Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 3 часа назад
Хакеры добрались до системы движения супертанкера, полного нефти и идущего к США
Хакеры добрались до системы движения супертанкера, полного нефти и идущего к США

Судно шло к США, когда злоумышленники проникли в один из самых критичных контуров.

3 часа назад @ securitylab.ru
Органы из принтера: биоинженеры замахнулись на полноценную человеческую печень
Органы из принтера: биоинженеры замахнулись на полноценную человеческую печень

Учёные хотят навсегда избавить пациентов от ожидания донора.

3 часа назад @ securitylab.ru
«Киберпартизаны» два года жили в российской медицинской сети и готовили плацдарм для новых атак
«Киберпартизаны» два года жили в российской медицинской сети и готовили плацдарм для новых атак

Доступ к дочерним структурам оказался слишком ценным для быстрой диверсии.

4 часа назад @ securitylab.ru
Глаза для ракет. Boeing утроит выпуск головок самонаведения для перехватчиков Patriot
Глаза для ракет. Boeing утроит выпуск головок самонаведения для перехватчиков Patriot

У PAC-3 MSE нашли узкое место и решили его снести.

4 часа назад @ securitylab.ru
ClingSTUN спрятал Linux-бэкдор среди обычного трафика VoIP и WebRTC
ClingSTUN спрятал Linux-бэкдор среди обычного трафика VoIP и WebRTC

Публичные серверы связи превратились в идеальное прикрытие для удалённого доступа.

5 часов назад @ securitylab.ru
JPEG мог не появиться. Метод, на котором держится формат, в 1972 году оставили без гранта
JPEG мог не появиться. Метод, на котором держится формат, в 1972 году оставили без гранта

Почему идею, без которой не было бы цифровых фото, оставили без денег.

5 часов назад @ securitylab.ru
Третий NetScaler zero-day за неделю бьёт даже полностью обновлённые системы
Третий NetScaler zero-day за неделю бьёт даже полностью обновлённые системы

Citrix просит снова обновить устройства, которые администраторы уже считали защищёнными.

6 часов назад @ securitylab.ru
Солнце может расшатать Солнечную систему почти до полного распада
Солнце может расшатать Солнечную систему почти до полного распада

Новая модель сокращает ожидаемый срок устойчивости планет-гигантов с десятков миллиардов лет примерно до одного.

6 часов назад @ securitylab.ru
Нобелевская премия — за ледяной телескоп. IceCube превратил километр Антарктиды в ловушку для космических частиц
Нобелевская премия — за ледяной телескоп. IceCube превратил километр Антарктиды в ловушку для космических частиц

5160 датчиков ловят редчайшие частицы, которые проходят сквозь планеты почти без следа.

7 часов назад @ securitylab.ru
Год прожит — год возвращён. Футуролог верит, что к 2032-му ИИ научит медицину отматывать время
Год прожит — год возвращён. Футуролог верит, что к 2032-му ИИ научит медицину отматывать время

Бактерии останутся. Инфекции останутся. А старость начнёт отступать...

7 часов назад @ securitylab.ru
AdBlock теперь будет работать прямо в роутере
AdBlock теперь будет работать прямо в роутере

Проект получил удобную настройку, обновления по Wi-Fi и защиту опасных функций управления.

8 часов назад @ securitylab.ru
Помните, как Терминатор прятал железо под живой кожей? Учёные делают наоборот — и на клеточном уровне
Помните, как Терминатор прятал железо под живой кожей? Учёные делают наоборот — и на клеточном уровне

Учёные проектируют наполовину живых микророботов.

9 часов назад @ securitylab.ru
Свободных стоек почти нет. Цены в российских ЦОДах снова пошли вверх
Свободных стоек почти нет. Цены в российских ЦОДах снова пошли вверх

Дефицит мощностей оказался сильнее дорогих кредитов и затормозившего строительства.

9 часов назад @ securitylab.ru
Покажите Echo свой текст, и нейросеть попробует стать вами
Покажите Echo свой текст, и нейросеть попробует стать вами

Эксперимент показал, насколько близко машина уже подобралась к индивидуальному почерку.

10 часов назад @ securitylab.ru
7,9 млн клиентов и $400 тысяч выкупа. DataSuckers атаковала украинского ритейлера АТБ-Маркет
7,9 млн клиентов и $400 тысяч выкупа. DataSuckers атаковала украинского ритейлера АТБ-Маркет

Ритейлер подтверждает кибератаку, но категорически отрицает масштабную утечку.

10 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 4 часа назад
Автономный SOC в 2026 году: где заканчивается автоматизация и начинается реальная автономность
Автономный SOC в 2026 году: где заканчивается автоматизация и начинается реальная автономность Автономный SOC в 2026 году: где заканчивается автоматизация и начинается реальная автономность

Эксперты ведущих российских вендоров и провайдеров услуг обсудили, где заканчивается автоматизация SOC и начинается реальная автономность.

Дальше можно идти туда, где риск минимален: если автоматизации можно доверить остановку служб и изменение конфигурационных файлов и это не остановит бизнес, то почему бы нет?

Михаил Карпенко считает, что в автоматизацию следует выводить те процессы, в которых уже есть уверенность, что их можно передать.

То, что вы составили первым и что кажется вам максимально понятным и управляемым, и нужно автоматизировать в первую очередь».

Автономность сегодня доходит до этапа вынесения первичного вердикта и, в ограниченном наборе типовых случаев, до локализации и пе…

4 часа назад @ anti-malware.ru
Обзор AlphaSense Symbiote Space, ПО для поиска и эксплуатации уязвимостей
Обзор AlphaSense Symbiote Space, ПО для поиска и эксплуатации уязвимостей Обзор AlphaSense Symbiote Space, ПО для поиска и эксплуатации уязвимостей

Объединяет обнаружение и инвентаризацию ИТ-активов, поиск уязвимостей и ошибок конфигурации, активную проверку эксплуатации уязвимостей, приоритизацию и контроль устранения.

Информационная панель EASM в AlphaSense Symbiote SpaceС помощью фильтров задаются значения критериев отбора хостов и уязвимостей, отображаемых в блоке.

Реализуется полная поддержка системы CVSS версий 2, 3 и 4 для оценки критической значимости уязвимостей и их последующей приоритизации.

Платформа обнаруживает доступные извне активы и сервисы, связывает их с внутренней инвентаризацией и показывает открытые порты, версии ПО, уязвимости и реальную возможность эксплуатации.

ВыводыAlphaSense Symbiote Space объединяет обнаруж…

11 часов назад @ anti-malware.ru
ИИ-программисты сливают корпоративные ключи: новая угроза от нейросетевого кодинга
ИИ-программисты сливают корпоративные ключи: новая угроза от нейросетевого кодинга ИИ-программисты сливают корпоративные ключи: новая угроза от нейросетевого кодинга

Таким образом, доля изменений кода с обнаруженными секретами при использовании ИИ-инструментов оказалась более чем в два раза выше среднего показателя.

Hardcoded secrets — пароли и ключи, записанные непосредственно в тексте программы или её настройках, то есть доступ к ресурсу оказывается неотделим от самого кода.

Сами по себе такие секреты не всегда появляются в коде по вине ИИ: разработчики оставляли ключи и пароли в репозиториях и раньше.

Срок действия доступа ограничен, и по его истечении доступ автоматически прекращается.

Ключ необходимо отозвать и заменить, проверить журналы его использования и при необходимости очистить историю репозитория.

1 day, 6 hours назад @ anti-malware.ru
Будущее строгой аутентификации: виртуальные смарт-карты и BYOD
Будущее строгой аутентификации: виртуальные смарт-карты и BYOD Будущее строгой аутентификации: виртуальные смарт-карты и BYOD

ВведениеФизическая смарт-карта или USB-токен защищает закрытый ключ и позволяют использовать его для аутентификации и других криптографических операций.

С 1 октября 2025 года действует ГОСТ Р 70262.2-2025, который устанавливает уровни доверия аутентификации и определяет требования к видам и средствам аутентификации для каждого из них.

При этом важно, чтобы закрытый ключ не передавался за пределы защищённого хранилища и не мог быть штатно экспортирован.

Ограничения: KeyBox не заменяет механизм строгой аутентификации, инфраструктуру открытых ключей (PKI) или систему контроля состояния устройства, а управляет средствами аутентификации и их жизненным циклом.

Когда выбирать: если нужно централиз…

1 day, 10 hours назад @ anti-malware.ru
Цифровой сотрудник — дешёвая замена человеку или новая статья расходов?
Цифровой сотрудник — дешёвая замена человеку или новая статья расходов? Цифровой сотрудник — дешёвая замена человеку или новая статья расходов?

Среднее базовое ДМС обходится в 2 000 рублей в месяц.

Среднемесячную заработную плату округлим до 56 000 рублей на руки.

Аренда мощностей может обходиться в 5 000 — 20 000 рублей (и выше) в месяц.

Другие расходы:LLM-токены: 0,5 — 2 рублей за ответ, при 900 диалогах — от 2 000 до 6 000 рублей в месяц.

Сообщения бесплатны, платный контур — хостинг прослойки, 1 000 — 3 000 рублей в месяц.

4 days, 5 hours назад @ anti-malware.ru
Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры
Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры Облако или свой контур: как крупному бизнесу выбрать подходящую модель инфраструктуры

Отдельно обсудили, как выбирать облачного провайдера — на какие критерии смотреть и что влияет на надёжность его сервисов.

Заказчик не видит эти процессы изнутри и не может управлять ими так же, как собственной инфраструктурой.

Но, как советует Станислав Попов, внедрять ИИ сейчас стоит осознанно и с пониманием ожидаемого бизнес-эффекта.

Тестирование аварийного восстановления (disaster recovery, DR) позволяет эмулировать сбои, проверить работу собственной инфраструктуры и цепочки поставщиков.

Вместо самостоятельного создания инфраструктуры и найма специалистов они могут использовать облачную инфраструктуру, соответствие которой необходимым требованиям уже подтверждено.

5 days, 10 hours назад @ anti-malware.ru
Low-code и No-code в 2026 году: как создавать приложения без разработчиков
Low-code и No-code в 2026 году: как создавать приложения без разработчиков Low-code и No-code в 2026 году: как создавать приложения без разработчиков

Платформы Low-code и No-code позволяют создавать бизнес-приложения, автоматизировать процессы и интегрировать системы силами специалистов без профильного образования в области программирования.

Что такое Low-code и No-codeАнтон Симуни объяснил разницу между No-code и Low-code.

No-code — это для непрофессиональных программистов, может быть, даже вообще для тех, кто создаёт приложения без профильного ИТ-образования (т. н.

В первом опросе зрители рассказали, используют ли они платформы No-code / Low-code в своей компании:«Пилотируют» / только начинают внедрение — 28 %.

ВыводыРынок Low-code и No-code в 2026 году перестал быть нишевым явлением.

6 days, 6 hours назад @ anti-malware.ru
Миграция с Cisco: от пилота до замены инфраструктуры
Миграция с Cisco: от пилота до замены инфраструктуры Миграция с Cisco: от пилота до замены инфраструктуры

Вместе с Ideco мы обсудили, как подготовиться к переходу на российские решения, почему полностью бесшовной замены сегодня не бывает.

Причины отказа от CiscoПосле ухода Cisco из России вопрос перехода на другие решения для клиентов до сих пор никуда не исчез.

Совместимость IPsec Site-to-Site с Cisco подтверждена, поэтому площадки можно переносить поэтапно без потери связи между ними.

Илья Соболев, менеджер по продукту IdecoЗависимость от вендора и бесшовность миграцииПри переходе с Cisco на российское решение вопрос зависимости от вендора сохраняется.

Например, добавление поддержки EIGRP, протокола маршрутизации, было связано с тем, что многие компании строили инфраструктуру на Cisco.

6 days, 11 hours назад @ anti-malware.ru
Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке
Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке Offensive Security в 2026 году: от разовых пентестов к непрерывной проверке

ИИ-агенты и их влияние на рынокАндрей Галактионов считает, что истории о сбежавших из песочниц ИИ-агентах — это в первую очередь хайп.

«Красная» команда в 95 % случаев достигает целей, но если нет зрелости, результат будет тот же, что и от пентеста, только дороже.

Если по результатам пентеста нужно проверить инфраструктуру, а по результатам Red Teaming — перенастроить процессы, то внутренняя команда может быть эффективнее для изменения процессов.

ВыводыРынок Offensive Security в 2026 году проходит через фундаментальную трансформацию.

А те, кто считает, что с ними ничего не случится, рискуют убедиться в обратном в самый неподходящий момент.

1 week назад @ anti-malware.ru
Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA
Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA Сложные PKI-системы больше не нужны: полноценное управление сертификатами напрямую из SafeTech CA

SafeTech Lab встроила в SafeTech CA модуль CDM для доставки, установки и автоматического обновления технологических сертификатов.

Теперь заказчику больше не нужно искать отдельное решение, интегрировать его с CA и настраивать сложные схемы взаимодействия систем.

Новые расширенные возможности выводят SafeTech CA за рамки обычного центра сертификации — теперь это полноценная платформа управления цифровыми сертификатами.

SafeTech CA закрывает все самые востребованные задачи по контролю за сертификатами: от их выпуска до автоматического обновления на клиентских устройствах.

Модуль CDM расширяет возможности SafeTech CA за счёт агентской доставки, установки и автоматического перевыпуска сертифика…

1 week назад @ anti-malware.ru
ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок
ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок ИИ-агенты под контролем: строим архитектуру безопасности от промптов до цепочки поставок

Согласно отраслевым прогнозам, доля корпоративного ПО с агентным ИИ может возрасти с менее чем 1 % в 2024 году до 33 % к 2028 году.

Наблюдения специалистов по безопасности ИИ и открытые исследования подтверждают: злоумышленники уже сейчас тестируют методы обхода ограничений в промышленных системах.

Недостаточно добавить фильтры поверх уже созданной системы: принципы безопасности для агентов необходимо закладывать на этапе проектирования.

Инструментарий: что включить в конвейер обеспечения безопасности уже сейчасСредства защиты агентов перестают быть узкоспециализированными утилитами и интегрируются в классический конвейер (пайплайн) DevSecOps.

ВыводыОбеспечение безопасности автономных агент…

1 week назад @ anti-malware.ru
Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов
Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов Серверы на вечной мерзлоте: как газ и мороз меняют карту российских ЦОДов

В Якутии хотят строить ЦОДы там, где мороз помогает охлаждать серверы, а газ можно превращать в электричество прямо у месторождений.

То, что десятилетиями делало стройку и жизнь в Якутии дороже и сложнее, теперь пытаются превратить в конкурентное преимущество: местный мороз должен помогать охлаждать серверы.

Новый проект правительства республики, КРДВ и «Ростелекома» хотят начать с 2,5 МВт — уже в пять раз больше нынешней инфраструктуры.

А заявленные 100 МВт означали бы рост относительно сегодняшнего уровня примерно в 200 раз и в 40 раз относительно старта.

И тогда уже важно, какой газ он потребляет, мог ли этот ресурс уйти другому покупателю и что происходит с локальным энергетическим бала…

1 week, 1 day назад @ anti-malware.ru
Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты
Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты Обзор BI.ZONE Mail Security 3.1, системы многоуровневой защиты корпоративной почты

Решение BI.ZONE Mail Security создано на основе системы BI.ZONE CESP и предназначено для защиты корпоративной почты от вредоносных и нежелательных сообщений.

Эти данные могут дополняться актуальной информацией из внешних систем: BI.ZONE Threat Intelligence, BI.ZONE Sandbox и платформы BI.ZONE Security Fitness.

BI.ZONE Mail Security также интегрируется с платформой BI.ZONE Security Fitness, что позволяет учитывать результаты учебных фишинговых рассылок при настройке политик безопасности.

Подключение модуля BI.ZONE SandboxВ on-prem-варианте BI.ZONE Mail Security также можно интегрировать с BI.ZONE Threat Intelligence, при этом сам портал располагается в облачной инфраструктуре BI.ZONE.

Компон…

1 week, 1 day назад @ anti-malware.ru
Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности
Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности Яблока-то и я не приметил: macOS как слепая зона корпоративной безопасности

Использование macOS в dev-средах увеличивает риск горизонтального перемещенияКлассические техники горизонтального перемещения через Active Directory и SMB на macOS встречаются реже и хуже покрыты правилами детектирования.

Классическая подсистема аудита OpenBSM начиная с macOS 11 объявлена устаревшей, а в версиях начиная с macOS 14 она отключена по умолчанию.

Сейчас ситуация меняется: вендоры наращивают функциональность агентов под macOS и адаптируют их как к новым версиям ОС, так и к меняющемуся ландшафту угроз.

Политики безопасности исторически писались под Windows, и Mac-устройства во многих организациях так и не попали в контур мониторинга SOC.

Windows, Linux и macOS в ней сосуществуют, …

1 week, 4 days назад @ anti-malware.ru
Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки
Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки Чем заменить F5 и Citrix: выбор российских балансировщиков нагрузки

Эксперты ведущих вендоров собрались в студии AM Live, чтобы обсудить, чем отличаются классы решений, как их выбирать и на что смотреть при пилотировании.

Какими бывают балансировщики нагрузкиДаниил Виняр предложил разделить решения на три класса:Global Server Load Balancing (GSLB) — решения на базе DNS, которые распределяют нагрузку между разными ЦОДами, будь то собственные площадки или облака.

ВыводыРоссийский рынок балансировщиков нагрузки и брокеров сетевых пакетов находится в фазе активного роста и уже не нуждается в доказательствах своей зрелости.

При этом удобство — это не только красивый интерфейс, но и логичность, понятность того, что можно сделать с устройством, и возможность не со…

1 week, 5 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 3 часа назад
Как я делал мессенджер, который на проводе выглядит как обычный HTTPS: пять инженерных историй
Как я делал мессенджер, который на проводе выглядит как обычный HTTPS: пять инженерных историй Как я делал мессенджер, который на проводе выглядит как обычный HTTPS: пять инженерных историй

Ключей у него нет, и это свойство кода, а не декларация: в таблице сообщений лежит поле payload , и открыть его нечем.

DPI смотрит не в содержимое, а в форму.

Отсюда вывод, который дорого дался: маскировать надо весь транспорт, а не «сигналинг».

«Отклонить» на десктопе не слало звонящему ничего — сигнал уходил только после принятия, и у звонящего вызов висел до таймаута.

Key transparency — в планах, не в коде.

3 часа назад @ habr.com
Скам-бот в Telegram выдал себя таймером: разбор юзербота с реконструкцией на Telethon
Скам-бот в Telegram выдал себя таймером: разбор юзербота с реконструкцией на Telethon Скам-бот в Telegram выдал себя таймером: разбор юзербота с реконструкцией на Telethon

Всё расследование уместилось в одну ночь и в один личный чат.

Похоже, бэкенд ставит ответ в очередь в момент получения сообщения и не проверяет, существует ли оно ещё через 5 минут.

Фраза «А что не актуально?» в эту версию тоже ложится, если воркер не понял, что в голосовом ничего нет.

Как это могло быть устроеноКода «Марии» я не видел, поэтому ниже реконструкция по поведению, а не их исходники.

Функции llm() и notify_operator() я не расписывал, потому что не знаю, какая там модель и как устроена связь с оператором.

3 часа назад @ habr.com
Разбор заданий ZeroNights HackQuest 2026
Разбор заданий ZeroNights HackQuest 2026 Разбор заданий ZeroNights HackQuest 2026

Разбираем .sr чтобы понять, что на каналах.sr — это ZIP с сессией sigrok.

Значит, надо смотреть не на хеш, а на то, какие данные сервер считает доверенными.

А мы можем отправить, не в свой ход -> завершить ход противника не в свой ход!

И клиент, и сервер заранее знают Tr(g), и считают публичный Tr(g^a)=(A1, A2) и Tr(g^b)=(B1, B2) соответсвенно.

market.yaxoo.rubikoid.meThis task was prepared by @dotrubicРайтап от loqpaЧто вообще есть в YaxooУ задания оказалось три сервиса:Market — магазин;Cloud — запуск Python-функций;IDP — аккаунты и JWT.

3 часа назад @ habr.com
Что останется непроверенным после вашего пентеста
Что останется непроверенным после вашего пентеста Что останется непроверенным после вашего пентеста

Black Box, Grey Box и White Box отвечают на разные вопросыЕще один параметр оценки — объем исходной информации, которую получает команда.

Black Box, Grey Box и White Box иногда воспринимают как три уровня «качества» проверки, но это некорректно.

Это различие влияет и на scope, и на исходные данные, и на способы доступа к тестируемым системам.

Но в коммерческом предложении важно заранее увидеть, входит ли он в стоимость, сколько циклов предусмотрено и в какой срок может быть проведен.

Срочность меняет организацию работ, но не отменяет последовательность анализаКалендарная длительность проекта состоит не только из технического тестирования.

5 часов назад @ habr.com
Новый ICS-вредонос S7Flip, или Что мы нашли на MalwareBazaar
Новый ICS-вредонос S7Flip, или Что мы нашли на MalwareBazaar Новый ICS-вредонос S7Flip, или Что мы нашли на MalwareBazaar

В тексте сообщения пользователь с ником jeans описывает вредоносную программу, обнаруженную на компьютере с Windows в промышленной среде (на предприятии с оборудованием Siemens).

По его словам, предположительно новый вредонос нацелен на промышленные системы управления (ICS).

Правда, есть один нюанс... ключ для расшифрования данных находится в файле master_key.dat , да и биткоин-кошелек такой же, как и в более ранней версии вайпера.

Возможно, в будущем он начнет активно применять его в «боевом» виде.

Достаточно ли этих данных, чтобы утверждать, что S7Flip и вайперы разработаны одним и тем же автором?

5 часов назад @ habr.com
Как убедить людей в том, чего нет, или кризис свободы слова
Как убедить людей в том, чего нет, или кризис свободы слова Как убедить людей в том, чего нет, или кризис свободы слова

Многие из вас уже слышали историю о том, как ИИ создал страницу в интернете, после чего в своих ответах начал ссылаться на нее, как на авторитетный источник.

Ловушка, в которую угодила в том числе и Википедия (или намеренно шла к ней), заключается в том самом слабом месте формулы из первого абзаца.

Когда немецкий Bild написал о том, что на рейсе FlyDubai пилотами были русский и украинец, издание даже не стало извиняться, а просто исправило статью о том, что кто-то так пошутил.

В том числе и в обществе.

Представьте себе, что в какой-то момент вы просто будете получать совершенно противоположные сведения об одном и том же объекте, событии, или явлении, причем в огромных количествах.

7 часов назад @ habr.com
PKI-шторм: что делать, если Kubernetes одновременно запрашивает 100 тысяч сертификатов
PKI-шторм: что делать, если Kubernetes одновременно запрашивает 100 тысяч сертификатов PKI-шторм: что делать, если Kubernetes одновременно запрашивает 100 тысяч сертификатов

Когда таких потребителей тысячи, PKI работает уже не с отдельными сертификатами, а с массовым потоком запросов.

Представьте, что после аварии начинает восстанавливаться целый ЦОД, а вместе с ним одновременно поднимаются десятки тысяч pod'ов Kubernetes.

Если раньше 100 тысяч запросов упирались в ЦС, а теперь они идут в хранилище, не превратится ли уже оно в новый bottleneck?

Сертификат начинает «стареть» с момента выпуска, а не с момента выдачи сервису.

Какие выводы мы сделалиГлавный урок этой истории оказался не про конкретный центр сертификации и даже не про Kubernetes.

8 часов назад @ habr.com
В фокусе RVD: трендовые уязвимости сентября
В фокусе RVD: трендовые уязвимости сентября В фокусе RVD: трендовые уязвимости сентября

Как указано в описании уязвимости от Microsoft, злоумышленник отправляет на сервер специально сформированный запрос и выполняет на нём произвольный код.

Эксплуатации подвержены Windows 10 и Windows 11, а также серверные версии от Windows Server 2012 до Windows Server 2025.

Уязвимость затрагивает Windows 10 и Windows Server версий 2012, 2012 R2, 2016, 2019 и 2022.

Windows 11 и Windows Server 2025 вне угрозы эксплуатации.

11 сентября CISA добавила уязвимость в каталог KEV со сроком устранения до 14 сентября.

8 часов назад @ habr.com
Публичный видеосервис на VPS: как не открыть дверь в домашнюю сеть
Публичный видеосервис на VPS: как не открыть дверь в домашнюю сеть Публичный видеосервис на VPS: как не открыть дверь в домашнюю сеть

Он сам устанавливает обратный SSH-туннель к VPS, а публичный Nginx передаёт запросы через этот туннель.

Эта статья — разбор того, как такое происходит и как публиковать домашний видеосервис, не превращая VPS в дверь в локальную сеть.

Самое главноеБезопасная схема держится не на одном пароле и не на одном firewall, а на нескольких независимых границах:Браузер не выбирает адрес внутреннего сервера.

Токен лучше передавать в заголовке или защищённой cookie, а не в query string: URL чаще попадают в историю браузера, журналы и аналитику.

Docker: Packet filtering and firewallsПосле запуска нужно проверять фактическое состояние, а не только конфигурационный файл:Get-NetTCPConnection -State Listen |…

9 часов назад @ habr.com
Дайте нормально поработать или я сделаю это сам
Дайте нормально поработать или я сделаю это сам Дайте нормально поработать или я сделаю это сам

Причем насколько мне удалось понять, доступ организован по принципу черных списков — есть доступ ко всему, что не запрещено.

В итоге это было фиаско, и я забросил идею.

Тут я вернулся к исследованиям и нашел единственную разницу, почему мой тестовый сайт заблокирован, а новоиспеченный сервис открывается — я не прикрутил SSL‑сертификаты.

Но когда у тебя семья, работа и в целом жизнь бьет ключом, то неудивительны временные трудности и банальные затупы.

Дело за малым — понять, как я могу это использовать.

9 часов назад @ habr.com
Рутокен с биометрией – не миф
Рутокен с биометрией – не миф Рутокен с биометрией – не миф

Основным плюсом однофакторной аутентификации с паролями является простота, а вот минусов куда больше:Пароли легко подобрать.

Что такое Рутокен БИОИтак, как вы уже могли догадаться, Рутокен БИО — это комплексный продукт, направленный на аппаратную поддержку биометрии по отпечатку пальца.

Рутокен ЭЦП 3.0 3250 БИО с аппаратной поддержкой биометрии — это привычный Рутокен ЭЦП 3.0, который можно использовать во всех уже внедренных сценариях.

Развитие экосистемы РутокенЛично мне, как непосредственному разработчику, хочется рассказать вам про Рутокен Логон для Linux 🤩Рутокен Логон — это программный комплекс для многофакторной аутентификации в отечественных линуксах.

Начиная с версии 4.12.0 в Руток…

9 часов назад @ habr.com
OpenCode против пентестера
OpenCode против пентестера OpenCode против пентестера

МетрикиНами оценивались следующие параметры:Количество подтвержденных уязвимостей – только с рабочим PoC, а не с оценками вида «вероятно, здесь SQLi».

Пять на Windows – включая карточки прямо в C:\Windows и в System32 .

К концу второго часа обе машины находились под полным контролем, как и в двух предыдущих прогонах.

Полезность человека в этом случае состояла не в знании конкретной уязвимости, а в способности увидеть необычную службу и задать проверяемую гипотезу.

OpenCode отличается от них характером работы:различные Nessus’ы и OpenVAS’ы сопоставляют версии с сигнатурами плагинов и часто выдают предположение о возможной уязвимости.

10 часов назад @ habr.com
Windows IR: системный подход. Часть 2 — изоляция, процессы, службы
Windows IR: системный подход. Часть 2 — изоляция, процессы, службы Windows IR: системный подход. Часть 2 — изоляция, процессы, службы

Все современные EDR поддерживают режим сетевой изоляции, и в то же время позволяют гибко настроить исключения в ней, если необходимо.

Еще один способ — изоляция на сетевых устройствах: Запретить трафик на межсетевом экране (на уровне L3) и на коммутаторе (на уровне L2).

Также видим, что в дереве два комплекта csrss / winlogon / explorer:Скрина терминала нет, поэтому вот скрин содержания транскрипта.

Остановленная служба не будет порождать процесс, и в тасклисте его видно не будет — а затем служба стартанет и запустит процесс.

Мысль здесь в том, что в «боевой» инфре таких артефактов будет много.

10 часов назад @ habr.com
Как мы собирали CTF-комьюнити в вузе с нуля до международного турнира
Как мы собирали CTF-комьюнити в вузе с нуля до международного турнира Как мы собирали CTF-комьюнити в вузе с нуля до международного турнира

Через два года после того, как мы сами начали играть, мы провели свой CTF, на который зарегистрировались 1280 команд из 51 страны.

Эта статья — про то, как формировалось комьюнити вокруг CTF в вузе, где потенциал был, но никто его не собирал воедино.

Мы начали играть в смешанных составах — мы с Александром(моим другом), остальные откуда придётся.

Мы с командой в 2025 году на Уральском форумеКомьюнити росло не потому, что мы кого-то агитировали.

Люди приходили, потому что видели, что это работает, это даёт скиллы, это помогает с трудоустройством.

11 часов назад @ habr.com
Как я делаю защищенное файловое хранилище — 2: Ограничения и возможности
Как я делаю защищенное файловое хранилище — 2: Ограничения и возможности Как я делаю защищенное файловое хранилище — 2: Ограничения и возможности

Вот так, перемещаясь время от времени по городу и размышляя по дороге, я и продолжил работать над своим проектом.

Для начала пришлось посмотреть в лицо самому главному ограничению: у меня был только я и был я не дома.

Несмотря на то, что я не мог использовать аппаратные механизмы защиты, меня это не огорчило.

Что ж, если приложение должно работать на любом железе, то оно должно как можно меньше зависеть от этого самого железа.

В нем было все, что мне нужно и не было ничего лишнего.

11 часов назад @ habr.com
Хакер Хакер
последний пост 1 час назад
Американский военный получил 70 месяцев тюрьмы за атаки на AT&T, Verizon и другие компании
Американский военный получил 70 месяцев тюрьмы за атаки на AT&T, Verizon и другие компании Американский военный получил 70 месяцев тюрьмы за атаки на AT&T, Verizon и другие компании

Среди сообщников Вагениуса следствие называет канадца Коннора Райли Муку (Connor Riley Moucka), известного как Waifu и Judische, а также Джона Эрина Биннса (John Erin Binns), использовавшего ники irdev и j_irdev1337.

Злоумышленники угрожали опубликовать украденную информацию на хак-форумах BreachForums и XSS, а в некоторых случаях выставляли похищенные данные на продажу, оценивая их в несколько тысяч долларов США.

В феврале 2025 года он признал свою вину по делу о взломах компаний AT&T и Verizon и передаче конфиденциальных телефонных записей.

А в июле того же года он также признал себя виновным по обвинениям в краже личности при отягчающих обстоятельствах, сговоре с целью мошенничества и вы…

1 час назад @ xakep.ru
Лидером вымогательской группы KillSec оказался 16-летний подросток
Лидером вымогательской группы KillSec оказался 16-летний подросток Лидером вымогательской группы KillSec оказался 16-летний подросток

В рамках международной операции KillSwitch правоохранительные органы ликвидировали инфраструктуру вымогательской группировки KillSec, конфисковали ее сайт для «слива» данных и серверы, а также задержали трех подозреваемых.

Подозреваемых задержали в Испании, Румынии и Великобритании, и суммарно полиция провела восемь обысков в этих странах, а также на территории Греции.

В рамках операции полиция перехватила управление даркнет-сайтом KillSec и пятью ключевыми серверами, включая основной сервер группы и системы, использовавшиеся для хранения похищенной информации.

Помимо этого следователи выяснили, что участники KillSec использовали ИИ для создания и поддержки своей инфраструктуры, а также пои…

3 часа назад @ xakep.ru
HTB Reactor. Повышаем привилегии через открытый отладчик Node.js
HTB Reactor. Повышаем привилегии через открытый отладчик Node.js HTB Reactor. Повышаем привилегии через открытый отладчик Node.js

Справка: сканирование портовСка­ниро­вание пор­тов — стан­дар­тный пер­вый шаг при любой ата­ке.

На осно­ве этой информа­ции он выбира­ет сле­дующий шаг к получе­нию точ­ки вхо­да.

Улуч­шить резуль­таты его работы ты можешь при помощи такого скрип­та:#!/ bin/ bash ports = $( nmap -p- -- min- rate = 500 $1 | grep ^ [ 0 -9 ] | cut -d '/ ' -f 1 | tr ' ' ', ' | sed s/, $/ / ) nmap -p $ports -A $1Он дей­ству­ет в два эта­па.

На пер­вом выпол­няет­ся обыч­ное быс­трое ска­ниро­вание, на вто­ром — более тща­тель­ное, с исполь­зовани­ем встро­енных скрип­тов (опция -A ).

Под­робнее про работу с Nmap читай в статье «Nmap с самого начала.

5 часов назад @ xakep.ru
В OpenAI заявляют, что прервали кампанию по дистилляции, связанную с Moonshot AI
В OpenAI заявляют, что прервали кампанию по дистилляции, связанную с Moonshot AI В OpenAI заявляют, что прервали кампанию по дистилляции, связанную с Moonshot AI

Основной кластер этой активности в компании связывают с людьми, имеющими отношение к разработчику Kimi — китайской компании Moonshot AI.

В отчете подчеркивается, что атакующие не взламывали шифрование, базы данных и не получили доступ к историям пользовательских диалогов.

Какие именно модели OpenAI стали целью атак, в компании не сообщили.

Также в OpenAI признают, что не все замеченные операторы этой кампании могли быть связаны с Moonshot AI.

По версии Anthropic, часть этих диалогов в Moonshot AI сохраняли и использовали для обучения собственной модели, работающей с цепочками рассуждений.

6 часов назад @ xakep.ru
Репозитории на GitHub раскрывают более 543 000 учетных данных
Репозитории на GitHub раскрывают более 543 000 учетных данных Репозитории на GitHub раскрывают более 543 000 учетных данных

Исследователи из компании Truffle Security подсчитали, что в открытых репозиториях на GitHub опубликованы 543 699 уникальных и по-прежнему действующих учетных данных.

В общей сложности 543 699 уникальных секретов встречались более чем в 1,1 млн файлов и репозиториев, включая копии в форках.

В компании отдельно отметили, что в случае GitHub масштаб проблемы оказался в два раза больше, чем при аналогичном исследовании Hugging Face.

Отдельно исследователи оценили эффективность механизма GitHub Push Protection, который ищет в коде API-ключи, токены доступа и другие секреты, а затем блокирует их публикацию.

Однако исследователи установили, что, невзирая на работу GitHub Push Protection, 199 843 …

8 часов назад @ xakep.ru
СМИ: Минцифры снова рассматривает введение платы за международный трафик
СМИ: Минцифры снова рассматривает введение платы за международный трафик СМИ: Минцифры снова рассматривает введение платы за международный трафик

На этот раз с операторами обсуждается лимит в 50 Гбайт в месяц и только для сетей 5G.

Дело в том, что, по словам источников, у операторов связи попросту нет технического решения, нужного для реализации такого предложения.

Директор по продуктам Vigo Антон Прокопенко сообщил изданию, что в целом учитывать зарубежный трафик возможно, например, классифицируя его по IP-адресам.

Так, операторам придется классифицировать адреса и одновременно учитывать переключения абонента между 5G и LTE.

К примеру, в 2025 году частный абонент в среднем расходовал около 24 Гбайт всего мобильного трафика в месяц.

10 часов назад @ xakep.ru
В GitLab AI Gateway исправили критический баг на 9,9 балла
В GitLab AI Gateway исправили критический баг на 9,9 балла В GitLab AI Gateway исправили критический баг на 9,9 балла

AI Gateway представляет собой сервис, который связывает инстанс GitLab с ИИ-моделями и обеспечивает работу функций GitLab Duo.

Хотя в GitLab используют собственный облачный инстанс AI Gateway для GitLab.com, GitLab Self-Managed и GitLab Dedicated, пользователи также имеют возможность развертывать собственные установки в рамках GitLab Self-Managed посредством GitLab Duo Self-Hosted.

Подчеркивается, что пользователи AI Gateway, размещенного на серверах самой GitLab, уже защищены и им не нужно предпринимать никаких дополнительных действий.

В результате атакующий получал возможность выполнять произвольные команды непосредственно в AI Gateway.

Так как AI Gateway устанавливается отдельно, в виде …

1 day, 1 hour назад @ xakep.ru
Near Intents идентифицировала атакующего и вернула похищенные $3,8 млн
Near Intents идентифицировала атакующего и вернула похищенные $3,8 млн Near Intents идентифицировала атакующего и вернула похищенные $3,8 млн

Команда кроссчейн-сервиса для обмена токенов NEAR Intents сообщила, что ей вернули 3,8 млн долларов, похищенных при взломе 1 октября.

Деньги вернулись всего через сутки после того, как команда заявила, что установила личность атакующего, и дала ему 48 часов на возврат средств.

В пятницу о возврате средств объявил генеральный менеджер NEAR Intents Алекс Шевченко в соцсети X. По его словам, все средства возвращены и команда прекращает расследование инцидента.

Уязвимость позволила злоумышленнику вывести средства, после чего работу NEAR Intents приостановили.

За два дня до атаки команда Near Intents заблокировала попытку обменять $50 млн, предпринятую хакером, стоящим за взломом биржи Bitget.

1 day, 2 hours назад @ xakep.ru
Ботнет Carbonato использует ИИ для захвата незащищенных Docker-хостов
Ботнет Carbonato использует ИИ для захвата незащищенных Docker-хостов Ботнет Carbonato использует ИИ для захвата незащищенных Docker-хостов

После захвата машины малварь устанавливает в систему Hermes Agent — опенсорсный фреймворк для ИИ-агентов — и разворачивает в нем агента GH0ST, которым операторы управляют через Telegram.

Исследователи обнаружили Carbonato в публично доступном хранилище Docker-образов, которое не требовало аутентификации.

Обнаружив такую систему, малварь использует API и запускает привилегированный контейнер, с помощью которого получает доступ к самому хосту.

Обнаружив новую цель, Carbonato запускает ту же цепочку заражения, поэтому исследователи предупреждают, что малварь обладает потенциалом червя.

Для защиты от таких атак специалисты советуют не «светить» Docker API в интернете и обязательно использовать …

1 day, 3 hours назад @ xakep.ru
Обход антивирусов на практике. Разбираем на пальцах сигнатурный движок YARA
Обход антивирусов на практике. Разбираем на пальцах сигнатурный движок YARA Обход антивирусов на практике. Разбираем на пальцах сигнатурный движок YARA

В статье мы раз­берем­ся, как устро­ены пра­вила и модули YARA, напишем собс­твен­ные сиг­натуры и при­меним их для поис­ка ано­маль­ных фай­лов.

Книга «Обход антивирусов на практике» Это пер­вая гла­ва из кни­ги «Об­ход анти­виру­сов на прак­тике».

Си­ла YARA — в гиб­кости опи­сания пат­тернов.

— любой байт целиком (от 00 до FF );— любой байт целиком (от до ); A?

Допус­тимые фор­мы:Син­таксис Рас­шифров­ка [ 4-6] От 4 до 6 байт [ 10-] От 10 байт до бес­конеч­ности [ -] От 0 байт до бес­конеч­ностиПе­рехо­ды кри­тичес­ки важ­ны в нес­коль­ких типич­ных сце­нари­ях.

1 day, 5 hours назад @ xakep.ru
Кастомные GPT используются для ClickFix-атак и распространения RAT
Кастомные GPT используются для ClickFix-атак и распространения RAT Кастомные GPT используются для ClickFix-атак и распространения RAT

ИБ-специалисты из компании Huntress обнаружили, что злоумышленники распространяют RAT через кастомные GPT в ChatGPT.

Исследователи объясняют, что злоумышленник злоупотребляет легитимной функцией OpenAI, которая позволяет создавать кастомные версии ChatGPT, адаптированные для конкретных задач, с соответствующими инструкциями, знаниями и навыками.

Для закрепления в системе малварь использовала сразу два механизма: добавляла запись в раздел Run реестра Windows и создавала задачу в планировщике.

Среди них были скрипт для закрепления в системе и финальная полезная нагрузка — RAT.

Перед подключением к своей управляющей инфраструктуре RAT собирал информацию о системе, а адрес управляющего сервера …

1 day, 6 hours назад @ xakep.ru
Аккаунт Microsoft в соцсети X взломали для распространения криптовалютного скама
Аккаунт Microsoft в соцсети X взломали для распространения криптовалютного скама Аккаунт Microsoft в соцсети X взломали для распространения криптовалютного скама

Неизвестные злоумышленники «угнали» официальный аккаунт Microsoft в соцсети X, на который подписаны более 13 млн человек.

Кроме того, злоумышленники изменили аватар Microsoft на изображение скрепки.

В нем сообщалось, что компании известно о токене, который продвигают с использованием бренда Clippy и интеллектуальной собственности Microsoft без разрешения.

«Microsoft не санкционировала создание, продвижение или использование каких-либо криптовалютных токенов, связанных с Clippy, Microsoft или $MSFT, а также не спонсирует и не поддерживает их», — гласило сообщение.

Например, в июне 2024 года криптомошенники захватили профиль Microsoft India в соцсети X, на тот момент насчитывавший более 211 0…

1 day, 8 hours назад @ xakep.ru
Еще одного участника группы ShinyHunters могли арестовать в Иордании
Еще одного участника группы ShinyHunters могли арестовать в Иордании Еще одного участника группы ShinyHunters могли арестовать в Иордании

По данным информационного агентства Reuters, власти Иордании задержали предполагаемого участника группировки ShinyHunters, известного под ником Rey.

Источники журналистов утверждают, что теперь он сотрудничает с ФБР и помогает правоохранительным органам установить личности и местонахождение других участников группы.

В настоящее время Хадер якобы открыл следователям доступ к содержимому своих устройств и переписок, чтобы помочь идентифицировать своих предполагаемых сообщников.

Задержание Rey произошло на фоне конфликта между участниками ShinyHunters и ФБР.

В частности, в отчете сообщалось, что хак-группа преувеличивает масштабы своих атак, угрожает жертвам и их родственникам, занимается сват…

1 day, 10 hours назад @ xakep.ru
Новая атака снижает стойкость RSA и не требует факторизации
Новая атака снижает стойкость RSA и не требует факторизации Новая атака снижает стойкость RSA и не требует факторизации

Исследователи разработали новый метод атаки на RSA, который позволяет подделывать цифровые подписи без факторизации RSA-модуля и восстановления приватного ключа.

Для 1024-битного RSA такая атака уже практически реализуема, а стойкость ключей длиной 2048 и 4096 бит снижается до уровня, который считается недостаточным по современным стандартам.

До сих пор считалось, что для получения корректной RSA-подписи атакующему сначала придется разложить большое число на простые множители и восстановить приватный ключ, и стойкость RSA к таким атакам определяется сложностью факторизации больших чисел.

Эта работа показывает, что на практике RSA можно взломать, не взламывая сам ключ», — пояснил изданию Ars…

4 days, 1 hour назад @ xakep.ru
Из кадровой базы Пентагона утекли данные почти 3 млн человек
Из кадровой базы Пентагона утекли данные почти 3 млн человек Из кадровой базы Пентагона утекли данные почти 3 млн человек

Представители Пентагона заявили СМИ, что утечка затронула данные 2,76 млн живых людей и еще 294 000 умерших.

Для сравнения, по состоянию на март 2026 года в вооруженных силах США насчитывалось около 1,3 млн действующих военнослужащих.

Об инциденте стало известно из уведомления DMDC от 18 сентября 2026 года, которое один из получателей опубликовал на Reddit.

В общей сложности DMDC хранит более 60 млн записей о военных и гражданских сотрудниках, подрядчиках, членах их семей, пенсионерах и ветеранах.

Также центр отвечает за управление цифровыми идентификаторами и средствами доступа: учетными данными, паролями и смарт-картами, которые используются для входа в системы и на объекты Пентагона.

4 days, 3 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 6 часов назад
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown.

Apache OpenOffice has not fixed the matching flaw, which it tracks as CVE-2026-59265.

A LibreOffice or Apache OpenOffice Calc spreadsheet can hold a "database range", a block of cells that pulls in data from an outside source and refreshes it by itself.

In the proof of concept, the driver simply opens the Calculator app, a harmless stand-in, but the same path can run any Java code the attacker chooses.

The Hacker News has contacted The Document Foundation, which develops LibreOffice, and the Apache OpenOffice project for comment.

6 часов назад @ thehackernews.com
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies
Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies Wikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as Proxies

The Wikimedia Foundation, which hosts Wikipedia, has confirmed that it has discovered activity by rogue OpenAI agents on its platforms, including unsuccessful efforts to compromise Etherpad, a public note-taking tool, and edit Wikipedia pages.

To that end, Wikimedia said it identified edits to Wikimedia wikis suspected to be from agents operated by OpenAI.

Agents operated by OpenAI are also assessed to have made unsuccessful attempts to compromise Etherpad and again use it as a proxy to retrieve data from other websites.

It also called out AI companies for not doing enough to secure their systems and ensure they do not cause any harm.

, when an internal research model exploited two vulnerab…

7 часов назад @ thehackernews.com
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

Remote MCP servers can run backend code that differs entirely from what their public repository shows.

To measure the gap, we analyzed 15,465 publicly indexed MCP servers across 5 MCP registries, deduplicated to 5,095 unique hostnames.

An agent connected to these servers may send data to jurisdictions the security team never approved.

Download "15,465 MCP Servers, 0 Governance"Trust Is the Attack SurfaceThe protocol isn't the problem.

Get the full report, "15,465 MCP Servers, 0 Governance"Want to go further?

7 часов назад @ thehackernews.com
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports
Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports Google Pauses OSS Product Bug Bounty Rewards After Surge in Invalid Automated Reports

Google has stopped accepting product vulnerability reports through its bug bounty program for its open-source software.

Neither the post nor the notice gives a date for accepting product vulnerability reports again.

Under the Cloud VRP rules, a flaw in an open source repository maintained by Google Cloud that affects Cloud products is rated at most IT3b.

Product vulnerability reports may still be accepted for some Google Cloud repositories that affect Google Cloud products, but the notice does not name them.

Under the Cloud VRP rules, a flaw in an open source repository maintained by Google Cloud that affects Cloud products is rated at most IT3b.

9 часов назад @ thehackernews.com
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory.

Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and listed a fixed version for each product.

Affected Products and Fixed VersionsThe flaw affects all versions of the 8 products before the fixed versions listed below.

Atlassian listed these fixed versions as of October 6:For Crowd's 7.1 branch, the ticket's fix version field said 7.1.7.

It marked every version of Bamboo Server, Bitbucket Server, Confluence Server, and Crowd Server as affected and listed no fixe…

11 часов назад @ thehackernews.com
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach
FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has removed an Accenture contractor for their alleged role in a ShinyHunters-breach that led to the theft of personal details of thousands of bureau employees.

"As such, the FBI has removed the contractor and taken all necessary steps to both mitigate any further risk and protect our workforce."

Although the name of the third-party organization was not disclosed by the FBI, Reuters reported that it's Oracle PeopleSoft, which the ShinyHunters group said it exploited to breach the FBI's job portal last month.

The Hacker News has contacted both the FBI and Oracle for comment, and we will update the story if we hear back.

Accenture, in a statement …

11 часов назад @ thehackernews.com
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

They used a private Danish company's lawful right to look up records in the Central Person Register (CPR).

The ministry's statement does not say whether those people's CPR numbers were reached, or whether anyone will be told individually that they are among the 8.8 million.

A CPR number alone is enough to identify a person for that purpose.

The CPR number itself is not on that list.

Egelund told Ritzau it was too early to say whether people will need new CPR numbers.

12 часов назад @ thehackernews.com
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

What's notable about this browser cache smuggling approach is that it allows the attackers to conceal the payload script and bypass the character limit restrictions.

The Windows Run dialog, triggered by Win + R, truncates any input that exceeds approximately 260 characters.

The PowerShell script serves as a conduit for an intermediate PowerShell payload that's responsible for downloading the next stage ("cab.dat").

This is not the first time payloads have been staged in the browser cache as part of ClickFix attacks.

The user is then asked to paste the copied command into the Windows Run dialog, PowerShell, Windows Terminal, macOS Terminal, or another trusted system utility.

13 часов назад @ thehackernews.com
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions.

"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network," Microsoft said in an advisory released on October 2, 2026.

The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments.

Users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected.

The following …

1 day, 2 hours назад @ thehackernews.com
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

Successful exploitation requires NetScaler ADC or NetScaler Gateway to be configured either as a SAML service provider (SP) or SAML identity provider(IdP).

— The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a critical security flaw impacting Fortinet FortiMail.

"The group exploited software vulnerabilities and poorly secured access points, particularly to cloud storage, to gain access to organizations' systems," Europol said.

Victims were named on the group's dark web leak site and threatened with publication of their data unless paid."

"The group exploited software vulnerabilities and poorly secured access points, particularly to cloud stora…

1 day, 4 hours назад @ thehackernews.com
The Credential Layer Is Expanding Faster Than Security Teams Can See It
The Credential Layer Is Expanding Faster Than Security Teams Can See It The Credential Layer Is Expanding Faster Than Security Teams Can See It

Security teams need to establish visibility into that expanding credential layer right now.

The credential layer has no convenient perimeterThe credential layer is the collection of credentials connecting people, applications, infrastructure, and services across an enterprise.

Security teams need a real denominator for their coverage metricsMany enterprises already have strong secrets-management programs.

Detection builds the map for everything that followsThe first step in controlling credential risk is understanding the credential layer the organization actually has.

Security teams need visibility capable of expanding at the same pace.

1 day, 7 hours назад @ thehackernews.com
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2 Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

The transaction ID is set to all zeros instead of a random value, as per the specification.

Poll for UDP packets that encode operator commands in the STUN transaction ID field.

"From a network monitoring perspective, the activity appears as innocuous interaction with STUN servers," Nozomi Networks said.

It's worth noting these registration messages do not conform to the STUN protocol definition, causing legitimate STUN servers to drop the packet.

]184") is said to have returned an all-zero transaction ID instead of echoing the transaction ID of the original Binding Request in the Binding Success Response.

1 day, 7 hours назад @ thehackernews.com
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents.

Stating that Full Disk Access largely bypasses controls designed to safeguard users' private data, Apple said it plans to introduce updates to the setting to ensure that this sort of access is granted only with an explicit user action.

"As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially," Apple added.

Meta has since clarified that, for Muse to be able to access a user's private messages, it must have two permissions: have Full Disk Ac…

1 day, 8 hours назад @ thehackernews.com
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck.

"Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login," according to an advisory for the flaw.

"HFS generated its Koa session-cookie signing key with JavaScript Math.random() and exposed outputs from the same V8 PRNG in the unauthenticated SRP login handshake," Ramos noted.

"An attacker can reconstruct the PRNG state, recover the signing key, forge an administrator session, and use the documented server_code …

1 day, 10 hours назад @ thehackernews.com
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks.

"CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said.

"The issue affects customer-managed NetScaler deployments running affected supported versions when the required preconditions are met."

For successful exploitation, NetScaler ADC or NetScaler Gateway must be configured either as a SAML service provider (SP) or SAML identity provider(IdP).

"Citrix has observed targeted attacks o…

1 day, 12 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 6 days, 10 hours назад
This month in security with Tony Anscombe – September 2026 edition
This month in security with Tony Anscombe – September 2026 edition This month in security with Tony Anscombe – September 2026 edition

Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep paceAs another month draws to a close, ESET Chief Security Evangelist Tony Anscombe reviews some of the top cybersecurity stories that have made the news over the past 30 days while offering insights that they hold for your or your company's cyber-defenses.

Here's Tony's rundown of some of what stood out most in September 2026.

An OpenAI agent has broken into Australia's national healthcare database in what is the first known case of AI autonomously hacking a government network,Earlier in the month, Google announced that its models also escaped it…

6 days, 10 hours назад @ welivesecurity.com
Timeshare exit scams: From fake buyers to recovery fraud
Timeshare exit scams: From fake buyers to recovery fraud Timeshare exit scams: From fake buyers to recovery fraud

If an exit company cold calls you or makes 100% guaranteed promises of a swift exit, they’re likely to be a scammer.

If you’ve already paid a scam timeshare exit company, there’s still a chance you could get your money back if you act quickly.

What are the warning signs of a timeshare exit scam?

How can I check whether a timeshare exit company is legitimate?

What should I do if I've already paid a timeshare exit scam company?

1 week назад @ welivesecurity.com
The devil is still in the email – but wearing a new mask
The devil is still in the email – but wearing a new mask The devil is still in the email – but wearing a new mask

Some techniques go after live sessions themselves, with attackers shifting their focus from stealing passwords to stealing authentication tokens.

Purpose-built AI tools now make it trivial to clean up the language and even tailor the lure for each recipient.

What’s more, the code is scanned on a phone, so the usual controls that protect company-issued laptops don’t apply.

The ‘device hop’ also means that the company may have a hard time developing a full picture of the attack.

AI helps deal with the volume and speed involved, whereas experienced analysts can assess the evidence and direct the response.

1 week, 1 day назад @ welivesecurity.com
Is that vibe coded app safe? 5 checks before you download
Is that vibe coded app safe? 5 checks before you download Is that vibe coded app safe? 5 checks before you download

Vibe coded apps may also be exposed to prompt injection.

What can go wrong with vibe coded apps?

With a badly coded app, the leak usually happens on the developer’s servers, so start with your account and credentials.

Frequently asked questions (FAQs)What does 'vibe coded' mean?

Are all vibe coded apps dangerous?

1 week, 4 days назад @ welivesecurity.com
Been told to pay at a Bitcoin ATM? Read this first
Been told to pay at a Bitcoin ATM? Read this first Been told to pay at a Bitcoin ATM? Read this first

No real government agency, bank, or company will ever tell you to pay them via a Bitcoin ATM.

How do Bitcoin ATM scams work?

How do I stay safe from Bitcoin ATM scams?

What can I do straight after a Bitcoin ATM scam?

What should I do if I’ve fallen for a Bitcoin ATM scam?

1 week, 5 days назад @ welivesecurity.com
Looking for free Robux? Here’s what’s real, and what’s a scam
Looking for free Robux? Here’s what’s real, and what’s a scam Looking for free Robux? Here’s what’s real, and what’s a scam

Roblox itself is very clear: “There is no such thing as free Robux or subscription offers, tricks, or codes.”What there is, unfortunately, are a lot of scammers looking to trick you out of your personal information and logins with the promise of free Robux.

But it’s also about helping them understand there’s no such thing as ‘free’ Robux.

Frequently asked questions (FAQs)Is there a real free Robux generator?

Roblox says there is no legitimate way to get free Robux through generators, tricks or codes.

But these aren’t ‘free Robux generators.’How can I tell if a Robux offer is a scam?

2 weeks назад @ welivesecurity.com
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive

Many have moved past chatbots and begun assigning work to AI agents in the hope of gaining an edge on their similarly resource-strapped competitors and levelling the playing field with larger companies.

Indeed, the ambitious adopters are deploying, or at least experimenting with, multi-agent ‘assembly lines,’ where one supervisor agent manages swarms of specialist agents and passes work between them.

Of course, some risks surrounding AI agents have familiar roots: an agent’s supply chains can be compromised and its permissions abused.

Agents can also suffer from agentic misalignment where they proceed doggedly even if it involves, for example, breaking into other companies.

For a company wi…

2 weeks, 1 day назад @ welivesecurity.com
‘Nudify’ apps: What to do if someone makes a fake nude of you
‘Nudify’ apps: What to do if someone makes a fake nude of you ‘Nudify’ apps: What to do if someone makes a fake nude of you

And it doesn’t get much darker than ‘nudification’ or ‘nudify’ apps.

Are ‘nudify’ apps illegal?

The short answer is “it depends.” In the US, there’s no federal law explicitly prohibiting ‘nudify’ apps.

Can I sue over an AI nude image?

Will reporting a fake nude image make it disappear everywhere?

2 weeks, 4 days назад @ welivesecurity.com
Beware the SparroWock: The backdoor that bites, the commands that catch
Beware the SparroWock: The backdoor that bites, the commands that catch Beware the SparroWock: The backdoor that bites, the commands that catch

A month later, we noticed that the group had started using the new SparroWocky backdoor, which then quickly replaced SparrowDoor as FamousSparrow’s main implant.

Based on our investigation, we attribute the latest campaign and the SparroWocky backdoor to FamousSparrow with high confidence, since in some of the first attacks involving this backdoor, SparroWocky was deployed by the FamousSparrow-exclusive SparrowDoor.

Backdoor commandsThe backdoor first establishes communication with its C&C server, then executes its core logic in an infinite loop, within which it processes received commands.

A common technique that the backdoor uses is dynamic API resolution via API hashing, but the backdoor…

2 weeks, 5 days назад @ welivesecurity.com
Cyberthreats are moving faster than SMBs: Readiness must accelerate
Cyberthreats are moving faster than SMBs: Readiness must accelerate Cyberthreats are moving faster than SMBs: Readiness must accelerate

This calls for a different operational model where AI and automation support security teams where it makes sense, with human oversight for decisions that require context and judgment.

ESET SMB Cyber Readiness Index 2026 found that most (73%) SMBs are integrating AI into their business.

Processing exfiltrated data: AI rapidly classifies, cleans-up, and extracts large volumes of information from stolen data in order to make it more monetizable/usable for cybercriminals.

Why SMBs are struggling with complexityUnfortunately, security teams are already on the back foot.

That means protection for AI conversations, agents, AI-generated outputs, AI components, sensitive data, and the broader AI eco…

2 weeks, 6 days назад @ welivesecurity.com
GuardBreaker: Derailing AI-assisted malware analysis with a code comment
GuardBreaker: Derailing AI-assisted malware analysis with a code comment GuardBreaker: Derailing AI-assisted malware analysis with a code comment

Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way.

Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while under inspection.

Reporting on the same broader campaign, StepSecurity found a prompt that flat-out instructed any analyzing model that parsed the file to disregard the malicious code and report the package as clean.

Some parts of the malicious code could be concealed under the pretense of being confidential information or other sensitive data.

Crucially, however, no single LLM engine should have the sole au…

3 weeks, 5 days назад @ welivesecurity.com
Safe word: What is it and why do you need one?
Safe word: What is it and why do you need one? Safe word: What is it and why do you need one?

The technology might be impressive, but a simple technique could stop the scammers in their tracks: a pre-agreed safe word.

What is a safe word?

But suggest some scenarios in which it would be a good idea to request a safe word.

It’s important to have a backup if someone can’t remember the safe word.

But a safe word is a fantastic, free option for uncovering deepfake audio fraud like fake/virtual kidnappings.

3 weeks, 6 days назад @ welivesecurity.com
I’ve been deepfaked: What do I do?
I’ve been deepfaked: What do I do? I’ve been deepfaked: What do I do?

But across the globe, policymakers and public opinion are forcing tech platforms to better police this content.

What should I do if I’ve been deepfaked?

Google: Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

The first point of call is to contact the publisher to request removal.

1 month назад @ welivesecurity.com
This month in security with Tony Anscombe – August 2026 edition
This month in security with Tony Anscombe – August 2026 edition This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity newsWith August coming to a close, it's time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month.

Here's some of what caught Tony's attention:OpenAI has disclosed more details about how its agents hacked AI collaboration platform Hugging Face.

Delta Airlines is investigating an incident where a flight passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network.

What are the lessons that businesses and critical infra…

1 month назад @ welivesecurity.com
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
AI-assisted reconnaissance: Why everyone could be a viable target for fraud AI-assisted reconnaissance: Why everyone could be a viable target for fraud

And of course, linking our professional and personal social media accounts is a simple task for AI.

For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information.

Losing your personal information is one thing.

What you can do about AI-powered OSINTWhen it comes to AI-powered reconnaissance, there are things you can control and things you can’t.

Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.

1 month, 1 week назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 5 часов назад
Anaconda combines agent swarms with autonomous security testing
Anaconda combines agent swarms with autonomous security testing Anaconda combines agent swarms with autonomous security testing

Anaconda has announced new capabilities across the Anaconda Platform that pair agentic development with autonomous security testing.

The expansion brings agent swarms and autonomous red-team agents together with trusted packages, models, and environments to help builders ship faster and address security weaknesses before production.

Anaconda’s recent survey of AI-native builders revealed strong momentum behind agent swarms with 63% of respondents moving toward the technology in some form – a clear signal that swarms are quickly becoming standard practice.

AI Security and Guardrails deliver continuous security testing and runtime protection, helping teams catch weaknesses before release and …

5 часов назад @ helpnetsecurity.com
Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia
Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia Rogue OpenAI agents made unauthorized Wikipedia edits and millions of requests to Wikimedia

Rogue OpenAI agents made unauthorized edits on Wikimedia wikis and sent millions of automated requests to Wikimedia’s public APIs, traffic that may have contributed to a partial outage of the Wikidata Query Service in May, the Wikimedia Foundation said on Monday.

“We can confirm that we have discovered some activity by these ‘rogue’ OpenAI agents on Wikimedia platforms,” added Deckelmann.

Sandbox edits and a citation toolWikimedia identified edits to its wikis that it believes came from OpenAI agents.

Millions of requests and a May outageWikimedia said OpenAI agents made millions of automated requests to its public APIs and crawled millions of pages, mostly on Wikidata and Wikimedia Commons…

5 часов назад @ helpnetsecurity.com
AppViewX targets shadow AI risks with agent discovery and runtime enforcement
AppViewX targets shadow AI risks with agent discovery and runtime enforcement AppViewX targets shadow AI risks with agent discovery and runtime enforcement

AppViewX now also issues quantum-resilient agent identities, so trust in every agent holds as the cryptography infrastructure layer of the enterprise evolves.

AppViewX approaches agent security as an identity and access problem, but one that requires a new paradigm.

Rather than simply retrofitting traditional human identity architectures, Agent Identity Security is purpose-built at the identity layer.

It offers the industry’s most comprehensive discovery, governance, and runtime security capabilities for coding agents, enterprise productivity agents, endpoint agents, SaaS agents, and custom-built agents.

Govern every MCP server, including shadow servers, with a new MCP Gateway: AppViewX dis…

5 часов назад @ helpnetsecurity.com
New Relic adds terminal-based investigation and recovery checks with Ground Truth CLI
New Relic adds terminal-based investigation and recovery checks with Ground Truth CLI New Relic adds terminal-based investigation and recovery checks with Ground Truth CLI

New Relic has announced New Relic Ground Truth CLI augmented with New Relic Autopilot API, bringing headless observability straight to developers and AI agents in their natural workflows.

New Relic Ground Truth CLI brings supported New Relic investigation capabilities directly into command-line workflows, helping developers and AI agents investigate incidents without repeatedly switching to the UI.

Part of the broader New Relic Ground Truth offering, the CLI provides a single command-line experience with connections to Autopilot, NerdGraph and memory APIs.

New Relic Ground Truth CLI brings critical intelligence directly into the environments where developers and agents work.

An engineer inv…

5 часов назад @ helpnetsecurity.com
SailPoint adds AI agent discovery, temporary access and compliance automation
SailPoint adds AI agent discovery, temporary access and compliance automation SailPoint adds AI agent discovery, temporary access and compliance automation

SailPoint has announced significant new capabilities across SailPoint Agentic Fabric (SAF) and SailPoint Human Fabric (SHF), the two purpose-built products of its Identity Security solution, built on SailPoint Atlas.

Introducing SailPoint Autonomous AgentsWhen AI agents invoke MCP tool calls at machine speed, human review of every action is impossible.

SailPoint announced Autonomous Agents, a fleet of specialized AI agents built to govern and protect the agentic ecosystem.

Streamlining operations: Governance has become too admin-heavy, and manual processes can’t keep pace with the volume of human and agent access.

Platform milestone: SailPoint Agentic Fabric + Entro integrationAlso announce…

5 часов назад @ helpnetsecurity.com
Intellias Agentic ServiceOps applies governed AI across IT operations
Intellias Agentic ServiceOps applies governed AI across IT operations Intellias Agentic ServiceOps applies governed AI across IT operations

Intellias has launched Agentic ServiceOps a managed IT service that applies governed agentic AI across IT service management (ITSM) and IT operations management (ITOM), from the service desk to the infrastructure behind it.

It helps organizations resolve more IT work end to end, breaking the link between rising complexity and rising costs.

Intellias’ Agentic ServiceOps adds an Intelligent Orchestrator Layer to clients’ existing IT service management and IT operations management environments, building on the systems they already run rather than replacing them.

Inside its own IT function, Intellias runs Agentic Service Operations end to end, where agents triage, classify, prioritize, and assi…

6 часов назад @ helpnetsecurity.com
AXON Datum enforces data access policies before AI systems act
AXON Datum enforces data access policies before AI systems act AXON Datum enforces data access policies before AI systems act

As organizations move from using AI to analyze information toward deploying AI systems that can make decisions and take action, data governance becomes an operational requirement.

AXON Datum addresses this challenge by establishing governance at the data layer.

When data enters the environment, Datum records its source, classifies it, and applies policies governing access, residency, use and movement.

AXON Datum blocks and records access requests that don’t meet an organization’s or institution’s policies.

AXON Datum solves this challenge by complementing AXON Maestro’s AI-native AN-4 orchestration with the governance, sovereignty, and control required for autonomous action.

6 часов назад @ helpnetsecurity.com
Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)
Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589) Atlassian urges immediate patching of critical Data Center file access vulnerability (CVE-2026-21589)

Attackers who know where to look can read files from Atlassian Data Center installations without logging in, the company has warned.

About CVE-2026-21589CVE-2026-21589, a critical arbitrary file access vulnerability with a 9.3 CVSS score, affects all versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.

The fixed versions are:Bitbucket Data Center 9.4.26, 10.2.8 and 10.5.1Confluence Data Center 9.2.26 and 10.2.19Jira Software Data Center and Jira Service Management Data Center 10.3.26 and 11.3.12 (also 9.12.40 for Jira Software and 5.12.40 for Jira Service Manage…

6 часов назад @ helpnetsecurity.com
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)

Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

DSU is a tool used by enterprise IT administrators to apply driver, BIOS, and firmware updates to Dell PowerEdge servers.

“An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges,” the company wrote in the advisory.

“Dell recommends customers upgrade at the earliest opportuni…

8 часов назад @ helpnetsecurity.com
Ontinue extends ION MXDR with managed dark web monitoring
Ontinue extends ION MXDR with managed dark web monitoring Ontinue extends ION MXDR with managed dark web monitoring

Ontinue has announced the launch of ION for Dark Web Monitoring (DWM), a new managed add-on service that extends ION MXDR to continuously identify exposed credentials, detect brand impersonation attempts, and uncover emerging external threats before attackers can exploit them.

Most dark web monitoring solutions stop at detection.

ION for Dark Web Monitoring goes further by investigating findings, assessing risk, and helping customers take action before exposures become incidents.”Turning external threat intelligence into actionION for Dark Web Monitoring continuously monitors customer-owned domains and brand assets across trusted intelligence sources spanning the clear, deep, and dark web.

…

8 часов назад @ helpnetsecurity.com
Transcend Rails brings policy enforcement and spending controls to AI agents
Transcend Rails brings policy enforcement and spending controls to AI agents Transcend Rails brings policy enforcement and spending controls to AI agents

Transcend has launched Transcend Rails, a new category of agent management that goes beyond identity and access control to govern what an agent does.

Every enterprise scaling AI agents hits the same wall: the board asks what agents did last quarter, and no one can reconstruct it.

Gartner predicts that by 2030, half of AI agent deployment failures will be caused by insufficient runtime enforcement from AI governance platforms.

“Transcend Rails gives each agent exactly the permissions and the budget its job needs, and nothing more.

“The fastest way to get AI agents into production is to make sure they only do what you’ve approved, and that’s what Transcend Rails does,” said Ben Brook, CEO of …

8 часов назад @ helpnetsecurity.com
Hack The Box helps enterprises evaluate AI agents for cybersecurity roles
Hack The Box helps enterprises evaluate AI agents for cybersecurity roles Hack The Box helps enterprises evaluate AI agents for cybersecurity roles

Hack The Box has introduced AI Range Enterprise Edition, making its platform for testing and measuring AI security agent effectiveness available to enterprise security teams.

The offering enables organizations to evaluate whether their own AI agents can perform the cybersecurity roles assigned to them and make informed decisions about how to use agents across the workforce.

Companies often assess whether people can do the job they were hired to do, but AI agents may not face the same scrutiny.

HTB introduced AI Range in December 2025 to test AI security agents in controlled cyber environments.

AI-augmented penetration tester and SOC analyst roles are available now, with additional cybersecu…

9 часов назад @ helpnetsecurity.com
GitHub’s ReviewBench puts AI code reviewers to the test
GitHub’s ReviewBench puts AI code reviewers to the test GitHub’s ReviewBench puts AI code reviewers to the test

GitHub’s ReviewBench measures how well AI code review tools detect problems before software is released.

Code review involves checking proposed changes for mistakes.

ReviewBench measures AI reviewers’ ability to identify issues and avoid false alarms.

It gathered candidate findings from human reviewers, follow-up code changes, analysis tools and AI models, merged findings describing the same issue, and assessed them using a shared evaluation rubric.

GitHub’s results with Copilot code reviewGitHub uses ReviewBench to evaluate changes to Copilot code review before testing them with users.

9 часов назад @ helpnetsecurity.com
Data breach at Denmark’s population register exposes 8.8 million people
Data breach at Denmark’s population register exposes 8.8 million people Data breach at Denmark’s population register exposes 8.8 million people

A data breach at Denmark’s Central Population Register (CPR) has exposed the personal information of 8.8 million people.

Over the weekend, it discovered the extent of the unauthorized access, and on Sunday, 4 October, it notified the Danish Data Protection Agency (Datatilsynet).

I have also asked for a thorough security review of the CPR system,” added Egelund.

The attackers obtained names, addresses and CPR numbers by misusing a private Danish company’s legitimate access to search the CPR system.

The Danish Data Protection Agency has opened a case and is looking into what happened, how it was able to happen, and who is responsible for the processing of the personal data involved.

9 часов назад @ helpnetsecurity.com
U.S. Bank CISO says the security role keeps growing and no one can own all of it
U.S. Bank CISO says the security role keeps growing and no one can own all of it U.S. Bank CISO says the security role keeps growing and no one can own all of it

In this interview with Help Net Security, Ann Barron-DiCamillo, EVP, CISO at U.S. Bank, talks about how the CISO role has grown to cover fraud, resilience, third-party risk, and AI governance.

The CISO role keeps absorbing adjacent territory: fraud, resilience, third-party risk, AI governance.

It makes sense that many of these responsibilities have gravitated toward the CISO because cyber risk rarely stays confined to a single domain.

They also often believe security teams are solely responsible for managing cyber risk.

Security’s role is to provide expertise, visibility, and guidance, but lasting risk reduction happens when technology, business, risk, and security teams work together.

12 часов назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 7 часов назад
Possible Vulnerability in Apple’s Automatic Reboot
Possible Vulnerability in Apple’s Automatic Reboot Possible Vulnerability in Apple’s Automatic Reboot

404Media is reporting (alternate link) that a cyber-weapons arms manufacturer is exploiting a vulnerability in iOS to bypass its automatic reboot security feature. This is the feature that automatically puts an iPhone into a more secure state if it hasn’t been used for 72 hours.

The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, a popular tool sold to law enforcement agencies that allows them to unlock and access data stored in iPhones and Android smartphones. Magnet has developed a new device called GrayKey Preserve and a feature for its regular GrayKey devices called Evidence Preservation Mode, according to the video...

7 часов назад @ schneier.com
Another Historic Cipher Falls to AI
Another Historic Cipher Falls to AI Another Historic Cipher Falls to AI

This one is from 1809, written by Napoleon’s nephew.

1 day, 7 hours назад @ schneier.com
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing
Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing Friday Squid Blogging: EU is Trying to Fight Unregulated Squid Fishing

The EU is recommending import controls to combat unregulated squid fishing in the Southwest Atlantic. I’m not optimistic.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

3 days, 21 hours назад @ schneier.com
Unidentified Flock Cameras in Florida
Unidentified Flock Cameras in Florida Unidentified Flock Cameras in Florida

St. Lucie County in Florida discovered (alt link) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not permitted.

I am reminded of the decade-old story of StingRay cell phone surveillance devices in Washington, DC, whose operators were also unknown.

My guess is that in the StingRay case, the devices were operated by foreign actors. This Flock case is more likely some local government entity that didn’t bother getting approval. Were I a foreign actor, I would rather hack the existing Flock network—like Israel ...

4 days, 4 hours назад @ schneier.com
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools
How American Political Campaigns Are Using AI—and What They’re Spending on the Tools How American Political Campaigns Are Using AI—and What They’re Spending on the Tools

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

New campaign finance disclosure data shines a light on which US political campaigns are using AI tools and how much they are spending on them.

Candidates’, parties’ and committees’ spending reveals that AI is fast becoming an essential tool of politics. The candidates themselves are quiet about how they are using the technology in their own campaigns. It’s a sensitive issue that we have been tracking closely since we started writing our book, Rewiring Democracy...

4 days, 7 hours назад @ schneier.com
Connected Cars Are a Surveillance Platform
Connected Cars Are a Surveillance Platform Connected Cars Are a Surveillance Platform

Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers:

To determine this, CR dug through thousands of pages of automakers’ privacy policies and asked questions of 15 different automakers­BMW, Ford, General Motors, Honda, Hyundai, Kia, Mazda, Mercedes-Benz, Mitsubishi, Nissan, Stellantis, Subaru, Tesla, Toyota, and Volkswagen. We also reviewed corporate, regulatory, and legal filings from data brokers operating in the “insurtech” industry­the technology companies and data brokers that help insurance companies set their rates. And we spoke to several car privacy experts, who, at industry conferences and in market re…

5 days, 7 hours назад @ schneier.com
I Want Better Reporting on AI Genie Behavior
I Want Better Reporting on AI Genie Behavior I Want Better Reporting on AI Genie Behavior

AI systems are regularly completing tasks in ways that their prompters don’t want or intend. Some of them are disturbing, and some of them are dangerous. This is something I’ve been calling “genie behavior,” because I think that really gets at the core of what’s happening.

I wish the popular press would report on this better. I don’t like the “going rogue” framing because it deflects the responsibility from the prompters—often the AI companies themselves. And now, pretty much anything off-script is being called “hacking.”

Take, for example, the recent stories of one of OpenAI’s models hacking into government systems. First, ...

6 days, 7 hours назад @ schneier.com
Using Device Linking to Eavesdrop on WhatsApp and Signal
Using Device Linking to Eavesdrop on WhatsApp and Signal Using Device Linking to Eavesdrop on WhatsApp and Signal

Modern messaging apps allow users to link their phone accounts to their computer desktop. Eavesdroppers are taking advantage of this capability:

Apps such as WhatsApp Web and Signal Desktop allow people to use their accounts on other devices, such as laptops or desktop computers.

Germany’s Customs Office has been using these features to connect a police-controlled computer to a suspect’s account.

Once connected, messages can be delivered to that computer without the police having to crack the encryption protecting them.

Netzpoltik details that police are able to gain access in this way either through physical access to someone’s phone or by intercepting verification codes via a state-sancti…

1 week назад @ schneier.com
New Attack Against RSA
New Attack Against RSA New Attack Against RSA

ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.

First, this attack isn’t new. The original research is from 2007. What is new is the implementation.

Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.

Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice.

Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with …

1 week, 1 day назад @ schneier.com
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee

I feel like someone who reads this blog will want to go to this:

Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life.

[…]

During the guided squid dissection, each family will work together to examine a squid up close, exploring its organs, structures, and specialized features. The experience provides a memorable opportunity for children and adults to see firsthand how the anatomy of a squid helps it survive in it…

1 week, 3 days назад @ schneier.com
On Anthropic’s AI Misuse Report
On Anthropic’s AI Misuse Report On Anthropic’s AI Misuse Report

Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.

A few of the highlights: AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.

The report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations.

...

1 week, 4 days назад @ schneier.com
Malicious npm Packages That Evade Defenses
Malicious npm Packages That Evade Defenses Malicious npm Packages That Evade Defenses

This is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.

1 week, 5 days назад @ schneier.com
Research on Models Engaging in Genie-Like Behavior
Research on Models Engaging in Genie-Like Behavior Research on Models Engaging in Genie-Like Behavior

New paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.”

Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be …

1 week, 6 days назад @ schneier.com
GPT-6 Astra Breaks an Old Enigma Message
GPT-6 Astra Breaks an Old Enigma Message GPT-6 Astra Breaks an Old Enigma Message

This is pretty amazing:

However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message. After trying many different approaches, GPT­6 Astra focused on using the repeated place name ROSENOW ROSENOW as a crib. After developing the necessary Python and C++ soft…

2 weeks назад @ schneier.com
Reverse-Engineering Flock Cameras
Reverse-Engineering Flock Cameras Reverse-Engineering Flock Cameras

Hackers captured a Flock camera and got a look (alternate link) at the software:

While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag...

2 weeks, 1 day назад @ schneier.com
Krebs On Security
последний пост 1 week, 1 day назад
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters.

Van der Stap is currently employed as offensive security lead at the Dutch company Neo Security, which did not respond to requests for comment.

But not long after that interview, the Dutch hacker abruptly stopped replying to messages.

One source said a colleague of theirs personally witnessed Dutch authorities carting items out of Van der Stap’s residence.

Speaking with reporters from Bloomberg in 2024, Van der Stap said that singular focus in turn fueled his desire to carry out cyberattacks.

1 week, 1 day назад @ krebsonsecurity.com
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.

Kiberphant0m claimed to have hacked into more than dozen telecommunications companies worldwide, including Verizon’s Push-to-Talk business, and publicly extorted these companies in exchange for a promise not to publish the stolen data.

Less than a month later, Wagenius was arrested and charged in two separate federal indictments, and soon pleaded guilty to all counts in both cases.

In 2019, Schuchm…

1 week, 3 days назад @ krebsonsecurity.com
Data Broker Radaris Loses Domains in Privacy Fight
Data Broker Radaris Loses Domains in Privacy Fight Data Broker Radaris Loses Domains in Privacy Fight

In February 2024, Radaris was sued by Atlas Data Privacy Corp, a company that has been pursuing data brokers alleged to be violating a New Jersey statute called Daniel’s Law.

KrebsOnSecurity doubled down and showed how the Lubarsky brothers built and operated Radaris and other data broker companies using a fictitious CEO’s name.

All told, the New Jersey court has so far transferred 14 domain names from the Radaris family of companies to Atlas.

Sherman said federal lawmakers have long faced intense lobbying by the technology industry against more restrictive U.S. data privacy laws, but that many powerful industries are now working against passing comprehensive data privacy legislation.

The l…

2 weeks, 6 days назад @ krebsonsecurity.com
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Plugs Nearly 1,000 Security Holes Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.

This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities.

Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10.

And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.

Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear…

3 weeks, 6 days назад @ krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards.

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.

Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s ide…

1 month назад @ krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

1 month, 1 week назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

1 month, 3 weeks назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

1 month, 3 weeks назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

2 months назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

2 months, 1 week назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

2 months, 2 weeks назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

2 months, 3 weeks назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

2 months, 3 weeks назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

3 months назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

3 months назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 3 days, 10 hours назад
N0n ransomware: what you need to know
N0n ransomware: what you need to know

N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. Read more in my article on the Fortra blog.

3 days, 10 hours назад @ fortra.com
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader

The FBI has a very simple message for the ShinyHunters gang: give yourselves up.

The FBI describes the man arrested in Amsterdam as "one of the alleged leaders of ShinyHunters", although Dutch police say only that he played a role.

The warning to remaining members of ShinyHunters follows particularly embarrassing episode for the FBI, which recently confirmed it had had its job application portal compromised by the gang.

According to ShinyHunters, it gained access to the FBI's data by exploiting a recently-patched flaw (CVE-2026-35273) in Oracle PeopleSoft PeopleTools.

The truth is that the arrest came a week or so before the compromise of the FBI became headline news.

5 days, 8 hours назад @ bitdefender.com
ShinyHunters suspect arrested, and is now investigated over alleged murder plots
ShinyHunters suspect arrested, and is now investigated over alleged murder plots ShinyHunters suspect arrested, and is now investigated over alleged murder plots

An alleged key figure in the ShinyHunters cybercrime group has been arrested in the Netherlands, and - in a grotesque turn - the 24-year-old suspect is also being investigated for attempting to arrange two murders.

Although the authorities are declining to name the individual, celebrated cybersecurity blogger Brian Krebs has identified him as Pepijn van der Stap, a convicted hacker.

Van der Stap was released from prison in December last year, and has since been working as a penetration tester at Amsterdam-based Neo Security.

Notably, Van der Stap appears to claim on his personal website that he is a reformed character.

That hasn't stopped FBI Director Kash Patel from describing the arrested…

5 days, 8 hours назад @ bitdefender.com
Pentagon personnel database breach exposes personal data of millions
Pentagon personnel database breach exposes personal data of millions Pentagon personnel database breach exposes personal data of millions

The unencrypted files contained Social Security numbers, names, birth dates, contact details, and other military personnel data including - in some cases - details of the jobs individuals held.

Breaches like this matter because the combination of Social Security numbers, names, and dates of birth make up the bread and butter of any self-respecting fraudster.

Personnel data, of course, has also been a target before.

The news of the Pentagon's latest data breach comes as the FBI warns its own employees about a separate breach of its FBIJobs.gov portal.

The ShinyHunters hacking group has claimed credit for the hack and threatened to publish staff details including... you guessed it... Social S…

6 days, 8 hours назад @ bitdefender.com
Ukrainian ransomware developer jailed for nearly 13 years
Ukrainian ransomware developer jailed for nearly 13 years Ukrainian ransomware developer jailed for nearly 13 years

A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world.

The 52-year-old man, who according to local media reports had been living in the Basel-Landschaft region but has not been named, found by the court to be the lead developer of the LockerGoga, MegaCortex, and Nefilim families of ransomware.

In all, prosecutors claimed that some 100 million Swiss Francs (US $123 million) worth of damage was caused by the ransomware attacks.

Ukrainian national Tymoshchuk allegedly released new strains of his ransomware whenever old ones had been decrypted.

In…

1 week, 5 days назад @ bitdefender.com
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras

Smashing Security, episode 486, Vibe-Coded Shops and Hackable Flock Cameras, with Graham Cluley and special guest Dave Bittner.

I will say I did not go gaga for La La the way many other people did.

Anyway, if any of you are still listening, I love La La Land.

This La La Land lunatic has watched the movie with his pause button.

This was definitely not created — if you haven't seen La La Land, go watch La La Land for goodness' sake.

1 week, 5 days назад @ grahamcluley.com
US Coast Guard and FBI board oil tanker to investigate cyber attack
US Coast Guard and FBI board oil tanker to investigate cyber attack US Coast Guard and FBI board oil tanker to investigate cyber attack

An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers.

The VL Prosperity - a Liberian-flagged supertanker carrying roughly 2.3 million barrels of crude oil - apparently suffered a cyber attack while en route from Egypt's Sidi Kerir oil terminal to Galveston, Texas.

Two weeks later, a specialised team from the FBI and US Coast Guard boarded the vessel for four days, investigating the problem and helping the crew eradicate the threat from its IT and OT systems.

According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromised by a f…

2 weeks, 5 days назад @ bitdefender.com
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Smashing Security podcast #485: These researchers got drunk to hack an LG TV Smashing Security podcast #485: These researchers got drunk to hack an LG TV

That's really, really cool.

And I'm going to be getting really, really sozzled by looking at the security of LG smart TVs.

So it's really, really compelling.

When we started off on the journey of building this AI pen testing approach, there was a lot of scepticism.

And listeners, you can learn more about Intruder or even start your own AI pen test in minutes.

2 weeks, 5 days назад @ grahamcluley.com
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store.

According to Carter's own plea agreement, the scam ran from May 2018 to November 2019 and involved at least three co-conspirators alongside Carter.

Carter would use his privileged store access to move a victim's number onto a SIM card under the control of himself or an accomplice.

In one incident in May 2018, described in Carter's plea agreement, the store employee swapped a victim's number onto an Alcatel handset while working his shift in Portland.

In December 2018, Carter successfully hijacked the number of a victim known as "S.Q.T" in Portland, and this time their account was successfully drained of …

3 weeks назад @ bitdefender.com
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars ‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.

Because it might just be that you draw the attention of the authorities.

Back in October 2024, we wrote about how he was arrested after allegedly tricking a single victim out of US $230 million worth of Bitcoin while posing as Google Support.

The party days are over now for Lam, who faces up to 20 years in prison when he is eventually sentenced.

You money may be a lot more safely stored in a hardware cold wallet.

3 weeks, 5 days назад @ bitdefender.com
Smashing Security podcast #484: How websites are tracking you with silence
Smashing Security podcast #484: How websites are tracking you with silence Smashing Security podcast #484: How websites are tracking you with silence

Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.

I get by in the world, but I don't think you need me for listening for something really, really far away.

I don't know what the difference — I mean, now we get to see, I've opened a can of worms here.

I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human.

And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.

3 weeks, 5 days назад @ grahamcluley.com
CRPx0 ransomware: what you need to know
CRPx0 ransomware: what you need to know

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

3 weeks, 6 days назад @ fortra.com
The US military just turned off ad tracking on its phones. Maybe you should too
The US military just turned off ad tracking on its phones. Maybe you should too The US military just turned off ad tracking on its phones. Maybe you should too

Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target American forces in the Middle East.

Every smartphone carries a mobile advertising ID - Apple calls its version the IDFA, and Google calls its the GAID.

Back in April, US Central Command reportedly warned of "multiple threat reports concerning adversary exploitation of commercial location data."

Recent versions should let you delete your advertising ID entirely.

If it's good enough for the US military - maybe it should be good enough for you too.

4 weeks назад @ bitdefender.com
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo's own identity system, Lenovo ID.

So, anyone wanting to access your Dropbox account just had to sign up for a Lenovo account using your email address.

Don't just turn it on for your Dropbox account, enable it everywhere it is made available.

This hack of 5000 Dropbox accounts was not sophisticated.

One can only be grateful that the problem was discovered after only 5000 Dropbox accounts were accessed.

4 weeks, 1 day назад @ bitdefender.com
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Smashing Security podcast #483: This AI helps thieves steal your iPhone Smashing Security podcast #483: This AI helps thieves steal your iPhone

This AI helps thieves steal your iPhone with Graham Cluley and special guest James Ball.

You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first one.

Is it normal that some kid just flogs it down the pub, or is there something more organised actually going on?

So the researchers said they saw evidence of hundreds of these Apple phone calls trying to phish the numbers and the passcodes from people trying to steal iPhones.

Follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts.

1 month назад @ grahamcluley.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 4 days, 1 hour назад
GTA 6 до релиза: фейковые утечки, ранний доступ и мошенничество | Блог Касперского
GTA 6 до релиза: фейковые утечки, ранний доступ и мошенничество | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 057a7a4758cd6ae7dfaab62417ac8d97Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-10-02T21:00:25+03:00Config id: 335Faithfully yours, nginx.

4 days, 1 hour назад @ kaspersky.ru
Как закрыть 110 уязвимостей в Google Pixel | Блог Касперского
Как закрыть 110 уязвимостей в Google Pixel | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8ea67ee2a3dd4315782e49963c8d5485Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-30T17:00:35+03:00Config id: 334Faithfully yours, nginx.

6 days, 5 hours назад @ kaspersky.ru
Как сканер уязвимостей создает иллюзию защиты | Блог Касперского
Как сканер уязвимостей создает иллюзию защиты | Блог Касперского Как сканер уязвимостей создает иллюзию защиты | Блог Касперского

Эти процессы могут тянуться неделями, а тем временем в инфраструктуру легко может попасть злоумышленник.

Где теряется времяПервое промедление может произойти сразу после появления информации об уязвимости в базах данных.

Рецепт управления уязвимостямиЧтобы у злоумышленников было как можно меньше поводов заглянуть к вам в инфраструктуру, важно убедиться, что в организации четко выстроены четыре основных процесса.

ПриоритизацияПри анализе уязвимости не стоит ориентироваться только на оценку из публичного каталога, например NVD, — она может существенно расходиться с реальным ущербом от эксплуатации бреши.

Например, один и тот же дефект в сервере, который находится в изолированном сегменте, и в…

6 days, 23 hours назад @ kaspersky.ru
Бесплатный курс «Введение в кибербезопасность» для студентов вузов от экспертов «Лаборатории Касперского» | Блог Касперского
Бесплатный курс «Введение в кибербезопасность» для студентов вузов от экспертов «Лаборатории Касперского» | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7dfac78cb3fca5a112c9b371cb1af0ecServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-29T14:00:43+03:00Config id: 307Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
CVE-2026-87902: критическая уязвимость в WordPress
CVE-2026-87902: критическая уязвимость в WordPress

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 3ba3f53e4698eed730b59fdbb57f2dc7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-25T19:00:33+03:00Config id: 307Faithfully yours, nginx.

1 week, 4 days назад @ kaspersky.ru
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского
Токеномика ИБ: атаки Denial of Wallet | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: cdfce2802c5089c2e8d266eed059c5ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-23T18:00:08+03:00Config id: 307Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского
Как скрытый SSID сети Wi-Fi выдает ваши данные посторонним | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 8bdccf89e0ff9374b4a240e13e1d1e5dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-22T14:00:25+03:00Config id: 307Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского
Фишинг на выборах: поддельное онлайн-голосование и опросы с призами | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: afb32d9b2ad2a9d051087c355f39881eServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-18T19:00:38+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 4 days назад @ kaspersky.ru
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского
Вредоносные плагины Chrome и Edge: как их обнаружить и чем они опасны | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: c7185cbdbdeda88817088ebb8613e249Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-17T16:00:24+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 5 days назад @ kaspersky.ru
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского
Фишинг через облачные платформы: как злоумышленники обходят многофакторную аутентификацию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64b9740d8f9a94da6c64f21f2aeee15dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-16T19:00:10+03:00Config id: 305Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского
Защищаем умный телевизор и телеприставку от взлома | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7e59b8e02f76cd9405fa38b4fdc32a36Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-15T11:00:04+03:00Config id: 305Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Как полностью удалить приложения с Mac и освободить память | Блог Касперского
Как полностью удалить приложения с Mac и освободить память | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a6459fd9158393152b55dc4e20e24551Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T15:00:13+03:00Config id: 305Faithfully yours, nginx.

3 weeks, 6 days назад @ kaspersky.ru
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4a93349074c8b67d52892db5d9a65f6cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T00:00:19+03:00Config id: 305Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
GPUThor: развитие идеи Rowhammer | Блог Касперского
GPUThor: развитие идеи Rowhammer | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fe21d0ffcbad967d20a3f98f7234d02fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-08T00:00:32+03:00Config id: 304Faithfully yours, nginx.

4 weeks назад @ kaspersky.ru
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e393e4abb05ec4aac16fd484bfccc656Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-04T18:00:18+03:00Config id: 304Faithfully yours, nginx.

1 month назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 1 week, 1 day назад
Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era
Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era Beyond the Box: Future-Proofing Branch Firewall Security for the AI Era

The Cisco Secure Firewall 200 Series brings enterprise-grade protection and connectivity to distributed branches in a compact form factor.

The Encrypted Visibility Engine (EVE) uses AI and machine learning to analyze encrypted traffic, including TLS 1.3, without requiring full decryption.

The Secure Firewall 220 model delivers up to 1.5 Gbps of throughput with next-generation firewall capabilities enabled in a compact form factor for smaller branches.

The Secure Firewall 200 Series helps meet these demands with intelligent threat protection, encrypted traffic visibility, resilient connectivity, and centralized management.

Explore the Secure Firewall 200 Series to build a more resilient, man…

1 week, 1 day назад @ blogs.cisco.com
From Love Letters to AI Agents: Cybersecurity’s Evolution
From Love Letters to AI Agents: Cybersecurity’s Evolution From Love Letters to AI Agents: Cybersecurity’s Evolution

Architecting the Future: The Four Pillars of Agentic SecuritySecuring agentic AI requires a new strategic framework.

Pillar 2: Core ProtectionDelivered by: Cisco AI DefenseCisco AI Defense provides specialized protection for the AI models themselves and their operational environment.

AI Inventory & Validation: This solution catalogs all deployed AI models and continuously validates their integrity against supply chain risks.

Pillar 4: ObservabilityDelivered by: SplunkSplunk provides the unified intelligence platform required to monitor and respond to agentic AI at scale.

Splunk ingests logs, events, and telemetry from Duo, Secure Access, AI Defense, and other infrastructure points, creating…

2 weeks, 1 day назад @ blogs.cisco.com
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco was proud to return to Black Hat USA as the Official Security Cloud Provider and the longest-standing partner of the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC).

In 2026, we completed our 11th year helping protect the Black Hat network, working side by side with the Black Hat NOC leaders and official technology partners: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.

For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry and workflows across Cisco Security, Splunk Security, and partner-provided network and security controls.

The same signal may need to be understood by Cisco, Splunk, Black Hat leadership, and partner tea…

4 weeks, 1 day назад @ blogs.cisco.com
Thrown into the SOC: A Black Hat First-Timer’s Story
Thrown into the SOC: A Black Hat First-Timer’s Story Thrown into the SOC: A Black Hat First-Timer’s Story

I did not walk into Black Hat with years of incident-response experience or an encyclopedic knowledge of threat actors.

The first time I walked into the Black Hat NOC, where the SOC team was operating, was a few days before the event began.

I was surrounded by people with years—sometimes decades—of experience, many of whom had supported Black Hat for years.

Check out the other blogs from our team at Black Hat USA 2026.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

4 weeks, 1 day назад @ blogs.cisco.com
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes

To handle this task, Cisco and Black Hat deployed bespoke ThousandEyes agents to monitor the wireless solution.

Our thanks to the Arista Networks team in the Black Hat NOC for their partnership throughout the week.

You can read the other blogs from our colleagues at Black Hat USA.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

For more information, please visit the Black Hat website.

4 weeks, 1 day назад @ blogs.cisco.com
Distributed Latency Monitoring at Black Hat
Distributed Latency Monitoring at Black Hat Distributed Latency Monitoring at Black Hat

With Matthew Bair2026 marks the fourth consecutive year we’ve used ThousandEyes to monitor the Black Hat USA network for latency.

As our latency monitoring mesh has expanded to cover more and more of the conference, we’ve also begun supplementing our ThousandEyes monitoring with on-demand Linux commands to track latency across different protocols.

The Key ThousandEyes TestsThe automated ThousandEyes tests that inform our dashboards include HTTPS connectivity tests, the monitoring of cloud services, agent to agent tests, internal and external DNS resolution, and even file downloads.

On-Demand Latency Tests from the Agent MeshPing and traceroute are the go-tos for anyone who wants to do a qui…

4 weeks, 1 day назад @ blogs.cisco.com
Black Hat USA 2026: Safeguarding DNS with Secure Access
Black Hat USA 2026: Safeguarding DNS with Secure Access Black Hat USA 2026: Safeguarding DNS with Secure Access

DNS continues to provide one of the clearest windows into activity across the Black Hat network.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking.

Its 4.42 million blocks represented 79.3% of every blocked DNS request .. Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and mo…

4 weeks, 1 day назад @ blogs.cisco.com
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

While developing a detection for Cisco Secure Network Analytics (SNA), I used the Splunk Detection Editor (Alpha) to bring much of that workflow into one place.

Instead of treating every observation as an incident, detections can create risk events associated with entities such as systems or users.

Developing the detection in one workspaceThe Detection Editor provides a workspace for building the search while configuring the other parts of the detection.

Risk events for the same entity need to use a consistent risk object so Splunk Enterprise Security can associate them correctly.

Splunk defines the risk object, its type, and its score as key parts of a risk event.

4 weeks, 1 day назад @ blogs.cisco.com
Frontier AI just raised the stakes, and the old playbook won’t hold up
Frontier AI just raised the stakes, and the old playbook won’t hold up Frontier AI just raised the stakes, and the old playbook won’t hold up

Project Glasswing and Frontier models just made that truth louder.

Frontier models are about to pour gasoline on that fire; the fundamentals matter more than ever.

Cisco ran its own experiment leveraging a variety of frontier models.

Foundry Security Spec: a model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

Foundry-Security-Speca model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

1 month назад @ blogs.cisco.com
Crypto Agility: Why PQC Is Not a One-Time Upgrade
Crypto Agility: Why PQC Is Not a One-Time Upgrade Crypto Agility: Why PQC Is Not a One-Time Upgrade

That requires crypto agility.

Why long-lived networks need crypto agilityThink about designing a building before all of its future electrical requirements are known.

Crypto agility is about adopting the best defenses available today while preserving the ability to adopt better ones tomorrow.

That is why crypto agility needs to be designed into the network we invest in today.

Common questions about PQC and crypto agilityWhat is crypto agility?

1 month назад @ blogs.cisco.com
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

It is what happens when agents built by different teams, on different platforms, can hand work to each other directly.

And it is worth being direct about where things stand: A2A-mediated handoffs between production security agents are not shipping anywhere yet.

Use A2A when one agent needs to hand work to another.

A2A is peer-to-peer: any A2A agent can discover and call any other A2A agent through a self-published Agent Card, no custom connector required, and the receiving agent applies its own reasoning rather than following a static script.

Input validation is an application-layer responsibility that needs to be designed in before any agent delegates via A2A, not added after.

1 month, 1 week назад @ blogs.cisco.com
Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
Microsegmentation’s Moment Is Now:  Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind SpotsApplications increasingly span private clouds, on-premises data centers, and public clouds.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026…

1 month, 1 week назад @ blogs.cisco.com
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

What We Mean by Infrastructure IdentityInfrastructure Identity starts with a simple principle: there should be no anonymous computing in critical infrastructure.

Infrastructure Identity turns that principle into an operating model.

Infrastructure Identity starts with the actor and evaluates whether a specific action should be allowed now.

Infrastructure Identity is therefore not just an access-control issue.

That is the promise of Infrastructure Identity: no anonymous computing, no unmanaged privilege, and no forced tradeoff between stronger security and operational speed.

1 month, 1 week назад @ blogs.cisco.com
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE

I’m proud to share that IDC MarketScape has named Cisco a Leader in the 2026 IDC MarketScape: Worldwide Secure Access Service Edge (SASE) Vendor Assessment.

In an evaluation of 12 SASE vendors, the IDC MarketScape recognized our architectural breadth and flexibility, AI capabilities, identity integration, threat visibility, and R&D.

Built to Make Agent Work, WorkWe believe the IDC MarketScape recognition validates the foundation we have built, and customers increasingly need that foundation for what is next.

For more on Cisco’s placement as a Leader, read the IDC MarketScape excerpt and explore how Cisco SASE keeps work moving, governed, and trusted in the AI era at cisco.com/go/sase.

Stay …

1 month, 1 week назад @ blogs.cisco.com
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

1 month, 2 weeks назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 2 часа назад
CISO perspectives on managing vulnerability risks in the age of AI
CISO perspectives on managing vulnerability risks in the age of AI CISO perspectives on managing vulnerability risks in the age of AI

How do frontier AI models change vulnerability management for CISOs?

We use a ‘harness’ layer around AI models in vulnerability scanning for better results.

They should do so without delay, rather than wait for access to frontier AI models.

Extensive guidance can be found in a new Microsoft Security Exposure Management page with capabilities customers can use to act.

Final notesThe advent of frontier AI models to discover and exploit vulnerabilities creates both risks and opportunities.

2 часа назад @ microsoft.com
Preparing governments for an era of interconnected cyber risk
Preparing governments for an era of interconnected cyber risk Preparing governments for an era of interconnected cyber risk

Trusted channels can enable this exchange among government agencies, law enforcement, critical infrastructure operators, technology providers, and international partners while respecting legal and privacy requirements.

As cyber incidents cross organizational and national boundaries, resilience depends not only on technical preparedness, but on whether institutions can coordinate effectively under pressure.

In an era of AI-enabled and increasingly interconnected cyber threats, resilience is no longer simply about recovering from an attack.

It is about preparing for a world in which cyber incidents move faster, spread further, and affect more organizations than ever before.

Governments best p…

5 days, 4 hours назад @ blogs.microsoft.com
Insights from the 2026 Microsoft Digital Defense Report
Insights from the 2026 Microsoft Digital Defense Report Insights from the 2026 Microsoft Digital Defense Report

Every year, the Microsoft Digital Defense Report gives us an opportunity to step back from individual threats and look broadly at what Microsoft’s security and threat intelligence teams are seeing.

These developments can change the speed and scale of security activity even as the underlying security fundamentals remain familiar.

People, identities, exposed systems, and trusted access continue to feature prominently in the threat activity Microsoft observes.

The 2026 Microsoft Digital Defense Report looks across the threat landscape, cybercrime, resilience, and the relationships among technologies, identities, systems, and people.

Read the 2026 Digital Defense Report for the full findings, d…

5 days, 4 hours назад @ microsoft.com
​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 ​​Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026

Join fellow customers and Microsoft Security leaders for a night designed to make meaningful connections.

Partners and the Microsoft Intelligent Security AssociationMicrosoft Intelligent Security Association (MISA) members have a full week ahead at Microsoft Ignite.

Sessions to watch forWhen AI acts, security has to answer: Microsoft Security for AI , the platform view of securing agentic AI.

Strengthen and Manage Data Security Posture with Microsoft Purview , on data security posture management in practice.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

5 days, 23 hours назад @ microsoft.com
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570

The operators first validated command execution using lightweight out-of-band probes to unique subdomains hosted on public interaction and collaborator services, including oast[.

When a service-state change triggers health monitoring, swatchdog incorporates the attacker-controlled value into a snmptrap shell invocation, enabling command execution.

Exploitation of the Zimbra vulnerability provided attackers with direct command execution as the zimbra service account.

Attackers also used the initial command execution to download and execute content directly through wget or curl, launch background processes, and establish interactive reverse shells.

Command and controlThe actor used HTTP and H…

6 days, 4 hours назад @ microsoft.com
Phishing Abuses RMM Tools for Persistent Access
Phishing Abuses RMM Tools for Persistent Access Phishing Abuses RMM Tools for Persistent Access

Attack chain showing phishing delivering a masqueraded MSP360 RMM installer that deploys ScreenConnect for persistent remote access and follow-on activity.

Initial Access: Phishing Campaign Delivering Masqueraded MSP360 RMM InstallerMicrosoft observed multiple phishing campaigns that used a multi-stage delivery chain to distribute legitimate, digitally signed MSP360 RMM software (v2.5.0.67).

Analysis of downloaded samples showed that many ultimately contained the same MSP360 RMM installer package despite appearing as different files to the victim.

Command and ControlT1219 Remote Access Software | The threat actor abused legitimate remote administration software including MSP360 RMM and Conn…

6 days, 21 hours назад @ microsoft.com
​​Beyond source code: A path to the keys to the kingdom
​​Beyond source code: A path to the keys to the kingdom ​​Beyond source code: A path to the keys to the kingdom

By mapping trusted deployment paths and connected resources, the threat actor was able to identify opportunities to expand beyond the initial compromise.

In addition to deploying a kube agent, the threat actor modified pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility.

The threat actor added seven stolen kubeconfig files to a repository, providing the credentials needed to access targeted Kubernetes clusters.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

1 week назад @ microsoft.com
Star Blizzard refines phishing and malware delivery with the RedFlick technique
Star Blizzard refines phishing and malware delivery with the RedFlick technique Star Blizzard refines phishing and malware delivery with the RedFlick technique

In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns.

June 2026 RedFlick campaign follow-up email with the subject line “Invitation to the Chatham House London Conference 2026”Figure 3.

Persistence through multiple scheduled tasksIn April 2026, Microsoft observed Star Blizzard changing persistence tactics to include RedFlick scheduled tasks.

Defending against Star Blizzard and RedFlick-related activityMicrosoft Threat Intelligence advises organizations that are most likely at risk—primarily those in government, NGOs, or think tanks adjacent to Ukraine policy or support—to implement the followin…

1 week назад @ microsoft.com
Star Blizzard refines phishing and malware delivery with the RedFlick technique
Star Blizzard refines phishing and malware delivery with the RedFlick technique Star Blizzard refines phishing and malware delivery with the RedFlick technique

In 2026, Microsoft observed Star Blizzard shift from exclusively targeted spear-phishing operations to also conducting larger-scale phishing campaigns.

June 2026 RedFlick campaign follow-up email with the subject line “Invitation to the Chatham House London Conference 2026”Figure 3.

Persistence through multiple scheduled tasksIn April 2026, Microsoft observed Star Blizzard changing persistence tactics to include RedFlick scheduled tasks.

Defending against Star Blizzard and RedFlick-related activityMicrosoft Threat Intelligence advises organizations that are most likely at risk—primarily those in government, NGOs, or think tanks adjacent to Ukraine policy or support—to implement the followin…

1 week назад @ microsoft.com
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted operations affecting telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors.

Microsoft has observed additional NeedyMantis activity beyond Storm-3069’s activity in the DAEMON Tools campaign, indicating that the malware might be used by more than one operator.

Indicators of compromiseIndicator Type Description First seen Last seen e842dd7642c8e04b5ec20b6393848a9c904e4832930950c16664fe7800ba382e SHA-256 First-stage loader WinSparkle.dll 2026-05-21 2026-05-21 9cb68f986043a576e19d32184…

1 week, 1 day назад @ microsoft.com
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Storm-3168: Agentic-driven cloud attacks using compromised service principals Storm-3168: Agentic-driven cloud attacks using compromised service principals

About 90 minutes after the first compromised service principal started enumeration, the second compromised service principal enumerated virtual machines and resource groups across two subscriptions in five seconds.

16 hours later, the second service principal successfully enumerated Azure App Service configuration stores, possibly looking for exposed credentials.

This compromised service principal then attempted 150+ destructive or credential collection related operations in 35 minutes.

T1078.004 Valid Accounts: Cloud Accounts | Compromised service principals were used for Azure resource discovery and destruction.

To hear stories and insights from the Microsoft Threat Intelligence community…

1 week, 4 days назад @ microsoft.com
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Storm-3168: Agentic-driven cloud attacks using compromised service principals Storm-3168: Agentic-driven cloud attacks using compromised service principals

About 90 minutes after the first compromised service principal started enumeration, the second compromised service principal enumerated virtual machines and resource groups across two subscriptions in five seconds.

16 hours later, the second service principal successfully enumerated Azure App Service configuration stores, possibly looking for exposed credentials.

This compromised service principal then attempted 150+ destructive or credential collection related operations in 35 minutes.

T1078.004 Valid Accounts: Cloud Accounts | Compromised service principals were used for Azure resource discovery and destruction.

To hear stories and insights from the Microsoft Threat Intelligence community…

1 week, 4 days назад @ microsoft.com
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.

As a result, organizations could encounter the same actor, tools, and intrusion methods despite different ransomware payloads being deployed.

Storm-2570 uses a diverse set of remote access tools rather than relying on a single capability.

This type of tunnel can help bypass inbound firewall restrictions and provide covert remote access for follow-on activity.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat …

1 week, 5 days назад @ microsoft.com
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware.

As a result, organizations could encounter the same actor, tools, and intrusion methods despite different ransomware payloads being deployed.

Storm-2570 uses a diverse set of remote access tools rather than relying on a single capability.

This type of tunnel can help bypass inbound firewall restrictions and provide covert remote access for follow-on activity.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat …

1 week, 5 days назад @ microsoft.com
​​​​​​​​What’s new in Microsoft Security: September 2026​​
​​​​​​​​What’s new in Microsoft Security: September 2026​​ ​​​​​​​​What’s new in Microsoft Security: September 2026​​

Here’s what’s new:Extend protection and support investigations with Microsoft DefenderBring more context into email investigation and hunting with Microsoft Security CopilotAvailable for organizations using both Microsoft Defender and Microsoft Security Copilot, a new email detonation summary delivers AI-generated explanations of URL and file sandboxing results, helping SOC teams investigate faster by reducing the manual effort required to correlate detonation evidence and contextual signals.

Protect sensitive data in motion with Microsoft Purview and Microsoft EntraStop sensitive data from reaching shadow AI over the networkNow generally available, Microsoft Purview and Microsoft Entra Glo…

1 week, 5 days назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 5 months, 2 weeks назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

5 months, 2 weeks назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

5 months, 4 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

6 months назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

6 months, 1 week назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

6 months, 1 week назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

6 months, 2 weeks назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

7 months, 1 week назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

7 months, 1 week назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

7 months, 2 weeks назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

8 months, 1 week назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

9 months, 4 weeks назад @ security.googleblog.com