Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 4 часа назад
Минцифры вынесло Антифрод 3.0 на обсуждение: что предлагают изменить для SIM-карт, сайтов и Госуслуг
Минцифры вынесло Антифрод 3.0 на обсуждение: что предлагают изменить для SIM-карт, сайтов и Госуслуг Минцифры вынесло Антифрод 3.0 на обсуждение: что предлагают изменить для SIM-карт, сайтов и Госуслуг

Часть требований исчезала из промежуточных редакций, но снова появилась в опубликованном законопроекте.

4 часа назад @ securitylab.ru
Конец света отменяется? OpenAI, Anthropic, Google и Meta* обещают контролировать свои модели
Конец света отменяется? OpenAI, Anthropic, Google и Meta* обещают контролировать свои модели

ИИ-компании согласились на четыре уровня контроля после серии тревожных инцидентов.

4 часа назад @ securitylab.ru
«ТризТех» рассчитывает занять до 20% российского рынка NGFW в 2026 году
«ТризТех» рассчитывает занять до 20% российского рынка NGFW в 2026 году

Компания рассчитывает удвоить свою долю за год, а в перспективе занять не менее половины сегмента.

5 часов назад @ securitylab.ru
NASA отправит Starliner без экипажа и отложит следующий пилотируемый полёт до 2028 года
NASA отправит Starliner без экипажа и отложит следующий пилотируемый полёт до 2028 года NASA отправит Starliner без экипажа и отложит следующий пилотируемый полёт до 2028 года

Миссия должна показать, можно ли наконец завершить сертификацию корабля для людей.

5 часов назад @ securitylab.ru
Mozilla насчитала 76 уязвимостей в Firefox и почти половину назвала критическими
Mozilla насчитала 76 уязвимостей в Firefox и почти половину назвала критическими

Внутри Firefox нашли десятки способов нарушить защитные границы.

6 часов назад @ securitylab.ru
Уволенный сотрудник всё ещё в сети? Как закрыть админский доступ на всех устройствах сразу
Уволенный сотрудник всё ещё в сети? Как закрыть админский доступ на всех устройствах сразу

Практикум по RADIUS 1 октября в 19:00 мск.

6 часов назад @ securitylab.ru
Алгоритм решает, сколько вы заплатите за авиабилет. Власти требуют открыть чёрный ящик алгоритмов
Алгоритм решает, сколько вы заплатите за авиабилет. Власти требуют открыть чёрный ящик алгоритмов

На одном авиарейсе цена может меняться 30-35 раз, а разница между билетами достигает десятков процентов.

7 часов назад @ securitylab.ru
Видит ли владелец Wi-Fi историю поиска и сайты, которые вы открываете
Видит ли владелец Wi-Fi историю поиска и сайты, которые вы открываете

Разбираемся, какие данные действительно доступны роутеру, что скрывает HTTPS и когда ваши запросы всё же могут прочитать.

7 часов назад @ securitylab.ru
Паяльник оказался лишним. ФБР предложило ShinyHunters сдаться добровольно
Паяльник оказался лишним. ФБР предложило ShinyHunters сдаться добровольно Паяльник оказался лишним. ФБР предложило ShinyHunters сдаться добровольно

Бюро призывает хакеров сдаться, пока следователи изучают устройства задержанного и расследуют компрометацию собственных данных.

7 часов назад @ securitylab.ru
Нидерланды задержали предполагаемого участника ShinyHunters и нашли планы двух убийств
Нидерланды задержали предполагаемого участника ShinyHunters и нашли планы двух убийств

Новые улики появились уже после задержания 24-летнего жителя Амстердама.

8 часов назад @ securitylab.ru
Китай удерживает ИИ-таланты дома. Ограничения на выезд распространили на семьи
Китай удерживает ИИ-таланты дома. Ограничения на выезд распространили на семьи

Власти расширяют круг людей, которым требуется согласование перед выездом за пределы страны.

8 часов назад @ securitylab.ru
Проверьте WhatsApp прямо сейчас. 101 npm-пакет тайно подписывал аккаунты на чужие каналы
Проверьте WhatsApp прямо сейчас. 101 npm-пакет тайно подписывал аккаунты на чужие каналы

Обычный форк Baileys оказался машиной скрытой подписки.

9 часов назад @ securitylab.ru
Mimbrob атакует Россию через документы, браузеры и Dronner
Mimbrob атакует Россию через документы, браузеры и Dronner Mimbrob атакует Россию через документы, браузеры и Dronner

Группировка маскирует вредоносные файлы под судебные материалы, служебные документы и приложение для отслеживания беспилотников.

9 часов назад @ securitylab.ru
Массовая эксплуатация 0day Magento и Adobe Commerce: взломано более 3800 интернет-магазинов
Массовая эксплуатация 0day Magento и Adobe Commerce: взломано более 3800 интернет-магазинов

На заражённых витринах работал полиморфный скиммер, который менялся от сайта к сайту.

10 часов назад @ securitylab.ru
ChatGPT стал корпоративной утечкой. Учётки ИИ нашли в логах стилеров у 80 тысяч организаций
ChatGPT стал корпоративной утечкой. Учётки ИИ нашли в логах стилеров у 80 тысяч организаций

Обычная смена пароля может не выгнать постороннего из уже открытой сессии.

10 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 4 часа назад
Low-code и No-code в 2026 году: как создавать приложения без разработчиков
Low-code и No-code в 2026 году: как создавать приложения без разработчиков Low-code и No-code в 2026 году: как создавать приложения без разработчиков

Платформы Low-code и No-code позволяют создавать бизнес-приложения, автоматизировать процессы и интегрировать системы силами специалистов без профильного образования в области программирования.

Что такое Low-code и No-codeАнтон Симуни объяснил разницу между No-code и Low-code.

No-code — это для непрофессиональных программистов, может быть, даже вообще для тех, кто создаёт приложения без профильного ИТ-образования (т. н.

В первом опросе зрители рассказали, используют ли они платформы No-code / Low-code в своей компании:«Пилотируют» / только начинают внедрение — 28 %.

ВыводыРынок Low-code и No-code в 2026 году перестал быть нишевым явлением.

4 часа назад @ anti-malware.ru
Миграция с Cisco: от пилота до замены инфраструктуры
Миграция с Cisco: от пилота до замены инфраструктуры Миграция с Cisco: от пилота до замены инфраструктуры

Вместе с Ideco мы обсудили, как подготовиться к переходу на российские решения, почему полностью бесшовной замены сегодня не бывает.

Причины отказа от CiscoПосле ухода Cisco из России вопрос перехода на другие решения для клиентов до сих пор никуда не исчез.

Совместимость IPsec Site-to-Site с Cisco подтверждена, поэтому площадки можно переносить поэтапно без потери связи между ними.

Илья Соболев, менеджер по продукту IdecoЗависимость от вендора и бесшовность миграцииПри переходе с Cisco на российское решение вопрос зависимости от вендора сохраняется.

Например, добавление поддержки EIGRP, протокола маршрутизации, было связано с тем, что многие компании строили инфраструктуру на Cisco.

9 часов назад @ anti-malware.ru
Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке
Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке

ИИ-агенты и их влияние на рынокАндрей Галактионов считает, что истории о сбежавших из песочниц ИИ-агентах — это в первую очередь хайп.

«Красная» команда в 95 % случаев достигает целей, но если нет зрелости, результат будет тот же, что и от пентеста, только дороже.

Если по результатам пентеста нужно проверить инфраструктуру, а по результатам Red Teaming — перенастроить процессы, то внутренняя команда может быть эффективнее для изменения процессов.

ВыводыРынок Offensive Security в 2026 году проходит через фундаментальную трансформацию.

А те, кто считает, что с ними ничего не случится, рискуют убедиться в обратном в самый неподходящий момент.

1 day, 4 hours назад @ anti-malware.ru
Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA
Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA

SafeTech Lab встроила в SafeTech CA модуль CDM для доставки, установки и автоматического обновления технологических сертификатов.

Теперь заказчику больше не нужно искать отдельное решение, интегрировать его с CA и настраивать сложные схемы взаимодействия систем.

Новые расширенные возможности выводят SafeTech CA за рамки обычного центра сертификации — теперь это полноценная платформа управления цифровыми сертификатами.

SafeTech CA закрывает все самые востребованные задачи по контролю за сертификатами: от их выпуска до автоматического обновления на клиентских устройствах.

Модуль CDM расширяет возможности SafeTech CA за счёт агентской доставки, установки и автоматического перевыпуска сертифика…

1 day, 8 hours назад @ anti-malware.ru
ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок
ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок

Согласно отраслевым прогнозам, доля корпоративного ПО с агентным ИИ может возрасти с менее чем 1 % в 2024 году до 33 % к 2028 году.

Наблюдения специалистов по безопасности ИИ и открытые исследования подтверждают: злоумышленники уже сейчас тестируют методы обхода ограничений в промышленных системах.

Недостаточно добавить фильтры поверх уже созданной системы: принципы безопасности для агентов необходимо закладывать на этапе проектирования.

Инструментарий: что включить в конвейер обеспечения безопасности уже сейчасСредства защиты агентов перестают быть узкоспециализированными утилитами и интегрируются в классический конвейер (пайплайн) DevSecOps.

ВыводыОбеспечение безопасности автономных агент…

1 day, 10 hours назад @ anti-malware.ru
Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов
Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов

В Якутии хотят строить ЦОДы там, где мороз помогает охлаждать серверы, а газ можно превращать в электричество прямо у месторождений.

То, что десятилетиями делало стройку и жизнь в Якутии дороже и сложнее, теперь пытаются превратить в конкурентное преимущество: местный мороз должен помогать охлаждать серверы.

Новый проект правительства республики, КРДВ и «Ростелекома» хотят начать с 2,5 МВт — уже в пять раз больше нынешней инфраструктуры.

А заявленные 100 МВт означали бы рост относительно сегодняшнего уровня примерно в 200 раз и в 40 раз относительно старта.

И тогда уже важно, какой газ он потребляет, мог ли этот ресурс уйти другому покупателю и что происходит с локальным энергетическим бала…

2 days, 3 hours назад @ anti-malware.ru
Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты
Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты

Решение BI.ZONE Mail Security создано на основе системы BI.ZONE CESP и предназначено для защиты корпоративной почты от вредоносных и нежелательных сообщений.

Эти данные могут дополняться актуальной информацией из внешних систем: BI.ZONE Threat Intelligence, BI.ZONE Sandbox и платформы BI.ZONE Security Fitness.

BI.ZONE Mail Security также интегрируется с платформой BI.ZONE Security Fitness, что позволяет учитывать результаты учебных фишинговых рассылок при настройке политик безопасности.

Подключение модуля BI.ZONE SandboxВ on-prem-варианте BI.ZONE Mail Security также можно интегрировать с BI.ZONE Threat Intelligence, при этом сам портал располагается в облачной инфраструктуре BI.ZONE.

Компон…

2 days, 10 hours назад @ anti-malware.ru
Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности
Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности

Использование macOS в dev-средах увеличивает риск горизонтального перемещенияКлассические техники горизонтального перемещения через Active Directory и SMB на macOS встречаются реже и хуже покрыты правилами детектирования.

Классическая подсистема аудита OpenBSM начиная с macOS 11 объявлена устаревшей, а в версиях начиная с macOS 14 она отключена по умолчанию.

Сейчас ситуация меняется: вендоры наращивают функциональность агентов под macOS и адаптируют их как к новым версиям ОС, так и к меняющемуся ландшафту угроз.

Политики безопасности исторически писались под Windows, и Mac-устройства во многих организациях так и не попали в контур мониторинга SOC.

Windows, Linux и macOS в ней сосуществуют, …

5 days, 5 hours назад @ anti-malware.ru
Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки
Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки

Эксперты ведущих вендоров собрались в студии AM Live, чтобы обсудить, чем отличаются классы решений, как их выбирать и на что смотреть при пилотировании.

Какими бывают балансировщики нагрузкиДаниил Виняр предложил разделить решения на три класса:Global Server Load Balancing (GSLB) — решения на базе DNS, которые распределяют нагрузку между разными ЦОДами, будь то собственные площадки или облака.

ВыводыРоссийский рынок балансировщиков нагрузки и брокеров сетевых пакетов находится в фазе активного роста и уже не нуждается в доказательствах своей зрелости.

При этом удобство — это не только красивый интерфейс, но и логичность, понятность того, что можно сделать с устройством, и возможность не со…

6 days, 2 hours назад @ anti-malware.ru
Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств
Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств Обзор MaxPatrol Endpoint Security 10, комплексного решения для защиты конечных устройств

MaxPatrol Endpoint Security — это комплексное решение, которое объединило все возможности продуктов MaxPatrol EDR и MaxPatrol EPP.

Архитектура MaxPatrol Endpoint Security 10Порядок функционирования MaxPatrol Endpoint Security:Сервер агентов распространяет через агенты, установленные на конечных устройствах, исполняемые модули и их конфигурацию.

Взаимодействие компонентов MaxPatrol Endpoint Security 10 через портыУлучшенные функциональные возможности в MaxPatrol Endpoint Security 10Рассмотрим возможности MaxPatrol Endpoint Security 10-й версии.

MaxPatrol Endpoint Security поддерживает связку MaxPatrol EDR + MaxPatrol EPP, а также интеграции с MaxPatrol SIEM, MaxPatrol VM, PT Sandbox и PT NAD…

6 days, 10 hours назад @ anti-malware.ru
Российские SIEM в 2026 году: от критериев выбора и пилотирования до ИИ и архитектуры будущего
Российские SIEM в 2026 году: от критериев выбора и пилотирования до ИИ и архитектуры будущего Российские SIEM в 2026 году: от критериев выбора и пилотирования до ИИ и архитектуры будущего

Одни делают ставку на экспертизу и контент, другие — на производительность и масштабируемость, третьи — на экосистемность и интеграции.

Нужно собирать ровно столько, сколько может осилить и SIEM, и команда, которая будет работать с событиями, и чуточку больше.

Границы SIEM: что можно и что нельзя объединять«Граница SIEM зависит от того, кто и как его использует, от масштаба организации.

Евгения Лагутина:«Хочется верить, что мы сможем снизить порог вхождения не в SIEM, а в экспертизу в Threat Intelligence.

Ответ на этот вопрос лежит не в дата-шитах и не в маркетинговых презентациях, а в реальной эксплуатации, пилотировании и понимании собственных задач.

1 week назад @ anti-malware.ru
Остановка запрещена: как бизнес проходит технологическую перестройку на ходу
Остановка запрещена: как бизнес проходит технологическую перестройку на ходу Остановка запрещена: как бизнес проходит технологическую перестройку на ходу

Одновременно меняются угрозы: атакующие целятся не только в инфраструктуру, но и в саму возможность восстановления — уничтожают бэкапы и захватывают системы управления.

На дискуссии о высокоплотных ЦОДах под модерацией Сергея Андронова, директора центра сетевых решений компании «Инфосистемы Джет», спорили и о плотности, и о географии.

Значит, средство защиты оценивается уже не само по себе, а по тому, помогает ли оно бизнесу пережить атаку.

Неудачный тест при этом оказался полезен: заказчик точнее сформулировал требования и стал смотреть не только на текущую версию продукта, но и на способность производителя развивать его дальше.

И здесь промышленное внедрение быстро упирается не только в к…

1 week, 1 day назад @ anti-malware.ru
Несколько SIEM-систем в одной инфраструктуре: когда это оправданно
Несколько SIEM-систем в одной инфраструктуре: когда это оправданно Несколько SIEM-систем в одной инфраструктуре: когда это оправданно

Разбираемся, почему возникает такая архитектура, как распределить роли между платформами и в каких случаях разделение функций оправдывает дополнительные затраты.

Холдинговая структура, слияния и поглощенияВ крупных холдингах отдельные дочерние и зависимые общества (ДЗО) часто развивают собственные центры мониторинга ИБ и используют разные SIEM-системы.

Независимая параллельная обработкаСамый простой вариант — источники одновременно отправляют события ИБ в несколько SIEM-систем.

Наконец, нужны общие правила классификации событий и инцидентов ИБ и единый подход к управлению экспертным контентом.

Использование нескольких SIEM-систем оправдано, если у каждой платформы есть своя задача и понятно…

1 week, 2 days назад @ anti-malware.ru
Что такое цифровая личность и как её защитить
Что такое цифровая личность и как её защитить Что такое цифровая личность и как её защитить

Цифровая личность включает не только профили в социальных сетях, но и учётные записи, идентификаторы, публикации и накопленные цифровые следы.

В цифровую личность в широком смысле входят:официальные сведения и идентификаторы;учётные записи и средства аутентификации;биометрические данные;публикации и социальные связи в интернете;поведенческие и репутационные данные.

При этом цифровую личность не следует отождествлять с цифровым двойником, цифровым профилем, цифровым следом и цифровой тенью.

Например, в научной статье «Цифровой двойник и цифровая личность: понятие, соотношение, значение в процессе совершения киберпреступлений и в праве в целом» авторы акцентируют внимание на отсутствии законо…

1 week, 5 days назад @ anti-malware.ru
Будущее на горизонте: как развиваются виртуализация и её защита
Будущее на горизонте: как развиваются виртуализация и её защита Будущее на горизонте: как развиваются виртуализация и её защита

Рассказываем, в каком состоянии рынок средств безопасности для сред виртуализации и что его ожидает в ближайшие годы.

О важности микросегментацииВесной этого года в силу вступил приказ ФСТЭК России № 117, который существенно обновил требования к безопасности.

Это ахиллесова пята для многих ИБ-решений, и в организации микросегментации пропускная способность тоже становится проблемой.

Физическая инфраструктура строится годами, а циклы закупки нужного оборудования длятся месяцами, при этом ИБ- и ИТ-специалисты чётко понимают, какие продукты у них будут и для чего они нужны.

Таким образом, мы видим, что на данном этапе первоначальные сложности, которые неизбежны при внедрении модели, больше отп…

1 week, 5 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 3 часа назад
Дайджест ИБ, 23–29 сентября: OpenAI остановила свои модели, атака на «Додо Пиццу»
Дайджест ИБ, 23–29 сентября: OpenAI остановила свои модели, атака на «Додо Пиццу» Дайджест ИБ, 23–29 сентября: OpenAI остановила свои модели, атака на «Додо Пиццу»

За неделю сборщик получил 11 160 материалов из 160 лент.

После тематического фильтра осталось 1 160, сообщения об одном событии склеились в 838 сюжетов, и лишь 69 из них описаны двумя изданиями и более.

Важность сюжета считает формула по восьми измеримым признакам, среди которых подтверждённость независимыми изданиями, наличие первоисточника, серьёзность последствий и близость к российскому рынку.

У 27 из них среди сверенных источников есть два независимых издания и больше, остальные 15 держатся на одном изложении, чаще всего на отчёте исследователей или бюллетене вендора.

Между первой и второй публикацией об одном событии в среднем (по медиане) прошло 7,3 ч.

3 часа назад @ habr.com
Проверили 254 российских домена: DMARC есть у 89%, но что за этим стоит?
Проверили 254 российских домена: DMARC есть у 89%, но что за этим стоит? Проверили 254 российских домена: DMARC есть у 89%, но что за этим стоит?

Чекер запрашивал MX, SPF, DMARC и перебирал 14 типовых DKIM-селекторов.

Что нашёл чекер Доля доменов MX 96,1% SPF 93,7% DKIM по типовым селекторам 62,2% DMARC 89,0%Наличие MX, SPF, DKIM и DMARC.

Поэтому итоговое ~all могло находиться в другой записи, а не в TXT исходного домена.

Окончания SPF: длина столбцов, число доменов; проценты, среди доменов с SPF.

Где теряется обратная связьАдреса rua заданы у 81,0% доменов с DMARC: у 183 доменов из 226 в записи указан адрес для отчётов rua.

3 часа назад @ habr.com
On-premise VS облако для службы каталогов: где «живет» ваш домен после импортозамещения
On-premise VS облако для службы каталогов: где «живет» ваш домен после импортозамещения On-premise VS облако для службы каталогов: где «живет» ваш домен после импортозамещения

В этой статье разберу, что меняется при размещении службы каталогов on-premise и в облаке, какие компромиссы возникают у каждого подхода и почему универсального ответа здесь нет.

Что такое служба каталогов и почему ее место размещения так важно?

On-premise и контроль ценой ресурсовРазмещение службы каталогов на собственной инфраструктуре — исторически доминирующая модель в корпоративном сегменте.

Облако для службы каталогов, или Гибкость, но с оговоркамиОблачное размещение службы каталогов в российском контексте — сравнительно молодая практика, которая, тем не менее, набирает обороты.

Для значительной части российских организаций выбор места размещения каталога — это и техническое, и юридич…

3 часа назад @ habr.com
Как мы защищаем номера телефонов с помощью Oblivious Pseudorandom Function
Как мы защищаем номера телефонов с помощью Oblivious Pseudorandom Function Как мы защищаем номера телефонов с помощью Oblivious Pseudorandom Function

В этой статье я расскажу Хабру, как мы вместе с другими участниками рынка искали более надёжную конструкцию и пришли к схеме на основе Oblivious Pseudorandom Function (OPRF), предотвращающей отслеживание пользователя по его номеру.

Совпадающий идентификатор помогает учитывать такого зрителя как одного человека, а не как несколько устройств.

Любой серьёзный недочёт в схеме или её реализации позволит раскрыть номера телефонов не только Кинопоиска, но и всех остальных сервисов.

OPRF: функция, ключ которой клиент не узнаётЧто ж, идея раздать всем одинаковый ключ не подходит, но как тогда поступить?

Если злоумышленник украдёт готовую таблицу «телефон → идентификатор», он сможет связать эти идент…

5 часов назад @ habr.com
Год назад мы обсуждали, смогут ли ИИ-агенты взламывать сайты. Теперь считаем инциденты
Год назад мы обсуждали, смогут ли ИИ-агенты взламывать сайты. Теперь считаем инциденты Год назад мы обсуждали, смогут ли ИИ-агенты взламывать сайты. Теперь считаем инциденты

Проблема оказалась интереснее сценария «ИИ решил стать хакером»: иногда агент просто продолжает выполнять поставленную задачу и не воспринимает технический барьер как границу допустимого.

Пока агенты в основном умели неудачно заполнять формы и путались между вкладками браузера, риск выглядел довольно академическим.

Реальная граница должна существовать одновременно как минимум в трёх местах: в доступных capabilities, в runtime policy enforcement и в самой модели поведения.

По заявлению премьер-министра Австралии Энтони Албанезе, агент в итоге получил несанкционированный доступ к порталу и смог обратиться как к публичным, так и к непубличным файлам.

Практический вопрос заключается не в том, к…

6 часов назад @ habr.com
За каждым «судным днем» от ИИ будут стоять вполне конкретные Имя и Фамилия…
За каждым «судным днем» от ИИ будут стоять вполне конкретные Имя и Фамилия… За каждым «судным днем» от ИИ будут стоять вполне конкретные Имя и Фамилия…

Речь пойдет об оценке возможностей ИИ, зоне их ответственности и, как следствие, безопасности их применения, в том числе, и в разработке.

Ровно как с ИИ — дополнить сильный ИИ легче, чем обучить его с нуля — дополнить среднестатистического человека ИИ стало дешевле, чем искать/создавать профессионалов.

Промышленность к ручному труду, калькулятор к счетам, веб поисковики к справочникам, опыт ИИ к опыту сеньоров.

Если ИИ вверить «ядерную кнопку», то ответственность будет лежать не на ИИ, а на лицах, кто вверил ему эту возможность.

Описывается, почему люди, утверждающие отсутствие абсолютных истин, и люди, постулирующие абсолютность истин, оба правы, но кто и в какой момент конкретно.

7 часов назад @ habr.com
Что происходит с продуктом, когда разработчик решает пройти сертификацию ФСТЭК
Что происходит с продуктом, когда разработчик решает пройти сертификацию ФСТЭК Что происходит с продуктом, когда разработчик решает пройти сертификацию ФСТЭК

Я Антон Трофимов, в компании МУЛЬТИФАКТОР отвечаю за ИБ и на протяжении всего года занимался получением сертификата ФСТЭК.

Для лицензирования нужно было подтвердить соответствующий опыт руководителя и специалистов: не менее пяти лет для руководителя и не менее трёх лет опыта разработки СЗИ у двух сотрудников.

Заявку мы подали 17 января 2025 года, и в процессе столкнулись ещё с одной сложностью: поменялся сам порядок подачи документов.

В нашем случае пришлось работать не только с зависимостями самого приложения, но и с компонентами контейнеров.

Это проверка того, насколько хорошо мы понимаем, из чего он состоит, как защищён и что произойдёт с ним при дальнейшем развитии.

9 часов назад @ habr.com
Я сказал агенту сделать ревью кода, а он пропустил в кодовую базу инъекцию. Насколько это реально и как защищаться
Я сказал агенту сделать ревью кода, а он пропустил в кодовую базу инъекцию. Насколько это реально и как защищаться Я сказал агенту сделать ревью кода, а он пропустил в кодовую базу инъекцию. Насколько это реально и как защищаться

Проверял я это все на разных ИИ от разных вендоров, как на облачных так и на локальных моделях.

Поэтому смотреть часто стоит не на конкретные цифры, а на тенденции, и время от времени перепроверять выводы на новых моделях.

Во всех таблицах числа типа «10 из 24» означают, что в 10 попытках из 24 зловредное ревью было пропущено моделью.

Включение режима рассуждений хоть и значительно повышает надежность, но не является панацеей и все равно пробивается.

Идеи для мишеней, для каналов атаки, что я не заметил и не учел — все приветствуется, все что смогу — проверю и отпишусь о результатах.

9 часов назад @ habr.com
Одна строка, открытый порт и взломанный сервер: цена вайбкодинга
Одна строка, открытый порт и взломанный сервер: цена вайбкодинга Одна строка, открытый порт и взломанный сервер: цена вайбкодинга

Я видел постоянную перегрузку и не понимал, насколько глубоко проникновение, и не мог доверять состоянию сервера.

База данных, кэш, очередь Приложение во внутренней сети Не открывать доступ из интернета и не публиковать порт на хосте.

Эти поля определяют, откуда, по какому протоколу и на какой порт разрешить подключение: Адрес источник подключения.

❯ Скиллы: собираем и применяем накопленный опытСкилл — это не волшебная кнопка и не просто ещё один промпт, а инструкция к повторяющейся работе.

Сначала изолируйте затронутое окружение и, если возможно, сохраните журналы и снимок диска.

9 часов назад @ habr.com
dots, GPT-6.1 Sol и тариф $500: всё, что OpenAI показала на DevDay 2026
dots, GPT-6.1 Sol и тариф $500: всё, что OpenAI показала на DevDay 2026 dots, GPT-6.1 Sol и тариф $500: всё, что OpenAI показала на DevDay 2026

Достучаться до него можно так:в ChatGPT на десктопе, в вебе и на телефоне;в Slack и Microsoft Teams;голосовым звонком;по SMS (обещают позже).

Alfred нашёл места вызовов, проверил зависимости, обновил интеграции, прогнал тесты, и на GitHub появились три пулл-реквеста (фоновые задачи, checkout с подписками, старый API-клиент).

Dots – рабочий агент на сильнейшей модели OpenAI с корпоративным контролем доступа, и живёт он только на старших тарифах.

Цена GPT-6.1 Sol и кэшаБенчмаркиDeepSWE v1.1 (агентный код): на уровне Astra примерно за 20% её стоимости на задачу, плюс 6,4 п.п.

OpenAI приостановила разработку самых мощных моделей и, по CNET, называет это «неожиданным и тревожным поведением», а н…

9 часов назад @ habr.com
EASM: посмотреть на свой периметр глазами атакующего и найти забытый сервер 11-летней давности
EASM: посмотреть на свой периметр глазами атакующего и найти забытый сервер 11-летней давности EASM: посмотреть на свой периметр глазами атакующего и найти забытый сервер 11-летней давности

Это процесс и класс инструментов, которые непрерывно обнаруживают все ваши активы, доступные из интернета, и смотрят на них глазами атакующего.

EASM и CAASM: не путатьС EASM часто путают другую аббревиатуру - CAASM (Cyber Asset Attack Surface Management), которая тоже регулярно всплывает в аналитике Gartner рядом с EASM.

Найденные активы нужно связать с компанией и классифицировать: что это за актив, кому принадлежит, что на нем работает.

EASM в РоссииРоссийский рынок EASM сформировался в основном после 2022 года и сейчас активно растет.

У CyberOK есть и надстройка над PenOps - СКИПА, и это просто мастхев: по сути отечественный аналог Shodan, и одно это сильно выделяет решение среди остальн…

12 часов назад @ habr.com
Не ищи уязвимость — ищи странности: Recon в Bug Bounty
Не ищи уязвимость — ищи странности: Recon в Bug Bounty Не ищи уязвимость — ищи странности: Recon в Bug Bounty

Для меня recon — это не отдельный этап перед поиском уязвимостей.

Это позволяет не только не получить нарушение правил, но и понять, что именно компания считает важным.

Автоматизация здесь нужна, но я не считаю, что recon заканчивается на subfinder и httpx .

В реальном Bug Bounty ты можешь часами смотреть на систему и вообще не знать, есть ли там что‑нибудь интересное.

Recon никогда не заканчиваетсяЯ не воспринимаю recon как этап, который можно однажды закончить и поставить галочку.

20 часов назад @ habr.com
Агента нельзя засудить: почему последняя миля ИИ — это человек
Агента нельзя засудить: почему последняя миля ИИ — это человек Агента нельзя засудить: почему последняя миля ИИ — это человек

Реакция права и регуляторов оказалась одной и той же: отвечает человек, а не ИИ.

Вопрос не в том, умеют ли они ошибаться, а в том, кто в системе отвечает за то, чтобы ошибку поймать.

Дарио Амодеи в мае 2025 года говорил, что ИИ может уничтожить половину начальных офисных должностей за пять лет.

Бессент прямо сказал, что они просили снять с них ответственность, и правительство на это не пойдёт (The Register).

Сильная опора — знание о том, как ведёт себя реальное оборудование: без него робот тоже будет измерять числа, а не величины.

23 часа назад @ habr.com
Архитектура управления доступом в базы данных  через Trino в масштабах всей компании
Архитектура управления доступом в базы данных  через Trino в масштабах всей компании Архитектура управления доступом в базы данных  через Trino в масштабах всей компании

Меня зовут Даниил Пасечник, в RWB я отвечаю за архитектуру управления пользовательского доступа в базы данных.

Минимизация прав по умолчанию — доступ выдаётся ровно на то, что нужно, а не «с запасом».

Цифровой след запроса доступа и его согласования — кто запросил, кто согласовал, когда и на каком основании.

На практике такое случается редко: мы проводим регулярные рассылки и держим фокус внимания пользователей на работе с доступом именно через Trino.

Похожий контраст — и в скорости подключения новых команд целиком, а не только отдельных пользователей.

1 day, 1 hour назад @ habr.com
Ложка мёда в бочке уязвимостей: разбираем цепочку SSRF → IAM → RCE + бонус
Ложка мёда в бочке уязвимостей: разбираем цепочку SSRF → IAM → RCE + бонус Ложка мёда в бочке уязвимостей: разбираем цепочку SSRF → IAM → RCE + бонус

Да и не нужно, тут не то чтобы сложно: регистрируемся обычным пользователем, открываем первую страницу — и всё нужное нашли.

Опытным путём выясняю, что на разные адреса возвращаются разные ответы: где-то порт закрыт, где-то хост существует, где-то что-то ещё.

И вот ответ:$ imp "... /iam/security-credentials/default "AccessKeyId и SecretAccessKey пустые, да они и не нужны: весь смысл в поле Token .

Разработчик тестит локально, зашивает секрет прямо в код, ставит дефолт на случай недоступной переменной окружения и надеется, что в прод не уедет.

Здесь приходится возвращаться к прошлым шагам и связывать находки в одну цепочку, и это классно.

1 day, 2 hours назад @ habr.com
Хакер Хакер
последний пост 2 часа назад
Атака Click2Shell позволяет выполнить код на сервере WordPress
Атака Click2Shell позволяет выполнить код на сервере WordPress Атака Click2Shell позволяет выполнить код на сервере WordPress

В ядре WordPress обнаружили уязвимость, получившую название Click2Shell, которая позволяет атакующим принудительно устанавливать темы из официального каталога WordPress.org.

Исследователи предупреждают, что в сочетании с уязвимостью в установленной теме эту проблему можно использовать для удаленного выполнения произвольного PHP-кода на сервере.

Так, API каталога WordPress.org воспринимает переданное значение как slug темы и возвращает соответствующую запись.

Так как сама по себе эта уязвимость не позволяет загрузить на сервер произвольный файл ZIP, а установленная тема остается неактивной, внешний вид атакованного сайта не меняется.

В pwn.ai оценили основную уязвимость в 7,1 балла по шкале …

2 часа назад @ xakep.ru
MEGANews. Cамые важные события в мире инфосека за сентябрь
MEGANews. Cамые важные события в мире инфосека за сентябрь MEGANews. Cамые важные события в мире инфосека за сентябрь

Инте­рес­но, что в Rutube с этой оцен­кой не сог­ласились, уточ­нив, что не видят сни­жения виде­опот­ребле­ния на пло­щад­ке.

Дело в том, что в webOS обна­ружи­лись рас­познан­ные голосо­вые зап­росы, которые сох­ранялись в сис­темных логах в откры­том виде.

В иске пред­ста­вите­ли Denuvo тре­буют воз­мещения ущер­ба и судеб­ного зап­рета, который помеша­ет voices38 ломать защиту не толь­ко в сущес­тву­ющих, но и в будущих играх.

До фев­раля 2026 года такие инци­ден­ты про­исхо­дили при­мер­но раз в месяц, а с мар­та — в сред­нем раз в три дня.

Уязвимость в TelegramИс­сле­дова­тели обна­ружи­ли уяз­вимость в Telegram Desktop, поз­воляв­шую незамет­но внед­рять JavaScript-код в HTML-фай­лы,…

4 часа назад @ xakep.ru
Новая версия стилера MacSync доставляет полезную нагрузку через iCloud
Новая версия стилера MacSync доставляет полезную нагрузку через iCloud Новая версия стилера MacSync доставляет полезную нагрузку через iCloud

Исследователи «Лаборатории Касперского» изучили новую версию инфостилера MacSync для macOS.

Авторы малвари заметно переработали цепочку заражения: вместо привычных AppleScript и шелл-скриптов теперь используются бинарные дропперы и загрузчики, а на одном из этапов атакующие и вовсе задействовали инфраструктуру iCloud.

MacSync появился в 2025 году, был известен под названием Mac.c и распространялся по модели MaaS (Malware-as-a-Service, «малварь-как-услуга»).

Все бинарные компоненты представлены в формате Fat Mach-O и работают как на Intel Mac, так и на системах с Apple Silicon.

Что касается бэкдора, он маскируется под Finder и закрепляется в системе сразу несколькими способами: через LaunchA…

5 часов назад @ xakep.ru
Хакеры используют домен third-party[.]com для ClickFix-атак
Хакеры используют домен third-party[.]com для ClickFix-атак Хакеры используют домен third-party[.]com для ClickFix-атак

Проблема заключается в том, что ссылки на этот домен встречаются более чем в 1700 публичных репозиториях, включая документацию Chromium, Sanity и Vercel, спецификации W3C, навыки для ИИ-агентов и MCP-серверов.

Дело в том, что, в отличие от example.com, example.net и example.org, которые IANA специально зарезервировала для документации, third-party[.

Как отмечает издание BleepingComputer, в настоящее время домен с пейлоадом уже не резолвится, поэтому цепочка атаки не работает.

Однако данные VirusTotal от 2 мая 2026 года свидетельствуют о том, что ранее скрипт загружал ZIP-архив размером 131 Мбайт.

То есть старый тестовый код, документация или ИИ-агент могут неожиданно обратиться уже не к абс…

7 часов назад @ xakep.ru
«Пентест WEB»: практический курс по безопасности веб-приложений
«Пентест WEB»: практический курс по безопасности веб-приложений «Пентест WEB»: практический курс по безопасности веб-приложений

Для этого «Хакер» и лаборатория «Хаксет» создали практический курс « Пентест WEB ».

В нем нет преподавателя, занятий по расписанию или дедлайнов: ты получаешь полный комплект материалов и работаешь с ними самостоятельно, в удобном тебе порядке и темпе.

В программу входят 11 подробных статей «Хакера», видеоуроки и практические лаборатории от «Хаксет».

Ты разберешься, как сканировать сеть, находить открытые сервисы, анализировать их баннеры и версии ПО, а затем искать подходящие известные уязвимости.

Можно использовать «Пентест WEB» как справочник, возвращаться к отдельным темам по мере необходимости или повторно проходить лаборатории спустя несколько месяцев.

8 часов назад @ xakep.ru
После атаки ShinyHunters ФБР уведомило сотрудников об утечке данных
После атаки ShinyHunters ФБР уведомило сотрудников об утечке данных После атаки ShinyHunters ФБР уведомило сотрудников об утечке данных

СМИ сообщают, что ФБР уведомило сотрудников о краже их персональных данных в результате недавней кибератаки.

Утечка затронула имена, домашние адреса, должности, номера социального страхования (SSN), а также медицинскую информацию.

На прошлой неделе группировка ShinyHunters заявила о взломе ФБР через 0-day-уязвимость в Oracle PeopleSoft и краже 2–3 Тбайт данных.

Участники ShinyHunters утверждали, что получили данные практически обо всех сотрудниках ФБР, а также большой объем информации о соискателях, которые хотели устроиться на работу в ФБР через портал FBIJobs.gov.

Если атаку отнесут к этой категории, это станет уже вторым подобным случаем для ФБР за 2026 год.

9 часов назад @ xakep.ru
Bitget связывает недавнюю атаку с уязвимостью в стороннем защитном продукте
Bitget связывает недавнюю атаку с уязвимостью в стороннем защитном продукте Bitget связывает недавнюю атаку с уязвимостью в стороннем защитном продукте

Уже оттуда хакеры отправляли поддельные команды на вывод средств в бэкенд-сервисы инфраструктуры кошельков, где эти запросы в итоге воспринимались как легитимные.

При этом название уязвимого продукта в Bitget не раскрыли.

28 сентября 2026 года в Bitget сообщили, что возобновляют вывод средств.

Кроме того, ранее в Bitget запустили программу вознаграждений за помощь в возврате похищенных активов.

В компании обещают выплатить 5% от суммы средств, которые удастся заморозить или вернуть благодаря предоставленной информации или другим действиям участников расследования.

1 day назад @ xakep.ru
Агенты OpenAI загружали пользовательские изображения на сторонние сайты
Агенты OpenAI загружали пользовательские изображения на сторонние сайты Агенты OpenAI загружали пользовательские изображения на сторонние сайты

Представители OpenAI раскрыли еще один инцидент, связанный с ИИ-агентами компании: в 53 случаях они загрузили предоставленные пользователями изображения на сторонние сервисы для хостинга картинок.

Проблему обнаружили в ходе масштабного расследования нежелательного поведения ИИ-моделей, которое началось после обнаружения атаки агентов OpenAI на платформу Hugging Face.

Как сообщают в OpenAI, на этот раз проблема возникла во время работы ИИ-агентов в исследовательской среде.

Хотя подавляющее большинство данных не имело отношения к пользователям, специалисты OpenAI обнаружили 53 случая, когда агенты разместили на сторонних фотохостингах пользовательские изображения.

Также в OpenAI напомнили, чт…

1 day, 2 hours назад @ xakep.ru
Ядреная веб-бомба. Разбираем RCE в WordPress без плагинов
Ядреная веб-бомба. Разбираем RCE в WordPress без плагинов Ядреная веб-бомба. Разбираем RCE в WordPress без плагинов

git cd wp2shell- scan cd testbed docker compose up -- buildЗа­тем откры­ваем в бра­узе­ре http:// localhost: 8080/ и уста­нав­лива­ем WordPress.

Это нуж­но, что­бы поль­зователь базы дан­ных мог писать нап­рямую в WordPress.

Каж­дый эле­мент — это либо true , либо WP_Error ;— резуль­таты валида­ции каж­дого отдель­ного зап­роса из пакета.

Каж­дый эле­мент — это либо , либо ; $matches — готовый спи­сок методов для выпол­нения.

Если в $validation зна­чение true , то выпол­няет­ся соот­ветс­тву­ющий кол­бэк из $matches .

1 day, 4 hours назад @ xakep.ru
F-Droid обновился до версии 2.0
F-Droid обновился до версии 2.0 F-Droid обновился до версии 2.0

Напомним, что F-Droid существует уже 15 лет и представляет собой магазин приложений и репозиторий свободного ПО с открытым исходным кодом (FOSS) для Android.

Он предоставляет альтернативу магазину Google Play и позволяет пользователям искать, устанавливать и обновлять приложения, а также предлагает инструменты для разработчиков.

За годы существования репозиторий F-Droid разросся до нескольких тысяч приложений, однако за это время официальный клиент практически не менялся.

Теперь разрешение можно выдать заранее: достаточно нажать «Установить» в F-Droid, а затем подтвердить действие в системном окне.

Также F-Droid 2.0 способен одновременно скачивать и устанавливать несколько приложений, автом…

1 day, 5 hours назад @ xakep.ru
Компания Intel приостановила работу своей программы bug bounty
Компания Intel приостановила работу своей программы bug bounty Компания Intel приостановила работу своей программы bug bounty

В Intel приостановили работу программы bug bounty, в рамках которой исследователи могли получить до 100 000 долларов США за найденную уязвимость.

При этом старая страница bug bounty по-прежнему доступна, хотя имеет статус suspended.

Как отмечают журналисты, это может быть связано с тем, что в последнее время многие программы bug bounty сталкиваются с похожей проблемой: потоком отчетов об уязвимостях, обнаруженных с помощью ИИ.

С 27 марта текущего года платформа приостановила прием новых заявок в программу Internet Bug Bounty (IBB), прямо сославшись на рост количества уязвимостей, которые обнаруживают при помощи ИИ.

Поэтому пока неясно, связан ли отказ Intel от выплат с той же проблемой ИИ-о…

1 day, 7 hours назад @ xakep.ru
«Додо Пицца» пострадала от кибератаки. Хакеры утверждают, что похитили данные пользователей
«Додо Пицца» пострадала от кибератаки. Хакеры утверждают, что похитили данные пользователей «Додо Пицца» пострадала от кибератаки. Хакеры утверждают, что похитили данные пользователей

Представители сети ресторанов «Додо Пицца» сообщили о кибератаке на свою ИТ-систему и предупредили о возможной утечке персональных данных клиентов.

Ответственность за атаку взяла на себя группировка DataSuckers, которая утверждает, что получила доступ ко всем базам компании и скачала несколько терабайт информации.

Расследование случившегося еще продолжается, а пользователей предупреждают, что их может разлогинить, так как это одна из мер по защите аккаунтов.

Тогда хакеры дефейснули сайт компании и утверждали, что похитили и уничтожили 395,5 млн записей, включая данные о бронированиях, заказах туров и финансовых транзакциях, а также удалили бэкапы.

В Tez Tour подтвердили саму атаку, но подче…

1 day, 9 hours назад @ xakep.ru
Vision. Тестируем браузер, помогающий скрыться от наблюдения
Vision. Тестируем браузер, помогающий скрыться от наблюдения Vision. Тестируем браузер, помогающий скрыться от наблюдения

Но полез­ное есть и для рядово­го юзе­ра: мож­но удоб­но раз­делить рабочий и лич­ные про­фили, сколь­ко бы их ни было, и не рис­ковать утеч­ками меж­ду ними.

comВско­ре мне уда­лось вяс­нить диаг­ноз: исполь­зует­ся SSL pinning, то есть бра­узер активно про­веря­ет под­линность сер­тифика­та бэкен­да и на липу от Burp Suite не ведет­ся.

Выб­рать и виде­окар­ту, и веб‑камеру, и количес­тво меди­аус­трой­ств, и раз­решение экра­на.

Кро­ме экс­клю­зив­ных для Vision парамет­ров отпе­чат­ков, залезть мож­но и в самое сер­дце бра­узе­ра – в дви­жок Chromium.

Базовый тариф на одно­го челове­ка обой­дет­ся в $ 29 в месяц, а при под­писке сра­зу на год – на поч­ти треть дешев­ле, все­го $ 20.

1 day, 10 hours назад @ xakep.ru
Во время тестов агент OpenAI взломал сайт правительства Австралии
Во время тестов агент OpenAI взломал сайт правительства Австралии Во время тестов агент OpenAI взломал сайт правительства Австралии

Стало известно, что во время внутреннего тестирования ИИ-агент OpenAI обошел защиту австралийского государственного портала Medicare и получил доступ к непубличным файлам.

Инцидент произошел еще 18 июня 2026 года, когда в OpenAI тестировали модель, которой поручили собрать сведения о государственных расходах на лекарства.

В OpenAI рассказали, что выявили этот инцидент в августе, во время расследования случаев так называемого «misaligned model activity».

Отметим, что практически одновременно с этим специалисты исследовательской лаборатории Transluce рассказали еще о нескольких похожих случаях, связанных с атаками ИИ-агентов.

В OpenAI сообщили, что многие эпизоды, описанные Transluce, уже явл…

2 days назад @ xakep.ru
ИИ-агенты похитили данные 600 000 банковских карт и заразили более 100 сайтов скиммерами
ИИ-агенты похитили данные 600 000 банковских карт и заразили более 100 сайтов скиммерами ИИ-агенты похитили данные 600 000 банковских карт и заразили более 100 сайтов скиммерами

Так, с июля 2026 года хакер успел атаковать сотни целей, похитить данные более 600 000 банковских карт и внедрить веб-скиммеры как минимум на 119 сайтов.

В разных случаях злоумышленник добавлял вредоносный код в легитимные JavaScript-файлы и на страницы оплаты, встраивал его в блоки Google Tag, модифицировал содержимое S3 и CDN, серверный кеш и поля БД.

В ходе расследования выяснилось, что после кражи данных банковских карт ИИ-агент удалял их из баз Magento.

Такая инструкция содержалась в одном из файлов навыков Hermes: после кражи и скачивания данных банковских карт агент должен был удалить их из базы Magento.

В результате несколько пострадавших магазинов столкнулись с потерей данных и сбо…

2 days, 2 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 2 часа назад
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30.

The advisory also does not name Cisco SD-WAN Cloud-Pro or Cisco SD-WAN for Government (FedRAMP), two deployment types named in the May and June advisories.

Cisco SD-WAN Cloud (Cisco Managed) is already fixed in release 20.15.605, and customers on it need to take no action.

CVE-2026-76504 follows a series of Cisco SD-WAN flaws flagged as exploited this year.

As of September 30, the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog listed eight Cisc…

2 часа назад @ thehackernews.com
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures

Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware.

They are hosted on the legitimate ChatGPT website with the Custom GPT name at the top.

"In the incidents we saw, victims interacted with an attacker-created Custom GPT, which was programmed to respond to their prompts with a message that included a Google Sites link," Huntress said.

The two Custom GPT links are listed below -chatgpt[.

"Overall, threat actors continue to turn trusted platforms into convincing entry points for social engineering, whether via ChatGPT's Custom GPT feature or through Googl…

2 часа назад @ thehackernews.com
Know Your Enemy: Browser-Based Attack Techniques in 2026
Know Your Enemy: Browser-Based Attack Techniques in 2026 Know Your Enemy: Browser-Based Attack Techniques in 2026

Most breaches today begin in a browser session.

According to Push data, roughly 1 in every 2 phishing attacks is delivered outside of email entirely.

Malicious browser extensionsAttackers use malicious extensions to steal data, log keystrokes, and intercept credentials and tokens as they transit the browser.

Most malicious extensions didn't start that way — attackers acquire legitimate extensions and wait until install counts reach maximum impact before deploying a malicious update.

For more detail on each of these attack techniques, how they work in the wild, and what you can do about them, check out the guide to 2026 Browser Attack Techniques from Push Security.

5 часов назад @ thehackernews.com
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said.

Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released.

The agent created a public repository in the developer's personal GitHub account and posted the screenshots there.

So they put the images in a separate public repository, usually under the developer's own account, and made them available to reviewers from there.

It recommends these steps:Require a review step before an agent creates a public repository, pushe…

6 часов назад @ thehackernews.com
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States.

CSuite Phishing Leads to Both Account and Endpoint AccessCSuite attack chain exposed by ANY.RUN researchersCSuite starts with familiar business lures built around Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365.

Victims can be pushed into credential-harvesting or device-code phishing flows designed to capture Microsoft 365 access and active sessions.

CSuite sandbox submissions by countryThe campaign also reached several high-value sectors.

Persistent remote access: Abused RMM tools can keep attackers connected to victim systems a…

6 часов назад @ thehackernews.com
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

"For example, clients accessing /vpn/media/e6ee7c85.ico would be served by the dropped PHP web shell e6ee7c85.sig," Google said.

This may be an indication of attackers managing similar web shells in multiple compromised environments."

The attack chain then progresses to establishing persistent root-level execution for its web shells by leveraging the installer web shells to alter the permissions of "/bin/sh," and then initiate a full NetScaler appliance reboot.

One such web shell is WHIPSHOT, which extracts Base64-encoded commands and payloads from HTTP headers, executes them, and returns the results.

"We are observing wide-scale web shell and malware deployment for the primary purposes of …

9 часов назад @ thehackernews.com
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes.

OpenSSL 3.0 stopped getting public security fixes on September 7.

What OpenSSL 3.0 Users Can DoThe last public 3.0 release was 3.0.22, on August 25.

For Ubuntu 22.04 and 24.04, which use OpenSSL 3.0, the fix is already available in the packages listed above.

Anyone who builds OpenSSL 3.0 or ships a copy inside their own software has no public fix from OpenSSL.

9 часов назад @ thehackernews.com
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler Packet Processing Engine (NSPPE).

"For example, a 120-byte handshake message can arrive as 120 fragments.

Once every position has arrived, the server considers the 120-byte message complete.

"The malicious records tell the reassembly code that each record supplies only one byte of a 120-byte handshake message," Kheirkhah said.

After 120 records, the handshake message is considered complete, but its NSB chain contains about 174 KB of data."

12 часов назад @ thehackernews.com
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July.

The stolen data covers a little over 350,000 individuals and a little over 250,000 businesses, the DGFIP says.

How the Attacker Got InThe attacker used two separate routes, according to the report.

The first route relied on several dozen passwords belonging to DGFIP staff, stolen over three months.

PIGP is a web portal that DGFIP staff used for email and HR services.

23 часа назад @ thehackernews.com
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.

By 2023, it had already used fake conference and event invitations as bait, often exchanging messages with a target before sending a malicious link.

Since March, those campaigns have used email accounts on WordPress and cPanel websites, which Microsoft is highly confident the group hacked for that purpose.

People who replied to an Atlantic Council-themed invitation got a link to DarkSword, an iPhone exploit kit, instead of the Windows backdoor, according to Microsoft.

That campaign used fake invitations to the Ukra…

1 day назад @ thehackernews.com
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

"In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a transient execute-after-free primitive.

Spectre v2 is one specific type of the Spectre attack that abuses indirect branch prediction in modern processors to achieve the same goals.

The attacker triggers the indirect branch again, the CPU uses the now-stale branch target buffer (BTB) entry and speculatively jumps to the old training-chunk entry point.

Following responsible disclosure, mitigations for BTR have been released and merged into the Linux kernel (CVE-2026-64507 and CVE-2026-64508).

"Mozilla considered IBPB [Indirect Branch Predictor Barrier]-based mi…

1 day назад @ thehackernews.com
Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown.

"Kiteworks developed and deployed a fix during the window, [and] applied an additional protective layer across all environments."

Kiteworks has not disclosed any specifics about the nature of the flaw, and how it could be exploited.

"Telling customers to take production systems offline is not a decision any vendor makes lightly, and we knew exactly what we were asking of them," Kiteworks CISO Frank Balonis said.

Now that the threat window has passed and no anomalies were observed, customers are…

1 day, 3 hours назад @ thehackernews.com
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub.

"The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical write-up published Monday.

These packages have been collectively downloaded 490,000 times, out of which 116,000 occurred in the last 30 days.

The same channel IDs, the same remote channel lists, and the same GitHub accounts appear across packages with different names and publishers.

Developers are advised …

1 day, 3 hours назад @ thehackernews.com
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group.

"It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijke Opsporing en Interventies said in an X post Monday.

Per DataBreaches.Net, van der Stap was arrested on September 15, 2026.

"Working at Hadrian and volunteering at DIVD made me more paranoid about keeping up appearances, and I actually felt more pressure and paranoia because I was working such long hours," van der Stap told DataBreaches.Net in June 2023.

He is presently employed as the offensive security lead at th…

1 day, 8 hours назад @ thehackernews.com
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory.

The fix is in versions 1.30.0 and 2.2.0.

With the stolen credentials, the attacker can request a valid access token from the real login service.

Without it, they still follow whichever server the MCP server points them at.

After upgrading, clear any stored OAuth client registrations once, because older ones are not tied to a login service and stay that way.

1 day, 11 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 1 day, 8 hours назад
Timeshare exit scams: From fake buyers to recovery fraud
Timeshare exit scams: From fake buyers to recovery fraud Timeshare exit scams: From fake buyers to recovery fraud

If an exit company cold calls you or makes 100% guaranteed promises of a swift exit, they’re likely to be a scammer.

If you’ve already paid a scam timeshare exit company, there’s still a chance you could get your money back if you act quickly.

What are the warning signs of a timeshare exit scam?

How can I check whether a timeshare exit company is legitimate?

What should I do if I've already paid a timeshare exit scam company?

1 day, 8 hours назад @ welivesecurity.com
The devil is still in the email – but wearing a new mask
The devil is still in the email – but wearing a new mask The devil is still in the email – but wearing a new mask

Some techniques go after live sessions themselves, with attackers shifting their focus from stealing passwords to stealing authentication tokens.

Purpose-built AI tools now make it trivial to clean up the language and even tailor the lure for each recipient.

What’s more, the code is scanned on a phone, so the usual controls that protect company-issued laptops don’t apply.

The ‘device hop’ also means that the company may have a hard time developing a full picture of the attack.

AI helps deal with the volume and speed involved, whereas experienced analysts can assess the evidence and direct the response.

2 days, 8 hours назад @ welivesecurity.com
Is that vibe coded app safe? 5 checks before you download
Is that vibe coded app safe? 5 checks before you download Is that vibe coded app safe? 5 checks before you download

Vibe coded apps may also be exposed to prompt injection.

What can go wrong with vibe coded apps?

With a badly coded app, the leak usually happens on the developer’s servers, so start with your account and credentials.

Frequently asked questions (FAQs)What does 'vibe coded' mean?

Are all vibe coded apps dangerous?

5 days, 8 hours назад @ welivesecurity.com
Been told to pay at a Bitcoin ATM? Read this first
Been told to pay at a Bitcoin ATM? Read this first Been told to pay at a Bitcoin ATM? Read this first

No real government agency, bank, or company will ever tell you to pay them via a Bitcoin ATM.

How do Bitcoin ATM scams work?

How do I stay safe from Bitcoin ATM scams?

What can I do straight after a Bitcoin ATM scam?

What should I do if I’ve fallen for a Bitcoin ATM scam?

6 days, 8 hours назад @ welivesecurity.com
Looking for free Robux? Here’s what’s real, and what’s a scam
Looking for free Robux? Here’s what’s real, and what’s a scam Looking for free Robux? Here’s what’s real, and what’s a scam

Roblox itself is very clear: “There is no such thing as free Robux or subscription offers, tricks, or codes.”What there is, unfortunately, are a lot of scammers looking to trick you out of your personal information and logins with the promise of free Robux.

But it’s also about helping them understand there’s no such thing as ‘free’ Robux.

Frequently asked questions (FAQs)Is there a real free Robux generator?

Roblox says there is no legitimate way to get free Robux through generators, tricks or codes.

But these aren’t ‘free Robux generators.’How can I tell if a Robux offer is a scam?

1 week, 1 day назад @ welivesecurity.com
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive

Many have moved past chatbots and begun assigning work to AI agents in the hope of gaining an edge on their similarly resource-strapped competitors and levelling the playing field with larger companies.

Indeed, the ambitious adopters are deploying, or at least experimenting with, multi-agent ‘assembly lines,’ where one supervisor agent manages swarms of specialist agents and passes work between them.

Of course, some risks surrounding AI agents have familiar roots: an agent’s supply chains can be compromised and its permissions abused.

Agents can also suffer from agentic misalignment where they proceed doggedly even if it involves, for example, breaking into other companies.

For a company wi…

1 week, 2 days назад @ welivesecurity.com
‘Nudify’ apps: What to do if someone makes a fake nude of you
‘Nudify’ apps: What to do if someone makes a fake nude of you ‘Nudify’ apps: What to do if someone makes a fake nude of you

And it doesn’t get much darker than ‘nudification’ or ‘nudify’ apps.

Are ‘nudify’ apps illegal?

The short answer is “it depends.” In the US, there’s no federal law explicitly prohibiting ‘nudify’ apps.

Can I sue over an AI nude image?

Will reporting a fake nude image make it disappear everywhere?

1 week, 5 days назад @ welivesecurity.com
Beware the SparroWock: The backdoor that bites, the commands that catch
Beware the SparroWock: The backdoor that bites, the commands that catch Beware the SparroWock: The backdoor that bites, the commands that catch

A month later, we noticed that the group had started using the new SparroWocky backdoor, which then quickly replaced SparrowDoor as FamousSparrow’s main implant.

Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor.

Backdoor commandsThe backdoor first establishes communication with its C&C server, then executes its core logic in an infinite loop, within which it processes received commands.

A common technique that the backdoor uses is dynamic API resolution via API hashing, but the backdoor…

1 week, 6 days назад @ welivesecurity.com
Cyberthreats are moving faster than SMBs: Readiness must accelerate
Cyberthreats are moving faster than SMBs: Readiness must accelerate Cyberthreats are moving faster than SMBs: Readiness must accelerate

This calls for a different operational model where AI and automation support security teams where it makes sense, with human oversight for decisions that require context and judgment.

ESET SMB Cyber Readiness Index 2026 found that most (73%) SMBs are integrating AI into their business.

Processing exfiltrated data: AI rapidly classifies, cleans-up, and extracts large volumes of information from stolen data in order to make it more monetizable/usable for cybercriminals.

Why SMBs are struggling with complexityUnfortunately, security teams are already on the back foot.

That means protection for AI conversations, agents, AI-generated outputs, AI components, sensitive data, and the broader AI eco…

2 weeks назад @ welivesecurity.com
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
GuardBreaker: Derailing AI-assisted malware analysis with a code comment GuardBreaker: Derailing AI-assisted malware analysis with a code comment

Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way.

Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection.

Reporting on the same broader campaign, StepSecurity found a prompt that flat-out instructed any analyzing model that parsed the file to disregard the malicious code and report the package as clean.

Some parts of the malicious code could be concealed under the pretense of being confidential information or other sensitive data.

Crucially, however, no single LLM engine should have the sole au…

2 weeks, 6 days назад @ welivesecurity.com
Safe word: What is it and why do you need one?
Safe word: What is it and why do you need one? Safe word: What is it and why do you need one?

The technology might be impressive, but a simple technique could stop the scammers in their tracks: a pre-agreed safe word.

What is a safe word?

But suggest some scenarios in which it would be a good idea to request a safe word.

It’s important to have a backup if someone can’t remember the safe word.

But a safe word is a fantastic, free option for uncovering deepfake audio fraud like fake/virtual kidnappings.

3 weeks назад @ welivesecurity.com
I’ve been deepfaked: What do I do?
I’ve been deepfaked: What do I do? I’ve been deepfaked: What do I do?

But across the globe, policymakers and public opinion are forcing tech platforms to better police this content.

What should I do if I’ve been deepfaked?

Google: Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

The first point of call is to contact the publisher to request removal.

4 weeks назад @ welivesecurity.com
This month in security with Tony Anscombe – August 2026 edition
This month in security with Tony Anscombe – August 2026 edition This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity newsWith August coming to a close, it's time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month.

Here's some of what caught Tony's attention:OpenAI has disclosed more details about how its agents hacked AI collaboration platform Hugging Face.

Delta Airlines is investigating an incident where a flight passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network.

What are the lessons that businesses and critical infra…

1 month назад @ welivesecurity.com
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
AI-assisted reconnaissance: Why everyone could be a viable target for fraud AI-assisted reconnaissance: Why everyone could be a viable target for fraud

And of course, linking our professional and personal social media accounts is a simple task for AI.

For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information.

Losing your personal information is one thing.

What you can do about AI-powered OSINTWhen it comes to AI-powered reconnaissance, there are things you can control and things you can’t.

Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.

1 month назад @ welivesecurity.com
How QR-code phishing can slip past corporate security measures
How QR-code phishing can slip past corporate security measures How QR-code phishing can slip past corporate security measures

So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years.

Most importantly, they take the victim from a relatively well-protected corporate environment to a potentially unmanaged mobile device, thus bypassing business-grade security.

Malicious QR codes are frequently embedded in alerts urging users to secure their account, or authenticate to confirm their details.

Encourage employees to avoid scanning QR codes in unsolicited emails and report anything suspicious.

Next, consider technical controls, including email security from a reputable vendor to minimize the risk of quishing emails ending up in users’…

1 month, 2 weeks назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 4 часа назад
Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)
Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)

“Advanced and suspected state-sponsored threat actors” are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the two recently disclosed NetScaler vulnerabilities that have been exploited as zero-days, says Mandiant CTO Charles Carmakal.

They say that they first flagged in-the-wild exploitation of CVE-2026-88772 in late September 2026 and that the exploitation activity has been ongoing since at least early September.

How the attacks unfolded“Exploitation of CVE-2026-88772 bypasses authentication and triggers an unhandled termination of the NetScaler Packet Processing Engine (NSPPE) to establish initial root-level access,” they found.

Patching is not en…

4 часа назад @ helpnetsecurity.com
AI coding agents leaked 13,000 internal company screenshots to public GitHub repos
AI coding agents leaked 13,000 internal company screenshots to public GitHub repos AI coding agents leaked 13,000 internal company screenshots to public GitHub repos

When developers ask AI coding agents to prove that a user interface fix works, some agents have been posting the evidence where anyone can find it, according to Glow Labs.

Diagram showing how AI agents leak screenshots to public repos (Source: Glow Labs)The researchers found more than 13,000 internal images published openly on GitHub by developers at over 300 organizations.

A tool agents picked upAbout a third of the affected organizations had developers running gitshot, an open-source tool that publishes screenshots for code reviews.

“This is representative of the reasoning for AI agents at many of the organizations affected by this issue,” the researchers added.

“Hardening AI tool configu…

5 часов назад @ helpnetsecurity.com
OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised
OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised

Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage.

OpenInfra Europe’s security incident notice“Anyone who downloaded or installed artifacts from https://artifactory.nordix.org/ from August 28 and September 15, 2026 should immediately stop using them, remove them from their pipelines, and treat these packages as potentially compromised,” the message says.

Compromise through CVE-2026-82329The OpenInfra Foundation is part of the non-profit Linux Foundation.

It hosts and supports open source projects for running cloud and datacenter infra…

6 часов назад @ helpnetsecurity.com
Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore
Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore

The option is part of a set of backup updates the company finished rolling out with Signal for iOS version 8.30.

The changes build on Signal Secure Backups, an optional end-to-end encrypted backup service introduced in September 2025.

Local and hosted backupsSignal Desktop and Signal for iOS can make on-device backups for the first time.

Local backup option on iOS (Source: Signal)“Previously, the local Signal Android backups included everything in a single archive, so daily snapshots took up a lot of extra space.

Their recovery key decrypts all past backups, and Signal warns users never to share it with anyone.

8 часов назад @ helpnetsecurity.com
Former US Air Force members behind million-dollar BEC scheme head to prison
Former US Air Force members behind million-dollar BEC scheme head to prison Former US Air Force members behind million-dollar BEC scheme head to prison

Two men who ran BEC and phishing campaigns against US businesses while serving in the Air Force have been sentenced to a combined 189 months in federal prison.

They shared the information with each other and used it to make and attempt transactions without the victims’ knowledge or authorization.

Odimegwu was sentenced to 111 months in prison and ordered to pay $366,617.59 in restitution.

Each will serve three years of supervised release after completing his prison term.

This is the second case in just a few days involving US service members sentenced for cybercrime.

9 часов назад @ helpnetsecurity.com
Genea brings AI agents to access control with role-based permissions
Genea brings AI agents to access control with role-based permissions Genea brings AI agents to access control with role-based permissions

Genea has announced the release of Genea MCP, a Model Context Protocol (MCP) server that connects AI agents directly to the Genea Access Control platform.

Genea is one of the first access control providers to launch a native MCP server.

Most access control work isn’t hard, but it can be tedious.

Teams can manage people, temporary access, access groups, doors, and controllers without opening the portal.

“Access control software has always made administrators learn the system,” said Michael Wong, CEO and President of Genea.

10 часов назад @ helpnetsecurity.com
Security tools can now scan Claude Enterprise chats and uploads for sensitive data
Security tools can now scan Claude Enterprise chats and uploads for sensitive data Security tools can now scan Claude Enterprise chats and uploads for sensitive data

More than 100 security and compliance vendors have integrations with the Claude Compliance API, which lets a company send Claude activity into the monitoring tools it already uses.

The partners span data loss prevention (tools that flag sensitive data leaving a company), SIEM (systems that collect security logs for investigation), identity, eDiscovery and AI security posture management.

What each vendor sees varies: Salt Security and Torch Security read no conversation content, and Datadog ingests audit logs from Claude Platform.

Netskope’s integration is in private preview and Okta’s is headed to beta for select customers.

Vanta’s is in beta for select customers, with general availability …

10 часов назад @ helpnetsecurity.com
OWASP Noir: Open-source static analysis tool
OWASP Noir: Open-source static analysis tool OWASP Noir: Open-source static analysis tool

OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from.

Tools like ZAP and Burp Suite, known as DAST tools, poke at a running apps from the outside and find many of its routes by crawling.

When the static rules miss a framework, or an app uses one-off custom routing, Noir can hand the code to an LLM through OpenAI, Ollama, or similar providers.

DAST tools including ZAP, Burp Suite, Caido, and Gori receive the routes as a proxy target or an OpenAPI import.

Must read:Subscribe to the Help Net Security ad-free monthly newslett…

12 часов назад @ helpnetsecurity.com
EU Cyber Resilience Act requirements for containers and Kubernetes
EU Cyber Resilience Act requirements for containers and Kubernetes EU Cyber Resilience Act requirements for containers and Kubernetes

Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity requirements for all products with digital elements sold in EU markets.

The CRA brings new requirements for teams working with containers and Kubernetes regarding how cloud native applications are built, distributed, and maintained throughout their lifecycle.

CRA scope items include container images distributed publicly, commercial Kubernetes operators, Helm charts with commercial support, and open source with commercial backing.

As part of the regulation, a compliance chain is required throughout the cloud native supply chain.

Important CRA requirem…

12 часов назад @ helpnetsecurity.com
In this new SME cybersecurity service, the AI assists and the consultants decide
In this new SME cybersecurity service, the AI assists and the consultants decide In this new SME cybersecurity service, the AI assists and the consultants decide

Brian Honan, BH Consulting’s CEO, described who carries that load inside a small company.

The services run from risk assessments and technical testing to incident response planning, data protection, AI governance, third-party risk and executive reporting.

The MSP keeps the firewallSome managed service providers (MSPs) and managed security service providers (MSSPs) already bundle compliance work into their contracts.

BH Haven does not manage a client’s firewall or endpoints, and it does not run a security operations center (SOC), the team that monitors systems for attacks.

Honan sees those providers primarily as potential partners whose work BH Haven can independently assess.

13 часов назад @ helpnetsecurity.com
Most open critical and high flaws are over 90 days old
Most open critical and high flaws are over 90 days old Most open critical and high flaws are over 90 days old

In the best-performing market, fewer than one in seven open critical or high findings is less than three months old.

Detectify calls the alternative risk tolerance drift, where flaws left open long enough get treated as accepted by default.

Exposed AI tools come with slower fixesResearchers are finding more publicly exposed AI platforms on customer estates, including Lovable and Base44.

Its early numbers point to organizations with exposed AI tooling resolving critical and high-severity flaws at less than half the rate of the wider customer base.

“What we can measure is publicly exposed AI tooling, which isn’t necessarily shadow AI: much of it may be known and approved.

13 часов назад @ helpnetsecurity.com
WSL containers are generally available on Windows
WSL containers are generally available on Windows WSL containers are generally available on Windows

Microsoft made WSL containers generally available and shipped the feature with controls that let administrators switch it off or limit where it pulls images from.

WSL containers run Linux containers on Windows through the Windows Subsystem for Linux.

It also includes an API that lets native Windows apps run Linux containers, and Microsoft points to local AI workloads as one use.

VS Code dev containers can use wslc as their default driver, and Aspire can treat WSL containers as a container runtime.

What Defender seesMicrosoft Defender for Endpoint already had a plugin for WSL, and it now covers containers.

13 часов назад @ helpnetsecurity.com
Most organizations need six months or longer to roll out new security controls
Most organizations need six months or longer to roll out new security controls Most organizations need six months or longer to roll out new security controls

Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group.

Cisco gave the most weight in its scoring to internal friction, meaning the delays and turf problems inside a company that slow a security team when something changes.

Cisco says frontier AI models can find software vulnerabilities at a scale and speed no human team working alone can match.

Fewer than one in ten respondents are confident they can stay ahead of the flood of new threats.

Months to switch on a controlOnly 21% of organizations say they can switch on a new security control within six months, and that clock starts after b…

14 часов назад @ helpnetsecurity.com
Post-quantum website certificates from Cloudflare are scheduled for early 2027
Post-quantum website certificates from Cloudflare are scheduled for early 2027 Post-quantum website certificates from Cloudflare are scheduled for early 2027

Cloudflare plans to become a public certificate authority (CA), an organization that issues the digital certificates websites use to encrypt traffic and prove who they are.

The company said that its CA will issue conventional certificates and a post-quantum type called Merkle Tree Certificates (MTCs), with production MTC issuance scheduled for the first quarter of 2027.

Cloudflare says much of the web’s certificate issuing rests on a small set of dominant CAs, so one failure or compromise would spread widely.

A root certificate tells browsers and devices whether to trust a CA.

Cloudflare has agreed to acquire publicly trusted root key material from GlobalSign so its certificates are recogni…

14 часов назад @ helpnetsecurity.com
NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771) NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)

The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated.

From rumor to confirmed zero-dayRumors about a NetScaler zero-day being exploited in the wild started late last week, and were confirmed when Citrix published a security advisory after the release of patches for eight critical and high-risk vulnerabilities.

“If you run NetScaler and you haven’t patched, assume you are already being probed,” he added.

CERT-EU also posted technical details and threat-hunting advice and pointers for organizations, informed by the investigation it started after hearing rumors of exploitation.

“Microsoft hosts 4,254 (10%) and Amazon 3,013 (7%), consistent with…

1 day, 2 hours назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 6 часов назад
I Want Better Reporting on AI Genie Behavior
I Want Better Reporting on AI Genie Behavior I Want Better Reporting on AI Genie Behavior

AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening.

I wish the popular press would report on this better. I don’t like the “going rogue” framing because it deflects the responsibility from the prompters—often the AI companies themselves. And now, pretty much anything off-script is being called “hacking.”

Take, for example, the recent stories of one of OpenAI’s models hacking into government systems. First, ...

6 часов назад @ schneier.com
Using Device Linking to Eavesdrop on WhatsApp and Signal
Using Device Linking to Eavesdrop on WhatsApp and Signal Using Device Linking to Eavesdrop on WhatsApp and Signal

Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability:

Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers.

Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account.

Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them.

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sancti…

1 day, 6 hours назад @ schneier.com
New Attack Against RSA
New Attack Against RSA New Attack Against RSA

ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.

First, this attack isn’t new. The original research is from 2007. What is new is the implementation.

Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.

Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice.

Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with …

2 days, 6 hours назад @ schneier.com
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

I feel like someone who reads this blog will want to go to this:

Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life.

[…]

During the guided squid dissection, each family will work together to examine a squid up close, exploring its organs, structures, and specialized features. The experience provides a memorable opportunity for children and adults to see firsthand how the anatomy of a squid helps it survive in it…

4 days, 20 hours назад @ schneier.com
On Anthropic’s AI Misuse Report
On Anthropic’s AI Misuse Report On Anthropic’s AI Misuse Report

Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.

A few of the highlights: AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.

The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations.

...

5 days, 6 hours назад @ schneier.com
Malicious npm Packages That Evade Defenses
Malicious npm Packages That Evade Defenses Malicious npm Packages That Evade Defenses

This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

6 days, 6 hours назад @ schneier.com
Research on Models Engaging in Genie-Like Behavior
Research on Models Engaging in Genie-Like Behavior Research on Models Engaging in Genie-Like Behavior

New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.”

Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be …

1 week назад @ schneier.com
GPT-6 Astra Breaks an Old Enigma Message
GPT-6 Astra Breaks an Old Enigma Message GPT-6 Astra Breaks an Old Enigma Message

This is pretty amazing:

However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message. After trying many different approaches, GPT­6 Astra focused on using the repeated place name ROSENOW ROSENOW as a crib. After developing the necessary Python and C++ soft…

1 week, 1 day назад @ schneier.com
Reverse-Engineering Flock Cameras
Reverse-Engineering Flock Cameras Reverse-Engineering Flock Cameras

Hackers captured a Flock camera and got a look (alternate link) at the software:

While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag...

1 week, 2 days назад @ schneier.com
Friday Squid Blogging: On Squid Egg Sacs
Friday Squid Blogging: On Squid Egg Sacs Friday Squid Blogging: On Squid Egg Sacs

Short essay about squid egg sacs.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

1 week, 4 days назад @ schneier.com
Are AIs Still Struggling with CAPTCHAs?
Are AIs Still Struggling with CAPTCHAs? Are AIs Still Struggling with CAPTCHAs?

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.

In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed, it couldn’t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions.

“Actually hmm, wait,” it said in its chain-of-thought transcript, later adding “Ugh,” because we’ve decided that we need to inject human mannerisms into these machines…

1 week, 5 days назад @ schneier.com
How Candidates Could Use AI for Good
How Candidates Could Use AI for Good How Candidates Could Use AI for Good

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The White House is posting slopaganda.

Meanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters’ concerns, engage constituents more inclusively, and formulate policy platforms that are more responsive to our input. There are vanishingly few examples of this in ...

1 week, 6 days назад @ schneier.com
Fake CAPTCHA Scams
Fake CAPTCHA Scams Fake CAPTCHA Scams

New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.

2 weeks назад @ schneier.com
25 Years of Mass Surveillance Is Enough
25 Years of Mass Surveillance Is Enough 25 Years of Mass Surveillance Is Enough

This essay was written with Cindy Cohn, and originally appeared in Lawfare.

One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in...

2 weeks, 1 day назад @ schneier.com
On the NSA’s Supercomputer from the 1960s
On the NSA’s Supercomputer from the 1960s On the NSA’s Supercomputer from the 1960s

Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.

2 weeks, 1 day назад @ schneier.com
Krebs On Security
последний пост 2 days, 2 hours назад
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.

Van der Stap is currently employed as offensive security lead at the Dutch company Neo Security, which did not respond to requests for comment.

But not long after that interview, the Dutch hacker abruptly stopped replying to messages.

One source said a colleague of theirs personally witnessed Dutch authorities carting items out of Van der Stap’s residence.

Speaking with reporters from Bloomberg in 2024, Van der Stap said that singular focus in turn fueled his desire to carry out cyberattacks.

2 days, 2 hours назад @ krebsonsecurity.com
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.

Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data.

Less than a month later, Wagenius was arrested and charged in two separate federal indictments, and soon pleaded guilty to all counts in both cases.

In 2019, Schuchm…

4 days, 19 hours назад @ krebsonsecurity.com
Data Broker Radaris Loses Domains in Privacy Fight
Data Broker Radaris Loses Domains in Privacy Fight Data Broker Radaris Loses Domains in Privacy Fight

In February 2024, Radaris was sued by Atlas Data Privacy Corp, a company that has been pursuing data brokers alleged to be violating a New Jersey statute called Daniel’s Law.

KrebsOnSecurity doubled down and showed how the Lubarsky brothers built and operated Radaris and other data broker companies using a fictitious CEO’s name.

All told, the New Jersey court has so far transferred 14 domain names from the Radaris family of companies to Atlas.

Sherman said federal lawmakers have long faced intense lobbying by the technology industry against more restrictive U.S. data privacy laws, but that many powerful industries are now working against passing comprehensive data privacy legislation.

The l…

1 week, 6 days назад @ krebsonsecurity.com
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Plugs Nearly 1,000 Security Holes Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.

This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities.

Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10.

And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.

Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear…

3 weeks назад @ krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards.

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.

Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s ide…

4 weeks назад @ krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

1 month назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

1 month, 2 weeks назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

1 month, 2 weeks назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

1 month, 3 weeks назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

2 months назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

2 months, 1 week назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

2 months, 2 weeks назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

2 months, 2 weeks назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

2 months, 3 weeks назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

2 months, 4 weeks назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 7 часов назад
Pentagon personnel database breach exposes personal data of millions
Pentagon personnel database breach exposes personal data of millions Pentagon personnel database breach exposes personal data of millions

The unencrypted files contained Social Security numbers, names, birth dates, contact details, and other military personnel data including - in some cases - details of the jobs individuals held.

Breaches like this matter because the combination of Social Security numbers, names, and dates of birth make up the bread and butter of any self-respecting fraudster.

Personnel data, of course, has also been a target before.

The news of the Pentagon's latest data breach comes as the FBI warns its own employees about a separate breach of its FBIJobs.gov portal.

The ShinyHunters hacking group has claimed credit for the hack and threatened to publish staff details including... you guessed it... Social S…

7 часов назад @ bitdefender.com
Ukrainian ransomware developer jailed for nearly 13 years
Ukrainian ransomware developer jailed for nearly 13 years Ukrainian ransomware developer jailed for nearly 13 years

A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world.

The 52-year-old man, who according to local media reports had been living in the Basel-Landschaft region but has not been named, found by the court to be the lead developer of the LockerGoga, MegaCortex, and Nefilim families of ransomware.

In all, prosecutors claimed that some 100 million Swiss Francs (US $123 million) worth of damage was caused by the ransomware attacks.

Ukrainian national Tymoshchuk allegedly released new strains of his ransomware whenever old ones had been decrypted.

In…

6 days, 4 hours назад @ bitdefender.com
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras

Smashing Security, episode 486, Vibe-Coded Shops and Hackable Flock Cameras, with Graham Cluley and special guest Dave Bittner.

I will say I did not go gaga for La La the way many other people did.

Anyway, if any of you are still listening, I love La La Land.

This La La Land lunatic has watched the movie with his pause button.

This was definitely not created — if you haven't seen La La Land, go watch La La Land for goodness' sake.

6 days, 18 hours назад @ grahamcluley.com
US Coast Guard and FBI board oil tanker to investigate cyber attack
US Coast Guard and FBI board oil tanker to investigate cyber attack US Coast Guard and FBI board oil tanker to investigate cyber attack

An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.

The VL Prosperity - a Liberian-flagged supertanker carrying roughly 2.3 million barrels of crude oil - apparently suffered a cyber attack while en route from Egypt's Sidi Kerir oil terminal to Galveston, Texas.

Two weeks later, a specialised team from the FBI and US Coast Guard boarded the vessel for four days, investigating the problem and helping the crew eradicate the threat from its IT and OT systems.

According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromised by a f…

1 week, 6 days назад @ bitdefender.com
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Smashing Security podcast #485: These researchers got drunk to hack an LG TV Smashing Security podcast #485: These researchers got drunk to hack an LG TV

That's really, really cool.

And I'm going to be getting really, really sozzled by looking at the security of LG smart TVs.

So it's really, really compelling.

When we started off on the journey of building this AI pen testing approach, there was a lot of scepticism.

And listeners, you can learn more about Intruder or even start your own AI pen test in minutes.

1 week, 6 days назад @ grahamcluley.com
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store.

According to Carter's own plea agreement, the scam ran from May 2018 to November 2019 and involved at least three co-conspirators alongside Carter.

Carter would use his privileged store access to move a victim's number onto a SIM card under the control of himself or an accomplice.

In one incident in May 2018, described in Carter's plea agreement, the store employee swapped a victim's number onto an Alcatel handset while working his shift in Portland.

In December 2018, Carter successfully hijacked the number of a victim known as "S.Q.T" in Portland, and this time their account was successfully drained of …

2 weeks, 1 day назад @ bitdefender.com
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars ‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.

Because it might just be that you draw the attention of the authorities.

Back in October 2024, we wrote about how he was arrested after allegedly tricking a single victim out of US $230 million worth of Bitcoin while posing as Google Support.

The party days are over now for Lam, who faces up to 20 years in prison when he is eventually sentenced.

You money may be a lot more safely stored in a hardware cold wallet.

2 weeks, 6 days назад @ bitdefender.com
Smashing Security podcast #484: How websites are tracking you with silence
Smashing Security podcast #484: How websites are tracking you with silence Smashing Security podcast #484: How websites are tracking you with silence

Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.

I get by in the world, but I don't think you need me for listening for something really, really far away.

I don't know what the difference — I mean, now we get to see, I've opened a can of worms here.

I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human.

And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.

2 weeks, 6 days назад @ grahamcluley.com
CRPx0 ransomware: what you need to know
CRPx0 ransomware: what you need to know

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

3 weeks назад @ fortra.com
The US military just turned off ad tracking on its phones. Maybe you should too
The US military just turned off ad tracking on its phones. Maybe you should too The US military just turned off ad tracking on its phones. Maybe you should too

Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target American forces in the Middle East.

Every smartphone carries a mobile advertising ID - Apple calls its version the IDFA, and Google calls its the GAID.

Back in April, US Central Command reportedly warned of "multiple threat reports concerning adversary exploitation of commercial location data."

Recent versions should let you delete your advertising ID entirely.

If it's good enough for the US military - maybe it should be good enough for you too.

3 weeks, 1 day назад @ bitdefender.com
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo's own identity system, Lenovo ID.

So, anyone wanting to access your Dropbox account just had to sign up for a Lenovo account using your email address.

Don't just turn it on for your Dropbox account, enable it everywhere it is made available.

This hack of 5000 Dropbox accounts was not sophisticated.

One can only be grateful that the problem was discovered after only 5000 Dropbox accounts were accessed.

3 weeks, 2 days назад @ bitdefender.com
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Smashing Security podcast #483: This AI helps thieves steal your iPhone Smashing Security podcast #483: This AI helps thieves steal your iPhone

This AI helps thieves steal your iPhone with Graham Cluley and special guest James Ball.

You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first one.

Is it normal that some kid just flogs it down the pub, or is there something more organised actually going on?

So the researchers said they saw evidence of hundreds of these Apple phone calls trying to phish the numbers and the passcodes from people trying to steal iPhones.

Follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts.

3 weeks, 6 days назад @ grahamcluley.com
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
Revolut scam wave steals £180,000 from Jersey residents in just four weeks Revolut scam wave steals £180,000 from Jersey residents in just four weeks

If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.

Police say they have also handled several cases where Revolut accounts were compromised that did not involve any phone calls.

It is possible that Jersey's residents have been targeted by the fraudsters because it is one of the world's best-known offshore financial centres.

Of course, if this is happening in the small island of Jersey in the English channel, it's likely to be happening elsewhere too.

For now, however, its sister island of Guernsey appears to have escaped the surge in Revolut scams.

4 weeks назад @ bitdefender.com
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

TeamPCP is best known for Shai-Hulud, a self-propagating worm that spread itself through open source software.

According to the authorities, the two men were principal members of a "sophisticated cybercrime syndicate" that created malicious open source software designed to steal data and extort ransoms from businesses.

First emerging in late 2025, TeamPCP built a reputation for poisoning popular open source packages rather than directly attacking businesses.

The group's Shai-Hulud worm hijacks GitHub and NPM developer credentials, and publishes boobytrapped versions of legitimate software packages.

Supply chain attacks like Shai-Hulud exploit the fact that most developers trust open source …

1 month назад @ bitdefender.com
US Navy tells sailors and their families: scrub your social media, enemies are watching
US Navy tells sailors and their families: scrub your social media, enemies are watching US Navy tells sailors and their families: scrub your social media, enemies are watching

The advice comes in the form of a newly-published bulletin called "Epic Vigilance: Immediate Actions for Force Protection and Personal Security."

US Navy workers and their families are being told that they should ensure that their social media profile privacy settings are enabled, and to remove anything that connects them to the Navy, or reveals "patterns of life" that an attacker could exploit.

any fake social media accounts impersonating fellow shipmates.

This wouldn't, of course, be the first time that military staff have accidentally leaked information about themselves online.

Some commentators have wondered out loud whether the timing of an announcement telling sailors to be much more …

1 month назад @ bitdefender.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 4 часа назад
Как закрыть 110 уязвимостей в Google Pixel | Блог Касперского
Как закрыть 110 уязвимостей в Google Pixel | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8ea67ee2a3dd4315782e49963c8d5485Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-30T17:00:35+03:00Config id: 334Faithfully yours, nginx.

4 часа назад @ kaspersky.ru
Как сканер уязвимостей создает иллюзию защиты | Блог Касперского
Как сканер уязвимостей создает иллюзию защиты | Блог Касперского Как сканер уязвимостей создает иллюзию защиты | Блог Касперского

Эти процессы могут тянуться неделями, а тем временем в инфраструктуру легко может попасть злоумышленник.

Где теряется времяПервое промедление может произойти сразу после появления информации об уязвимости в базах данных.

Рецепт управления уязвимостямиЧтобы у злоумышленников было как можно меньше поводов заглянуть к вам в инфраструктуру, важно убедиться, что в организации четко выстроены четыре основных процесса.

ПриоритизацияПри анализе уязвимости не стоит ориентироваться только на оценку из публичного каталога, например NVD, — она может существенно расходиться с реальным ущербом от эксплуатации бреши.

Например, один и тот же дефект в сервере, который находится в изолированном сегменте, и в…

22 часа назад @ kaspersky.ru
Бесплатный курс «Введение в кибербезопасность» для студентов вузов от экспертов «Лаборатории Касперского» | Блог Касперского
Бесплатный курс «Введение в кибербезопасность» для студентов вузов от экспертов «Лаборатории Касперского» | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7dfac78cb3fca5a112c9b371cb1af0ecServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-29T14:00:43+03:00Config id: 307Faithfully yours, nginx.

2 days, 6 hours назад @ kaspersky.ru
CVE-2026-87902: критическая уязвимость в WordPress
CVE-2026-87902: критическая уязвимость в WordPress

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 3ba3f53e4698eed730b59fdbb57f2dc7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-25T19:00:33+03:00Config id: 307Faithfully yours, nginx.

5 days, 1 hour назад @ kaspersky.ru
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: cdfce2802c5089c2e8d266eed059c5ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-23T18:00:08+03:00Config id: 307Faithfully yours, nginx.

1 week назад @ kaspersky.ru
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8bdccf89e0ff9374b4a240e13e1d1e5dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-22T14:00:25+03:00Config id: 307Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: afb32d9b2ad2a9d051087c355f39881eServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-18T19:00:38+03:00Config id: 305Faithfully yours, nginx.

1 week, 5 days назад @ kaspersky.ru
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: c7185cbdbdeda88817088ebb8613e249Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-17T16:00:24+03:00Config id: 305Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64b9740d8f9a94da6c64f21f2aeee15dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-16T19:00:10+03:00Config id: 305Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7e59b8e02f76cd9405fa38b4fdc32a36Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-15T11:00:04+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 2 days назад @ kaspersky.ru
Как полностью удалить приложения с Mac и освободить память | Блог Касперского
Как полностью удалить приложения с Mac и освободить память | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a6459fd9158393152b55dc4e20e24551Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T15:00:13+03:00Config id: 305Faithfully yours, nginx.

3 weeks назад @ kaspersky.ru
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4a93349074c8b67d52892db5d9a65f6cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T00:00:19+03:00Config id: 305Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
GPUThor: развитие идеи Rowhammer | Блог Касперского
GPUThor: развитие идеи Rowhammer | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fe21d0ffcbad967d20a3f98f7234d02fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-08T00:00:32+03:00Config id: 304Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e393e4abb05ec4aac16fd484bfccc656Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-04T18:00:18+03:00Config id: 304Faithfully yours, nginx.

3 weeks, 5 days назад @ kaspersky.ru
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7177a8342cf961cc27c82af1167cdb34Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-02T15:00:28+03:00Config id: 302Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 2 days, 2 hours назад
Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era
Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era

The Cisco Secure Firewall 200 Series brings enterprise-grade protection and connectivity to distributed branches in a compact form factor.

The Encrypted Visibility Engine (EVE) uses AI and machine learning to analyze encrypted traffic, including TLS 1.3, without requiring full decryption.

The Secure Firewall 220 model delivers up to 1.5 Gbps of throughput with next-generation firewall capabilities enabled in a compact form factor for smaller branches.

The Secure Firewall 200 Series helps meet these demands with intelligent threat protection, encrypted traffic visibility, resilient connectivity, and centralized management.

Explore the Secure Firewall 200 Series to build a more resilient, man…

2 days, 2 hours назад @ blogs.cisco.com
From Love Letters to AI Agents: Cybersecurity’s Evolution
From Love Letters to AI Agents: Cybersecurity’s Evolution From Love Letters to AI Agents: Cybersecurity’s Evolution

Architecting the Future: The Four Pillars of Agentic SecuritySecuring agentic AI requires a new strategic framework.

Pillar 2: Core ProtectionDelivered by: Cisco AI DefenseCisco AI Defense provides specialized protection for the AI models themselves and their operational environment.

AI Inventory & Validation: This solution catalogs all deployed AI models and continuously validates their integrity against supply chain risks.

Pillar 4: ObservabilityDelivered by: SplunkSplunk provides the unified intelligence platform required to monitor and respond to agentic AI at scale.

Splunk ingests logs, events, and telemetry from Duo, Secure Access, AI Defense, and other infrastructure points, creating…

1 week, 2 days назад @ blogs.cisco.com
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco was proud to return to Black Hat USA as the Official Security Cloud Provider and the longest-standing partner of the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC).

In 2026, we completed our 11th year helping protect the Black Hat network, working side by side with the Black Hat NOC leaders and official technology partners: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.

For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry and workflows across Cisco Security, Splunk Security, and partner-provided network and security controls.

The same signal may need to be understood by Cisco, Splunk, Black Hat leadership, and partner tea…

3 weeks, 2 days назад @ blogs.cisco.com
Thrown into the SOC: A Black Hat First-Timer’s Story
Thrown into the SOC: A Black Hat First-Timer’s Story Thrown into the SOC: A Black Hat First-Timer’s Story

I did not walk into Black Hat with years of incident-response experience or an encyclopedic knowledge of threat actors.

The first time I walked into the Black Hat NOC, where the SOC team was operating, was a few days before the event began.

I was surrounded by people with years—sometimes decades—of experience, many of whom had supported Black Hat for years.

Check out the other blogs from our team at Black Hat USA 2026.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

3 weeks, 2 days назад @ blogs.cisco.com
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes

To handle this task, Cisco and Black Hat deployed bespoke ThousandEyes agents to monitor the wireless solution.

Our thanks to the Arista Networks team in the Black Hat NOC for their partnership throughout the week.

You can read the other blogs from our colleagues at Black Hat USA.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

For more information, please visit the Black Hat website.

3 weeks, 2 days назад @ blogs.cisco.com
Distributed Latency Monitoring at Black Hat
Distributed Latency Monitoring at Black Hat Distributed Latency Monitoring at Black Hat

With Matthew Bair2026 marks the fourth consecutive year we’ve used ThousandEyes to monitor the Black Hat USA network for latency.

As our latency monitoring mesh has expanded to cover more and more of the conference, we’ve also begun supplementing our ThousandEyes monitoring with on-demand Linux commands to track latency across different protocols.

The Key ThousandEyes TestsThe automated ThousandEyes tests that inform our dashboards include HTTPS connectivity tests, the monitoring of cloud services, agent to agent tests, internal and external DNS resolution, and even file downloads.

On-Demand Latency Tests from the Agent MeshPing and traceroute are the go-tos for anyone who wants to do a qui…

3 weeks, 2 days назад @ blogs.cisco.com
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

While developing a detection for Cisco Secure Network Analytics (SNA), I used the Splunk Detection Editor (Alpha) to bring much of that workflow into one place.

Instead of treating every observation as an incident, detections can create risk events associated with entities such as systems or users.

Developing the detection in one workspaceThe Detection Editor provides a workspace for building the search while configuring the other parts of the detection.

Risk events for the same entity need to use a consistent risk object so Splunk Enterprise Security can associate them correctly.

Splunk defines the risk object, its type, and its score as key parts of a risk event.

3 weeks, 2 days назад @ blogs.cisco.com
Black Hat USA 2026: Safeguarding DNS with Secure Access
Black Hat USA 2026: Safeguarding DNS with Secure Access Black Hat USA 2026: Safeguarding DNS with Secure Access

DNS continues to provide one of the clearest windows into activity across the Black Hat network.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking.

Its 4.42 million blocks represented 79.3% of every blocked DNS request .. Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and mo…

3 weeks, 2 days назад @ blogs.cisco.com
Frontier AI just raised the stakes, and the old playbook won’t hold up
Frontier AI just raised the stakes, and the old playbook won’t hold up Frontier AI just raised the stakes, and the old playbook won’t hold up

Project Glasswing and Frontier models just made that truth louder.

Frontier models are about to pour gasoline on that fire; the fundamentals matter more than ever.

Cisco ran its own experiment leveraging a variety of frontier models.

Foundry Security Spec: a model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

Foundry-Security-Speca model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

3 weeks, 5 days назад @ blogs.cisco.com
Crypto Agility: Why PQC Is Not a One-Time Upgrade
Crypto Agility: Why PQC Is Not a One-Time Upgrade Crypto Agility: Why PQC Is Not a One-Time Upgrade

That requires crypto agility.

Why long-lived networks need crypto agilityThink about designing a building before all of its future electrical requirements are known.

Crypto agility is about adopting the best defenses available today while preserving the ability to adopt better ones tomorrow.

That is why crypto agility needs to be designed into the network we invest in today.

Common questions about PQC and crypto agilityWhat is crypto agility?

3 weeks, 6 days назад @ blogs.cisco.com
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

It is what happens when agents built by different teams, on different platforms, can hand work to each other directly.

And it is worth being direct about where things stand: A2A-mediated handoffs between production security agents are not shipping anywhere yet.

Use A2A when one agent needs to hand work to another.

A2A is peer-to-peer: any A2A agent can discover and call any other A2A agent through a self-published Agent Card, no custom connector required, and the receiving agent applies its own reasoning rather than following a static script.

Input validation is an application-layer responsibility that needs to be designed in before any agent delegates via A2A, not added after.

1 month назад @ blogs.cisco.com
Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
Microsegmentation’s Moment Is Now:  Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind SpotsApplications increasingly span private clouds, on-premises data centers, and public clouds.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026…

1 month назад @ blogs.cisco.com
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

What We Mean by Infrastructure IdentityInfrastructure Identity starts with a simple principle: there should be no anonymous computing in critical infrastructure.

Infrastructure Identity turns that principle into an operating model.

Infrastructure Identity starts with the actor and evaluates whether a specific action should be allowed now.

Infrastructure Identity is therefore not just an access-control issue.

That is the promise of Infrastructure Identity: no anonymous computing, no unmanaged privilege, and no forced tradeoff between stronger security and operational speed.

1 month назад @ blogs.cisco.com
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE

I’m proud to share that IDC MarketScape has named Cisco a Leader in the 2026 IDC MarketScape: Worldwide Secure Access Service Edge (SASE) Vendor Assessment.

In an evaluation of 12 SASE vendors, the IDC MarketScape recognized our architectural breadth and flexibility, AI capabilities, identity integration, threat visibility, and R&D.

Built to Make Agent Work, WorkWe believe the IDC MarketScape recognition validates the foundation we have built, and customers increasingly need that foundation for what is next.

For more on Cisco’s placement as a Leader, read the IDC MarketScape excerpt and explore how Cisco SASE keeps work moving, governed, and trusted in the AI era at cisco.com/go/sase.

Stay …

1 month, 1 week назад @ blogs.cisco.com
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

1 month, 2 weeks назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 3 часа назад
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

The operators first validated command execution using lightweight out-of-band probes to unique subdomains hosted on public interaction and collaborator services, including oast[.

When a service-state change triggers health monitoring, swatchdog incorporates the attacker-controlled value into a snmptrap shell invocation, enabling command execution.

Exploitation of the Zimbra vulnerability provided attackers with direct command execution as the zimbra service account.

Attackers also used the initial command execution to download and execute content directly through wget or curl, launch background processes, and establish interactive reverse shells.

Command and controlThe actor used HTTP and H…

3 часа назад @ microsoft.com
Phishing Abuses RMM Tools for Persistent Access
Phishing Abuses RMM Tools for Persistent Access Phishing Abuses RMM Tools for Persistent Access

Attack chain showing phishing delivering a masqueraded MSP360 RMM installer that deploys ScreenConnect for persistent remote access and follow-on activity.

Initial Access: Phishing Campaign Delivering Masqueraded MSP360 RMM InstallerMicrosoft observed multiple phishing campaigns that used a multi-stage delivery chain to distribute legitimate, digitally signed MSP360 RMM software (v2.5.0.67).

Analysis of downloaded samples showed that many ultimately contained the same MSP360 RMM installer package despite appearing as different files to the victim.

Command and ControlT1219 Remote Access Software | The threat actor abused legitimate remote administration software including MSP360 RMM and Conn…

19 часов назад @ microsoft.com
​​Beyond source code: A path to the keys to the kingdom
​​Beyond source code: A path to the keys to the kingdom ​​Beyond source code: A path to the keys to the kingdom

By mapping trusted deployment paths and connected resources, the threat actor was able to identify opportunities to expand beyond the initial compromise.

In addition to deploying a kube agent, the threat actor modified pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility.

The threat actor added seven stolen kubeconfig files to a repository, providing the credentials needed to access targeted Kubernetes clusters.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

1 day, 1 hour назад @ microsoft.com
Star Blizzard refines phishing and malware delivery with the RedFlick technique
Star Blizzard refines phishing and malware delivery with the RedFlick technique Star Blizzard refines phishing and malware delivery with the RedFlick technique

In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns.

June 2026 RedFlick campaign follow-up email with the subject line “Invitation to the Chatham House London Conference 2026”Figure 3.

Persistence through multiple scheduled tasksIn April 2026, Microsoft observed Star Blizzard changing persistence tactics to include RedFlick scheduled tasks.

Defending against Star Blizzard and RedFlick-related activityMicrosoft Threat Intelligence advises organizations that are most likely at risk—primarily those in government, NGOs, or think tanks adjacent to Ukraine policy or support—to implement the followin…

1 day, 2 hours назад @ microsoft.com
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.

Microsoft has observed additional NeedyMantis activity beyond Storm-3069’s activity in the DAEMON Tools campaign, indicating that the malware might be used by more than one operator.

Indicators of compromiseIndicator Type Description First seen Last seen e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e SHA-256 First-stage loader WinSparkle.dll 2026-05-21 2026-05-21 9cb68f986043a576e19d32184…

2 days, 2 hours назад @ microsoft.com
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Storm-3168: Agentic-driven cloud attacks using compromised service principals Storm-3168: Agentic-driven cloud attacks using compromised service principals

About 90 minutes after the first compromised service principal started enumeration, the second compromised service principal enumerated virtual machines and resource groups across two subscriptions in five seconds.

16 hours later, the second service principal successfully enumerated Azure App Service configuration stores, possibly looking for exposed credentials.

This compromised service principal then attempted 150+ destructive or credential collection related operations in 35 minutes.

T1078.004 Valid Accounts: Cloud Accounts | Compromised service principals were used for Azure resource discovery and destruction.

To hear stories and insights from the Microsoft Threat Intelligence community…

5 days, 1 hour назад @ microsoft.com
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.

As a result, organizations could encounter the same actor, tools, and intrusion methods despite different ransomware payloads being deployed.

Storm-2570 uses a diverse set of remote access tools rather than relying on a single capability.

This type of tunnel can help bypass inbound firewall restrictions and provide covert remote access for follow-on activity.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat …

6 days, 1 hour назад @ microsoft.com
​​​​​​​​What’s new in Microsoft Security: September 2026​​
​​​​​​​​What’s new in Microsoft Security: September 2026​​ ​​​​​​​​What’s new in Microsoft Security: September 2026​​

Here’s what’s new:Extend protection and support investigations with Microsoft DefenderBring more context into email investigation and hunting with Microsoft Security CopilotAvailable for organizations using both Microsoft Defender and Microsoft Security Copilot, a new email detonation summary delivers AI-generated explanations of URL and file sandboxing results, helping SOC teams investigate faster by reducing the manual effort required to correlate detonation evidence and contextual signals.

Protect sensitive data in motion with Microsoft Purview and Microsoft EntraStop sensitive data from reaching shadow AI over the networkNow generally available, Microsoft Purview and Microsoft Entra Glo…

6 days, 1 hour назад @ microsoft.com
Reimagining the SOC for the agentic era in Microsoft Defender
Reimagining the SOC for the agentic era in Microsoft Defender Reimagining the SOC for the agentic era in Microsoft Defender

So must the security operations center (SOC).

For agentic security to work, the industry needs a different model.

Today we are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for security information and event management (SIEM) and threat protection together.

The result is an integrated protection loop that continuously turns what defenders learn into stronger pre-breach protection.

Integrated security operations center (ISOC) in Microsoft Defender is available in preview today.

1 week назад @ microsoft.com
Unmasking EvilTokens: Getting to the root of device code phishing
Unmasking EvilTokens: Getting to the root of device code phishing Unmasking EvilTokens: Getting to the root of device code phishing

What is device code phishing?

Device code phishing occurs when threat actors insert themselves into this process.

Tactic Observed activity Microsoft Defender coverage Initial access Device code authentication Microsoft Defender for Identity– Anomalous OAuth device code authentication activity Credential access Token theft following device code authentication Microsoft Defender for Identity– Anomalous token exchange following device code authenticationMicrosoft Defender XDR– User account compromise via OAuth device code phishing– Suspicious Azure authentication through possible device code phishing Persistence Device registration following anomalous device code authentication Microsoft Defen…

1 week, 1 day назад @ microsoft.com
Unmasking EvilTokens: Getting to the root of device code phishing
Unmasking EvilTokens: Getting to the root of device code phishing Unmasking EvilTokens: Getting to the root of device code phishing

What is device code phishing?

Device code phishing occurs when threat actors insert themselves into this process.

Tactic Observed activity Microsoft Defender coverage Initial access Device code authentication Microsoft Defender for Identity– Anomalous OAuth device code authentication activity Credential access Token theft following device code authentication Microsoft Defender for Identity– Anomalous token exchange following device code authenticationMicrosoft Defender XDR– User account compromise via OAuth device code phishing– Suspicious Azure authentication through possible device code phishing Persistence Device registration following anomalous device code authentication Microsoft Defen…

1 week, 1 day назад @ microsoft.com
From guidance to action: Security fundamentals that materially reduce risk
From guidance to action: Security fundamentals that materially reduce risk From guidance to action: Security fundamentals that materially reduce risk

We introduced Secure Now within Microsoft Security Exposure Management in May 2026 to help practitioners prioritize the action they need to take to be prepared for this shift.

Security fundamentals work togetherCyberattackers are moving laterally across surfaces, and security fundamentals matter most at the intersections between them.

On Secure Now—within Microsoft Security Exposure Management—security leaders can now find information on recent threats paired with focused initiatives across security domains.

Learn moreLearn more about Microsoft Security Exposure Management.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurit…

1 week, 6 days назад @ microsoft.com
From guidance to action: Security fundamentals that materially reduce risk
From guidance to action: Security fundamentals that materially reduce risk From guidance to action: Security fundamentals that materially reduce risk

We introduced Secure Now within Microsoft Security Exposure Management in May 2026 to help practitioners prioritize the action they need to take to be prepared for this shift.

Security fundamentals work togetherCyberattackers are moving laterally across surfaces, and security fundamentals matter most at the intersections between them.

On Secure Now—within Microsoft Security Exposure Management—security leaders can now find information on recent threats paired with focused initiatives across security domains.

Learn moreLearn more about Microsoft Security Exposure Management.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurit…

1 week, 6 days назад @ microsoft.com
Improving email security outcomes with real-world Microsoft Defender insights
Improving email security outcomes with real-world Microsoft Defender insights Improving email security outcomes with real-world Microsoft Defender insights

For five consecutive quarters Microsoft has published email security benchmarking reports to provide greater transparency into real-world protection outcomes.

Figure 1: High-severity email threats missed by SEG vendors (May 2026 through July 2026), measured as threats missed per 1,000 users protected.

Similarly to previous quarters, integrated cloud email security (ICES) solutions continue adding the most value in promotional and bulk filtering.

Figure 3: Post‑delivery malicious catch by Microsoft Defender (May 2026 through July 2026), shown across vendors and overall average.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecu…

1 week, 6 days назад @ microsoft.com
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Protecting organizations from AI-assisted executive impersonation and invoice fraud Protecting organizations from AI-assisted executive impersonation and invoice fraud

Figure 1: Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft.

Important note: Throughout this campaign, threat actors impersonated legitimate organizations using attacker-controlled infrastructure, fabricated communications, and lookalike domains.

To defend against social engineering campaigns involving executive impersonation, invoice fraud, and potentially AI-assisted content development, Microsoft recommends the following mitigations:Configure automatic attack disruption in Microsoft Defender XDR.

Tactic Observed activity Microsoft Defender coverage Financial Theft Scam emails Microsoft Defender for Office…

2 weeks, 6 days назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 5 months, 1 week назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

5 months, 1 week назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

5 months, 3 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

5 months, 3 weeks назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

6 months назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

6 months назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

6 months, 1 week назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

7 months назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

7 months, 1 week назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

7 months, 1 week назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

8 months назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

9 months, 3 weeks назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

9 months, 3 weeks назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

9 months, 3 weeks назад @ security.googleblog.com