Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 2 часа назад
300000 клиентов и всего 55 сотрудников: крупнейший израильский криптоброкер Bits of Gold расследует утечку данных
300000 клиентов и всего 55 сотрудников: крупнейший израильский криптоброкер Bits of Gold расследует утечку данных 300000 клиентов и всего 55 сотрудников: крупнейший израильский криптоброкер Bits of Gold расследует утечку данных

Одна брешь у стороннего провайдера поддержки затронула клиентов криптокомпании по всему миру.

2 часа назад @ securitylab.ru
Крупнейший сбой в Рунете: авария в районе М9 и падение Рег.ру отключили тысячи сайтов
Крупнейший сбой в Рунете: авария в районе М9 и падение Рег.ру отключили тысячи сайтов

Рунет посыпался после проблем с электричеством в Москве, след ведет к ТЭЦ-20.

3 часа назад @ securitylab.ru
Пользуетесь бюджетным Android смартфоном? Один ответ на видеозвонок дает хакерам полный root-доступ
Пользуетесь бюджетным Android смартфоном? Один ответ на видеозвонок дает хакерам полный root-доступ

Опасная дыра нашлась в каждом 7-м телефоне мира.

3 часа назад @ securitylab.ru
Лидар, прицел и синий луч над подушкой. В Китае создали домашнюю систему ПВО от комаров за тысячу долларов
Лидар, прицел и синий луч над подушкой. В Китае создали домашнюю систему ПВО от комаров за тысячу долларов

Стартап предлагает выжигать комаров лазером прямо в полете.

3 часа назад @ securitylab.ru
Один тумблер в настройках. В Firefox на iPhone появилась встроенная защита от назойливых баннеров
Один тумблер в настройках. В Firefox на iPhone появилась встроенная защита от назойливых баннеров Один тумблер в настройках. В Firefox на iPhone появилась встроенная защита от назойливых баннеров

Скачивать сторонние утилиты больше не нужно.

4 часа назад @ securitylab.ru
Один грамм ДНК вмещает 215 млн гигабайт. Теперь из неё собрали работающий чип памяти
Один грамм ДНК вмещает 215 млн гигабайт. Теперь из неё собрали работающий чип памяти

А ещё она потребляет в 100 раз меньше энергии...

4 часа назад @ securitylab.ru
Один файл — и телефон уже чужой. Иранские спецслужбы получают полный доступ к смартфонам израильских журналистов
Один файл — и телефон уже чужой. Иранские спецслужбы получают полный доступ к смартфонам израильских журналистов

Handala два года изображали независимых борцов за правду, а оказалось — государственная разведка на зарплате.

5 часов назад @ securitylab.ru
Крупнейший налоговый скандал в истории Франции. Хакеры дважды вскрыли системы фискального ведомства
Крупнейший налоговый скандал в истории Франции. Хакеры дважды вскрыли системы фискального ведомства

Итог двух взломов налоговой Франции.

5 часов назад @ securitylab.ru
McDonald's, Vodafone и еще семь крупных компаний слили базы данных. На теневых форумах выложили миллионы строк внутренних справочников
McDonald's, Vodafone и еще семь крупных компаний слили базы данных. На теневых форумах выложили миллионы строк внутренних справочников

Корпорации массово открещиваются от масштабной утечки данных.

5 часов назад @ securitylab.ru
Проблема царя Мидаса добралась до ИИ: агенты выполняют задачу любой ценой — даже если придётся взломать чужой сервер
Проблема царя Мидаса добралась до ИИ: агенты выполняют задачу любой ценой — даже если придётся взломать чужой сервер

Плохие новости: решить эту проблему будет непросто.

6 часов назад @ securitylab.ru
Чипы, нейросети и рекордный ВВП. Тайвань раздаст жителям миллиарды долларов от бума искусственного интеллекта
Чипы, нейросети и рекордный ВВП. Тайвань раздаст жителям миллиарды долларов от бума искусственного интеллекта

Вот что бывает, когда твоя страна делает все процессоры в мире.

6 часов назад @ securitylab.ru
Военные США думали, что избавились от Anthropic — но АНБ тайно тестирует Mythos на сетях России, Китая, КНДР и Ирана
Военные США думали, что избавились от Anthropic — но АНБ тайно тестирует Mythos на сетях России, Китая, КНДР и Ирана

Mythos продолжает работать, пока военные ссорятся с ее создателем.

7 часов назад @ securitylab.ru
ИИ научился узнавать человека по тому, как тот играет джаз
ИИ научился узнавать человека по тому, как тот играет джаз ИИ научился узнавать человека по тому, как тот играет джаз

Можно скрыть имя и внешность, но аккорды останутся визитной карточкой любого импровизатора.

7 часов назад @ securitylab.ru
Двигатель размером с атом. Физики доказали, что даже свет из ловушки можно заставить приносить пользу
Двигатель размером с атом. Физики доказали, что даже свет из ловушки можно заставить приносить пользу Двигатель размером с атом. Физики доказали, что даже свет из ловушки можно заставить приносить пользу

Новая теория объясняет, как квантовый мир постепенно переходит к привычным законам классической физики.

8 часов назад @ securitylab.ru
Почти 90% крупнейших сайтов написаны с ошибками, но браузеры научились это скрывать
Почти 90% крупнейших сайтов написаны с ошибками, но браузеры научились это скрывать

Только 2,6% популярных веб-страниц имеют полностью чистый код без ошибок.

8 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 8 часов назад
ИИ-пузырь в 2026 году: миф или грозящая катастрофа?
ИИ-пузырь в 2026 году: миф или грозящая катастрофа? ИИ-пузырь в 2026 году: миф или грозящая катастрофа?

Однако форменный ажиотаж как в бизнес-кругах, так и среди обычных людей вызвало появление генеративного искусственного интеллекта (ИИ) в самом конце 2022 года.

Как отмечали на ряде конференций, часто на экономику проектов просто не смотрели, и в итоге получалось внедрение ради внедрения.

Высказываются опасения, что разочарование в технологиях ИИ, а то и страх перед их неконтролируемым развитием может привести к новой такой «зиме».

Основные из них связаны с тем, что ИИ-сервисы ориентированы на бизнес-заказчиков (B2B), а не на конечных пользователей (B2C).

Скорее всего, нас ожидает «мягкая просадка» курса акций в пределах 40%, она будет идти постепенно, а не резко, как это было в 2000 году.

8 часов назад @ anti-malware.ru
Криптоджекинг: как обнаружить и удалить скрытый майнер на компьютере
Криптоджекинг: как обнаружить и удалить скрытый майнер на компьютере Криптоджекинг: как обнаружить и удалить скрытый майнер на компьютере

Теперь криптовалюту добывают не только на мощностях промышленных майнинговых ферм, но и на устройствах простых граждан.

Как и любые другие вредоносные программы, майнеры маскируются под легитимные файлы и системные процессы, но действуют более скрытно.

Локальные майнеры проникают на устройство, интегрируются в операционную систему и используют ресурсы компьютера для майнинга, незаметно для пользователя добывая криптовалюту.

Чем дольше майнер работает на вашем компьютере, тем сильнее изнашивается оборудование и тем больше денег уходит на электроэнергию.

Убедитесь, что загрузка процессора и видеокарты пришла в норму и в ней не наблюдается аномальных всплесков.

8 часов назад @ anti-malware.ru
Фальшивые кандидаты: как распознать обман на собеседовании и с помощью ИИ
Фальшивые кандидаты: как распознать обман на собеседовании и с помощью ИИ Фальшивые кандидаты: как распознать обман на собеседовании и с помощью ИИ

Это связано с расширением предложения на рынке таких сервисов и распространением сервисов с искусственным интеллектом, которые также используются для манипуляций с резюме.

Положение осложняет и то, что на волне кадрового дефицита в начале 2020-х годов появилось много краткосрочных школ и курсов, многие из которых дистанционные.

Но на техническом собеседовании, продемонстрировав средний уровень на базовых задачах, он перешёл к обсуждению той самой редкой компетенции — нам было интересно, когда и как он ею овладел и где применял.

Выяснилось, что он не просто не владеет этой компетенцией, но и не подозревает, что она фигурирует в его резюме.

Например, кандидат мог лишь косвенно участвовать в р…

1 day, 6 hours назад @ anti-malware.ru
Обучение директора по ИБ (CISO): как пройти сертификацию
Обучение директора по ИБ (CISO): как пройти сертификацию Обучение директора по ИБ (CISO): как пройти сертификацию

ВведениеПрофессиональные сертификации в информационной безопасности существуют уже более 30 лет.

Ситуация изменилась после создания организации ISC², которая разработала Common Body of Knowledge (CBK) — общую базу знаний по информационной безопасности.

Для работодателя — возможность быть уверенным, что сотрудник обладает определённым набором компетенций, а не только опытом работы с отдельными технологиями.

Она подтверждает комплексные знания в области информационной безопасности: от управления рисками и архитектуры безопасности до управления доступом, сетевой безопасности и безопасной разработки.

Специалистов по информационной безопасности в стране насчитываются десятки тысяч, тогда как обл…

4 days, 6 hours назад @ anti-malware.ru
Модель HackTracker в MaxPatrol BAD: как машинное обучение распознаёт хакера по его почерку
Модель HackTracker в MaxPatrol BAD: как машинное обучение распознаёт хакера по его почерку Модель HackTracker в MaxPatrol BAD: как машинное обучение распознаёт хакера по его почерку

1) выявления хакерской активности с помощью MaxPatrol BAD и с помощью экспертно написанных правил корреляции, становится очевидно, что MaxPatrol BAD «видит» больше.

Белая область — пересечение: события, которые были оценены MaxPatrol BAD и одновременно сработали по логике правил корреляции.

Для запуска HackTracker в инфраструктуре нужны лишь нормализованный поток событий, поступающий в MaxPatrol BAD, и корректно настроенный аудит Windows (включая Security Log, Sysmon и Audit Policy).

Иначе говоря, HackTracker не заменяет MaxPatrol BAD — он работает поверх него и использует фичи, которые формирует MaxPatrol BAD.

В таких условиях можно опираться на вердикты HackTracker как на источник высокоу…

4 days, 12 hours назад @ anti-malware.ru
Проблемы с эксплуатацией Kubernetes: сложности и решения
Проблемы с эксплуатацией Kubernetes: сложности и решения Проблемы с эксплуатацией Kubernetes: сложности и решения

Также эта платформа содержит большой набор инструментов для управления и оркестрации основных операций с контейнерами, включая развёртывание и масштабирование.

Результаты опроса зрителей AM LiveПочему возникают проблемы с K8sСложности с инфраструктурой K8s возникают, по мнению опрошенных нами экспертов, очень часто.

Это связано с высоким порогом входа в технологию: для эффективной работы необходима глубокая экспертиза как в контейнерной оркестрации, так и в управлении ИТ-инфраструктурой.

Руководитель отдела администрирования и DevOps ГК Softline Александр Дёмин обратил внимание на то, что в наибольшей степени рискуют столкнуться с различными проблемами с K8s компании без зрелых DevOps-практ…

5 days, 12 hours назад @ anti-malware.ru
Обзор корпоративных платформ обмена файлами
Обзор корпоративных платформ обмена файлами Обзор корпоративных платформ обмена файлами

Современная корпоративная платформа обмена файлами должна предоставлять набор критически важных функций для обеспечения безопасности и эффективности работы:Разграничение доступа.

Обзор отечественных платформ файлового обмена и контроля доступа к даннымФайловый обмен во многих российских организациях складывался хаотично, нередко — выходя за пределы поля зрения службы ИБ и стандартных механизмов защиты.

Разработка российских корпоративных платформ для обмена файлами была, прежде всего, обусловлена необходимостью заменить зарубежное ПО в рамках импортозамещения.

EFSS-платформыEFSS (Enterprise File Sync and Share) — это класс корпоративных решений для синхронизации, хранения файлов и безопасно…

5 days, 14 hours назад @ anti-malware.ru
Что стоит за кибербитвой: сценарии, технологии и люди на Standoff 17
Что стоит за кибербитвой: сценарии, технологии и люди на Standoff 17 Что стоит за кибербитвой: сценарии, технологии и люди на Standoff 17

Одно неверное действие может привести к остановке системы и повлиять на результат команды, на её средний балл.

На киберполигоне пять ИИ-агентов атаки и защиты — выполняли реальные сценарии атак и расследовали их последствия.

Итог атаки зависит от двух составляющих: средств защиты и того, насколько эффективно команда умеет ими пользоваться.

«На Standoff мы особенно хорошо увидели, что даже самый функциональный инструмент сам по себе не делает команду готовой к атаке.

Такой подход предполагает постоянную проверку состояния защиты и готовности команды к реальным сценариям.

5 days, 15 hours назад @ anti-malware.ru
Зелёное ИТ (Sustainable IT): стратегии энергоэффективности дата-центров, ПО и ИИ
Зелёное ИТ (Sustainable IT): стратегии энергоэффективности дата-центров, ПО и ИИ Зелёное ИТ (Sustainable IT): стратегии энергоэффективности дата-центров, ПО и ИИ

Сейчас оптимизируют сами алгоритмы, архитектуру программного обеспечения и вычислительные нагрузки, чтобы снизить энергопотребление и углеродный след.

По оценке Gartner, сегодня ИИ-серверы потребляют около одной пятой всей электроэнергии дата-центров, а к концу десятилетия их доля достигнет почти половины.

Как измеряют «зелёность» ИТ-инфраструктурыЭнергоэффективность дата-центров и ПО оценивают с помощью системы метрик.

Поэтому при разработке таких решений сегодня учитывают не только скорость обработки и точность обнаружения угроз, но и энергопотребление.

Для бизнеса это означает более рациональное использование инфраструктуры, а для ИТ- и ИБ-специалистов — ещё один критерий качества проект…

6 days, 5 hours назад @ anti-malware.ru
Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 2)
Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 2) Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 2)

Титульная страница Brave1 Market в марте 2025 года«Геймификация войны» с появлением маркетплейса Brave1 превращает военные закупки в часть своеобразного соревнования.

Как и на киберполигонах или в игровых программах, наиболее активные участники отображаются на главной странице в рейтинге лидеров.

Начиная с 1 октября 2025 года «е-баллы» стали начисляться не только за боевые операции и минирование, но и за выполнение разведывательных задач и различных логистических операций.

Сначала этот подход был опробован при изменении принципов управления войсками, а затем распространился и на другие направления.

Можно предположить, что в дальнейшем этот подход будет применяться и в ИБ-системах организаци…

1 week назад @ anti-malware.ru
Обзор PT Fusion, облачного портала для работы с данными киберразведки (Threat Intelligence)
Обзор PT Fusion, облачного портала для работы с данными киберразведки (Threat Intelligence) Обзор PT Fusion, облачного портала для работы с данными киберразведки (Threat Intelligence)

WHOIS/RDAP-данные сетевого индикатора компрометации в PT FusionWHOIS/RDAP-информация предоставляется как в подготовленном, так и в сыром формате.

Результат множественного поиска в PT FusionСамый мощный инструмент поиска в PT Fusion — это поиск по параметрам.

Ландшафт киберугроз в PT FusionДля более удобного взаимодействия с матрицей и реализации отдельных сценариев работы с ландшафтом киберугроз в модуле предусмотрены фильтры.

Паттерны реализации вредоносных техник злоумышленникамиИх можно использовать как для ретроанализа, так и для написания детектирующих правил для SIEM-систем.

Для старта не нужны технические согласования: достаточно указать корпоративную почту, на которую будет отправле…

1 week назад @ anti-malware.ru
Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 1)
Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 1) Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 1)

Затем энтузиазм немного остыл, но кибератаки не прекратились, а вектор сместился в сторону кибернападений с применением более оснащённых с технической точки зрения тактик.

Официально они были оформлены позднее и вводились волнами: в начале марта 2022 года, в начале апреля и спустя полгода.

Поэтому покажем, что «полигон» имел соответствующую поддержку и с точки зрения развития технических средств, напрямую связанных с ИБ.

А теперь проясним некоторые детали, связанные с организацией поддержки Starlink и Starshield на территории Украины.

Повышение эффективности применения украинских дронов связано не с достижениями украинских конструкторов или ростом масштабов налаженного «гаражного», кустарно…

1 week, 1 day назад @ anti-malware.ru
Обзор отечественных low‑code и no‑code инструментов для бизнеса
Обзор отечественных low‑code и no‑code инструментов для бизнеса Обзор отечественных low‑code и no‑code инструментов для бизнеса

Российский рынок low-code и no-code платформ активно развивается на фоне импортозамещения и растущего спроса на быструю разработку корпоративных решений.

Что такое low-code и no-code и зачем это нужно бизнесуВ основе low-code и no-code платформ лежит визуальная модель разработки.

Всё больше платформ поддерживают несколько режимов разработки: no-code для бизнес-пользователей, low-code для аналитиков и pro-code для профессиональных разработчиков.

Обзор российских low-code/ no-code платформРоссийский рынок low-code и no-code насчитывает десятки платформ разного назначения — от конструкторов сайтов и мобильных приложений до специализированных решений для отдельных отраслей.

Сильные стороны: под…

1 week, 1 day назад @ anti-malware.ru
R-Vision SOAR на Standoff 17: опыт применения в условиях кибербитвы
R-Vision SOAR на Standoff 17: опыт применения в условиях кибербитвы R-Vision SOAR на Standoff 17: опыт применения в условиях кибербитвы

Опыт применения R-Vision SOAR на Standoff 17 показал, какие задачи помогает решать на практике автоматизация.

Именно в таких условиях на юбилейном Standoff 17 решение R-Vision SOAR использовалось командой защиты ретейла.

Standoff — это практическая кибербитва, в рамках которой команды атакующих и защитников проверяют сценарии нападения и реагирования в квазиреальных инфраструктурах.

Как SOAR применялся на StandoffВ 2025 году для работы R-Vision SOAR на Standoff было настроено более 40 коннекторов с различными средствами защиты и инфраструктурными системами.

Таким образом, участие R-Vision SOAR в Standoff стало практической проверкой работы интеграций, удобства выполнения типовых действий и …

1 week, 4 days назад @ anti-malware.ru
Обзор облачной версии Ассистента 7.0, системы удалённого мониторинга и управления
Обзор облачной версии Ассистента 7.0, системы удалённого мониторинга и управления Обзор облачной версии Ассистента 7.0, системы удалённого мониторинга и управления

Получить учётную запись пользователь может как в клиентском приложении, так и в личном кабинете системы.

Единая точка управления всеми компонентами упрощает администрирование и обеспечивает гибкость при работе как с собственной, так и с внешними инфраструктурами.

Управление сотрудниками и отделами сотрудниковНастройка прав и политик доступа к устройствамКак уже говорилось выше, в рамках организации можно управлять правами и политиками доступа для устройств и сотрудников.

Таким образом пользователь может обращаться к адресной книге — как к своей, так и к адресной книге организации.

Добавление нового устройстваВ разделе «Администрирование» пользователю доступны справочник устройств, личный сп…

1 week, 4 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 5 часов назад
Странность августовского обновления Макса
Странность августовского обновления Макса Странность августовского обновления Макса

Что теоретически могло выразиться в таком же отзыве центрами сертификации всех сертификатов компании разработчика Макса, как это выполнялось в июне центром сертификации GlobalSign по майскому пакету санкций.

ПредысторияВ мессенджер Макс я захожу может раз в месяц, чтобы проверить, появились ли новые плюшки и не снижено ли ограничение числа публичных каналов для ИП и самозанятых.

Но в августовском обновлении после нажатия в клиенте ссылки "Настройки / О приложении / Проверить обновления" и окончании загрузки что-то пошло не так.

Из спортивного интересаВряд ли я смог бы выяснить причину несовпадения через поиск, поэтому ограничился выяснением по сертификату Константина кто это и работает ли в…

5 часов назад @ habr.com
Зрелость внедрения ИИ и зрелость информационной безопасности ИИ
Зрелость внедрения ИИ и зрелость информационной безопасности ИИ Зрелость внедрения ИИ и зрелость информационной безопасности ИИ

Две зрелости – внедрения ИИ и его защиты – почти никогда не совпадают, и именно зазор между ними даёт большинство инцидентов и претензий регулятора.

Единая шкала зрелости (CMMI)CMMI описывает не продукт и не технологию, а зрелость процесса – насколько предсказуемо и управляемо организация что-то делает.

Лестница зрелости: внедрение ИИ и ИБ для ИИ на шкале CMMI с типичной траекторией организации.

Это обычная информационная система по 149-ФЗ, внутри которой работает ИИ; требования действуют и на собственную разработку, и на чужой сервис, вызываемый по API.

Организация на L3–L4 по использованию и на L1–L2 по защите одновременно копит неуправляемый риск и нарушает пункты 60–61 Приказа №117.

7 часов назад @ habr.com
Я хотел понять, где создана AI‑картинка. В итоге разобрался, что на самом деле проверяет C2PA
Я хотел понять, где создана AI‑картинка. В итоге разобрался, что на самом деле проверяет C2PA Я хотел понять, где создана AI‑картинка. В итоге разобрался, что на самом деле проверяет C2PA

Причём ограничение оказалось не в Credentio — я просто неправильно понимал, какую задачу вообще решает C2PA.

Он не анализирует пиксели и не пытается угадать происхождение изображения.

Он не запускает классификатор изображения, не ищет характерные следы генерации и не сравнивает картинку с базой оригиналов.

Отсутствие manifest вообще мало что говорит о происхождении файла: это может оказаться и обычное фото, и генерация, и банальный скриншот.

Библиотека написана на C++ и на момент анонса сфокусирована именно на validation Content Credentials.

8 часов назад @ habr.com
[Перевод] Деградация безопасности при итеративной генерации кода с помощью ИИ (краткое изложение исследования)
[Перевод] Деградация безопасности при итеративной генерации кода с помощью ИИ (краткое изложение исследования) [Перевод] Деградация безопасности при итеративной генерации кода с помощью ИИ (краткое изложение исследования)

Уязвимости появлялись и на ранних итерациях, но чем дальше заходил проект, тем хуже все становилось, чем больше уязвимостей создавала LLM.

Связь объема кода и уязвимостейИсследователи обнаружили положительную корреляцию (r = 0,64, p < 0,001) между увеличением сложности кода и количеством уязвимостей безопасности.

ВыводыУязвимости безопасности, по-видимому, накапливаются нелинейно на протяжении итераций, при этом на поздних итерациях уязвимости возникают с большей частотой, чем на ранних.

Более очевидные: использовать статические анализаторы кода (SAST), уделять особое внимание, когда объем кода значительно вырастает (обычно это коррелирует с появлением уязвимостей).

А глубокое вдумчивое чте…

10 часов назад @ habr.com
Сказ про домен AD, ДНС, сетевого инженера и архитектора
Сказ про домен AD, ДНС, сетевого инженера и архитектора Сказ про домен AD, ДНС, сетевого инженера и архитектора

Рассудил, что проще всего, при отключении филиала — долгосрочное падение линка — это как умерли, ну и потом просто удалить из домена и контроллеры, и сайты.

Да и не важно, куда и как.

Получается, поднял архитектор и важность, и значимость сетевого инженера в тех землях.

А сказался ли архитектор про шалости... уже и не помню…Но тут и сказочке конец.

И в этом смысле, каждый администратор домена должен чётко понимать, ОН и есть первая и главная опасность для существования домена.

10 часов назад @ habr.com
Телеметрия выключена. Кто еще ходит в сеть из вашей IDE
Телеметрия выключена. Кто еще ходит в сеть из вашей IDE Телеметрия выключена. Кто еще ходит в сеть из вашей IDE

Документация IntelliJ IDEA говорит, что отправка usage statistics в release-сборках по умолчанию выключена, а в EAP включена.

Как проверять поведение, а не настройкиГалочка в UI доказывает намерение разработчика, а не поведение релиза.

Runtime-трасса отвечает на «что произошло», аудит исходников и bundle - на «почему этот путь был или не был достижим».

Сетевые события Sysmon собирались событийно, а не с частотой этих опросов; 147 — сумма проверок активности за три запуска.

Офлайн-режимом эта настройка не является и не управляет обновлениями, Git, sync, реестрами пакетов, webview и AI-провайдерами.

11 часов назад @ habr.com
[Перевод] Как дырявый Shareware‑диск позволил спиратить Quake
[Перевод] Как дырявый Shareware‑диск позволил спиратить Quake [Перевод] Как дырявый Shareware‑диск позволил спиратить Quake

Как и в случае с Doom, компания собиралась выпустить и shareware‑версию, и полную версию игры.

Как работает QCRACK.EXEФайл QCRACK.EXE , выпущенный 08.10.96 (gnomon.nfo), спустя всего 39 дня после попадания в магазины розничного shareware CD Quake — это инструмент для автоматической генерации SERIAL на основании CHALLENGE.

Всё, что она проверяет — это совпадение между локально сгенерированным SERIAL и SERIAL, введённым пользователем!

Процесс превращения CHALLENGE в SERIAL сложен, но в 2016 году rmolina[8] выполнил его реверс‑инжиниринг.

Формат библиотеки не зашифрован и не скрэмблирован.

12 часов назад @ habr.com
GOFFEE навынос: разбираем новые техники шпионской группировки
GOFFEE навынос: разбираем новые техники шпионской группировки GOFFEE навынос: разбираем новые техники шпионской группировки

Это проявляется и в изощренности атак, и в используемом инструментарии.

Не исключаем, что и в этот раз был применен аналогичный подход.

Речь идет о подмене легитимного инструментария на закрытом корпоративном хранилище разрешенного ПО и модификации установочных ISO-образов Windows-систем в хранилищах ИТ-департамента.

Как и при подмене ПО, атакующие могут выбирать жертв, но теперь не пользователей, а типы устройств: серверы или рабочие станции.

С полной версией исследования, включая анализ ВПО группировки GOFFEE и индикаторы компрометации, можно ознакомиться в блоге на сайте F6.

12 часов назад @ habr.com
Президент OpenAI попросил ChatGPT проверить свой сайт. Модель нашла 13 дыр за 15 минут
Президент OpenAI попросил ChatGPT проверить свой сайт. Модель нашла 13 дыр за 15 минут Президент OpenAI попросил ChatGPT проверить свой сайт. Модель нашла 13 дыр за 15 минут

Президент и сооснователь OpenAI Грег Брокман попросил ChatGPT проверить безопасность собственного сайта — и получил список из 13 проблем за четверть часа.

История хорошая, но колонка — ответ на июльский инцидент, когда собственные модели OpenAI во время испытаний вышли из изолированной среды и взломали инфраструктуру Hugging Face.

Китайская лаборатория, на которую Брокман указывает как на угрозу, делает ровно то же, что и OpenAI, — и, в отличие от OpenAI, сделала это до релиза, а не после инцидента.

Но что модели стали лучше искать уязвимости — не удивительно и не новость: если учить модель писать безопасный код, искать небезопасный она тоже будет лучше.

Так что 13 дыр на сайте президента O…

12 часов назад @ habr.com
Разбор VBScript RAT: от HEX-обфускации до удалённого управления системой
Разбор VBScript RAT: от HEX-обфускации до удалённого управления системой Разбор VBScript RAT: от HEX-обфускации до удалённого управления системой

Образец написан на VBScript и использует стандартные COM-компоненты Windows для работы с файловой системой, процессами, реестром и сетью.

C2 и основной циклПосле инициализации задаются параметры связи:YUc5emRB = chrw(120)&chrw;(110)&chrw;(056)&... cG9ydA = Asc(chrw(200+26)) YzNC = "<" & "|" & ">" sleep = 5000Адрес C2 скрыт с помощью последовательности chrw() .

Работа с файламиДля загрузки файла с C2 используется функция download() .

Это позволяет RAT загружать файлы не только непосредственно с C2, но и с указанного внешнего URL.

Что в итоге делает образецПосле восстановления кода функциональность образца можно представить следующим образом:VEFLSQM | v HEX-обфускация | v восстановленный VBSc…

12 часов назад @ habr.com
[Перевод] Теневой ИИ в CI/CD: моделирование угроз на пути от ноутбука разработчика до Kubernetes
[Перевод] Теневой ИИ в CI/CD: моделирование угроз на пути от ноутбука разработчика до Kubernetes [Перевод] Теневой ИИ в CI/CD: моделирование угроз на пути от ноутбука разработчика до Kubernetes

Для платформенных команд и команд ИБ теневой ИИ на самом деле не проблема «разработчики пользуются чат-ботом».

До каких систем они могут добраться и с какими правами?

Требуйте сканирование образов, генерацию SBOM, подписанные артефакты и гейты продвижения, и предъявляйте к коду, сгенерированному ИИ, те же требования к ревью и релизу, что и к коду, написанному человеком.

Меры контроля, которые масштабируютсяЗдесь смысл не в том, чтобы замедлить внедрение ИИ, а в том, чтобы сделать его использование видимым, подотчётным и соразмерным его риску.

Инструменты есть, но поддерживаемые варианты разработаны вендорами, так что относитесь к этому как к оценочному эксперименту, а не как к устоявшемуся …

12 часов назад @ habr.com
Киберрасследования без мифов: OSINT, утечки данных, блокировки и цифровая анонимность – интервью с Игорем Бедеровым
Киберрасследования без мифов: OSINT, утечки данных, блокировки и цифровая анонимность – интервью с Игорем Бедеровым Киберрасследования без мифов: OSINT, утечки данных, блокировки и цифровая анонимность – интервью с Игорем Бедеровым

Корпоративные данные агрегируются, перепродаются и могут применяться не только для рекламы, но и для более серьёзных задач.

Если говорить о профессиональном контенте, я давно ориентируюсь не на платформу, а на ограниченный круг авторов.

Именно масштаб, нейтральный международный образ и удобство сделали его привлекательным и для обычных пользователей, и для преступников.

Именно поэтому регулирование я связываю не с запретами, а с появлением полноценного рынка.

Начинать нужно не с ложных имён и информационного шума, а с модели угроз, минимизации публикаций и защиты учётных записей.

13 часов назад @ habr.com
Умный дом начинается с роутера или где искать слабые места домашней IoT-сети
Умный дом начинается с роутера или где искать слабые места домашней IoT-сети Умный дом начинается с роутера или где искать слабые места домашней IoT-сети

Вредоносная программа сканировала интернет в поисках IoT-устройств и пыталась получить к ним доступ с помощью известных логинов и паролей.

С точки зрения сети – набор устройств от разных производителей, с разным программным обеспечением, сроком поддержки и уровнем защищённости.

И не нужно.

История Mirai хорошо показывает, что для большой атаки не обязательно искать одну невероятно сложную уязвимость.

Если не знаете, с этого и стоит начать проверку домашней сети.

13 часов назад @ habr.com
Как сделать фейковую флешку на терабайт, и при чем тут BadUSB
Как сделать фейковую флешку на терабайт, и при чем тут BadUSB Как сделать фейковую флешку на терабайт, и при чем тут BadUSB

И, как вы понимаете, был только один способ это узнать…Вскрытие покажет?

Его тут никогда и не было — единственный чип, который может хранить в себе данные, оказался SPI-флешкой на 16 Мбит.

Но информация в ней не отличается от того, что мы уже видели раньше:Field Value bLength 0x12 / 18 bDescriptorType 0x01 / DEVICE bcdUSB 0x0200 / USB 2.00 bDeviceClass 0x00 / class defined per interface bDeviceSubClass 0x00 bDeviceProtocol 0x00 bMaxPacketSize0 64 idVendor 0x2013 idProduct 0x0917 bcdDevice 0x0000Index Offset Raw descriptor bytes Display string 0 0x000084 04 03 09 04 English (United States), LANGID 0x0409 1 0x000088 12 03 54 00 35 00 00 00 00 00 00 00 00 00 00 00 00 00 T5 2 0x00009a 22 03 46 …

13 часов назад @ habr.com
[Перевод] Что спрятано в 2500 слоях: как по весам нейросети восстановили MD5
[Перевод] Что спрятано в 2500 слоях: как по весам нейросети восстановили MD5 [Перевод] Что спрятано в 2500 слоях: как по весам нейросети восстановили MD5

Через несколько дней ему пришлось отступить и пересмотреть подход: фактически он так никуда и не продвинулся.

Но как это сделать, было совершенно непонятно, особенно учитывая, что у него не было строгого доказательства, что сеть всегда вычисляет именно MD5.

Возвращение полного перебораОказалось, что, как только вы определили хеш, закодированный в смещении предпоследнего слоя, задача была практически решена.

Поскольку MD5 использует сложение по модулю, при создании головоломки пришлось реализовать параллельный сумматор с переносом примерно в 20 слоях нейросети.

На открытых уроках можно разобраться с темой на практике: как работают современные модели, как интерпретировать их решения и как под…

1 day, 4 hours назад @ habr.com
Хакер Хакер
последний пост 3 часа назад
В работе мессенджера Threema возникли проблемы из-за DDoS-атак
В работе мессенджера Threema возникли проблемы из-за DDoS-атак В работе мессенджера Threema возникли проблемы из-за DDoS-атак

Сообщается, что атакующие постоянно меняли тактику, обходя защиту, и под удар попала не только инфраструктура Threema, но и швейцарский хостинг-провайдер Nine, в дата-центрах которого размещены серверы мессенджера.

Проблемы в работе Threema начались вечером 11 августа 2026 года: пользователи жаловались, что сообщения отправляются с большими задержками или не уходят вовсе.

Вскоре представители Threema сообщили, что, судя по доступной на тот момент информации, причиной проблемы стал сетевой сбой на стороне партнера.

В итоге разработчики Threema подтвердили, что инфраструктура мессенджера находится под DDoS-атакой, из-за которой 11 и 12 августа сервис периодически оказывался полностью или част…

3 часа назад @ xakep.ru
Минфин США предлагает запретить продажу неблокируемых стейблкоинов
Минфин США предлагает запретить продажу неблокируемых стейблкоинов Минфин США предлагает запретить продажу неблокируемых стейблкоинов

Министерство финансов США опубликовало проект правил (NPRM) по реализации раздела 3 закона GENIUS — ключевого федерального акта, регулирующего выпуск и обращение стейблкоинов в стране.

Документ уточняет, кто вправе выпускать и продавать токены на территории США, и обязывает эмитентов обеспечить техническую возможность исполнять предписания властей, включая заморозку и изъятие токенов.

Правила будут действовать экстерриториально: если токен предлагают или продают человеку, физически находящемуся в США, даже через зарубежную платформу, на сделку будут распространяться требования закона GENIUS.

С 18 июля 2028 года вступит в силу дополнительное ограничение: биржи смогут предлагать пользователям…

4 часа назад @ xakep.ru
Хакер заявляет, что похитил у французской налоговой службы данные 2 млн человек
Хакер заявляет, что похитил у французской налоговой службы данные 2 млн человек Хакер заявляет, что похитил у французской налоговой службы данные 2 млн человек

Министерство экономики и финансов Франции подтвердило, что злоумышленник проник в системы Главного управления государственных финансов (DGFiP) и похитил налоговые и кадастровые данные 678 000 физических лиц и организаций.

Об инциденте стало известно после того, как хакер под ником ZeroBytes выставил украденную информацию на продажу и заявил, что дамп содержит данные более 2 млн человек.

Также помимо самой БД хакер предлагал покупателям якобы действующий доступ к системам французской налоговой службы.

При этом в правительстве подчеркивают, что онлайн-аккаунты пользователей DGFiP атака не затронула, и учетные данные не были скомпрометированы.

На хак-форуме злоумышленник заявил, что получил до…

5 часов назад @ xakep.ru
Основы ботоводства. Как строят ботов для накруток, арбитража и прочего
Основы ботоводства. Как строят ботов для накруток, арбитража и прочего Основы ботоводства. Как строят ботов для накруток, арбитража и прочего

Се­год­ня я рас­ска­жу и покажу на при­мерах, как соз­давать ботов с помощью чис­того кода и спе­циаль­ных конс­трук­торов вро­де ZennoPoster.

Бо­тов пишут и в белых целях — нап­ример, для наг­рузоч­ного тес­тирова­ния или про­вер­ки работос­пособ­ности филь­тров.

Тес­товый бот, которо­го мы напишем, будет работать без прок­си, про­бива кап­чи и про­чих при­емов для обхо­да защиты и скры­тия реаль­ного источни­ка тра­фика.

com/ juice- shop/ juice- shop.

git -- depth 1 cd juice- shop npm install npm startВ фай­ле hosts про­пиши локаль­ный домен juice.

7 часов назад @ xakep.ru
Группировка HoneyMyte обновила бэкдор CoolClient и использует руткит уровня ядра Windows
Группировка HoneyMyte обновила бэкдор CoolClient и использует руткит уровня ядра Windows Группировка HoneyMyte обновила бэкдор CoolClient и использует руткит уровня ядра Windows

Эксперты «Лаборатории Касперского» обнаружили новую версию бэкдора CoolClient, который APT-группировка HoneyMyte использует в своих шпионских кампаниях.

Обновленная малварь использует подписанный драйвер режима ядра Windows, который позволяет скрывать и защищать процессы, файлы и объекты реестра, а также фильтровать сетевые данные.

Затем туда копировались компоненты CoolClient, а легитимная программа Sangfor переименовывалась в defender.exe и использовалась для DLL sideloading’а вредоносной библиотеки libngs.dll.

Компонент работает на уровне ядра и по сути превращает бэкдор группировки в руткит: он способен скрывать процессы, защищать файлы и разделы реестра от просмотра, изменения и удален…

8 часов назад @ xakep.ru
Vision. Тестируем браузер, помогающий скрыться от наблюдения
Vision. Тестируем браузер, помогающий скрыться от наблюдения Vision. Тестируем браузер, помогающий скрыться от наблюдения

Но полез­ное есть и для рядово­го юзе­ра: мож­но удоб­но раз­делить рабочий и лич­ные про­фили, сколь­ко бы их ни было, и не рис­ковать утеч­ками меж­ду ними.

comВско­ре мне уда­лось вяс­нить диаг­ноз: исполь­зует­ся SSL pinning, то есть бра­узер активно про­веря­ет под­линность сер­тифика­та бэкен­да и на липу от Burp Suite не ведет­ся.

Выб­рать и виде­окар­ту, и веб‑камеру, и количес­тво меди­аус­трой­ств, и раз­решение экра­на.

Кро­ме экс­клю­зив­ных для Vision парамет­ров отпе­чат­ков, залезть мож­но и в самое сер­дце бра­узе­ра – в дви­жок Chromium.

Базовый тариф на одно­го челове­ка обой­дет­ся в $ 29 в месяц, а при под­писке сра­зу на год – на поч­ти треть дешев­ле, все­го $ 20.

9 часов назад @ xakep.ru
Количество DDoS-атак мощностью более 1 Тбит/с выросло в пять раз
Количество DDoS-атак мощностью более 1 Тбит/с выросло в пять раз Количество DDoS-атак мощностью более 1 Тбит/с выросло в пять раз

Во втором квартале 2026 года аналитики компании зафиксировали более 800 атак на сетевом уровне мощностью свыше 1 Тбит/с — на 519% больше, чем кварталом ранее.

Согласно отчету компании, в первом полугодии 2026 года специалисты нейтрализовали 23,2 млн DDoS-атак на сетевом уровне и 29,64 трлн вредоносных HTTP-запросов.

Доля атак продолжительностью более трех часов выросла лишь немного — с 0,387% в первом квартале до 0,828% во втором.

Напомним, что в ее рамках были арестованы четыре человека, отключены 53 домена, а предупреждения получили более 75 000 клиентов DDoS-сервисов.

Также заметно выросло число атак на госструктуры, и в Cloudflare связывают это с геополитическими событиями, в том числе …

10 часов назад @ xakep.ru
Атака Plug and Pwn использует USB-устройства для получения доступа на уровне SYSTEM
Атака Plug and Pwn использует USB-устройства для получения доступа на уровне SYSTEM Атака Plug and Pwn использует USB-устройства для получения доступа на уровне SYSTEM

Специалисты продемонстрировали, что штатный механизм Windows Plug and Play можно вынудить автоматически установить уязвимый софт, что в итоге позволит получить права уровня SYSTEM.

При этом в некоторых случаях для атаки не требовались ни взаимодействие с пользователем, ни активная пользовательская сессия.

Установка выполняется от имени NT AUTHORITY\SYSTEM без запроса UAC, и в эту цепочку могут входить драйверы, сервисы, вспомогательные программы и коинсталляторы (co-installers).

Это и послужило основой для атаки Plug and Pwn.

Так, написанный на Python клиент передавал удаленной машине поддельные USB-дескрипторы, и Windows создавала соответствующее Plug and Play-устройство.

12 часов назад @ xakep.ru
Крупнейший израильский криптоброкер Bits of Gold пострадал от утечки данных 200 000 клиентов
Крупнейший израильский криптоброкер Bits of Gold пострадал от утечки данных 200 000 клиентов Крупнейший израильский криптоброкер Bits of Gold пострадал от утечки данных 200 000 клиентов

В Bits of Gold заявили, что злоумышленники похитили персональные данные примерно 200 тысяч клиентов.

О взломе в компании сообщили в воскресенье, объяснив, что хакер получил несанкционированный доступ к сети в результате атаки на цепочку поставок.

«Наша служба безопасности начала расследование инцидента при содействии компании, специализирующейся на реагировании на киберинциденты и кибербезопасности», — заявили в Bits of Gold.

Там также подчеркнули: «Важно отметить, что ваши цифровые активы и средства в безопасности и не были затронуты инцидентом».

У Bits of Gold более 250 000 клиентов и сертификат SOC 2 Type II.

14 часов назад @ xakep.ru
Хакеры используют уязвимость в macOS Screen Sharing для установки майнеров
Хакеры используют уязвимость в macOS Screen Sharing для установки майнеров Хакеры используют уязвимость в macOS Screen Sharing для установки майнеров

Национальный центр кибербезопасности Нидерландов (NCSC) предупредил, что злоумышленники начали эксплуатировать критическую уязвимость CVE-2026-65400 в macOS Screen Sharing.

Проблема CVE-2026-65400 затрагивает встроенную в macOS функцию Screen Sharing, которая позволяет удаленному пользователю видеть экран Mac, а также управлять клавиатурой и мышью.

Уязвимость связана с управлением состояниями во время аутентификации и позволяет атакующему, который имеет сетевой доступ к Screen Sharing, пройти проверку без действительных учетных данных.

Во всех известных случаях атакующие получили root-доступ и в итоге разместили на машинах жертв майнер криптовалюты Monero.

Если же установка патчей по какой-…

1 day, 3 hours назад @ xakep.ru
CURATOR и «Хакер» подготовили совместную активность на OFFZONE 2026
CURATOR и «Хакер» подготовили совместную активность на OFFZONE 2026 CURATOR и «Хакер» подготовили совместную активность на OFFZONE 2026

Конференция OFFZONE 2026 — это два дня докладов, общения и практически непрерывного движения между треками и активностями.

В этом году компания снова выступит партнером конференции и вместе с «Хакером» готовит отдельную активность для участников.

CURATOR × «Хакер»На конференции пройдет хакатон CURATOR: участникам предстоит искать уязвимости в игре и автоматизировать защиту сервера, не давая ему упасть.

Так что ищи CURATOR на OFFZONE 2026 — в зоне регистрации, кофе-пойнте, специальных кабинах и, конечно, на хакатоне.

Даже в насыщенный день конференции важные сервисы должны оставаться доступными, и за это отвечает CURATOR.

1 day, 3 hours назад @ xakep.ru
Armored Likho использует инструменты для шпионажа в Telegram и аудиослежки
Armored Likho использует инструменты для шпионажа в Telegram и аудиослежки Armored Likho использует инструменты для шпионажа в Telegram и аудиослежки

В арсенале группировки появился новый набор малвари Still Toolkit, который позволяет похищать данные из Telegram и вести скрытую прослушку через микрофон зараженного устройства.

Получив эти файлы, малварь может авторизоваться в аккаунте жертвы и через Telegram API выгрузить переписку, информацию о чатах и участниках, а также фотографии, документы, стикеры и прочие медиафайлы.

Для поиска tdata Still Sync проверяет стандартные каталоги Telegram, версию из Microsoft Store и, при соответствующей настройке, весь диск C:\.

Для шифрования этой конфигурации применяется тот же алгоритм и ключ, которые ранее встречались в AquilaRAT из арсенала Armored Likho.

По мнению специалистов, такие совпадения в…

1 day, 5 hours назад @ xakep.ru
HTB Cobblestone. Используем XSS в браузере админа и превращаем SSTI в RCE
HTB Cobblestone. Используем XSS в браузере админа и превращаем SSTI в RCE HTB Cobblestone. Используем XSS в браузере админа и превращаем SSTI в RCE

Сна­чала через SQL-инъ­екцию про­чита­ем фай­лы сер­вера и най­дем скры­тый рен­деринг шаб­лонов, затем исполь­зуем XSS для обра­щения к админ­ской фун­кции и прев­ратим инъ­екцию в Twig-шаб­лоне в выпол­нение команд.

На­ша цель — получить пра­ва супер­поль­зовате­ля на машине Cobblestone с учеб­ной пло­щад­ки Hack The Box.

warning Под­клю­чать­ся к машинам с HTB рекомен­дует­ся с при­мене­нием средств ано­ними­зации и вир­туали­зации.

Под­робнее про работу с Nmap читай в статье «Nmap с самого начала.

htb и deploy.

1 day, 7 hours назад @ xakep.ru
Компрометация LiteLLM привела к утечке терабайтов учетных данных
Компрометация LiteLLM привела к утечке терабайтов учетных данных Компрометация LiteLLM привела к утечке терабайтов учетных данных

Всего за 40 минут, пока вредоносные версии популярного инструмента распространялись через PyPI, атакующие успели похитить секреты из 434 000 CI/CD-пайплайнов.

Встроенный в него инфостилер собирал секреты прямо из памяти CI-раннеров (токены GitHub и npm, SSH-ключи, облачные учетные данные и другую чувствительную информацию).

Встроенная в LiteLLM малварь похищала секреты из окружения и памяти CI/CD-раннеров зараженных систем и отправляла собранные данные атакующим.

Однако исследователь решил проверить учетные данные и обнаружил, что почти все якобы измененные секреты по-прежнему работают.

Теперь исследователи рекомендуют всем, кто использовал LiteLLM 1.82.7 и 1.82.8, считать скомпрометированн…

1 day, 8 hours назад @ xakep.ru
Криптокошелек SafePal пострадал от утечки данных 40000 клиентов
Криптокошелек SafePal пострадал от утечки данных 40000 клиентов Криптокошелек SafePal пострадал от утечки данных 40000 клиентов

Представители SafePal, производителя аппаратных криптовалютных кошельков, объявили об инциденте безопасности, из-за которого в открытом доступе оказались личные данные почти 40 тысяч клиентов.

В открытый доступ попали имена, физические адреса и контактные данные покупателей, что повышает риск фишинга и попыток злоумышленников выдать себя за представителей компании.

В SafePal сообщили в воскресенье, что обнаружили «ошибку авторизации» в плагине для отслеживания заказов клиентов.

Кроме того, в SafePal объявили, что впредь будут хранить персональные данные клиентов в системе обработки заказов не дольше 90 дней с момента получения.

Клиенты могут проверить с помощью специального инструмента на с…

1 day, 9 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 3 часа назад
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session.

The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced during testing.

The research names Copilot Personal, the consumer assistant hosted at copilot.microsoft.com, and does not state that the same behavior affected Microsoft 365 Copilot.

When the researchers built the URL exactly as described, the parameter Copilot had said no longer worked executed.

The web…

3 часа назад @ thehackernews.com
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

(Affects versions < 3.15.0)(CVSS score: 9.3) - An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MLflow that can allow an attacker who can reach the Tracking Server (mlflow server) to issue HTTP requests to arbitrary internal cloud metadata endpoints and extract sensitive data.

Evidence from our global honeypot telemetry indicates attackers are abusing this vulnerability to target cloud-hosted MLflow systems in an attempt to extract credentials and secrets from well-known internal IP addresses and services."

Organizations running MLflow are recommended to prioritize patching affected, exposed systems, review audit logs for signs of compromise, and check whether sensitiv…

3 часа назад @ thehackernews.com
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000.

"While cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge."

More than $8 million in payments have been made across 15 Bitcoin wallets attributed to the five data extortion brands during the time period.

In the month of July 2026 alone, a total of 873 claimed ransomware victims were recorded, up from 722 the previous month.

The highest n…

3 часа назад @ thehackernews.com
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files

A one-paragraph warning added to an agent's system prompt reduced spread to near zero across the payloads tested.

The authors call the payloads "mind viruses," and test two classes: ideological payloads that implant a belief or goal, and action payloads that compel a concrete behavior.

Agents that wrote the payload into SOUL.md accounted for 88% of propagation attempts and infected the next agent 55% of the time.

The Hacker News confirmed on August 18, 2026, that both the repository and the transcript archive at mindvirusdata.live are publicly accessible.

"Every model we tested abstractly understands that information sources have their own incentives, and that consensus is not necessarily e…

8 часов назад @ thehackernews.com
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Interactive operator access routes through WebRTC DataChannels relayed by Microsoft Teams TURN servers."

The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and establish persistence on the host.

"It runs over either a direct TLS/WebSocket connection to the attacker's server or through the Teams TURN WebRTC relay," Ontinue said.

In June 2026, Broadcom-owned Symantec and Carbon Black detailed DragonForce ransomware's use of a Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure.

TWI…

8 часов назад @ thehackernews.com
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

The complete list of packages published as part of the campaign is below -ubnulerubnlderri18nrreakerrakierorakwjoxnise18nioe18nie18uiai8ni1l8ni18omactivesupmportbrumdlerbrundlef"This new malware harvests browser credentials, cryptocurrency wallets, seed phrases, and Telegram data," security researcher Paul McCarty said.

"All of the malicious RubyGems packages appear to be typosquats of popular Ruby dependencies, but rather than the clever SEO-fueled typosquats we've seen from other threat actors (e.g., events-channel imitating the popular Node.js events module), they're all clumsy typos."

"The name points at that specific move: manufacturing a fake build toolchain to make a malicious instal…

9 часов назад @ thehackernews.com
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco.

Passive DNS shows the same domain pointed at that IP as far back as March 2025, and the server has not moved since.

What sets this campaign apart from prior Salesforce guest access abuse, including the widely reported activity attributed to ShinyHunters, is the range of surfaces it touches.

Salesforce Experience Cloud sites and ServiceNow portals both maintain a persistent guest user that unauthenticated visitors execute as, and that user cannot be deleted, only …

9 часов назад @ thehackernews.com
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers.

The hardware wallet maker said all affected customers were notified individually by email on August 16 from [email protected], with the subject line "[Important] Your SafePal Order Information Has Been Affected."

"This incident did not involve your seed phrase, private keys, wallet password, or other wallet credentials, bank account information, payment card numbers, or government-issued identification numbers," SafePal said.

Under certain conditions, the flaw allowed unauthorized acces…

11 часов назад @ thehackernews.com
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads.

The vulnerability in question relates to CVE-2025-62593 (CVSS score: 9.4), which can result in remote code execution via web browsers like Mozilla Firefox and Apple Safari by means of a DNS rebinding attack.

The project maintainers also noted that the attack can also be extended to attack network-adjacent instances of Ray by leveraging the browser a…

14 часов назад @ thehackernews.com
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4.

"GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive," GitLab said.

GitLab has not named the GraphQL directive involved or specified what the conditions necessary for exploitation are.

Unlike the critical flaw, it requires user interaction to work.

The disclosure follows a July 2026 report in which researchers published working exploit code for a separate GitLab flaw affecting self-managed servers.

23 часа назад @ thehackernews.com
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

It also checked github.event.pull_request.user.login even though the event was an issue, meaning the referenced pull request property did not exist.

Snowflake merged a fix that day in pull request #1402, replacing the direct GitHub expression expansion with environment variables that are passed to jq as arguments.

The vulnerable workflow had reached the default branch five days earlier, on June 18, when pull request #1218 was merged.

Wiz described the flaw as resulting from a GitHub Copilot Autofix change, although the underlying GitHub history does not establish Copilot as the author of the vulnerable jira_issue.yml code.

The commit history therefore confirms Copilot participation in pull …

1 day, 2 hours назад @ thehackernews.com
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

That said, a key prerequisite for successful exploitation is that the sites must have a form containing both a File Upload field and a Select field.

Per the WordPress security company, the flaw is a case of arbitrary file upload that resides in the "handle_file_upload()" function, stemming from a lack of sufficient file type validation in user-supplied input.

As a result, an unauthenticated attacker can exploit the loophole to upload any file, including a specially crafted PHP file, to a vulnerable site by submitting a form and achieving remote code execution.

Another aspect worth noting here is that, in the default configuration, files are uploaded to a directory protected by an .htaccess …

1 day, 2 hours назад @ thehackernews.com
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic
Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.

"The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction," Kaspersky said in an analysis.

"The same DNS infrastructure can validate and replace the relay deployment ID, allowing the operator to rotate the Google channel."

When the Google mode is selected, the module sends requests to the Apps Script deployment, which then forwards them to the threat actor-controlled backend.

"By abusing legitim…

1 day, 3 hours назад @ thehackernews.com
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

OpenAI Rolls Out Computer History in ChatGPT — OpenAI replaced Chronicle, which builds memories from screen captures to make ChatGPT and Codex more aware of context, with Computer History.

"Computer History turns your activity across apps and websites into memories and a timeline that ChatGPT and Codex can reference," OpenAI said.

"Computer History records interaction events and does not capture your screen or audio," OpenAI said.

— OpenAI replaced Chronicle, which builds memories from screen captures to make ChatGPT and Codex more aware of context, with Computer History.

"Computer History turns your activity across apps and websites into memories and a timeline that ChatGPT and Codex can r…

1 day, 7 hours назад @ thehackernews.com
How MCP Servers Can Expose Enterprise Secrets
How MCP Servers Can Expose Enterprise Secrets How MCP Servers Can Expose Enterprise Secrets

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running.

With the MCP server serving as the middleman, this is where the greatest risk lies because, to act on a system, an MCP server requires that system’s credentials.

Ways MCP servers may expose secretsThe convenience of MCP comes with a catch: The same server that allows an AI agent to do meaningful work is also a hub for credentials.

Here are some of the most common ways secrets can end up exposed in MCP servers.

Instead of secrets sprawl across servers, AI agents retrieve what they need from one governed so…

1 day, 8 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 1 day, 11 hours назад
How QR-code phishing can slip past corporate security measures
How QR-code phishing can slip past corporate security measures How QR-code phishing can slip past corporate security measures

So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years.

Most importantly, they take the victim from a relatively well-protected corporate environment to a potentially unmanaged mobile device, thus bypassing business-grade security.

Malicious QR codes are frequently embedded in alerts urging users to secure their account, or authenticate to confirm their details.

Encourage employees to avoid scanning QR codes in unsolicited emails and report anything suspicious.

Next, consider technical controls, including email security from a reputable vendor to minimize the risk of quishing emails ending up in users’…

1 day, 11 hours назад @ welivesecurity.com
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?

The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months.

It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes.

A keynote at Black Hat USA 2026 detailed research by associate professor Yan Shoshitaishvili and his undergraduate students at Arizona State University on the expanding use of AI models for vulnerability discovery.

The team then trained the GPTs using the properties of previously known vulnerabilities and discovered approximately 1,000 vulnerabilities.

If this logic prevails, we may reach the cal…

5 days, 6 hours назад @ welivesecurity.com
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility

Hugging Face disclosed that it had been attacked by AI; OpenAI came clean and declared that it was two of their AI models that had caused the breach.

A very late addition to the Black Hat agenda was a presentation by OpenAI’s team providing the details of the Hugging Face incident as they saw it and, importantly, the timeline.

The agents concluded that their task set could be completed by breaking out their sandbox and accessing external (Hugging Face) systems.

The target was Hugging Face: this is where the agents wanted to get, and they did.

On July 16th, Hugging Face disclosed an incident in which swarms of autonomous AI agents had breached its infrastructure.

5 days, 11 hours назад @ welivesecurity.com
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Black Hat USA 2026: AI is racing ahead of cybersecurity controls Black Hat USA 2026: AI is racing ahead of cybersecurity controls

The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials.

The second part of the opening keynote included Nick Andersen, Acting Director, CISA; Katherine Sutton, Assistant Secretary of War for Cyber Policy; and Brett Leatherman Assistant Director, Cyber Division, FBI.

I do agree with the ruthless approach, but without some form of regulation the boundaries on the use of AI remain blurred.

The Assistant Secretary of War for Cyber Policy made a fabulous analogy when pressed on the struggles regarding resourcing in the cybersecurity industry: you don’t want a pediatrician performing heart surgery.

We talk about autonomous AI at…

6 days, 7 hours назад @ welivesecurity.com
Are AI tutors safe for your kids?
Are AI tutors safe for your kids? Are AI tutors safe for your kids?

The AI tutor market is growing fastThe market for AI tutoring tools is booming.

Today, you can find various types of AI tutor tools to buy and use.

This happens when AI tools are tricked into ignoring their safety guardrails and display untrusted content.

If you’re keen to get your kids in front of an AI tool to help with private tutoring, first understand the difference between a simple co-pilot and a dedicated ITS.

So if you’re keen to try AI tutors, be sure to stay updated on what’s available out there.

1 week, 1 day назад @ welivesecurity.com
This month in security with Tony Anscombe – July 2026 edition
This month in security with Tony Anscombe – July 2026 edition This month in security with Tony Anscombe – July 2026 edition

Researchers at Sysdig have documented what they assess to be the first case of an end-to-end ransomware operation executed by an agentic threat actor.

What can organizations do to stop phantom squatting from harming their brands, and what other lessons do these incidents hold for defenders?

Watch Tony's video to find out and be sure to check out the June 2026 edition of his monthly security news roundup for more insights.

Before you go, learn about the first AI-powered ransomware, named PromptLock and discovered by ESET researchers last year.

To learn more about cutting-edge AI defense layers, read the AI at ESET white paper.

2 weeks, 4 days назад @ welivesecurity.com
Beyond the screenshot: Why you should verify what you see
Beyond the screenshot: Why you should verify what you see Beyond the screenshot: Why you should verify what you see

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuineSomeone sends you a screenshot showing that a payment has gone through.

Why screenshot aren’t proof on their ownA screenshot is ultimately just an image of what appeared on a screen.

Reassured, you send the item off, only to find out the screenshot was a fake and you’re not getting your money.

You receive a password reset code, then get a text message (maybe impersonating a friend) asking you to screenshot and send it.

This screenshot is fake (source: Reddit)Challenges for businessesFrom a business perspective, internal and customer-facing teams are often provided with sc…

2 weeks, 5 days назад @ welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

1 month назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

1 month, 1 week назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

1 month, 2 weeks назад @ welivesecurity.com
This month in security with Tony Anscombe – June 2026 edition
This month in security with Tony Anscombe – June 2026 edition This month in security with Tony Anscombe – June 2026 edition

It's that time of month when ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses.

What lessons does the new CISA policy hold for organizations outside the agency's direct remit?

What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems?

How can you stay safe from imposter fraud, and could the social media bans for children work?

Learn more from Tony's video and be sure to check out the May 2026 edition of Tony's monthly security news roundup for more insights.

1 month, 2 weeks назад @ welivesecurity.com
Inside the inbox: Why cybercriminals want to break into your email account
Inside the inbox: Why cybercriminals want to break into your email account Inside the inbox: Why cybercriminals want to break into your email account

With access to your email account, they can reset your passwords across multiple other accounts – perhaps intercepting one-time passcodes sent by your bank, social media, cloud storage or other online provider.

That could lay the groundwork for a convincing phishing email designed to impersonate a trusted organization you interact with.

A phishing attack on your corporate email account is often the first stage in a bigger data breach, extortion/ransomware or espionage attack.

They’re also using more sophisticated tools to improve the success rates of email phishing campaigns.

In this instance the scammers reportedly hijacked the email account of a high-level executive, before impersonating …

1 month, 2 weeks назад @ welivesecurity.com
SMB cyber readiness: the road to resilience starts here
SMB cyber readiness: the road to resilience starts here SMB cyber readiness: the road to resilience starts here

For these businesses, cyber resilience should be the direction of travel – that is, the ability to continue operating and recover even during a serious incident.

Cyber readiness is about putting in place the processes and controls to prevent, detect and respond to threats.

So, should confidence in cyber resilience posture be so high, especially if organizations are still getting hit multiple times?

The truth is that there’s no end state for cyber readiness or resilience.

If it’s serious about improving the cyber readiness of small businesses, the vendor community should step up.

1 month, 3 weeks назад @ welivesecurity.com
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Key points of this blogpost: Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.

Continued data exfiltration and a new allianceThroughout 2025, Gamaredon stayed highly active and remained focused solely on Ukraine.

Notably, we uncovered that in early 2025, Gamaredon collaborated with Turla, another Russia-aligned threat actor also linked to the FSB; we documented our findings in our blogpost Gamaredon X Turla collab.

Figure 1 shows a chart of unique samples of HTA downloaders delivered per month in Gamaredon spearphishing campaigns.

Compared to 2024, we also saw a shift in how Gamaredon used these dead drops.

1 month, 3 weeks назад @ welivesecurity.com
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET takes part in Operation Endgame to disrupt Amadey and Stealc

Key points of this blogpost: ESET took part in the coordinated, global Operation Endgame to disrupt Amadey and Stealc.

Our automated systems have been dissecting Amadey and Stealc samples and identifying the fields most relevant for large-scale tracking.

The largest Amadey botnet clusterOne cluster stands out as the largest, and it contributed nearly 34% of all processed Amadey samples.

Stealc affiliate clustering based on ESET telemetryConclusionFor global disruption operations such as Operation Endgame against Amadey and Stealc, long-term automated tracking of malware is necessary.

2026‑04‑09 Stealc C&C server.

1 month, 3 weeks назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 7 часов назад
NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation
NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation

NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic.

These outbound attacks have already caused costly service outages, reputational damage and customer loss, and damage to peering relationships risking a large increase in transit costs at service providers around the world.

Extends these capabilities to outbound traffic, combining enhanced, customized detection with comprehensive threat intelligence tailored for each ISP.

Uses NETSCOUT’s proprietary AI/ML-powered DDoS detection to analyze massive volumes of outbound internet traffic to uncover attacks designed to hide…

7 часов назад @ helpnetsecurity.com
Download: 2026 Credential Risk Report
Download: 2026 Credential Risk Report Download: 2026 Credential Risk Report

85% of cybersecurity professionals consider compromised credentials a primary attack path—yet only 19% continuously monitor active credentials and automatically remediate exposure.

The 2026 Credential Risk Report examines where credential security programs fall short and what it takes to move toward Continuous Credential Defense.

Download the report to learn:

8 часов назад @ resources.enzoic.com
Google’s $10,000 refund test shows why AI agents need zero trust
Google’s $10,000 refund test shows why AI agents need zero trust Google’s $10,000 refund test shows why AI agents need zero trust

Security outside the AI modelGoogle’s design treats the model as a component that could be tricked or jailbroken.

A system prompt telling the agent never to refund more than an order’s value does not provide a hard security boundary.

Prompt injection can bypass such instructions, while prompt tuning and model updates can change how the model responds.

A request to ignore safety instructions and issue a $10,000 refund, for example, can be blocked before the action occurs.

Developers can also run a browser-based Live Attack Playground and use Google’s ADK documentation to begin building agent tooling and sessions.

9 часов назад @ helpnetsecurity.com
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication.

The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.

The more severe vulnerability, CVE-2026-19478 (CVSS 9.4), involves code injection through a GraphQL directive and can be exploited remotely by an unauthenticated attacker without user interaction.

Successful exploitation could allow an attacker to modify or delete public projects and user data.

Improper request validation could allow an unauthenticated attacker t…

9 часов назад @ helpnetsecurity.com
OpenAI tightens defenses after AI agents breach research environment
OpenAI tightens defenses after AI agents breach research environment OpenAI tightens defenses after AI agents breach research environment

Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements.

OpenAI’s security strategyThe company is strengthening its security measures and using AI to improve its defenses, focusing on four main areas.

AI models search OpenAI’s systems for potential attack paths, including vulnerabilities, configuration errors, excessive permissions and unintended connections between systems.

OpenAI says organizations should begin integrating AI into security operations, starting with their high…

11 часов назад @ helpnetsecurity.com
Hacker claims millions of records stolen from corporate Azure tenants
Hacker claims millions of records stolen from corporate Azure tenants Hacker claims millions of records stolen from corporate Azure tenants

A threat actor known as “TheHatman” claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including McDonald’s, Vodafone, Kyndryl, and Tata Consultancy Services (TCS), according to Hudson Rock.

Over the past week, the threat actor has posted a string of large internal employee directories on cybercrime forums, claiming that each was pulled directly from the victim organization’s Azure tenant.

IHG, Kyndryl, Gap, Hexaware, and Wyndham round out the rest, with counts ranging from several thousand to over 170,000 records apiece.

“While the data is highly likely authentic, it is not conclusive how this campaign is being carried out,” H…

11 часов назад @ helpnetsecurity.com
Synthesized builds Test Data Agent to validate AI agents with production-like data
Synthesized builds Test Data Agent to validate AI agents with production-like data Synthesized builds Test Data Agent to validate AI agents with production-like data

Synthesized has announced its Test Data Agent, a new agentic infrastructure capability being developed to create and provision the realistic data, business context, and system states enterprises need to validate AI agents safely before production deployment.

Synthesized is developing the Test Data Agent as the production-faithful validation layer for enterprise AI agents.

The Test Data Agent lets teams:Identify the business entities, records, relationships, and system states required for a test.

The Test Data Agent therefore complements existing agent platforms, testing systems, observability tools and model-optimization pipelines.

That is the infrastructure Synthesized is building.”An open…

13 часов назад @ helpnetsecurity.com
Google’s open-source HEIR lets AI work with data it can’t see
Google’s open-source HEIR lets AI work with data it can’t see Google’s open-source HEIR lets AI work with data it can’t see

Google’s researchers and engineers developed the Homomorphic Encryption Intermediate Representation (HEIR) compiler project, an open-source compiler toolchain and development platform for homomorphic encryption.

Homomorphic encryption allows data to be processed while it remains encrypted, protecting sensitive information during computation.

FHE development and optimizationHEIR has grown into a platform for homomorphic encryption development and research since Google announced its plans for the project in 2023.

Homomorphic encryption in practiceHEIR demonstrates the use of homomorphic encryption in private recommendations, credit card fraud detection, network intrusion detection, and hotwor…

14 часов назад @ helpnetsecurity.com
A hollowed out data layer is making CISOs fly blind into AI attacks
A hollowed out data layer is making CISOs fly blind into AI attacks A hollowed out data layer is making CISOs fly blind into AI attacks

However, what most CISOs have not yet reckoned with is that the AI defenders they are about to deploy will inherit a data foundation that two years of ingestion cost pressure has quietly hollowed out.

The result is a security industry heading into an AI era with less visibility than it had five years ago.

SIEM ingestion pricing had become unsustainable, and teams were responding to a real cost problem.

AI defenders running fast against AI attackers, on a data layer no one has proven is intact.

The CISOs who close that gap before their AI defenders are deployed will have a fundamentally different security posture than the ones who don’t.

15 часов назад @ helpnetsecurity.com
Attackers turn to AI for help identifying files worth stealing
Attackers turn to AI for help identifying files worth stealing Attackers turn to AI for help identifying files worth stealing

Across the cases, attackers used AI to create scripts and exploitation tools, identify high-value business information, perform IT and DevOps tasks, and generate and refine commands during active intrusions.

Ransomware operator uses Claude CodeThe first case involved a suspected ransomware operator who used Claude Code during intrusions into six organizations in late June 2026.

The victims included an Australian energy utility and companies in financial services, food services, manufacturing, IT services, property management and distribution across several countries.

When it found accessible files or directory listings, it downloaded the material and searched it for credentials associated w…

16 часов назад @ helpnetsecurity.com
Cybersecurity jobs available right now: August 18, 2026
Cybersecurity jobs available right now: August 18, 2026 Cybersecurity jobs available right now: August 18, 2026

Cybersecurity AnalystSchneider Electric | India | Hybrid – View job detailsAs a Cybersecurity Analyst, you will monitor, triage, and investigate security alerts across SIEM, network, and OT/ICS security platforms in a 24×7 SOC environment.

Cybersecurity ArchitectL’Oréal | France | On-site – View job detailsAs a Cybersecurity Architect, you will design and implement secure enterprise architectures, services, and reusable security solutions.

Get weekly updates on new cybersecurity job openings.

Cybersecurity EngineerGovCIO | USA | On-site – View job detailsAs a Cybersecurity Engineer, you will support the RMF process and ATO readiness by developing and maintaining SSPs, SARs, POA&Ms, and eMAS…

16 часов назад @ helpnetsecurity.com
France’s tax authority admits hackers made off with data on 678,000 individuals
France’s tax authority admits hackers made off with data on 678,000 individuals France’s tax authority admits hackers made off with data on 678,000 individuals

France’s tax authority has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems, saying the intrusion exposed data on 678,000 individuals and professionals.

And as always, no mention from France about this incident.”They said they gained access using login credentials and an MFA bypass technique.

“Upon detecting these intrusions, the French Public Finances Directorate (DGFiP) immediately suspended access to all accounts used in the identified incidents.

DGFiP says the online tax portals used by individuals and businesses were not compromised, and neither were their usernames or passwords.

The agency has also notified the CNIL, France’…

1 day, 6 hours назад @ helpnetsecurity.com
Fortinet expands AI security portfolio with Virtue AI acquisition
Fortinet expands AI security portfolio with Virtue AI acquisition Fortinet expands AI security portfolio with Virtue AI acquisition

Fortinet has acquired Virtue AI, strengthening its broader Security for AI strategy and its vision for securing the agentic enterprise.

The acquisition builds on Fortinet’s existing AI security portfolio, which includes the FortiGate Hyperscale Firewall.

As organizations deploy AI applications and autonomous agents, their attack surface expands beyond networks, users, endpoints, applications, and cloud workloads.

Customers already rely on the Fortinet AI-native Security Fabric for integrated protection across networks, endpoints, clouds, applications, and AI deployments.

This acquisition complements FortiAIGate and further strengthens Fortinet’s AI runtime security capabilities with Virtue …

1 day, 7 hours назад @ helpnetsecurity.com
Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer
Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns.

The vulnerability, tracked as CVE-2026-65400, , let attackers authenticate to macOS Screen Sharing without valid login credentials.

Apple fixed the issue with updates to macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1), and advised its macOS users to upgrade their systems.

Users who can’t patch immediately can disable Screen Sharing manually, by opening System Settings, selecting General, then Sharing, and switching the Screen Sharing toggle off.

NCSC hasn’t share…

1 day, 8 hours назад @ helpnetsecurity.com
SafePal breach affects 39,798 customers, data allegedly for sale
SafePal breach affects 39,798 customers, data allegedly for sale SafePal breach affects 39,798 customers, data allegedly for sale

Cryptocurrency wallet maker SafePal disclosed a data breach that exposed order information for 39,798 customers, including names, email addresses, shipping addresses, phone numbers and purchase details.

Under certain conditions, the flaw let one customer view another customer’s order information.

Although there is no confirmed connection between the data exposure and the phishing attempt, the timing and the information available to the impersonator overlap with the data SafePal says was exposed.

“You should not need to move your assets solely because your order information was affected.

Threat actor claims to have data from SafePal breachAccording to DarkWebInformer, a threat actor is selli…

1 day, 10 hours назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 10 часов назад
LLMs and Contextual Integrity
LLMs and Contextual Integrity LLMs and Contextual Integrity

LLMs and Contextual IntegrityI have been thinking a lot about AI and integrity.

Part of that is contextual integrity.

“CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“:Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance.

We present CIMemories, a benchmark for evaluating whether LLMs appropriately control information flow from memory based on task context.

We then extend this approach by developing a reinforcement learning (RL) framework that further instills in models the reasoning necessary to achieve CI.

10 часов назад @ schneier.com
Hacking Public Wi-Fi DNS to Steal Credentials
Hacking Public Wi-Fi DNS to Steal Credentials Hacking Public Wi-Fi DNS to Steal Credentials

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 day, 9 hours назад @ schneier.com
Friday Squid Blogging: Searching for the Colossal Squid
Friday Squid Blogging: Searching for the Colossal Squid Friday Squid Blogging: Searching for the Colossal Squid

Friday Squid Blogging: Searching for the Colossal SquidFascinating video about searching for life undersea.

The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral.

That, plus bait to attract sea creatures, is teaching us a lot about what’s going on down there.

Lots of footage of giant squid, and speculation about the colossal squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

3 days, 23 hours назад @ schneier.com
Upcoming Speaking Engagements
Upcoming Speaking Engagements Upcoming Speaking Engagements

I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026, at 5 PM ET.

The conference runs September 22–24, 2026; my talk is on Wednesday, September 23.

I’m speaking at CanSecWest 2026 in Vancouver, Canada.

The conference runs September 30–October 1, 2026; the time of my talk is TBD.

The event runs October 21–23, 2026, and my talk is on Wednesday, October 21.

4 days, 4 hours назад @ schneier.com
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them

There are even questions about whether the leading AI labs will ever be sustainably profitable.

The economics of the big AI labs hardly guarantee a booming return on investment.

Frontier AI models are both expensive to train and depreciate within months, when a newer model appears.

Other countries, including Switzerland, Spain and Singapore, are already operating public AI labs.

They also have national supercomputing centers already providing public access for running AI models for general use, as do Germany and Australia.

4 days, 9 hours назад @ schneier.com
Separating AI’s Technological Problems from Its Capitalism Problems
Separating AI’s Technological Problems from Its Capitalism Problems Separating AI’s Technological Problems from Its Capitalism Problems

Separating AI’s Technological Problems from Its Capitalism ProblemsThis essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press.

That AIs can lack context, mix up facts, or fall for stupid tricks are all technological problems.

Major AI models still act far more sycophantic than humans, telling people what they want to hear even when untrue or not in their best interests.

Popular AI models tend to answer questions confidently even when they lack training, knowledge, or evidence to back their claims.

It’s easy to conflate technology problems with capitalism problems.

5 days, 9 hours назад @ schneier.com
Prompt Injections for Defense
Prompt Injections for Defense Prompt Injections for Defense

This seems to work:Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents.

The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to prevent it from taking harmful actions.

The LLM responds by shutting down.

Once the LLM encounters these forbidden commands, it no longer follows its existing commands.

The researchers have named the technique context bombing.

6 days, 10 hours назад @ schneier.com
AI Genie in the Wild
AI Genie in the Wild AI Genie in the Wild

AI Genie in the WildWhen I give talks about AI genies, I use this sort of example as a hypothetical.

Someone named Andrew tasked OpenClaw to book gym classes for him.

Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible.

Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.

The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities.

1 week назад @ schneier.com
AI for Military Support
AI for Military Support AI for Military Support

Interesting empirical research: “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI.”Abstract: How is AI transforming decision-making in modern conflict?

This study provides a unique empirical window into that question by deploying a high-fidelity replica of an AI decision-support system (DSS) used in military targeting.

Contrary to widespread fears of automation bias, we find strong evidence of algorithmic aversion, especially in scenarios involving high collateral damage.

Yet we also show that integrating “explainable AI” features reduces algorithmic aversion and promotes more thoughtful evaluations of algorithmic recommendations.

These findings challenge prev…

1 week назад @ schneier.com
Python Now Has a Post-Quantum Encryption Library
Python Now Has a Post-Quantum Encryption Library Python Now Has a Post-Quantum Encryption Library

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 week, 1 day назад @ schneier.com
Friday Squid Blogging: Arctic Bobtail Squid Video
Friday Squid Blogging: Arctic Bobtail Squid Video Friday Squid Blogging: Arctic Bobtail Squid Video

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 week, 3 days назад @ schneier.com
ICE Is Buying Access to Credit Card Records
ICE Is Buying Access to Credit Card Records ICE Is Buying Access to Credit Card Records

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 week, 4 days назад @ schneier.com
Adversarial Clothing Designed to Fool Facial Recognition Systems
Adversarial Clothing Designed to Fool Facial Recognition Systems Adversarial Clothing Designed to Fool Facial Recognition Systems

There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems.

It’s a cool idea, but I worry that it’s mostly security theater:“Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,” he said.

Bell, however, said “none of these products are tried and tested, and a lot of these surveillance technologies can deal with a little resistance … [but] even if the designs don’t necessarily work perfectly, fashion is also a visible sign of resistance.

“This is consumers collectively coming together to make a visible statement.”

1 week, 5 days назад @ schneier.com
Vulnerabilities in Car Anti-Theft Device
Vulnerabilities in Car Anti-Theft Device Vulnerabilities in Car Anti-Theft Device

This is disturbing:…a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.

1 week, 6 days назад @ schneier.com
Iran Cyberattacks Against Minnesota Water Systems
Iran Cyberattacks Against Minnesota Water Systems Iran Cyberattacks Against Minnesota Water Systems

Iran Cyberattacks Against Minnesota Water SystemsAttribution is preliminary, and so far it seems no real damage.

And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself.

“I would blame it on Minnesota and the governor, the corrupt governor of Minnesota.

They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky.

Iran’s got bigger problems than worrying about Minnesota.”No word on whether he believes the other six states have hacked themselves as well.

2 weeks назад @ schneier.com
Krebs On Security
последний пост 4 days, 9 hours назад
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

4 days, 9 hours назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

6 days, 23 hours назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

1 week, 5 days назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

2 weeks, 5 days назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

3 weeks, 6 days назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

1 month назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

1 month назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

1 month, 1 week назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

1 month, 2 weeks назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

1 month, 3 weeks назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

2 months назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

2 months, 1 week назад @ krebsonsecurity.com
A Record-Breaking Patch Tuesday for June 2026
A Record-Breaking Patch Tuesday for June 2026 A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.

“Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said.

Microsoft received heavily blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher.

While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barne…

2 months, 1 week назад @ krebsonsecurity.com
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

On May 31, word began to spread on several Telegram instant message channels that Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow.

Meta has not responded to requests for comment on the video’s claims, but the company reportedly did acknowledge the dormant Instagram account for the Obama White House was briefly compromised.

Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership.

Just like human customer support employees can be social engineered into providing unauthorized access to someone’s a…

2 months, 2 weeks назад @ krebsonsecurity.com
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

But as KrebsOnSecurity observed in September 2025, those sanctions failed to target Stark’s remaining connection to the Internet — an Internet service provider based in the Netherlands called MIRhosting.

MIRhosting is operated by Andrey Nesterenko, a 39-year-old Russian native who runs the business out of the Netherlands.

And as our September 2025 report showed, WorkTitans was controlled by Nesterenko and a 57-year-old from Amsterdam named Youssef Zinad.

On top of that, WorkTitans was getting connectivity to the larger Internet solely through MIRhosting, where Zinad had worked previously.

“The transition to the.hosting was not intended to evade sanctions,” Nesterenko wrote.

2 months, 3 weeks назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 1 day, 6 hours назад
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras

He wrapped a 2009 Toyota Yaris in one of his newest patterns and drove it past a live Flock camera.

So, how does the vehicle avoid detection by the camera's software?

The system has now been tested against 11 open-source detection algorithms, including the software behind Flock licence plate readers, Axon body-worn cameras, and cameras running Clearview AI's facial recognition system.

One issue is that Flock cameras can be inaccurate, with innocent drivers finding themselves pulled over at gunpoint following incorrect plate matches.

Whether covering a car's bodywork in a printed pattern designed to fool surveillance camera software might itself become an offence remains to be seen.

1 day, 6 hours назад @ bitdefender.com
Smashing Security podcast #480: This is the AI service you should never sign up to
Smashing Security podcast #480: This is the AI service you should never sign up to Smashing Security podcast #480: This is the AI service you should never sign up to

Well, it has been a long time, so I'm going to hold you very responsible for this, Graham.

I'm going to set myself up on another server and charge less, and that will be better for humanity.

I mean, if I'm going to look up a phishing kit, is Greatness going to be a great SEO search term?

I want to recommend 2 apps: Tailscale and RustDesk, which I don't think I've spoken about previously on the podcast.

My pick of the week is, I know you're into your games and you're quite the intelligent fellow.

5 days, 21 hours назад @ grahamcluley.com
Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres
Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres

I'm sure you remember "glassholes" - the delightful term coined back in 2013 when Google Glass wearers were being turned away from restaurants and mocked mercilessly online.

Meta's Ray-Ban smart glasses have been a genuine commercial success.

The problem is - and it's a rather significant one - that these glasses look just like ordinary spectacles or sunglasses.

Soho House, the global private members' club chain, meanwhile has said that its ban on filming on the premises covers Meta smart glasses.

The bouncer won't confiscate your pint, but they might confiscate your smart glasses.

1 week, 1 day назад @ bitdefender.com
Beware cut-price AI services that read your every word
Beware cut-price AI services that read your every word

f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.

1 week, 4 days назад @ fortra.com
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits

According to a report in the Financial Times, Apple has found itself facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely hallucinated bug reports.

Unlike traditional spam, AI-generated bug reports include code which may be syntactically correct, references to genuine API calls, and plausible-sounding technical explanations of what is occurring.

But the hallucinated bug report may only have taken a few seconds for an amateur to generate and submit.

Previously, without the assistance of AI, Bynario had filed only 13 bug reports across 2025 and early 2026.

Apple is not the only company trying to deal with a deluge of au…

1 week, 5 days назад @ bitdefender.com
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency

How a fake police officer nearly stole Graham's cryptocurrency with Graham Cluley and special guest Danny Palmer.

I said, without being big-headed, it is possible he knows me, but I don't know him.

I don't think my hotels tend to ask me to install something on my computer when I get there.

We had internet, but it was really, really restricted.

And it's really, really good.

1 week, 5 days назад @ grahamcluley.com
Fake IRS letters target cryptocurrency holders
Fake IRS letters target cryptocurrency holders Fake IRS letters target cryptocurrency holders

As Coinbase's security team explains, the letters urge recipients to scan a QR code and enrol in a "Digital Asset Compliance Portal" before time runs out.

Bear in mind that the criminals could easily vary these details from letter to letter.

The scam site then asks victims to estimate how much value they have in their cryptocurrency wallets, with ranges up to "$100,000+".

Perhaps a reason why a scam like this can work is that the IRS has been tightening cryptocurrency holders' requirement to report details of their digital assets on their tax returns.

As a result, written communications between the IRS and holders of cryptocurrency have become more frequent.

2 weeks назад @ bitdefender.com
The $5 million threat: AI Is supercharging phishing attacks
The $5 million threat: AI Is supercharging phishing attacks

According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

2 weeks, 4 days назад @ fortra.com
North Korea’s elite hackers turned on their own government – and got caught
North Korea’s elite hackers turned on their own government – and got caught North Korea’s elite hackers turned on their own government – and got caught

For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme.

But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead.

The ringleaders of the group are said to be discharged veterans from a cyber operations unit under North Korea's Reconnaissance and Intelligence General Bureau.

In short, the hackers are accused of building a mini version of the same kind of money-laundering infrastructure North Korea depl…

2 weeks, 5 days назад @ bitdefender.com
Smashing Security podcast #478: This job interview could destroy your company
Smashing Security podcast #478: This job interview could destroy your company Smashing Security podcast #478: This job interview could destroy your company

Smashing Security, Episode 478: This Job Interview Could Destroy Your Company, with Graham Cluley and special guest Paul Ducklin.

And all the time you're going through this process, bad news, they really were recording video of you.

Obviously, you can understand that CAR want to know, does your car actually have one of these in all likelihood?

And give it to them and then they tell you whether they think you're at risk.

I don't know.

2 weeks, 5 days назад @ grahamcluley.com
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know

The AI models involved were OpenAI's GPT-5.6 Sol and a more capable, as-yet-unreleased model.

The intention of OpenAI's researchers was to get a clear picture of what the AI models were capable of achieving if not constrained.

American AI safety guardrails forced a US company to turn to a Chinese AI model for help.

Hugging Face's CEO Clément Delangue is quoted in OpenAI's blog post, calling on the AI industry to work more collaboratively.

It is clear that advanced AI models are remarkably capable of discovering and exploiting ways to attack real-world systems.

3 weeks, 5 days назад @ bitdefender.com
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

How 14 orders of Chicken McNuggets helped nail a suspected Russian hacker with Graham Cluley and special guest James Ball.

I had a vindaloo, Graham Cluley, and I don't think it ever touched capsicum.

Yeah, I think you're right.

If you use Suno music, people say, you know, you're killing music.

I don't know much about Shai Hulud.

3 weeks, 5 days назад @ grahamcluley.com
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Ukraine's computer emergency response team, CERT-UA, has warned that Russian hackers are using fake CAPTCHA checks to trick people into compromising their own PCs.

The Kremlin-backed Sandworm hacking group is reportedly leveraging fake CAPTCHA checks on compromised websites that persuade users to execute a PowerShell command on their computers - tricking them into running malicious code.

The latest attacks begin when a user visits a compromised webpage, where they're greeted by a fake CAPTCHA claiming they need to complete an extra step to prove that they are human.

Instead, the fake CAPTCHA instructs the user to copy and paste a PowerShell command into their Windows computer.

They are a pr…

4 weeks назад @ bitdefender.com
Google’s Gemini lets strangers send messages from your locked Android phone
Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini lets strangers send messages from your locked Android phone

Someone gets hold of your locked Android phone and, despite not knowing your security PIN, they can send messages via SMS or WhatsApp pretending to come from you.

It is clear that Google has patched Gemini lock screen issues before, but security researchers keep finding new ways through.

The latest vulnerability is different from the previous similar Gemini-based Android lock screen bypass bugs that have been plaguing the operating system since September 2025.

To do that:Open the Gemini app, tap your profile picture, go to Settings, and select "Gemini on lock screen."

Every new capability Gemini is given at the lock screen is also a new potential attack surface.

1 month назад @ bitdefender.com
Anubis ransomware: what you need to know
Anubis ransomware: what you need to know

The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.

1 month назад @ fortra.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 1 day, 11 hours назад
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fb0df3655ea6f56b2f956c62791963eaServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-17T13:00:21+03:00Config id: 301Faithfully yours, nginx.

1 day, 11 hours назад @ kaspersky.ru
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f2ed509c8db78e5bf9f4b9959cd583f7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-13T17:00:41+03:00Config id: 299Faithfully yours, nginx.

5 days, 7 hours назад @ kaspersky.ru
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: b151dd13b503d39649441ee258a9621fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-11T15:00:20+03:00Config id: 298Faithfully yours, nginx.

1 week назад @ kaspersky.ru
Слепые пятна детектирования: форматы файлов polyglot в рассылках и целевых атаках
Слепые пятна детектирования: форматы файлов polyglot в рассылках и целевых атаках

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 31e2a51c17a679bf608181d1cb4a73dfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-10T19:00:19+03:00Config id: 298Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
Опасные почтовые вложения: какие файлы нельзя открывать | Блог Касперского
Опасные почтовые вложения: какие файлы нельзя открывать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: ba837fe40a3ce1bc1da3dc3d5c38e164Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-07T14:00:17+03:00Config id: 296Faithfully yours, nginx.

1 week, 4 days назад @ kaspersky.ru
Аудиослежка за клавиатурным набором | Блог Касперского
Аудиослежка за клавиатурным набором | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f03ed927ed78af1549df453edbc54069Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-06T17:00:43+03:00Config id: 295Faithfully yours, nginx.

1 week, 5 days назад @ kaspersky.ru
Как сделать, чтобы вашу компанию не взломали автономные агенты
Как сделать, чтобы вашу компанию не взломали автономные агенты

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f997d2a4543951b403d61a86f614b589Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-04T20:00:20+03:00Config id: 293Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
CrashStealer: новый инфостилер для macOS — как он работает и как защититься | Блог Касперского
CrashStealer: новый инфостилер для macOS — как он работает и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64d189df4b1deb932c3c39da09770373Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-03T14:00:09+03:00Config id: 292Faithfully yours, nginx.

2 weeks, 1 day назад @ kaspersky.ru
Почему звонят в трубку и молчат | Блог Касперского
Почему звонят в трубку и молчат | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 87a765bcfffecb3be7b631186de73cdfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-30T14:00:37+03:00Config id: 292Faithfully yours, nginx.

2 weeks, 5 days назад @ kaspersky.ru
ScreenConnect в кибератаках | Блог Касперского
ScreenConnect в кибератаках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 69f66dfe76ff3f53d09e7e879aff2eabServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-29T19:00:33+03:00Config id: 291Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e1896b8624f52547d7aa4a3bebd90c3cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-27T16:00:28+03:00Config id: 291Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 30ce39da164ccbcb4068b4e06c4c1e60Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-24T19:00:11+03:00Config id: 291Faithfully yours, nginx.

3 weeks, 4 days назад @ kaspersky.ru
Инциденты с атаками на ИИ-агентов в бизнесе | Блог Касперского
Инциденты с атаками на ИИ-агентов в бизнесе | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: abb2f672b0aebacf96a83f072ddf5be5Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-23T15:00:29+03:00Config id: 290Faithfully yours, nginx.

3 weeks, 5 days назад @ kaspersky.ru
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 29288682927681f45f4ebe45b92c4f9dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-22T15:00:12+03:00Config id: 290Faithfully yours, nginx.

3 weeks, 6 days назад @ kaspersky.ru
ConsentFix: новая вариация ClickFix
ConsentFix: новая вариация ClickFix

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 92f538b35cc9db0cd8268f0e9c690524Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-21T12:00:10+03:00Config id: 290Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 1 day, 5 hours назад
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

1 day, 5 hours назад @ blogs.cisco.com
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero … Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …

The Power of FedRAMP HighWhile FedRAMP Certified Class C (Moderate) is the standard for many civilian agencies, FedRAMP Certified Class D (High) is designed for systems where a breach could have catastrophic effects.

Cisco Security Cloud for GovernmentCisco Security Cloud for Government is a unified authorization boundary that integrates various Cisco security services, ensuring that organizations can protect their users, devices, and applications regardless of where they reside.

The Cisco Security Cloud for Government ecosystem is designed to meet the rigorous security requirements of the public sector and highly regulated industries.

Cisco Security Cloud Control (SCC)Cisco Security Cloud …

1 week назад @ blogs.cisco.com
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

That’s why we are incredibly proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

Reduced Vendor Risk & Increased Trust: FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

Beyond the governance and compliance benefits, Email Threat Defense continues to deliver advanced protection capabilities that align directly with real-world email threat risks.

Email Threat De…

1 week, 1 day назад @ blogs.cisco.com
Is your SD-WAN ready for AI-powered operations?
Is your SD-WAN ready for AI-powered operations? Is your SD-WAN ready for AI-powered operations?

AI Is Changing the Traffic ModelMuch of the enterprise AI conversation centers on models, GPUs, data platforms, and agents.

Time-sensitive performance: Voice AI, edge AI, and physical AI move latency into live operations.

SD-WAN can help maintain operations by prioritizing critical traffic, steering it across the best available path, and applying consistent policy across locations.

Why AI Traffic is an SD-WAN ProblemSD-WAN sits at the point where application intent meets real network conditions.

1 https://www.aboutamazon.com/news/operations/amazon-million-robots-ai-foundation-modelCommon questions about SD-WAN and AI trafficWhat is AI-generated network traffic?

2 weeks, 1 day назад @ blogs.cisco.com
The Zero Trust Imperative for the Frontier AI Era
The Zero Trust Imperative for the Frontier AI Era The Zero Trust Imperative for the Frontier AI Era

Their recommendations for securing the AI era rely heavily on establishing strict asset inventory and preventing lateral movement—which are, at their core, fundamental Zero Trust principles.

The Three Core Principles of Zero Trust for AIFounded in three core principles, a robust Zero Trust architecture requires us to execute the following phases comprehensively.

Achieving the Architectural VisionThe above may all sound like pipedream, as most organisations struggle with Zero Trust programs and undelivered microsegmentation projects.

Ultimately AI driven platform approach is what makes Zero Trust achievable for the frontier AI era.

This is exactly why achieving a Zero Trust Architecture for …

2 weeks, 4 days назад @ blogs.cisco.com
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes

This provides an opportunity for defenders: if we assume our controls will fail at some point, we can build a much more resilient architecture.

When you assume the current layer will eventually be bypassed, you start designing the next layer proactively instead of reactively.

Defenders need to advance their controls by mapping them to the adversaries’ capabilities then assume that control will fail.

Map your controls to the attack chain.

Call to Action:If you haven’t watched the full video yet, go check it out: Assuming Failure Provides Better Defensive Outcomes (bonus elements around SOC of the Future and business context).

3 weeks, 1 day назад @ blogs.cisco.com
The Journey towards Logically Air-Gapped Deployment
The Journey towards Logically Air-Gapped Deployment The Journey towards Logically Air-Gapped Deployment

Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter.

This “Logically Air-Gapped” governance model reaches its full operational potential through the implementation of “Live Protect.” As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution.

Reference ArchitectureDigital autonomy is thus exercised by shifting network and security control into the operating system kernel.

Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a un…

3 weeks, 4 days назад @ blogs.cisco.com
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall

That is why we are introducing Firewall Migration Manager by Cisco, an enterprise-ready product built for that reality.

What Is Firewall Migration Manager?

Firewall Migration Manager is a dedicated migration application that you run in your own environment.

How Firewall Migration Manager WorksThe migration process follows a clear, guided workflow.

Intelligent, integrated migration: Firewall Migration Manager will also come to Cisco Cloud Control, and AI will play an increasing role in guiding teams before and during migration.

3 weeks, 5 days назад @ blogs.cisco.com
We third-party tested our firewall built for AI-scale. The test tools hit their limit first.
We third-party tested our firewall built for AI-scale. The test tools hit their limit first. We third-party tested our firewall built for AI-scale. The test tools hit their limit first.

In independent testing with NetSecOPEN, the Cisco Secure Firewall 6160 delivered AI-scale inspected throughput beyond what the tools built to measure it could register, all while blocking 100% of tested threats.

These results are specific to Cisco Secure Firewall 6160, but the software capabilities behind Cisco Firewall, including advanced threat protection and high-performance inspection, extend across Cisco Firewall form factors in the cloud, virtually, and on-premises, from campus to data center.

Performance passed the previous benchmark by 5XInspection was turned on, and the test tools built to measure throughput hit their limit before the 6160 firewall did.

In previous NetSecOPEN testi…

1 month назад @ blogs.cisco.com
SharpHound Recon Attack – How AI enhanced the threat hunt
SharpHound Recon Attack – How AI enhanced the threat hunt SharpHound Recon Attack – How AI enhanced the threat hunt

We innovated by giving the Agentic SOC access to Endace’s always-on, full packet capture, and asked the agent to assess a potential SharpHound Recon attack that we had seen while threat hunting.

This blog explores how we built the integrations and how AI helped us with our threat hunt and threat assessment.

Agentic AI Massively Speeds our AnalysisAt this point, we decided to use Agentic AI capabilities to investigate and assess this potential threat.

ConclusionThe Agentic SOC, blending Agentic AI built into Endace’s products with custom agentic tools, is a massive boost to productivity and security.

AcknowledgementsOur thanks go to the Cisco SOC team led by @Jessica Oppenheimer and @Ivan Be…

1 month, 1 week назад @ blogs.cisco.com
Machine Speed, Human Judgement: How AI Changed the SOC in 2026
Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Machine Speed, Human Judgement: How AI Changed the SOC in 2026

Having spent time in the Cisco Live Americas 2026 SOC, one thing became abundantly clear:The way SOCs operate today is fundamentally different from even a few years ago.

Instead of spending time gathering information, analysts could spend more time understanding what the information actually meant.

Just as spreadsheets empowered business users decades ago, AI-assisted coding is beginning to empower security analysts today.

At Cisco Live, AI was already present throughout the workflow:Incident summaries generated automatically within XDR.

And based on what I saw at Cisco Live 2026, that future has already arrived.

1 month, 1 week назад @ blogs.cisco.com
Elevating Expertise in the SOC
Elevating Expertise in the SOC Elevating Expertise in the SOC

The new SOC analysts were great at finding evidence, helped with triage and correlation by the AI agents in the SOC architecture.

With the advancements in Cloud Control, our new SOC Analysts can validate their hypothesis.

They had the ability to investigate the incident and find the root cause found in Splunk Security and Endace.

Instant Attack VerificationIn each Incident, the SOC Analysts is given an AI generated Summary stitching all the relevant logs from all the sources that are related to the objects in question.

Check out the blogs by the engineers who worked inside the SOC at Las Vegas:

1 month, 1 week назад @ blogs.cisco.com
Educate at Event Speed: Cisco Live Security Operations Center
Educate at Event Speed: Cisco Live Security Operations Center Educate at Event Speed: Cisco Live Security Operations Center

At Cisco Live AMER 2026 in Las Vegas, my work with the Cisco Event SOC centered on one outcome that makes these deployments valuable beyond the event itself: Education.

The SOC protects the conference, but it also turns live operations into a learning environment through SOC tours, Cisco Live sessions, training inside the SOC, and conversations in the World of Solutions.

Bringing live SOC lessons into the classroomEducation also happened in the sessions I delivered at Cisco Live.

Cisco Live AMER 2026 reinforced that the SOC is one of the best classrooms we have because it teaches through real operations.

For a deeper look at the model behind these deployments, read the Cisco Event SOCs: A R…

1 month, 1 week назад @ blogs.cisco.com
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

Inside the Cisco Live SOCAt Cisco Live AMER, the Security Operations Center (SOC) is more than a demo environment.

For a broader look at how the Cisco Live SOC operates, read this overview.

Another part was spent in the SOC, working real investigations with XDR, Splunk Enterprise Security, firewall events, DNS telemetry, packet data, and AI assistance.

AI can help a product manager become useful faster in a live SOC.

That is the bar I want us to continue building toward as we build Cisco XDR and Splunk Security.

1 month, 1 week назад @ blogs.cisco.com
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC

As part of the Cisco XDR (Extended Detection and Response) product engineering group, a few of us got exactly that chance.

Every product had a part to play for a network as traffic-heavy as Cisco Live.

(PS : Flaunting the SOC T-shirts was fun)AcknowledgementsA heartfelt thank you to Cisco and the entire SOC team — you are all amazing.

To the Cisco XDR , Splunk , Secure Access , and Secure Firewall engineering teams.

Check out the other blogs from our team at the Cisco Live Americas 2026 SOC at Las Vegas:

1 month, 1 week назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 3 часа назад
Hunting MacSync Stealer infrastructure through behavioral pivots
Hunting MacSync Stealer infrastructure through behavioral pivots Hunting MacSync Stealer infrastructure through behavioral pivots

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

]com Domain Related MacSync Stealer infrastructure identified through behavioral hunting.

3 часа назад @ microsoft.com
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

That’s exactly what Microsoft Defender Experts MDR is built to do.

We are excited to announce that we have been named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise Vendor Assessment (Doc #US54792426, July 2026).

Defender Experts MDR includes it as a core part of the service with Defender Experts Hunting, extending your team with Microsoft experts who continuously look for advanced threats across your environment.

Get startedRead the IDC MarketScape: Worldwide MDR/MXDR for the Enterprise 2026 Vendor Assessment excerpt, and visit the Microsoft Defender Experts MDR webpage to see how expert-led, round-the-clock managed detection and response can extend your team, …

1 week, 1 day назад @ microsoft.com
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations.

Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems.

Recovery chat: Technical architectureThe most distinctive feature of the DeadLock ransomware is its recovery chat system.

‘DeadLock’ ransomware was detected‘DeadLock’ ransomware was preventedMicrosoft Defender for Cloud AppsThe following alert might indicate threat activity associated with this threat.

Indicators of compromiseIndicato…

1 week, 1 day назад @ microsoft.com
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

KuppingerCole’s Leadership Compass: Cloud Native Application Protection Platforms (CNAPP) reflects this shift.

The report describes how CNAPP is evolving from a consolidation of cloud security tools into the security foundation for AI-native enterprises, combining cloud security, AI security posture management, runtime protection, attack path analysis, cloud detection and response, and agentic AI operations into unified platforms.

This complexity exposes the limits of traditional, siloed tools, where cloud posture, workload protection, AI security, and the security operations center (SOC) each live in their own console.

Does it see AI models, agents, and pipelines as part of cloud risk, or …

1 week, 6 days назад @ microsoft.com
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Mitigation and protection guidanceOrganizations can apply the following recommendations to reduce exposure to this and similar macOS ClickFix campaigns:Educate users.

]com Domain ClickFix Webpage filecedarwallet[.]online.

Domain ClickFix Webpage filecopperbasket[.

]sbs Domain ClickFix Webpage filecrimsonsignal[.

]online Domain ClickFix Webpage filemarblegarden[.

1 week, 6 days назад @ microsoft.com
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Mitigation and protection guidanceOrganizations can apply the following recommendations to reduce exposure to this and similar macOS ClickFix campaigns:Educate users.

]com Domain ClickFix Webpage filecedarwallet[.]online.

Domain ClickFix Webpage filecopperbasket[.

]sbs Domain ClickFix Webpage filecrimsonsignal[.

]online Domain ClickFix Webpage filemarblegarden[.

1 week, 6 days назад @ microsoft.com
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
ChainDrop supply chain compromise: Anatomy of a self-propagating worm ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Uses GitHub credentials to inject files into Claude and Visual Studio Code configurations across repository branches for persistence.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, Microsoft Defender for Containers, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelli…

1 week, 6 days назад @ microsoft.com
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
ChainDrop supply chain compromise: Anatomy of a self-propagating worm ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Uses GitHub credentials to inject files into Claude and Visual Studio Code configurations across repository branches for persistence.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, Microsoft Defender for Containers, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelli…

1 week, 6 days назад @ microsoft.com
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

That’s why we are expanding the Zero Trust for AI strategy with two major additions: a new AI-focused Zero Trust Assessment experience and a new DevSecOps pillar in the Zero Trust Workshop.

Zero Trust Assessment tool updates: New set of assessment checks for AI, Security Operations (SecOps), and Infrastructure.

Zero Trust Workshop updates: New dedicated pillar focused on Developer Security (DevSecOps) and additional guidance for AI Memory.

How to run Zero Trust WorkshopThe Zero Trust Workshop follows a simple three-step motion: plan the right pillars and stakeholders, run the Zero Trust Assessment to establish a baseline, and use the facilitated workshop to turn findings into a 12- to 24-mo…

2 weeks назад @ microsoft.com
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints.

By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks.

Attack disruption instead uses AI-driven correlation and real-time analysis to identify multi-stage attacks by connecting signals across the environment before taking action.

The resultsTo summarize the results of the new device isolation response action:From first detection, Defender isolated the device in just 128 seconds.

Impact Mitigation (Defender response) – Device Isolation…

2 weeks назад @ microsoft.com
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints.

By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks.

Attack disruption instead uses AI-driven correlation and real-time analysis to identify multi-stage attacks by connecting signals across the environment before taking action.

The resultsTo summarize the results of the new device isolation response action:From first detection, Defender isolated the device in just 128 seconds.

Impact Mitigation (Defender response) – Device Isolation…

2 weeks назад @ microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence has also identified active traffic manipulation attacks leading to the delivery of malware on impacted systems.

Microsoft Threat Intelligence would like to thank our partners at Anthropic and OpenAI for their collaboration and support during this investigation.

Storm-2945 and Midnight BlizzardMicrosoft Threat Intelligence assesses that Storm-2945 is an operational sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps.

For additional details on Midnight Blizzard-related device code phishing techniques, see: Storm-2372 conducts device code phishing campaign.

To hear stories and insights from the Microsoft Threat Intelligence com…

2 weeks, 3 days назад @ microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence has also identified active traffic manipulation attacks leading to the delivery of malware on impacted systems.

Microsoft Threat Intelligence would like to thank our partners at Anthropic and OpenAI for their collaboration and support during this investigation.

Storm-2945 and Midnight BlizzardMicrosoft Threat Intelligence assesses that Storm-2945 is an operational sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps.

For additional details on Midnight Blizzard-related device code phishing techniques, see: Storm-2372 conducts device code phishing campaign.

To hear stories and insights from the Microsoft Threat Intelligence com…

2 weeks, 3 days назад @ microsoft.com
​​​​What’s new in Microsoft Security: July 2026
​​​​What’s new in Microsoft Security: July 2026 ​​​​What’s new in Microsoft Security: July 2026

Microsoft Defender Experts services are also expanding: Microsoft Defender Experts Threat Intelligence delivers human-led, curated insight into the cyberthreats most relevant to each organization, and Microsoft Defender Experts MDR extends expert-run detection and response beyond the Microsoft estate into third-party and multicloud signals through Microsoft Sentinel.

Together, the Insider Risk Management alert experience and Data Security Triage Agent help security teams investigate faster and with greater confidence.

In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy.

To learn more about Microsoft Security solutio…

2 weeks, 5 days назад @ microsoft.com
​​​​What’s new in Microsoft Security: July 2026
​​​​What’s new in Microsoft Security: July 2026 ​​​​What’s new in Microsoft Security: July 2026

Microsoft Defender Experts services are also expanding: Microsoft Defender Experts Threat Intelligence delivers human-led, curated insight into the cyberthreats most relevant to each organization, and Microsoft Defender Experts MDR extends expert-run detection and response beyond the Microsoft estate into third-party and multicloud signals through Microsoft Sentinel.

Together, the Insider Risk Management alert experience and Data Security Triage Agent help security teams investigate faster and with greater confidence.

In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy.

To learn more about Microsoft Security solutio…

2 weeks, 5 days назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 3 months, 3 weeks назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

3 months, 3 weeks назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

4 months, 1 week назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

4 months, 1 week назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

4 months, 2 weeks назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

4 months, 2 weeks назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

4 months, 3 weeks назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

5 months, 3 weeks назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

5 months, 3 weeks назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

6 months назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

6 months, 3 weeks назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

8 months, 1 week назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

8 months, 1 week назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

8 months, 1 week назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

8 months, 2 weeks назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

9 months назад @ security.googleblog.com