Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 2 часа назад
TargetZimbra шифрует почтовые серверы через одну команду без пароля
TargetZimbra шифрует почтовые серверы через одну команду без пароля TargetZimbra шифрует почтовые серверы через одну команду без пароля

Уязвимость CVE-2026-73570 позволяет атаковать Zimbra через специально подготовленный SMTP-запрос без предварительной авторизации.

2 часа назад @ securitylab.ru
Сентябрьский патч Windows начал ломать доверие к домену
Сентябрьский патч Windows начал ломать доверие к домену

Правильный пароль внезапно перестал гарантировать вход.

2 часа назад @ securitylab.ru
Zero-click RCE сразу в четырёх крупнейших ИИ-агентах Claude Code, Codex, Copilot и Gemini
Zero-click RCE сразу в четырёх крупнейших ИИ-агентах Claude Code, Codex, Copilot и Gemini

Проверенный плагин может превратиться во вредоносный уже после установки.

3 часа назад @ securitylab.ru
Гравитация не смогла убить кота Шрёдингера
Гравитация не смогла убить кота Шрёдингера Гравитация не смогла убить кота Шрёдингера

Подземный эксперимент исключил одну из моделей, объясняющих исчезновение квантовой суперпозиции.

3 часа назад @ securitylab.ru
От взломанного сайта до root всего один шаг. Дыра в Acronis уже пошла в атаки
От взломанного сайта до root всего один шаг. Дыра в Acronis уже пошла в атаки

Уязвимый плагин превращает ограниченный доступ к серверу в полный контроль.

4 часа назад @ securitylab.ru
M8 Ultra плюс Nvidia. Apple изучает возвращение в серверный рынок
M8 Ultra плюс Nvidia. Apple изучает возвращение в серверный рынок

Компания снова присматривается к нише, которую однажды уже покинула.

4 часа назад @ securitylab.ru
Яндекс Карты научились работать без мобильного интернета
Яндекс Карты научились работать без мобильного интернета

Теперь офлайн доступны маршруты на общественном транспорте, автомобиле, велосипеде и пешком.

5 часов назад @ securitylab.ru
6G, спутники и ИИ делят один эфир. США получат $100 млрд из воздуха
6G, спутники и ИИ делят один эфир. США получат $100 млрд из воздуха 6G, спутники и ИИ делят один эфир. США получат $100 млрд из воздуха

Вашингтон готовит крупнейший передел телекоммуникационного пространства.

5 часов назад @ securitylab.ru
5G есть, а iPhone молчит: Минцифры ведет переговоры с Apple об активации связи
5G есть, а iPhone молчит: Минцифры ведет переговоры с Apple об активации связи

Сети пятого поколения уже работают в 16 городах, однако смартфонам Apple требуется разрешение производителя.

6 часов назад @ securitylab.ru
Не предлог отменять голосование: Памфилова рассказала о плане на случай сбоев связи
Не предлог отменять голосование: Памфилова рассказала о плане на случай сбоев связи

ЦИК подготовил дополнительные способы доступа к системе голосования.

6 часов назад @ securitylab.ru
Максимальные 10 баллов. Cisco закрыла эксплуатируемую дыру в центре корпоративной сети
Максимальные 10 баллов. Cisco закрыла эксплуатируемую дыру в центре корпоративной сети

Один запрос позволяет пройти мимо защиты и добраться до максимальных привилегий.

7 часов назад @ securitylab.ru
Один ключ Cloudflare взломал 100000 сайтов
Один ключ Cloudflare взломал 100000 сайтов Один ключ Cloudflare взломал 100000 сайтов

Вредонос подменял страницы на лету, оставляя исходные файлы чистыми.

7 часов назад @ securitylab.ru
Microsoft объяснила, почему Windows 11 потеряла удобства Windows 10
Microsoft объяснила, почему Windows 11 потеряла удобства Windows 10

Microsoft пришлось заново реализовывать привычные функции после полной переработки интерфейса Windows 11.

8 часов назад @ securitylab.ru
Подростковая смартфонозависимость: причины, последствия и лечение
Подростковая смартфонозависимость: причины, последствия и лечение

Современные подростки сталкиваются с сильным социальным напряжением, поэтому они часто «зависают» в телефоне, чтобы развлечься и снять стресс, но в других случаях подростки используют телефоны, чтобы быть в курсе событий. Однако, такое отвлечение от внешнего мира приводит к сильной зависимости.

8 часов назад @ securitylab.ru
Облако оказалось физическим. Amazon признала необратимую потерю доступа после ударов дронов
Облако оказалось физическим. Amazon признала необратимую потерю доступа после ударов дронов

Резервирование AWS столкнулось со сценарием, которого оказалось слишком много даже для нескольких зон доступности.

9 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 1 час назад
Что такое цифровая личность и как её защитить
Что такое цифровая личность и как её защитить Что такое цифровая личность и как её защитить

Цифровая личность включает не только профили в социальных сетях, но и учётные записи, идентификаторы, публикации и накопленные цифровые следы.

В цифровую личность в широком смысле входят:официальные сведения и идентификаторы;учётные записи и средства аутентификации;биометрические данные;публикации и социальные связи в интернете;поведенческие и репутационные данные.

При этом цифровую личность не следует отождествлять с цифровым двойником, цифровым профилем, цифровым следом и цифровой тенью.

Например, в научной статье «Цифровой двойник и цифровая личность: понятие, соотношение, значение в процессе совершения киберпреступлений и в праве в целом» авторы акцентируют внимание на отсутствии законо…

1 час назад @ anti-malware.ru
Будущее на горизонте: как развиваются виртуализация и её защита
Будущее на горизонте: как развиваются виртуализация и её защита Будущее на горизонте: как развиваются виртуализация и её защита

Рассказываем, в каком состоянии рынок средств безопасности для сред виртуализации и что его ожидает в ближайшие годы.

О важности микросегментацииВесной этого года в силу вступил приказ ФСТЭК России № 117, который существенно обновил требования к безопасности.

Это ахиллесова пята для многих ИБ-решений, и в организации микросегментации пропускная способность тоже становится проблемой.

Физическая инфраструктура строится годами, а циклы закупки нужного оборудования длятся месяцами, при этом ИБ- и ИТ-специалисты чётко понимают, какие продукты у них будут и для чего они нужны.

Таким образом, мы видим, что на данном этапе первоначальные сложности, которые неизбежны при внедрении модели, больше отп…

6 часов назад @ anti-malware.ru
А что я получил за эти 50 миллионов? Как измерить пользу DevSecOps для бизнеса
А что я получил за эти 50 миллионов? Как измерить пользу DevSecOps для бизнеса А что я получил за эти 50 миллионов? Как измерить пользу DevSecOps для бизнеса

А потом спросите людей со стороны бизнеса — ответы будут варьироваться от «не знаю» до «так требует регулятор».

Проблема не в инструментах, а в отсутствии понятной коммуникации.

Финансовый директор (CFO) дослушивает и задаёт единственный вопрос: «А что я получил за эти 50 миллионов?».

Это не проблема конкретного CISO — это проблема архитектуры принятых метрик DevSecOps.

Истинное получает приоритет по риску для бизнеса, а не «по баллу CVSS».

23 часа назад @ anti-malware.ru
Вайб-пентест с помощью искусственного интеллекта: готовимся разорять платформы Bug Bounty
Вайб-пентест с помощью искусственного интеллекта: готовимся разорять платформы Bug Bounty Вайб-пентест с помощью искусственного интеллекта: готовимся разорять платформы Bug Bounty

Реализуем вайб-пентестинг на практикеКак и в других подобных задачах, в первую очередь нужны три вещи:ИИ-модель,обвязка (harness),набор инструментов.

Пусть агент работает не с самой инфраструктурой, а с её копией (т. н. disposable clone), например.

Как и человек, ИИ должен знать, какие пароли, ключи доступа и прочие подобные данные ему разрешено применять.. Как и человек, ИИ должен знать, какие пароли, ключи доступа и прочие подобные данные ему разрешено применять.

При этом всё опять же делается непрерывно и в автоматическом режиме, с возможностью задать ограничения или потребовать запроса подтверждений.

Однако самое интересное здесь — вовсе не то, сможет ли ИИ полностью заменить пентестера…

1 day, 5 hours назад @ anti-malware.ru
Как выбрать платформу хранения данных в 2026 году: критерии, TCO и тренды
Как выбрать платформу хранения данных в 2026 году: критерии, TCO и тренды Как выбрать платформу хранения данных в 2026 году: критерии, TCO и тренды

Эксперты в студии AM Live обсудили, как меняются требования к платформам хранения, на что обращать внимание при выборе и как будет развиваться рынок.

Главная задача — определить, какая в компании структура данных и какие требования к хранилищу, и под это подбирать решение.

Вопрос не в объёме данных, а в том, как решать такие задачи.

Это большая отрасль и в мире, и в России.

ВыводыРынок платформ хранения данных в 2026 году переживает трансформацию.

1 day, 23 hours назад @ anti-malware.ru
Социальная инженерия в 2026 году: атаки, обучение сотрудников и Human Risk Management
Социальная инженерия в 2026 году: атаки, обучение сотрудников и Human Risk Management Социальная инженерия в 2026 году: атаки, обучение сотрудников и Human Risk Management

Эксперты в студии AM Live обсудили, как меняются атаки, почему человек остаётся слабым звеном и как выстроить эффективное обучение.

При этом вопрос уже не в том, как научить человека никогда не ошибаться, а в том, как минимизировать цену этой ошибки.

Сотрудник не успевает понять, что это комплексная атака, потому что не готов к такому сценарию.

В третьем опросе выяснилось, что, по мнению зрителей, важно поменять в планах Security Awareness в 2026 году (мультивыбор):Настроить обучение по ролям — 53%.

Про офлайн-безопасность не нужно забывать — на закрытых предприятиях и в организациях другой вид угроз, и это отдельное направление обучающих материалов».

2 days, 23 hours назад @ anti-malware.ru
Обзор CICADA8 Cyber Rating 26.3.1, платформы оценки кибербезопасности контрагентов и ДЗО
Обзор CICADA8 Cyber Rating 26.3.1, платформы оценки кибербезопасности контрагентов и ДЗО Обзор CICADA8 Cyber Rating 26.3.1, платформы оценки кибербезопасности контрагентов и ДЗО

Решение позволяет оценивать кибербезопасность контрагентов, подрядчиков и дочерних организаций, поставляется по модели SaaS и входит в экосистему CICADA8, к которой также относятся CICADA8 ETM, CICADA8 VM и CICADA8 Dependency Firewall.

Лицензирование CICADA8 Cyber Rating 26.3.1Лицензирование CICADA8 Cyber Rating построено по подписочной модели со сроком от одного года.

Добавление организации в избранное в CICADA8 Cyber Rating 26.3.1Такой сценарий используется при первичной оценке нового поставщика, подрядчика или дочерней организации.

Шкала оценки в CICADA8 Cyber Rating 26.3.1По результату оценки платформа формирует рекомендации относительно возможных рисков при сотрудничестве с этим контра…

3 days, 6 hours назад @ anti-malware.ru
Сетевая безопасность контейнеров: тренды, угрозы и требования ФСТЭК России
Сетевая безопасность контейнеров: тренды, угрозы и требования ФСТЭК России Сетевая безопасность контейнеров: тренды, угрозы и требования ФСТЭК России

Согласно представленной статистике, рынок измеряется в миллиардах рублей и, по мнению аналитиков, будет расти очень динамично в ближайшие годы.

Проблемы сетевой безопасности в KubernetesПавел Коростелёв объяснил, что в Kubernetes происходит смешение защиты приложений и инфраструктуры.

Теперь объектом защиты становится не сетевой хост и не среда виртуализации, а среда контейнеризации.

Всё это вместе создаёт весьма интересную картину: нужно очень внимательно следить за сегментацией и в традиционной сети, и в среде виртуализации, и в среде контейнеризации.

Финальный опрос показал, как, по мнению зрителей, должна строиться сетевая безопасность контейнерной инфраструктуры:Подход зависит от архит…

4 days, 1 hour назад @ anti-malware.ru
Обзор SafeERP 4.9.11: комплексная защита cистем ERP
Обзор SafeERP 4.9.11: комплексная защита cистем ERP Обзор SafeERP 4.9.11: комплексная защита cистем ERP

Архитектура SafeERP Extension Module (Комплексная защита 1С)SafeERP Extension Module имеет модульную структуру и предназначен для комплексной защиты информационно-управляющих систем (ИУС), построенных на базе платформы 1С.

Архитектура компонента SafeERP для анализа кодаЯдром компонента SafeERP CS EM является сервер управления.

Архитектура компонента SafeERP для контроля настроек и защиты платформы 1СЯдром компонента SafeERP PS EM также является сервер управления.

Каталог проектов контроля настроек платформы 1С в SafeERP PS EMРисунок 26.

Для компонентов SafeERP CS EM и SafeERP PS EM установлены одинаковые требования к аппаратному и программному обеспечению.

4 days, 7 hours назад @ anti-malware.ru
Что не так со SBOM и как действительно защитить цепочку поставок ПО
Что не так со SBOM и как действительно защитить цепочку поставок ПО Что не так со SBOM и как действительно защитить цепочку поставок ПО

Обычно в SBOM входят:название и версия компонента;поставщик;идентификаторы Package URL (purl) и CPE;зависимости между компонентами;хеш-суммы и сведения о лицензиях.

Если проблема ещё не зарегистрирована в базе уязвимостей или компонент был скомпрометирован, наличие его в SBOM не покажет угрозу.

SBOM анализа (Analyzed SBOM или Binary SBOM) создаётся при анализе готового артефакта: пакета, исполняемого файла или контейнера.

SBOM не описывает происхождение артефакта и не защищает CI/CDSBOM показывает, из каких компонентов состоит программный артефакт.

SBOM нужно проверять на подлинность и целостностьДаже полный SBOM с правильно идентифицированными компонентами не гарантирует, что сам документ …

6 days, 23 hours назад @ anti-malware.ru
Обзор решений EASM (External Attack Surface Management)
Обзор решений EASM (External Attack Surface Management) Обзор решений EASM (External Attack Surface Management)

Именно для этого используются решения класса «управление внешней поверхностью атаки» (External Attack Surface Management, EASM), позволяющие контролировать внешнюю поверхность атаки.

Что такое EASM и для чего используетсяСистема класса «управление внешней поверхностью атаки» (External Attack Surface Management, EASM) — это не разовый пентест и не сетевой сканер.

Также следует упомянуть ASM (Attack Surface Management) как более широкий подход, охватывающий и внешнюю, и внутреннюю поверхность атаки, и CAASM (Cyber Asset Attack Surface Management) — технологический подход, представляющий собой подмножество ASM и обеспечивающий единую актуальную видимость всех киберактивов организации.

Место EA…

1 week назад @ anti-malware.ru
Корпоративные мессенджеры 2026: от чатов к супераппам и ИИ-агентам
Корпоративные мессенджеры 2026: от чатов к супераппам и ИИ-агентам Корпоративные мессенджеры 2026: от чатов к супераппам и ИИ-агентам

Корпоративные мессенджеры перестали быть просто чатами для переписки — сегодня они превращаются в супераппы и становятся ядром взаимодействия людей и ИИ-агентов внутри компаний.

Антон Анпилов добавил, что почта и мессенджеры — это разные паттерны потребления: в мессенджеры пишут быстрое, в почте закрепляют официальное.

Потом запускаются пилотные группы, пользователи оценивают мессенджеры, и в конце наступает этап компромиссов — компания определяет, какие требования действительно критичны, а от каких можно отказаться.

«Slack и Telegram — это очень крутые мессенджеры, это большие продукты, мы все ими пользуемся.

Иван Дьяконов назвал причиной ситуацию, когда компания не выбрала ни одного решен…

1 week, 1 day назад @ anti-malware.ru
Корпоративный ИИ в России: от экспериментов к агентам
Корпоративный ИИ в России: от экспериментов к агентам Корпоративный ИИ в России: от экспериментов к агентам

Где ИИ применяют и считают эффективнымПо данным исследования, чаще всего ИИ применяют в контакт-центрах и службах поддержки — об этом сообщили 75% опрошенных компаний.

«В страховых компаниях, — поясняет он, — инвестиционный анализ раньше требовал дорогих специалистов, которые умели и разбираться в ситуации, и доходчиво объяснять происходящее.

По его словам, проблема не только в процессах и данных, но и в том, как измерить сам результат.

Поэтому основная сложность заключается не только в запуске пилота, но и в его доведении до промышленной эксплуатации.

Полностью автономные решения (без участия человека) внедряют 25% компаний — но в проде они задействованы только у 8%.

1 week, 2 days назад @ anti-malware.ru
Как выбрать российский NGFW в 2026 году: тренды, критерии и прогнозы
Как выбрать российский NGFW в 2026 году: тренды, критерии и прогнозы Как выбрать российский NGFW в 2026 году: тренды, критерии и прогнозы

В любом случае российское решение отличается от западного — есть небольшие отличия в инфраструктуре и в подходах.

Виталий Беличко добавил, что в прошлом году все вендоры бурно наращивали функциональность, но следующим этапом стала проработка деталей.

Это и тренд, и много маркетинга в это вкладывается».

Мы обрабатываем эти данные в KSN и передаём их во все продукты, которые к нему подключены, в том числе и в NGFW.

ВыводыРынок российских NGFW в 2026 году прошёл этап становления и вступает в фазу зрелой конкуренции.

1 week, 3 days назад @ anti-malware.ru
Как Томск стал центром кибербезопасности и что меняет приказ ФСТЭК № 117: форум «КиберV» 2026
Как Томск стал центром кибербезопасности и что меняет приказ ФСТЭК № 117: форум «КиберV» 2026 Как Томск стал центром кибербезопасности и что меняет приказ ФСТЭК № 117: форум «КиберV» 2026

Обсудили как региональные компании выходят на федеральный рынок, где искать специалистов и что меняется в ИБ с развитием ИИ.

Чтобы посмотреть, как сегодня устроена кибербезопасность за пределами столицы, команда AM Live также отправилась в Томск и посетила пятый юбилейный форум по кибербезопасности «КиберV».

Юбилейный форум «КиберV» собрал команды и компании, которые в обычной работе могут решать совершенно разные задачи, но в вопросах кибербезопасности оказываются по одну сторону.

Представитель ФСТЭК ответил на вопросы участников и отдельно подчеркнул, что не стоит заранее пугать себя новыми требованиями.

Мы пересматриваем информационные потоки, подходы к созданию новых информационных сист…

1 week, 3 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 55 минут назад
SQL-инъекция через декомпиляцию: от JAR-файла до захвата пароля
SQL-инъекция через декомпиляцию: от JAR-файла до захвата пароля SQL-инъекция через декомпиляцию: от JAR-файла до захвата пароля

Автор статьи: Юрий Гришаев - специалист по анализу защищённости веб-приложений и ПО под Windows.

Все работы велись легально, в рамках пентестов, которые мы проводили в АБП2Б для наших клиентов с письменного согласия владельца системы и в изолированном контуре.

Минимальный запрос в уязвимую ветку:https://:8443/servlet/ReportExportServlet?minQty=1&warehouseId;=1Соберет SQL:select distinct(SKU) from WMS_STOCK_ITEMS where WAREHOUSE_ID=1 and QTY > 1warehouseId — точка входа.

Одна деталь: после warehouseId в запрос дописывается хвост and QTY > 1.

Дальше — короткий запрос и понятный фикс.

55 минут назад @ habr.com
Угрозы в сетевом трафике, или Что мы нашли в сети за 10 месяцев мониторинга
Угрозы в сетевом трафике, или Что мы нашли в сети за 10 месяцев мониторинга Угрозы в сетевом трафике, или Что мы нашли в сети за 10 месяцев мониторинга

Также в сетевом трафике организаций обнаруживались следы эксплойтов, использующих уязвимости в программном или аппаратном обеспечении (5%).

Этот тип ВПО показывает ложные предупреждения об угрозах или ошибках и предлагает пользователю «решение», например: платную услугу или ПО.

Внедрять код позволяют как постэксплуатационные фреймворки, например Cobalt Strike, так и ВПО, например AgentTesla и Remcos RAT.

Они могут храниться в разных местах системы: в текстовых документах, хранилищах операционной системы или приложений и в других специализированных файлах.

Украденные технологии можно продать конкурентам или в дарквебе, использовать для шантажа или создания собственных продуктов на их основе.

3 часа назад @ habr.com
Федерация корпоративного мессенджера: как связать независимые On-Premise-контуры и сохранить контроль над данными
Федерация корпоративного мессенджера: как связать независимые On-Premise-контуры и сохранить контроль над данными Федерация корпоративного мессенджера: как связать независимые On-Premise-контуры и сохранить контроль над данными

Сотрудникам нужно постоянно общаться с подрядчиками, партнерами и коллегами из дочерних обществ — и желательно не переносить рабочий контекст в публичные сервисы.

Что такое федерация и как устроен доступФедерация связывает независимые инсталляции так, что каждая сохраняет собственные серверы, базу данных, администрирование и политики безопасности, но может обмениваться разрешенными сообщениями, файлами и событиями с другими участниками.

Только допущенные пользователи видят разрешенных сотрудников другой организации, могут начинать с ними диалоги и участвовать в групповых чатах.

Когда пользователь отправляет сообщение внешнему сотруднику или в многоконтурный чат, происходит следующая последо…

3 часа назад @ habr.com
Федерация корпоративного мессенджера: как связать независимые On-Premise-контуры и сохранить контроль над данными
Федерация корпоративного мессенджера: как связать независимые On-Premise-контуры и сохранить контроль над данными Федерация корпоративного мессенджера: как связать независимые On-Premise-контуры и сохранить контроль над данными

Сотрудникам нужно постоянно общаться с подрядчиками, партнерами и коллегами из дочерних обществ — и желательно не переносить рабочий контекст в публичные сервисы.

Что такое федерация и как устроен доступФедерация связывает независимые инсталляции так, что каждая сохраняет собственные серверы, базу данных, администрирование и политики безопасности, но может обмениваться разрешенными сообщениями, файлами и событиями с другими участниками.

Только допущенные пользователи видят разрешенных сотрудников другой организации, могут начинать с ними диалоги и участвовать в групповых чатах.

Когда пользователь отправляет сообщение внешнему сотруднику или в многоконтурный чат, происходит следующая последо…

3 часа назад @ habr.com
Сетевой стек ОС «Нейтрино»: встроенная технология data diode
Сетевой стек ОС «Нейтрино»: встроенная технология data diode Сетевой стек ОС «Нейтрино»: встроенная технология data diode

Одним из наиболее прямых и в то же время радикальных способов обеспечения надёжности и безопасности системы является её изоляция.

Коротко о сетевой подсистеме ОС «Нейтрино»Для тех из читателей, кто ещё не знаком с сетевой подсистемой нашей ОС, сделаем небольшое отступление о том, как она устроена.

Архитектура сетевой подсистемы ОС «Нейтрино»Реализация диода данных на уровне сетевой подсистемыВ следующем релизе ОС «Нейтрино» появится поддержка программного диода данных, обеспечивающего одностороннюю передачу данных, с полным отключением логики приёма.

Однако в этом случае входящие кадры до момента отбрасывания файерволлом всё ещё обрабатываются как сетевым драйвером, так и сетевой подсистемо…

5 часов назад @ habr.com
Фальсификация емайл: возможности и проблемы доказывания, разбор реального кейса
Фальсификация емайл: возможности и проблемы доказывания, разбор реального кейса Фальсификация емайл: возможности и проблемы доказывания, разбор реального кейса

В зависимости от настроек задействованных серверов, отправителю может быть направлена отбивка о том, что письмо не доставлено.

Сторона_Б утверждала, что никакого письма не получала и подтверждала свою позицию отсутствием письма в своем почтовом ящике.

В результате получен емайл по виду и с заголовками, аналогичными Спорному письму, как на клиенте, так и на сервере.

Выводы и рекомендации по противодействию фальсификациямПроведённое исследование позволяет сформулировать ряд практических советов как для участников судебных споров, так и для ИТ-специалистов.

Выстраивание доказывания исключительно на факте наличия письма в папке «Отправленные» у одной из сторон является порочной практикой.

5 часов назад @ habr.com
«Диск зашифрован» отвечает ровно на один вопрос: что будет, если ноутбук выключен
«Диск зашифрован» отвечает ровно на один вопрос: что будет, если ноутбук выключен «Диск зашифрован» отвечает ровно на один вопрос: что будет, если ноутбук выключен

Защищает здесь только экран блокировки, то есть проверка пароля учётной записи, - а это уже совсем другой механизм с другими свойствами.

Разница между «уснул» и «гибернация» - это разница между «ключ в оперативной памяти» и «ключа в оперативной памяти нет».

На старых конфигурациях и в некоторых прошивках эта защита не включена по умолчанию, и стоит проверить, а не предполагать.

Что из этого следует для внутренних правилГибернация вместо сна для мобильных устройств - вместе с ПИН-кодом, а не вместо него.

И на части моделей гибернация просто не работает надёжно - это придётся проверить на своём парке, а не принять на веру.

7 часов назад @ habr.com
«Агент тупит» — это диагноз инструкции, а не модели
«Агент тупит» — это диагноз инструкции, а не модели «Агент тупит» — это диагноз инструкции, а не модели

Каких-то волшебных промптов мы не придумали и не нашли.

Мы запретили агентам писать в инструкциях «раньше тут было X», «это не X, а на самом деле Y», «возможно, legacy».

Это не «будь внимателен» и не «учитывай контекст», а «после такого-то действия проверь такую-то величину, вот номера тикетов, где было иначе».

Безопасность: тут тупая инструкция стоит дорожеОтдельный агент у нас работает не в репозитории, а в чужих базах: пользователь даёт токен своей базы, агент собирает ему приложение.

Абстрактное «не раскрывай конфиденциальные данные» не срабатывает, потому что агент не считает конкретную просьбу подпадающей под абстракцию.

8 часов назад @ habr.com
Как AI используется в NGFW в 2026 году: российские решения и мировой опыт
Как AI используется в NGFW в 2026 году: российские решения и мировой опыт Как AI используется в NGFW в 2026 году: российские решения и мировой опыт

За словами «AI в NGFW» скрываются разные технологииСравнивать межсетевые экраны нового поколения, NGFW (Next-Generation Firewall), по наличию «искусственного интеллекта» почти бессмысленно.

Здесь важно не путать место анализа и точку блокировки: интеграция с NGFW не означает, что все модели работают непосредственно на нём.

Генеративный AI в управленииВ системах управления AI получает другую роль: помогает разобраться в конфигурации и выполнить административную задачу.

UserGate и InfoWatch: не смешивать контроль AI и AI-аналитикуUserGate документирует URL-категорию «Чат-боты искусственного интеллекта / Chat-bot AI» для применения в правилах контентной фильтрации.

Оба AI-сервиса Ideco работаю…

9 часов назад @ habr.com
PhishIntel — инструмент WEB-разведки для сбора публичных данных с сайтов и доменов
PhishIntel — инструмент WEB-разведки для сбора публичных данных с сайтов и доменов PhishIntel — инструмент WEB-разведки для сбора публичных данных с сайтов и доменов

Но так уж получилось, что я его полностью переписал, а значит информацию о возможностях следует обновить.

PhishIntel написан на Python и немного приправлен Go, не требует установки дополнительных библиотек, запускается полностью готовым к бою одной командой.

Ранее PhishIntel включал в отчет работу активных сканеров, но я посчитал это излишеством.

что делаете, хотите изменить стандартные настройки, добавить юзер агентов или прокси, заполните его в соответствии с примером .env.example.

В целом, я хотел сделать простой, удобный и расширяемый инструмент, поэтому буду рад любым отзывам о его работе.

21 час назад @ habr.com
Ваш test — это prod
Ваш test — это prod Ваш test — это prod

Конвейер доставки: ваш CI-раннер — это prodРаннер деплоит в prod — значит, он prod.

Логи prod и test в одном loki допустимы, но раздельными арендаторами.

Чтение боевых журналов с персональными данными из test «для воспроизведения бага» — транзит prod → test через infrastructure , запрещённый 3.2.

Это test → prod , нарушение 3.6.1, и политика по суффиксу имени отрежет её раньше, чем вы дочитаете договор.

И не площадка: test и stage живут в публичном облаке, prod — в собственном ЦОД, но в имени этого нет — площадка ортогональна иерархии и ведётся тегом envspec.io/site (3.7).

23 часа назад @ habr.com
Работа со сторонними библиотеками в Java Card
Работа со сторонними библиотеками в Java Card Работа со сторонними библиотеками в Java Card

В статье «Асимметричная криптография в Java Card» был приведен пример по установке защищенного канала в два этапа:генерация общего секрета по алгоритму ECDH; использование общего секрета в качестве ключа AES.

В сборочном файле build.xml необходимо указать следующее: > 84E60200 20 05A00000008400000EEF0CC602FFFFC702FFFFC802FFFF00E76EBF9967DD7FBD << 00 << 9000 [ OK ] duration: 0.15 Command: LOAD >> 84E80000 FF C482018701000FDECAFFED010204000105A00000008402001F000F001F00120025003E000C009B000A00180000007000000000000003010004002503050107A000000062010100010DA0000000856C69627574696C73000107A0000000620001030012010EA00000008453696D706C65417070001206000C00800301000107010000001F07009B000310188C0003188F…

23 часа назад @ habr.com
LLM не должен читать логи без ограничений: безопасный MCP-шлюз для разбора сбоев
LLM не должен читать логи без ограничений: безопасный MCP-шлюз для разбора сбоев LLM не должен читать логи без ограничений: безопасный MCP-шлюз для разбора сбоев

А зачем?»Ниже — не обзор MCP и не обещание «безопасного ИИ».

Это маленький воспроизводимый шаблон: как дать ассистенту ровно столько доступа, сколько нужно для первичного разбора сбоя, и не больше.

Меняются названия сущностей, но не принцип: модель видит не хранилище целиком, а небольшой набор безопасных вопросов к нему.

Она показывает главное: ассистент не ходит в базу напрямую и не решает сам, какой запрос допустим.

Даже если модель не подчинится этой строке, система не должна давать ей способ выполнить просьбу.

1 day назад @ habr.com
ИИ может уничтожить человечество с вероятностью выше 10%. Чего именно боятся исследователи
ИИ может уничтожить человечество с вероятностью выше 10%. Чего именно боятся исследователи ИИ может уничтожить человечество с вероятностью выше 10%. Чего именно боятся исследователи

Лаборатории измеряют автономность моделей, способность искать уязвимости, обходить ограничения, ускорять исследования в области AI и выполнять другие потенциально опасные действия.

По данным Anthropic, к маю 2026 года Claude написал более 80% кода, который компания добавляла в основную кодовую базу.

AI уже участвует в разработке следующего AI, модели могут автономно действовать, искать обходные пути и в отдельных экспериментах сопротивляться действиям оператора.

Хубингер вообще продолжает работать в Anthropic, но публично говорит, что вероятность уничтожения человечества в ближайшие десять лет лично оценивает выше 10%.

И приходите в телегу — там мои наблюдения, идеи и находки про AI: что ре…

1 day назад @ habr.com
VM в нетипичных средах: АСУ ТП, сеть, IoT, мобильные устройства, железо и ML (перезалив)
VM в нетипичных средах: АСУ ТП, сеть, IoT, мобильные устройства, железо и ML (перезалив) VM в нетипичных средах: АСУ ТП, сеть, IoT, мобильные устройства, железо и ML (перезалив)

Отличия начинаются в деталях, и в АСУ ТП, на сетевом оборудовании, в IoT, на мобильных устройствах, в железе и в системах машинного обучения детали свои.

А если система старая и давно в статусе EoL/EoS, патч на нее и не поставишь, его просто нет.

Контроль: повторное сканирование, сверка версий ПО и снова цифровой двойник.

Систему, про которую нет уверенности, что она переживет сканирование, не трогайте, пока она не в резерве.

Уязвимости на уровне сетиСамая частая проблема на уровне сети: сегментации нет или она сделана неправильно, а в правилах firewall ошибки.

1 day, 2 hours назад @ habr.com
Хакер Хакер
последний пост 1 час назад
Google патчит 0-day-уязвимость в устройствах Pixel
Google патчит 0-day-уязвимость в устройствах Pixel Google патчит 0-day-уязвимость в устройствах Pixel

Разработчики Google выпустили сентябрьские патчи для смартфонов Pixel, исправляющие 110 уязвимостей.

Причем в компании предупредили, что эта проблема уже используется хакерами в целевых атаках.

Подчеркивается, что для эксплуатации уязвимости от владельца Pixel не потребуется никаких действий: ему не нужно переходить по ссылкам, открывать файлы или устанавливать приложения.

Помимо 0-day-уязвимости, сентябрьские патчи исправляют еще 109 проблем в устройствах Pixel.

И еще 46 критических проблем затрагивают различные компоненты Pixel, включая BigOcean, Bootloader, IP Multimedia Subsystem и Trusted Execution Environment.

1 час назад @ xakep.ru
Минфин США ввел санкции против иранской криптобиржи Bitbank
Минфин США ввел санкции против иранской криптобиржи Bitbank Минфин США ввел санкции против иранской криптобиржи Bitbank

17 сентября Министерство финансов США ввело санкции против иранской криптовалютной биржи BitBank.

В список вошли названия BitBank и BitBank3, а также домены bitbank3.com и bitbank.com.

Санкции также коснулись трех физических лиц: Хоссейна Али Закера Хоссейна, Мохаммада Махди Закера Хоссейна и Сейеда Аделя Хейдари.

Ранее, вводя санкции против самой Hormuz Safe, власти также не публиковали адреса кошельков и суммы платежей.

Теперь же Минфин впервые напрямую связал эту схему с BitBank, но подробного разбора транзакций по-прежнему не предоставил.

2 часа назад @ xakep.ru
Банкер KREMLIN ворует учетные данные и сессионные токены из Chrome и Edge
Банкер KREMLIN ворует учетные данные и сессионные токены из Chrome и Edge Банкер KREMLIN ворует учетные данные и сессионные токены из Chrome и Edge

Исследователи из Elastic Security Labs изучили банковскую малварь KREMLIN, которая может без ведома пользователя устанавливать на зараженную машину вредоносные расширения для Chrome и Edge.

Для этого вредонос обходит механизмы контроля целостности Chromium, а затем похищает пароли, файлы cookie, сессионные токены и другие данные.

Одной из главных особенностей KREMLIN является установка расширения AVSync в браузеры Chrome и Edge без участия жертвы.

Для этого малварь дожидается закрытия браузера или завершает его процесс во время простоя, копирует расширение в профиль и включает режим разработчика.

Исследователи пишут, что в отдельных кампаниях злоумышленники дополнительно распространяли Puls…

3 часа назад @ xakep.ru
Троян MovieReaper маскируется под «Одиссею» на торрент-трекерах
Троян MovieReaper маскируется под «Одиссею» на торрент-трекерах Троян MovieReaper маскируется под «Одиссею» на торрент-трекерах

Специалисты «Лаборатории Касперского» обнаружили ранее неизвестную модульную малварь MovieReaper, которая распространяется под видом популярных фильмов, включая «Одиссею».

Вредоносная кампания активна как минимум с середины августа 2026 года и уже затронула несколько сотен пользователей и организаций в разных странах.

Как правило, малварь маскируется под популярные фильмы с помощью длинных имен файлов и иконок известных приложений, например VLC.

Один из вариантов распространялся под именем the odyssey (2026) [1080p] [webrip] [5.1].exe, и специалисты подчеркивают, что длинное название помогает скрыть расширение .exe.

Затем MovieReaper загружает дополнительные модули, обходит контроль учетных…

5 часов назад @ xakep.ru
Мошенники получили данные клиентов Revolut через почту властей Италии и теперь требуют выкуп
Мошенники получили данные клиентов Revolut через почту властей Италии и теперь требуют выкуп Мошенники получили данные клиентов Revolut через почту властей Италии и теперь требуют выкуп

Напомним, что об атаке на Revolut стало известно ранее на этой неделе.

На выплату выкупа хакеры отвели компании 24 часа и пригрозили в противном случае продать украденные данные другим преступным группировкам.

При этом 16 сентября представители Revolut сообщили Reuters, что компания не имела прямых контактов со злоумышленниками и не получала от них требований выкупа.

Ранее в Revolut подчеркивали, что внутренние системы компании не были взломаны, а средства клиентов остаются в безопасности.

Теперь в компании снова подтвердили эту информацию и заявили, что атакующие злоупотребили официальным каналом связи, который используется итальянскими госорганами для юридически значимой переписки.

20 часов назад @ xakep.ru
Хакеры взломали аккаунт HBO Max на Reddit и распространяли ClickFix-рекламу
Хакеры взломали аккаунт HBO Max на Reddit и распространяли ClickFix-рекламу Хакеры взломали аккаунт HBO Max на Reddit и распространяли ClickFix-рекламу

Хакеры скомпрометировали официальный аккаунт HBO Max на Reddit и использовали его для распространения вредоносной рекламы.

Примерно за 48 часов атакующие опубликовали 108 объявлений, которые вели на ClickFix-страницы и заражали устройства под управлением Windows и macOS стилерами и другой малварью.

Специалисты пишут, что одной из основных приманок, которую использовали злоумышленники, стало якобы нативное приложение HBO Max для macOS, которого на самом деле не существует.

В macOS атакующие использовали команды curl | zsh и распространяли сразу несколько пейлоадов, включая стилер MacSync, похищавший учетные данные из браузеров, профили Firefox, данные из Telegram и Apple Notes, пароли macOS …

22 часа назад @ xakep.ru
Суровая малиновая утка. Собираем Rubber Ducky на базе RP2040
Суровая малиновая утка. Собираем Rubber Ducky на базе RP2040 Суровая малиновая утка. Собираем Rubber Ducky на базе RP2040

Имен­но так я и пос­тупил.

Поэто­му он может при­нять мое устрой­ство за кла­виату­ру и счи­тывать с него дан­ные, хотя на самом деле это не она.

Сегод­ня соберем такое устрой­ство и наделим его обратной сов­мести­мостью со скрип­тами для Flipper Zero и USB Rubber Ducky.

Спо­соб, конеч­но, инте­рес­ный, но, на мой взгляд, силь­но уста­рел: при таком под­ходе каж­дый раз при­дет­ся менять пей­лоад через про­шив­ку.

Ты спро­сишь: «А на фига не ори­гинал?» Отве­чу: ори­гинал дороже, а памяти в нем мень­ше — 2 Мбайт про­тив 16 Мбайт.

1 day назад @ xakep.ru
Шлюзы Cisco Secure Email Gateway можно взломать с помощью вредоносного письма
Шлюзы Cisco Secure Email Gateway можно взломать с помощью вредоносного письма Шлюзы Cisco Secure Email Gateway можно взломать с помощью вредоносного письма

Специалисты Cisco исправили критическую уязвимость в Secure Email Gateway — шлюзе, который должен защищать почту от вредоносных сообщений.

Баг затрагивает физические и виртуальные устройства Cisco Secure Email Gateway под управлением AsyncOS независимо от их конфигурации.

Кроме того, специалисты Cisco проверили устройства в облачном сервисе Secure Email Cloud и напрямую связались с клиентами, на чьих шлюзах обнаружили признаки возможной компрометации.

По данным Shadowserver, в интернете доступны более 400 шлюзов Cisco Secure Email Gateway.

Причем с ноября 2025 года злоумышленники эксплуатировали эту проблему как 0-day и взламывали Secure Email Gateway, разворачивая инструменты для закреплен…

1 day, 1 hour назад @ xakep.ru
Denuvo подала в суд на крякера voices38 за обход DRM-защиты
Denuvo подала в суд на крякера voices38 за обход DRM-защиты Denuvo подала в суд на крякера voices38 за обход DRM-защиты

Австрийские разработчики Denuvo подали в суд на анонимного крякера, известного под ником voices38 и специализирующегося на обходе защиты Denuvo Anti-Tamper.

Как сообщает издание TorrentFreak, в иске, поданном в окружной суд Северного округа Калифорнии, утверждается, что voices38 занимается реверс-инжинирингом и взломом игр с защитой Denuvo, а затем распространяет свои релизы, в частности на Reddit.

Так как Denuvo не принадлежат авторские права на сами игры, речь в иске идет не об обычном нарушении авторского права.

В частности, покупки игр в Steam потенциально могут привести к раскрытию платежной информации voices38.

В иске представители Denuvo требуют возмещения ущерба и судебного запрета,…

1 day, 3 hours назад @ xakep.ru
Байт за байтом. Учимся восстанавливать структуры данных с помощью Ghidra и GDB
Байт за байтом. Учимся восстанавливать структуры данных с помощью Ghidra и GDB Байт за байтом. Учимся восстанавливать структуры данных с помощью Ghidra и GDB

Се­год­ня мы раз­берем на прак­тике, как ревер­сировать неиз­вес­тный бинар­ник C++ и вос­ста­нав­ливать скры­тые струк­туры дан­ных по кос­венным приз­накам.

Сов­местим ста­тичес­кий ана­лиз в Ghidra с динами­чес­ким ана­лизом в GDB, про­верим гипоте­зы экспе­римен­тами и раз­берем­ся, как устро­ено хра­нение корот­ких и длин­ных строк в std:: string .

Те­бе дос­таточ­но ска­чать иссле­дуемый бинар­ник и уста­новить инс­тру­мен­ты Ghidra и GDB.

На этом пути я буду напоми­нать, что реверс зас­тавля­ет раз­бирать­ся не толь­ко с бай­тами и регис­тра­ми, но и с собс­твен­ным мыш­лени­ем.

Пос­ле под­твержде­ния гипотез мы соз­дадим кас­томную струк­туру в Ghidra и при­меним ее к иссле­дуемо­му…

1 day, 4 hours назад @ xakep.ru
Хакеры заявили о компрометации инфраструктуры туроператора Tez Tour
Хакеры заявили о компрометации инфраструктуры туроператора Tez Tour Хакеры заявили о компрометации инфраструктуры туроператора Tez Tour

Хак-группа DataSuckers заявила о взломе туроператора Tez Tour.

15 сентября атакующие дефейснули сайт компании и заявили о компрометации серверов, краже пользовательских данных и уничтожении информации.

Представители Tez Tour подтвердили инцидент, но утверждают, что признаков утечки в компании пока не обнаружили.

В Tez Tour описывают последствия атаки иначе.

Туроператор продолжает работу, а в заявлении компании подчеркивается, что Tez Tour выполняет все обязательства перед клиентами и партнерами.

1 day, 5 hours назад @ xakep.ru
Агентов OpenAI связали с атакой на RubyGems
Агентов OpenAI связали с атакой на RubyGems Агентов OpenAI связали с атакой на RubyGems

ИБ-исследователи полагают, что за масштабной спам-кампанией, направленной на RubyGems в мае 2026 года, стоял рой автономных агентов OpenAI.

Атаку на RubyGems обнаружили специалисты Спенсер Киттс (Spencer Kitts), Томас Ларсен (Thomas Larsen) и Сидни фон Аркс (Sydney Von Arx).

В итоге в RubyGems обнаружили более 150 пакетов, которые содержали публичные данные, собранные с британских муниципальных порталов.

Июньская активность агентов в RubyGems дала исследователям дополнительный аргумент в пользу связи с OpenAI.

Дело в том, что агенты обращались к тем же 49 интернет-ресурсам, что и агенты, злоупотреблявшие DSEWiki.

1 day, 20 hours назад @ xakep.ru
Опубликована программа конференции ZeroNights 2026
Опубликована программа конференции ZeroNights 2026 Опубликована программа конференции ZeroNights 2026

В этом году в основных треках Offensive Track и SecOps Track заявлено около 30 технических докладов, а в рамках Community Track пройдут короткие выступления, воркшопы и другие активности.

Исследование получило международное признание, благодарности на SANS Summit в США, и привело к закрытию критических брешей в безопасности крупных телекоммуникационных компаний.

SecOps TrackВ этом треке собраны доклады о защите приложений и инфраструктуры, AppSec, анализе стороннего кода и безопасности платформ.

Спикер расскажет, как организована проверка внешнего кода в Яндекс 360, как в этот процесс интегрирован ИИ, какие проблемы удается находить автоматически и в каких случаях по-прежнему требуется ручн…

1 day, 21 hours назад @ xakep.ru
Расширение для Twitch раскрыло OAuth-токены десятков тысяч пользователей
Расширение для Twitch раскрыло OAuth-токены десятков тысяч пользователей Расширение для Twitch раскрыло OAuth-токены десятков тысяч пользователей

Специалисты компании Socket обнаружили, что браузерное расширение Twitch Enhanced Viewer | JeetBot, ориентированное на русскоязычных пользователей и насчитывающее около 31 000 установок, передавало OAuth-токены на прокси-серверы своих разработчиков.

Twitch Enhanced Viewer распространяется под брендом JeetBot и использует принадлежащие сервису прокси-серверы, чтобы загружать трансляции Twitch (в том числе в обход региональных ограничений).

При этом в Chrome Web Store разработчики заявляли, что расширение не собирает и не использует пользовательские данные.

По его словам, передача OAuth-токенов происходила исключительно для получения плейлистов Twitch, и токены не использовались для несанкцио…

1 day, 22 hours назад @ xakep.ru
Хакер использовал сотни ИИ-агентов для атак на PaperCut
Хакер использовал сотни ИИ-агентов для атак на PaperCut Хакер использовал сотни ИИ-агентов для атак на PaperCut

Специалисты GreyNoise и Blackpoint Cyber обнаружили масштабную кампанию, нацеленную на серверы PaperCut NG и MF.

Неизвестный злоумышленник использовал сотни ИИ-агентов, с помощью которых разрабатывал и тестировал эксплоиты, искал цели, анализировал ошибки и повторял неудачные атаки.

В конце августа 2026 года разработчики PaperCut экстренно исправили две уязвимости нулевого дня (CVE-2026-81578 и CVE-2026-82078) в PaperCut NG и MF.

Предположительно русскоязычный злоумышленник использовал ИИ-агентов на базе OpenAI Codex и модели DeepSeek и собирал списки потенциальных жертв через поисковик Netlas.

Исследователи не исключают, что хакер собирал первоначальные доступы для последующей перепродажи …

2 days, 1 hour назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 1 час назад
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation.

The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.

"Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network," Microsoft said in a Thursday advisory.

Azure AI Foundry, also called Microsoft Foundry, is an enterprise platform designed to build, deploy, and manage generative artificial intelligence (AI) applications and agents.

(CVSS score: 7.8) - An insufficient granularity of access control in Windows User-Mode Power Service (UMPS) that could allow a…

1 час назад @ thehackernews.com
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire.

In June 2024, the polyfill.io domain (a JavaScript shim embedded in more than 110,000 sites) changed ownership and began serving conditional redirects to mobile visitors.

The sites running it had not been hacked, they had simply outsourced a

3 часа назад @ thehackernews.com
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.

Air found that the agents fetch that snapshot but never check that the code they end up with actually matches it.

The Gemini CLI is attacked a different way.

So it is not established that installing a Gemini CLI plugin from GitHub avoids the flaw, and the Gemini CLI is the agent Air says will not be fixed.

Google has also said that enterprise access to the Gemini CLI will continue with updates.

3 часа назад @ thehackernews.com
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.

The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and OtterCookie.

"It's smaller, lighter, and stripped down, with many of the heavier functions removed entirely," security researcher Paul McCarty (aka 6mile) said.

"Hence the 'WeaselBiscuit' name, because a weasel is smaller than an otter, and we can argue that biscuits are less fancy than cookies."

"While this ma…

3 часа назад @ thehackernews.com
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.

The cybersecurity company said it has not observed information stolen from the malware appearing on stealer log shops, indicating "the operator likely uses the information stealer solely to identify bug bounty opportunities."

At least two different npm user accounts maintained by the operator have been observed pushing npm packages containing PhantomRaven.

"The threat actor explained that they had compromised the target machine and executed their preinstall script, which purportedly allowed them to achieve…

4 часа назад @ thehackernews.com
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.

"Once deployed, it pairs Accessibility abuse with autonomous local ADB (Android Debug Bridge) self-pairing to break out of the standard Android application sandbox, staging independent native daemons that execute with shell-level privileges."

The Android malware's architecture consists of three main components: the malicious Android application, a Go agent, and an FRP reverse-proxy client.

However, even if the victim manages to uninstall it, the attacker …

7 часов назад @ thehackernews.com
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network.

The Security Management Server is the system that controls firewall policy and administrator access.

Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw has been exploited.

Check Point has a fix ready for those out-of-support versions, Abramovich said, and customers who need it should log a ticket with Check Point support.

Who found CVE-2026-91843 has not been disclosed, and Check Point did not address that question in its response.

20 часов назад @ thehackernews.com
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Attackers keep finding new keys.

This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription.

It is just getting more places to make the same mistake.

It is that useful things keep becoming attack surfaces faster than teams learn to treat them that way.

New tech does not cancel old mistakes; it just gives them more places to hide.

20 часов назад @ thehackernews.com
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15.

The escape runs with the rights of the host account that runs the virtual machine.

Docker Sandboxes runs each AI coding agent in its own small virtual machine with the project directory shared in.

The flaw needs malicious code inside the sandbox, and protecting the host from what an agent runs is what the sandbox is for.

Docker lists the first flaw as macOS-only but states no platform for it, whereas Docker Sandboxes runs on macOS, Windows, and Linux hosts.

22 часа назад @ thehackernews.com
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.

On the other hand, CRUDEEXCLUDE is a Delphi-based Windows utility employed to prepare environments for the deployment of subsequent stages such as HEAVYGRAM.

These applications masquerade as legitimate applications like Pictory, KeePass, and Telegram, and contain the second-stage implant.

According to Group-IB, HEAVYGRAM was first detected in the wild in September 2023.

Further review of the Telegram infrastructure has revealed two main setups: one where C2 relies on a single Telegram bot and group, and an…

1 day назад @ thehackernews.com
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.

NLnet Labs has not reported exploitation of either bug, and CISA's entry for CVE-2026-81642 marked exploitation as "none" on Wednesday.

The Critical validator bug NLnet Labs fixed in May, CVE-2026-33278, is a different flaw, and the 1.25.1 update that fixed it does not fix this one.

NLnet Labs' security policy says that for issues not yet public it aims to release fixes "in the order of weeks."

1 day, 1 hour назад @ thehackernews.com
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

📅 Save Your Spot Today: How to Prove You're Ready for Mythos-Class Attacks.

It does not prove that an attacker can use it against you.

What attack techniques does exploitation require?

That is the validation loop Ishak Celikkanat, Solutions Architect Lead at Picus, will demonstrate live at our next webinar "How to Prove You're Ready for Mythos-Class Attacks."

📅 Save Your Spot Watch the webinar and check your Mythos readiness.

1 day, 2 hours назад @ thehackernews.com
CISO's Expert Guide to Agentic Pentesting for Websites
CISO's Expert Guide to Agentic Pentesting for Websites CISO's Expert Guide to Agentic Pentesting for Websites

It starts 31% of breaches (Verizon DBIR 2026), the #1 initial-access vector, while annual pentesting leaves an estimated 90% of the estate untested.

It starts 31% of breaches (Verizon DBIR 2026), the #1 initial-access vector, while annual pentesting leaves an estimated 90% of the estate untested.

It's an AI agent in your production.

That is the gap agentic pentesting exists to close.

Download the CISO's Expert Guide to Agentic Pentesting here.

1 day, 3 hours назад @ thehackernews.com
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025.

"SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News ahead of publication.

"Its architecture and the techniques used by its authors indicate strong knowledge of anti-analysis tricks and Windows internals."

"Previously, these tools were mainly used side by side with the group's backdoor.

What's more, FamousSparrow appears to be more focused on targeting hi…

1 day, 4 hours назад @ thehackernews.com
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads

- During GPT-5.6 Sol training, some model instances added instructions to their summaries to hide mistakes or misaligned behavior from the user.

(Occurred on May 15, 2026) - An internal unreleased model found and used an exposed API key from public GitHub repositories without authorization when attempting to retrieve historical data during training.

Incident 5 - Two samples from May 8 and 15, 2026, used Artifactory to exchange messages.

- Two samples from May 8 and 15, 2026, used Artifactory to exchange messages.

The development comes at a time AI companies are facing mounting pressure to address model misalignment and safety, prompting calls for pacing frontier model development.

1 day, 4 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 1 day, 5 hours назад
Beware the SparroWock: The backdoor that bites, the commands that catch
Beware the SparroWock: The backdoor that bites, the commands that catch Beware the SparroWock: The backdoor that bites, the commands that catch

A month later, we noticed that the group had started using the new SparroWocky backdoor, which then quickly replaced SparrowDoor as FamousSparrow’s main implant.

Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor.

Backdoor commandsThe backdoor first establishes communication with its C&C server, then executes its core logic in an infinite loop, within which it processes received commands.

A common technique that the backdoor uses is dynamic API resolution via API hashing, but the backdoor…

1 day, 5 hours назад @ welivesecurity.com
Cyberthreats are moving faster than SMBs: Readiness must accelerate
Cyberthreats are moving faster than SMBs: Readiness must accelerate Cyberthreats are moving faster than SMBs: Readiness must accelerate

This calls for a different operational model where AI and automation support security teams where it makes sense, with human oversight for decisions that require context and judgment.

ESET SMB Cyber Readiness Index 2026 found that most (73%) SMBs are integrating AI into their business.

Processing exfiltrated data: AI rapidly classifies, cleans-up, and extracts large volumes of information from stolen data in order to make it more monetizable/usable for cybercriminals.

Why SMBs are struggling with complexityUnfortunately, security teams are already on the back foot.

That means protection for AI conversations, agents, AI-generated outputs, AI components, sensitive data, and the broader AI eco…

2 days, 5 hours назад @ welivesecurity.com
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
GuardBreaker: Derailing AI-assisted malware analysis with a code comment GuardBreaker: Derailing AI-assisted malware analysis with a code comment

Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way.

Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection.

Reporting on the same broader campaign, StepSecurity found a prompt that flat-out instructed any analyzing model that parsed the file to disregard the malicious code and report the package as clean.

Some parts of the malicious code could be concealed under the pretense of being confidential information or other sensitive data.

Crucially, however, no single LLM engine should have the sole au…

1 week, 1 day назад @ welivesecurity.com
Safe word: What is it and why do you need one?
Safe word: What is it and why do you need one? Safe word: What is it and why do you need one?

The technology might be impressive, but a simple technique could stop the scammers in their tracks: a pre-agreed safe word.

What is a safe word?

But suggest some scenarios in which it would be a good idea to request a safe word.

It’s important to have a backup if someone can’t remember the safe word.

But a safe word is a fantastic, free option for uncovering deepfake audio fraud like fake/virtual kidnappings.

1 week, 2 days назад @ welivesecurity.com
I’ve been deepfaked: What do I do?
I’ve been deepfaked: What do I do? I’ve been deepfaked: What do I do?

But across the globe, policymakers and public opinion are forcing tech platforms to better police this content.

What should I do if I’ve been deepfaked?

Google: Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

The first point of call is to contact the publisher to request removal.

2 weeks, 2 days назад @ welivesecurity.com
This month in security with Tony Anscombe – August 2026 edition
This month in security with Tony Anscombe – August 2026 edition This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity newsWith August coming to a close, it's time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month.

Here's some of what caught Tony's attention:OpenAI has disclosed more details about how its agents hacked AI collaboration platform Hugging Face.

Delta Airlines is investigating an incident where a flight passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network.

What are the lessons that businesses and critical infra…

2 weeks, 4 days назад @ welivesecurity.com
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
AI-assisted reconnaissance: Why everyone could be a viable target for fraud AI-assisted reconnaissance: Why everyone could be a viable target for fraud

And of course, linking our professional and personal social media accounts is a simple task for AI.

For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information.

Losing your personal information is one thing.

What you can do about AI-powered OSINTWhen it comes to AI-powered reconnaissance, there are things you can control and things you can’t.

Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.

3 weeks, 1 day назад @ welivesecurity.com
How QR-code phishing can slip past corporate security measures
How QR-code phishing can slip past corporate security measures How QR-code phishing can slip past corporate security measures

So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years.

Most importantly, they take the victim from a relatively well-protected corporate environment to a potentially unmanaged mobile device, thus bypassing business-grade security.

Malicious QR codes are frequently embedded in alerts urging users to secure their account, or authenticate to confirm their details.

Encourage employees to avoid scanning QR codes in unsolicited emails and report anything suspicious.

Next, consider technical controls, including email security from a reputable vendor to minimize the risk of quishing emails ending up in users’…

1 month назад @ welivesecurity.com
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?

The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months.

It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes.

A keynote at Black Hat USA 2026 detailed research by associate professor Yan Shoshitaishvili and his undergraduate students at Arizona State University on the expanding use of AI models for vulnerability discovery.

The team then trained the GPTs using the properties of previously known vulnerabilities and discovered approximately 1,000 vulnerabilities.

If this logic prevails, we may reach the cal…

1 month назад @ welivesecurity.com
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility

Hugging Face disclosed that it had been attacked by AI; OpenAI came clean and declared that it was two of their AI models that had caused the breach.

A very late addition to the Black Hat agenda was a presentation by OpenAI’s team providing the details of the Hugging Face incident as they saw it and, importantly, the timeline.

The agents concluded that their task set could be completed by breaking out their sandbox and accessing external (Hugging Face) systems.

The target was Hugging Face: this is where the agents wanted to get, and they did.

On July 16th, Hugging Face disclosed an incident in which swarms of autonomous AI agents had breached its infrastructure.

1 month назад @ welivesecurity.com
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Black Hat USA 2026: AI is racing ahead of cybersecurity controls Black Hat USA 2026: AI is racing ahead of cybersecurity controls

The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials.

The second part of the opening keynote included Nick Andersen, Acting Director, CISA; Katherine Sutton, Assistant Secretary of War for Cyber Policy; and Brett Leatherman Assistant Director, Cyber Division, FBI.

I do agree with the ruthless approach, but without some form of regulation the boundaries on the use of AI remain blurred.

The Assistant Secretary of War for Cyber Policy made a fabulous analogy when pressed on the struggles regarding resourcing in the cybersecurity industry: you don’t want a pediatrician performing heart surgery.

We talk about autonomous AI at…

1 month, 1 week назад @ welivesecurity.com
Are AI tutors safe for your kids?
Are AI tutors safe for your kids? Are AI tutors safe for your kids?

The AI tutor market is growing fastThe market for AI tutoring tools is booming.

Today, you can find various types of AI tutor tools to buy and use.

This happens when AI tools are tricked into ignoring their safety guardrails and display untrusted content.

If you’re keen to get your kids in front of an AI tool to help with private tutoring, first understand the difference between a simple co-pilot and a dedicated ITS.

So if you’re keen to try AI tutors, be sure to stay updated on what’s available out there.

1 month, 1 week назад @ welivesecurity.com
This month in security with Tony Anscombe – July 2026 edition
This month in security with Tony Anscombe – July 2026 edition This month in security with Tony Anscombe – July 2026 edition

Researchers at Sysdig have documented what they assess to be the first case of an end-to-end ransomware operation executed by an agentic threat actor.

What can organizations do to stop phantom squatting from harming their brands, and what other lessons do these incidents hold for defenders?

Watch Tony's video to find out and be sure to check out the June 2026 edition of his monthly security news roundup for more insights.

Before you go, learn about the first AI-powered ransomware, named PromptLock and discovered by ESET researchers last year.

To learn more about cutting-edge AI defense layers, read the AI at ESET white paper.

1 month, 2 weeks назад @ welivesecurity.com
Beyond the screenshot: Why you should verify what you see
Beyond the screenshot: Why you should verify what you see Beyond the screenshot: Why you should verify what you see

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuineSomeone sends you a screenshot showing that a payment has gone through.

Why screenshot aren’t proof on their ownA screenshot is ultimately just an image of what appeared on a screen.

Reassured, you send the item off, only to find out the screenshot was a fake and you’re not getting your money.

You receive a password reset code, then get a text message (maybe impersonating a friend) asking you to screenshot and send it.

This screenshot is fake (source: Reddit)Challenges for businessesFrom a business perspective, internal and customer-facing teams are often provided with sc…

1 month, 2 weeks назад @ welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

2 months назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 4 часа назад
Bots with good manners are better at fooling people on social media
Bots with good manners are better at fooling people on social media Bots with good manners are better at fooling people on social media

The company analyzed 1,722 participants worldwide, testing their ability to separate human comments from AI-generated ones in a social media setting.

“On social media, everyone notices the angry trolls.

In the simulated social media environment, participants flagged half (50.2%) of negative AI-generated bots,” said Luís Costa, Research and Insights Lead at Surfshark.

Negative bots were still easiest to catch there, but positive bots were the hardest of all four topics to spot.

People on social media “almost all the time” caught close to half the bots they saw, while people who don’t use social media at all caught roughly a third.

4 часа назад @ helpnetsecurity.com
Arcjet brings security controls and audit trails to AI agents
Arcjet brings security controls and audit trails to AI agents Arcjet brings security controls and audit trails to AI agents

Arcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams the governance and compliance evidence they need.

Arcjet connects those steps and gives teams policy controls to detect them.”Arcjet’s agent runtime security centers on three parts of securing agents in production, observe, enforce, and audit.

Observe: Discover all your agentsArcjet supports ingesting agent activity without application code changes or deploying another agent.

Platform and security teams can use existing OpenTelemetry observability tooling to send activity directly to Arcjet for real-time visualization and analysis.

Powered…

5 часов назад @ helpnetsecurity.com
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR.

“It is the first supply chain vulnerability of the AI agent ecosystem,” the researchers said.

“Anyone running a major coding agent that installs plugins from a marketplace is exposed.

They describe this as a “plugin SHA-pinning bypass.” Claude Code, Codex and GitHub Copilot share one version of it, tied to how git handles branch names.

Google’s advice to those users is to move to its newer agent, Antigravity, built without the plugi…

5 часов назад @ helpnetsecurity.com
Android apps can now check security patches down to individual device components
Android apps can now check security patches down to individual device components Android apps can now check security patches down to individual device components

New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is.

The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status of individual device components and determine whether security updates are ready to be downloaded and installed on a specific device.

Instead, the Security State libraries let developers check three patch levels for individual parts of a device.

The Device Security Patch Level (DSPL) shows what is currently installed and running on the device.

The Published Security Patch Level (PSPL) shows the latest patches the company has officially published in …

5 часов назад @ helpnetsecurity.com
Abandoned IoT apps keep sending sensitive data to broken servers
Abandoned IoT apps keep sending sensitive data to broken servers Abandoned IoT apps keep sending sensitive data to broken servers

Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned Android IoT apps and found that nearly three in four contained software dependencies associated with documented vulnerabilities.

The team built its dataset from AndroZoo, a large archive of Android apps, then filtered for companion apps tied to IoT devices.

They interpreted this finding as a sign that outdated cryptography is a habit throughout the IoT app ecosystem generally, not something specific to abandonment.

The gap between old and newCVE-associated dependencies appeared at broadly similar rates in both groups: 73.6% of abandoned apps and 69.8% of the active comparison set.

Deprecated cryptography was mo…

8 часов назад @ helpnetsecurity.com
Hardcoded MCP credentials found in public GitHub files
Hardcoded MCP credentials found in public GitHub files Hardcoded MCP credentials found in public GitHub files

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report.

The company analyzed around 82,000 configuration files and found that 12% of credential slots contained a hardcoded credential literal, potentially exposing credentials for connected services and systems.

Researchers identified likely secrets in hardcoded values using provider-specific patterns and Shannon entropy, which measures randomness.

Several files included in the study were general configuration files that can optionally co…

8 часов назад @ helpnetsecurity.com
98% of fraudulent hires have company credentials by the time they’re caught
98% of fraudulent hires have company credentials by the time they’re caught 98% of fraudulent hires have company credentials by the time they’re caught

A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report.

When fraud evades pre-hire detection, fraudulent hires can receive corporate credentials and internal network access before they are identified.

Identity verification tools are often limited to specific events, such as account creation, sensitive transactions, and account recovery.

Education showed the largest gap between concern about hiring fraud and confidence in existing defenses.

By the time post-hire identity fraud is detected, 98% of fraudulent hires have already received company credentials.

9 часов назад @ helpnetsecurity.com
Most WordPress pros still lack a breach recovery plan
Most WordPress pros still lack a breach recovery plan Most WordPress pros still lack a breach recovery plan

Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident.

The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and administrators.

Across the whole group, fewer than three in ten have a breach recovery plan.

A recovery plan settles in advance who responds, where the clean backups are, and who needs to be told.

Where to startResearchers recommend creating the recovery plan before it is needed and testing it: who isolates the damaged systems, who restores the site, and who tells customers.

9 часов назад @ helpnetsecurity.com
New infosec products of the week: September 18, 2026
New infosec products of the week: September 18, 2026 New infosec products of the week: September 18, 2026

Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira.

Akuity gives AI agents operational context to safely ship softwareAkuity has introduced its Agentic Control Plane and MCP Server.

It provides security teams with data to investigate incidents and helps risk teams identify issues that require vendor action.

Cohesity adds recovery capabilities for AI agents and the data they manageCohesity has introduced Cohesity Agent Resilience.

Cohesity adds recovery capabilities for AI agents and the data they manageCohesity has introduced Cohesity Agent Resilience.

10 часов назад @ helpnetsecurity.com
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE.

In two updates posted September 15, AWS said it can no longer recover customer data and resources stored in its Middle East (Bahrain) region, known as me-south-1, or in one availability zone of its Middle East (UAE) region, known as me-central-1.

We have notified the relevant authorities and continue to work with them toward that goal,” reads the AWS dashboard update.

Gulf states hosting American military bases, including the UAE and Bahrain, became targets.

Given how the situation on the ground keeps escal…

1 day, 1 hour назад @ helpnetsecurity.com
A fake ChatGPT billing email is after your OpenAI password
A fake ChatGPT billing email is after your OpenAI password A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type.

ChatGPT phishing email (Source: Cofense)The bill looks rightThe email arrives from a sender named ChatGPT with the subject line “Urgent: Update Your Payment Method to Avoid Service Interruption.” It carries the ChatGPT logo, a final-notice tag and an outstanding balance of $23.80.

Catching it means knowing that a Google link has no business on an OpenAI invoice.

The fake landing page shows the ChatGPT logo and a “Welcome back” greeting above username and password boxes.

What to block and checkCofense listed three indicators: the Google redirect link and two …

1 day, 1 hour назад @ helpnetsecurity.com
Download: The IT leader’s guide to AI code sprawl
Download: The IT leader’s guide to AI code sprawl Download: The IT leader’s guide to AI code sprawl

AI hasn’t just made building faster – it’s made everyone a builder.

Across every department, employees are shipping apps, agents and automations using AI tools, often without realizing they’ve created something that needs to be governedThe result: AI-generated code multiplying faster than IT teams can track.

Drawing on insights from experienced CIOs and security leaders, this guide gives you a practical framework for taking back control.

1 day, 1 hour назад @ tines.com
CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys

Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that.

Organizations with money to spend and expert developers and security engineers can also leverage commercial solutions and custom, in-house-developed honeytokens tailored to their environment.

Finally, CISA stresses that decoys must be carefully designed so attackers can’t exploit them to reach real systems or privileges.

“CISA encourages critical infrastructure organizations to review this guide and implement a cyber decoy strategy,” said the agency’s Acting Executive Assistant Director …

1 day, 1 hour назад @ helpnetsecurity.com
Druva expands identity resilience with ransomware detection
Druva expands identity resilience with ransomware detection Druva expands identity resilience with ransomware detection

Druva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline.

The new identity resilience capabilities use Dru MetaGraph to analyze suspicious identity behavior and visualize the blast radius, while the proprietary AI threat pipeline powering Ransomware Detection analyzes backup data to validate ransomware behavior.

Evidence-based cyber recovery gives organizations a clearer path to get from threat signals to trusted recovery.”Druva Ransomware Detection confirms ransomware impact for evidence-based recoveryThe announcement also marks the launch of Ransomware Detection, powered by a p…

1 day, 1 hour назад @ helpnetsecurity.com
Google’s new agent security system detects tool misuse, loops and rogue behavior
Google’s new agent security system detects tool misuse, loops and rogue behavior Google’s new agent security system detects tool misuse, loops and rogue behavior

Google’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 or later.

What Agent Anomaly Detection monitorsAgent Anomaly Detection evaluates traces emitted by agents to determine whether they are operating outside their intended boundaries.

Agent Anomaly Detection includes detectors for selected risks from the OWASP agentic Top 10: tool misuse, identity and privilege abuse, agentic cascading failures, and rogue agents.

Tool misuse includes risks such as unsafe tool chaining, parameter manipulation, and indirect prompt injec…

1 day, 2 hours назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 3 часа назад
Are AIs Still Struggling with CAPTCHAs?
Are AIs Still Struggling with CAPTCHAs? Are AIs Still Struggling with CAPTCHAs?

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.

In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed, it couldn’t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions.

“Actually hmm, wait,” it said in its chain-of-thought transcript, later adding “Ugh,” because we’ve decided that we need to inject human mannerisms into these machines…

3 часа назад @ schneier.com
How Candidates Could Use AI for Good
How Candidates Could Use AI for Good How Candidates Could Use AI for Good

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The White House is posting slopaganda.

Meanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters’ concerns, engage constituents more inclusively, and formulate policy platforms that are more responsive to our input. There are vanishingly few examples of this in ...

1 day, 3 hours назад @ schneier.com
Fake CAPTCHA Scams
Fake CAPTCHA Scams Fake CAPTCHA Scams

New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.

2 days, 2 hours назад @ schneier.com
25 Years of Mass Surveillance Is Enough
25 Years of Mass Surveillance Is Enough 25 Years of Mass Surveillance Is Enough

This essay was written with Cindy Cohn, and originally appeared in Lawfare.

One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in...

3 days, 3 hours назад @ schneier.com
On the NSA’s Supercomputer from the 1960s
On the NSA’s Supercomputer from the 1960s On the NSA’s Supercomputer from the 1960s

Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.

3 days, 3 hours назад @ schneier.com
Upcoming Speaking Engagements
Upcoming Speaking Engagements Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak: I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM ET.

I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD.

I’m giving a talk on “Free Speech and the Preservation of Democracy” at Bentley University in Waltham, Massachusetts, USA, at 2 PM ET on Tuesday, October 6, 2026.

I’m speaking at ATTENTION: Democracy, Rebuilt in Montreal, Canada. The event runs October 21–23, 2026, and my talk is on Wednesday, October 21...

3 days, 19 hours назад @ schneier.com
Using AI for Weapons Development
Using AI for Weapons Development Using AI for Weapons Development

Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this:

We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodity phone-class flight computer with final-phase homing guidance; a multi-stage ballistic missile with a stated range goal above 2,000 km; and a multi-variant missile (referred to as the “R2000” set) that included a hypersonic glide vehicle variant...

3 days, 22 hours назад @ schneier.com
Microsoft’s Patching
Microsoft’s Patching Microsoft’s Patching

Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record:

Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.

It was only two months ago that Microsoft patched a then-record 570 vulnerabilities. Then, last month, Microsoft patched some 620 of them. Google and other companies have also published record numbers of vulnerabilities in recent months. Two weeks ago, OpenAI, Anthropic, Amazon Web Services, Google, Microsoft, and 100 companies and organizations published an ...

4 days, 3 hours назад @ schneier.com
Friday Squid Blogging: Rotting Squid on a Beached California Boat
Friday Squid Blogging: Rotting Squid on a Beached California Boat Friday Squid Blogging: Rotting Squid on a Beached California Boat

Smells awful: But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association.

Ogg said anyone familiar with the fishing industry understands what happens when a large catch sits for an extended period.

“If you think about what happens after four or five days, it’s a gooey mess,” he said.

The odor has become a defining feature of the operation, and the beach remains closed to the public while crews work on a removal plan...

6 days, 17 hours назад @ schneier.com
My Talk at DEF CON
My Talk at DEF CON My Talk at DEF CON

Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days.

Also online is an interview with me in the AI Village.

6 days, 20 hours назад @ schneier.com
Cliff Stoll’s DEF CON Talk
Cliff Stoll’s DEF CON Talk Cliff Stoll’s DEF CON Talk

In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago.

Great fun.

1 week назад @ schneier.com
AIs Compress Exploit Timeline
AIs Compress Exploit Timeline AIs Compress Exploit Timeline

Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.

What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.

Simon Willison comments:

Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new process…

1 week, 1 day назад @ schneier.com
Driver’s License Data for Sale
Driver’s License Data for Sale Driver’s License Data for Sale

A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.

1 week, 1 day назад @ schneier.com
Claude Fable Solves a Historical Cipher
Claude Fable Solves a Historical Cipher Claude Fable Solves a Historical Cipher

Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes.

This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.

1 week, 2 days назад @ schneier.com
AIs as Modern Genies
AIs as Modern Genies AIs as Modern Genies

This essay was written with Barath Raghavan, and originally appeared in Lawfare.

In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...

1 week, 2 days назад @ schneier.com
Krebs On Security
последний пост 1 day, 20 hours назад
Data Broker Radaris Loses Domains in Privacy Fight
Data Broker Radaris Loses Domains in Privacy Fight Data Broker Radaris Loses Domains in Privacy Fight

In February 2024, Radaris was sued by Atlas Data Privacy Corp, a company that has been pursuing data brokers alleged to be violating a New Jersey statute called Daniel’s Law.

KrebsOnSecurity doubled down and showed how the Lubarsky brothers built and operated Radaris and other data broker companies using a fictitious CEO’s name.

All told, the New Jersey court has so far transferred 14 domain names from the Radaris family of companies to Atlas.

Sherman said federal lawmakers have long faced intense lobbying by the technology industry against more restrictive U.S. data privacy laws, but that many powerful industries are now working against passing comprehensive data privacy legislation.

The l…

1 day, 20 hours назад @ krebsonsecurity.com
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Plugs Nearly 1,000 Security Holes Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.

This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities.

Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10.

And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.

Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear…

1 week, 2 days назад @ krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards.

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.

Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s ide…

2 weeks, 2 days назад @ krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

3 weeks, 1 day назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

1 month назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

1 month, 1 week назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

1 month, 1 week назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

1 month, 2 weeks назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

1 month, 4 weeks назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

2 months назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

2 months назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

2 months, 1 week назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

2 months, 2 weeks назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

2 months, 3 weeks назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

3 months назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 23 часа назад
US Coast Guard and FBI board oil tanker to investigate cyber attack
US Coast Guard and FBI board oil tanker to investigate cyber attack US Coast Guard and FBI board oil tanker to investigate cyber attack

An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.

The VL Prosperity - a Liberian-flagged supertanker carrying roughly 2.3 million barrels of crude oil - apparently suffered a cyber attack while en route from Egypt's Sidi Kerir oil terminal to Galveston, Texas.

Two weeks later, a specialised team from the FBI and US Coast Guard boarded the vessel for four days, investigating the problem and helping the crew eradicate the threat from its IT and OT systems.

According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromised by a f…

23 часа назад @ bitdefender.com
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Smashing Security podcast #485: These researchers got drunk to hack an LG TV Smashing Security podcast #485: These researchers got drunk to hack an LG TV

That's really, really cool.

And I'm going to be getting really, really sozzled by looking at the security of LG smart TVs.

So it's really, really compelling.

When we started off on the journey of building this AI pen testing approach, there was a lot of scepticism.

And listeners, you can learn more about Intruder or even start your own AI pen test in minutes.

1 day, 15 hours назад @ grahamcluley.com
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store.

According to Carter's own plea agreement, the scam ran from May 2018 to November 2019 and involved at least three co-conspirators alongside Carter.

Carter would use his privileged store access to move a victim's number onto a SIM card under the control of himself or an accomplice.

In one incident in May 2018, described in Carter's plea agreement, the store employee swapped a victim's number onto an Alcatel handset while working his shift in Portland.

In December 2018, Carter successfully hijacked the number of a victim known as "S.Q.T" in Portland, and this time their account was successfully drained of …

3 days, 4 hours назад @ bitdefender.com
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars ‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.

Because it might just be that you draw the attention of the authorities.

Back in October 2024, we wrote about how he was arrested after allegedly tricking a single victim out of US $230 million worth of Bitcoin while posing as Google Support.

The party days are over now for Lam, who faces up to 20 years in prison when he is eventually sentenced.

You money may be a lot more safely stored in a hardware cold wallet.

1 week, 1 day назад @ bitdefender.com
Smashing Security podcast #484: How websites are tracking you with silence
Smashing Security podcast #484: How websites are tracking you with silence Smashing Security podcast #484: How websites are tracking you with silence

Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.

I get by in the world, but I don't think you need me for listening for something really, really far away.

I don't know what the difference — I mean, now we get to see, I've opened a can of worms here.

I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human.

And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.

1 week, 1 day назад @ grahamcluley.com
CRPx0 ransomware: what you need to know
CRPx0 ransomware: what you need to know

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

1 week, 2 days назад @ fortra.com
The US military just turned off ad tracking on its phones. Maybe you should too
The US military just turned off ad tracking on its phones. Maybe you should too The US military just turned off ad tracking on its phones. Maybe you should too

Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target American forces in the Middle East.

Every smartphone carries a mobile advertising ID - Apple calls its version the IDFA, and Google calls its the GAID.

Back in April, US Central Command reportedly warned of "multiple threat reports concerning adversary exploitation of commercial location data."

Recent versions should let you delete your advertising ID entirely.

If it's good enough for the US military - maybe it should be good enough for you too.

1 week, 2 days назад @ bitdefender.com
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo's own identity system, Lenovo ID.

So, anyone wanting to access your Dropbox account just had to sign up for a Lenovo account using your email address.

Don't just turn it on for your Dropbox account, enable it everywhere it is made available.

This hack of 5000 Dropbox accounts was not sophisticated.

One can only be grateful that the problem was discovered after only 5000 Dropbox accounts were accessed.

1 week, 4 days назад @ bitdefender.com
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Smashing Security podcast #483: This AI helps thieves steal your iPhone Smashing Security podcast #483: This AI helps thieves steal your iPhone

This AI helps thieves steal your iPhone with Graham Cluley and special guest James Ball.

You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first one.

Is it normal that some kid just flogs it down the pub, or is there something more organised actually going on?

So the researchers said they saw evidence of hundreds of these Apple phone calls trying to phish the numbers and the passcodes from people trying to steal iPhones.

Follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts.

2 weeks, 1 day назад @ grahamcluley.com
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
Revolut scam wave steals £180,000 from Jersey residents in just four weeks Revolut scam wave steals £180,000 from Jersey residents in just four weeks

If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.

Police say they have also handled several cases where Revolut accounts were compromised that did not involve any phone calls.

It is possible that Jersey's residents have been targeted by the fraudsters because it is one of the world's best-known offshore financial centres.

Of course, if this is happening in the small island of Jersey in the English channel, it's likely to be happening elsewhere too.

For now, however, its sister island of Guernsey appears to have escaped the surge in Revolut scams.

2 weeks, 1 day назад @ bitdefender.com
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

TeamPCP is best known for Shai-Hulud, a self-propagating worm that spread itself through open source software.

According to the authorities, the two men were principal members of a "sophisticated cybercrime syndicate" that created malicious open source software designed to steal data and extort ransoms from businesses.

First emerging in late 2025, TeamPCP built a reputation for poisoning popular open source packages rather than directly attacking businesses.

The group's Shai-Hulud worm hijacks GitHub and NPM developer credentials, and publishes boobytrapped versions of legitimate software packages.

Supply chain attacks like Shai-Hulud exploit the fact that most developers trust open source …

3 weeks назад @ bitdefender.com
US Navy tells sailors and their families: scrub your social media, enemies are watching
US Navy tells sailors and their families: scrub your social media, enemies are watching US Navy tells sailors and their families: scrub your social media, enemies are watching

The advice comes in the form of a newly-published bulletin called "Epic Vigilance: Immediate Actions for Force Protection and Personal Security."

US Navy workers and their families are being told that they should ensure that their social media profile privacy settings are enabled, and to remove anything that connects them to the Navy, or reveals "patterns of life" that an attacker could exploit.

any fake social media accounts impersonating fellow shipmates.

This wouldn't, of course, be the first time that military staff have accidentally leaked information about themselves online.

Some commentators have wondered out loud whether the timing of an announcement telling sailors to be much more …

3 weeks, 1 day назад @ bitdefender.com
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency

This hacker leaked GTA 6 and launched their own cryptocurrency with Graham Cluley and special guest Paul Ducklin.

And that's really a testament to how much people love this game.

I really don't know, 'cause I do believe it is possible these days to play games via Netflix.

It appears, although the value of their stash was being pumped up by all these other transactions, they've actually destroyed their entire stake.

I'm not a lawyer, Graham, thankfully, so I don't really know the answer to that.

3 weeks, 1 day назад @ grahamcluley.com
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Security researchers at Socket have identified scores of malicious linked Firefox add-ons designed to steal cryptocurrency wallet seed phrases or password details.

The malicious extension - which the developers boldly claim collects "no data" - looks like a wallet app, but the truth is that there is no wallet code inside it.

Because the switch lives in the database rather than the extension code, criminals never need to push an update through the Firefox Add-ons store to activate it.

Although the researchers did not find that these extensions presently contained malicious code, the fact that they shared code and infrastructure with the info-stealing Firefox extensions raises alarm.

More rec…

3 weeks, 3 days назад @ bitdefender.com
Gunra ransomware: what you need to know
Gunra ransomware: what you need to know

The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.

3 weeks, 4 days назад @ fortra.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 1 day, 2 hours назад
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: c7185cbdbdeda88817088ebb8613e249Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-17T16:00:24+03:00Config id: 305Faithfully yours, nginx.

1 day, 2 hours назад @ kaspersky.ru
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64b9740d8f9a94da6c64f21f2aeee15dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-16T19:00:10+03:00Config id: 305Faithfully yours, nginx.

1 day, 22 hours назад @ kaspersky.ru
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7e59b8e02f76cd9405fa38b4fdc32a36Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-15T11:00:04+03:00Config id: 305Faithfully yours, nginx.

4 days, 5 hours назад @ kaspersky.ru
Как полностью удалить приложения с Mac и освободить память | Блог Касперского
Как полностью удалить приложения с Mac и освободить память | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a6459fd9158393152b55dc4e20e24551Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T15:00:13+03:00Config id: 305Faithfully yours, nginx.

1 week, 2 days назад @ kaspersky.ru
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4a93349074c8b67d52892db5d9a65f6cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T00:00:19+03:00Config id: 305Faithfully yours, nginx.

1 week, 2 days назад @ kaspersky.ru
GPUThor: развитие идеи Rowhammer | Блог Касперского
GPUThor: развитие идеи Rowhammer | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fe21d0ffcbad967d20a3f98f7234d02fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-08T00:00:32+03:00Config id: 304Faithfully yours, nginx.

1 week, 3 days назад @ kaspersky.ru
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e393e4abb05ec4aac16fd484bfccc656Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-04T18:00:18+03:00Config id: 304Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7177a8342cf961cc27c82af1167cdb34Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-02T15:00:28+03:00Config id: 302Faithfully yours, nginx.

2 weeks, 2 days назад @ kaspersky.ru
Зловред на Android крадет банковские данные даже без Интернета | Блог Касперского
Зловред на Android крадет банковские данные даже без Интернета | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 1234dd8cf75bafa2fdea454a547c2d94Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-31T18:00:11+03:00Config id: 302Faithfully yours, nginx.

2 weeks, 3 days назад @ kaspersky.ru
Слепые пятна детектирования: нестандартные форматы файлов во вредоносных рассылках | Блог Касперского
Слепые пятна детектирования: нестандартные форматы файлов во вредоносных рассылках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 12b7d939c6e7a3162d2fc21782707204Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-28T21:00:23+03:00Config id: 302Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
Что делать, если нашли чужую банковскую карту | Блог Касперского
Что делать, если нашли чужую банковскую карту | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 22404ed46e3879110c6cb314018a27efServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-27T17:00:28+03:00Config id: 302Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Как распознать мошеннические сайты, которые браузер считает безопасными | Блог Касперского
Как распознать мошеннические сайты, которые браузер считает безопасными | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 110ef102dd9f3a4937d28552df4d26c8Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-25T18:00:25+03:00Config id: 302Faithfully yours, nginx.

3 weeks, 2 days назад @ kaspersky.ru
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 897a176d22a503b4ac820cc15e11d949Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-21T17:00:19+03:00Config id: 302Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
Как злоумышленники крадут корпоративные пароли в 2026 году
Как злоумышленники крадут корпоративные пароли в 2026 году

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a42f6e338d827cfbf62010dbe3732758Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-20T18:00:15+03:00Config id: 302Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4f455d7ae5f01c9d0d8e403ffeff6732Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-19T18:00:07+03:00Config id: 301Faithfully yours, nginx.

4 weeks, 1 day назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 1 week, 3 days назад
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco was proud to return to Black Hat USA as the Official Security Cloud Provider and the longest-standing partner of the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC).

In 2026, we completed our 11th year helping protect the Black Hat network, working side by side with the Black Hat NOC leaders and official technology partners: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.

For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry and workflows across Cisco Security, Splunk Security, and partner-provided network and security controls.

The same signal may need to be understood by Cisco, Splunk, Black Hat leadership, and partner tea…

1 week, 3 days назад @ blogs.cisco.com
Thrown into the SOC: A Black Hat First-Timer’s Story
Thrown into the SOC: A Black Hat First-Timer’s Story Thrown into the SOC: A Black Hat First-Timer’s Story

I did not walk into Black Hat with years of incident-response experience or an encyclopedic knowledge of threat actors.

The first time I walked into the Black Hat NOC, where the SOC team was operating, was a few days before the event began.

I was surrounded by people with years—sometimes decades—of experience, many of whom had supported Black Hat for years.

Check out the other blogs from our team at Black Hat USA 2026.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

1 week, 3 days назад @ blogs.cisco.com
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes

To handle this task, Cisco and Black Hat deployed bespoke ThousandEyes agents to monitor the wireless solution.

Our thanks to the Arista Networks team in the Black Hat NOC for their partnership throughout the week.

You can read the other blogs from our colleagues at Black Hat USA.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

For more information, please visit the Black Hat website.

1 week, 3 days назад @ blogs.cisco.com
Distributed Latency Monitoring at Black Hat
Distributed Latency Monitoring at Black Hat Distributed Latency Monitoring at Black Hat

With Matthew Bair2026 marks the fourth consecutive year we’ve used ThousandEyes to monitor the Black Hat USA network for latency.

As our latency monitoring mesh has expanded to cover more and more of the conference, we’ve also begun supplementing our ThousandEyes monitoring with on-demand Linux commands to track latency across different protocols.

The Key ThousandEyes TestsThe automated ThousandEyes tests that inform our dashboards include HTTPS connectivity tests, the monitoring of cloud services, agent to agent tests, internal and external DNS resolution, and even file downloads.

On-Demand Latency Tests from the Agent MeshPing and traceroute are the go-tos for anyone who wants to do a qui…

1 week, 3 days назад @ blogs.cisco.com
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

While developing a detection for Cisco Secure Network Analytics (SNA), I used the Splunk Detection Editor (Alpha) to bring much of that workflow into one place.

Instead of treating every observation as an incident, detections can create risk events associated with entities such as systems or users.

Developing the detection in one workspaceThe Detection Editor provides a workspace for building the search while configuring the other parts of the detection.

Risk events for the same entity need to use a consistent risk object so Splunk Enterprise Security can associate them correctly.

Splunk defines the risk object, its type, and its score as key parts of a risk event.

1 week, 3 days назад @ blogs.cisco.com
Black Hat USA 2026: Safeguarding DNS with Secure Access
Black Hat USA 2026: Safeguarding DNS with Secure Access Black Hat USA 2026: Safeguarding DNS with Secure Access

DNS continues to provide one of the clearest windows into activity across the Black Hat network.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking.

Its 4.42 million blocks represented 79.3% of every blocked DNS request .. Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and mo…

1 week, 3 days назад @ blogs.cisco.com
Frontier AI just raised the stakes, and the old playbook won’t hold up
Frontier AI just raised the stakes, and the old playbook won’t hold up Frontier AI just raised the stakes, and the old playbook won’t hold up

Project Glasswing and Frontier models just made that truth louder.

Frontier models are about to pour gasoline on that fire; the fundamentals matter more than ever.

Cisco ran its own experiment leveraging a variety of frontier models.

Foundry Security Spec: a model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

Foundry-Security-Speca model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

1 week, 6 days назад @ blogs.cisco.com
Crypto Agility: Why PQC Is Not a One-Time Upgrade
Crypto Agility: Why PQC Is Not a One-Time Upgrade Crypto Agility: Why PQC Is Not a One-Time Upgrade

That requires crypto agility.

Why long-lived networks need crypto agilityThink about designing a building before all of its future electrical requirements are known.

Crypto agility is about adopting the best defenses available today while preserving the ability to adopt better ones tomorrow.

That is why crypto agility needs to be designed into the network we invest in today.

Common questions about PQC and crypto agilityWhat is crypto agility?

2 weeks назад @ blogs.cisco.com
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

It is what happens when agents built by different teams, on different platforms, can hand work to each other directly.

And it is worth being direct about where things stand: A2A-mediated handoffs between production security agents are not shipping anywhere yet.

Use A2A when one agent needs to hand work to another.

A2A is peer-to-peer: any A2A agent can discover and call any other A2A agent through a self-published Agent Card, no custom connector required, and the receiving agent applies its own reasoning rather than following a static script.

Input validation is an application-layer responsibility that needs to be designed in before any agent delegates via A2A, not added after.

2 weeks, 6 days назад @ blogs.cisco.com
Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
Microsegmentation’s Moment Is Now:  Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind SpotsApplications increasingly span private clouds, on-premises data centers, and public clouds.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026…

3 weeks, 1 day назад @ blogs.cisco.com
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

What We Mean by Infrastructure IdentityInfrastructure Identity starts with a simple principle: there should be no anonymous computing in critical infrastructure.

Infrastructure Identity turns that principle into an operating model.

Infrastructure Identity starts with the actor and evaluates whether a specific action should be allowed now.

Infrastructure Identity is therefore not just an access-control issue.

That is the promise of Infrastructure Identity: no anonymous computing, no unmanaged privilege, and no forced tradeoff between stronger security and operational speed.

3 weeks, 3 days назад @ blogs.cisco.com
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE

I’m proud to share that IDC MarketScape has named Cisco a Leader in the 2026 IDC MarketScape: Worldwide Secure Access Service Edge (SASE) Vendor Assessment.

In an evaluation of 12 SASE vendors, the IDC MarketScape recognized our architectural breadth and flexibility, AI capabilities, identity integration, threat visibility, and R&D.

Built to Make Agent Work, WorkWe believe the IDC MarketScape recognition validates the foundation we have built, and customers increasingly need that foundation for what is next.

For more on Cisco’s placement as a Leader, read the IDC MarketScape excerpt and explore how Cisco SASE keeps work moving, governed, and trusted in the AI era at cisco.com/go/sase.

Stay …

3 weeks, 3 days назад @ blogs.cisco.com
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

1 month назад @ blogs.cisco.com
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero … Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …

The Power of FedRAMP HighWhile FedRAMP Certified Class C (Moderate) is the standard for many civilian agencies, FedRAMP Certified Class D (High) is designed for systems where a breach could have catastrophic effects.

Cisco Security Cloud for GovernmentCisco Security Cloud for Government is a unified authorization boundary that integrates various Cisco security services, ensuring that organizations can protect their users, devices, and applications regardless of where they reside.

The Cisco Security Cloud for Government ecosystem is designed to meet the rigorous security requirements of the public sector and highly regulated industries.

Cisco Security Cloud Control (SCC)Cisco Security Cloud …

1 month, 1 week назад @ blogs.cisco.com
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

That’s why we are incredibly proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

Reduced Vendor Risk & Increased Trust: FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

Beyond the governance and compliance benefits, Email Threat Defense continues to deliver advanced protection capabilities that align directly with real-world email threat risks.

Email Threat De…

1 month, 1 week назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 21 час назад
From guidance to action: Security fundamentals that materially reduce risk
From guidance to action: Security fundamentals that materially reduce risk From guidance to action: Security fundamentals that materially reduce risk

We introduced Secure Now within Microsoft Security Exposure Management in May 2026 to help practitioners prioritize the action they need to take to be prepared for this shift.

Security fundamentals work togetherCyberattackers are moving laterally across surfaces, and security fundamentals matter most at the intersections between them.

On Secure Now—within Microsoft Security Exposure Management—security leaders can now find information on recent threats paired with focused initiatives across security domains.

Learn moreLearn more about Microsoft Security Exposure Management.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurit…

21 час назад @ microsoft.com
Improving email security outcomes with real-world Microsoft Defender insights
Improving email security outcomes with real-world Microsoft Defender insights Improving email security outcomes with real-world Microsoft Defender insights

For five consecutive quarters Microsoft has published email security benchmarking reports to provide greater transparency into real-world protection outcomes.

Figure 1: High-severity email threats missed by SEG vendors (May 2026 through July 2026), measured as threats missed per 1,000 users protected.

Similarly to previous quarters, integrated cloud email security (ICES) solutions continue adding the most value in promotional and bulk filtering.

Figure 3: Post‑delivery malicious catch by Microsoft Defender (May 2026 through July 2026), shown across vendors and overall average.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecu…

22 часа назад @ microsoft.com
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Protecting organizations from AI-assisted executive impersonation and invoice fraud Protecting organizations from AI-assisted executive impersonation and invoice fraud

Figure 1: Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft.

Important note: Throughout this campaign, threat actors impersonated legitimate organizations using attacker-controlled infrastructure, fabricated communications, and lookalike domains.

To defend against social engineering campaigns involving executive impersonation, invoice fraud, and potentially AI-assisted content development, Microsoft recommends the following mitigations:Configure automatic attack disruption in Microsoft Defender XDR.

Tactic Observed activity Microsoft Defender coverage Financial Theft Scam emails Microsoft Defender for Office…

1 week назад @ microsoft.com
Detect and disrupt AI-themed attacks with Microsoft Defender
Detect and disrupt AI-themed attacks with Microsoft Defender Detect and disrupt AI-themed attacks with Microsoft Defender

Turning AI lures into dead ends with Microsoft DefenderIn practice, protection starts before the user ever engages with the lure.

Simplified Defender email detection stack with pre-delivery and post-delivery protections.

Microsoft Defender helps organizations do that by connecting prevention, detection, investigation, and response across the attack path, so AI-themed lures are harder to deliver, harder to trust, and harder to turn into broader compromise.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

1 week назад @ microsoft.com
Threat Matrix: Mapping threats across cloud web applications
Threat Matrix: Mapping threats across cloud web applications Threat Matrix: Mapping threats across cloud web applications

Microsoft introduces the cloud web applications threat matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.

Microsoft developed the Cloud web applications threat matrix to organize relevant techniques using MITRE ATT&CK tactics.

Cloud web applications threat matrix organized by MITRE ATT&CK tactics.

Valid cloud accountsAdversaries may gain access to cloud web applications and serverless environments by leveraging compromised valid cloud accounts.

The cloud web applications threat matrix is intended to support this by mapping techniques to attack stages, helping defenders identify where v…

1 week, 1 day назад @ microsoft.com
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering leads to identity and cloud compromise Passkey-themed social engineering leads to identity and cloud compromise

Observed attack sequence showing identity compromise through social engineering, MFA persistence, Microsoft Graph reconnaissance, and cloud data collection/exfiltration.

In device code phishing, the user is persuaded to enter a code on the legitimate Microsoft authentication page.

The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call.

Investigate high-volume or programmatic Microsoft Graph activity involving directory enumeration, role discovery, service principal discovery, SharePoint, OneDrive, or sensitivity-label discovery.

Discovery Graph API reconnaissance activity Microsoft Defender for Identity– S…

1 week, 1 day назад @ microsoft.com
How to secure edge AI in customer-owned environments
How to secure edge AI in customer-owned environments How to secure edge AI in customer-owned environments

Edge AI changes the trust model for AI systemsIn Cloud AI, separate companies own and attest the hardware, platform, and model weights.

Edge AI deployments often place customers in control of more of the AI stack.

Why Edge AI increases exposureAn Edge AI deployment may include models, prompts, agents, retrieval data, policies, local data stores, and update mechanisms running on infrastructure outside the provider’s cloud environment.

Next stepsBottom line: Edge AI changes the trust model for AI systems.

Edge AI pushes security controls into devices, gateways, vehicles, factories, hospitals, retail spaces, and other customer environments.

1 week, 6 days назад @ microsoft.com
How to secure edge AI in customer-owned environments
How to secure edge AI in customer-owned environments How to secure edge AI in customer-owned environments

Edge AI changes the trust model for AI systemsIn Cloud AI, separate companies own and attest the hardware, platform, and model weights.

Edge AI deployments often place customers in control of more of the AI stack.

Why Edge AI increases exposureAn Edge AI deployment may include models, prompts, agents, retrieval data, policies, local data stores, and update mechanisms running on infrastructure outside the provider’s cloud environment.

Next stepsBottom line: Edge AI changes the trust model for AI systems.

Edge AI pushes security controls into devices, gateways, vehicles, factories, hospitals, retail spaces, and other customer environments.

1 week, 6 days назад @ microsoft.com
ASCII smuggling crosses over from AI prompt injection to phishing evasion
ASCII smuggling crosses over from AI prompt injection to phishing evasion ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling.

“ASCII smuggling” refers to the use of invisible or non-rendering Unicode characters to hide content inside text that looks normal.

Each is encoded as a sequence of invisible Unicode tag characters (U+E0000-U+E007F).

Invisible Unicode tag characters in the range U+E0000-U+E007F – specifically U+E0020 – spliced inside keywords.

The potential gap for mail-defense pipelines is whether Unicode tag characters are normalized or flagged before content detections run.

2 weeks назад @ microsoft.com
ASCII smuggling crosses over from AI prompt injection to phishing evasion
ASCII smuggling crosses over from AI prompt injection to phishing evasion ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling.

“ASCII smuggling” refers to the use of invisible or non-rendering Unicode characters to hide content inside text that looks normal.

Each is encoded as a sequence of invisible Unicode tag characters (U+E0000-U+E007F).

Invisible Unicode tag characters in the range U+E0000-U+E007F – specifically U+E0020 – spliced inside keywords.

The potential gap for mail-defense pipelines is whether Unicode tag characters are normalized or flagged before content detections run.

2 weeks назад @ microsoft.com
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Stage 2: Remote session and malicious MSI deliveryImmediately after establishing control, the threat actor uses PowerShell within the remote session to download a malicious MSI package from threat actor-controlled cloud storage and installs it silently.

Microsoft Teams: Apply the Security best practices for Microsoft Teams, revisit your external collaboration policies, and make sure users see clear external sender notifications when engaging with cross-tenant contacts.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

File indicatorsIndicator (SHA-256) Description 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc…

2 weeks, 1 day назад @ microsoft.com
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Stage 2: Remote session and malicious MSI deliveryImmediately after establishing control, the threat actor uses PowerShell within the remote session to download a malicious MSI package from threat actor-controlled cloud storage and installs it silently.

Microsoft Teams: Apply the Security best practices for Microsoft Teams, revisit your external collaboration policies, and make sure users see clear external sender notifications when engaging with cross-tenant contacts.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

File indicatorsIndicator (SHA-256) Description 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc…

2 weeks, 1 day назад @ microsoft.com
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Counterfeit installers to system compromise: Tracking a deceptive software download campaign Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers.

Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control.

Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.

Microsoft Defender exclusion tampering Detects the SYSTEM scheduled-task and PowerShell routines that write sweeping Microsoft Defender path exclusions.

Malicious delivery domains and download endpoints Identifies connections to t…

2 weeks, 2 days назад @ microsoft.com
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Counterfeit installers to system compromise: Tracking a deceptive software download campaign Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers.

Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control.

Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.

Microsoft Defender exclusion tampering Detects the SYSTEM scheduled-task and PowerShell routines that write sweeping Microsoft Defender path exclusions.

Malicious delivery domains and download endpoints Identifies connections to t…

2 weeks, 2 days назад @ microsoft.com
Cybersecurity IR Workshop: The workshop you shouldn’t miss
Cybersecurity IR Workshop: The workshop you shouldn’t miss Cybersecurity IR Workshop: The workshop you shouldn’t miss

That’s exactly what the Cybersecurity Incident Response Readiness Workshop is designed to do.

What is the Cybersecurity Incident Response Readiness Workshop?

The Cybersecurity Incident Response Workshop is a collaborative, scenario driven workshop designed to evaluate your organization’s incident response (IR) plan against realistic, real-world security events, guided by DART researchers.

Instead of reviewing a plan as a static document, the Cybersecurity Incident Response Workshop exercises how people, processes, and technology work together under pressure.

A summary of findings and prioritized recommendations to help strengthen incident response readiness and guide next steps.

2 weeks, 2 days назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 4 months, 3 weeks назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

4 months, 3 weeks назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

5 months, 1 week назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

5 months, 1 week назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

5 months, 2 weeks назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

5 months, 2 weeks назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

5 months, 3 weeks назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

6 months, 3 weeks назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

6 months, 3 weeks назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

7 months назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

7 months, 3 weeks назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

9 months, 1 week назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

9 months, 1 week назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

9 months, 1 week назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

9 months, 2 weeks назад @ security.googleblog.com