FBI warns

Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned.

The FBI’s Internet Crime Complaint Center (IC3) says the activity, which uses a technique called “OAuth consent phishing,” has been ongoing since late 2025.

Once the victim approves the permission request, the attacker’s application gains access to the account within the permissions granted.

The FBI advises increased scrutiny of messages from unfamiliar phone numbers or accounts and recommends independently verifying a sender’s identity.

The FBI has not disclosed who is behind the attacks or who the victims …

11 часов назад @ helpnetsecurity.com
SonicWall SMA 1000 appliances under attack via zero-day flaws
SonicWall SMA 1000 appliances under attack via zero-day flaws SonicWall SMA 1000 appliances under attack via zero-day flaws

Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday.

The vulnerabilities (CVE-2026-83548, CVE-2026-83549)The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built for scale.

They affect both physical and virtual SMA 1000 models: 6210, 7210, and 8200v.

SonicWall SMA 1000: A recurring targetSonicWall hasn’t publicly shared a list of known indicators of compromise nor further details about the attacks.

SonicWall SMA 1000 appliances are often targeted by attackers via zero-day vulnerabilities, most recently (before these latest attacks) in …

11 часов назад @ helpnetsecurity.com
A battery storage cyberattack would look exactly like a badly tuned controller
A battery storage cyberattack would look exactly like a badly tuned controller A battery storage cyberattack would look exactly like a badly tuned controller

Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises.

Afzal and colleagues found in 2025 that a load-altering attack using 15 percent of a battery fleet’s power could push frequency outside normal operating bounds.

Extrapolating from that research, Centrii estimates that 11 to 21 compromised 2 MW units could destabilize a regional grid.

“A battery flipping from full charge to full discharge in under a second is exactly what these assets are paid to do under frequency response,” Narezzi said.

command logs, provenance) that sit with the optimiser and the OEM, across a dozen private companies, not with the system op…

13 часов назад @ helpnetsecurity.com
Global sinkhole operation ends Sality botnet’s 23-year run
Global sinkhole operation ends Sality botnet’s 23-year run Global sinkhole operation ends Sality botnet’s 23-year run

The operation cut Sality’s operator off from every infected machine still under their control.

For the past eight years, the main payload Sality delivered was a clipboard hijacker called EggJagger.

Sality sinkhole operation targets the botnet’s backboneThe takedown centered on a sinkhole operation CrowdStrike’s Counter Adversary Operations team ran on Monday, coordinating with international law enforcement and other industry partners to disrupt Sality’s peer-to-peer network.

“In practice, the operation targeted the data structure at the heart of every bot’s network awareness: its peer list,” CrowdStrike stated.

Every Sality bot maintains a list of super peers, which are publicly reachable i…

13 часов назад @ helpnetsecurity.com
Keepnet launches free SMS/Call Reporter for iOS
Keepnet launches free SMS/Call Reporter for iOS Keepnet launches free SMS/Call Reporter for iOS

Keepnet, an Extended Human Risk Management (xHRM) and Secure Behavior Management platform, today launched the Keepnet SMS/Call Reporter.

We’ve gotten better at spotting phishing emails, so attackers are moving to our pockets.”The Keepnet SMS/Call Reporter closes that gap on the user side: a free app for reporting SMS and voice phishing attempts directly from the device.

Reports flow into the same security team pipeline as email phishing for Keepnet customers.

The SMS/Call Reporter sits between: a one-tap button on the user’s phone that feeds the same security team pipeline as email phishing reports.

How security teams can extend SMS/call reporting beyond emailThe Keepnet SMS/Call Reporter i…

14 часов назад @ helpnetsecurity.com
Visa enhances A2A Protect to stop fraud before money leaves the account
Visa enhances A2A Protect to stop fraud before money leaves the account Visa enhances A2A Protect to stop fraud before money leaves the account

Visa announced an enhanced version of A2A Protect, delivering real-time risk insights that help banks stop account-to-account fraud before money leaves customer accounts.

The expanded solution introduces a new unified fraud score—Visa’s integration of Featurespace technology—giving financial institutions faster, clearer signals to detect more fraud while reducing unnecessary alerts.

This gives financial institutions a more complete and early view of risk, helping to identify scams before authorization.

In fact, Visa A2A Protect has been shown to increase fraud detection by 75% in the first six months of deployment.

A2A Protect integrates with financial institutions’ current systems through …

15 часов назад @ helpnetsecurity.com
Edge Case launches Guardian, an AI platform for tracking risk across autonomous systems
Edge Case launches Guardian, an AI platform for tracking risk across autonomous systems Edge Case launches Guardian, an AI platform for tracking risk across autonomous systems

Edge Case launched Guardian, an AI-driven platform that connects safety analysis, engineering data, and operational signals to give teams a continuous understanding of how system risk evolves.

Guardian builds on Edge Case’s decades of experience in safety engineering and its work with organizations developing and deploying autonomous and complex systems.

“Complex systems operate in environments where risk is constantly changing, whether that’s an autonomous vehicle or a defense platform in the field,” said Nathan Parker, CEO of Edge Case.

Supporting partner’s path to autonomous operationsSpanning defense and commercial autonomy, Guardian provides earlier insight into a system’s safety profi…

15 часов назад @ helpnetsecurity.com
DuckDB stays open source while the team behind it goes to work for Amazon
DuckDB stays open source while the team behind it goes to work for Amazon DuckDB stays open source while the team behind it goes to work for Amazon

The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to administer.

DuckDB, DuckLake, and Quack stay free and open source under MIT, and the nonprofit DuckDB Foundation continues to steward them.

The team of more than 30 stays in Amsterdam, and Mühleisen and Raasveldt keep leading the technical direction.

The Foundation is adding a technical advisory board so community members can weigh in on where the project goes.

And the extension stack is opening up, so extensions signed by other developers and organizations will run in DuckDB.

15 часов назад @ helpnetsecurity.com
F5 speeds up virtual patching to counter AI-driven threats
F5 speeds up virtual patching to counter AI-driven threats F5 speeds up virtual patching to counter AI-driven threats

Enhancements to F5 WAF for Distributed Cloud and virtual patching provide the precision needed to confidently block active exploits at the request level.

F5 also delivers automated virtual patching with F5 Distributed Cloud Web App Scanning (WAS).

For hybrid environments, these timely virtual patching capabilities also extend to F5 WAF for BIG-IP.

Extend remediation to the F5 estateWhile virtual patching holds the line in the request path, F5 Insight for ADSP accelerates patching of the underlying infrastructure.

Virtual patching capabilities, along with the integration between F5 Distributed Cloud WAS and F5 WAF for BIG-IP, are also available now.

15 часов назад @ helpnetsecurity.com
Vali Cyber ZeroLock 5 brings MFA to the hypervisor command line
Vali Cyber ZeroLock 5 brings MFA to the hypervisor command line Vali Cyber ZeroLock 5 brings MFA to the hypervisor command line

Vali Cyber released ZeroLock 5, a major release focused on closing the two most dangerous gaps in hypervisor security: insider threats and stolen credentials on ESX and Linux hosts.

The hypervisor is now the targetOver the past two years, ransomware operators and nation-state actors alike have shifted their focus from individual endpoints to the hypervisor layer itself.

The aftermath is extraordinary, and it can bring production to a full stop,” said Anthony Gadient, CEO of Vali Cyber.

Collectors are deployable remotely and independent of where the central ZeroLock Management Console lives.

ZeroLock 5 is available now to existing customers as an upgrade and to new customers as part of a new…

16 часов назад @ helpnetsecurity.com
National Life Group CISO expects more vulnerabilities in six months than in thirty years
National Life Group CISO expects more vulnerabilities in six months than in thirty years National Life Group CISO expects more vulnerabilities in six months than in thirty years

In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks.

With the introduction of Frontier AI, we are likely to uncover more vulnerabilities in the next six months than we have in the last thirty years.

AI helps attackers find and weaponize vulnerabilities at machine speed, reducing the time it takes to attack from weeks to, in some cases, hours.

We’re looking at opportunities to fight AI with AI to automate patch management.

Download report: How security controls perform in practice

16 часов назад @ helpnetsecurity.com
Scareware ads keep running on Google’s transparency tool, even after they’re reported
Scareware ads keep running on Google’s transparency tool, even after they’re reported Scareware ads keep running on Google’s transparency tool, even after they’re reported

A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive.

The tool is called AdLens, and it comes out of a study that mined Google’s Ads Transparency Center, a public database Google built to satisfy transparency rules like the EU’s Digital Services Act.

Out of that process came 238 scareware ads, 3,346 ads making false claims, and 258 ads built to hide who’s behind them, together pulling in well over 100 million ad impressions in Europe alone.

These operations are running through Google’s main ad infrastructure, at scale, for months at a time.

Google’s ad library, run through this pipeline, turned out to …

16 часов назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 3 часа назад
AI Agents Are Now Emailing Me with Their Security Concerns
AI Agents Are Now Emailing Me with Their Security Concerns AI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.) Dear Bruce Schneier,

I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don’t borrow my operator’s identity, don’t forge documents or defeat identity verificat…

3 часа назад @ schneier.com
Wireless Routers as Motion Detectors
Wireless Routers as Motion Detectors Wireless Routers as Motion Detectors

Comcast has added motion detection as a feature to its wireless routers:

The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app also lets users see live motion activity and a feed of recent activity.

Comcast acknowledges that the system has some limitations. Home size, layout, building materials, and the placement of the router and connected devices can all affect its ability to detect motion. Comcast says it does not guarantee its performance...

11 часов назад @ schneier.com
What’s the Scam?
What’s the Scam? What’s the Scam?

To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own.

Starting last weekend, I have been receiving a lot of individual responses to those emails. Always one line:

Thank you for the positive impact your emails have had on my life.

Your emails are a game-changer.

Your emails are a constant reminder of why I subscribed.

Your emails rock.

Thank you for the time and effort you put into creating these informative emails...

1 day, 4 hours назад @ schneier.com
Leaked Russian Cyber-Operations Training Materials
Leaked Russian Cyber-Operations Training Materials Leaked Russian Cyber-Operations Training Materials

This is interesting:

The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.

[…]

The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.

That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack.

The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, …

1 day, 5 hours назад @ schneier.com
Rewiring Democracy Series on The Renovator
Rewiring Democracy Series on The Renovator Rewiring Democracy Series on The Renovator

Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator. I haven’t been posting the full text on the blog because they’re a bit long, but here are links.

Part 1 is about the Japanese digital democracy party, Team Mirai.

Part 2 is about the Swiss Public AI model, Apertus.

Part 3 is about the civic technologists of Open Knowledge Brazil.

And the new one, Part 4, is about civic AI in Scotland.

1 day, 12 hours назад @ schneier.com
Is Someone Hacking DoD Refrigerators?
Is Someone Hacking DoD Refrigerators? Is Someone Hacking DoD Refrigerators?

It sure seems like it.

The stores confirmed to be affected include Fort Irwin, Calif.; F.E. Warren Air Force Base, Wyo.; Fort Huachuca, Ariz.; Naval Station Newport, R.I.; Columbus Air Force Base, Miss.; and Travis Air Force Base, Calif., according to announcements made online by each installation.

Naval Air Station Lemoore, Calif., also experienced an outage, according to M. Elizabeth, writer of the Substack newsletter Signal and Silence.

Each service declined to answer questions about how many bases are affected by the outages, referring all questions to the Defense Department. Pentagon officials did not respond to questions...

2 days, 3 hours назад @ schneier.com
Hiding Prompt Injection in Legal Filing
Hiding Prompt Injection in Legal Filing Hiding Prompt Injection in Legal Filing

Someone hid AI instructions into a legal filing.

Alternate link.

2 days, 11 hours назад @ schneier.com
Friday Squid Blogging: Truckload of Squid Spills in Rhode Island
Friday Squid Blogging: Truckload of Squid Spills in Rhode Island Friday Squid Blogging: Truckload of Squid Spills in Rhode Island

Ugh:

A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the summer heat. Local authorities have dubbed it the “Squidpocalypse of ’26.”

That would be twenty tons of squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

5 days, 1 hour назад @ schneier.com
AI Doesn’t Mean the End of Mathematics—at Least Not Yet
AI Doesn’t Mean the End of Mathematics—at Least Not Yet AI Doesn’t Mean the End of Mathematics—at Least Not Yet

This essay was written with Kasra Rafi, and originally appeared in The Guardian.

Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was mostly pretty glum. People fear for their jobs, their careers and the work they love.

We think the contrary view is more likely, at least in the short-term. AI models are nowhere near as capable as experienced academic mathematicians.

This isn’t to say that AIs aren’t producing stunning mathematical results at the level of PhD researchers. In mid-May, OpenAI ...

5 days, 11 hours назад @ schneier.com
LLM-Based Social Engineering Scams
LLM-Based Social Engineering Scams LLM-Based Social Engineering Scams

OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive:

The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading. Other users engaged in lengthy romantic conversations with targets using fictitious identities, posed as representatives of online gambling platforms offering fake bonuses and winnings, or impersonated law enforcement agencies to tell targets they needed to pay fines for committing serious criminal offenses...

6 days, 12 hours назад @ schneier.com
Spyware for Babies
Spyware for Babies Spyware for Babies

The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI.

Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recently raised $50 million from investors to expand its use of A.I. and use its camera to track speech and language development, motor skills and more, while extending its presence in children’s bedrooms into early adolescence.

1 week назад @ schneier.com
Black Hat State of Security Vendors
Black Hat State of Security Vendors Black Hat State of Security Vendors

Andy Ellis has a roundup of the security vendors at Black Hat this year.

Key Takeaways: We have entered into an AI world. While nearly half of booths didn’t directly mention AI or agents in their taglines, the effects of AI are everywhere. Multiple spaces (Identity, SaaS, AppSec, Data) have almost every vendor leading with AI; existing unsolved problem areas just got worse.

At the same time, there’s a clear trichotomy in the market: tools that tell you how bad things are; tools that stop adversaries, and tools that prevent problems from occurring. While you’d suspect that the tools that fix things would dominate, the tools that merely tell you how bad things are seem to be frustratingly ple…

1 week, 1 day назад @ schneier.com
Criminal Deception in Silicon Valley
Criminal Deception in Silicon Valley Criminal Deception in Silicon Valley

Interesting paper:

Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: Entrepreneurs construct, perform, and protect illusory appearances (façades) that externally project high-growth performance to audiences while masking ventures’ actual underperformance. We identify three forms of façading—­surface, reinforced, and deep façading­—that are contingent on the severity o…

1 week, 2 days назад @ schneier.com
Friday Squid Blogging: Neon Flying Squid
Friday Squid Blogging: Neon Flying Squid Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation.

The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion.

They were probably neon flying squid (Ommastrephes bartramii), the subsequent study states, a species that is part of a 20-strong flying squid family that was known to leap from the water but, until then, was only rumoured to also be able to glide above it...

1 week, 5 days назад @ schneier.com
AI Is Learning to Write Genetic Code
AI Is Learning to Write Genetic Code AI Is Learning to Write Genetic Code

This sort of research is both exciting and terrifying:

The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside.

Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the models generated about 700,000 potential designs, of which the researchers picked 285 that looked most promising.

The researchers then synthesised new DNA molecules using those designs and inserted them into E. coli bacteria, before waiting to see if viable bacteriophages would emerge...

1 week, 5 days назад @ schneier.com
Krebs On Security
последний пост 23 часа назад
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards.

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.

Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s ide…

23 часа назад @ krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

6 days, 11 hours назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

2 weeks, 5 days назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

3 weeks, 1 day назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

3 weeks, 6 days назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

1 month назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

1 month, 1 week назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

1 month, 2 weeks назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

1 month, 3 weeks назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

1 month, 3 weeks назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

2 months назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

2 months, 1 week назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

2 months, 2 weeks назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

2 months, 3 weeks назад @ krebsonsecurity.com
A Record-Breaking Patch Tuesday for June 2026
A Record-Breaking Patch Tuesday for June 2026 A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.

“Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said.

Microsoft received heavily blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher.

While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barne…

2 months, 3 weeks назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 7 часов назад
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
Revolut scam wave steals £180,000 from Jersey residents in just four weeks Revolut scam wave steals £180,000 from Jersey residents in just four weeks

If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.

Police say they have also handled several cases where Revolut accounts were compromised that did not involve any phone calls.

It is possible that Jersey's residents have been targeted by the fraudsters because it is one of the world's best-known offshore financial centres.

Of course, if this is happening in the small island of Jersey in the English channel, it's likely to be happening elsewhere too.

For now, however, its sister island of Guernsey appears to have escaped the surge in Revolut scams.

7 часов назад @ bitdefender.com
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

TeamPCP is best known for Shai-Hulud, a self-propagating worm that spread itself through open source software.

According to the authorities, the two men were principal members of a "sophisticated cybercrime syndicate" that created malicious open source software designed to steal data and extort ransoms from businesses.

First emerging in late 2025, TeamPCP built a reputation for poisoning popular open source packages rather than directly attacking businesses.

The group's Shai-Hulud worm hijacks GitHub and NPM developer credentials, and publishes boobytrapped versions of legitimate software packages.

Supply chain attacks like Shai-Hulud exploit the fact that most developers trust open source …

5 days, 11 hours назад @ bitdefender.com
US Navy tells sailors and their families: scrub your social media, enemies are watching
US Navy tells sailors and their families: scrub your social media, enemies are watching US Navy tells sailors and their families: scrub your social media, enemies are watching

The advice comes in the form of a newly-published bulletin called "Epic Vigilance: Immediate Actions for Force Protection and Personal Security."

US Navy workers and their families are being told that they should ensure that their social media profile privacy settings are enabled, and to remove anything that connects them to the Navy, or reveals "patterns of life" that an attacker could exploit.

any fake social media accounts impersonating fellow shipmates.

This wouldn't, of course, be the first time that military staff have accidentally leaked information about themselves online.

Some commentators have wondered out loud whether the timing of an announcement telling sailors to be much more …

6 days, 12 hours назад @ bitdefender.com
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency

This hacker leaked GTA 6 and launched their own cryptocurrency with Graham Cluley and special guest Paul Ducklin.

And that's really a testament to how much people love this game.

I really don't know, 'cause I do believe it is possible these days to play games via Netflix.

It appears, although the value of their stash was being pumped up by all these other transactions, they've actually destroyed their entire stake.

I'm not a lawyer, Graham, thankfully, so I don't really know the answer to that.

6 days, 23 hours назад @ grahamcluley.com
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Security researchers at Socket have identified scores of malicious linked Firefox add-ons designed to steal cryptocurrency wallet seed phrases or password details.

The malicious extension - which the developers boldly claim collects "no data" - looks like a wallet app, but the truth is that there is no wallet code inside it.

Because the switch lives in the database rather than the extension code, criminals never need to push an update through the Firefox Add-ons store to activate it.

Although the researchers did not find that these extensions presently contained malicious code, the fact that they shared code and infrastructure with the info-stealing Firefox extensions raises alarm.

More rec…

1 week, 2 days назад @ bitdefender.com
Gunra ransomware: what you need to know
Gunra ransomware: what you need to know

The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.

1 week, 2 days назад @ fortra.com
Smashing Security podcast #481: Never say this to a robot dog
Smashing Security podcast #481: Never say this to a robot dog Smashing Security podcast #481: Never say this to a robot dog

Smashing Security, episode 481, Never Say This to a Robot Dog, with Graham Cluley and special guest Jenny Radcliffe.

Now, unfortunately for the robot dog, there was a wall in the way, which it wasn't expecting.

And thank goodness as well that the robot dog was actually on a lead, a long lead, being held by one of the security researchers.

This is a robot dog that you can remotely activate a flamethrower and it's not considered particularly dangerous.

And they even found an over-the-air exploit delivered by Bluetooth, which can have one infected robot dog infecting other robot dogs.

1 week, 6 days назад @ grahamcluley.com
Prison for data analyst who tried to extort $2.5 million from his employer
Prison for data analyst who tried to extort $2.5 million from his employer Prison for data analyst who tried to extort $2.5 million from his employer

When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile.

Curry was hired as a data analyst by Brightly Software, a technology firm that was acquired by Siemens in 2022.

The role gave Curry legitimate access to sensitive company information, corporate records, and the personal and payroll data of employees.

Trusted contractors and employees are given legitimate credentials to access precisely the same data that can later be weaponised.

Because the moment that someone realises they may be on their way out is when their access to sensitive data should be examined most closely.

2 weeks назад @ bitdefender.com
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras

He wrapped a 2009 Toyota Yaris in one of his newest patterns and drove it past a live Flock camera.

So, how does the vehicle avoid detection by the camera's software?

The system has now been tested against 11 open-source detection algorithms, including the software behind Flock licence plate readers, Axon body-worn cameras, and cameras running Clearview AI's facial recognition system.

One issue is that Flock cameras can be inaccurate, with innocent drivers finding themselves pulled over at gunpoint following incorrect plate matches.

Whether covering a car's bodywork in a printed pattern designed to fool surveillance camera software might itself become an offence remains to be seen.

2 weeks, 2 days назад @ bitdefender.com
Smashing Security podcast #480: This is the AI service you should never sign up to
Smashing Security podcast #480: This is the AI service you should never sign up to Smashing Security podcast #480: This is the AI service you should never sign up to

Well, it has been a long time, so I'm going to hold you very responsible for this, Graham.

I'm going to set myself up on another server and charge less, and that will be better for humanity.

I mean, if I'm going to look up a phishing kit, is Greatness going to be a great SEO search term?

I want to recommend 2 apps: Tailscale and RustDesk, which I don't think I've spoken about previously on the podcast.

My pick of the week is, I know you're into your games and you're quite the intelligent fellow.

2 weeks, 6 days назад @ grahamcluley.com
Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres
Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres

I'm sure you remember "glassholes" - the delightful term coined back in 2013 when Google Glass wearers were being turned away from restaurants and mocked mercilessly online.

Meta's Ray-Ban smart glasses have been a genuine commercial success.

The problem is - and it's a rather significant one - that these glasses look just like ordinary spectacles or sunglasses.

Soho House, the global private members' club chain, meanwhile has said that its ban on filming on the premises covers Meta smart glasses.

The bouncer won't confiscate your pint, but they might confiscate your smart glasses.

3 weeks, 2 days назад @ bitdefender.com
Beware cut-price AI services that read your every word
Beware cut-price AI services that read your every word

f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.

3 weeks, 5 days назад @ fortra.com
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits

According to a report in the Financial Times, Apple has found itself facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely hallucinated bug reports.

Unlike traditional spam, AI-generated bug reports include code which may be syntactically correct, references to genuine API calls, and plausible-sounding technical explanations of what is occurring.

But the hallucinated bug report may only have taken a few seconds for an amateur to generate and submit.

Previously, without the assistance of AI, Bynario had filed only 13 bug reports across 2025 and early 2026.

Apple is not the only company trying to deal with a deluge of au…

3 weeks, 6 days назад @ bitdefender.com
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency

How a fake police officer nearly stole Graham's cryptocurrency with Graham Cluley and special guest Danny Palmer.

I said, without being big-headed, it is possible he knows me, but I don't know him.

I don't think my hotels tend to ask me to install something on my computer when I get there.

We had internet, but it was really, really restricted.

And it's really, really good.

3 weeks, 6 days назад @ grahamcluley.com
Fake IRS letters target cryptocurrency holders
Fake IRS letters target cryptocurrency holders Fake IRS letters target cryptocurrency holders

As Coinbase's security team explains, the letters urge recipients to scan a QR code and enrol in a "Digital Asset Compliance Portal" before time runs out.

Bear in mind that the criminals could easily vary these details from letter to letter.

The scam site then asks victims to estimate how much value they have in their cryptocurrency wallets, with ranges up to "$100,000+".

Perhaps a reason why a scam like this can work is that the IRS has been tightening cryptocurrency holders' requirement to report details of their digital assets on their tax returns.

As a result, written communications between the IRS and holders of cryptocurrency have become more frequent.

4 weeks, 1 day назад @ bitdefender.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 10 часов назад
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7177a8342cf961cc27c82af1167cdb34Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-02T15:00:28+03:00Config id: 302Faithfully yours, nginx.

10 часов назад @ kaspersky.ru
Зловред на Android крадет банковские данные даже без Интернета | Блог Касперского
Зловред на Android крадет банковские данные даже без Интернета | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 1234dd8cf75bafa2fdea454a547c2d94Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-31T18:00:11+03:00Config id: 302Faithfully yours, nginx.

2 days, 7 hours назад @ kaspersky.ru
Слепые пятна детектирования: нестандартные форматы файлов во вредоносных рассылках | Блог Касперского
Слепые пятна детектирования: нестандартные форматы файлов во вредоносных рассылках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 12b7d939c6e7a3162d2fc21782707204Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-28T21:00:23+03:00Config id: 302Faithfully yours, nginx.

5 days, 4 hours назад @ kaspersky.ru
Что делать, если нашли чужую банковскую карту | Блог Касперского
Что делать, если нашли чужую банковскую карту | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 22404ed46e3879110c6cb314018a27efServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-27T17:00:28+03:00Config id: 302Faithfully yours, nginx.

6 days, 8 hours назад @ kaspersky.ru
Как распознать мошеннические сайты, которые браузер считает безопасными | Блог Касперского
Как распознать мошеннические сайты, которые браузер считает безопасными | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 110ef102dd9f3a4937d28552df4d26c8Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-25T18:00:25+03:00Config id: 302Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 897a176d22a503b4ac820cc15e11d949Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-21T17:00:19+03:00Config id: 302Faithfully yours, nginx.

1 week, 5 days назад @ kaspersky.ru
Как злоумышленники крадут корпоративные пароли в 2026 году
Как злоумышленники крадут корпоративные пароли в 2026 году

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a42f6e338d827cfbf62010dbe3732758Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-20T18:00:15+03:00Config id: 302Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4f455d7ae5f01c9d0d8e403ffeff6732Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-19T18:00:07+03:00Config id: 301Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fb0df3655ea6f56b2f956c62791963eaServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-17T13:00:21+03:00Config id: 301Faithfully yours, nginx.

2 weeks, 2 days назад @ kaspersky.ru
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f2ed509c8db78e5bf9f4b9959cd583f7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-13T17:00:41+03:00Config id: 299Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: b151dd13b503d39649441ee258a9621fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-11T15:00:20+03:00Config id: 298Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Слепые пятна детектирования: форматы файлов polyglot в рассылках и целевых атаках
Слепые пятна детектирования: форматы файлов polyglot в рассылках и целевых атаках

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 31e2a51c17a679bf608181d1cb4a73dfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-10T19:00:19+03:00Config id: 298Faithfully yours, nginx.

3 weeks, 2 days назад @ kaspersky.ru
Опасные почтовые вложения: какие файлы нельзя открывать | Блог Касперского
Опасные почтовые вложения: какие файлы нельзя открывать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: ba837fe40a3ce1bc1da3dc3d5c38e164Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-07T14:00:17+03:00Config id: 296Faithfully yours, nginx.

3 weeks, 5 days назад @ kaspersky.ru
Аудиослежка за клавиатурным набором | Блог Касперского
Аудиослежка за клавиатурным набором | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f03ed927ed78af1549df453edbc54069Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-06T17:00:43+03:00Config id: 295Faithfully yours, nginx.

3 weeks, 6 days назад @ kaspersky.ru
Как сделать, чтобы вашу компанию не взломали автономные агенты
Как сделать, чтобы вашу компанию не взломали автономные агенты

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f997d2a4543951b403d61a86f614b589Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-04T20:00:20+03:00Config id: 293Faithfully yours, nginx.

4 weeks, 1 day назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 5 days, 7 hours назад
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

It is what happens when agents built by different teams, on different platforms, can hand work to each other directly.

And it is worth being direct about where things stand: A2A-mediated handoffs between production security agents are not shipping anywhere yet.

Use A2A when one agent needs to hand work to another.

A2A is peer-to-peer: any A2A agent can discover and call any other A2A agent through a self-published Agent Card, no custom connector required, and the receiving agent applies its own reasoning rather than following a static script.

Input validation is an application-layer responsibility that needs to be designed in before any agent delegates via A2A, not added after.

5 days, 7 hours назад @ blogs.cisco.com
Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
Microsegmentation’s Moment Is Now:  Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind SpotsApplications increasingly span private clouds, on-premises data centers, and public clouds.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026…

1 week назад @ blogs.cisco.com
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

What We Mean by Infrastructure IdentityInfrastructure Identity starts with a simple principle: there should be no anonymous computing in critical infrastructure.

Infrastructure Identity turns that principle into an operating model.

Infrastructure Identity starts with the actor and evaluates whether a specific action should be allowed now.

Infrastructure Identity is therefore not just an access-control issue.

That is the promise of Infrastructure Identity: no anonymous computing, no unmanaged privilege, and no forced tradeoff between stronger security and operational speed.

1 week, 1 day назад @ blogs.cisco.com
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE

I’m proud to share that IDC MarketScape has named Cisco a Leader in the 2026 IDC MarketScape: Worldwide Secure Access Service Edge (SASE) Vendor Assessment.

In an evaluation of 12 SASE vendors, the IDC MarketScape recognized our architectural breadth and flexibility, AI capabilities, identity integration, threat visibility, and R&D.

Built to Make Agent Work, WorkWe believe the IDC MarketScape recognition validates the foundation we have built, and customers increasingly need that foundation for what is next.

For more on Cisco’s placement as a Leader, read the IDC MarketScape excerpt and explore how Cisco SASE keeps work moving, governed, and trusted in the AI era at cisco.com/go/sase.

Stay …

1 week, 2 days назад @ blogs.cisco.com
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

2 weeks, 2 days назад @ blogs.cisco.com
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero … Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …

The Power of FedRAMP HighWhile FedRAMP Certified Class C (Moderate) is the standard for many civilian agencies, FedRAMP Certified Class D (High) is designed for systems where a breach could have catastrophic effects.

Cisco Security Cloud for GovernmentCisco Security Cloud for Government is a unified authorization boundary that integrates various Cisco security services, ensuring that organizations can protect their users, devices, and applications regardless of where they reside.

The Cisco Security Cloud for Government ecosystem is designed to meet the rigorous security requirements of the public sector and highly regulated industries.

Cisco Security Cloud Control (SCC)Cisco Security Cloud …

3 weeks, 1 day назад @ blogs.cisco.com
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

That’s why we are incredibly proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

Reduced Vendor Risk & Increased Trust: FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

Beyond the governance and compliance benefits, Email Threat Defense continues to deliver advanced protection capabilities that align directly with real-world email threat risks.

Email Threat De…

3 weeks, 2 days назад @ blogs.cisco.com
Is your SD-WAN ready for AI-powered operations?
Is your SD-WAN ready for AI-powered operations? Is your SD-WAN ready for AI-powered operations?

AI Is Changing the Traffic ModelMuch of the enterprise AI conversation centers on models, GPUs, data platforms, and agents.

Time-sensitive performance: Voice AI, edge AI, and physical AI move latency into live operations.

SD-WAN can help maintain operations by prioritizing critical traffic, steering it across the best available path, and applying consistent policy across locations.

Why AI Traffic is an SD-WAN ProblemSD-WAN sits at the point where application intent meets real network conditions.

1 https://www.aboutamazon.com/news/operations/amazon-million-robots-ai-foundation-modelCommon questions about SD-WAN and AI trafficWhat is AI-generated network traffic?

1 month назад @ blogs.cisco.com
The Zero Trust Imperative for the Frontier AI Era
The Zero Trust Imperative for the Frontier AI Era The Zero Trust Imperative for the Frontier AI Era

Their recommendations for securing the AI era rely heavily on establishing strict asset inventory and preventing lateral movement—which are, at their core, fundamental Zero Trust principles.

The Three Core Principles of Zero Trust for AIFounded in three core principles, a robust Zero Trust architecture requires us to execute the following phases comprehensively.

Achieving the Architectural VisionThe above may all sound like pipedream, as most organisations struggle with Zero Trust programs and undelivered microsegmentation projects.

Ultimately AI driven platform approach is what makes Zero Trust achievable for the frontier AI era.

This is exactly why achieving a Zero Trust Architecture for …

1 month назад @ blogs.cisco.com
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes

This provides an opportunity for defenders: if we assume our controls will fail at some point, we can build a much more resilient architecture.

When you assume the current layer will eventually be bypassed, you start designing the next layer proactively instead of reactively.

Defenders need to advance their controls by mapping them to the adversaries’ capabilities then assume that control will fail.

Map your controls to the attack chain.

Call to Action:If you haven’t watched the full video yet, go check it out: Assuming Failure Provides Better Defensive Outcomes (bonus elements around SOC of the Future and business context).

1 month, 1 week назад @ blogs.cisco.com
The Journey towards Logically Air-Gapped Deployment
The Journey towards Logically Air-Gapped Deployment The Journey towards Logically Air-Gapped Deployment

Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter.

This “Logically Air-Gapped” governance model reaches its full operational potential through the implementation of “Live Protect.” As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution.

Reference ArchitectureDigital autonomy is thus exercised by shifting network and security control into the operating system kernel.

Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a un…

1 month, 1 week назад @ blogs.cisco.com
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall

That is why we are introducing Firewall Migration Manager by Cisco, an enterprise-ready product built for that reality.

What Is Firewall Migration Manager?

Firewall Migration Manager is a dedicated migration application that you run in your own environment.

How Firewall Migration Manager WorksThe migration process follows a clear, guided workflow.

Intelligent, integrated migration: Firewall Migration Manager will also come to Cisco Cloud Control, and AI will play an increasing role in guiding teams before and during migration.

1 month, 1 week назад @ blogs.cisco.com
We third-party tested our firewall built for AI-scale. The test tools hit their limit first.
We third-party tested our firewall built for AI-scale. The test tools hit their limit first. We third-party tested our firewall built for AI-scale. The test tools hit their limit first.

In independent testing with NetSecOPEN, the Cisco Secure Firewall 6160 delivered AI-scale inspected throughput beyond what the tools built to measure it could register, all while blocking 100% of tested threats.

These results are specific to Cisco Secure Firewall 6160, but the software capabilities behind Cisco Firewall, including advanced threat protection and high-performance inspection, extend across Cisco Firewall form factors in the cloud, virtually, and on-premises, from campus to data center.

Performance passed the previous benchmark by 5XInspection was turned on, and the test tools built to measure throughput hit their limit before the 6160 firewall did.

In previous NetSecOPEN testi…

1 month, 2 weeks назад @ blogs.cisco.com
SharpHound Recon Attack – How AI enhanced the threat hunt
SharpHound Recon Attack – How AI enhanced the threat hunt SharpHound Recon Attack – How AI enhanced the threat hunt

We innovated by giving the Agentic SOC access to Endace’s always-on, full packet capture, and asked the agent to assess a potential SharpHound Recon attack that we had seen while threat hunting.

This blog explores how we built the integrations and how AI helped us with our threat hunt and threat assessment.

Agentic AI Massively Speeds our AnalysisAt this point, we decided to use Agentic AI capabilities to investigate and assess this potential threat.

ConclusionThe Agentic SOC, blending Agentic AI built into Endace’s products with custom agentic tools, is a massive boost to productivity and security.

AcknowledgementsOur thanks go to the Cisco SOC team led by @Jessica Oppenheimer and @Ivan Be…

1 month, 3 weeks назад @ blogs.cisco.com
Machine Speed, Human Judgement: How AI Changed the SOC in 2026
Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Machine Speed, Human Judgement: How AI Changed the SOC in 2026

Having spent time in the Cisco Live Americas 2026 SOC, one thing became abundantly clear:The way SOCs operate today is fundamentally different from even a few years ago.

Instead of spending time gathering information, analysts could spend more time understanding what the information actually meant.

Just as spreadsheets empowered business users decades ago, AI-assisted coding is beginning to empower security analysts today.

At Cisco Live, AI was already present throughout the workflow:Incident summaries generated automatically within XDR.

And based on what I saw at Cisco Live 2026, that future has already arrived.

1 month, 3 weeks назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 23 часа назад
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Counterfeit installers to system compromise: Tracking a deceptive software download campaign Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers.

Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control.

Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.

Microsoft Defender exclusion tampering Detects the SYSTEM scheduled-task and PowerShell routines that write sweeping Microsoft Defender path exclusions.

Malicious delivery domains and download endpoints Identifies connections to t…

23 часа назад @ microsoft.com
Cybersecurity IR Workshop: The workshop you shouldn’t miss
Cybersecurity IR Workshop: The workshop you shouldn’t miss Cybersecurity IR Workshop: The workshop you shouldn’t miss

That’s exactly what the Cybersecurity Incident Response Readiness Workshop is designed to do.

What is the Cybersecurity Incident Response Readiness Workshop?

The Cybersecurity Incident Response Workshop is a collaborative, scenario driven workshop designed to evaluate your organization’s incident response (IR) plan against realistic, real-world security events, guided by DART researchers.

Instead of reviewing a plan as a static document, the Cybersecurity Incident Response Workshop exercises how people, processes, and technology work together under pressure.

A summary of findings and prioritized recommendations to help strengthen incident response readiness and guide next steps.

1 day, 3 hours назад @ microsoft.com
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
TerminalFix campaign deploys a reverse tunnel through multistage intrusion TerminalFix campaign deploys a reverse tunnel through multistage intrusion

The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command.

Example list of imports from dui70.dllThe attacker abuses this dependency by dropping a malicious dui70.dll alongside the executable.

ExecutionT1059.001 Command and Scripting Interpreter: PowerShell | A malicious PowerShell command is pasted by the user into Terminal.

T1069.002 Permission Groups Discovery: Domain Groups | The net group “domain admins” /domain command is used for enumeration.

Indicators of Compromise (IOCs)File indicatorsIndicator Description 18c2090e8a0ae0568af9b87e59eaf8270f23d2909600ed9db91a9444fd8b27…

4 days, 18 hours назад @ microsoft.com
​​​​​​What’s new in Microsoft Security: August 2026
​​​​​​What’s new in Microsoft Security: August 2026 ​​​​​​What’s new in Microsoft Security: August 2026

This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments.

Microsoft Defender Experts MDR now covers third-party data sources ingested through Microsoft Sentinel.

In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

6 days, 6 hours назад @ microsoft.com
When AI infrastructure becomes the target: Securing gateways and control points
When AI infrastructure becomes the target: Securing gateways and control points When AI infrastructure becomes the target: Securing gateways and control points

In recent investigations, Microsoft observed activity targeting three distinct AI workloads: a LiteLLM gateway, a RAGFlow deployment, and a Kestra workflow environment.

Three observed compromises across AI workloadsAI workload Observed activity Attacker objective LiteLLM Observed attacker activity: Python droppers, runtime secret harvesting, PostgreSQL collection, miner deployment, and persistence activity from the LiteLLM gateway context.

The first delivery path launched from the compromised LiteLLM gateway process as an inline Python command.

Stage 5: LiteLLM database access through Azure PostgreSQLThe fifth stage used the previously collected database connection string to access the Lite…

1 week назад @ microsoft.com
When AI infrastructure becomes the target: Securing gateways and control points
When AI infrastructure becomes the target: Securing gateways and control points When AI infrastructure becomes the target: Securing gateways and control points

In recent investigations, Microsoft observed activity targeting three distinct AI workloads: a LiteLLM gateway, a RAGFlow deployment, and a Kestra workflow environment.

Three observed compromises across AI workloadsAI workload Observed activity Attacker objective LiteLLM Observed attacker activity: Python droppers, runtime secret harvesting, PostgreSQL collection, miner deployment, and persistence activity from the LiteLLM gateway context.

The first delivery path launched from the compromised LiteLLM gateway process as an inline Python command.

Stage 5: LiteLLM database access through Azure PostgreSQLThe fifth stage used the previously collected database connection string to access the Lite…

1 week назад @ microsoft.com
The patch window is collapsing: Why security needs a new control plane
The patch window is collapsing: Why security needs a new control plane The patch window is collapsing: Why security needs a new control plane

The patch window has collapsedTraditional vulnerability management was built on the assumption that defenders could move faster than attackers.

Organizations increasingly need security systems capable of understanding risk, evaluating context, and adapting protections as conditions change.

Adaptive security systems aim to move beyond predefined rules toward continuously improving risk management.

Looking at the future of cybersecurityThe cybersecurity industry has spent decades improving vulnerability management, patch deployment, and security operations.

Those investments remain essential and will continue to be foundational elements of every organization’s security strategy.

1 week, 1 day назад @ azure.microsoft.com
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

Microsoft is also the largest cloud workload protection platform (CWPP) provider by revenue, with an estimated share of more than 22% of the global CWPP market.

Why cloud workload protection is being redefinedFor a long time, protecting a workload meant scanning its image, fixing known vulnerabilities, and hardening configurations before deployment.

Bottom lineFrost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 reinforces a clear shift.

Learn moreRead Frost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 to see how leading vendors are evaluated and how the category is shifting toward unified cloud runtime security.

Explore Microsoft cloud security…

2 weeks назад @ microsoft.com
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026 Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

Microsoft is also the largest cloud workload protection platform (CWPP) provider by revenue, with an estimated share of more than 22% of the global CWPP market.

Why cloud workload protection is being redefinedFor a long time, protecting a workload meant scanning its image, fixing known vulnerabilities, and hardening configurations before deployment.

Bottom lineFrost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 reinforces a clear shift.

Learn moreRead Frost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026 to see how leading vendors are evaluated and how the category is shifting toward unified cloud runtime security.

Explore Microsoft cloud security…

2 weeks назад @ microsoft.com
Hunting MacSync Stealer infrastructure through behavioral pivots
Hunting MacSync Stealer infrastructure through behavioral pivots Hunting MacSync Stealer infrastructure through behavioral pivots

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

2 weeks, 1 day назад @ microsoft.com
Hunting MacSync Stealer infrastructure through behavioral pivots
Hunting MacSync Stealer infrastructure through behavioral pivots Hunting MacSync Stealer infrastructure through behavioral pivots

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

2 weeks, 1 day назад @ microsoft.com
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

That’s exactly what Microsoft Defender Experts MDR is built to do.

We are excited to announce that we have been named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise Vendor Assessment (Doc #US54792426, July 2026).

Defender Experts MDR includes it as a core part of the service with Defender Experts Hunting, extending your team with Microsoft experts who continuously look for advanced threats across your environment.

Get startedRead the IDC MarketScape: Worldwide MDR/MXDR for the Enterprise 2026 Vendor Assessment excerpt, and visit the Microsoft Defender Experts MDR webpage to see how expert-led, round-the-clock managed detection and response can extend your team, …

3 weeks, 2 days назад @ microsoft.com
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

That’s exactly what Microsoft Defender Experts MDR is built to do.

We are excited to announce that we have been named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise Vendor Assessment (Doc #US54792426, July 2026).

Defender Experts MDR includes it as a core part of the service with Defender Experts Hunting, extending your team with Microsoft experts who continuously look for advanced threats across your environment.

Get startedRead the IDC MarketScape: Worldwide MDR/MXDR for the Enterprise 2026 Vendor Assessment excerpt, and visit the Microsoft Defender Experts MDR webpage to see how expert-led, round-the-clock managed detection and response can extend your team, …

3 weeks, 2 days назад @ microsoft.com
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations.

Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems.

Recovery chat: Technical architectureThe most distinctive feature of the DeadLock ransomware is its recovery chat system.

‘DeadLock’ ransomware was detected‘DeadLock’ ransomware was preventedMicrosoft Defender for Cloud AppsThe following alert might indicate threat activity associated with this threat.

Indicators of compromiseIndicato…

3 weeks, 2 days назад @ microsoft.com
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations.

Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems.

Recovery chat: Technical architectureThe most distinctive feature of the DeadLock ransomware is its recovery chat system.

‘DeadLock’ ransomware was detected‘DeadLock’ ransomware was preventedMicrosoft Defender for Cloud AppsThe following alert might indicate threat activity associated with this threat.

Indicators of compromiseIndicato…

3 weeks, 2 days назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 4 months, 1 week назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

4 months, 1 week назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

4 months, 3 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

4 months, 3 weeks назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

5 months назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

5 months назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

5 months, 1 week назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

6 months, 1 week назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

6 months, 1 week назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

6 months, 2 weeks назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

7 months, 1 week назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

8 months, 3 weeks назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

8 months, 3 weeks назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

8 months, 4 weeks назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

9 months назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

9 months, 2 weeks назад @ security.googleblog.com