Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 1 час назад
Как внутренний мир коровы меняет атмосферу всей Земли
Как внутренний мир коровы меняет атмосферу всей Земли Как внутренний мир коровы меняет атмосферу всей Земли

Новая находка в рубце: органелла, которая одновременно производит топливо для метана и защищает его создателей.

1 час назад @ securitylab.ru
Дженсен Хуанг начал войну за открытые нейросети ради спасения империи Nvidia
Дженсен Хуанг начал войну за открытые нейросети ради спасения империи Nvidia

Борьба за open source стала вопросом выживания для производителя ускорителей

1 час назад @ securitylab.ru
Левые, либертарианцы, противники евгеники: политический портрет 16 ведущих нейросетей
Левые, либертарианцы, противники евгеники: политический портрет 16 ведущих нейросетей

Нейросети не любят корпорации и не верят в рынок.

2 часа назад @ securitylab.ru
Список чертежей в простом .txt. Хакеры Cl0p теперь сортируют украденное прямо на взломанном сервере
Список чертежей в простом .txt. Хакеры Cl0p теперь сортируют украденное прямо на взломанном сервере

Чертежи ракет и автомобилей утекли через дыру, которую не закрыли вовремя.

2 часа назад @ securitylab.ru
10 дней от патча до эксплойта: в открытый доступ выложили рабочий инструмент для атаки Certighost на Active Directory
10 дней от патча до эксплойта: в открытый доступ выложили рабочий инструмент для атаки Certighost на Active Directory 10 дней от патча до эксплойта: в открытый доступ выложили рабочий инструмент для атаки Certighost на Active Directory

То, что должно было подтверждать личность, стало инструментом для её подмены.

3 часа назад @ securitylab.ru
/proc/self/fd вместо эксплойта. Хакер обманул Java через файловые дескрипторы
/proc/self/fd вместо эксплойта. Хакер обманул Java через файловые дескрипторы

Alibaba поставила 9 из 10 и развела руками без фикса.

3 часа назад @ securitylab.ru
4340 ссылок за несколько недель. Вот что Европол нашёл в сети, вербующей детей
4340 ссылок за несколько недель. Вот что Европол нашёл в сети, вербующей детей

Рекомендательные алгоритмы могут показывать подросткам контент The Com.

4 часа назад @ securitylab.ru
От загрузки SVG до root за секунды: 1-пиксельный SVG-файл давал полный контроль над серверами Microsoft
От загрузки SVG до root за секунды: 1-пиксельный SVG-файл давал полный контроль над серверами Microsoft

Ошибка в обработке графики открыла путь к самым привилегированным процессам гиганта из Редмонда.

4 часа назад @ securitylab.ru
ИИ станет отягчающим фактором: СК подготовил поправки в Уголовный кодекс
ИИ станет отягчающим фактором: СК подготовил поправки в Уголовный кодекс ИИ станет отягчающим фактором: СК подготовил поправки в Уголовный кодекс

За применение ИИ предложили наказывать строже.

5 часов назад @ securitylab.ru
2400°C и ноль трещин: китайские материаловеды закрыли главную проблему гиперзвука
2400°C и ноль трещин: китайские материаловеды закрыли главную проблему гиперзвука

Новый материал выдержит температуру, при которой плавятся авиационные двигатели.

5 часов назад @ securitylab.ru
Один спутник против 271 посольства США. Ким Чен Ын решил наверстать отставание в разведке
Один спутник против 271 посольства США. Ким Чен Ын решил наверстать отставание в разведке

Как страны договариваются делить мир на зоны наблюдения.

6 часов назад @ securitylab.ru
Сбой Xbox на сутки лишил игроков доступа даже к купленным играм на дисках
Сбой Xbox на сутки лишил игроков доступа даже к купленным играм на дисках Сбой Xbox на сутки лишил игроков доступа даже к купленным играм на дисках

Почти сутки владельцы консолей не могли запускать цифровые покупки и часть игр на физических носителях из-за недоступной проверки лицензий.

6 часов назад @ securitylab.ru
Ideco NGFW Novum — стремительное развитие и стабильность, по результатам независимого тестирования лаборатории «Инфосистемы Джет»
Ideco NGFW Novum — стремительное развитие и стабильность, по результатам независимого тестирования лаборатории «Инфосистемы Джет»

Решение подтвердило 189 функциональных проверок из 242 по актуальной Методике 3.0.

7 часов назад @ securitylab.ru
Подключил тачку — отдал root: как за $130 взломать зарядную станцию через пистолет
Подключил тачку — отдал root: как за $130 взломать зарядную станцию через пистолет

Уязвимость скрывалась там, где водители привыкли видеть только источник энергии.

7 часов назад @ securitylab.ru
Уроки маскировки от APT32: как захватить систему через бинарный реестр и файл NTUSER.MAN
Уроки маскировки от APT32: как захватить систему через бинарный реестр и файл NTUSER.MAN

За внешне безобидными файлами скрывалась многоступенчатая операция с удалённым управлением.

8 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 4 часа назад
Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть I
Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть I Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть I

Детально описываем Ideco NGFW, Kaspersky NGFW, PT NGFW, UserGate NGFW, Континент 4 и ViPNet Coordinator HW по 260 критериям сравнения.

Поэтому, когда из России ушли иностранные ИБ-вендоры и на рынке освободилось место, отечественные производители тут же устремились в сегмент NGFW.

Как бизнес выбирает NGFW в 2026 годуМожно сказать, что сейчас заказчики выбирают не столько межсетевой экран, сколько производителя межсетевого экрана.

Нет Нет(будет доступно в будущих версиях) Да Да Да Двунаправленная поддержка DSCP Нет(появится в версии 23, август 2026 г.)

Да Да Да Да Да Экспорт логов Да(Syslog, выгрузка CSV.

4 часа назад @ anti-malware.ru
Что опаснее: компрометация учётной записи или вредоносная программа?
Что опаснее: компрометация учётной записи или вредоносная программа? Что опаснее: компрометация учётной записи или вредоносная программа?

Это означает, что после получения действительных учётных данных, независимо от способа их компрометации, дальнейшее продвижение по сети становится почти гарантированным.

Если собрать это вместе, становится понятно: всё чаще первоначальное проникновение в инфраструктуру начинается не с запуска вредоносного кода, а с использования скомпрометированной учётной записи.

Знакомство с бойцамиКомпрометация учётной записи — это когда злоумышленник получает доступ к чужой учётной записи и начинает работать с ней так, будто он и есть её владелец.

И наоборот: вредоносная программа может применяться для хищения учётных данных и последующей компрометации аккаунтов.

После получения действующих учётных данн…

23 часа назад @ anti-malware.ru
Обзор решений Cloud-Native Application Protection Platform (CNAPP)
Обзор решений Cloud-Native Application Protection Platform (CNAPP) Обзор решений Cloud-Native Application Protection Platform (CNAPP)

И в этот момент привычная схема, где разработка, эксплуатация и безопасность живут отдельно, начинает давать задержки и трения.

В этой точке логично появляется Cloud-Native Application Protection Platform (CNAPP) как способ связать безопасность с разработкой и эксплуатацией так, чтобы риски контролировались внутри процесса, а не поверх него, и не замедляли работу команд.

Иногда значение платформы пытаются объяснить через связку Cloud Security Posture Management (CSPM) и Cloud Workload Protection Platform (CWPP).

Что такое CNAPP (источник: Venison Magazine)Смысл такой сборки не в количестве модулей, а в том, что они перестают жить разрозненно.

Карта мирового рынка CNAPPЧтобы помочь компаниям…

1 day, 5 hours назад @ anti-malware.ru
Атака без вредоноса: Living-off-the-Land в АСУ ТП и ограничения сигнатурной защиты
Атака без вредоноса: Living-off-the-Land в АСУ ТП и ограничения сигнатурной защиты Атака без вредоноса: Living-off-the-Land в АСУ ТП и ограничения сигнатурной защиты

Риск возникает не в самом инструменте, а в том, кто его запустил, зачем и что он начал делать после запуска.

Такой мониторинг работает пассивно, на зеркалированном трафике, не ставит агенты на контроллеры и не нагружает критичные узлы.

Проблема не в том, что сигнатуры «больше не нужны»: против известного вредоноса они работают.

Проблема в том, что living-off-the-land проходит без файла, без хеша и без явной вредоносной нагрузки.

ВыводыСигнатурная защита остаётся важным элементом кибербезопасности, но в промышленных сетях она уже не способна закрыть весь спектр угроз.

4 days, 1 hour назад @ anti-malware.ru
«Лаборатория Касперского» пытается повторить успех в новом сегменте. Получится ли это?
«Лаборатория Касперского» пытается повторить успех в новом сегменте. Получится ли это? «Лаборатория Касперского» пытается повторить успех в новом сегменте. Получится ли это?

Всё это не оставалось без внимания регуляторов.

Однако потенциал роста и в России, и в мире на ближайшие годы довольно высок: среднегодовой прирост в компании ожидают на уровне 12–14 % на ближайший период.

И в целом, насколько рискует вендор, пытаясь выйти в новый для себя сегмент, который, по большому счёту, уже занят?

Цена ошибки несоизмерима с прикладным ПО, и репутационный ущерб от одного массового сбоя в узком ИБ-сообществе догоняет вендора годами.

Однако у «Антивируса Касперского» были существенные преимущества, что и позволило ему занять место не только на российском, но и на внешних рынках.

4 days, 5 hours назад @ anti-malware.ru
Последний универсал ИТ. Почему сеть снова оказалась в центре инфраструктуры
Последний универсал ИТ. Почему сеть снова оказалась в центре инфраструктуры Последний универсал ИТ. Почему сеть снова оказалась в центре инфраструктуры

Почему сетевой инженер снова становится одной из ключевых фигур в ИТ — на примере «Сетевого лета 2026».

Теперь такие проекты не исчезли, а распались на более конкретные и управляемые части, способные дать эффект в течение двух–четырёх лет.

По оценке Пантелеева, то, на что при ручной проверке могло уйти несколько дней, в отдельных сценариях теперь занимает полчаса.

Но главный сдвиг видит даже не в происхождении оборудования, а в отношении к управлению.

Даниил Виняр, руководитель группы перспективных разработок «Инфосистемы Джет»Незаметная инфраструктураПод конец разговора Виняр неожиданно сравнивает сеть не с высокотехнологичным продуктом, а с водопроводом.

5 days, 2 hours назад @ anti-malware.ru
Обзор Kaspersky NGFW 1.2, межсетевого экрана нового поколения
Обзор Kaspersky NGFW 1.2, межсетевого экрана нового поколения Обзор Kaspersky NGFW 1.2, межсетевого экрана нового поколения

Kaspersky NGFW 1.2 — это новый релиз коммерческой версии межсетевого экрана нового поколения от «Лаборатории Касперского».

Функциональные возможности Kaspersky NGFW 1.2Kaspersky NGFW версии 1.2 — это многофункциональный межсетевой экран нового поколения, предназначенный для фильтрации трафика, контроля сетевых соединений и защиты корпоративных сетей от угроз.

Централизованное администрирование нескольких устройств Kaspersky NGFW и других продуктов вендора через единую консоль управления (Open Single Management Platform).

Аппаратные платформы KX-Series позволяют полностью реализовать возможности межсетевого экрана нового поколения Kaspersky NGFW, оставаясь эффективными даже в сложных сетевых…

5 days, 5 hours назад @ anti-malware.ru
Российские браузеры 2026: полный гид по выбору для работы и личной безопасности
Российские браузеры 2026: полный гид по выбору для работы и личной безопасности Российские браузеры 2026: полный гид по выбору для работы и личной безопасности

Разбираемся, какие российские браузеры представлены на рынке в 2026 году, какими они бывают и для чего используются.

Техподдержка зарубежных продуктов не учитывает российские реалии и не решает специфические проблемы.

Российские браузеры: становление и развитие рынкаРоссийские браузеры одно время активно появлялись и развивались, но многие из них уже стали историей.

Среди них есть десктопные (для компьютеров) и мобильные (для смартфонов и планшетов) приложения, корпоративные браузеры для бизнеса и защищённые сборки с поддержкой ГОСТ-криптографии.

Актуальные российские браузеры по состоянию на 2026 годМы разделили все представленные в обзоре браузеры на две категории: настольные и мобильные …

5 days, 22 hours назад @ anti-malware.ru
Девять безопасных DNS-резольверов, доступных в России
Девять безопасных DNS-резольверов, доступных в России Девять безопасных DNS-резольверов, доступных в России

Таких случаев было немало, в том числе и в России, иногда с очень печальными последствиями.

Сервисы, доступные в РоссииТребование к сервисам для обзора было по большому счёту одно: корректная работа в России по состоянию на конец июня 2026 года.

Она как самостоятельно, так и в сотрудничестве с 18 другими организациями и компаниями, в том числе, например, IBM, собирает данные о проблемных доменах.

И в целом Quad9 пока не был замечен ни в одном инциденте, связанном с безопасностью.

Рассчитан не только на конечных пользователей, но и на использование в организациях, в том числе сферы образования и детского отдыха.

6 days, 4 hours назад @ anti-malware.ru
SIEM в АСУ ТП: как построить мониторинг, который помогает производству, а не мешает
SIEM в АСУ ТП: как построить мониторинг, который помогает производству, а не мешает SIEM в АСУ ТП: как построить мониторинг, который помогает производству, а не мешает

В АСУ ТП проблема редко заключается только в том, что не хватает SIEM.

Ключевые сложности мониторинга в АСУ ТПНа практике трудности связаны в основном не с возможностями самой SIEM, а с особенностями промышленной инфраструктуры.

События из технологического сегмента поступают редко или не поступают вообщеОдна из главных проблем — не качество SIEM, а отсутствие стабильного потока данных из АСУ ТП.

Что получает CISOДля руководителя ИБ ценность SIEM в АСУ ТП не в том, что «ещё один сегмент подключили к мониторингу».

ВыводыSIEM в АСУ ТП не решает задачу сама по себе.

6 days, 23 hours назад @ anti-malware.ru
Как атакуют e-commerce? Опыт BrandSecurity и М.Видео
Как атакуют e-commerce? Опыт BrandSecurity и М.Видео Как атакуют e-commerce? Опыт BrandSecurity и М.Видео

Как меняется ландшафт угроз в электронной коммерции и как удалось добиться удаления 97,5 % всех выявленных нарушений за 6 лет сотрудничества BrandSecurity и «М.Видео».

На примере многолетнего сотрудничества «М.Видео» и BrandSecurity рассмотрим, как выстроить такую систему защиты и какие результаты получены за шесть лет работы.

Как меняется ландшафт угроз для брендов в электронной коммерцииМошенники стремятся обмануть как можно больше пользователей, поэтому они имитируют популярные магазины и бренды, уже завоевавшие доверие.

Чтобы минимизировать репутационные риски, необходимо отслеживать:пустые боты и каналы с логотипом бренда;визуально схожие домены и страницы;упоминания бренда в акциях и …

1 week назад @ anti-malware.ru
Суверенные GPU-платформы: как компании строят безопасную инфраструктуру для ИИ
Суверенные GPU-платформы: как компании строят безопасную инфраструктуру для ИИ Суверенные GPU-платформы: как компании строят безопасную инфраструктуру для ИИ

Сервер (узел) с восемью графическими процессорами (Источник: APNIC)Где брать GPU‑ресурсы:Выделенные серверы (bare metal) — физический сервер с GPU полностью в распоряжении компании.

Как работают вместе GPU‑инфраструктура и суверенные облакаКомпания арендует кластеры GPU не в любом публичном облаке, а в суверенном.

Данные, журналы, модели и сервисы остаются внутри защищённой инфраструктуры, а провайдер выполняет требования 152‑ФЗ, приказов ФСТЭК, норм для КИИ и отраслевых стандартов.

Шифрование и управление ключамиДанные шифруются в покое и в движении.

Компании переходят к гибридным схемам, используют механизмы разделения GPU и усиливают требования к прозрачности и безопасности.

1 week, 1 day назад @ anti-malware.ru
Какая российская серверная ОС лучше подойдёт бизнесу: сравнение 9 решений
Какая российская серверная ОС лучше подойдёт бизнесу: сравнение 9 решений Какая российская серверная ОС лучше подойдёт бизнесу: сравнение 9 решений

Виртуальные контексты и производительность, часть IIПараметр / Продукт Атлант ОСнова РЕД ОС РОСА Хром Виртуализация Да Да Да Да Отказоустойчивая конфигурация Сведения отсутствуют Сведения отсутствуют Да Да Балансировка нагрузки Сведения отсутствуют Сведения отсутствуют Да Да Высокая доступность (HA) Сведения отсутствуют Сведения отсутствуют Да Да Контейнеризация приложений Да (Docker, Podman, Kubernetes) Да (Docker, Podman, Kubernetes) Да (Docker, Podman, Kubernetes) Да (Docker, Podman, Kubernetes) Встроенные инструменты оптимизации производительности Сведения отсутствуют Сведения отсутствуют Да (TuneD) Да (TuneD)Таблица 4.1.

Службы сетевой инфраструктуры «из коробки», часть IПараметр / Про…

1 week, 1 day назад @ anti-malware.ru
Удалёнка без защиты: почему VPN и MFA больше не работают
Удалёнка без защиты: почему VPN и MFA больше не работают Удалёнка без защиты: почему VPN и MFA больше не работают

Стоимость простоя после кибератаки достигает 21,7 млн рублей в час для ИТ- и телеком-компаний и 9,6 млн рублей в час для ритейла.

Компания не управляет его сетью, устройством, каналами связи и окружением и не может гарантировать, что сессия остаётся безопасной.

ИТ-отдел не видит трафик и устройства сотрудников, а значит, не может блокировать доступ к неавторизованным сервисам.

Он шифрует трафик, но не контролирует устройство, не отслеживает состояние сессии и не ограничивает доступ внутри сети.

VPN не проверяет состояние устройства и не управляет сессией.

1 week, 4 days назад @ anti-malware.ru
Чем опасен вайбкодинг и как проверять код, созданный ИИ
Чем опасен вайбкодинг и как проверять код, созданный ИИ Чем опасен вайбкодинг и как проверять код, созданный ИИ

Интеграция ИИ в конвейер безопасной разработки, как это часто бывает сегодня, становится ответом на рост вызовов и угроз, связанных с применением нейросетевых инструментов как в разработке, так и злоумышленниками в ходе атак.

ИИ как вызовКак показало исследование ГК «Солар» и УЦСБ, инструменты с ИИ для написания и анализа программного кода используют 80 % опрошенных российских компаний.

Руководитель отдела разработки пользовательского интерфейса компании «НЕКСТБИ» Григорий Голиков среди организационных рисков выделил появление кода, который внешне работает, но не адаптируется, не оптимизирован и небезопасен: непрозрачен, потенциально уязвим и не проходит проверку.

ИИ как инструмент злоумышл…

1 week, 4 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 4 часа назад
Пентест через GitLab. От раннера до контроля над облаком
Пентест через GitLab. От раннера до контроля над облаком Пентест через GitLab. От раннера до контроля над облаком

Вряд ли в начале проекта заказчик ожидал серьезного импакта, но мы доказали, что при типовых настройках CI/CD такая учетка находится на расстоянии нескольких прыжков до контроля над облаком.

Начальная точка: учетка в GitLabИтак, на старте у нас была только учетная запись разработчика в GitLab.

Мы зашли в систему, создали тестовый проект и добавили в него .gitlab-ci.yml — файл, который описывает логику пайплайна.

Наш .gitlab-ci.ymlСконфигурировали файл так, чтобы выполнить на раннере базовые команды разведки и попробовать достучаться до внешнего вебхука на нашем сервере.

Переход в облакоПодготовив клиент OpenStack, мы выполнили команды:openstack server list openstack network list openstack u…

4 часа назад @ habr.com
Как защитить Manticore Search с помощью встроенной аутентификации и авторизации
Как защитить Manticore Search с помощью встроенной аутентификации и авторизации Как защитить Manticore Search с помощью встроенной аутентификации и авторизации

В Manticore Search теперь (с релиза 27.1.5 ) есть встроенная аутентификация и авторизация — для SQL по протоколу MySQL, для HTTP/HTTPS‑эндпоинтов и для операций, связанных с репликацией.

Пользователи, которые уже используют Manticore могут подключить новую функциональность, сохранив привычные способы работы с Manticore.

В этом случае Manticore будет хранить данные аутентификации в файле auth.json в каталоге data_dir .

Проверка прав в обоих случаях одинакова: клиент проходит аутентификацию, Manticore определяет пользователя, и запрошенное действие сверяется с правами этого пользователя.

Во время работы с кластером обращайтесь с логом аутентификации (по умолчанию файл searchd.log.auth ) с бер…

4 часа назад @ habr.com
OAuth‑сервер, который не хранит пользователей
OAuth‑сервер, который не хранит пользователей OAuth‑сервер, который не хранит пользователей

«Что ты у нас за пользователь?» — профиль приложения (ваш id , роль, отображаемое имя), который относится к домену, а не к личности.

scope — это не «что разрешено вам», а «что вы разрешили приложению делать от вашего имени».

Фактически aud в токене берётся из scope клиента, поэтому aud ‑claim представляет собой аудитории, чьи scope попали в токен.

SW перехватывает fetch и автоматически подвешивает Authorization , поэтому приложение основной токен не хранит и не запрашивает.

Этот токен не содержит refresh , а исходный токен не отзывается.

5 часов назад @ habr.com
Методические рекомендации Банка России по безопасности ИИ на финрынке (№ 3-МР): обзор и что делать на практике
Методические рекомендации Банка России по безопасности ИИ на финрынке (№ 3-МР): обзор и что делать на практике Методические рекомендации Банка России по безопасности ИИ на финрынке (№ 3-МР): обзор и что делать на практике

Сегодня рассмотрим Методические рекомендации Банка России от 16.06.2026 № 3-МР по обеспечению информационной безопасности при разработке и применении ИИ на финансовом рынке.

Поэтому читать документ стоит уже сейчас, причём не как «что нас заставят», а как «куда идёт регулятор и на что он смотрит».

Важная привязка: документ опирается на Кодекс этики в сфере разработки и применения ИИ на финансовом рынке (информационное письмо Банка России от 09.07.2025 № ИН-016-13/91).

Что в документе принципиально новогоПробежимся по тому, что отличает 3-МР от того, что мы видели раньше.

И, что ценно, сразу перечислены возможные последствия: от нарушения прав граждан и убытков до угрозы стабильности финансо…

5 часов назад @ habr.com
Отпечатки браузера: что это такое и как работает? Переосмысление технологии
Отпечатки браузера: что это такое и как работает? Переосмысление технологии Отпечатки браузера: что это такое и как работает? Переосмысление технологии

В этом материале мы рассмотрим, что такое отпечаток браузера и что изменилось в технологии за 6 лет, кофе или чай приветствуются — мы начинаем!

От cookies к физической биометрииДавайте разбираться с этой эволюцией и с тем, как работают конкретные составляющие отпечатка браузера сейчас.

Трекеры не следят за вами и не собирают персональные данные таким образом, они просто следят за вашим устройством.

Если кратко — анализ фингерпринта уже приравнен к сбору cookies и не может выполняться без явного на то согласия конечного пользователя.

Но площадки все равно его собирают и не получают за это штрафов, почему?

6 часов назад @ habr.com
416 тестов и кнопка «снести все»: где ломаются агентные проекты
416 тестов и кнопка «снести все»: где ломаются агентные проекты 416 тестов и кнопка «снести все»: где ломаются агентные проекты

Это не один универсальный гайд (такого и не существует).

Одна оговорка: свои проекты я диагностировал сам агентами, это самодиагностика, не внешний аудит и не чтение кода экспертом.

Есть хотя бы один тест на поведение агента, а не на качество его ответов?

416 тестов проверяют, что индекс собирается и поиск отвечает; ни один не проверяет, что агент не сделал лишнего, пока делал правильное.

Но вместе с ними арендуется и невидимое — матрица прав, песочница, потолки автономии, настроенные кем-то другим и не под мои риски.

7 часов назад @ habr.com
[Перевод] Книга аутентификации
[Перевод] Книга аутентификации [Перевод] Книга аутентификации

Как следует из названия, эта книга в значительной степени посвящена системе аутентификации и авторизации для веб-приложений.

Примеры на GoПример базовой аутентификации - пример аутентификации с помощью пароля с подтверждением email и сбросом пароля (исходный код)Пример аутентификации без пароля - пример аутентификации с помощью passkey и кода, отправляемого на email, с подтверждением email (исходный код)Методы аутентификацииПростейший метод аутентификации - использование имени пользователя и пароля.

Сессии аутентификацииСессия аутентификации (auth session) - это сессия, которая отслеживает состояние аутентификации пользователя путем хранения ID аутентифицированного пользователя.

Однако, есл…

7 часов назад @ habr.com
Лицензионный ключ на 202 символа: почему не Ed25519 и не RSA
Лицензионный ключ на 202 символа: почему не Ed25519 и не RSA Лицензионный ключ на 202 символа: почему не Ed25519 и не RSA

Проверять решил не по памяти и не по статьям — рефлексией по самой сборке, в двух версиях рантайма сразу.

Формулировка, кстати, лукавая: дело не в «этой платформе», а в том, что такого примитива нет в API вообще.

Кодирую в Base32, а не в более компактный Base64, намеренно: в алфавите Base32 нет строчных букв и нет пар-двойников вроде 0 и O, 1 и l, так что ключ можно продиктовать по телефону и не получить в ответ: «не подходит».

Значит, RSA отпадает не по производительности, по которой он как раз хорош, а по внешнему виду письма.

Четыре мегабайта чужого кода — это не только четыре мегабайта: это ещё и чужие решения о том, какие версии платформы поддерживать.

11 часов назад @ habr.com
Click to Pray: один if — и ты ошибся
Click to Pray: один if — и ты ошибся Click to Pray: один if — и ты ошибся

Обычная, прямо скажем, недоделанная авторизация, которая одинаково хорошо портит жизнь и пет‑проектам, и сервисам с сотнями тысяч пользователей.

К 2026 году Click to Pray был вполне большим интернет‑сервисом: больше семисот тысяч профилей, backend, мобильные клиенты, API, регистрация и персональные данные.

Исследователь заметил ещё одну деталь: его почтовый клиент показал предупреждение, что совершенно настоящее письмо Click to Pray не прошло требования доменной аутентификации.

Тогда специалисты британской Fidus Information Security заинтересовались Click to Pray после выпуска — не смейтесь — электронных чёток Click to Pray eRosary.

И снова Click to Pray, API, пользовательские данные и отсу…

15 часов назад @ habr.com
redb 3.4.0: переигрываем упавшее, патчим фреймворк без пересборки и раздаём права — экосистема.NET
redb 3.4.0: переигрываем упавшее, патчим фреймворк без пересборки и раздаём права — экосистема.NET redb 3.4.0: переигрываем упавшее, патчим фреймворк без пересборки и раздаём права — экосистема.NET

Snapshot() — и почему это не Clone()Здесь пришлось добавить в ядро новый примитив, и это самая интересная часть.

Первая версия умеет неизменяемые тела, byte[] и ICloneable , а на всём остальном громко падает, а не делает молча поверхностную копию.

Это принципиально: тихо разделённое тело в системе точек сохранения — это баг, который проявится через месяц и в самый неудачный момент.

Это и есть тот самый «патч без пересборки Tsak», уже как готовая команда.

Работает и в long polling, и в вебхуке — маппер общий.

16 часов назад @ habr.com
Security Week 2631: новые приемы корпоративных кибервымогателей
Security Week 2631: новые приемы корпоративных кибервымогателей Security Week 2631: новые приемы корпоративных кибервымогателей

Оба инцидента, произошедшие в мае этого года в Мексике и в июне в Колумбии, удалось подробно проанализировать, в результате чего стали понятны методы взлома корпоративной инфраструктуры, а также дальнейшие шаги киберпреступников.

Примечательно, что в обоих случаях для шифрования данных с последующим требованием выкупа использовался штатный инструмент Windows, известный как BitLocker.

Еще одной любопытной особенностью данной атаки стала печать записки с требованием выкупа прямо на корпоративных принтерах в офисе организации.

Для них же на атакованном сервере была частично отключена защита, что не позволило своевременно зафиксировать вредоносную активность с помощью мониторинга.

Соответствующ…

17 часов назад @ habr.com
Как устроена Kimi K3: 2,8 трлн параметров, линейное внимание и агенты на миллион токенов
Как устроена Kimi K3: 2,8 трлн параметров, линейное внимание и агенты на миллион токенов Как устроена Kimi K3: 2,8 трлн параметров, линейное внимание и агенты на миллион токенов

В K3 Moonshot изменила параметризацию коэффициента забывания:g = g_min * sigmoid(exp(A) * z) alpha = exp(g) g_min = -5У Kimi Linear логарифм затухания не был ограничен снизу.

Отдельная работа Moonshot по AttnRes показывает улучшение на модели Kimi Linear с 48 млрд параметров, из которых активны 3 млрд.

Для K3 опубликована конфигурация и описание реализации, но независимой репликации на масштабе 2,8 трлн параметров пока нет.

Смещение эксперта влияет на выбор Top‑k, но не входит в веса смеси и не искажает градиент маршрутизатора.

Независимый DeepSWE на 25 июля показывает K3 на 69% ± 5%: ниже GPT-5.6 Sol и номинально Fable 5, но выше Opus 4.8.

19 часов назад @ habr.com
Автоматизация реверс‑инжиниринга через локальную LLM
Автоматизация реверс‑инжиниринга через локальную LLM Автоматизация реверс‑инжиниринга через локальную LLM

Выбрана из‑за удобства последующего обхода последовательностей вызовов функций и последующего добавления описания из БЯМ.

Локальная LLM (Qwen3, запущенная через LM Studio с API‑ключом для доступа) — для анализа каждой функции.

LLM‑анализ функций ( worker.py + mcp.py ) — каждая функция по очереди отправляется в локальную LLM с запросом на выполнение анализа: назначение, IOC, теги, сетевые индикаторы, команды запуска, техники уклонения.

Каждой функции в промпт передаётся не только декомпилированный код, но и её позиция в графе вызовов — какие функции она вызывает и кто вызывает её.

Граф решает это следующим образом: функция — это узел, вызов другой функции — это ребро между узлами.

21 час назад @ habr.com
Архитектурный паттерн «LangGraph, гибридный RAG + Сигнатурный движок»: универсальный граф для потоковых данных
Архитектурный паттерн «LangGraph, гибридный RAG + Сигнатурный движок»: универсальный граф для потоковых данных Архитектурный паттерн «LangGraph, гибридный RAG + Сигнатурный движок»: универсальный граф для потоковых данных

Интересная фича: Agent 1 дополнительно отправляет свой анализ напрямую в Agent 3 (ребро agent1 → agent3 ).

AI‑ядро: Agent 1 → Agent 2 (RAG) → Agent 3AI‑ядроВ этом разделе не будет промптов, потому что они слишком огромные.

YARA и Sigma — детерминированная веткаДетерминированная веткаИзначально добавили 8 YARA и 9 Sigma правил как минимальную базу.

Замена YARA на движок модерации контента, RAG — на базу знаний компании, позволит тому же графу анализировать комментарии или документы.

В репозитории есть тесты в pipeline_tests/, docker‑compose на 5 сервисов, CI/CD (Docker Hub + зеркало для GitVerse), метрики для RAG.

1 day назад @ habr.com
Ваш парсер .evtx молча прочитал 4% журнала — и не считает это ошибкой
Ваш парсер .evtx молча прочитал 4% журнала — и не считает это ошибкой Ваш парсер .evtx молча прочитал 4% журнала — и не считает это ошибкой

магия 00000008 00 00 00 00 00 00 00 00 oldest_chunk 00000010 00 00 00 00 00 00 00 00 current_chunk_num 00000018 b9 2b 00 00 00 00 00 00 next_record_num = 11193 00000020 80 00 00 00 01 00 03 00 hdr_size=128, minor=1, major=3 00000028 00 10 01 00 hdr_chunk_size=0x1000, chunk_count = 1 <-- ... 00000078 01 00 00 00 flags = 0x1 (DIRTY) <--chunk_count = 1 .

Это не повреждение.

Флаг 0x1 (dirty) означает ровно то, что написано в спецификации libevtx: журнал открыт и изменялся, и не все изменения отражены в заголовке.

Попутно: CRC32 в 0x7C я не пересчитывал, и python-evtx этого не заметил — контрольную сумму заголовка он по умолчанию не проверяет.

Число записей — это не полнотаОдна мысль, ради котор…

1 day, 1 hour назад @ habr.com
Хакер Хакер
последний пост 1 час назад
Reuters: в OpenAI неделю не замечали, что их ИИ-агент проводил атаки
Reuters: в OpenAI неделю не замечали, что их ИИ-агент проводил атаки Reuters: в OpenAI неделю не замечали, что их ИИ-агент проводил атаки

Чтобы проверить реальные возможности моделей, в OpenAI намеренно ослабили ограничения на опасные ИБ-запросы, а также отключили часть защитных механизмов, которые обычно блокируют высокорисковую активность.

Лишь после этого в OpenAI предположили, что за атакой может стоять их собственный ИИ.

В итоге первый прямой контакт между Hugging Face и OpenAI состоялся примерно 20 июля, а публично об инциденте в OpenAI рассказали 21 июля.

Источники агентства отмечают, что в OpenAI одновременно тестируют множество моделей, и эти тесты генерируют огромные объемы логов, за которыми сотрудники компании не всегда успевают следить.

Представитель OpenAI заявил агентству, что в материале Reuters есть «ряд нето…

1 час назад @ xakep.ru
В Microsoft сообщили, что добавят TPM-аттестацию для KMS-хостов
В Microsoft сообщили, что добавят TPM-аттестацию для KMS-хостов В Microsoft сообщили, что добавят TPM-аттестацию для KMS-хостов

В Microsoft анонсировали механизм KMS Hardware-Secured, который призван защитить корпоративную активацию Windows от поддельных и клонированных серверов.

Перед обработкой запросов на активацию KMS-хосту придется подтвердить с помощью TPM, что он работает на доверенном оборудовании и не был скомпрометирован.

Изменения не затронут обычную OEM- или retail-активацию Windows и не вводят обязательную привязку пользовательских лицензий к железу.

Развертывание нового механизма начнется в августе 2026 года: в Windows Server 2025 появятся уведомления, которые помогут администраторам проверить, соответствует ли KMS-хост новым требованиям, и система сообщит, подходит ли сервер для KMS Hardware-Secured.

3 часа назад @ xakep.ru
Активист стер данные со своего телефона на границе США. Ему предъявили обвинения
Активист стер данные со своего телефона на границе США. Ему предъявили обвинения Активист стер данные со своего телефона на границе США. Ему предъявили обвинения

Министерство юстиции США предъявило обвинения жителю Атланты Самуэлю Тунику (Samuel Tunick), который стер данные со своего смартфона во время досмотра в аэропорту.

Инцидент произошел больше года назад — 24 января 2025 года, когда Туник возвращался в США из-за рубежа через международный аэропорт Хартсфилд-Джексон в Атланте.

Сотрудники Погранично-таможенной службы США (U.S. Customs and Border Protection, CBP) отправили его на дополнительный досмотр и потребовали разблокировать смартфон Google Pixel.

Тренировочный центр, стоимость постройки которого оценивается в 118 млн долларов США, в итоге открылся весной 2025 года.

Предположительно, это первое подобное разбирательство в США.

5 часов назад @ xakep.ru
«Хакер» и лаборатория «Хаксет» запускают курс «Пентест WEB»
«Хакер» и лаборатория «Хаксет» запускают курс «Пентест WEB» «Хакер» и лаборатория «Хаксет» запускают курс «Пентест WEB»

Курс поможет по-настоящему разобраться в том, как работают атаки на веб, и подходит для начинающих: темы разбираются последовательно, с видео, понятными примерами и практикой.

Потом перейдешь к первичному доступу: разберешь reverse shell, bind shell и web shell, а также увидишь, как уязвимость превращается в управляемую командную оболочку.

В основной части ты разберешь классические векторы веб-атак:Занятие про фаззингу покажет, как находить скрытые директории, служебные файлы и резервные копии.

Статьи «Хакера» помогут разобраться в теории и инструментах, а видео и лаборатории «Хаксет» позволят сразу применить знания на практике.

Если ты не подписан на «Хакер», оплата курса откроет все матер…

6 часов назад @ xakep.ru
Хакеры атакуют 0-day в Check Point SmartConsole
Хакеры атакуют 0-day в Check Point SmartConsole Хакеры атакуют 0-day в Check Point SmartConsole

В компании Check Point предупредили клиентов о критической уязвимости CVE-2026-16232, которая затрагивает продукты Security Management и Multi-Domain Management.

При этом уязвимость уже применяется в реальных атаках.

Специалисты объясняют, что благодаря этой 0-day атакующий может получить токен для входа в приложение, авторизоваться через SmartConsole с привилегиями администратора, а затем изменить настройки и конфигурацию системы безопасности.

Агентство по кибербезопасности и защите инфраструктуры США (CISA) уже добавило CVE-2026-16232 в каталог активно эксплуатируемых уязвимостей (Known Exploited Vulnerabilities, KEV).

Наряду с CVE-2026-16232 разработчики исправили еще две проблемы: крити…

20 часов назад @ xakep.ru
Исследователь получил 78 000 долларов США за баг в инфраструктуре поддержки Meta*
Исследователь получил 78 000 долларов США за баг в инфраструктуре поддержки Meta* Исследователь получил 78 000 долларов США за баг в инфраструктуре поддержки Meta*

Независимый ИБ-исследователь Рони К. Рой (Rony K Roy) заработал 78 000 долларов США за обнаружение уязвимости во внутренней инфраструктуре службы поддержки Meta (деятельность компании признана экстремистской и запрещена на территории РФ).

В своем блоге Рой пишет, что обнаружил проблему и сообщил о ней разработчикам еще в январе 2026 года.

Сначала исследователь решил, что нашел небольшой баг в механизме авторизации Meta Horizon Managed Solutions — корпоративной платформы для централизованного администрирования устройств Meta Quest.

Однако дальнейший анализ показал, что проблема была намного серьезнее и затрагивала общую бэкенд-инфраструктуру поддержки Meta.

Стоит отметить, что представители …

22 часа назад @ xakep.ru
HTB Fries. Подделываем права в NFS, чтобы добраться от контейнера до домена
HTB Fries. Подделываем права в NFS, чтобы добраться от контейнера до домена HTB Fries. Подделываем права в NFS, чтобы добраться от контейнера до домена

Сегод­ня покажу, как через тун­нель доб­рать­ся до внут­ренне­го NFS-ресур­са, выдать себя за нуж­ную груп­пу, заб­рать сер­тифика­ты для Docker и под­делать кли­ент­ский серт.

На­ша конеч­ная цель — получить пра­ва супер­поль­зовате­ля на машине Fries с учеб­ной пло­щад­ки Hack The Box.

warning Под­клю­чать­ся к машинам с HTB рекомен­дует­ся с при­мене­нием средств ано­ними­зации и вир­туали­зации.

На пер­вом выпол­няет­ся обыч­ное быс­трое ска­ниро­вание, на вто­ром — более тща­тель­ное, с исполь­зовани­ем встро­енных скрип­тов (опция -A ).

Осва­иваем раз­ведку и ска­ниро­вание сети».

1 day назад @ xakep.ru
На форумах Steam обнаружили приманки для ClickFix-атак
На форумах Steam обнаружили приманки для ClickFix-атак На форумах Steam обнаружили приманки для ClickFix-атак

Злоумышленники публикуют на форумах Steam фальшивые решения для различных проблем с играми и Windows.

По его словам, атакующие регистрируют аккаунты в Steam и активно отвечают пользователям, которые жалуются на вылеты игр, пропажу предметов из инвентаря и другие технические проблемы.

В классической версии жертв заманивают на вредоносные сайты и там обманом заставляют скопировать в буфер и выполнить некие команды PowerShell.

Хотя чаще всего ClickFix-атаки нацелены на пользователей Windows, ИБ-специалисты уже давно предупреждают и о кампаниях, направленных на пользователей macOS и Linux.

Для закрепления в системе скрипт создает задачу XMRig-[имя компьютера], которая запускает майнер с правами…

1 day, 1 hour назад @ xakep.ru
Всего 100 адресов владеют 90% объема токена Сэма Альтмана
Всего 100 адресов владеют 90% объема токена Сэма Альтмана Всего 100 адресов владеют 90% объема токена Сэма Альтмана

По данным документов, поданных специалистами Grayscale в SEC для запуска ETF на Worldcoin, примерно 90% всех токенов WLD в обращении сосредоточено в руках владельцев всего 100 адресов.

В разделе о рисках документа прямо сказано: 100 крупнейших кошельков WLD держат около 90% токенов в обращении.

Один из этих кошельков — мост между Ethereum и World Chain, который, вероятно, обслуживает множество пользователей одновременно, но общей картины концентрации токенов это не меняет.

Согласно заявке, WLD «в будущем может быть использован» для участия в управлении сетью World Network, однако механизмы такого перехода названы «новыми и непроверенными в масштабе».

На момент публикации токен WLD торговалс…

1 day, 2 hours назад @ xakep.ru
Министерство финансов Таиланда атаковали с помощью ИИ-агента Hermes
Министерство финансов Таиланда атаковали с помощью ИИ-агента Hermes Министерство финансов Таиланда атаковали с помощью ИИ-агента Hermes

Специалисты Hunt.io и ИБ-исследователь Боб Дьяченко (Bob Diachenko) нашли незащищенную инфраструктуру хакера, который применял ИИ-агента Hermes для автоматизации атаки на сеть Министерства финансов Таиланда.

На сервере в Гонконге эксперты обнаружили три открытые директории, содержащие 585 файлов общим объемом около 470 Мбайт.

Hermes — опенсорсный ИИ-ассистент, созданный компанией Nous Research, который можно развернуть на собственном сервере и использовать для автоматизации разных задач.

Подчеркивается, что нет никаких свидетельств того, что агент самостоятельно нашел новую уязвимость, выбрал цель или успешно эксплуатировал какие-либо баги.

Кроме того, на сервере нашли 62 сборки ранее неизв…

1 day, 3 hours назад @ xakep.ru
Вредоносные сайты собирают малварь по частям в памяти браузера
Вредоносные сайты собирают малварь по частям в памяти браузера Вредоносные сайты собирают малварь по частям в памяти браузера

Кампания маскируется под официальные приложения TradingView, Solana и Luno и в основном нацелена на трейдеров и владельцев криптовалюты.

Жертвы попадают на сайты SourTrade по рекламным ссылкам, в том числе из поисковой выдачи.

Так, сначала вредоносная страница регистрирует ServiceWorker, отвечающий за загрузку файла, а затем создает SharedWorker, который выполняет роль движка для сборки.

При этом метка Mark of the Web сохраняется, а источником файла в ней указан вредоносный сайт, хотя часть компонентов поступила с другого сервера.

К отчету Confiant приложены три SHA-256-хеша и список из более чем 90 доменов, задействованных в этой кампании.

1 day, 5 hours назад @ xakep.ru
FortiBleed. Как десятки тысяч устройств Fortinet стали фабрикой для сбора данных
FortiBleed. Как десятки тысяч устройств Fortinet стали фабрикой для сбора данных FortiBleed. Как десятки тысяч устройств Fortinet стали фабрикой для сбора данных

В июне 2026 года ИБ‑спе­циалист Боб Дьячен­ко (Bob Diachenko) на­шел в сети откры­тый сер­вер с базой дан­ных, содер­жащей тысячи URL-адре­сов FortiGate и Fortinet VPN, логины, email-адре­са и пароли в откры­том виде.

Счи­тает­ся, что это одна из круп­ней­ших в исто­рии под­борок учет­ных дан­ных для устрой­ств Fortinet.

Fortinet и FortiGate Fortinet — один из круп­ней­ших в мире про­изво­дите­лей средств сетевой защиты.

Спе­циалис­ты ком­пании Hudson Rock, получив­шие от Дьячен­ко дамп для ана­лиза, наз­вали эту наход­ку одной из круп­ней­ших извес­тных кол­лекций учет­ных дан­ных, свя­зан­ных с Fortinet.

Дело в том, что часть записей напоми­нала дан­ные из экспор­тирован­ных кон­фигура­ци…

1 day, 8 hours назад @ xakep.ru
Ежеквартальный «Хакер» #3 готовится к печати. Предзаказы открыты
Ежеквартальный «Хакер» #3 готовится к печати. Предзаказы открыты Ежеквартальный «Хакер» #3 готовится к печати. Предзаказы открыты

Первые два выпуска ежеквартального «Хакера» уже отпечатаны, а третий готовится к выходу в сентябре.

#1: еще в продажеПервый ежеквартальный выпуск, с которого началось возвращение «Хакера» к регулярному печатному формату.

В журнал вошло более 20 материалов — от вводных руководств по сетевой разведке до исследований железа и хардкорных технических разборов.

Первый и второй номера уже готовы к отправке, а третий и четвертый будут доставлены тебе по мере их подготовки и выхода.

В результате к концу года ты получишь полную бумажную подшивку ежеквартальных выпусков «Хакера».

3 days, 19 hours назад @ xakep.ru
GitHub снижает выплаты по программе bug bounty
GitHub снижает выплаты по программе bug bounty GitHub снижает выплаты по программе bug bounty

С 27 июля 2026 года GitHub как минимум вдвое снизит выплаты участникам публичной программы bug bounty.

К примеру, за критическую уязвимость исследователи будут получать фиксированные 10 000 долларов США вместо прежних 20 000–30 000 долларов.

Ее участникам будут платить 1000 долларов США за баги низкой степени опасности, 7500 долларов за проблемы среднего уровня, 20 000 долларов за уязвимости высокой серьезности и не менее 30 000 долларов за критические баги.

Также пока в GitHub не раскрывают, какого минимального значения нужно добиться в HackerOne Signal, но известно, что исследователи, которые не достигнут установленного порога, смогут отправить не более четырех пробных отчетов.

При этом в…

3 days, 20 hours назад @ xakep.ru
BitMEX завершает работу после 11 лет на рынке
BitMEX завершает работу после 11 лет на рынке BitMEX завершает работу после 11 лет на рынке

С этой даты и до финального сентябрьского дедлайна оператор будет принудительно закрывать все оставшиеся сделки, чтобы упорядоченно свернуть работу рынка.

Уход биржи BitMEX стал результатом многолетней потери позиций на рынке бессрочных фьючерсов — том самом сегменте, который когда-то создали в BitMEX.

В 2020 году BitMEX обвинили в отсутствии надлежащих мер по борьбе с отмыванием денег, а позже представители биржи признали вину по этим обвинениям.

За 11 лет работы платформа, зарегистрированная на Сейшельских островах, ни разу не теряла средства пользователей из-за взломов или эксплоитов, а также на протяжении многих лет справлялась с жесткими проверками со стороны международных регуляторов.…

3 days, 21 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 1 час назад
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain covert access.

The as-yet-undetermined access route is then abused to deliver the malicious payloads, including NightLedger, which is launched as a DLL via DLL side-loading.

The use of BridgeHead and ArcBridge indicates the threat actor's continued use of tunneling utilities, which has been previously observed relying on bespoke tunnelers such as LIGHTRAIL and POLLBLEND.

"HOLLOWGRAPH abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel," i…

1 час назад @ thehackernews.com
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions.

"If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process," JetBrains said.

Depending on the privileges granted to the TeamCity server process, a successful compromise can lead to the exposure of TeamCity data, configurations, and stored credentials, or modification of server state.

"The security patch plugin will address only the vulnerability described above (CVE-2026-63077)," JetBrains cautioned.

"Even exposin…

5 часов назад @ thehackernews.com
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted.

The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.

Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development.

Linux users should install a distribution kernel carrying the fix rather than rely on the upstream version number alone.

The practical risk is narrower than a generic "Linux root exploit" label may suggest, but public exploit code raises the urgency for compatible systems that remain unpatched.

5 часов назад @ thehackernews.com
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost
Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex.

It is available only inside MDASH, not as a standalone public model or general-purpose application programming interface.

According to Microsoft's model card, MAI-Cyber-1-Flash is a sparse mixture-of-experts transformer with 137 billion total parameters, five billion active parameters, and a 256,000-token context window.

Microsoft's launch announcement defines the 50% saving against its current best MDASH model mix of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex.

The model card also warns that generated text and code may be inaccurate or incomplete and should be r…

7 часов назад @ thehackernews.com
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.

"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host," Arista said in a Monday advisory.

"Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

The American network equipment company said the issue has already been addressed in hosted and dedicated versions of VCO in advance.

"Compromises to the VCO platform may allow attackers access …

8 часов назад @ thehackernews.com
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Foundation.

Hugging Face identified unauthorized access to a limited set of internal datasets and several credentials used by its services.

They then chained vulnerabilities and stolen credentials across OpenAI and Hugging Face systems while seeking benchmark answers.

The primary disclosures establish that the open model helped Hugging Face reconstruct the intrusion and supported its response.

For now, the public record shows a coalition, a policy position, several member commitments, and one iden…

19 часов назад @ thehackernews.com
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure.

The lineage runs through JackSkid, one of four IoT botnets targeted in coordinated U.S., German, and Canadian law-enforcement actions on March 19.

XLab's Dysphoria timeline opens with a JackSkid sample captured on March 25, six days after the disruption, that resolves C2 through the same domain.

The relay-only build drops the DDoS modules and instead uses UPnP to map ports on the local gateway and Linux epoll to shuttle traffic between an outside connection and a remote C2…

20 часов назад @ thehackernews.com
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server.

SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version boundary.

SSD's technical analysis identifies it as CVE-2026-61511 , an unauthenticated remote code execution flaw in vBulletin's template engine.

The exploit code is new; the flaw it targets was already fixed.

This is the same corner of vBulletin that has produced pre-authentication code execution before.

22 часа назад @ thehackernews.com
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

The AI company said its AI models broke out of a sealed testing environment and broke into Hugging Face's production system to find solutions for the ExploitGym benchmark.

"The incident also makes clear that advanced models can discover and exploit novel attack paths in real-world systems without source-code access," OpenAI said.

Against end-user targets in Latin America, spear-phishing ZIP archives or MSI installers are used to deliver TriBack Loader.

→ AI can now find vulnerabilities, build exploits, and chain attacks faster than traditional security operations can respond.

- A new campaign has been observed using shareable Claude chats to host ClickFix instructions, leading to the deploy…

23 часа назад @ thehackernews.com
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

n8n fixed the flaw in versions 2.31.5 and 2.32.1 .

A successful exploit executes commands with the privileges of the n8n process.

n8n workflow builders use expressions such as ={{ $json.email }} .

It does not independently confirm the complete Reflect.get() exploit chain described in Security Joes' report.

Neither was covered by tests," Security Joes' research team said of the two conditions its exploit relied on.

1 day назад @ thehackernews.com
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools.

The same PowerShell command has been found to download and deploy ConnectWise ScreenConnect in parallel, indicating an attempt to drop multiple RMM tools with an intent to establish persistent remote access.

This is not the first time threat actors have abused RMM tools to their advantage.

The commit history indicates that the campaign has been active since at least February 2026, when the repository was created with the fake Microsoft Store page featuring an "update" for Teams.

"The messages used an authen…

1 day, 1 hour назад @ thehackernews.com
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote access trojans (RATs) and information stealer malware.

"Cruciferra is written in Mono and features numerous techniques designed to evade detection, analysis, and incident response efforts," the enterprise security company said in an analysis published last week.

The service has been advertised on the cybercrime underground as the "most lethal crypter" for $450 to $2,000 a month.

Some of the commodity malware families distributed via Cruciferra include Agent Tesla, AsyncRAT, DarkCloud Stealer, Formbook, Phantom Stealer, Remcos RAT, Snake…

1 day, 2 hours назад @ thehackernews.com
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.

The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz.

TELESHIM also employs an array of methods to detect the presence of virtualization-based analysis environments.

The attack sequence culminates with the deployment of BINDCLOAK, a 64-bit C2 implant written in C++ that contacts an external server ("cert.hypersnet[.]com").

It has not been attributed to any known threat actor or group at this stage.

1 day, 4 hours назад @ thehackernews.com
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request.

"The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project," the Microsoft-owned subsidiary said.

According to GitHub, the three-day cooldown default only applies to version updates, which are designed to keep software dependencies up-to-date.

GitHub said it arrived at three days as the default as it considers the duration to be in the goldilocks zone.

"A cooldown is built for a specific pattern: a malicious version that …

1 day, 5 hours назад @ thehackernews.com
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

The landing page begins preparing the delivery path without waiting for a download click.

The browser retrieves and decompresses a clean Bun runtime from that second domain, purelogicbox[.

It then follows the supplied template as a byte-copy recipe, combining selected ranges from the Bun runtime, the generated stream, and the attacker-controlled executable material.

The resulting MotW record identifies the landing page as the download source, not the separate domain that supplied the Bun runtime.

The report also says Bitdefender found a modified Bun executable in this cluster.

2 days, 18 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 2 weeks назад
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

2 weeks назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

2 weeks, 6 days назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

3 weeks, 4 days назад @ welivesecurity.com
This month in security with Tony Anscombe – June 2026 edition
This month in security with Tony Anscombe – June 2026 edition This month in security with Tony Anscombe – June 2026 edition

It's that time of month when ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses.

What lessons does the new CISA policy hold for organizations outside the agency's direct remit?

What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems?

How can you stay safe from imposter fraud, and could the social media bans for children work?

Learn more from Tony's video and be sure to check out the May 2026 edition of Tony's monthly security news roundup for more insights.

3 weeks, 6 days назад @ welivesecurity.com
Inside the inbox: Why cybercriminals want to break into your email account
Inside the inbox: Why cybercriminals want to break into your email account Inside the inbox: Why cybercriminals want to break into your email account

With access to your email account, they can reset your passwords across multiple other accounts – perhaps intercepting one-time passcodes sent by your bank, social media, cloud storage or other online provider.

That could lay the groundwork for a convincing phishing email designed to impersonate a trusted organization you interact with.

A phishing attack on your corporate email account is often the first stage in a bigger data breach, extortion/ransomware or espionage attack.

They’re also using more sophisticated tools to improve the success rates of email phishing campaigns.

In this instance the scammers reportedly hijacked the email account of a high-level executive, before impersonating …

4 weeks, 1 day назад @ welivesecurity.com
SMB cyber readiness: the road to resilience starts here
SMB cyber readiness: the road to resilience starts here SMB cyber readiness: the road to resilience starts here

For these businesses, cyber resilience should be the direction of travel – that is, the ability to continue operating and recover even during a serious incident.

Cyber readiness is about putting in place the processes and controls to prevent, detect and respond to threats.

So, should confidence in cyber resilience posture be so high, especially if organizations are still getting hit multiple times?

The truth is that there’s no end state for cyber readiness or resilience.

If it’s serious about improving the cyber readiness of small businesses, the vendor community should step up.

1 month назад @ welivesecurity.com
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Key points of this blogpost: Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.

Continued data exfiltration and a new allianceThroughout 2025, Gamaredon stayed highly active and remained focused solely on Ukraine.

Notably, we uncovered that in early 2025, Gamaredon collaborated with Turla, another Russia-aligned threat actor also linked to the FSB; we documented our findings in our blogpost Gamaredon X Turla collab.

Figure 1 shows a chart of unique samples of HTA downloaders delivered per month in Gamaredon spearphishing campaigns.

Compared to 2024, we also saw a shift in how Gamaredon used these dead drops.

1 month назад @ welivesecurity.com
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET takes part in Operation Endgame to disrupt Amadey and Stealc

Key points of this blogpost: ESET took part in the coordinated, global Operation Endgame to disrupt Amadey and Stealc.

Our automated systems have been dissecting Amadey and Stealc samples and identifying the fields most relevant for large-scale tracking.

The largest Amadey botnet clusterOne cluster stands out as the largest, and it contributed nearly 34% of all processed Amadey samples.

Stealc affiliate clustering based on ESET telemetryConclusionFor global disruption operations such as Operation Endgame against Amadey and Stealc, long-term automated tracking of malware is necessary.

2026‑04‑09 Stealc C&C server.

1 month назад @ welivesecurity.com
Killing me gently: Inside Gentlemen’s EDR killer framework
Killing me gently: Inside Gentlemen’s EDR killer framework Killing me gently: Inside Gentlemen’s EDR killer framework

The group distinguishes itself through a mature, operator-maintained set of endpoint detection and response (EDR) killers, i.e., tools for disrupting security software.

In this blogpost, we share our findings on Gentlemen’s suite of EDR killers gained through extensive research and corroborated by the recent leak.

Third‑party EDR killers (HexKiller, ThrottleBlood, and HavocKiller) are operationally integrated.

Rather than relying on affiliates to source their own EDR killers, Gentlemen operators actively develop and maintain a portfolio of EDR killers for affiliates.

It allows the Gentlemen operators to integrate abused drivers into their toolset very soon after an EDR killer PoC is disclos…

1 month, 1 week назад @ welivesecurity.com
Protecting legacy OT systems against modern cyberthreats
Protecting legacy OT systems against modern cyberthreats Protecting legacy OT systems against modern cyberthreats

Of course, connecting production systems to enterprise networks delivers tangible benefits, but the security implications – that systems once safe were suddenly no longer so – arrived more quietly.

Start by mapping which systems in an environment are connected and have no security coverage, where IT and OT networks intersect, which segments are unmonitored, and which production systems have fallen outside any vendor support agreement.

Meanwhile, off-the-peg security tools often don’t efficiently meet the enterprise requirements in legacy OT systems that run on older hardware and outdated operating system versions.

The production systems running that version continue to operate for years, ac…

1 month, 1 week назад @ welivesecurity.com
FishMonger’s arsenal upgraded: SprySOCKS for Windows
FishMonger’s arsenal upgraded: SprySOCKS for Windows FishMonger’s arsenal upgraded: SprySOCKS for Windows

Key points of this blogpost: We discovered two previously undocumented Windows variants of FishMonger’s SprySOCKS backdoor.

Technical analysisIn this section, we provide a technical analysis of these new, Windows variants of FishMonger’s SprySOCKS backdoor.

Figure 3. klelam00007.bat setting up persistence for the SprySOCKS backdoor (newlines added for readability)Figure 4 depicts the execution chain of the SprySOCKS WIN_DRV variant.

It contained the SprySOCKS backdoor and the SprySOCKS loader.

6490B8E4AADE25A3EE2D A9A47F312DB2122470BC X1B5206BDC1 743DD.dat Win64/SprySOCKS.A Encrypted container of the encrypted WIN_DRV variant of SprySOCKS backdoor, encrypted SprySOCKS RawWNPF and SprySOCKS …

1 month, 1 week назад @ welivesecurity.com
EvilTokens: A phishing attack that doesn’t steal your password
EvilTokens: A phishing attack that doesn’t steal your password EvilTokens: A phishing attack that doesn’t steal your password

Instead, attackers get the victim to complete a legitimate authentication process – including two-factor authentication (2FA) – on a real Microsoft login page.

What makes EvilTokens dangerousThe OAuth device code flow was designed for devices that may be awkward to sign into directly, such as smart TVs or printers.

No document, invoice, email, or another platform should ask for a device code without a clear reason.

A real Microsoft page doesn’t automatically make a request safe.

Sometimes the attacker could ask them to enter a real code on a real page – but for the wrong device.

1 month, 1 week назад @ welivesecurity.com
OceanLotus: From external espionage to domestic targeting
OceanLotus: From external espionage to domestic targeting OceanLotus: From external espionage to domestic targeting

During this period, the Vietnam-aligned OceanLotus adopted a more selective approach to external operations while placing increasing emphasis on domestic espionage.

We identified two distinct campaigns involving the SPECTRALVIPER backdoor: a supply-chain attack targeting stock investors in Vietnam and a prolonged espionage operation against a Vietnamese infrastructure and transport construction company.

The domain resolved to the genuine IP address of the FireAnt update server, suggesting a supply-chain compromise scenario.

LTD 2025‑09‑20 SPECTRALVIPER C&C server.

]com IRT‑CHOOPALLC‑AP 2025‑09‑20 SPECTRALVIPER C&C server.

1 month, 2 weeks назад @ welivesecurity.com
SMB cyber-readiness: What makes or breaks it
SMB cyber-readiness: What makes or breaks it SMB cyber-readiness: What makes or breaks it

But that realization alone clearly doesn’t prepare them to withstand an attack.

Have the repeat victims come to view their brushes with cyber-incidents as proof of “what doesn’t kill me makes me stronger”?

For all the talk around AI, automation and attacker sophistication, many SMB breaches still begin with a familiar opening.

A total of 71% of SMBs globally now carry cyber insurance, rising to 84% in North America, with adoption climbing sharply among repeat victims.

While “when, not if” has never been more true, that alone doesn’t prepare a business for adversity.

1 month, 2 weeks назад @ welivesecurity.com
Cybercriminals: the 'auditors' you never hired
Cybercriminals: the 'auditors' you never hired Cybercriminals: the 'auditors' you never hired

There’s a phrase that is peddled out by governments and companies alike when a catastrophe of any type – including a cybersecurity breach – occurs: “Lessons have been learnt”.

The 130% increase in significant incidents between 2024 and 2025 severely challenges this assertion and points to lessons not being learnt, at a macro level.

In fact, this reluctance to look could also be normalcy bias quietly doing its work.

That is why this metaphor matters – cybercriminals discover the gap between what an organisation believes about its security and what the reality is.

We must accept that normalcy bias exists and act upon it.

1 month, 2 weeks назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 43 минуты назад
Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence
Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence Intel 471 expands Verity471 with AI agent and MCP support for threat intelligence

Intel 471 has announced two new AI capabilities in the Verity471 platform, MCP471 and Agent471.

The Verity471 platform turns adversary tradecraft into pre-attack intelligence and proactive threat hunting, helping security teams act on any threat before it’s weaponized.

MCP471 makes Intel 471 a native part of automated defensive tools, giving teams a way to combine that intelligence with their own internal data.

A connector, built on the Model Context Protocol, that brings Verity471 intelligence into the AI tools and agentic workflows organizations already run, Claude, ChatGPT, and custom harnesses.

MCP471 makes Intel 471 a native part of automated defensive tools, giving teams a way to comb…

43 минуты назад @ helpnetsecurity.com
SpecterOps brings AWS attack path management and AI to hybrid identity security
SpecterOps brings AWS attack path management and AI to hybrid identity security SpecterOps brings AWS attack path management and AI to hybrid identity security

BloodHound Enterprise adds support for Amazon Web Services and Microsoft Entra Agent ID, expanding the reach of attack path management.

New capabilities include:Add attack path intelligence to AI Workflows: Built natively into BloodHound Enterprise and leveraging the Model Context Protocol, BloodHound Hunter, connects your approved AI agents and knowledge sources directly to BloodHound Enterprise findings.

Built natively into BloodHound Enterprise and leveraging the Model Context Protocol, BloodHound Hunter, connects your approved AI agents and knowledge sources directly to BloodHound Enterprise findings.

Security teams can now investigate how AI agents, delegated identities, service princi…

50 минут назад @ helpnetsecurity.com
Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response
Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response Team Cymru unveils Pure Signal Command for AI-powered threat intelligence and incident response

Team Cymru has announced Pure Signal Command, the connected operating environment for analysts, security teams, applications, and AI agents to access and act on Team Cymru’s internet infrastructure intelligence.

Command unlocks Team Cymru’s globally observed threat intelligence data by connecting telemetry, investigative and attack surface management capabilities, expert analysis, and machine-native access within a common architecture.

“Pure Signal Command is transforming how we identify and stop threats,” said Tim Jones, Chief Technology Officer, Team Cymru.

Pure Signal Command is designed to serve the full operational team, including AI agents, extending Pure Signal™ from human investigat…

1 час назад @ helpnetsecurity.com
Exposed BMCs hand out password hashes before login
Exposed BMCs hand out password hashes before login Exposed BMCs hand out password hashes before login

An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in.

Roughly one in six of the exposed hosts answered for an empty username, with a weak password behind it.

Unique factory passwords crack tooSupermicro hardware made up the majority of responding BMCs in the dataset.

HPE iLO uses a shorter factory password built from uppercase letters and digits, giving a smaller keyspace still.

Supermicro also said it will review the default password policy on future hardware revisions, including longer passwords or a wider character set.

1 час назад @ helpnetsecurity.com
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible.

“For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, Solutions Engineering Lead at JetBrains.

State-sponsored hacking groups and ransomware affiliates have been known to leverage vulnerabilities in unpatched TeamCity On-Premises servers in the past.

JetBrains has already implemented the fix for TeamCity Cloud deployments, and is now advising customers to do the same on their self-hosted instances, as CVE-2026-63077 affects all TeamCity On-Premises versions.

TeamCity On-Premises cust…

2 часа назад @ helpnetsecurity.com
VERITAS project could change the way scientists secure AI
VERITAS project could change the way scientists secure AI VERITAS project could change the way scientists secure AI

A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by establishing AI Assurance as a core function of scientific research infrastructure.

The project brings together experts in adversarial AI, research cyberinfrastructure, data science and workforce development to address security risks unique to AI-powered science.

The second is a new operational role, an AI Assurance Engineer, piloted at the National Center for Supercomputing Applications.

However, it has rarely been applied to scientific research infrastructure, where compromised AI models or datasets can influence research without obvious warning signs.

“AI systems can fail in way…

2 часа назад @ helpnetsecurity.com
Grafana Assistant expands with AI agents for investigations, automation, and observability
Grafana Assistant expands with AI agents for investigations, automation, and observability Grafana Assistant expands with AI agents for investigations, automation, and observability

The releases include Grafana Assistant Investigations, Grafana Assistant Workspace, Grafana Assistant Automations, the Grafana Cloud MCP server, gcx, and Grafana Agent Observability.

Paired with Grafana Assistant Investigations, a running investigation becomes a shareable report, no rewriting required.

Grafana Assistant Investigations and Grafana Assistant Automations are both now generally available, helping engineers get answers out of production faster than they can type their questions.

Grafana Assistant Automations let a saved Grafana Assistant prompt run again automatically, on a schedule, or on demand, so recurring checks like a daily error rate summary are sent to your Slack channel…

3 часа назад @ helpnetsecurity.com
AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027
AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027 AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

The rule group is available to all AWS WAF customers, and is included with AWS Shield Advanced subscriptions.

AWS recommends reviewing the new Anti-DDoS dashboard in the AWS WAF console, comparing the DDoSDetected and DDoSAttackRequests metrics to validate detection, and using AWS WAF labels to analyze suspicious requests.

Beginning January 1, 2027, AWS will discontinue Shield Advanced application-layer automatic mitigation.

Anti-DDoS rule group capabilitiesThe managed rule group expands Shield Advanced automatic mitigation by learning normal traffic patterns, responding to attacks, and operating independently of health checks.

AWS configures the rule group through AWS WAF, requiring existi…

4 часа назад @ helpnetsecurity.com
Coca-Cola confirms hackers stole data in Fairlife ransomware attack
Coca-Cola confirms hackers stole data in Fairlife ransomware attack Coca-Cola confirms hackers stole data in Fairlife ransomware attack

Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities.

In a statement published on Monday, Coca-Cola said Fairlife has resumed the majority of production across its four US manufacturing facilities.

On July 20, the Anubis ransomware group added Fairlife to its dark web leak site, claiming it had encrypted servers and stolen 1 terabyte of confidential data.

Coca-Cola has not confirmed the volume or nature of any data stolen, and the ransomware group’s claims remain independently unverified.

Anubis operates as a Ransomware-as-a-Service (RaaS) platform, …

4 часа назад @ helpnetsecurity.com
Shadow AI incident response begins with logs that may already be gone
Shadow AI incident response begins with logs that may already be gone Shadow AI incident response begins with logs that may already be gone

In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident.

Wityak also discusses the gap between an AI policy in a wiki and a control a company can defend, and when documentation helps or hurts.

When you walk into an organization after a shadow AI incident, what is the first artifact you ask to see, and how often does that single request surface a gap the company didn’t know it had?

The central question in shadow AI incidents is likely to be whether the organisation took measures within its power to restrict employee activity and mitigate risk.

It’s whether the actions of the organisation to mitigate…

7 часов назад @ helpnetsecurity.com
AI took more than junior developer jobs and the bill comes later
AI took more than junior developer jobs and the bill comes later AI took more than junior developer jobs and the bill comes later

Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong.

Work-related AI usage there reaches 51.8 percent, close to double the U.S. rate, and major technology firms have shut down open recruitment of junior developers.

One founder with more than twelve years as a developer described what happened after he cut his junior headcount.

“We let a lot of junior engineers go in the second half of last year.

She calls the design “a kind of learning by doing.”The study found one senior, at a large enterprise with formal onboarding pipelines, who reported that junior work had changed very little.

8 часов назад @ helpnetsecurity.com
Download: The High-Performance Team Playbook
Download: The High-Performance Team Playbook Download: The High-Performance Team Playbook

Get practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level.

Most engineering teams don’t fail because of bad engineers.

They fail because performance is assumed.

This playbook shows how high-performance teams are built intentionally across people, structure, leadership, and AI.

What you’ll learn:

8 часов назад @ helpnetsecurity.com
Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts
Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts

Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned.

Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency, before being redirected to a second page requesting their 2FA code.

Call of Duty Mobile has been downloaded an estimated 489 million times and generated around $1.8 billion in lifetime in-app purchases, according to Malwarebytes.

How the scam worksDisguised as the official Call of Duty Mobile site, the first phishing page offers 10,800 free Call of Duty Points in exchange for an email address and passwor…

9 часов назад @ helpnetsecurity.com
Cybersecurity jobs available right now: July 28, 2026
Cybersecurity jobs available right now: July 28, 2026 Cybersecurity jobs available right now: July 28, 2026

Cybersecurity ArchitectVELUX | Denmark | Hybrid – View job detailsAs a Cybersecurity Architect, you will define and drive the organisation’s cybersecurity architecture and technical roadmap, providing guidance across cloud, identity, application, infrastructure, data, and network security.

Get weekly updates on new cybersecurity job openings.

Senior Cloud Security DeveloperRBC | Canada | On-site – View job detailsAs a Senior Cloud Security Developer, you will design and build automated AWS security solutions using serverless technologies, infrastructure as code, and secure CI/CD practices.

You will develop and operate cloud security controls, evaluate new security technologies, improve plat…

9 часов назад @ helpnetsecurity.com
Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost
Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost

Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system.

Microsoft argues that advances in AI are giving attackers increasingly powerful capabilities to search large codebases for vulnerabilities, increasing the need for AI models designed to help identify software flaws.

“As the cost of finding a flaw collapses, the old model of security, where you scan occasionally and patch eventually, is now obsolete.

(Source: Microsoft)“When combined with MDASH, it delivers world-class performance at 50 percent of the cost of leading models,” said Satya Nadella, CEO of Microsoft.

It can reaso…

18 часов назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 2 часа назад
Axon Is Another License Plate Surveillance Company
Axon Is Another License Plate Surveillance Company Axon Is Another License Plate Surveillance Company

Governments are switching, but I’m not sure it makes a difference:…some municipalities, including Denver, Colorado, are ditching their Flock arrays.

But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon, it’s like a gambling addict trying to kick the habit by switching from FanDuel to DraftKings.

[…]Despite what you may read on the Flock website, Axon cameras are pretty effective when it comes to hoovering up personal details that can go far beyond your license plate numbers.

That means a municipality that opts for Axon cameras instead of Flock units won’t necessarily reduce the amount privacy its citizens lose through their use.

2 часа назад @ schneier.com
Cognyte Sells a Mobile Cell Surveillance Van
Cognyte Sells a Mobile Cell Surveillance Van Cognyte Sells a Mobile Cell Surveillance Van

Yet another Israeli mass surveillance company:Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it.

That enables cops to keep tabs on any phones in the vicinity ­ whether they’re owned by a suspect in a case or not.

Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed within the vehicles, hidden in a backpack for on-foot missions or attached to a helicopter.

It’s the same technology as the infamous Stingray, one of the original cell-site simulators made by defense giant L3Harris.

1 day, 2 hours назад @ schneier.com
Friday Squid Blogging: Illex Squid Catch in the Falklands
Friday Squid Blogging: Illex Squid Catch in the Falklands Friday Squid Blogging: Illex Squid Catch in the Falklands

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

3 days, 16 hours назад @ schneier.com
Why AI Needs a “Genie Coefficient”
Why AI Needs a “Genie Coefficient” Why AI Needs a “Genie Coefficient”

Beyond the AI model itself, what has changed is the harness: the ordinary code that wraps around an AI model, decides when and how to use the model, and controls access to tools like a browser, a low-level command line, or a financial API.

Genie behavior isn’t new.

If we get the measurement right, it enables things that aren’t possible today, like policies concerning AI behavior.

If an AI system betrays the reasonable meaning of an instruction, that’s the AI’s misbehavior, not the user’s.

Test a diverse array of skills, use cases, and tools, and give the AI system sparse, confusing, or overwhelming context.

4 days, 2 hours назад @ schneier.com
End-to-End Encryption and “Going Dark”
End-to-End Encryption and “Going Dark” End-to-End Encryption and “Going Dark”

Governments around the world have proposed, and in some cases enacted, laws limiting E2EE for law enforcement and national security purposes.

The Article proceeds in three parts tracking three rounds of the Going Dark Debate.

Round 3 addresses the current debate over E2EE, where no entity between sender and recipient can read the plaintext.

The Article’s first major contribution is identifying five technically distinct scenarios for how E2EE operates in practice, each with different implications for lawful access.

These scenarios reveal a substantial gap between the assumption that E2EE categorically blocks lawful access and the reality of how communications are sent and received.

5 days, 2 hours назад @ schneier.com
First-Person Identity Theft Story
First-Person Identity Theft Story First-Person Identity Theft Story

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

6 days, 2 hours назад @ schneier.com
MIT to Become Hotbed of AI Video Surveillance
MIT to Become Hotbed of AI Video Surveillance MIT to Become Hotbed of AI Video Surveillance

Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026.

Technical specifications for the cameras suggest that they will be capable of collecting real-time face and object classification data, including detection of motion, loitering, crowds, face masks, and camera tampering.

According to a statement from MIT spokesperson Kimberly Allen, any collected data is “retained up to 30 days,” unless an exception is granted.

They support resolutions ranging from 2MP to 4K while also recognizing faces, license plates, vehicles, and other objects in real time.

Nearly all cameras will accommodate…

1 week назад @ schneier.com
On Flock License Plate Tracking Cameras
On Flock License Plate Tracking Cameras On Flock License Plate Tracking Cameras

The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM.

It just saw 34 DTM in large type and started alerting the local police.

In fact, four other 34 ## DTM cars were being tracked around Minnesota that week, according to Officer Ganshyn.

It was fed those characters that you said, 34 DTM, and it spit back out [a result] with the characters, 34 DTM,” Thomas said.

Last year, he even called one group that tracks the location of Flock cameras “terrorists.” But he’s had a change of heart.

1 week, 1 day назад @ schneier.com
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach Friday Squid Blogging: Squid Washing Up on Cape Cod Beach

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 week, 3 days назад @ schneier.com
Details of Alan Turing’s Voice Encryption System
Details of Alan Turing’s Voice Encryption System Details of Alan Turing’s Voice Encryption System

Really interesting piece of cryptographic history:In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars.

The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945.

Delilah was Turing’s portable voice-encryption system, named after the biblical deceiver of men.

There is also material written by Bayley, often in the form of notes he took while Turing was speaking.

It is thanks to Bayley that the papers survived: He kept them until he died in 2020, 66 years after Turing passed away.

1 week, 4 days назад @ schneier.com
Protecting Privacy in an AI Era
Protecting Privacy in an AI Era Protecting Privacy in an AI Era

Protecting Privacy in an AI EraDaniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era.

Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies.

Measures such as rigorous data minimization, fiduciary duties, liability for negligent or reckless technological design, liability for algorithms that cause harm, and multi-stakeholder review of technologies will be far more effective.

Posted on July 16, 2026 at 10:34 AM • 0 Comments

1 week, 4 days назад @ schneier.com
A Video Screen That Is Also a Camera
A Video Screen That Is Also a Camera A Video Screen That Is Also a Camera

Amazing:Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both.

This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipulating light’s intensity, oscillation phases, and polarization.

The team reported its findings in a paper published yesterday in Nature.

We are one step closer to 1984 technology:The telescreen received and transmitted simultaneously.

There was of course no way of knowing whether you were being watched at any given moment.

1 week, 6 days назад @ schneier.com
Upcoming Speaking Engagements
Upcoming Speaking Engagements Upcoming Speaking Engagements

I’m speaking at Boston Leadership Exchange in Boston, Massachusetts, USA, on Wednesday, July 22, 2026.

I’m speaking at Cognitive Security Conference in Las Vegas, Nevada, USA.

The conference runs August 6-7, 2026; my speaking time is TBD.

I’m speaking at DEF CON 34 in Las Vegas, Nevada, USA.

The conference runs September 30–October 1, 2026; the time of my talk is TBD.

1 week, 6 days назад @ schneier.com
Vulnerability in FIFA’s Network
Vulnerability in FIFA’s Network Vulnerability in FIFA’s Network

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

2 weeks назад @ schneier.com
AI Data Centers and the Concentration of Wealth
AI Data Centers and the Concentration of Wealth AI Data Centers and the Concentration of Wealth

AI Data Centers and the Concentration of WealthThis essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

Opposition to AI data centers has emerged as a primary theme in US politics, one that—surprisingly—doesn’t fall along party lines.

For some, data center opposition may feel like the only tangible mechanism for registering their concern, disapproval, or even anger about AI.

The problem is that this may be exactly what the AI companies are banking on.

And while data center opposition campaigns have been successful in building widespread appeal, their effectiveness in the US is mixed.

2 weeks, 1 day назад @ schneier.com
Krebs On Security
последний пост 6 days, 12 hours назад
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

6 days, 12 hours назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

1 week, 6 days назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

2 weeks назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

2 weeks, 6 days назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

3 weeks, 4 days назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

1 month назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

1 month, 1 week назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

1 month, 2 weeks назад @ krebsonsecurity.com
A Record-Breaking Patch Tuesday for June 2026
A Record-Breaking Patch Tuesday for June 2026 A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.

“Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said.

Microsoft received heavily blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher.

While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barne…

1 month, 2 weeks назад @ krebsonsecurity.com
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

On May 31, word began to spread on several Telegram instant message channels that Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow.

Meta has not responded to requests for comment on the video’s claims, but the company reportedly did acknowledge the dormant Instagram account for the Obama White House was briefly compromised.

Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership.

Just like human customer support employees can be social engineered into providing unauthorized access to someone’s a…

1 month, 3 weeks назад @ krebsonsecurity.com
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

But as KrebsOnSecurity observed in September 2025, those sanctions failed to target Stark’s remaining connection to the Internet — an Internet service provider based in the Netherlands called MIRhosting.

MIRhosting is operated by Andrey Nesterenko, a 39-year-old Russian native who runs the business out of the Netherlands.

And as our September 2025 report showed, WorkTitans was controlled by Nesterenko and a 57-year-old from Amsterdam named Youssef Zinad.

On top of that, WorkTitans was getting connectivity to the larger Internet solely through MIRhosting, where Zinad had worked previously.

“The transition to the.hosting was not intended to evade sanctions,” Nesterenko wrote.

2 months назад @ krebsonsecurity.com
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers Demand Answers as CISA Tries to Contain Data Leak Lawmakers Demand Answers as CISA Tries to Contain Data Leak

The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.

Experts who reviewed the exposed secrets said the commit logs for the code repository showed the CISA contractor disabled GitHub’s built-in protection against publishing sensitive credentials in public repos.

CISA acknowledged the leak but has not responded to questions about the duration of the data exposure.

TruffleHog does this by monitoring a live feed that GitHub publishes which includes a record of all commits and changes to public code repositories.

In practical terms, it is likely that cybercrime groups or foreign adversaries also noticed the publication of these CISA secrets, …

2 months назад @ krebsonsecurity.com
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

A criminal complaint unsealed today in an Alaska district court charges Jacob Butler, a.k.a.

“Dort,” of Ottawa, Canada with operating the Kimwolf DDoS botnet.

“KimWolf was tied to DDoS attacks which were measured at nearly 30 Terabits per second, a record in recorded DDoS attack volume,” the Justice Department statement reads.

Synthient was among many technology companies thanked by the Justice Department today, and Synthient’s founder Ben Brundage told KrebsOnSecurity he’s relieved Butler is in custody.

The DOJ said at least one of those services collaborated with Butler’s Kimwolf botnet.

2 months, 1 week назад @ krebsonsecurity.com
CISA Admin Leaked AWS GovCloud Keys on Github
CISA Admin Leaked AWS GovCloud Keys on Github CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems.

Another file exposed in their public GitHub repository — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems.

“The available Git metadata alone does not prove which endpoint or device was used.”Caturegli said he validated that the exposed credentials could authenticate to three AWS GovCloud accounts at a high privilege level.

CISA has not responded to questions about the p…

2 months, 1 week назад @ krebsonsecurity.com
Patch Tuesday, May 2026 Edition
Patch Tuesday, May 2026 Edition Patch Tuesday, May 2026 Edition

Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code.

May’s Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws.

But at the end of April, Oracle announced it was switching to a monthly update cycle for critical security issues.

Chrome automagically downloads available security updates, but installing them requires fully restarting the browser.

For a more granular look at the Microsoft updates released today, checkout this inventory by the SANS Internet Storm Center.

2 months, 2 weeks назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 4 days, 23 hours назад
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know

The AI models involved were OpenAI's GPT-5.6 Sol and a more capable, as-yet-unreleased model.

The intention of OpenAI's researchers was to get a clear picture of what the AI models were capable of achieving if not constrained.

American AI safety guardrails forced a US company to turn to a Chinese AI model for help.

Hugging Face's CEO Clément Delangue is quoted in OpenAI's blog post, calling on the AI industry to work more collaboratively.

It is clear that advanced AI models are remarkably capable of discovering and exploiting ways to attack real-world systems.

4 days, 23 hours назад @ bitdefender.com
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

How 14 orders of Chicken McNuggets helped nail a suspected Russian hacker with Graham Cluley and special guest James Ball.

I had a vindaloo, Graham Cluley, and I don't think it ever touched capsicum.

Yeah, I think you're right.

If you use Suno music, people say, you know, you're killing music.

I don't know much about Shai Hulud.

5 days, 14 hours назад @ grahamcluley.com
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Ukraine's computer emergency response team, CERT-UA, has warned that Russian hackers are using fake CAPTCHA checks to trick people into compromising their own PCs.

The Kremlin-backed Sandworm hacking group is reportedly leveraging fake CAPTCHA checks on compromised websites that persuade users to execute a PowerShell command on their computers - tricking them into running malicious code.

The latest attacks begin when a user visits a compromised webpage, where they're greeted by a fake CAPTCHA claiming they need to complete an extra step to prove that they are human.

Instead, the fake CAPTCHA instructs the user to copy and paste a PowerShell command into their Windows computer.

They are a pr…

1 week назад @ bitdefender.com
Google’s Gemini lets strangers send messages from your locked Android phone
Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini lets strangers send messages from your locked Android phone

Someone gets hold of your locked Android phone and, despite not knowing your security PIN, they can send messages via SMS or WhatsApp pretending to come from you.

It is clear that Google has patched Gemini lock screen issues before, but security researchers keep finding new ways through.

The latest vulnerability is different from the previous similar Gemini-based Android lock screen bypass bugs that have been plaguing the operating system since September 2025.

To do that:Open the Gemini app, tap your profile picture, go to Settings, and select "Gemini on lock screen."

Every new capability Gemini is given at the lock screen is also a new potential attack surface.

1 week, 3 days назад @ bitdefender.com
Anubis ransomware: what you need to know
Anubis ransomware: what you need to know

The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.

1 week, 4 days назад @ fortra.com
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

That is a really, really busy street potentially.

I don't know what the difference is between a tuk-tuk and a rickshaw.

I don't know.

Yeah, it's got to be a Bluetooth transmitter from the battery, and within the battery there's an operating system or something that'll need updating.

It's really, really great.

1 week, 5 days назад @ grahamcluley.com
The ransomware negotiator who was working for the other side
The ransomware negotiator who was working for the other side The ransomware negotiator who was working for the other side

When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help.

Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf.

41-year-old Martino worked as a ransomware negotiator for DigitalMint, an incident response company based in Chicago.

The ransomware victim, a hospitality company, ultimately paid out nearly US $16.5 million.

The company has since changed the way its negotiators communicate with ransomware gangs, and is working with the Department of Homeland Security to establish a registry for the currently highly-unregulated world of ransomware negotiation.

2 weeks назад @ bitdefender.com
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk

Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role?

Security experts have uncovered a phishing campaign which impersonates over 30 well-known brands in fake job interviews designed to steal Google account passwords.

When victims click on "Continue with Google," a pop-up appears that looks like a legitimate Google authentication dialog.

In the past the FBI has warned the public about scammers using fake job ads to steal money and personal information from applicants.

Earlier this year, Hot for Security published a guide explaining how many fake recruiter scams work, and how to avoid them.

2 weeks, 5 days назад @ bitdefender.com
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself

These stories appear different, but they're actually telling the same story.

I'm going to flag, I'm going to flag the point that I made earlier is that operational security isn't always there.

I know how to do this because it's done it for me, but I don't actually know how to apply it logically.

And when the technology you're relying on to protect you, and in some people's case it is protecting their life, and you're not doing it to the best of your ability, that's, that's really, really disappointing.

But I guess for now, all eyes are on Apple and how they're going to respond to this, albeit 13 months later.

2 weeks, 5 days назад @ grahamcluley.com
Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud
Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud

Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims.

According to a police press release, victims were duped into entering their payment card details on bogus phishing websites.

Investigators believe the arrested men, who have not been named, did not just misuse the stolen payment card details themselves, but also passed them on to other fraudsters.

Card payment fraud was found to be the single most common category, with over half a million fraudulent transactions (up more than a quarter on the year before).

In 2024, just 1% of Dutch fraud victims recovered their money, and while arou…

3 weeks назад @ bitdefender.com
The Gentlemen ransomware: what you need to know
The Gentlemen ransomware: what you need to know

Who Are The Gentlemen?

Despite the impeccably polite name, there is nothing polite or refined about this particular gang of cybercriminals. Read more in my article on the Fortra blog.

3 weeks, 4 days назад @ fortra.com
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack? Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?

And I'm going to be looking at whether you're wise to take a gamble with your security on Polymarket.

Right, well, I want to tell you about a company that's built its entire brand on being really, really good at predicting the future.

They've actually done it really, really well.

So it's The Summer Portraits by— remind me who it's by again, 'cause I'm going to butcher his name.

It's really, really good.

3 weeks, 5 days назад @ grahamcluley.com
Scammers race to cash in on Venezuelan earthquake disaster
Scammers race to cash in on Venezuelan earthquake disaster Scammers race to cash in on Venezuelan earthquake disaster

When a devastating earthquake struck north central Venezuela last week, rescue teams were not the only ones who mobilised fast.

Researchers at threat intelligence firm WhoisXML API say that they uncovered 212 newly-registered domains referencing the earthquake, all of which had been filed within five days of the disaster.

Even years after a natural disaster scammers can still exploit human misery.

And that's because exploitation of a major news event - whether it be a natural disaster of otherwise - can be a successful lure for criminals to deploy when defrauding the unwary out of their savings.

And when a natural disaster creates an urgent need for response, it is all the easier for cyberc…

3 weeks, 6 days назад @ bitdefender.com
USB drives carrying China-linked malware infected Japanese military networks for nearly a year
USB drives carrying China-linked malware infected Japanese military networks for nearly a year USB drives carrying China-linked malware infected Japanese military networks for nearly a year

Leaked internal documents have revealed that for nearly a year Japan's Ground Self-Defense Force (JGSDF) used counterfeit USB flash drives infected with malware on computers connected to sensitive military networks.

The USB drives have been linked to Chinese hacking operations, according to an investigation by Nikkei Asia.

Subsequent investigations found that six out of eight USB drives tested contained the same malicious code.

The infected USB drives had been attached to over 50 computers, with nearly half of those systems used to handle classified data, including information about the movement of troops.

The counterfeit drives, priced 30 to 50 percent below authentic brands, were traced t…

4 weeks назад @ bitdefender.com
Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup
Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup

Smashing Security, Episode 473: How a Hacker Could Have Rickrolled the Entire World.

You think, oh, hang on, they're going to ask me for a password or they're going to ask me for something like that.

Yeah, we'll take that money from under your bed and store it in a safety deposit box that you don't know where it is.

We saw a huge number of CVEs last year and with Mythos and the Frontier models, we think that's going to continue to spike.

So the blast radius of these IT service providers is really, really big.

1 month назад @ grahamcluley.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 1 day, 1 hour назад
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e1896b8624f52547d7aa4a3bebd90c3cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-27T16:00:28+03:00Config id: 291Faithfully yours, nginx.

1 day, 1 hour назад @ kaspersky.ru
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 30ce39da164ccbcb4068b4e06c4c1e60Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-24T19:00:11+03:00Config id: 291Faithfully yours, nginx.

3 days, 22 hours назад @ kaspersky.ru
Инциденты с атаками на ИИ-агентов в бизнесе | Блог Касперского
Инциденты с атаками на ИИ-агентов в бизнесе | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: abb2f672b0aebacf96a83f072ddf5be5Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-23T15:00:29+03:00Config id: 290Faithfully yours, nginx.

5 days, 2 hours назад @ kaspersky.ru
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 29288682927681f45f4ebe45b92c4f9dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-22T15:00:12+03:00Config id: 290Faithfully yours, nginx.

6 days, 1 hour назад @ kaspersky.ru
ConsentFix: новая вариация ClickFix
ConsentFix: новая вариация ClickFix

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 92f538b35cc9db0cd8268f0e9c690524Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-21T12:00:10+03:00Config id: 290Faithfully yours, nginx.

1 week назад @ kaspersky.ru
Как защитить свои данные после расставания | Блог Касперского
Как защитить свои данные после расставания | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7c4859afeb6714d16332cd516cc382ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-20T13:00:34+03:00Config id: 290Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
Кража почты через OAuth | Блог Касперского
Кража почты через OAuth | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 89a6c1c61d71bc406a42bd2d91dc48b6Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-17T15:00:29+03:00Config id: 290Faithfully yours, nginx.

1 week, 4 days назад @ kaspersky.ru
Промпт-атаки на умного помощника Gemini и ИИ-ассистента Gemini Workspace | Блог Касперского
Промпт-атаки на умного помощника Gemini и ИИ-ассистента Gemini Workspace | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 9e57da73febcf1364991851b3ffd4607Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-16T15:00:15+03:00Config id: 290Faithfully yours, nginx.

1 week, 5 days назад @ kaspersky.ru
Ключевые уязвимости Microsoft Patch Tuesday за июль 2026 | Блог Касперского
Ключевые уязвимости Microsoft Patch Tuesday за июль 2026 | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: ad5fb1fb73f446dedef7d1ec45313d70Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-15T17:00:41+03:00Config id: 289Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Meta* включила и тут же отключила функцию генерации ИИ-изображений на основе пользовательского контента в Instagram** | Блог Касперского
Meta* включила и тут же отключила функцию генерации ИИ-изображений на основе пользовательского контента в Instagram** | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: d28ecbce6fae6b24393f114511aa53c1Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-14T15:00:39+03:00Config id: 282Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Борьба с BEC-атаками на базе ИИ | Блог Касперского
Борьба с BEC-атаками на базе ИИ | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 0f43fc04a64ef8b4198bfe5f08f75233Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-13T17:00:32+03:00Config id: 281Faithfully yours, nginx.

2 weeks, 1 day назад @ kaspersky.ru
Что не так с функцией NameTag в умных очках Meta* и почему ее стоит опасаться | Блог Касперского
Что не так с функцией NameTag в умных очках Meta* и почему ее стоит опасаться | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 36cc4a8142dd177820e529f1c74777d2Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-09T14:00:09+03:00Config id: 281Faithfully yours, nginx.

2 weeks, 5 days назад @ kaspersky.ru
Целевой фишинг на производственные компании | Блог Касперского
Целевой фишинг на производственные компании | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 1ce0e45ab895fdb2ea63e5f66838efb9Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-08T18:00:10+03:00Config id: 281Faithfully yours, nginx.

2 weeks, 5 days назад @ kaspersky.ru
Почему капча скоро исчезнет: как ИИ изменил проверку на человечность | Блог Касперского
Почему капча скоро исчезнет: как ИИ изменил проверку на человечность | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 26a02984b49c814d5538d529e6b61e94Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-06T15:00:25+03:00Config id: 280Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Неотключаемый бэкдор в роботах-газонокосилках Yarbo | Блог Касперского
Неотключаемый бэкдор в роботах-газонокосилках Yarbo | Блог Касперского Неотключаемый бэкдор в роботах-газонокосилках Yarbo | Блог Касперского

Но в совершенно ином масштабе: в режиме газонокосилки данный робот может обслуживать территории до 2,5 гектар (это 250 соток, то есть небольшой садовый кооператив), а в режиме транспортировщика поддерживает угодья площадью до 12,5 гектар.

Вместе с исследователем Андреасом Макрисом они провели эксперимент, в рамках которого исследователь, будучи в Германии, удаленно захватил контроль над газонокосилкой Yarbo и переехал журналиста, лежащего на газоне у себя в США.

Чаще всего в качестве операционной системы в них используется Linux — и роботы Yarbo тут не исключение.

При этом серийные номера устройств имеют предсказуемый формат и используются в инфраструктуре Yarbo в качестве идентификаторов р…

3 weeks, 5 days назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 22 часа назад
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes

This provides an opportunity for defenders: if we assume our controls will fail at some point, we can build a much more resilient architecture.

When you assume the current layer will eventually be bypassed, you start designing the next layer proactively instead of reactively.

Defenders need to advance their controls by mapping them to the adversaries’ capabilities then assume that control will fail.

Map your controls to the attack chain.

Call to Action:If you haven’t watched the full video yet, go check it out: Assuming Failure Provides Better Defensive Outcomes (bonus elements around SOC of the Future and business context).

22 часа назад @ blogs.cisco.com
The Journey towards Logically Air-Gapped Deployment
The Journey towards Logically Air-Gapped Deployment The Journey towards Logically Air-Gapped Deployment

Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter.

This “Logically Air-Gapped” governance model reaches its full operational potential through the implementation of “Live Protect.” As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution.

Reference ArchitectureDigital autonomy is thus exercised by shifting network and security control into the operating system kernel.

Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a un…

3 days, 22 hours назад @ blogs.cisco.com
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall

That is why we are introducing Firewall Migration Manager by Cisco, an enterprise-ready product built for that reality.

What Is Firewall Migration Manager?

Firewall Migration Manager is a dedicated migration application that you run in your own environment.

How Firewall Migration Manager WorksThe migration process follows a clear, guided workflow.

Intelligent, integrated migration: Firewall Migration Manager will also come to Cisco Cloud Control, and AI will play an increasing role in guiding teams before and during migration.

4 days, 22 hours назад @ blogs.cisco.com
We third-party tested our firewall built for AI-scale. The test tools hit their limit first.
We third-party tested our firewall built for AI-scale. The test tools hit their limit first. We third-party tested our firewall built for AI-scale. The test tools hit their limit first.

In independent testing with NetSecOPEN, the Cisco Secure Firewall 6160 delivered AI-scale inspected throughput beyond what the tools built to measure it could register, all while blocking 100% of tested threats.

These results are specific to Cisco Secure Firewall 6160, but the software capabilities behind Cisco Firewall, including advanced threat protection and high-performance inspection, extend across Cisco Firewall form factors in the cloud, virtually, and on-premises, from campus to data center.

Performance passed the previous benchmark by 5XInspection was turned on, and the test tools built to measure throughput hit their limit before the 6160 firewall did.

In previous NetSecOPEN testi…

1 week, 5 days назад @ blogs.cisco.com
SharpHound Recon Attack – How AI enhanced the threat hunt
SharpHound Recon Attack – How AI enhanced the threat hunt SharpHound Recon Attack – How AI enhanced the threat hunt

We innovated by giving the Agentic SOC access to Endace’s always-on, full packet capture, and asked the agent to assess a potential SharpHound Recon attack that we had seen while threat hunting.

This blog explores how we built the integrations and how AI helped us with our threat hunt and threat assessment.

Agentic AI Massively Speeds our AnalysisAt this point, we decided to use Agentic AI capabilities to investigate and assess this potential threat.

ConclusionThe Agentic SOC, blending Agentic AI built into Endace’s products with custom agentic tools, is a massive boost to productivity and security.

AcknowledgementsOur thanks go to the Cisco SOC team led by @Jessica Oppenheimer and @Ivan Be…

2 weeks, 6 days назад @ blogs.cisco.com
Machine Speed, Human Judgement: How AI Changed the SOC in 2026
Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Machine Speed, Human Judgement: How AI Changed the SOC in 2026

Having spent time in the Cisco Live Americas 2026 SOC, one thing became abundantly clear:The way SOCs operate today is fundamentally different from even a few years ago.

Instead of spending time gathering information, analysts could spend more time understanding what the information actually meant.

Just as spreadsheets empowered business users decades ago, AI-assisted coding is beginning to empower security analysts today.

At Cisco Live, AI was already present throughout the workflow:Incident summaries generated automatically within XDR.

And based on what I saw at Cisco Live 2026, that future has already arrived.

2 weeks, 6 days назад @ blogs.cisco.com
Elevating Expertise in the SOC
Elevating Expertise in the SOC Elevating Expertise in the SOC

The new SOC analysts were great at finding evidence, helped with triage and correlation by the AI agents in the SOC architecture.

With the advancements in Cloud Control, our new SOC Analysts can validate their hypothesis.

They had the ability to investigate the incident and find the root cause found in Splunk Security and Endace.

Instant Attack VerificationIn each Incident, the SOC Analysts is given an AI generated Summary stitching all the relevant logs from all the sources that are related to the objects in question.

Check out the blogs by the engineers who worked inside the SOC at Las Vegas:

2 weeks, 6 days назад @ blogs.cisco.com
Educate at Event Speed: Cisco Live Security Operations Center
Educate at Event Speed: Cisco Live Security Operations Center Educate at Event Speed: Cisco Live Security Operations Center

At Cisco Live AMER 2026 in Las Vegas, my work with the Cisco Event SOC centered on one outcome that makes these deployments valuable beyond the event itself: Education.

The SOC protects the conference, but it also turns live operations into a learning environment through SOC tours, Cisco Live sessions, training inside the SOC, and conversations in the World of Solutions.

Bringing live SOC lessons into the classroomEducation also happened in the sessions I delivered at Cisco Live.

Cisco Live AMER 2026 reinforced that the SOC is one of the best classrooms we have because it teaches through real operations.

For a deeper look at the model behind these deployments, read the Cisco Event SOCs: A R…

2 weeks, 6 days назад @ blogs.cisco.com
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

Inside the Cisco Live SOCAt Cisco Live AMER, the Security Operations Center (SOC) is more than a demo environment.

For a broader look at how the Cisco Live SOC operates, read this overview.

Another part was spent in the SOC, working real investigations with XDR, Splunk Enterprise Security, firewall events, DNS telemetry, packet data, and AI assistance.

AI can help a product manager become useful faster in a live SOC.

That is the bar I want us to continue building toward as we build Cisco XDR and Splunk Security.

2 weeks, 6 days назад @ blogs.cisco.com
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC

As part of the Cisco XDR (Extended Detection and Response) product engineering group, a few of us got exactly that chance.

Every product had a part to play for a network as traffic-heavy as Cisco Live.

(PS : Flaunting the SOC T-shirts was fun)AcknowledgementsA heartfelt thank you to Cisco and the entire SOC team — you are all amazing.

To the Cisco XDR , Splunk , Secure Access , and Secure Firewall engineering teams.

Check out the other blogs from our team at the Cisco Live Americas 2026 SOC at Las Vegas:

2 weeks, 6 days назад @ blogs.cisco.com
The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth
The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth

We built an Experience Score model on Cisco and Splunk infrastructure and watched it run against real traffic, at real scale, in real time.

The result was a working model for how leaders measure what customers feel, act before friction surfaces, and tie operational decisions to revenue and trust.

At Cisco Live, the Experience Score model organized that architecture around four questions business and technology leaders can answer together.

The composite Experience Score tells a leader whether the experience is healthy enough to protect the moments the business depends on.

From Cisco Live to LA28Cisco Live was a rehearsal for larger exposure surfaces, where digital experience, revenue, brand …

2 weeks, 6 days назад @ blogs.cisco.com
AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026
AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026

And we kept thinking the same engineer thought: this flow is so consistent… could an agentic agent do the first 90%?

It was a great experiment — and a glimpse of a fully self-hosted agentic SOC — but for the event we pivoted to Claude Opus 4.8 running through Claude Code.

The division of labor we landed on: Tier-1 agentic SOC was already handled beautifully by the AI features in our own products — XDR’s Agentic Attack Storyboard and Splunk’s Triage Agent.

What does an agentic SOC actually need?

The MCP servers — an Endace MCP for packet capture/decode and a Splunk MCP for running queries.

2 weeks, 6 days назад @ blogs.cisco.com
Building the Agentic SOC at Cisco Live Americas 2026
Building the Agentic SOC at Cisco Live Americas 2026 Building the Agentic SOC at Cisco Live Americas 2026

Building on the Cisco Live EMEA SOC, Cisco Live Americas placed the Security Operations Center (SOC) and Network Operations Center (NOC) at the center of the World of Solutions, demonstrating the power of Cisco in bringing Networking, Security and Observability together.

The Cisco Live Americas Agentic SOC architecture shows how a “One Cisco” approach brings different security tools together to eliminate data silos, in close partnership with the NOC.

The SOC at Cisco Live was set up in just two days, thanks to lessons learned and continuous evolution.

For Cisco Live AMER, we treated agentic AI as an auditable review layer across the SOC, not as a replacement for analysts.

Agentic SOC: Incid…

2 weeks, 6 days назад @ blogs.cisco.com
Ten Years in the SOC at RSAC: What We Learned in 2026
Ten Years in the SOC at RSAC: What We Learned in 2026 Ten Years in the SOC at RSAC: What We Learned in 2026

Cisco Security and Splunk Security released the Findings Report from the Security Operations Center at RSAC 2026 Conference.

This year marked the 10th year of the SOC at RSAC.

Those lessons helped inform the Agentic SOC work that followed at Cisco Live Americas 2026.

The SOC used Cisco AI Defense to gain visibility into generative AI application usage and to help protect on-premises AI models running in the SOC in a Box.

Download the full RSAC 2026 SOC Findings Report to see the architecture, metrics, investigations, lessons learned, and recommendations from the 10th year of the SOC.

3 weeks, 5 days назад @ blogs.cisco.com
Uplevelling Black Hat Threat Hunters
Uplevelling Black Hat Threat Hunters Uplevelling Black Hat Threat Hunters

More telemetry means better visibility – but also more data for threat hunters to sift through.

Then came an important decision: Focus on what matters for detection of threats at Black Hat.

Enriching with Network Context and reducing noiseA file submitted via HTTP doesn’t exist in isolation – it has network context.

It was about:Surfacing high-risk submissions automaticallyProviding network context for faster triageHelping threat hunters dismiss noise fasterThis workflow is far from perfect.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

1 month назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 20 часов назад
Rethinking security for the age of AI
Rethinking security for the age of AI Rethinking security for the age of AI

The approaches built for a world of human actors cannot keep pace with a world of AI, agents and machine-speed attacks.

Microsoft transforms its breadth of visibility, threat intelligence and security expertise into a security context that connects security data, knowledge and semantics across the digital estate.

By grounding every interaction in this rich security context, Project Perception improves the accuracy and consistency of reasoning while reducing the time, compute and cost required to operate at scale.

Our security researchers continuously assess models against real-world security workflows, enabling us to match each task with the model that delivers the best outcome.

Tags: AI, P…

20 часов назад @ blogs.microsoft.com
Enhancing AI security through global AI red teaming
Enhancing AI security through global AI red teaming Enhancing AI security through global AI red teaming

Microsoft’s AI Red Team has observed that meaningful testing of advanced AI systems- and models similarly requires broader participation from researchers and practitioners who operate outside traditional corporate security boundaries.

To address that gap, today we are announcing the External Red Team Alliance (EXTRA), a formalized global extension of Microsoft’s AI Red Team designed to support and encourage external expertise to advance AI safety and security testing.

Building a global allianceEXTRA is a two-part initiative focused on expanding AI safety research and strengthening external collaboration.

The first component supports a global academic network focused on advancing AI safety a…

21 час назад @ microsoft.com
Email threat landscape: Q2 2026 trends and insights
Email threat landscape: Q2 2026 trends and insights Email threat landscape: Q2 2026 trends and insights

Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs.

Q2 AiTM token compromise April phishing campaign tactics, detections, and mitigations ›This blog provides a view of email threat activity across the second quarter of 2026, highlighting key trends in phishing techniques, payload delivery, and threat actor behavior observed by Microsoft Threat Intelligence.

email threat landscape Q1 trends that shaped Q2 activity ›Figure 1.

Trend of QR code phishing attacks by weekly volume (January 2026–June 2026)The delivery methods used in QR code attacks shifted notably during Q2.

To he…

4 days, 22 hours назад @ microsoft.com
Email threat landscape: Q2 2026 trends and insights
Email threat landscape: Q2 2026 trends and insights Email threat landscape: Q2 2026 trends and insights

Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs.

Q2 AiTM token compromise April phishing campaign tactics, detections, and mitigations ›This blog provides a view of email threat activity across the second quarter of 2026, highlighting key trends in phishing techniques, payload delivery, and threat actor behavior observed by Microsoft Threat Intelligence.

email threat landscape Q1 trends that shaped Q2 activity ›Figure 1.

Trend of QR code phishing attacks by weekly volume (January 2026–June 2026)The delivery methods used in QR code attacks shifted notably during Q2.

To he…

4 days, 22 hours назад @ microsoft.com
Real world incident response: Microsoft and AXA XL strengthen cyber resilience
Real world incident response: Microsoft and AXA XL strengthen cyber resilience Real world incident response: Microsoft and AXA XL strengthen cyber resilience

That experience continues to shape how we design Defender Experts Cybersecurity Incident Response—and how we work with partners like AXA XL.

Incident response must extend beyond technologyAs a global insurance provider, AXA XL plays a critical role in helping organizations navigate cyber risk and response.

AXA XL’s strategic partnerships with cyber incident response providers underscore our commitment to expertise, preparedness, and resilience.

Incident response engineered for high-stakes moments—and the readiness behind themWhat differentiates Microsoft Defender Experts Cybersecurity Incident Response is not only its deep technical expertise, but its direct connection to Microsoft engineer…

5 days, 21 hours назад @ microsoft.com
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

Follow the research in the Black Hat BriefingsMicrosoft Security researchers will also present peer-reviewed technical research in the Black Hat Briefings.

Visit booth #2144 for research, community, and hands-on defenseThis year we are transforming the Microsoft Security booth into a community center.

Partner presenceAt Black Hat 2026, the Microsoft booth will feature 13 partners from the Microsoft Intelligent Security Association (MISA) who will showcase solutions built with Microsoft Security technology.

Skill up before and after Black HatYou do not need to be in Las Vegas to take part in the broader Microsoft Security Black Hat experience.

The Microsoft Black Hat Skilling Challenge begin…

1 week, 3 days назад @ microsoft.com
ACR Stealer: Two observed intrusion chains amid increased threat activity
ACR Stealer: Two observed intrusion chains amid increased threat activity ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments.

Security teams should prioritize monitoring for ClickFix lures, suspicious WebDAV activity, obfuscated PowerShell execution, and attempts to access browser credential stores.

Microsoft Defender XDR detectionsMicrosoft Defender XDR customers can refer to the list of applicable detections below.

]art Payload hosting siteReferencesLearn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelligence community about the ev…

1 week, 4 days назад @ microsoft.com
ACR Stealer: Two observed intrusion chains amid increased threat activity
ACR Stealer: Two observed intrusion chains amid increased threat activity ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments.

Security teams should prioritize monitoring for ClickFix lures, suspicious WebDAV activity, obfuscated PowerShell execution, and attempts to access browser credential stores.

Microsoft Defender XDR detectionsMicrosoft Defender XDR customers can refer to the list of applicable detections below.

]art Payload hosting siteReferencesLearn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelligence community about the ev…

1 week, 4 days назад @ microsoft.com
Least privilege for AI agents: Identity, access, and tool binding
Least privilege for AI agents: Identity, access, and tool binding Least privilege for AI agents: Identity, access, and tool binding

When an agent operates without a managed identity and least-privilege role-based access controls (RBAC), it can access or modify sensitive data beyond intended permissions if controls are not properly configured.

Organizations are deploying agentic capabilities (multi-step automation, delegated actions, tool use) faster than their identity and authorization models are evolving to safely constrain them.

The right mental model is to treat every agent as a first-class principal: give it a lifecycle-managed identity, assign explicit roles, scope its permissions tightly, and scope tool usage to a preconfigured tools manifest or configuration.

In the next 30–90 days, inventory your agent identiti…

1 week, 4 days назад @ microsoft.com
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

On July 14, 2026, Microsoft Threat Intelligence identified a coordinated supply chain compromise of the @asyncapi npm organization, a widely used set of packages for the AsyncAPI specification and code generation.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories a…

1 week, 5 days назад @ microsoft.com
Turning threat intelligence into decisive action with Defender Experts
Turning threat intelligence into decisive action with Defender Experts Turning threat intelligence into decisive action with Defender Experts

Today we’re announcing a new service, Microsoft Defender Experts Threat Intelligence, and we are expanding Microsoft Defender Experts MDR to include new third-party and multi-cloud coverage.

Microsoft Defender Experts Threat Intelligence is a new, expert-delivered service that closes that distance.

Defender Experts MDR provides a fully managed detection and response service that reduces noise, adds expert context, and drives action.

This expanded coverage is available through Microsoft Defender Experts MDR Plan 2.

Everything available today as Defender Experts for XDR carries forward unchanged as Microsoft Defender Experts MDR Plan 1, while Plan 2 extends that same expert-led triage, invest…

1 week, 5 days назад @ microsoft.com
Turning threat intelligence into decisive action with Defender Experts
Turning threat intelligence into decisive action with Defender Experts Turning threat intelligence into decisive action with Defender Experts

Today we’re announcing a new service, Microsoft Defender Experts Threat Intelligence, and we are expanding Microsoft Defender Experts MDR to include new third-party and multi-cloud coverage.

Microsoft Defender Experts Threat Intelligence is a new, expert-delivered service that closes that distance.

Today we’re announcing that Microsoft Defender Threat Intelligence (MDTI) capabilities are now fully converged into the Defender portal.

Defender Experts MDR provides a fully managed detection and response service that reduces noise, adds expert context, and drives action.

Everything available today as Defender Experts for XDR carries forward unchanged as Microsoft Defender Experts MDR Plan 1, wh…

1 week, 5 days назад @ microsoft.com
Defending SaaS-based applications against ShinyHunters OAuth abuse
Defending SaaS-based applications against ShinyHunters OAuth abuse Defending SaaS-based applications against ShinyHunters OAuth abuse

The resulting quiet persistence and large-scale data access highlight the need for stronger detection, visibility, and governance of OAuth-connected applications and guest user accounts.

New posture and governance capabilities for connected OAuth appsWhile improved detection is critical, recent incidents have also highlighted the need for stronger preventive controls and ongoing governance of OAuth-connected applications.

Complete permission visibility for Salesforce connected apps and external client apps.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Micro…

2 weeks назад @ microsoft.com
Defending SaaS-based applications against ShinyHunters OAuth abuse
Defending SaaS-based applications against ShinyHunters OAuth abuse Defending SaaS-based applications against ShinyHunters OAuth abuse

Complete permission visibility for Salesforce connected apps and external client apps.

Microsoft Defender detectionsMicrosoft Defender customers can refer to the list of applicable detections including new detections powered by the upgraded Microsoft Defender for Cloud Apps Salesforce connector.

This research is provided by Microsoft Defender Security Research, Shruti Ranjit, Doug Cranston, Anand Deshpande, Ronen Rafaeli, and with contributions from members of Microsoft Threat Intelligence.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intel…

2 weeks назад @ microsoft.com
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

Beginning September 1, 2026, Microsoft will begin rolling out passkeys as the default authentication experience in Microsoft Entra ID.

Select a telecom provider in Microsoft Security StoreToday, Microsoft provides the telecom delivery behind SMS and voice authentication natively within Entra ID.

Microsoft Entra ID supports: Synced passkeys, such as passkeys stored in platform credential managers like iCloud Keychain and Google Password Manager.

Device-bound passkeys, such as Microsoft Authenticator passkeys, Entra passkey on Windows, and FIDO2 security keys.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

2 weeks назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 3 months назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

3 months назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

3 months, 2 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

3 months, 2 weeks назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

3 months, 3 weeks назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

3 months, 4 weeks назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

4 months назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

5 months назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

5 months назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

5 months, 1 week назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

6 months назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

7 months, 2 weeks назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

7 months, 2 weeks назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

7 months, 3 weeks назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

7 months, 3 weeks назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

8 months, 1 week назад @ security.googleblog.com