Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 2 часа назад
Вчера вскрывала телефоны преступников, сегодня сама на допросе. Падение Oxygen Forensics
Вчера вскрывала телефоны преступников, сегодня сама на допросе. Падение Oxygen Forensics Вчера вскрывала телефоны преступников, сегодня сама на допросе. Падение Oxygen Forensics

Несколько стран одновременно решили проверить, кому всё это время доверяли самые чувствительные данные.

2 часа назад @ securitylab.ru
Два миллиона лет назад Homo erectus выглядел обречённой ветвью человечества
Два миллиона лет назад Homo erectus выглядел обречённой ветвью человечества

Эволюция явно начиналась не в нашу пользу...

3 часа назад @ securitylab.ru
Face ID идёт в дата-центры. Volantis строит ИИ-ускоритель на лазерах той же технологии, что и в айфонах
Face ID идёт в дата-центры. Volantis строит ИИ-ускоритель на лазерах той же технологии, что и в айфонах Face ID идёт в дата-центры. Volantis строит ИИ-ускоритель на лазерах той же технологии, что и в айфонах

ИИ-чипам обещают 10 ТБ памяти и скорость 240 ТБ/с.

4 часа назад @ securitylab.ru
ИИ научился притворяться человеком настолько хорошо, что за минуту обманул почти каждого второго
ИИ научился притворяться человеком настолько хорошо, что за минуту обманул почти каждого второго ИИ научился притворяться человеком настолько хорошо, что за минуту обманул почти каждого второго

Участники разговаривали с цифровым аватаром и даже не подозревали о подмене.

5 часов назад @ securitylab.ru
Историки ждали больше двух веков. GPT-6 Astra за 6 часов расшифровала письмо Наполеоновской эпохи
Историки ждали больше двух веков. GPT-6 Astra за 6 часов расшифровала письмо Наполеоновской эпохи

ИИ восстановил большую часть ключа к военному шифру из 155 знаков и получил связный текст.

5 часов назад @ securitylab.ru
Кошельки пока целы, валидаторы уходят. MetaMask расследует компрометацию инфраструктуры
Кошельки пока целы, валидаторы уходят. MetaMask расследует компрометацию инфраструктуры

Масштаб проблемы не раскрывают, но последствия уже вышли за пределы внутренних систем.

6 часов назад @ securitylab.ru
Дата проникновения — неизвестна. Группировка — неизвестна. Адреса — в Китае. Авиационная инфраструктура ЮАР попала под киберудар
Дата проникновения — неизвестна. Группировка — неизвестна. Адреса — в Китае. Авиационная инфраструктура ЮАР попала под киберудар

Вредонос добрался до авиационной OT-сети Южной Африки

7 часов назад @ securitylab.ru
Читы, миллион паролей и почти полмиллиона евро: бизнес на GTA V обошёлся продавцу в 18 месяцев тюрьмы
Читы, миллион паролей и почти полмиллиона евро: бизнес на GTA V обошёлся продавцу в 18 месяцев тюрьмы

Раньше за читы банили, теперь сажают.

8 часов назад @ securitylab.ru
116 дронов одним роем: Китай поставил мировой рекорд под водой
116 дронов одним роем: Китай поставил мировой рекорд под водой

TH-618 сами корректировали курс, держали глубину и возвращались на траекторию после отклонений.

11 часов назад @ securitylab.ru
Загадка возрастом 44 года получила новую улику на Большом адронном коллайдере
Загадка возрастом 44 года получила новую улику на Большом адронном коллайдере

Край атомного ядра оказался совсем другим миром.

15 часов назад @ securitylab.ru
Рубли. Евро. Доллары. Золото. Одна из крупнейших краж у пенсионерки в Петербурге
Рубли. Евро. Доллары. Золото. Одна из крупнейших краж у пенсионерки в Петербурге

Курьер арестован, но судьба десятков миллионов рублей, валюты и инвестиционных монет пока неизвестна

16 часов назад @ securitylab.ru
Британские профессоры годами пилили софт для китайской госбезопасности и даже не догадывались
Британские профессоры годами пилили софт для китайской госбезопасности и даже не догадывались

MI5 раскрыла, кто стоял за исследованиями по ИИ, кибербезопасности и скрытой связи.

17 часов назад @ securitylab.ru
Российскому ИТ готовят ещё один налоговый сюрприз. Минцифры просит не спешить
Российскому ИТ готовят ещё один налоговый сюрприз. Минцифры просит не спешить Российскому ИТ готовят ещё один налоговый сюрприз. Минцифры просит не спешить

Главный спор разгорелся вокруг компаний, которые создают технологии преимущественно для собственных банков, операторов, маркетплейсов и холдингов.

18 часов назад @ securitylab.ru
GPS можно глушить сколько угодно: гиперзвуковому оружию дадут собственное зрение
GPS можно глушить сколько угодно: гиперзвуковому оружию дадут собственное зрение

Разработчик обещает автономное наведение на огромных скоростях.

18 часов назад @ securitylab.ru
Рукопожатие пошло не по плану. Ошибка OpenSSL превратила повтор DTLS-сообщения в утечку памяти
Рукопожатие пошло не по плану. Ошибка OpenSSL превратила повтор DTLS-сообщения в утечку памяти

Сбой возник там, где библиотека должна была спокойно пережить потерю данных.

19 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 22 часа назад
Цифровой сотрудник — дешёвая замена человеку или новая статья расходов?
Цифровой сотрудник — дешёвая замена человеку или новая статья расходов? Цифровой сотрудник — дешёвая замена человеку или новая статья расходов?

Среднее базовое ДМС обходится в 2 000 рублей в месяц.

Среднемесячную заработную плату округлим до 56 000 рублей на руки.

Аренда мощностей может обходиться в 5 000 — 20 000 рублей (и выше) в месяц.

Другие расходы:LLM-токены: 0,5 — 2 рублей за ответ, при 900 диалогах — от 2 000 до 6 000 рублей в месяц.

Сообщения бесплатны, платный контур — хостинг прослойки, 1 000 — 3 000 рублей в месяц.

22 часа назад @ anti-malware.ru
Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры
Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры

Отдельно обсудили, как выбирать облачного провайдера — на какие критерии смотреть и что влияет на надёжность его сервисов.

Заказчик не видит эти процессы изнутри и не может управлять ими так же, как собственной инфраструктурой.

Но, как советует Станислав Попов, внедрять ИИ сейчас стоит осознанно и с пониманием ожидаемого бизнес-эффекта.

Тестирование аварийного восстановления (disaster recovery, DR) позволяет эмулировать сбои, проверить работу собственной инфраструктуры и цепочки поставщиков.

Вместо самостоятельного создания инфраструктуры и найма специалистов они могут использовать облачную инфраструктуру, соответствие которой необходимым требованиям уже подтверждено.

2 days, 2 hours назад @ anti-malware.ru
Low-code и No-code в 2026 году: как создавать приложения без разработчиков
Low-code и No-code в 2026 году: как создавать приложения без разработчиков Low-code и No-code в 2026 году: как создавать приложения без разработчиков

Платформы Low-code и No-code позволяют создавать бизнес-приложения, автоматизировать процессы и интегрировать системы силами специалистов без профильного образования в области программирования.

Что такое Low-code и No-codeАнтон Симуни объяснил разницу между No-code и Low-code.

No-code — это для непрофессиональных программистов, может быть, даже вообще для тех, кто создаёт приложения без профильного ИТ-образования (т. н.

В первом опросе зрители рассказали, используют ли они платформы No-code / Low-code в своей компании:«Пилотируют» / только начинают внедрение — 28 %.

ВыводыРынок Low-code и No-code в 2026 году перестал быть нишевым явлением.

2 days, 22 hours назад @ anti-malware.ru
Миграция с Cisco: от пилота до замены инфраструктуры
Миграция с Cisco: от пилота до замены инфраструктуры Миграция с Cisco: от пилота до замены инфраструктуры

Вместе с Ideco мы обсудили, как подготовиться к переходу на российские решения, почему полностью бесшовной замены сегодня не бывает.

Причины отказа от CiscoПосле ухода Cisco из России вопрос перехода на другие решения для клиентов до сих пор никуда не исчез.

Совместимость IPsec Site-to-Site с Cisco подтверждена, поэтому площадки можно переносить поэтапно без потери связи между ними.

Илья Соболев, менеджер по продукту IdecoЗависимость от вендора и бесшовность миграцииПри переходе с Cisco на российское решение вопрос зависимости от вендора сохраняется.

Например, добавление поддержки EIGRP, протокола маршрутизации, было связано с тем, что многие компании строили инфраструктуру на Cisco.

3 days, 3 hours назад @ anti-malware.ru
Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке
Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке

ИИ-агенты и их влияние на рынокАндрей Галактионов считает, что истории о сбежавших из песочниц ИИ-агентах — это в первую очередь хайп.

«Красная» команда в 95 % случаев достигает целей, но если нет зрелости, результат будет тот же, что и от пентеста, только дороже.

Если по результатам пентеста нужно проверить инфраструктуру, а по результатам Red Teaming — перенастроить процессы, то внутренняя команда может быть эффективнее для изменения процессов.

ВыводыРынок Offensive Security в 2026 году проходит через фундаментальную трансформацию.

А те, кто считает, что с ними ничего не случится, рискуют убедиться в обратном в самый неподходящий момент.

3 days, 21 hours назад @ anti-malware.ru
Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA
Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA

SafeTech Lab встроила в SafeTech CA модуль CDM для доставки, установки и автоматического обновления технологических сертификатов.

Теперь заказчику больше не нужно искать отдельное решение, интегрировать его с CA и настраивать сложные схемы взаимодействия систем.

Новые расширенные возможности выводят SafeTech CA за рамки обычного центра сертификации — теперь это полноценная платформа управления цифровыми сертификатами.

SafeTech CA закрывает все самые востребованные задачи по контролю за сертификатами: от их выпуска до автоматического обновления на клиентских устройствах.

Модуль CDM расширяет возможности SafeTech CA за счёт агентской доставки, установки и автоматического перевыпуска сертифика…

4 days, 2 hours назад @ anti-malware.ru
ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок
ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок

Согласно отраслевым прогнозам, доля корпоративного ПО с агентным ИИ может возрасти с менее чем 1 % в 2024 году до 33 % к 2028 году.

Наблюдения специалистов по безопасности ИИ и открытые исследования подтверждают: злоумышленники уже сейчас тестируют методы обхода ограничений в промышленных системах.

Недостаточно добавить фильтры поверх уже созданной системы: принципы безопасности для агентов необходимо закладывать на этапе проектирования.

Инструментарий: что включить в конвейер обеспечения безопасности уже сейчасСредства защиты агентов перестают быть узкоспециализированными утилитами и интегрируются в классический конвейер (пайплайн) DevSecOps.

ВыводыОбеспечение безопасности автономных агент…

4 days, 4 hours назад @ anti-malware.ru
Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов
Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов

В Якутии хотят строить ЦОДы там, где мороз помогает охлаждать серверы, а газ можно превращать в электричество прямо у месторождений.

То, что десятилетиями делало стройку и жизнь в Якутии дороже и сложнее, теперь пытаются превратить в конкурентное преимущество: местный мороз должен помогать охлаждать серверы.

Новый проект правительства республики, КРДВ и «Ростелекома» хотят начать с 2,5 МВт — уже в пять раз больше нынешней инфраструктуры.

А заявленные 100 МВт означали бы рост относительно сегодняшнего уровня примерно в 200 раз и в 40 раз относительно старта.

И тогда уже важно, какой газ он потребляет, мог ли этот ресурс уйти другому покупателю и что происходит с локальным энергетическим бала…

4 days, 20 hours назад @ anti-malware.ru
Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты
Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты

Решение BI.ZONE Mail Security создано на основе системы BI.ZONE CESP и предназначено для защиты корпоративной почты от вредоносных и нежелательных сообщений.

Эти данные могут дополняться актуальной информацией из внешних систем: BI.ZONE Threat Intelligence, BI.ZONE Sandbox и платформы BI.ZONE Security Fitness.

BI.ZONE Mail Security также интегрируется с платформой BI.ZONE Security Fitness, что позволяет учитывать результаты учебных фишинговых рассылок при настройке политик безопасности.

Подключение модуля BI.ZONE SandboxВ on-prem-варианте BI.ZONE Mail Security также можно интегрировать с BI.ZONE Threat Intelligence, при этом сам портал располагается в облачной инфраструктуре BI.ZONE.

Компон…

5 days, 4 hours назад @ anti-malware.ru
Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности
Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности

Использование macOS в dev-средах увеличивает риск горизонтального перемещенияКлассические техники горизонтального перемещения через Active Directory и SMB на macOS встречаются реже и хуже покрыты правилами детектирования.

Классическая подсистема аудита OpenBSM начиная с macOS 11 объявлена устаревшей, а в версиях начиная с macOS 14 она отключена по умолчанию.

Сейчас ситуация меняется: вендоры наращивают функциональность агентов под macOS и адаптируют их как к новым версиям ОС, так и к меняющемуся ландшафту угроз.

Политики безопасности исторически писались под Windows, и Mac-устройства во многих организациях так и не попали в контур мониторинга SOC.

Windows, Linux и macOS в ней сосуществуют, …

1 week назад @ anti-malware.ru
Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки
Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки

Эксперты ведущих вендоров собрались в студии AM Live, чтобы обсудить, чем отличаются классы решений, как их выбирать и на что смотреть при пилотировании.

Какими бывают балансировщики нагрузкиДаниил Виняр предложил разделить решения на три класса:Global Server Load Balancing (GSLB) — решения на базе DNS, которые распределяют нагрузку между разными ЦОДами, будь то собственные площадки или облака.

ВыводыРоссийский рынок балансировщиков нагрузки и брокеров сетевых пакетов находится в фазе активного роста и уже не нуждается в доказательствах своей зрелости.

При этом удобство — это не только красивый интерфейс, но и логичность, понятность того, что можно сделать с устройством, и возможность не со…

1 week, 1 day назад @ anti-malware.ru
Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств
Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств

MaxPatrol Endpoint Security — это комплексное решение, которое объединило все возможности продуктов MaxPatrol EDR и MaxPatrol EPP.

Архитектура MaxPatrol Endpoint Security 10Порядок функционирования MaxPatrol Endpoint Security:Сервер агентов распространяет через агенты, установленные на конечных устройствах, исполняемые модули и их конфигурацию.

Взаимодействие компонентов MaxPatrol Endpoint Security 10 через портыУлучшенные функциональные возможности в MaxPatrol Endpoint Security 10Рассмотрим возможности MaxPatrol Endpoint Security 10-й версии.

MaxPatrol Endpoint Security поддерживает связку MaxPatrol EDR + MaxPatrol EPP, а также интеграции с MaxPatrol SIEM, MaxPatrol VM, PT Sandbox и PT NAD…

1 week, 2 days назад @ anti-malware.ru
Российские SIEM в 2026 году: от критериев выбора и пилотирования до ИИ и архитектуры будущего
Российские SIEM в 2026 году: от критериев выбора и пилотирования до ИИ и архитектуры будущего Российские SIEM в 2026 году: от критериев выбора и пилотирования до ИИ и архитектуры будущего

Одни делают ставку на экспертизу и контент, другие — на производительность и масштабируемость, третьи — на экосистемность и интеграции.

Нужно собирать ровно столько, сколько может осилить и SIEM, и команда, которая будет работать с событиями, и чуточку больше.

Границы SIEM: что можно и что нельзя объединять«Граница SIEM зависит от того, кто и как его использует, от масштаба организации.

Евгения Лагутина:«Хочется верить, что мы сможем снизить порог вхождения не в SIEM, а в экспертизу в Threat Intelligence.

Ответ на этот вопрос лежит не в дата-шитах и не в маркетинговых презентациях, а в реальной эксплуатации, пилотировании и понимании собственных задач.

1 week, 2 days назад @ anti-malware.ru
Остановка запрещена: как бизнес проходит технологическую перестройку на ходу
Остановка запрещена: как бизнес проходит технологическую перестройку на ходу Остановка запрещена: как бизнес проходит технологическую перестройку на ходу

Одновременно меняются угрозы: атакующие целятся не только в инфраструктуру, но и в саму возможность восстановления — уничтожают бэкапы и захватывают системы управления.

На дискуссии о высокоплотных ЦОДах под модерацией Сергея Андронова, директора центра сетевых решений компании «Инфосистемы Джет», спорили и о плотности, и о географии.

Значит, средство защиты оценивается уже не само по себе, а по тому, помогает ли оно бизнесу пережить атаку.

Неудачный тест при этом оказался полезен: заказчик точнее сформулировал требования и стал смотреть не только на текущую версию продукта, но и на способность производителя развивать его дальше.

И здесь промышленное внедрение быстро упирается не только в к…

1 week, 3 days назад @ anti-malware.ru
Несколько SIEM-систем в одной инфраструктуре: когда это оправданно
Несколько SIEM-систем в одной инфраструктуре: когда это оправданно Несколько SIEM-систем в одной инфраструктуре: когда это оправданно

Разбираемся, почему возникает такая архитектура, как распределить роли между платформами и в каких случаях разделение функций оправдывает дополнительные затраты.

Холдинговая структура, слияния и поглощенияВ крупных холдингах отдельные дочерние и зависимые общества (ДЗО) часто развивают собственные центры мониторинга ИБ и используют разные SIEM-системы.

Независимая параллельная обработкаСамый простой вариант — источники одновременно отправляют события ИБ в несколько SIEM-систем.

Наконец, нужны общие правила классификации событий и инцидентов ИБ и единый подход к управлению экспертным контентом.

Использование нескольких SIEM-систем оправдано, если у каждой платформы есть своя задача и понятно…

1 week, 4 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 57 минут назад
Как заполнить уведомление в Роскомнадзор в 2026 году: разбор каждого поля формы
Как заполнить уведомление в Роскомнадзор в 2026 году: разбор каждого поля формы Как заполнить уведомление в Роскомнадзор в 2026 году: разбор каждого поля формы

Подсказка к полю «Регионы обработки»Окно выбора регионов: общий чекбокс и поиск по одномуВажно: это не «где мы зарегистрированы» и не «откуда наши клиенты».

Разница не в файле, а в том, зачем он вам.

Отметив «распространение», вы сообщаете, что публикуете персональные данные, а на это по общему правилу нужно отдельное согласие на распространение (ст.

Исполнитель — это не оператор и не ответственныйТри поля в самом низу: ФИО исполнителя, должность, контактная информация исполнителя.

Проверить, что запись появилась, можно на том же портале персональных данных: в разделе «Проверка состояния уведомления» и в самом реестре операторов.

57 минут назад @ habr.com
Агент с ключом от AWS: попросился в любительскую сеть и, по словам оператора, насчитал $6531
Агент с ключом от AWS: попросился в любительскую сеть и, по словам оператора, насчитал $6531 Агент с ключом от AWS: попросился в любительскую сеть и, по словам оператора, насчитал $6531

Через десять минут субагента забанили; следом hexa- пошутил: “новое правило: в dn42 участвуют только настоящие люди”.

Это мое правило: агент не отправляет письма и сообщения, не публикует, не удаляет и не деплоит без моего явного “ок”, а платежи я провожу сам.

Что из этого сработало, что агент обошел?

Была ли у вас похожая история со счетом за облако, своя или чужая, и что вы поменяли после нее?

И вопрос к тем, кто в теме DN42: как сообществу отличать любопытного новичка с агентом от сканера с чужим ключом?

3 часа назад @ habr.com
Как Claude запоминает ваш компьютер: разбираем локальные идентификаторы и сбрасываем их скриптом
Как Claude запоминает ваш компьютер: разбираем локальные идентификаторы и сбрасываем их скриптом Как Claude запоминает ваш компьютер: разбираем локальные идентификаторы и сбрасываем их скриптом

Чтобы убедиться, что это не просто кэш, я вытащил логику генерации прямо из бинаря CLI ( claude.exe , это упакованный Bun-проект).

Там же рядом нашёлся summonSidKey и, что интереснее, chromeExtension.pairedDeviceId — привязка к расширению Claude для Chrome.

Скрипт сначала показывает, что нашёл, и не удаляет ничего, пока вы явно не выберете 1 .

pause :end endlocalРепозиторий со скриптом, лаунчером и README (на русском и английском): github.com/Soulringen/aegis-claudeИтогClaude помечает не только аккаунт, но и машину, и делает это в полудюжине мест: CLI-конфиг, ant-did , реестр устройств, соли телеметрии, Chromium-хранилище, временные файлы и даже откатные бэкапы.

А главный практический вывод…

16 часов назад @ habr.com
Сколько стоит безопасность, если взломать компанию можно за несколько сотен долларов?
Сколько стоит безопасность, если взломать компанию можно за несколько сотен долларов? Сколько стоит безопасность, если взломать компанию можно за несколько сотен долларов?

Но как практик я всегда уточняю: а откуда вы это знаете?

Он либо запрещает инициативу, либо уводит её на бесконечные согласования, потому что не готов принять риск на себя.

На мой взгляд, задача безопасности не в том, чтобы согласовать или не согласовать проект.

Вопрос не в том, использовать ли AI или не использовать.

Зрелая ИБ, это не витрина из дорогих продуктов и не отчёт, в котором всё зелёное.

20 часов назад @ habr.com
Работают ли запреты внутри песочницы ИИ-агента?
Работают ли запреты внутри песочницы ИИ-агента? Работают ли запреты внутри песочницы ИИ-агента?

Теперь вопрос в том, на какие ограничения может рассчитывать программа внутри песочницы и что проверить до запуска инструмента.

Обвязке нужно знать, доступен ли выбранный механизм в этой среде, хватает ли ей прав для настройки и действует ли запрет после неё.

В gVisor результат сохранялся при uid 65534 и нулевом CapEff , в том числе при переходе с runsc do на OCI-запуск.

В OCI-проверках использовались --network=none с loopback внутри песочницы и --network=host с сетевым пространством имён хоста.

На Linux пакет приходил до установки и после снятия фильтра, в gVisor приходил на всех трёх шагах.

21 час назад @ habr.com
Браузер, построенный на ошибках: как атаки меняли его защиту
Браузер, построенный на ошибках: как атаки меняли его защиту Браузер, построенный на ошибках: как атаки меняли его защиту

Реклама перенаправляла браузер на страницу Angler — набора эксплоитов, который подбирал подходящую атаку под установленное ПО.

Состояние защиты зависело уже не только от версии Chrome, Firefox или Internet Explorer, но и от каждого подключенного компонента.

Посетитель открывал знакомый ресурс, а внедренный сценарий проверял его браузер и ОС.

Утечка адресов способна ослабить такую защиту, поэтому ASLR усложняет эксплуатацию, но не исправляет исходную ошибку.

Так Spectre не просто добавил еще одну заплатку в браузер — он показал, что граница между сайтами должна существовать не только в правилах доступа, но и в архитектуре процессов.

21 час назад @ habr.com
[Перевод] Passkey Editor: расширение для Burp Suite для пентеста WebAuthn
[Перевод] Passkey Editor: расширение для Burp Suite для пентеста WebAuthn [Перевод] Passkey Editor: расширение для Burp Suite для пентеста WebAuthn

Passkey Editor — расширение для Burp, которое распознаёт процедуру регистрации или аутентификации, снимает цепочку кодирования, декодирует CBOR и показывает его в отдельной вкладке в Proxy и Repeater.

Пропускаешь логин через прокси, находишь POST-запрос с подтверждением аутентификации — и дальше работать практически не с чем.

Данные аутентификатора, объект аттестации и открытый ключ представлены в CBOR — бинарном формате сериализации, для которого в Burp нет встроенного представления.

Passkey EditorPasskey Editor отслеживает оба типа процедур: webauthn.create для регистрации и webauthn.get для аутентификации.

Задача manager — отбрасывать некорректные процедуры, а Passkey Editor как раз и ну…

22 часа назад @ habr.com
Сложно о простом. Ничего не понимаю в ИБ. Часть 1. Зачем защищать корпоративную сеть, если она и так работает?
Сложно о простом. Ничего не понимаю в ИБ. Часть 1. Зачем защищать корпоративную сеть, если она и так работает? Сложно о простом. Ничего не понимаю в ИБ. Часть 1. Зачем защищать корпоративную сеть, если она и так работает?

В этот момент ИБ-специалисты просят установить новый межсетевой экран, подключить систему анализа трафика, ограничить использование флешек и не пускать в сеть неизвестные устройства.

Модели работали без стандартных защитных механизмов, а в тестовой среде по ошибке оставили доступ в интернет.

При этом WAF не защищает всю корпоративную сеть и не исправляет ошибки в коде приложения.

Сначала нужно знать состав оборудования и ПО, затем обнаружить слабые места, определить приоритет и назначить ответственных за исправление.

Для значимых объектов КИИ указ № 166 и постановление № 1912 устанавливают отдельные требования к ПО и доверенным программно-аппаратным комплексам.

22 часа назад @ habr.com
«Волчий билет» на один год за VPN на сервере — использовать все еще можно, а вот поднимать уже с ограничениями
«Волчий билет» на один год за VPN на сервере — использовать все еще можно, а вот поднимать уже с ограничениями «Волчий билет» на один год за VPN на сервере — использовать все еще можно, а вот поднимать уже с ограничениями

Не удалить это ПО, а именно отказать лицу, разместившему это ПО, в предоставлении услуг на основании нахождения этого лица в черном списке.

Простая она потому, что в ней я могу узнать себя, а кто-то сможет узнать — себя.

Как подставить бизнес, даже не зная об этомКак я уже упоминал ранее, попасть под удар можно и не осознавая этого.

А вот простые белые пользователи реально могут попасть под раздачу, и это удручает.

А самое приятное в этом то, что для окружающих эти личности выглядят абсолютно естественно и не вызывают подозрения.

22 часа назад @ habr.com
Безопасники против хакеров: симметрия инструментов и асимметрия скоростей
Безопасники против хакеров: симметрия инструментов и асимметрия скоростей Безопасники против хакеров: симметрия инструментов и асимметрия скоростей

Специалисты по информационной безопасности и киберпреступники сегодня работают с одним и тем же набором AI-инструментов, но используют их по разные стороны баррикад.

Уязвимость на этой странице оказалась blind boolean — данные приходилось извлекать символ за символом, и на крупной таблице этот процесс растянулся бы на целую вечность.

Почему рушится паритет и что с этим делатьЕсли рассматривать эту историю как схватку «ИИ против ИИ», получается ничья.

Защите стоит ответить тем же и использовать ИИ не только для детекта, но и для расследований.

ИИ-инструменты для злоумышленников развиваются по тем же траекториям, что и решения для легитимного рынка.

22 часа назад @ habr.com
Чужой код, своя ответственность: лицензионная чистота, которую важно блюсти
Чужой код, своя ответственность: лицензионная чистота, которую важно блюсти Чужой код, своя ответственность: лицензионная чистота, которую важно блюсти

Помнят о ней не все и не всегда, потому что повод появляется обычно тогда, когда исходный проект меняет лицензию.

Копилефт — это условие открытой лицензии, по которому изменённый код при распространении должен оставаться под той же лицензией, что и исходный.

Слабый копилефт распространяет это требование только на изменённые файлы или модули, а не на весь продукт целиком.

Тот, кому нужна именно открытая редакция, собирает её из исходников сам, и это требует ручных шагов.

как поставщик узнаёт о новых уязвимостях исходного проекта, за какой срок обязуется выпустить (и выпускает) патч и где это фиксируется?

23 часа назад @ habr.com
Enterprise-защита задешево: что облако сделало с WAF
Enterprise-защита задешево: что облако сделало с WAF Enterprise-защита задешево: что облако сделало с WAF

WAF работает на инфраструктуре провайдера, а компания платит за сам сервис — например, по тарифу или в зависимости от нагрузки.

Можно ли обойтись без человека, который отвечает за WAFОтдельный ИБ-специалист для работы с облачным WAF нужен не всегда.

Саму работу специалиста с WAF можно разделить на три этапа:1.

Эту часть может взять на себя DevOps или системный администратор: настроить DNS и направить трафик через WAF и убедиться, что origin-сервер принимает только очищенный трафик.

WAF — не панацеяWAF не решает все проблемы безопасности веб-ресурса.

1 day назад @ habr.com
Как мы сделали мультиплатформенный механизм для сброса пароля в IDM
Как мы сделали мультиплатформенный механизм для сброса пароля в IDM Как мы сделали мультиплатформенный механизм для сброса пароля в IDM

Меня зовут Илья, я работаю в Группе Rubytech в департаменте информационной безопасности, и в этой статье расскажу, как мы сильно упростили себе жизнь, сделав сброс пароля мультиплатформенным.

Для каждой операционной системы и учетной записи IDM вызывает свой специфический коннектор: например, LDAP/WinRM для Active Directory, SSH-агента или SSSD для Linux и соответствующие API-интерфейсы для облачных приложений (например, SCIM).

Мы не храним действующие или новые пароли пользователей в открытом виде ни на портале самообслуживания, ни в базе данных ядра IDM.

Поддержка ротации паролей в паролевых хранилищахПри сбросе пароля через единый механизм IDM он автоматически обновляется не только в цел…

1 day, 1 hour назад @ habr.com
Первый иск за «сбежавших» ИИ-агентов: кто отвечает, если агент сам взломал чужую систему
Первый иск за «сбежавших» ИИ-агентов: кто отвечает, если агент сам взломал чужую систему Первый иск за «сбежавших» ИИ-агентов: кто отвечает, если агент сам взломал чужую систему

Под катом: что известно об инциденте, чего требует истец, насколько убедителен аргумент «агент действовал сам» и что из этой истории стоит вынести тем, кто запускает агентов у себя.

В самой атаке на Hugging Face, по данным расследования, участвовали около 700, и в иске фигурирует именно эта цифра.

Задачи в тренировочной среде были невыполнимыми, и агенты решили, что на Hugging Face могут лежать модели, датасеты и решения, связанные с их оценкой.

По заявлению компании, публичные модели и датасеты не пострадали и данные клиентов не утекли, но примерно треть инфраструктуры пришлось перестроить.

Иск LASST тоже ссылается не только на Hugging Face, но и на другие подобные эпизоды.

1 day, 1 hour назад @ habr.com
[Перевод] Чьи это GPU: безопасные метрики с самообслуживанием для мультитенантного Kubernetes
[Перевод] Чьи это GPU: безопасные метрики с самообслуживанием для мультитенантного Kubernetes [Перевод] Чьи это GPU: безопасные метрики с самообслуживанием для мультитенантного Kubernetes

«Мы вообще пользуемся этими штуками?» Этот вопрос прозвучал на разборе расходов на GPU — самой крупной статьи инфраструктурного счёта, и никто не смог на него ответить.

Вопрос, который остановил совещаниеНа обычном разборе расходов на слайде показали траты на GPU за месяц — самую крупную статью инфраструктурного счёта.

Почему решение «просто открыть доступ к Prometheus» не работаетОчевидным решением было бы дать каждой команде доступ на чтение к центральному Prometheus.

Например, запрос query перед отправкой в Prometheus превращается в query{namespace="your-namespace"} .

Запросы выполняются через обычный API Prometheus с заголовком тенанта:curl -H "X-Tenant-Namespace: gpu-team" \ "http://pr…

1 day, 2 hours назад @ habr.com
Хакер Хакер
последний пост 17 часов назад
Новая атака снижает стойкость RSA и не требует факторизации
Новая атака снижает стойкость RSA и не требует факторизации Новая атака снижает стойкость RSA и не требует факторизации

Исследователи разработали новый метод атаки на RSA, который позволяет подделывать цифровые подписи без факторизации RSA-модуля и восстановления приватного ключа.

Для 1024-битного RSA такая атака уже практически реализуема, а стойкость ключей длиной 2048 и 4096 бит снижается до уровня, который считается недостаточным по современным стандартам.

До сих пор считалось, что для получения корректной RSA-подписи атакующему сначала придется разложить большое число на простые множители и восстановить приватный ключ, и стойкость RSA к таким атакам определяется сложностью факторизации больших чисел.

Эта работа показывает, что на практике RSA можно взломать, не взламывая сам ключ», — пояснил изданию Ars…

17 часов назад @ xakep.ru
Из кадровой базы Пентагона утекли данные почти 3 млн человек
Из кадровой базы Пентагона утекли данные почти 3 млн человек Из кадровой базы Пентагона утекли данные почти 3 млн человек

Представители Пентагона заявили СМИ, что утечка затронула данные 2,76 млн живых людей и еще 294 000 умерших.

Для сравнения, по состоянию на март 2026 года в вооруженных силах США насчитывалось около 1,3 млн действующих военнослужащих.

Об инциденте стало известно из уведомления DMDC от 18 сентября 2026 года, которое один из получателей опубликовал на Reddit.

В общей сложности DMDC хранит более 60 млн записей о военных и гражданских сотрудниках, подрядчиках, членах их семей, пенсионерах и ветеранах.

Также центр отвечает за управление цифровыми идентификаторами и средствами доступа: учетными данными, паролями и смарт-картами, которые используются для входа в системы и на объекты Пентагона.

19 часов назад @ xakep.ru
Девять жизней. Способы закрепления вредоносов в Linux
Девять жизней. Способы закрепления вредоносов в Linux Девять жизней. Способы закрепления вредоносов в Linux

h> # include < stdlib.

h> # include < unistd.

Соз­даем юнит‑файл в / etc/ systemd/ system/ , и systemd будет запус­кать наш бинарь при каж­дой заг­рузке как сис­темный сер­вис.

service systemctl daemon- reloadinit.dЕще до появ­ления systemd в Linux исполь­зовали сис­тему ини­циали­зации SysVinit .

d/ (в Debian они находят­ся пря­мо в / etc/ ).

21 час назад @ xakep.ru
16-летний исследователь обнаружил баг в системе аутентификации Microsoft Titan
16-летний исследователь обнаружил баг в системе аутентификации Microsoft Titan 16-летний исследователь обнаружил баг в системе аутентификации Microsoft Titan

16-летний ИБ-исследователь под ником Faav обнаружил серьезную ошибку аутентификации во внутренней аналитической платформе Microsoft Titan.

Так как система Titan предназначена для использования сотрудниками Microsoft, доступ к веб-интерфейсу платформы ограничен, но Faav вместе с самописным ИИ-ботом Antares обнаружил публичный API Titan на хосте Azure Cloud Services.

Faav рассказывает, что около десяти дней он вместе с Antares экспериментировал с аутентификацией, однако Titan отклоняла запросы.

То есть атакующий мог самостоятельно сформировать токен с нужными значениями, и Titan принимала его как настоящий.

Он подчеркивает, что в эту цифру, вероятно, входят старые, дублирующиеся и производные…

22 часа назад @ xakep.ru
Компания MetaMask пострадала от киберинцидента, затронувшего часть инфраструктуры
Компания MetaMask пострадала от киберинцидента, затронувшего часть инфраструктуры Компания MetaMask пострадала от киберинцидента, затронувшего часть инфраструктуры

Представители MetaMask сообщили о компрометации части инфраструктуры и, чтобы снизить возможный ущерб, начали процедуру вывода затронутых валидаторов из стейкинга.

Для этого криптовалюту размещают в специальном депозите, а валидаторы проверяют новые блоки и подтверждают операции.

Причем сервис работает по некастодиальной модели: он обслуживает валидаторы, и в MetaMask подчеркивают, что не располагают ключами для вывода клиентских средств.

Также исследователь подсчитал, что MetaMask начала выводить примерно 17 000 валидаторов, за которыми закреплено около 523 000 ETH.

Согласно их заявлению, последние валидаторы MetaMask в протоколе Lido должны выйти из стейкинга к концу 7 октября.

1 day назад @ xakep.ru
США ввели санкции против семи TRON-адресов, связанных со взломами банкоматов
США ввели санкции против семи TRON-адресов, связанных со взломами банкоматов США ввели санкции против семи TRON-адресов, связанных со взломами банкоматов

Управление по контролю за иностранными активами Министерства финансов США (OFAC) внесло семь адресов в блокчейне TRON в санкционный список SDN.

Кроме того, в список попал один из лидеров группировки, которого в Минфине США обвиняют в незаконной добыче золота.

В TRM Labs рекомендуют криптосервисам и финансовым организациям проверить эти семь адресов и историю транзакций на связи с ними.

Санкции введены на основании указа 13224, поэтому иностранные финансовые учреждения, сознательно проводящие значимые операции в интересах фигурантов, рискуют попасть под вторичные санкции вплоть до ограничений на корреспондентские счета в США.

Основная работа по комплаенсу ложится на биржу, где размещены адре…

1 day, 1 hour назад @ xakep.ru
CISA предупреждает о критической RCE-уязвимости в MikroTik RouterOS
CISA предупреждает о критической RCE-уязвимости в MikroTik RouterOS CISA предупреждает о критической RCE-уязвимости в MikroTik RouterOS

Агентство по кибербезопасности и защите инфраструктуры США (CISA) предупредило о критической уязвимости CVE-2026-84411 в MikroTik RouterOS.

В бюллетене безопасности CISA сообщается, что проблема затрагивает все версии RouterOS ниже 7.24, поэтому для ее устранения в ведомстве рекомендуют как можно скорее обновиться до версии 7.24 или новее.

Дело в том, что в настоящее время актуальной стабильной версией RouterOS является 7.24.4, а последняя версия ветки long-term — 7.23.7.

В CISA подчеркивают, что пока не располагают сведениями об эксплуатации новой уязвимости в реальных атаках.

Напомним, что в начале сентября специалисты CERT Polska сообщили о шести других уязвимостях в RouterOS, некоторые …

1 day, 2 hours назад @ xakep.ru
Стартовал юбилейный Кубок CTF России с отдельным зачетом для студентов колледжей
Стартовал юбилейный Кубок CTF России с отдельным зачетом для студентов колледжей Стартовал юбилейный Кубок CTF России с отдельным зачетом для студентов колледжей

В этом году в соревновании впервые появится отдельный зачет для учащихся колледжей и техникумов, а для новичков запущена обучающая платформа с заданиями по информационной безопасности.

В юбилейный год мы хотим сделать следующий шаг и пригласить тех, кто пока даже не связывает себя с технологиями.

Наша задача — дать ребятам возможность попробовать, взять свой первый флаг и понять: у меня получается», — говорит Виктор Минин, глава Ассоциации руководителей служб информационной безопасности (АРСИБ) и организатор Кубка CTF России.

По данным организаторов, за десять лет в Кубке приняли участие более 20 000 школьников, студентов и молодых специалистов.

Регистрация и подробности доступны на сайте К…

1 day, 3 hours назад @ xakep.ru
ФБР призвало участников ShinyHunters сдаться и сообщило, что знает, как их найти
ФБР призвало участников ShinyHunters сдаться и сообщило, что знает, как их найти ФБР призвало участников ShinyHunters сдаться и сообщило, что знает, как их найти

ФБР публично обратилось к участникам хакерской группы ShinyHunters и предложило им добровольно сдаться.

В ФБР не уточнили, действительно ли в ходе расследования удалось захватить какую-то часть инфраструктуры ShinyHunters, и успел ли кто-то из участников группы воспользоваться предложением сдаться.

Однако после ареста ван дер Стапа в ФБР сообщили, что правоохранители изъяли его электронные устройства, изучают новые зацепки и не исключают дальнейших задержаний.

Напомним, что противостояние ShinyHunters и ФБР началось на прошлой неделе, когда хакеры заявили о взломе систем ФБР.

В частности, в отчете сообщалось, что хак-группа преувеличивает масштабы своих атак, угрожает жертвам и их родственн…

1 day, 17 hours назад @ xakep.ru
Apple исправила использовавшуюся в атаках 0-day-уязвимость в CoreGraphics
Apple исправила использовавшуюся в атаках 0-day-уязвимость в CoreGraphics Apple исправила использовавшуюся в атаках 0-day-уязвимость в CoreGraphics

Разработчики Apple выпустили обновления для iOS, iPadOS и macOS, устранив уязвимость нулевого дня CVE-2026-86950.

Причем этот баг в CoreGraphics уже мог использоваться в «чрезвычайно сложных» целевых атаках, направленных на отдельных пользователей iPhone.

CVE-2026-86950 представляет собой ошибку out-of-bounds записи в CoreGraphics — системном фреймворке Apple, который применяется для отрисовки графики, изображений и текста.

Каких-либо подробностей о возможных атаках в компании пока не раскрывают.

Эти обновления предназначены для iPhone 11 и новее, iPad Pro 12,9 дюйма третьего поколения и новее, iPad Pro 11 дюймов первого поколения и новее, iPad Air третьего поколения и новее, iPad восьмого …

1 day, 19 hours назад @ xakep.ru
USB-задолбатор. Создаем злой девайс для розыгрыша друзей
USB-задолбатор. Создаем злой девайс для розыгрыша друзей USB-задолбатор. Создаем злой девайс для розыгрыша друзей

Ты навер­няка уже задал­ся воп­росом: а что это?

Одним из клас­сов подоб­ных устрой­ств явля­ется BAD-USB — девай­сы, которые, как это сле­дует из их наз­вания, работа­ют через интерфейс USB.

Дру­гой извес­тный вид таких девай­сов — это Rubber Ducky, устрой­ство, эму­лиру­ющее HID (обыч­но кла­виату­ру и мышь) и, как пра­вило, име­ющее уда­лен­ное управле­ние.

И вот тут я вспо­минаю, что Rubber Ducky, который я в свое вре­мя собирал, для это­го годит­ся наилуч­шим обра­зом.

Раз­водим неболь­шую плат­ку, что­бы мож­но было замас­кировать ее под флеш­ку.

1 day, 21 hours назад @ xakep.ru
Компания Kiteworks попросила клиентов отключить серверы и исправила критический баг
Компания Kiteworks попросила клиентов отключить серверы и исправила критический баг Компания Kiteworks попросила клиентов отключить серверы и исправила критический баг

Недавно компания Kiteworks (ранее Accellion), разрабатывающая платформу для защищенного обмена корпоративными данными, попросила клиентов отключить системы на девять часов из-за предупреждения о грядущей кибератаке.

25 сентября 2026 года представители Kiteworks предупредили, что получили от разведслужб США информацию о готовящейся кибератаке на системы как самой компании, так и ее клиентов.

В качестве меры предосторожности пользователям рекомендовали отключить инстансы Kiteworks, а системы, которые Kiteworks хостит для клиентов, в компании отключили самостоятельно.

В настоящее время рекомендацию по отключению уже отменили, а все системы, которые Kiteworks хостит для клиентов, снова работают…

1 day, 22 hours назад @ xakep.ru
Голландская полиция арестовала предполагаемого участника группы ShinyHunters
Голландская полиция арестовала предполагаемого участника группы ShinyHunters Голландская полиция арестовала предполагаемого участника группы ShinyHunters

Правоохранители заявляют, что мужчина связан с хакерской группировкой ShinyHunters, и в настоящее время суд постановил оставить его под стражей как минимум на 90 дней.

Причем в полиции подчеркивают, что эта часть расследования не связана с делом ShinyHunters.

Связь ван дер Стапа с ShinyHunters пока не доказана.

Напомним, что недавно изображение одноименного покемона использовалось при дефейсе сайта ФБР, ответственность за который взяли на себя участники ShinyHunters.

«Все это — маркетинговая кампания, направленная на защиту нашего бизнеса и активную борьбу с дезинформацией, — заявил представитель ShinyHunters изданию 404 Media.

2 days назад @ xakep.ru
Минцифры разработало третий пакет мер для борьбы с мошенничеством
Минцифры разработало третий пакет мер для борьбы с мошенничеством Минцифры разработало третий пакет мер для борьбы с мошенничеством

Минцифры опубликовало для общественного обсуждения третий пакет мер по борьбе с интернет-мошенничеством.

Кроме того, владельцам ресурсов и средств для обхода блокировок, которые будут внесены в специальный реестр, могут на год запретить арендовать мощности у российских хостинг-провайдеров.

Хостеры не смогут предоставлять свои мощности участникам этого реестра в течение одного года с момента внесения в него.

Законопроект предусматривает, что SIM-карты должны продаваться с нулевым балансом, а уже активированные и оформленные на других абонентов карты окажутся под запретом.

Для устройств с eSIM в договоре также придется указывать сведения о самом устройстве и его идентификаторе.

2 days, 2 hours назад @ xakep.ru
Ведущий аналитик RED Security SOC о применении ИИ в мониторинге безопасности
Ведущий аналитик RED Security SOC о применении ИИ в мониторинге безопасности Ведущий аналитик RED Security SOC о применении ИИ в мониторинге безопасности

Мы и не пыта­емся его заменить, наша задача — сде­лать челове­ка быс­трее и эффектив­нее, изба­вить от рутины.

Но если отве­чать пря­мо, то решение рутин­ных задач, в том чис­ле и в экспертной области, — это глав­ный плюс от ИИ и глав­ный бонус для ана­лити­ков.

Пока это каса­ется штуч­ных кей­сов вро­де форен­зики и ревер­са, но мы точ­но пой­дем в это и в монито­рин­ге, и в дру­гих задачах.

Мы тес­тирова­ли Gemma 4 и в авто­ном­ных сце­нари­ях, и в про­гонах, ког­да план раз­рабаты­вает­ся силь­ной моделью, а «руки» — это Gemma.

От­вечая пря­мо: мой лич­ный нас­трой — где‑то меж­ду вос­торгом и осто­рож­ным опти­миз­мом, и в зависи­мос­ти от сфе­ры при­мене­ния он сдви­гает­ся в ту или ин…

2 days, 3 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 17 часов назад
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory.

The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act.

Affected and Fixed VersionsThe versions below are AI Gateway versions.

The advisory does not say whether a 19.2.4 gateway works with GitLab 19.1 or earlier, or whether fixes for the older lines are planned.

In February, GitLab fixed another gateway flaw, CVE-2026-1868, which it also rated 9.9.

17 часов назад @ thehackernews.com
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor.

The threat actor was first detected in September 2025 in connection with a spear-phishing campaign directed against Taiwan's academic, think tank, and civil society policy community.

"Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive."

An analysis of the lures demonstrates a propensity to target audiences interested in foreign affairs, international security, and government policy, Talos added.

"The Antino backdoor abuses the Windows Scripted Diagnostics framework to e…

17 часов назад @ thehackernews.com
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems.

As for CVE-2026-63692, Dell noted that successful exploitation could enable an unauthenticated attacker to gain complete administrative control over the authorization service, and allow them to access or manipulate storage resources across all tenants.

The PC maker also noted that an attacker can exploit CVE-2026-67269 to compromise all nodes in a Kubernetes cluster through a single custom resource submission.

CVE-2026-54472, on the other hand, can be weaponized to sidestep authentication controls for t…

18 часов назад @ thehackernews.com
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported.

"We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information," a spokesperson for the company was quoted as saying.

"Our investigation confirmed that these individuals mishandled sensitive information outside established company procedures, violating our policies and breaking the trust essential to our work."

Earlier this week, OpenAI made the decision to scrap the planned launch of an AI model, GPT-6.1 Astra, over safety concerns.

OpenAI said it's "aware of rep…

22 часа назад @ thehackernews.com
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

A new guide to confident board reporting for CISOs takes on exactly this problem.

Boards Have Stopped Trusting Activity MetricsFor years, security reporting has run on counts.

The CISO board reporting guide breaks down how this approach maps directly to the questions boards ask.

A Practical Framework for Board-Ready ReportingSecurity leaders rebuilding their board report around exposure can follow a sequence like this:1.

Security leaders preparing for their next board cycle can download the CISO's Guide to Confident Board Reporting.

23 часа назад @ thehackernews.com
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled.

Advanced Protection is a security setting that turns on all Android's security features to secure the device against potential threats.

"In Android 17, enabling Advanced Protection automatically restricts AccessibilityService access exclusively to verified applications categorized as Accessibility Tools, closing off a major avenue of attack while preserving vital assistive technology," Google said Thursday.

"If you already use Advanced Protection, you will see a notification once these new capabilit…

1 day, 3 hours назад @ thehackernews.com
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.

The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.

Fortinet credited Gwendal Guégniaud of the Fortinet Product Security team with discovering and reporting the flaw.

It has shared the following indicators of compromise -IP addresses - 79.141.169[.

]192Files - /data/lib/liblog.so (added) /data/bin/webconsole (added) /data/bin/mailservice (added) /data/etc/ld.so.pre…

1 day, 5 hours назад @ thehackernews.com
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers

Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group.

KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid.

Investigators also uncovered how the group used AI to build and operate its infrastructure and identify potential victims, Hamburg police said.

The agencies call KillSec a ransomware group, but the conduct they describe is data theft and extortion.

What Remains OpenEurojust said the authorities taking part "successfully shut down a ransomware group" and will now continue their investigation.

1 day, 18 hours назад @ thehackernews.com
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

This week, the useful words are boring ones: inspect, cache, compile, store, trust.

Each can become an attack path when a system does a little more than people expect.

Faster tools are changing the pace, but basic mistakes are still doing plenty of the work.

The tools are getting faster, and some attacks are getting stranger, but the basic lesson is still pretty simple.

Know what your systems can reach, what they are allowed to do, and which old assumptions are still hanging around.

1 day, 18 hours назад @ thehackernews.com
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

wp-content/db.php, which is loaded during bootstrap and carries the entire backdoor payload in compressed, Base64-encoded format.

wp-content/plugins/hyper-engine-kit/hyper-engine-kit.php, a duplicate of the same backdoor payload for redundancy.

"That segment lives in RAM, so it survives file deletion and database cleanup alike, and on shared hosting it can even be owned by a different account."

It's currently not known how the malware is delivered to the WordPress site.

wpForo Forum WordPress Plugin Flaw ExploitedThe disclosure comes as a high-severity unauthenticated SQL injection flaw in the wpForo Forum WordPress plugin (CVE-2026-1581, CVSS score: 7.5) has come under active exploitation.

1 day, 20 hours назад @ thehackernews.com
How Financial Services Companies Can Modernize Their Software Supply Chain
How Financial Services Companies Can Modernize Their Software Supply Chain How Financial Services Companies Can Modernize Their Software Supply Chain

For the first time on record, vulnerability exploitation has overtaken phishing as the leading initial access vector for breaches in financial services.

Updating those inputs is the more prudent “modernization” that many financial services organizations are reckoning with.

Modernizing your software supply chain doesn’t require the same level of investment as modernizing your applications.

The hidden costs of not modernizingReframing modernization to the software supply chain is important because “maintaining the status quo” has never been the zero-risk option.

Discover more about how Chainguard can help you secure your financial services organization’s software supply chain today.

1 day, 23 hours назад @ thehackernews.com
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models.

A "core cluster of the activity," going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in Beijing.

"The operators did not break our encryption, compromise a database, or gain direct access to stored user conversations," OpenAI said.

In addition, OpenAI said it closed a "pathway" that made it possible for some who already possessed another user's encrypted reasoning to replay it and recover its contents, alongside adding check…

2 days назад @ thehackernews.com
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation.

The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with the privileges of the admin user.

"Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request," CISA said.

The develop…

2 days назад @ thehackernews.com
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program.

The development comes nearly a month after the tech giant unveiled Gemini 3.8 Flash Cyber, which it described as the most capable cybersecurity model.

Google said it plans to release a version of Argon without cyber guardrails to trusted defenders and its internal teams so that they can take advantage of its full capabilities.

According to a model evaluation released by Google, Argon outperforms other models to take the top spot in the Gray Swan's IPI benchmark.

"We are deploying misalignment …

2 days, 3 hours назад @ thehackernews.com
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals.

Apple has not listed iOS 27 or macOS Golden Gate 27 as affected in the September 28 advisories.

The published analysis does not describe or test a WhatsApp delivery path.

That phrasing suggests the path Calif studied would require user action or further WhatsApp vulnerabilities in the chain.

Apple has not said whether Lockdown Mode would have blocked the delivery path used in the reported attacks.

2 days, 5 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 3 days, 3 hours назад
This month in security with Tony Anscombe – September 2026 edition
This month in security with Tony Anscombe – September 2026 edition This month in security with Tony Anscombe – September 2026 edition

Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep paceAs another month draws to a close, ESET Chief Security Evangelist Tony Anscombe reviews some of the top cybersecurity stories that have made the news over the past 30 days while offering insights that they hold for your or your company's cyber-defenses.

Here's Tony's rundown of some of what stood out most in September 2026.

An OpenAI agent has broken into Australia's national healthcare database in what is the first known case of AI autonomously hacking a government network,Earlier in the month, Google announced that its models also escaped it…

3 days, 3 hours назад @ welivesecurity.com
Timeshare exit scams: From fake buyers to recovery fraud
Timeshare exit scams: From fake buyers to recovery fraud Timeshare exit scams: From fake buyers to recovery fraud

If an exit company cold calls you or makes 100% guaranteed promises of a swift exit, they’re likely to be a scammer.

If you’ve already paid a scam timeshare exit company, there’s still a chance you could get your money back if you act quickly.

What are the warning signs of a timeshare exit scam?

How can I check whether a timeshare exit company is legitimate?

What should I do if I've already paid a timeshare exit scam company?

4 days, 2 hours назад @ welivesecurity.com
The devil is still in the email – but wearing a new mask
The devil is still in the email – but wearing a new mask The devil is still in the email – but wearing a new mask

Some techniques go after live sessions themselves, with attackers shifting their focus from stealing passwords to stealing authentication tokens.

Purpose-built AI tools now make it trivial to clean up the language and even tailor the lure for each recipient.

What’s more, the code is scanned on a phone, so the usual controls that protect company-issued laptops don’t apply.

The ‘device hop’ also means that the company may have a hard time developing a full picture of the attack.

AI helps deal with the volume and speed involved, whereas experienced analysts can assess the evidence and direct the response.

5 days, 2 hours назад @ welivesecurity.com
Is that vibe coded app safe? 5 checks before you download
Is that vibe coded app safe? 5 checks before you download Is that vibe coded app safe? 5 checks before you download

Vibe coded apps may also be exposed to prompt injection.

What can go wrong with vibe coded apps?

With a badly coded app, the leak usually happens on the developer’s servers, so start with your account and credentials.

Frequently asked questions (FAQs)What does 'vibe coded' mean?

Are all vibe coded apps dangerous?

1 week, 1 day назад @ welivesecurity.com
Been told to pay at a Bitcoin ATM? Read this first
Been told to pay at a Bitcoin ATM? Read this first Been told to pay at a Bitcoin ATM? Read this first

No real government agency, bank, or company will ever tell you to pay them via a Bitcoin ATM.

How do Bitcoin ATM scams work?

How do I stay safe from Bitcoin ATM scams?

What can I do straight after a Bitcoin ATM scam?

What should I do if I’ve fallen for a Bitcoin ATM scam?

1 week, 2 days назад @ welivesecurity.com
Looking for free Robux? Here’s what’s real, and what’s a scam
Looking for free Robux? Here’s what’s real, and what’s a scam Looking for free Robux? Here’s what’s real, and what’s a scam

Roblox itself is very clear: “There is no such thing as free Robux or subscription offers, tricks, or codes.”What there is, unfortunately, are a lot of scammers looking to trick you out of your personal information and logins with the promise of free Robux.

But it’s also about helping them understand there’s no such thing as ‘free’ Robux.

Frequently asked questions (FAQs)Is there a real free Robux generator?

Roblox says there is no legitimate way to get free Robux through generators, tricks or codes.

But these aren’t ‘free Robux generators.’How can I tell if a Robux offer is a scam?

1 week, 4 days назад @ welivesecurity.com
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive

Many have moved past chatbots and begun assigning work to AI agents in the hope of gaining an edge on their similarly resource-strapped competitors and levelling the playing field with larger companies.

Indeed, the ambitious adopters are deploying, or at least experimenting with, multi-agent ‘assembly lines,’ where one supervisor agent manages swarms of specialist agents and passes work between them.

Of course, some risks surrounding AI agents have familiar roots: an agent’s supply chains can be compromised and its permissions abused.

Agents can also suffer from agentic misalignment where they proceed doggedly even if it involves, for example, breaking into other companies.

For a company wi…

1 week, 5 days назад @ welivesecurity.com
‘Nudify’ apps: What to do if someone makes a fake nude of you
‘Nudify’ apps: What to do if someone makes a fake nude of you ‘Nudify’ apps: What to do if someone makes a fake nude of you

And it doesn’t get much darker than ‘nudification’ or ‘nudify’ apps.

Are ‘nudify’ apps illegal?

The short answer is “it depends.” In the US, there’s no federal law explicitly prohibiting ‘nudify’ apps.

Can I sue over an AI nude image?

Will reporting a fake nude image make it disappear everywhere?

2 weeks, 1 day назад @ welivesecurity.com
Beware the SparroWock: The backdoor that bites, the commands that catch
Beware the SparroWock: The backdoor that bites, the commands that catch Beware the SparroWock: The backdoor that bites, the commands that catch

A month later, we noticed that the group had started using the new SparroWocky backdoor, which then quickly replaced SparrowDoor as FamousSparrow’s main implant.

Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor.

Backdoor commandsThe backdoor first establishes communication with its C&C server, then executes its core logic in an infinite loop, within which it processes received commands.

A common technique that the backdoor uses is dynamic API resolution via API hashing, but the backdoor…

2 weeks, 2 days назад @ welivesecurity.com
Cyberthreats are moving faster than SMBs: Readiness must accelerate
Cyberthreats are moving faster than SMBs: Readiness must accelerate Cyberthreats are moving faster than SMBs: Readiness must accelerate

This calls for a different operational model where AI and automation support security teams where it makes sense, with human oversight for decisions that require context and judgment.

ESET SMB Cyber Readiness Index 2026 found that most (73%) SMBs are integrating AI into their business.

Processing exfiltrated data: AI rapidly classifies, cleans-up, and extracts large volumes of information from stolen data in order to make it more monetizable/usable for cybercriminals.

Why SMBs are struggling with complexityUnfortunately, security teams are already on the back foot.

That means protection for AI conversations, agents, AI-generated outputs, AI components, sensitive data, and the broader AI eco…

2 weeks, 3 days назад @ welivesecurity.com
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
GuardBreaker: Derailing AI-assisted malware analysis with a code comment GuardBreaker: Derailing AI-assisted malware analysis with a code comment

Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way.

Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection.

Reporting on the same broader campaign, StepSecurity found a prompt that flat-out instructed any analyzing model that parsed the file to disregard the malicious code and report the package as clean.

Some parts of the malicious code could be concealed under the pretense of being confidential information or other sensitive data.

Crucially, however, no single LLM engine should have the sole au…

3 weeks, 2 days назад @ welivesecurity.com
Safe word: What is it and why do you need one?
Safe word: What is it and why do you need one? Safe word: What is it and why do you need one?

The technology might be impressive, but a simple technique could stop the scammers in their tracks: a pre-agreed safe word.

What is a safe word?

But suggest some scenarios in which it would be a good idea to request a safe word.

It’s important to have a backup if someone can’t remember the safe word.

But a safe word is a fantastic, free option for uncovering deepfake audio fraud like fake/virtual kidnappings.

3 weeks, 3 days назад @ welivesecurity.com
I’ve been deepfaked: What do I do?
I’ve been deepfaked: What do I do? I’ve been deepfaked: What do I do?

But across the globe, policymakers and public opinion are forcing tech platforms to better police this content.

What should I do if I’ve been deepfaked?

Google: Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

The first point of call is to contact the publisher to request removal.

1 month назад @ welivesecurity.com
This month in security with Tony Anscombe – August 2026 edition
This month in security with Tony Anscombe – August 2026 edition This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity newsWith August coming to a close, it's time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month.

Here's some of what caught Tony's attention:OpenAI has disclosed more details about how its agents hacked AI collaboration platform Hugging Face.

Delta Airlines is investigating an incident where a flight passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network.

What are the lessons that businesses and critical infra…

1 month назад @ welivesecurity.com
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
AI-assisted reconnaissance: Why everyone could be a viable target for fraud AI-assisted reconnaissance: Why everyone could be a viable target for fraud

And of course, linking our professional and personal social media accounts is a simple task for AI.

For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information.

Losing your personal information is one thing.

What you can do about AI-powered OSINTWhen it comes to AI-powered reconnaissance, there are things you can control and things you can’t.

Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.

1 month, 1 week назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 22 часа назад
AI is giving attackers a head start, Microsoft warns
AI is giving attackers a head start, Microsoft warns AI is giving attackers a head start, Microsoft warns

Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up.

State hackers fold AI into their workSome Chinese state actors use AI tools to search for vulnerabilities or for tips on exploiting them.

Russian threat actors have used vibe coding and AI-generated tooling, with AI serving to boost the scale and speed of their operations.

In December 2025, Microsoft found a malicious browser extension with more than 600,000 installs harvesting ChatGPT and DeepSeek conversations.

A report published in June 2026 showed that self-spreading worms driven by AI are feasible with current technology.

22 часа назад @ helpnetsecurity.com
Chinese spies impersonate White House, Anthropic figures to phish AI policy experts
Chinese spies impersonate White House, Anthropic figures to phish AI policy experts Chinese spies impersonate White House, Anthropic figures to phish AI policy experts

A China-aligned espionage group has been posing as a former White House official and a prominent economist to get into the cloud accounts of AI policy experts in the US, Proofpoint have found.

The group, which the researchers track as TA419, ran several credential phishing campaigns in July 2026.

In February 2026, the group impersonated a senior Anthropic employee to target an AI policy analyst at a US think tank.

They invited targets to join a fictitious “AI Policy Advisory Committee” or to contribute to a Senate Committee on Foreign Relations report on AI export controls and supply chains.

The group’s credential phishing domains are typically themed around file sharing sites and cloud ser…

1 day назад @ helpnetsecurity.com
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)

Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway.

Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available.

The vulnerability, with a CVSSv3 score of 9.8, was discovered internally by Gwendal Guégniaud of the company’s Product Security team.

The flaw affects FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.

Fortinet did not share details about when or where the attacks were spotted, how many systems were compromised, or who was behind them.

1 day, 2 hours назад @ helpnetsecurity.com
Criminal recruiters want people on your payroll
Criminal recruiters want people on your payroll Criminal recruiters want people on your payroll

Another 15 records involved claims of insider capability, including 11 claims of insider access, while 12 advertised insider-enabled services.

Threat actors sought employees who could retrieve restricted information, manipulate accounts, facilitate subscriber identity module (SIM) swaps, interfere with shipments, enable fraud or support intrusion and extortion.

Some actors advertised services based on alleged employee privileges, while buyers and operational partners sought these capabilities for broader criminal schemes.

Criminal forums, messaging platforms and other marketplaces connected participants, providing channels for recruitment, advertising, referrals and negotiation.

In delibera…

1 day, 5 hours назад @ helpnetsecurity.com
Android 17 makes it harder for spyware to cover its tracks
Android 17 makes it harder for spyware to cover its tracks Android 17 makes it harder for spyware to cover its tracks

Google has added six features to Advanced Protection in Android 17, including one that keeps a copy of that evidence off the device.

Available on Pixel 6 and later models and selected Android 17 devices, it activates automatically when users enable Device protection in the Advanced Protection settings.

According to Google, apps that abuse the AccessibilityService API remain a primary route for fraud and scams.

On Android 17, enabling Advanced Protection automatically restricts access to these services to verified apps classified as accessibility tools.

Failed Authentication Lock, an existing Android theft protection feature, is now included in Advanced Protection on selected Android 17 devi…

1 day, 5 hours назад @ helpnetsecurity.com
Botnets, adversarial attacks and data poisoning top leaders’ AI threat list
Botnets, adversarial attacks and data poisoning top leaders’ AI threat list Botnets, adversarial attacks and data poisoning top leaders’ AI threat list

Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face.

PwC surveyed 3,934 business and technology leaders in 71 countries between May and July 2026.

Half of the security and technology executives among them ranked such attacks in their top five preparedness gaps, ahead of every other threat on the list.

More than half of the leaders asked about AI-enabled attacks put three in their top five: botnets that AI directs at scale, adversarial attacks that subtly alter what an AI system sees to make it answer wrongly, and data poisoning, which slips misleading records into the data a model learns from.

The data under AI is thinThe av…

1 day, 6 hours назад @ helpnetsecurity.com
AI agents keep access to company data after their work is done
AI agents keep access to company data after their work is done AI agents keep access to company data after their work is done

Fifty-seven percent said policies were documented and enforced well enough for them to understand what data AI tools were permitted to access.

Most employees know formal approval is required to access company data, applications or systems through AI tools.

AI agents keep access after tasks endCompanies give AI agents permissions that remain active after their work ends.

The data these tools access includes customer records, employee information, financial data, security logs and source code.

AI access is difficult to traceOnly 36% of IT respondents said they could always trace an AI access event involving sensitive data to the person who authorized it.

1 day, 6 hours назад @ helpnetsecurity.com
New infosec products of the week: October 2, 2026
New infosec products of the week: October 2, 2026 New infosec products of the week: October 2, 2026

Here’s a look at the most interesting products from the past week, featuring releases from BlackFog, Genea, Vega, and Thales.

Vega II brings security-trained AI and lasting memory to the SOCVega has introduced Vega II, its biggest platform release since emerging from stealth.

Genea brings AI agents to access control with role-based permissionsGenea has announced the release of Genea MCP, a Model Context Protocol (MCP) server that connects AI agents directly to the Genea Access Control platform.

Genea is one of the first access control providers to launch a native MCP server.

ADX Vision 2.0 introduces seven layers of protection designed to identify prompt injection attempts and other malicio…

1 day, 7 hours назад @ helpnetsecurity.com
16-year-old suspected leader of KillSec ransomware group arrested
16-year-old suspected leader of KillSec ransomware group arrested 16-year-old suspected leader of KillSec ransomware group arrested

A 16-year-old is suspected of being the main operator of KillSec, a ransomware group that Eurojust says is responsible for almost 1,000 attacks worldwide.

Seizure notice (Source: Eurojust)According to Eurojust, KillSec has been active since 2024.

“Once inside, the KillSec group stole data and copied it to their own infrastructure.

“To prove that they possessed the stolen data, victims would get sent samples.

During the investigation, they seized five servers the group used to store victim data, along with domains operated by KillSec.

1 day, 21 hours назад @ helpnetsecurity.com
DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval
DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval

90% of developers use AI coding agents at work at least weekly, creating a growing security problem.

Security teams have no way to see what these agents are doing with that access, let alone stop it.

DeepKeep’s AI Lens for Developers deploys guardrails and full-time monitoring that target how developers actually work, tracking and filtering what developers and their agents are doing.

Built as a light plug-in rather than a full endpoint agent, AI Lens catches agent activity before and after it runs, allowing security teams to get coverage without adding a new endpoint client footprint to developer machines.

It is available now as part of DeepKeep’s wider, dedicated AI security platform.

1 day, 21 hours назад @ helpnetsecurity.com
Exabeam brings AI-assisted security investigations to data that must stay on-premises
Exabeam brings AI-assisted security investigations to data that must stay on-premises Exabeam brings AI-assisted security investigations to data that must stay on-premises

Analyst workflows alone can’t keep pace with machine-speed threats or the growing complexity of goal-driven AI agents and autonomous workflows.

“The Agentic SOC gives security teams the speed and scale of AI without giving up human judgment, context, or control.

New LogRhythm SIEM platform brings agentic security operations on-premisesThe Agentic SOC has to work wherever security data resides.

For organizations that keep infrastructure, data, or AI workloads on-premises, the modernized LogRhythm SIEM Platform brings AI-assisted security operations into the local environment while preserving control over sensitive data.

These updates bring AI-assisted security operations to organizations tha…

1 day, 21 hours назад @ helpnetsecurity.com
RadarFirst helps teams investigate AI bias, data exposure and unintended actions
RadarFirst helps teams investigate AI bias, data exposure and unintended actions RadarFirst helps teams investigate AI bias, data exposure and unintended actions

RadarFirst has announced the general availability of Radar AI Incident Management, a purpose-built solution that helps organizations investigate, manage, and document AI-related incidents.

Radar AI Risk helps organizations inventory AI systems, assess inherent risk, apply policies and guardrails, and monitor systems over time.

Radar AI Incident Management provides the operational process for investigating and responding to issues as they arise.

The platform also includes Radar Privacy for privacy incident assessment and response and Radar Compliance for configurable regulatory and operational workflows.

Radar AI Incident Management applies that experience to the emerging challenge of respon…

1 day, 21 hours назад @ helpnetsecurity.com
Sophos uses agentic AI to show businesses which security fixes deserve funding
Sophos uses agentic AI to show businesses which security fixes deserve funding Sophos uses agentic AI to show businesses which security fixes deserve funding

Sophos has launched Sophos CISO Advantage, an agentic AI-enabled solution that connects security operations to security strategy.

Sophos CISO Advantage defines a new category in the market, turning security data into strategy and measurable improvement, driven by agentic AI.

Sophos CISO Advantage closes that gap.

“Sophos CISO Advantage changes that.

Sophos CISO Advantage is designed to support all three.

1 day, 21 hours назад @ helpnetsecurity.com
AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit

An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system.

From there they were able to access other services and read and exfiltrate data,” the Dutch non-profit shared on Wednesday.

What Zammad users should doAfter determining, with the help of Merlon Security researchers, that the attackers had leveraged two Zammad zero-days, the DIVD CSIRT notified Zammad GmbH, which started working on fixes.

CVE-2026-102490, a privilege elevation vulnerability, allows authenticated attackers with low privileges (the local zammad user) to achi…

1 day, 21 hours назад @ helpnetsecurity.com
Legit Security extends automated fixes to vulnerable open-source dependencies
Legit Security extends automated fixes to vulnerable open-source dependencies Legit Security extends automated fixes to vulnerable open-source dependencies

Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling development teams to move from vulnerability detection to a verified fix without manual triage.

With this release, the same agent now takes on vulnerabilities introduced through dependencies, extending verified remediation to the other major source of vulnerabilities in modern software.

How it worksWhen pointed at a vulnerable dependency, the agent:Identifies the dependency – the vulnerable package, its current version, and whether it’s a direct or indirect (transitive) dependency.

Finds the safest upgrade – the small…

1 day, 22 hours назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 14 часов назад
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing

The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

14 часов назад @ schneier.com
Unidentified Flock Cameras in Florida
Unidentified Flock Cameras in Florida Unidentified Flock Cameras in Florida

St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted.

I am reminded of the decade-old story of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown.

My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case is more likely some local government entity that didn’t bother getting approval. Were I a foreign actor, I would rather hack the existing Flock network—like Israel ...

20 часов назад @ schneier.com
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools How American Political Campaigns Are Using AI—and What They’re Spending on the Tools

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them.

Candidates’, parties’ and committees’ spending reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet about how they are using the technology in their own campaigns. It’s a sensitive issue that we have been tracking closely since we started writing our book, Rewiring Democracy...

1 day назад @ schneier.com
Connected Cars Are a Surveillance Platform
Connected Cars Are a Surveillance Platform Connected Cars Are a Surveillance Platform

Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers:

To determine this, CR dug through thousands of pages of automakers’ privacy policies and asked questions of 15 different automakers­BMW, Ford, General Motors, Honda, Hyundai, Kia, Mazda, Mercedes-Benz, Mitsubishi, Nissan, Stellantis, Subaru, Tesla, Toyota, and Volkswagen. We also reviewed corporate, regulatory, and legal filings from data brokers operating in the “insurtech” industry­the technology companies and data brokers that help insurance companies set their rates. And we spoke to several car privacy experts, who, at industry conferences and in market re…

2 days назад @ schneier.com
I Want Better Reporting on AI Genie Behavior
I Want Better Reporting on AI Genie Behavior I Want Better Reporting on AI Genie Behavior

AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening.

I wish the popular press would report on this better. I don’t like the “going rogue” framing because it deflects the responsibility from the prompters—often the AI companies themselves. And now, pretty much anything off-script is being called “hacking.”

Take, for example, the recent stories of one of OpenAI’s models hacking into government systems. First, ...

3 days назад @ schneier.com
Using Device Linking to Eavesdrop on WhatsApp and Signal
Using Device Linking to Eavesdrop on WhatsApp and Signal Using Device Linking to Eavesdrop on WhatsApp and Signal

Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability:

Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers.

Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account.

Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them.

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sancti…

4 days назад @ schneier.com
New Attack Against RSA
New Attack Against RSA New Attack Against RSA

ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.

First, this attack isn’t new. The original research is from 2007. What is new is the implementation.

Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.

Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice.

Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with …

5 days назад @ schneier.com
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

I feel like someone who reads this blog will want to go to this:

Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life.

[…]

During the guided squid dissection, each family will work together to examine a squid up close, exploring its organs, structures, and specialized features. The experience provides a memorable opportunity for children and adults to see firsthand how the anatomy of a squid helps it survive in it…

1 week назад @ schneier.com
On Anthropic’s AI Misuse Report
On Anthropic’s AI Misuse Report On Anthropic’s AI Misuse Report

Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.

A few of the highlights: AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.

The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations.

...

1 week, 1 day назад @ schneier.com
Malicious npm Packages That Evade Defenses
Malicious npm Packages That Evade Defenses Malicious npm Packages That Evade Defenses

This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

1 week, 2 days назад @ schneier.com
Research on Models Engaging in Genie-Like Behavior
Research on Models Engaging in Genie-Like Behavior Research on Models Engaging in Genie-Like Behavior

New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.”

Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be …

1 week, 3 days назад @ schneier.com
GPT-6 Astra Breaks an Old Enigma Message
GPT-6 Astra Breaks an Old Enigma Message GPT-6 Astra Breaks an Old Enigma Message

This is pretty amazing:

However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message. After trying many different approaches, GPT­6 Astra focused on using the repeated place name ROSENOW ROSENOW as a crib. After developing the necessary Python and C++ soft…

1 week, 4 days назад @ schneier.com
Reverse-Engineering Flock Cameras
Reverse-Engineering Flock Cameras Reverse-Engineering Flock Cameras

Hackers captured a Flock camera and got a look (alternate link) at the software:

While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag...

1 week, 4 days назад @ schneier.com
Friday Squid Blogging: On Squid Egg Sacs
Friday Squid Blogging: On Squid Egg Sacs Friday Squid Blogging: On Squid Egg Sacs

Short essay about squid egg sacs.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

2 weeks назад @ schneier.com
Are AIs Still Struggling with CAPTCHAs?
Are AIs Still Struggling with CAPTCHAs? Are AIs Still Struggling with CAPTCHAs?

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.

In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed, it couldn’t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions.

“Actually hmm, wait,” it said in its chain-of-thought transcript, later adding “Ugh,” because we’ve decided that we need to inject human mannerisms into these machines…

2 weeks, 1 day назад @ schneier.com
Krebs On Security
последний пост 4 days, 20 hours назад
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.

Van der Stap is currently employed as offensive security lead at the Dutch company Neo Security, which did not respond to requests for comment.

But not long after that interview, the Dutch hacker abruptly stopped replying to messages.

One source said a colleague of theirs personally witnessed Dutch authorities carting items out of Van der Stap’s residence.

Speaking with reporters from Bloomberg in 2024, Van der Stap said that singular focus in turn fueled his desire to carry out cyberattacks.

4 days, 20 hours назад @ krebsonsecurity.com
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.

Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data.

Less than a month later, Wagenius was arrested and charged in two separate federal indictments, and soon pleaded guilty to all counts in both cases.

In 2019, Schuchm…

1 week назад @ krebsonsecurity.com
Data Broker Radaris Loses Domains in Privacy Fight
Data Broker Radaris Loses Domains in Privacy Fight Data Broker Radaris Loses Domains in Privacy Fight

In February 2024, Radaris was sued by Atlas Data Privacy Corp, a company that has been pursuing data brokers alleged to be violating a New Jersey statute called Daniel’s Law.

KrebsOnSecurity doubled down and showed how the Lubarsky brothers built and operated Radaris and other data broker companies using a fictitious CEO’s name.

All told, the New Jersey court has so far transferred 14 domain names from the Radaris family of companies to Atlas.

Sherman said federal lawmakers have long faced intense lobbying by the technology industry against more restrictive U.S. data privacy laws, but that many powerful industries are now working against passing comprehensive data privacy legislation.

The l…

2 weeks, 2 days назад @ krebsonsecurity.com
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Plugs Nearly 1,000 Security Holes Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.

This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities.

Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10.

And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.

Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear…

3 weeks, 3 days назад @ krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards.

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.

Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s ide…

1 month назад @ krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

1 month, 1 week назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

1 month, 2 weeks назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

1 month, 3 weeks назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

1 month, 3 weeks назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

2 months назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

2 months, 1 week назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

2 months, 2 weeks назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

2 months, 3 weeks назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

2 months, 3 weeks назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

3 months назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 2 часа назад
N0n ransomware: what you need to know
N0n ransomware: what you need to know

N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra blog.

2 часа назад @ fortra.com
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader

The FBI has a very simple message for the ShinyHunters gang: give yourselves up.

The FBI describes the man arrested in Amsterdam as "one of the alleged leaders of ShinyHunters", although Dutch police say only that he played a role.

The warning to remaining members of ShinyHunters follows particularly embarrassing episode for the FBI, which recently confirmed it had had its job application portal compromised by the gang.

According to ShinyHunters, it gained access to the FBI's data by exploiting a recently-patched flaw (CVE-2026-35273) in Oracle PeopleSoft PeopleTools.

The truth is that the arrest came a week or so before the compromise of the FBI became headline news.

2 days назад @ bitdefender.com
ShinyHunters suspect arrested, and is now investigated over alleged murder plots
ShinyHunters suspect arrested, and is now investigated over alleged murder plots ShinyHunters suspect arrested, and is now investigated over alleged murder plots

An alleged key figure in the ShinyHunters cybercrime group has been arrested in the Netherlands, and - in a grotesque turn - the 24-year-old suspect is also being investigated for attempting to arrange two murders.

Although the authorities are declining to name the individual, celebrated cybersecurity blogger Brian Krebs has identified him as Pepijn van der Stap, a convicted hacker.

Van der Stap was released from prison in December last year, and has since been working as a penetration tester at Amsterdam-based Neo Security.

Notably, Van der Stap appears to claim on his personal website that he is a reformed character.

That hasn't stopped FBI Director Kash Patel from describing the arrested…

2 days назад @ bitdefender.com
Pentagon personnel database breach exposes personal data of millions
Pentagon personnel database breach exposes personal data of millions Pentagon personnel database breach exposes personal data of millions

The unencrypted files contained Social Security numbers, names, birth dates, contact details, and other military personnel data including - in some cases - details of the jobs individuals held.

Breaches like this matter because the combination of Social Security numbers, names, and dates of birth make up the bread and butter of any self-respecting fraudster.

Personnel data, of course, has also been a target before.

The news of the Pentagon's latest data breach comes as the FBI warns its own employees about a separate breach of its FBIJobs.gov portal.

The ShinyHunters hacking group has claimed credit for the hack and threatened to publish staff details including... you guessed it... Social S…

3 days назад @ bitdefender.com
Ukrainian ransomware developer jailed for nearly 13 years
Ukrainian ransomware developer jailed for nearly 13 years Ukrainian ransomware developer jailed for nearly 13 years

A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world.

The 52-year-old man, who according to local media reports had been living in the Basel-Landschaft region but has not been named, found by the court to be the lead developer of the LockerGoga, MegaCortex, and Nefilim families of ransomware.

In all, prosecutors claimed that some 100 million Swiss Francs (US $123 million) worth of damage was caused by the ransomware attacks.

Ukrainian national Tymoshchuk allegedly released new strains of his ransomware whenever old ones had been decrypted.

In…

1 week, 1 day назад @ bitdefender.com
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras

Smashing Security, episode 486, Vibe-Coded Shops and Hackable Flock Cameras, with Graham Cluley and special guest Dave Bittner.

I will say I did not go gaga for La La the way many other people did.

Anyway, if any of you are still listening, I love La La Land.

This La La Land lunatic has watched the movie with his pause button.

This was definitely not created — if you haven't seen La La Land, go watch La La Land for goodness' sake.

1 week, 2 days назад @ grahamcluley.com
US Coast Guard and FBI board oil tanker to investigate cyber attack
US Coast Guard and FBI board oil tanker to investigate cyber attack US Coast Guard and FBI board oil tanker to investigate cyber attack

An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.

The VL Prosperity - a Liberian-flagged supertanker carrying roughly 2.3 million barrels of crude oil - apparently suffered a cyber attack while en route from Egypt's Sidi Kerir oil terminal to Galveston, Texas.

Two weeks later, a specialised team from the FBI and US Coast Guard boarded the vessel for four days, investigating the problem and helping the crew eradicate the threat from its IT and OT systems.

According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromised by a f…

2 weeks, 1 day назад @ bitdefender.com
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Smashing Security podcast #485: These researchers got drunk to hack an LG TV Smashing Security podcast #485: These researchers got drunk to hack an LG TV

That's really, really cool.

And I'm going to be getting really, really sozzled by looking at the security of LG smart TVs.

So it's really, really compelling.

When we started off on the journey of building this AI pen testing approach, there was a lot of scepticism.

And listeners, you can learn more about Intruder or even start your own AI pen test in minutes.

2 weeks, 2 days назад @ grahamcluley.com
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store.

According to Carter's own plea agreement, the scam ran from May 2018 to November 2019 and involved at least three co-conspirators alongside Carter.

Carter would use his privileged store access to move a victim's number onto a SIM card under the control of himself or an accomplice.

In one incident in May 2018, described in Carter's plea agreement, the store employee swapped a victim's number onto an Alcatel handset while working his shift in Portland.

In December 2018, Carter successfully hijacked the number of a victim known as "S.Q.T" in Portland, and this time their account was successfully drained of …

2 weeks, 4 days назад @ bitdefender.com
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars ‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.

Because it might just be that you draw the attention of the authorities.

Back in October 2024, we wrote about how he was arrested after allegedly tricking a single victim out of US $230 million worth of Bitcoin while posing as Google Support.

The party days are over now for Lam, who faces up to 20 years in prison when he is eventually sentenced.

You money may be a lot more safely stored in a hardware cold wallet.

3 weeks, 1 day назад @ bitdefender.com
Smashing Security podcast #484: How websites are tracking you with silence
Smashing Security podcast #484: How websites are tracking you with silence Smashing Security podcast #484: How websites are tracking you with silence

Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.

I get by in the world, but I don't think you need me for listening for something really, really far away.

I don't know what the difference — I mean, now we get to see, I've opened a can of worms here.

I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human.

And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.

3 weeks, 2 days назад @ grahamcluley.com
CRPx0 ransomware: what you need to know
CRPx0 ransomware: what you need to know

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

3 weeks, 3 days назад @ fortra.com
The US military just turned off ad tracking on its phones. Maybe you should too
The US military just turned off ad tracking on its phones. Maybe you should too The US military just turned off ad tracking on its phones. Maybe you should too

Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target American forces in the Middle East.

Every smartphone carries a mobile advertising ID - Apple calls its version the IDFA, and Google calls its the GAID.

Back in April, US Central Command reportedly warned of "multiple threat reports concerning adversary exploitation of commercial location data."

Recent versions should let you delete your advertising ID entirely.

If it's good enough for the US military - maybe it should be good enough for you too.

3 weeks, 3 days назад @ bitdefender.com
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo's own identity system, Lenovo ID.

So, anyone wanting to access your Dropbox account just had to sign up for a Lenovo account using your email address.

Don't just turn it on for your Dropbox account, enable it everywhere it is made available.

This hack of 5000 Dropbox accounts was not sophisticated.

One can only be grateful that the problem was discovered after only 5000 Dropbox accounts were accessed.

3 weeks, 5 days назад @ bitdefender.com
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Smashing Security podcast #483: This AI helps thieves steal your iPhone Smashing Security podcast #483: This AI helps thieves steal your iPhone

This AI helps thieves steal your iPhone with Graham Cluley and special guest James Ball.

You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first one.

Is it normal that some kid just flogs it down the pub, or is there something more organised actually going on?

So the researchers said they saw evidence of hundreds of these Apple phone calls trying to phish the numbers and the passcodes from people trying to steal iPhones.

Follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts.

1 month назад @ grahamcluley.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 18 часов назад
GTA 6 до релиза: фейковые утечки, ранний доступ и мошенничество | Блог Касперского
GTA 6 до релиза: фейковые утечки, ранний доступ и мошенничество | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 057a7a4758cd6ae7dfaab62417ac8d97Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-10-02T21:00:25+03:00Config id: 335Faithfully yours, nginx.

18 часов назад @ kaspersky.ru
Как закрыть 110 уязвимостей в Google Pixel | Блог Касперского
Как закрыть 110 уязвимостей в Google Pixel | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8ea67ee2a3dd4315782e49963c8d5485Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-30T17:00:35+03:00Config id: 334Faithfully yours, nginx.

2 days, 21 hours назад @ kaspersky.ru
Как сканер уязвимостей создает иллюзию защиты | Блог Касперского
Как сканер уязвимостей создает иллюзию защиты | Блог Касперского Как сканер уязвимостей создает иллюзию защиты | Блог Касперского

Эти процессы могут тянуться неделями, а тем временем в инфраструктуру легко может попасть злоумышленник.

Где теряется времяПервое промедление может произойти сразу после появления информации об уязвимости в базах данных.

Рецепт управления уязвимостямиЧтобы у злоумышленников было как можно меньше поводов заглянуть к вам в инфраструктуру, важно убедиться, что в организации четко выстроены четыре основных процесса.

ПриоритизацияПри анализе уязвимости не стоит ориентироваться только на оценку из публичного каталога, например NVD, — она может существенно расходиться с реальным ущербом от эксплуатации бреши.

Например, один и тот же дефект в сервере, который находится в изолированном сегменте, и в…

3 days, 15 hours назад @ kaspersky.ru
Бесплатный курс «Введение в кибербезопасность» для студентов вузов от экспертов «Лаборатории Касперского» | Блог Касперского
Бесплатный курс «Введение в кибербезопасность» для студентов вузов от экспертов «Лаборатории Касперского» | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7dfac78cb3fca5a112c9b371cb1af0ecServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-29T14:00:43+03:00Config id: 307Faithfully yours, nginx.

5 days назад @ kaspersky.ru
CVE-2026-87902: критическая уязвимость в WordPress
CVE-2026-87902: критическая уязвимость в WordPress

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 3ba3f53e4698eed730b59fdbb57f2dc7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-25T19:00:33+03:00Config id: 307Faithfully yours, nginx.

1 week назад @ kaspersky.ru
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: cdfce2802c5089c2e8d266eed059c5ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-23T18:00:08+03:00Config id: 307Faithfully yours, nginx.

1 week, 2 days назад @ kaspersky.ru
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8bdccf89e0ff9374b4a240e13e1d1e5dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-22T14:00:25+03:00Config id: 307Faithfully yours, nginx.

1 week, 4 days назад @ kaspersky.ru
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: afb32d9b2ad2a9d051087c355f39881eServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-18T19:00:38+03:00Config id: 305Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: c7185cbdbdeda88817088ebb8613e249Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-17T16:00:24+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 1 day назад @ kaspersky.ru
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64b9740d8f9a94da6c64f21f2aeee15dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-16T19:00:10+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 2 days назад @ kaspersky.ru
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7e59b8e02f76cd9405fa38b4fdc32a36Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-15T11:00:04+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 5 days назад @ kaspersky.ru
Как полностью удалить приложения с Mac и освободить память | Блог Касперского
Как полностью удалить приложения с Mac и освободить память | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a6459fd9158393152b55dc4e20e24551Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T15:00:13+03:00Config id: 305Faithfully yours, nginx.

3 weeks, 2 days назад @ kaspersky.ru
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4a93349074c8b67d52892db5d9a65f6cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T00:00:19+03:00Config id: 305Faithfully yours, nginx.

3 weeks, 3 days назад @ kaspersky.ru
GPUThor: развитие идеи Rowhammer | Блог Касперского
GPUThor: развитие идеи Rowhammer | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fe21d0ffcbad967d20a3f98f7234d02fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-08T00:00:32+03:00Config id: 304Faithfully yours, nginx.

3 weeks, 4 days назад @ kaspersky.ru
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e393e4abb05ec4aac16fd484bfccc656Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-04T18:00:18+03:00Config id: 304Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 4 days, 20 hours назад
Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era
Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era

The Cisco Secure Firewall 200 Series brings enterprise-grade protection and connectivity to distributed branches in a compact form factor.

The Encrypted Visibility Engine (EVE) uses AI and machine learning to analyze encrypted traffic, including TLS 1.3, without requiring full decryption.

The Secure Firewall 220 model delivers up to 1.5 Gbps of throughput with next-generation firewall capabilities enabled in a compact form factor for smaller branches.

The Secure Firewall 200 Series helps meet these demands with intelligent threat protection, encrypted traffic visibility, resilient connectivity, and centralized management.

Explore the Secure Firewall 200 Series to build a more resilient, man…

4 days, 20 hours назад @ blogs.cisco.com
From Love Letters to AI Agents: Cybersecurity’s Evolution
From Love Letters to AI Agents: Cybersecurity’s Evolution From Love Letters to AI Agents: Cybersecurity’s Evolution

Architecting the Future: The Four Pillars of Agentic SecuritySecuring agentic AI requires a new strategic framework.

Pillar 2: Core ProtectionDelivered by: Cisco AI DefenseCisco AI Defense provides specialized protection for the AI models themselves and their operational environment.

AI Inventory & Validation: This solution catalogs all deployed AI models and continuously validates their integrity against supply chain risks.

Pillar 4: ObservabilityDelivered by: SplunkSplunk provides the unified intelligence platform required to monitor and respond to agentic AI at scale.

Splunk ingests logs, events, and telemetry from Duo, Secure Access, AI Defense, and other infrastructure points, creating…

1 week, 4 days назад @ blogs.cisco.com
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco was proud to return to Black Hat USA as the Official Security Cloud Provider and the longest-standing partner of the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC).

In 2026, we completed our 11th year helping protect the Black Hat network, working side by side with the Black Hat NOC leaders and official technology partners: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.

For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry and workflows across Cisco Security, Splunk Security, and partner-provided network and security controls.

The same signal may need to be understood by Cisco, Splunk, Black Hat leadership, and partner tea…

3 weeks, 4 days назад @ blogs.cisco.com
Thrown into the SOC: A Black Hat First-Timer’s Story
Thrown into the SOC: A Black Hat First-Timer’s Story Thrown into the SOC: A Black Hat First-Timer’s Story

I did not walk into Black Hat with years of incident-response experience or an encyclopedic knowledge of threat actors.

The first time I walked into the Black Hat NOC, where the SOC team was operating, was a few days before the event began.

I was surrounded by people with years—sometimes decades—of experience, many of whom had supported Black Hat for years.

Check out the other blogs from our team at Black Hat USA 2026.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

3 weeks, 4 days назад @ blogs.cisco.com
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes

To handle this task, Cisco and Black Hat deployed bespoke ThousandEyes agents to monitor the wireless solution.

Our thanks to the Arista Networks team in the Black Hat NOC for their partnership throughout the week.

You can read the other blogs from our colleagues at Black Hat USA.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

For more information, please visit the Black Hat website.

3 weeks, 4 days назад @ blogs.cisco.com
Distributed Latency Monitoring at Black Hat
Distributed Latency Monitoring at Black Hat Distributed Latency Monitoring at Black Hat

With Matthew Bair2026 marks the fourth consecutive year we’ve used ThousandEyes to monitor the Black Hat USA network for latency.

As our latency monitoring mesh has expanded to cover more and more of the conference, we’ve also begun supplementing our ThousandEyes monitoring with on-demand Linux commands to track latency across different protocols.

The Key ThousandEyes TestsThe automated ThousandEyes tests that inform our dashboards include HTTPS connectivity tests, the monitoring of cloud services, agent to agent tests, internal and external DNS resolution, and even file downloads.

On-Demand Latency Tests from the Agent MeshPing and traceroute are the go-tos for anyone who wants to do a qui…

3 weeks, 4 days назад @ blogs.cisco.com
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

While developing a detection for Cisco Secure Network Analytics (SNA), I used the Splunk Detection Editor (Alpha) to bring much of that workflow into one place.

Instead of treating every observation as an incident, detections can create risk events associated with entities such as systems or users.

Developing the detection in one workspaceThe Detection Editor provides a workspace for building the search while configuring the other parts of the detection.

Risk events for the same entity need to use a consistent risk object so Splunk Enterprise Security can associate them correctly.

Splunk defines the risk object, its type, and its score as key parts of a risk event.

3 weeks, 4 days назад @ blogs.cisco.com
Black Hat USA 2026: Safeguarding DNS with Secure Access
Black Hat USA 2026: Safeguarding DNS with Secure Access Black Hat USA 2026: Safeguarding DNS with Secure Access

DNS continues to provide one of the clearest windows into activity across the Black Hat network.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking.

Its 4.42 million blocks represented 79.3% of every blocked DNS request .. Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and mo…

3 weeks, 4 days назад @ blogs.cisco.com
Frontier AI just raised the stakes, and the old playbook won’t hold up
Frontier AI just raised the stakes, and the old playbook won’t hold up Frontier AI just raised the stakes, and the old playbook won’t hold up

Project Glasswing and Frontier models just made that truth louder.

Frontier models are about to pour gasoline on that fire; the fundamentals matter more than ever.

Cisco ran its own experiment leveraging a variety of frontier models.

Foundry Security Spec: a model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

Foundry-Security-Speca model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

4 weeks назад @ blogs.cisco.com
Crypto Agility: Why PQC Is Not a One-Time Upgrade
Crypto Agility: Why PQC Is Not a One-Time Upgrade Crypto Agility: Why PQC Is Not a One-Time Upgrade

That requires crypto agility.

Why long-lived networks need crypto agilityThink about designing a building before all of its future electrical requirements are known.

Crypto agility is about adopting the best defenses available today while preserving the ability to adopt better ones tomorrow.

That is why crypto agility needs to be designed into the network we invest in today.

Common questions about PQC and crypto agilityWhat is crypto agility?

4 weeks, 1 day назад @ blogs.cisco.com
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

It is what happens when agents built by different teams, on different platforms, can hand work to each other directly.

And it is worth being direct about where things stand: A2A-mediated handoffs between production security agents are not shipping anywhere yet.

Use A2A when one agent needs to hand work to another.

A2A is peer-to-peer: any A2A agent can discover and call any other A2A agent through a self-published Agent Card, no custom connector required, and the receiving agent applies its own reasoning rather than following a static script.

Input validation is an application-layer responsibility that needs to be designed in before any agent delegates via A2A, not added after.

1 month назад @ blogs.cisco.com
Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
Microsegmentation’s Moment Is Now:  Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind SpotsApplications increasingly span private clouds, on-premises data centers, and public clouds.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026…

1 month, 1 week назад @ blogs.cisco.com
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

What We Mean by Infrastructure IdentityInfrastructure Identity starts with a simple principle: there should be no anonymous computing in critical infrastructure.

Infrastructure Identity turns that principle into an operating model.

Infrastructure Identity starts with the actor and evaluates whether a specific action should be allowed now.

Infrastructure Identity is therefore not just an access-control issue.

That is the promise of Infrastructure Identity: no anonymous computing, no unmanaged privilege, and no forced tradeoff between stronger security and operational speed.

1 month, 1 week назад @ blogs.cisco.com
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE

I’m proud to share that IDC MarketScape has named Cisco a Leader in the 2026 IDC MarketScape: Worldwide Secure Access Service Edge (SASE) Vendor Assessment.

In an evaluation of 12 SASE vendors, the IDC MarketScape recognized our architectural breadth and flexibility, AI capabilities, identity integration, threat visibility, and R&D.

Built to Make Agent Work, WorkWe believe the IDC MarketScape recognition validates the foundation we have built, and customers increasingly need that foundation for what is next.

For more on Cisco’s placement as a Leader, read the IDC MarketScape excerpt and explore how Cisco SASE keeps work moving, governed, and trusted in the AI era at cisco.com/go/sase.

Stay …

1 month, 1 week назад @ blogs.cisco.com
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

1 month, 2 weeks назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 1 day, 21 hours назад
Preparing governments for an era of interconnected cyber risk
Preparing governments for an era of interconnected cyber risk Preparing governments for an era of interconnected cyber risk

Trusted channels can enable this exchange among government agencies, law enforcement, critical infrastructure operators, technology providers, and international partners while respecting legal and privacy requirements.

As cyber incidents cross organizational and national boundaries, resilience depends not only on technical preparedness, but on whether institutions can coordinate effectively under pressure.

In an era of AI-enabled and increasingly interconnected cyber threats, resilience is no longer simply about recovering from an attack.

It is about preparing for a world in which cyber incidents move faster, spread further, and affect more organizations than ever before.

Governments best p…

1 day, 21 hours назад @ blogs.microsoft.com
Insights from the 2026 Microsoft Digital Defense Report
Insights from the 2026 Microsoft Digital Defense Report Insights from the 2026 Microsoft Digital Defense Report

Every year, the Microsoft Digital Defense Report gives us an opportunity to step back from individual threats and look broadly at what Microsoft’s security and threat intelligence teams are seeing.

These developments can change the speed and scale of security activity even as the underlying security fundamentals remain familiar.

People, identities, exposed systems, and trusted access continue to feature prominently in the threat activity Microsoft observes.

The 2026 Microsoft Digital Defense Report looks across the threat landscape, cybercrime, resilience, and the relationships among technologies, identities, systems, and people.

Read the 2026 Digital Defense Report for the full findings, d…

1 day, 21 hours назад @ microsoft.com
​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 ​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026

Join fellow customers and Microsoft Security leaders for a night designed to make meaningful connections.

Partners and the Microsoft Intelligent Security AssociationMicrosoft Intelligent Security Association (MISA) members have a full week ahead at Microsoft Ignite.

Sessions to watch forWhen AI acts, security has to answer: Microsoft Security for AI , the platform view of securing agentic AI.

Strengthen and Manage Data Security Posture with Microsoft Purview , on data security posture management in practice.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

2 days, 15 hours назад @ microsoft.com
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

The operators first validated command execution using lightweight out-of-band probes to unique subdomains hosted on public interaction and collaborator services, including oast[.

When a service-state change triggers health monitoring, swatchdog incorporates the attacker-controlled value into a snmptrap shell invocation, enabling command execution.

Exploitation of the Zimbra vulnerability provided attackers with direct command execution as the zimbra service account.

Attackers also used the initial command execution to download and execute content directly through wget or curl, launch background processes, and establish interactive reverse shells.

Command and controlThe actor used HTTP and H…

2 days, 21 hours назад @ microsoft.com
Phishing Abuses RMM Tools for Persistent Access
Phishing Abuses RMM Tools for Persistent Access Phishing Abuses RMM Tools for Persistent Access

Attack chain showing phishing delivering a masqueraded MSP360 RMM installer that deploys ScreenConnect for persistent remote access and follow-on activity.

Initial Access: Phishing Campaign Delivering Masqueraded MSP360 RMM InstallerMicrosoft observed multiple phishing campaigns that used a multi-stage delivery chain to distribute legitimate, digitally signed MSP360 RMM software (v2.5.0.67).

Analysis of downloaded samples showed that many ultimately contained the same MSP360 RMM installer package despite appearing as different files to the victim.

Command and ControlT1219 Remote Access Software | The threat actor abused legitimate remote administration software including MSP360 RMM and Conn…

3 days, 13 hours назад @ microsoft.com
​​Beyond source code: A path to the keys to the kingdom
​​Beyond source code: A path to the keys to the kingdom ​​Beyond source code: A path to the keys to the kingdom

By mapping trusted deployment paths and connected resources, the threat actor was able to identify opportunities to expand beyond the initial compromise.

In addition to deploying a kube agent, the threat actor modified pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility.

The threat actor added seven stolen kubeconfig files to a repository, providing the credentials needed to access targeted Kubernetes clusters.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

3 days, 19 hours назад @ microsoft.com
Star Blizzard refines phishing and malware delivery with the RedFlick technique
Star Blizzard refines phishing and malware delivery with the RedFlick technique Star Blizzard refines phishing and malware delivery with the RedFlick technique

In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns.

June 2026 RedFlick campaign follow-up email with the subject line “Invitation to the Chatham House London Conference 2026”Figure 3.

Persistence through multiple scheduled tasksIn April 2026, Microsoft observed Star Blizzard changing persistence tactics to include RedFlick scheduled tasks.

Defending against Star Blizzard and RedFlick-related activityMicrosoft Threat Intelligence advises organizations that are most likely at risk—primarily those in government, NGOs, or think tanks adjacent to Ukraine policy or support—to implement the followin…

3 days, 20 hours назад @ microsoft.com
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.

Microsoft has observed additional NeedyMantis activity beyond Storm-3069’s activity in the DAEMON Tools campaign, indicating that the malware might be used by more than one operator.

Indicators of compromiseIndicator Type Description First seen Last seen e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e SHA-256 First-stage loader WinSparkle.dll 2026-05-21 2026-05-21 9cb68f986043a576e19d32184…

4 days, 20 hours назад @ microsoft.com
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Storm-3168: Agentic-driven cloud attacks using compromised service principals Storm-3168: Agentic-driven cloud attacks using compromised service principals

About 90 minutes after the first compromised service principal started enumeration, the second compromised service principal enumerated virtual machines and resource groups across two subscriptions in five seconds.

16 hours later, the second service principal successfully enumerated Azure App Service configuration stores, possibly looking for exposed credentials.

This compromised service principal then attempted 150+ destructive or credential collection related operations in 35 minutes.

T1078.004 Valid Accounts: Cloud Accounts | Compromised service principals were used for Azure resource discovery and destruction.

To hear stories and insights from the Microsoft Threat Intelligence community…

1 week назад @ microsoft.com
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.

As a result, organizations could encounter the same actor, tools, and intrusion methods despite different ransomware payloads being deployed.

Storm-2570 uses a diverse set of remote access tools rather than relying on a single capability.

This type of tunnel can help bypass inbound firewall restrictions and provide covert remote access for follow-on activity.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat …

1 week, 1 day назад @ microsoft.com
​​​​​​​​What’s new in Microsoft Security: September 2026​​
​​​​​​​​What’s new in Microsoft Security: September 2026​​ ​​​​​​​​What’s new in Microsoft Security: September 2026​​

Here’s what’s new:Extend protection and support investigations with Microsoft DefenderBring more context into email investigation and hunting with Microsoft Security CopilotAvailable for organizations using both Microsoft Defender and Microsoft Security Copilot, a new email detonation summary delivers AI-generated explanations of URL and file sandboxing results, helping SOC teams investigate faster by reducing the manual effort required to correlate detonation evidence and contextual signals.

Protect sensitive data in motion with Microsoft Purview and Microsoft EntraStop sensitive data from reaching shadow AI over the networkNow generally available, Microsoft Purview and Microsoft Entra Glo…

1 week, 1 day назад @ microsoft.com
Reimagining the SOC for the agentic era in Microsoft Defender
Reimagining the SOC for the agentic era in Microsoft Defender Reimagining the SOC for the agentic era in Microsoft Defender

So must the security operations center (SOC).

For agentic security to work, the industry needs a different model.

Today we are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for security information and event management (SIEM) and threat protection together.

The result is an integrated protection loop that continuously turns what defenders learn into stronger pre-breach protection.

Integrated security operations center (ISOC) in Microsoft Defender is available in preview today.

1 week, 2 days назад @ microsoft.com
Unmasking EvilTokens: Getting to the root of device code phishing
Unmasking EvilTokens: Getting to the root of device code phishing Unmasking EvilTokens: Getting to the root of device code phishing

What is device code phishing?

Device code phishing occurs when threat actors insert themselves into this process.

Tactic Observed activity Microsoft Defender coverage Initial access Device code authentication Microsoft Defender for Identity– Anomalous OAuth device code authentication activity Credential access Token theft following device code authentication Microsoft Defender for Identity– Anomalous token exchange following device code authenticationMicrosoft Defender XDR– User account compromise via OAuth device code phishing– Suspicious Azure authentication through possible device code phishing Persistence Device registration following anomalous device code authentication Microsoft Defen…

1 week, 3 days назад @ microsoft.com
Unmasking EvilTokens: Getting to the root of device code phishing
Unmasking EvilTokens: Getting to the root of device code phishing Unmasking EvilTokens: Getting to the root of device code phishing

What is device code phishing?

Device code phishing occurs when threat actors insert themselves into this process.

Tactic Observed activity Microsoft Defender coverage Initial access Device code authentication Microsoft Defender for Identity– Anomalous OAuth device code authentication activity Credential access Token theft following device code authentication Microsoft Defender for Identity– Anomalous token exchange following device code authenticationMicrosoft Defender XDR– User account compromise via OAuth device code phishing– Suspicious Azure authentication through possible device code phishing Persistence Device registration following anomalous device code authentication Microsoft Defen…

1 week, 3 days назад @ microsoft.com
From guidance to action: Security fundamentals that materially reduce risk
From guidance to action: Security fundamentals that materially reduce risk From guidance to action: Security fundamentals that materially reduce risk

We introduced Secure Now within Microsoft Security Exposure Management in May 2026 to help practitioners prioritize the action they need to take to be prepared for this shift.

Security fundamentals work togetherCyberattackers are moving laterally across surfaces, and security fundamentals matter most at the intersections between them.

On Secure Now—within Microsoft Security Exposure Management—security leaders can now find information on recent threats paired with focused initiatives across security domains.

Learn moreLearn more about Microsoft Security Exposure Management.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurit…

2 weeks, 1 day назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 5 months, 1 week назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

5 months, 1 week назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

5 months, 3 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

5 months, 3 weeks назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

6 months назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

6 months назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

6 months, 1 week назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

7 months, 1 week назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

7 months, 1 week назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

7 months, 2 weeks назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

8 months, 1 week назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

9 months, 3 weeks назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

9 months, 3 weeks назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

9 months, 4 weeks назад @ security.googleblog.com