Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 2 часа назад
В космосе нашли новый класс источников, который десятилетиями выпадал из обзоров
В космосе нашли новый класс источников, который десятилетиями выпадал из обзоров В космосе нашли новый класс источников, который десятилетиями выпадал из обзоров

За границей 0,3 кэВ скрывался неизвестный космический мир.

32 минуты назад @ securitylab.ru
ИИ стал ближе к пониманию человеческого намерения
ИИ стал ближе к пониманию человеческого намерения

Подход с ЭЭГ помогает точнее отделять реальные цели человека от двусмысленных действий и случайных сигналов.

57 минут назад @ securitylab.ru
Космическую броню построили по форме яйца и наполнили водой
Космическую броню построили по форме яйца и наполнили водой Космическую броню построили по форме яйца и наполнили водой

Природная геометрия неожиданно выиграла у привычной защиты.

2 часа назад @ securitylab.ru
«Канцлер», «Шеф» и сотни колл-центров. НАБУ раскручивает дело «Карфаген»
«Канцлер», «Шеф» и сотни колл-центров. НАБУ раскручивает дело «Карфаген»

Генпрокурор Украины Руслан Кравченко подал заявление об отставке после дела о предполагаемой защите мошеннических офисов его подчинёнными.

3 часа назад @ securitylab.ru
Chrome снова атакуют через V8. Google закрыла седьмой zero-day за год
Chrome снова атакуют через V8. Google закрыла седьмой zero-day за год

Для запуска достаточно специально подготовленной веб-страницы.

3 часа назад @ securitylab.ru
«Белые» оказались не совсем блефом. В Liquid Network вернули $263 млн
«Белые» оказались не совсем блефом. В Liquid Network вернули $263 млн «Белые» оказались не совсем блефом. В Liquid Network вернули $263 млн

После крупнейшего криптовзлома 2026 года обратно пришли 3400 BTC, но ещё $47 млн остаются у хакеров.

4 часа назад @ securitylab.ru
GPT-6 Astra уже бьёт по стоимости традиционного софта
GPT-6 Astra уже бьёт по стоимости традиционного софта

Один новый релиз заставил Уолл-стрит по-другому смотреть на SaaS.

4 часа назад @ securitylab.ru
Сисадмин нажал Enter, система записала: контроль СОРМ станет жестче
Сисадмин нажал Enter, система записала: контроль СОРМ станет жестче

Минцифры предлагает с марта 2027 года фиксировать команды, изменения конфигурации, установку программ и другие операции персонала.

5 часов назад @ securitylab.ru
Управление ИБ без хаоса: как выстроить процессы и не утонуть
Управление ИБ без хаоса: как выстроить процессы и не утонуть

16 сентября компания iCore проведёт вебинар «Управление ИБ без хаоса: как выстроить процессы и не утонуть».

5 часов назад @ securitylab.ru
Смарт-контракт надо тестировать от имени врага. OWASP поставила контроль доступа на первое место
Смарт-контракт надо тестировать от имени врага. OWASP поставила контроль доступа на первое место Смарт-контракт надо тестировать от имени врага. OWASP поставила контроль доступа на первое место

Обычные проверки бесполезны там, где никто не пытается сделать то, чего ему не разрешали.

6 часов назад @ securitylab.ru
ИИ-чипы стали слишком большими даже для новой литографии ASML
ИИ-чипы стали слишком большими даже для новой литографии ASML

ИИ-ускорители заставляют полупроводниковую отрасль менять стандарт фотошаблонов.

6 часов назад @ securitylab.ru
Цифровой суверенитет перестал быть политическим лозунгом. Компании посчитали, сколько месяцев проживут без Microsoft, AWS или другого критического поставщика
Цифровой суверенитет перестал быть политическим лозунгом. Компании посчитали, сколько месяцев проживут без Microsoft, AWS или другого критического поставщика

Советы директоров обнаружили зависимости, о которых раньше почти не думали.

7 часов назад @ securitylab.ru
Вселенная оказалась слишком прозрачной для частицы чудовищной энергии
Вселенная оказалась слишком прозрачной для частицы чудовищной энергии

Фотон на 300 ТэВ не должен был долететь до Земли. Возможно, виновата квантовая гравитация.

7 часов назад @ securitylab.ru
X-59 прошёл 25 полётов. Теперь NASA проверит, можно ли сделать сверхзвук тихим
X-59 прошёл 25 полётов. Теперь NASA проверит, можно ли сделать сверхзвук тихим

Concorde гремел, X-59 должен шептать.

8 часов назад @ securitylab.ru
Можно ли украсть нейросеть через её ответы? США говорят, что Китай делает это массово
Можно ли украсть нейросеть через её ответы? США говорят, что Китай делает это массово

Шесть компаний якобы собрали миллиарды токенов из Claude, GPT, Gemini и Grok.

17 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 22 часа назад
Корпоративный ИИ в России: от экспериментов к агентам
Корпоративный ИИ в России: от экспериментов к агентам Корпоративный ИИ в России: от экспериментов к агентам

Где ИИ применяют и считают эффективнымПо данным исследования, чаще всего ИИ применяют в контакт-центрах и службах поддержки — об этом сообщили 75% опрошенных компаний.

«В страховых компаниях, — поясняет он, — инвестиционный анализ раньше требовал дорогих специалистов, которые умели и разбираться в ситуации, и доходчиво объяснять происходящее.

По его словам, проблема не только в процессах и данных, но и в том, как измерить сам результат.

Поэтому основная сложность заключается не только в запуске пилота, но и в его доведении до промышленной эксплуатации.

Полностью автономные решения (без участия человека) внедряют 25% компаний — но в проде они задействованы только у 8%.

22 часа назад @ anti-malware.ru
Как выбрать российский NGFW в 2026 году: тренды, критерии и прогнозы
Как выбрать российский NGFW в 2026 году: тренды, критерии и прогнозы Как выбрать российский NGFW в 2026 году: тренды, критерии и прогнозы

В любом случае российское решение отличается от западного — есть небольшие отличия в инфраструктуре и в подходах.

Виталий Беличко добавил, что в прошлом году все вендоры бурно наращивали функциональность, но следующим этапом стала проработка деталей.

Это и тренд, и много маркетинга в это вкладывается».

Мы обрабатываем эти данные в KSN и передаём их во все продукты, которые к нему подключены, в том числе и в NGFW.

ВыводыРынок российских NGFW в 2026 году прошёл этап становления и вступает в фазу зрелой конкуренции.

2 days, 2 hours назад @ anti-malware.ru
Как Томск стал центром кибербезопасности и что меняет приказ ФСТЭК № 117: форум «КиберV» 2026
Как Томск стал центром кибербезопасности и что меняет приказ ФСТЭК № 117: форум «КиберV» 2026 Как Томск стал центром кибербезопасности и что меняет приказ ФСТЭК № 117: форум «КиберV» 2026

Обсудили как региональные компании выходят на федеральный рынок, где искать специалистов и что меняется в ИБ с развитием ИИ.

Чтобы посмотреть, как сегодня устроена кибербезопасность за пределами столицы, команда AM Live также отправилась в Томск и посетила пятый юбилейный форум по кибербезопасности «КиберV».

Юбилейный форум «КиберV» собрал команды и компании, которые в обычной работе могут решать совершенно разные задачи, но в вопросах кибербезопасности оказываются по одну сторону.

Представитель ФСТЭК ответил на вопросы участников и отдельно подчеркнул, что не стоит заранее пугать себя новыми требованиями.

Мы пересматриваем информационные потоки, подходы к созданию новых информационных сист…

2 days, 5 hours назад @ anti-malware.ru
Обзор Kaspersky Secure Mail Gateway 3.1, шлюза защиты корпоративной электронной почты
Обзор Kaspersky Secure Mail Gateway 3.1, шлюза защиты корпоративной электронной почты Обзор Kaspersky Secure Mail Gateway 3.1, шлюза защиты корпоративной электронной почты

Kaspersky Secure Mail Gateway (KSMG) — полностью интегрированное решение, объединяющее систему электронной почты и средства её защиты в составе готового к использованию виртуального устройства безопасности.

Добавление маршрута в Kaspersky Secure Mail Gateway 3.1Функция полезна, например, если сообщения разных подразделений или сервисов должны проходить через отдельные шлюзы.

Подключение к LDAP-серверам в Kaspersky Secure Mail Gateway 3.1Функциональные возможности Kaspersky Secure Mail Gateway 3.1На текущий момент управление возможностями осуществляется через веб-консоль.

Создание учётной записи в Kaspersky Secure Mail Gateway 3.1Рисунок 23.

Применение Kaspersky Secure Mail Gateway 3.1Решени…

2 days, 6 hours назад @ anti-malware.ru
Бесплатные ИИ-роутеры: как они работают и можно ли проверить модель
Бесплатные ИИ-роутеры: как они работают и можно ли проверить модель Бесплатные ИИ-роутеры: как они работают и можно ли проверить модель

Разбираемся, что происходит с запросом у посредника, можно ли проверить фактическую модель и на что смотреть российскому разработчику.

Например, в ответе и журналах OpenRouter можно увидеть названия модели и провайдера, который обслужил конкретный запрос.

Как проверить, какая модель отвечает на запросАбсолютно надёжного «паспорта модели» на стороне клиента обычно нет.

Сервис должен показывать фактическую модель и, по возможности, провайдера для каждого запроса, а также позволять управлять резервными маршрутами.

Нужно выяснить, сохраняются ли промпты и ответы, каков срок хранения, используются ли данные для аналитики или обучения и можно ли ограничить передачу отдельным провайдерам.

2 days, 21 hours назад @ anti-malware.ru
Бота не нужно блокировать — его нужно разорить
Бота не нужно блокировать — его нужно разорить Бота не нужно блокировать — его нужно разорить

Разбираем, из чего складывается стоимость скрейпинга, СМС-бомбинга, credential stuffing и LLM-ботов и как подобрать меры защиты, не мешая легитимным пользователям.

В деньгах кажется, что это почти ничего не стоит.

Но благодаря LLM, боты научились смотреть на страницу и понимать, что на ней происходит.

Он подстраивается под изменения, которые раньше его убивали, и пишет тексты (отзывы, заявки, сообщения в поддержку) не хуже, чем человек.

Главное: чем дешевле становится создание ботов и чем быстрее они умнеют, тем важнее защищаться не от конкретного скрипта, а от самой автоматизации.

3 days назад @ anti-malware.ru
Приказ № 270 Минцифры: как наладить эффективное сотрудничество ИТ-компаний и вузов
Приказ № 270 Минцифры: как наладить эффективное сотрудничество ИТ-компаний и вузов Приказ № 270 Минцифры: как наладить эффективное сотрудничество ИТ-компаний и вузов

Проблемами вузов остаются слабая материальная база и отсутствие доступа к российскому ПО и отечественному оборудованию.

Для их оценки в приказе предлагается использовать два подхода: по методике, изложенной в самом документе, и по фактическим затратам.

Как унифицировать требования вуза и Минцифры к трудоустройству сотрудников, чтобы сократить объём документов и согласований.

Также представитель ОмГТУ обратил внимание на то, что у вузов, которые сотрудничают с индустриальными партнёрами, появляется необходимость регулярно отправлять отчёты в Минцифры.

ВыводыИсполнение норм приказа № 270 Минцифры потребует довольно серьёзных усилий как от ИТ-компаний, так и от вузов.

6 days назад @ anti-malware.ru
Экономика кибербезопасности: предотвращать инциденты и управлять последствиями
Экономика кибербезопасности: предотвращать инциденты и управлять последствиями Экономика кибербезопасности: предотвращать инциденты и управлять последствиями

Допустим, на это отводится месяц и ограниченный бюджет.

Экстренное привлечение сторонних специалистов по кибербезопасности — часто по повышенным тарифам и без возможности выбрать оптимального подрядчика.

Презумпция взлома подразумевает ориентацию на факты, а не на формальное соответствие.

Но с их помощью обычно получается понять, как должно быть, а не как есть на самом деле.

Аналитики собирают актуальные и ретроспективные данные внутри инфраструктуры и во внешних источниках, проводят автоматизированный и ручной анализ, оценивают критичность инцидентов и расследуют выявленные атаки.

6 days, 20 hours назад @ anti-malware.ru
Битва алгоритмов: как ИИ меняет правила найма и поиска работы в 2026 году
Битва алгоритмов: как ИИ меняет правила найма и поиска работы в 2026 году Битва алгоритмов: как ИИ меняет правила найма и поиска работы в 2026 году

В 2026 году ИИ оказался по обе стороны найма: алгоритмы помогают компаниям оценивать кандидатов, а соискателям — готовиться к этой оценке.

Такая же формулировка встречается и в обсуждениях у других участников рынка.

В одном случае на массовые позиции приходит до 700 резюме в неделю, на узкоспециализированные и руководящие — около 100.

Например, работодатель может с помощью ГигаЧата или Gemini подготовить тестовое задание, а кандидат с помощью того же инструмента его выполнить.

Результаты опроса К2Тех по использованию ИИ в HR-процессахРиски для соискателяК рискам и барьерам мы бы отнесли те же, что при использовании ИИ в повседневных задачах.

6 days, 22 hours назад @ anti-malware.ru
Защита данных в 2026 году: почему DLP-системы перестают быть универсальным решением
Защита данных в 2026 году: почему DLP-системы перестают быть универсальным решением Защита данных в 2026 году: почему DLP-системы перестают быть универсальным решением

Даниил Бориславский согласился, что это синергетическая работа: бизнес знает, что для него ценно, ИБ предлагает инструменты защиты, а регуляторика добавляет свои требования.

Глеб Марченко как практикующий специалист по защите данных добавил, что в крупных компаниях подразделения информационной безопасности гораздо малочисленнее, чем бизнес-подразделения.

Он отметил, что в прошлом году было очень много мошеннических действий, телефонных «разводов», попыток закрепиться в инфраструктуре.

DCAP прекрасно справляется с классификацией данных в покое, у неё больше времени на анализ, и эта классификация затем используется в DLP для настройки политик безопасности.

ВыводыРынок защиты данных в 2026 год…

1 week назад @ anti-malware.ru
Как связка VM и SIEM помогает оценивать риски эксплуатации уязвимостей
Как связка VM и SIEM помогает оценивать риски эксплуатации уязвимостей Как связка VM и SIEM помогает оценивать риски эксплуатации уязвимостей

Разбираемся, как объединить данные VM, SIEM и CMDB, учесть EPSS и CISA KEV, настроить расчёт риска и расставить приоритеты устранения.

Уровни риска и сроки устранения уязвимостейКак работают вместе VM, SIEM и CMDBКаждый источник отвечает на отдельную группу вопросов.

Актив есть в VM, но не передаёт событияОбратная ситуация возникает, когда VM видит узел, а SIEM не получает от него событий.

Организовать обмен данными между VM, SIEM и CMDB.

ВыводыСвязка VM, SIEM и CMDB помогает оценивать уязвимости в контексте реальной инфраструктуры.

1 week назад @ anti-malware.ru
Обзор встроенных СЗИ операционной системы Astra Linux
Обзор встроенных СЗИ операционной системы Astra Linux Обзор встроенных СЗИ операционной системы Astra Linux

Статистика роста количества уязвимостей в ОС Linux в 1998–2026 гг.

Профили настройки СЗИ в Astra LinuxДля настройки СЗИ в Astra Linux предусмотрены готовые профили, соответствующие требованиям регулятора.

Выбор профиля защиты системы в Astra LinuxАрхитектура СЗИ ОС Astra LinuxДля обеспечения безопасности использования Astra Linux команда разработчиков переработала архитектуру исходной операционной системы.

Трёхзвенная клиент-серверная архитектура ОС Astra LinuxСогласно сертификату № 2557 ОС Astra Linux соответствует требованиям документов: Требования доверия (1), Требования доверия (2), Требования к ОС, Профиль защиты ОС (А первого класса защиты.

Сценарии использования встроенных СЗИ Astra …

1 week, 1 day назад @ anti-malware.ru
Гонка за ИИ-инфраструктурой: кто победит в 2026 году
Гонка за ИИ-инфраструктурой: кто победит в 2026 году Гонка за ИИ-инфраструктурой: кто победит в 2026 году

Аннотация: В 2026 году преимущество получают не компании с самым большим числом ИИ-пилотов, а те, кто умеет превращать эксперименты в управляемые сервисы.

В 2026 году гораздо важнее другое: способна ли компания превратить удачный ИИ-пилот в эффективный сервис, которым безопасно пользуются сотни или тысячи сотрудников?

Гонка 2026 года в пяти цифрахМасштаб разрыва между интересом к ИИ и готовностью к его промышленной эксплуатации показывают результаты исследования Orion soft и данные проектов компании.

Эта оценка окупаемости инвестиций (ROI) не проходила независимый аудит, но показывает принцип расчёта: стоимость инфраструктуры нужно сопоставлять с изменением конкретного процесса, а не с коли…

1 week, 1 day назад @ anti-malware.ru
Автоматизируем анализ защищённости в 2026 году: когда пентест уже не справляется
Автоматизируем анализ защищённости в 2026 году: когда пентест уже не справляется Автоматизируем анализ защищённости в 2026 году: когда пентест уже не справляется

Эксперты рынка обсудили, какие инструменты нужны для непрерывной оценки защищённости, как выстроить процессы и что ждёт отрасль в ближайшие годы.

Денис Гамаюнов указал, что не стоит безапелляционно отграничивать пентест от автоматизации.

Давид Ордян, генеральный директор METASCANМаксим Пятаков уточнил, что для внешнего периметра ограничений практически нет — любая компания может начать использовать ASM-решения.

Важно сначала оценить слабые места: возможно, проблема не в отсутствии какого-то инструмента, а в том, что у ИБ нет общего языка с ИТ-подразделениями.

При этом главная ценность автоматизации — не в количестве найденных уязвимостей, а в приоритизации: показать бизнесу не список пробле…

1 week, 2 days назад @ anti-malware.ru
Обзор Deckhouse Virtualization Platform 1.10, системы для управления ВМ и контейнерами в одной среде
Обзор Deckhouse Virtualization Platform 1.10, системы для управления ВМ и контейнерами в одной среде Обзор Deckhouse Virtualization Platform 1.10, системы для управления ВМ и контейнерами в одной среде

Отдельные редакции позволяют запускать контейнеры вместе с ВМ в одной среде для запуска гибридных приложений.

Для решения задач виртуализации существует множество решений с открытым кодом, в том числе и для управления виртуальными машинами (ВМ) с помощью Kubernetes.

DevOps-инструменты и практики для ВМ: IaC, GitOps, Helm, Argo CD для управления жизненным циклом.

Централизованная наблюдаемость: мониторинг, события и журналы инфраструктуры, ВМ и приложений из одной точки.

Снимок ВМ включает в себя параметры ВМ и состояние всех её дисков; снимок диска сохраняет только данные выбранного диска.

1 week, 3 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 1 час назад
Маскирование данных: 8 вопросов, которые волнуют бизнес и разработчиков
Маскирование данных: 8 вопросов, которые волнуют бизнес и разработчиков Маскирование данных: 8 вопросов, которые волнуют бизнес и разработчиков

Кто даст гарантию, что внешний периметр давно не скомпрометирован, а злоумышленник не затаился в инфраструктуре и не ворует информацию?

Так что маскирование данных внутри корпоративной сети — это вовсе не паранойя и не оверкилл, с точки зрения ИБ, а вполне оправданная и даже базовая мера защиты.

Как и в медицине, главное — соблюсти принцип «не навреди» и не сломать логику приложения радикальным «выкашиванием» данных.

И лишь понимание матчасти помогает выбрать оптимальный подход к маскированию и не поломать остальные процессы.

И скрипт здесь не помощник: он не умеет определять персональные данные и не может сам очертить уровни доступа.

1 час назад @ habr.com
Ловушки формального контроля: когда всё соответствует требованиям, но защищенности больше не становится
Ловушки формального контроля: когда всё соответствует требованиям, но защищенности больше не становится Ловушки формального контроля: когда всё соответствует требованиям, но защищенности больше не становится

Именно поэтому зрелое управление доступом должно анализировать не только отдельные права, но и комбинации полномочий.

На практике я начинаю не с проверки списка ролей пользователя, а с построения его эффективной модели доступа.

MFA — это один контроль, EDR — другой, UEBA — третий, SIEM — четвертый, а атака проходит через инфраструктуру, а не «продукты».

Поэтому при проверке MFA я стараюсь тестировать не только сам механизм второго фактора, но и сценарии его обхода и использования уже авторизованной сессии.

Но задача ИБ не в том, чтобы запретить исключения, а в том, чтобы не позволить им превратиться в постоянную дыру в защите.

2 часа назад @ habr.com
Runtime-контроль ИИ-агентов: единица контроля не модель, а действие
Runtime-контроль ИИ-агентов: единица контроля не модель, а действие Runtime-контроль ИИ-агентов: единица контроля не модель, а действие

Три слоя покрытия, а не бинарное «защищён / не защищён»Агенты в контуре живут на трёх уровнях.

Пока агент не на У2, у него нет запрета по умолчанию (deny-by-default) на инструменты.

Режим registry_only: неизвестный сервер уходит в карантин и на скан, а не в прод.

Если агент начал ходить в другого агента, это должно быть видно не в логе приложения, а в контуре безопасности.

Режим registry_only должен включаться сразу: неизвестный MCP – сразу в карантин, а не в прод.

2 часа назад @ habr.com
Неужели так просто найти хакера в сетевом трафике облака?
Неужели так просто найти хакера в сетевом трафике облака? Неужели так просто найти хакера в сетевом трафике облака?

В облаке точно так же разворачивают почтовые серверы, базы данных, GitLab, а иногда и рабочие станции — просто в меньшем количестве, чем в офисной сети.

Разница не в устройстве инфраструктуры, а в зрелости средств защиты вокруг неё.

В потоке HTTP-запросов обнаружился характерный паттерн: перебор множества различных URL, а в теле одного из запросов нашлась строка вида "hello" = "die(md5(Ch3ck1ng));".

И возможностью наблюдать за атакой не только в архиве, но и в моменте, пока злоумышленник ещё активен внутри инфраструктуры.

Это не конкурент SIEM, NGFW или EDR, а системы, которые закрывают именно то пространство, куда остальные инструменты физически не дотягиваются — по своей архитектуре, а не…

3 часа назад @ habr.com
Индустрия ИИ надела на себя наручники добровольно. Проверим, настоящие ли они
Индустрия ИИ надела на себя наручники добровольно. Проверим, настоящие ли они Индустрия ИИ надела на себя наручники добровольно. Проверим, настоящие ли они

Примерно как если бы производитель лекарств учредил внутри себя комитет по этике и на его основании выдавал себе разрешения, попутно редактируя устав комитета.

Сертификат безопасности на модель это сертификат на конкретную конфигурацию в конкретный день.

Не с тревогой и не с восхищением, а с чем-то вроде уважения к масштабу задачи, которую сейчас никто не умеет решать.

Компания честно ограничивает свой продукт и, что важнее, продолжает ограничивать его после релиза, когда давление выручки максимальное.

Мне же кажется, что настоящая новость той недели была не в ней, а в четырех неделях задержки, о которых почти не написали.

4 часа назад @ habr.com
Как я не выучил программирование, поймал шифровальщика и собрал AI-платформу
Как я не выучил программирование, поймал шифровальщика и собрал AI-платформу Как я не выучил программирование, поймал шифровальщика и собрал AI-платформу

Сначала расскажу, как человек, который так и не смог выучить программирование, вообще до него добрался.

Просто я начал изучать их не по курсам, а по мере того, как ломался мой собственный проект.

Он подключён только к внутренней Docker-сети sandbox и не видит интернет, PostgreSQL, Redis и остальные внутренние сервисы.

Я не юрист и не буду изображать специалиста по 152-ФЗ.

Очередь не рассыпалась и не потеряла основную массу заданий — это хорошо.

4 часа назад @ habr.com
Threat Intelligence без мифов: чем TI не является и почему его часто внедряют неправильно
Threat Intelligence без мифов: чем TI не является и почему его часто внедряют неправильно Threat Intelligence без мифов: чем TI не является и почему его часто внедряют неправильно

Поэтому важно проговорить: Threat Intelligence — это не магия и не автономная защита.

Threat Intelligence не может существовать в изоляцииОдна из причин, почему TI часто «не взлетает», — его пытаются выделить в отдельный мир.

Его ценность появляется только тогда, когда он влияет на приоритеты, на правила обнаружения, на threat hunting, на архитектурные решения.

Чем Threat Intelligence должен быть на самом делеЕсли убрать маркетинг и громкие формулировки, Threat Intelligence — это механизм поддержки решений.

Это не база «всего плохого», не серебряная пуля и не ещё один генератор алертов.

4 часа назад @ habr.com
Открыл обычный VBS, а внутри оказался PowerShell, AES и MSBuild
Открыл обычный VBS, а внутри оказался PowerShell, AES и MSBuild Открыл обычный VBS, а внутри оказался PowerShell, AES и MSBuild

То есть исходный файл выглядит примерно так:2.vbs | +-- VBScript | +-- DATA: | +-- данные №1 +-- данные №2 +-- PowerShellПричём PowerShell тоже не лежит в готовом виде.

Основной блок — 10 символов:if ($r -ge 0xA) { $v = [long]$lut[[int]$sc[$i]] for ($q = 1; $q -lt 0xA; $q++) { $v = $v * 0x34 + [long]$lut[[int]$sc[$i+$q]] } }Из этого значения потом достаются байты.

Осталось понять, что с ними делают дальше.

Есть ещё один моментВ PowerShell есть таймер:$_xt = New-Object Timers.Timer $_xt.Interval = 0x927C0 $_xt.AutoReset = $false $_xt.add_Elapsed({ [Environment]::Exit(0) }) $_xt.Start()0x927C0 — это 600000 миллисекунд.

Скрытый PowerShell — не новость.

4 часа назад @ habr.com
AI-агент в проде: песочница, RBAC и egress-контур вместо надежды на промпт
AI-агент в проде: песочница, RBAC и egress-контур вместо надежды на промпт AI-агент в проде: песочница, RBAC и egress-контур вместо надежды на промпт

Почему промпт не является границейЗа четыре года prompt injection так и не научились надёжно устранять, и есть основания считать, что окончательного решения так не будет.

Они собраны по документации Kubernetes (RBAC, ServiceAccount, ResourceQuota, NetworkPolicy) и по документации проекта Agent Sandbox от Kubernetes SIG, конфигурация Claw Patrol приведена по справочнику проекта.

Формулировку предложил вендор песочниц Edera, и в его интересе её продвигать.

Минимальная схема замера: запустить одного агента на одной задаче в трёх рантаймах — runc , gVisor и Kata — и сделать по полсотни прогонов.

RuntimeClass с gVisor и CRD Agent Sandbox в сервис не входят: их, как и в других managed-кластерах, …

4 часа назад @ habr.com
В журнале приложения лежит чужой пароль, и положил его туда не код авторизации
В журнале приложения лежит чужой пароль, и положил его туда не код авторизации В журнале приложения лежит чужой пароль, и положил его туда не код авторизации

Менеджер паролей подставил не туда, автозаполнение сработало со сдвигом, человек нажал Tab на один раз меньше - и пароль оказался в поле логина.

То, что в имя пользователя попал пароль, в коде определить нельзя.

Пароль в этот момент лежит в локальной переменной обработчика.

Отдельно - заголовки: Authorization и Cookie попадут под фильтр, только если заголовки вообще логируются как набор пар, и это надо проверить отдельно.

Разбор инцидента от этого не страдает: считать частоту попыток и группировать их по одному значению можно и по хешу.

4 часа назад @ habr.com
Как я восстанавливал WordPress после взлома и дважды ошибся
Как я восстанавливал WordPress после взлома и дважды ошибся Как я восстанавливал WordPress после взлома и дважды ошибся

Расскажу, как до этого дошло и на чём я сам попался.

Одну закладку пропустили, и она была не в uploads, а в виде обычного с виду плагина.

Во время июльской чистки его не заметили: он выглядел как установленный плагин, а не как посторонний файл.

Это дополнительный барьер на входе, не двухфакторная аутентификация и не защита всех остальных путей доступа.

А после любого ремонта проверяйте, что получает посетитель, а не что лежит на сервере.

5 часов назад @ habr.com
Ideco NGFW Novum v23: Shadow AI, enterprise-маршрутизация и контроль трафика
Ideco NGFW Novum v23: Shadow AI, enterprise-маршрутизация и контроль трафика Ideco NGFW Novum v23: Shadow AI, enterprise-маршрутизация и контроль трафика

Shadow AI Discovery: NGFW как точка наблюдения за AI-трафикомВ Ideco NGFW Novum v23 модуль «Контроль приложений» получил 83 протокола AI-приложений.

В Контент-фильтре уже существовала категория «ИИ чат-боты», но технологии развиваются и для лучшей категоризации мы добавили две новые: «ИИ-агенты» и «ИИ-сервисы».

Он не анализирует содержание промптов, не определяет автоматически тип передаваемого документа и не заменяет DLP.

Голос и видеоконференции чувствительны не только к объёму полосы, но и к очередям, задержке и джиттеру.

В Ideco NGFW Novum v23 появилось управление качеством обслуживания QoS (Quality of Service): приоритизация трафика и распределение полосы между категориями.

6 часов назад @ habr.com
Перестаньте спрашивать «этот скилл безопасен?» — спрашивайте «что он умеет?»
Перестаньте спрашивать «этот скилл безопасен?» — спрашивайте «что он умеет?» Перестаньте спрашивать «этот скилл безопасен?» — спрашивайте «что он умеет?»

Мы привыкли считать кодом .py и .js; текстовый файл выглядит безобидно, но для агента он и есть команда.

Сначала я надеялась добавить к каждой истории именно это, а потом пришлось признать, что это невозможно.

У меня получилось пять уровней, и суть в том, что они описывают возможности, а не добродетельность скила:Уровень Что означает T0 Инертный.

Сразу оговорюсь, потому что это будет первым вопросом в комментариях: «нельзя проинъектить» — не то же самое, что «нельзя обойти обфускацией».

Это v0.1, и он намеренно параноидальный — он метит высоко даже собственную документацию: весь репозиторий skill-xray сканируется как T4.

9 часов назад @ habr.com
PII-Guard: открытый детектор персональных данных для русского текста
PII-Guard: открытый детектор персональных данных для русского текста PII-Guard: открытый детектор персональных данных для русского текста

Полный цикл обработки запроса: замена ПД плейсхолдерами перед отправкой в модель и их обратное восстановление в финальном ответе.

Тип входит в ключ, поэтому фамилия Иванов и город Иванов лежат в разных корзинах и не сольются при любой похожести.

С cloud.ru вдвоём область шире на три типа — ИНН, СНИЛС и IP-адрес, — и на них картина видна полнее.

Обучили модель — и увидели, что доверять ей арифметику тоже нельзя: там, где достаточно посчитать контрольную сумму, она угадывает.

Модель видит на месте данных осмысленную сущность, а не звёздочки, и работает с текстом ровно так же, как работала бы с настоящим.

21 час назад @ habr.com
Атаки на агентные системы и защита данных
Атаки на агентные системы и защита данных Атаки на агентные системы и защита данных

Я — независимый эксперт в области ИТ и ИБ, преподаю в учебных центрах и пишу статьи и книги.

В этой статье мы разберём, как устроены атаки на агентные системы, на реальных примерах и без отрыва от технических деталей.

В текст сайта были встроены скрытые инструкции (помещённые в CSS за пределы видимой области или в JSON‑LD‑метаданные).

И это не теоретический риск.

Затем они дали агентам Anthropic, OpenAI и Google доступ к этим репозиториям и попросили ответить на вопросы на основе данных.

21 час назад @ habr.com
Хакер Хакер
последний пост 1 час назад
Более 5400 взломанных сайтов распространяют ClickFix-пейлоады, хранящиеся в блокчейне
Более 5400 взломанных сайтов распространяют ClickFix-пейлоады, хранящиеся в блокчейне Более 5400 взломанных сайтов распространяют ClickFix-пейлоады, хранящиеся в блокчейне

Специалисты компании Netskope обнаружили масштабную вредоносную кампанию, в которой атакующие используют более 5400 взломанных сайтов для распространения ClickFix-пейлоадов.

При этом сам вредоносный код хранится в смарт-контрактах BNB Smart Chain (BSC), что заметно усложняет блокировку инфраструктуры хакеров.

Но в этом случае скрипт сам генерирует и предложение, и ответ, после чего передает их локально в созданное соединение.

Всего за время наблюдения исследователи выявили более 5400 скомпрометированных сайтов, задействованных в этой кампании, и активность злоумышленников растет.

Так, в августе 2026 года наблюдалось почти 400 взломанных сайтов в сутки, а максимальный показатель достигал 536.

1 час назад @ xakep.ru
США заблокировали более $52 миллионов в крипте, связанной с даркнет-площадкой Xinbi Guarantee
США заблокировали более $52 миллионов в крипте, связанной с даркнет-площадкой Xinbi Guarantee США заблокировали более $52 миллионов в крипте, связанной с даркнет-площадкой Xinbi Guarantee

С учетом остальных заблокированных активов общая сумма, выведенная из-под контроля Xinbi и связанных с ней лиц, превысила $52 млн.

Ранее на этой неделе эмитент стейблкоина USDT самостоятельно заблокировал 39,3 млн долларов в USDT на десяти адресах сети TRON, связанных с Xinbi.

Одновременно с Минюстом США Управление по контролю за иностранными активами (OFAC) Минфина США внесло Xinbi Guarantee в санкционный список как значимую транснациональную преступную организацию.

Ранее, в феврале, аналитики TRM Labs оценивали объем операций Xinbi с середины 2025 года примерно в $17,9 млрд.

Ранее, 26 марта, власти Великобритании уже ввели санкции против Xinbi и заморозили связанные с площадкой активы в с…

2 часа назад @ xakep.ru
Появился новый 0-day-эксплоит ShieldCrash для повышения привилегий через Microsoft Defender
Появился новый 0-day-эксплоит ShieldCrash для повышения привилегий через Microsoft Defender Появился новый 0-day-эксплоит ShieldCrash для повышения привилегий через Microsoft Defender

Анонимный ИБ-исследователь Nightmare Eclipse (также известный под никами Chaotic Eclipse и MSNightmare) опубликовал PoC-эксплоит для новой уязвимости нулевого дня в Microsoft Defender.

Эксплоит ShieldCrash позволяет обойти свежее исправление для уязвимости ShieldBreak (CVE-2026-69414, 7,8 балла по шкале CVSS), о которой мы писали в августе.

Напомним, что эта проблема, в свою очередь, позволяла обойти патч для другой раскрытой Nightmare Eclipse уязвимости — RoguePlanet (CVE-2026-50656), исправленной в июле.

В Microsoft внесли несколько изменений, чтобы предотвратить новую эксплуатацию, но пропустили одно место», — объясняет исследователь.

С апреля 2026 года исследователь обнародовал целую се…

3 часа назад @ xakep.ru
Создан червь для WeChat, который распространяется через входящие звонки
Создан червь для WeChat, который распространяется через входящие звонки Создан червь для WeChat, который распространяется через входящие звонки

Исследователи из компании Calif разработали червя, который позволял захватывать аккаунты в WeChat с помощью простого входящего звонка.

Специалисты рассказывают, что для реализации атаки нужно было выполнить лишь одно условие: звонящий должен находиться в списке контактов WeChat жертвы.

Захватив один аккаунт, вредонос мог сам звонить другим людям из списка контактов, поскольку скомпрометированный пользователь уже был добавлен в их контакты в WeChat.

При этом полный список уязвимых версий WeChat неизвестен, а также не сообщается, затрагивала ли проблема клиенты WeChat для HarmonyOS, Windows, macOS и Linux.

21 августа в компании выпустили WeChat 8.0.77 для Android и 8.0.76 для iOS, которые, по…

18 часов назад @ xakep.ru
Microsoft выпустила патчи для почти 1000 уязвимостей
Microsoft выпустила патчи для почти 1000 уязвимостей Microsoft выпустила патчи для почти 1000 уязвимостей

В рамках сентябрьского «вторника обновлений» разработчики Microsoft устранили почти 1000 уязвимостей, включая два 0-day-бага, которые уже эксплуатируются в реальных атаках.

Если же подсчитать общее количество CVE, а также уязвимости в плагинах и компонентах стороннего ПО, речь идет уже о 974 уязвимостях.

Суммарно в Windows исправили 723 бага, в Office — 222, включая 111 проблем в Office 2016.

Кроме того, вышли свежие Servicing Stack Updates для Windows Server 2012, Server 2012 R2 и Windows 10 1607/Server 2016.

Первая из них, CVE-2026-85880, представляет собой проблему повышения привилегий и связана с переполнением буфера хипа в Windows Advanced Local Procedure Call (ALPC).

20 часов назад @ xakep.ru
Доверчивый банкир. Ищем уязвимости в мобильном банковском приложении
Доверчивый банкир. Ищем уязвимости в мобильном банковском приложении Доверчивый банкир. Ищем уязвимости в мобильном банковском приложении

Валидация OTPКог­да поль­зователь пыта­ется залоги­нить­ся в свой акка­унт в бан­ков­ском при­ложе­нии, ему нуж­но ввес­ти ПИН (пер­сональ­ный иден­тифика­цион­ный номер) и серию пас­порта на началь­ной стра­нице.

Генери­рует­ся зап­рос, где фотог­рафия зло­дея (ско­рее все­го, там будет не его нас­тоящее лицо) отправ­ляет­ся на сер­вер в фор­мате Base64 для про­вер­ки:POST / api/ v2/ identity/ liveness- test HTTP/ 1.

1 Accept: application/ json Content- Type: application/ json { "imageData": "/ 9j/ 4AAQSkZJRgABAQAAAQABAAD... < base64 картинка>.. . 5ErkJggg==" }Пос­ле это­го сер­вер вер­нет зло­умыш­ленни­ку такой ответ:HTTP/ 1.

В иссле­дуемом нами при­ложе­нии в момент нажатия на поле CVV …

22 часа назад @ xakep.ru
В Южной Корее обнаружили бэкдор Ted, который скрывается в HAProxy
В Южной Корее обнаружили бэкдор Ted, который скрывается в HAProxy В Южной Корее обнаружили бэкдор Ted, который скрывается в HAProxy

Исследователи из компании Rapid7 обнаружили новый Linux-инструментарий, предназначенный для кибершпионажа, который уже применялся для атак на две южнокорейские организации из автомобильной и медийной отраслей.

Своей главной находкой специалисты считают бэкдор Ted, который был встроен в модифицированную сборку балансировщика HAProxy.

В Rapid7 предполагают, что точкой входа могла стать уязвимость в одном из корейских Groupware-порталов, однако прямых доказательств этой теории нет.

Специальный HTTP-запрос переводит Ted в режим C&C, после чего бэкдор уменьшает счетчики активных соединений в HAProxy и перехватывает запрос прямо на уровне балансировщика.

В результате команда не попадает на бэкенд…

23 часа назад @ xakep.ru
Хакеры украли у Liquid Network 4000 биткоинов, но потом вернули большую часть
Хакеры украли у Liquid Network 4000 биткоинов, но потом вернули большую часть Хакеры украли у Liquid Network 4000 биткоинов, но потом вернули большую часть

Неизвестные злоумышленники, называющие себя «белыми хакерами», похитили 4000 BTC у сайдчейна Liquid Network, а затем вернули 3400 из них.

С помощью Liquid Network пользователи могут переводить BTC в Liquid: биткоины блокируются в кошельке с мультиподписью, а пользователь получает эквивалентное количество L-BTC.

До атаки в кошельке федерации находилось около 4200 BTC, и хакеры сумели вывести примерно 95% резервов — около 4000 BTC.

При этом подчеркивается, что ни системы SideSwap, ни PAK скомпрометированы не были.

В настоящее время ни в Blockstream, ни в Liquid публично не объяснили, что будет с этими 598,5 BTC и являются ли они согласованным «вознаграждением», которое хакеры оставят себе.

1 day, 1 hour назад @ xakep.ru
Исследователи выяснили, что телевизоры LG могут подслушивать разговоры при выключенном экране
Исследователи выяснили, что телевизоры LG могут подслушивать разговоры при выключенном экране Исследователи выяснили, что телевизоры LG могут подслушивать разговоры при выключенном экране

Как теперь отмечают исследователи Gamers Nexus, компания LG к тому же использует полученные с помощью ACR данные в своем рекламном бизнесе.

Дело в том, что в webOS обнаружились распознанные голосовые запросы, которые сохранялись в системных логах в открытом виде.

Однако сами расшифровки сохранялись в памяти устройства в читаемом виде, и специалисты отметили, что это создает дополнительные риски в случае компрометации телевизора.

Отдельно исследователи Gamers Nexus продемонстрировали, что в случае компрометации webOS телевизор можно использовать для скрытой записи звука.

Кроме того, по словам представителей компании, телевизоры вообще не собирают, не записывают и не передают вовне фоновые ра…

1 day, 3 hours назад @ xakep.ru
Хакеры атаковали уязвимость StyleSmuggler в Magento и Adobe Commerce
Хакеры атаковали уязвимость StyleSmuggler в Magento и Adobe Commerce Хакеры атаковали уязвимость StyleSmuggler в Magento и Adobe Commerce

Эксперты компании Sansec предупредили об активной эксплуатации критической уязвимости StyleSmuggler в Magento Open Source и Adobe Commerce.

Проблема затрагивает версии Adobe Commerce с 2.4.4 по 2.4.9, а также Magento Open Source с 2.4.6 по 2.4.9.

Сегодня, 8 сентября 2026 года, разработчики Adobe выпустили экстренный патч и подтвердили, что уязвимость уже активно применяется хакерами в реальных атаках.

Также администраторам рекомендуют проверить систему в поисках подозрительных процессов kworker, fc-cache и chronyd, неизвестных cron-задач и временных файлов.

В случае обнаружения на сервере признаков компрометации эксперты советуют сменить учетные данные Magento и проверить систему на наличие…

1 day, 18 hours назад @ xakep.ru
В Plex исправили многочисленные уязвимости и призвали обновиться
В Plex исправили многочисленные уязвимости и призвали обновиться В Plex исправили многочисленные уязвимости и призвали обновиться

Разработчики Plex призвали пользователей как можно скорее обновить Plex Media Server и Plex Desktop.

Дело в том, что в свежих версиях были исправлены сразу несколько серьезных уязвимостей, однако подробностей о них разработчики пока не раскрывают.

Сообщается, что многочисленные проблемы затрагивали Plex Media Server версии 1.43.2 и ниже, а исправления для них вошли в состав Plex Media Server 1.43.3 и Plex Desktop 1.115.0.

«Мы рекомендуем всем владельцам серверов и пользователям Desktop как можно скорее обновиться до последней версии», — предупреждают в Plex.

Для Plex это весьма необычный шаг, и в прошлом подобные адресные уведомления об отдельных уязвимостях компания отправляла лишь в неско…

1 day, 20 hours назад @ xakep.ru
Ботоферма. Как создать мини-ферму на Android и ESP32
Ботоферма. Как создать мини-ферму на Android и ESP32 Ботоферма. Как создать мини-ферму на Android и ESP32

В нашей мини‑фер­ме зап­ланиро­вано три основных ком­понен­та:Скрипт на Python для обме­на дан­ными меж­ду компь­юте­ром и ESP32 через пос­ледова­тель­ный порт.

ESP32 в роли оркес­тра­тора, который будет запус­кать задания на смар­тфо­нах с Android и воз­вра­щать получен­ные дан­ные на компь­ютер.

info Пол­ный код про­екта, вклю­чая скетч для ESP32 и про­ект Android-при­ложе­ния, ищи в моем ка­нале и на GitHub.

От­кры­ваем меню Tools, затем Board и в под­меню выбира­ем Boards Manager.

Нап­ример, если у тебя бес­про­вод­ная кла­виату­ра и мышь, бла­года­ря раз­ным иден­тифика­торам их сиг­налы не пересе­кут­ся с сиг­налами телефо­нов и ESP32.

1 day, 22 hours назад @ xakep.ru
Android-малварь Drama RAT маскируется под VPN и банковские приложения
Android-малварь Drama RAT маскируется под VPN и банковские приложения Android-малварь Drama RAT маскируется под VPN и банковские приложения

Специалисты Positive Technologies изучили Android-троян Drama RAT, который распространяется через фишинговые сообщения в мессенджерах и маскируется под VPN-сервисы, банковские приложения и взломанные утилиты с платными функциями.

Исследователи выяснили, что все фальшивые приложения, распространяющие Drama RAT, представляют собой дропперы-загрузчики.

После установки Drama RAT собирает подробную информацию об устройстве, включая версию Android, уровень заряда, тип сетевого подключения, данные SIM-карт и выданные разрешения.

Исследователи отмечают, что Drama RAT скрывает от жертвы процесс выдачи прав.

Фишинговые оверлеи в Drama RAT подготовлены сразу на 29 языках, включая русский, английский, …

1 day, 23 hours назад @ xakep.ru
Миллионам сайтов на WordPress угрожает уязвимость в плагине для резервного копирования
Миллионам сайтов на WordPress угрожает уязвимость в плагине для резервного копирования Миллионам сайтов на WordPress угрожает уязвимость в плагине для резервного копирования

В плагине All-in-One WP Migration and Backup для WordPress обнаружили уязвимость, связанную с SQL-инъекцией, которая позволяет удаленно выполнить код без аутентификации и полностью скомпрометировать сайт.

Уязвимость получила идентификатор CVE-2026-19949 (8,8 балла по шкале CVSS) и затрагивает все версии All-in-One WP Migration and Backup до 7.109 включительно.

Плагин All-in-One WP Migration предназначен для резервного копирования данных и миграции WordPress-сайтов.

Эксплоит срабатывает позднее, когда администратор создает резервную копию сайта, а затем импортирует ее через All-in-One WP Migration.

В результате заранее подготовленные атакующим данные превращаются в исполняемый SQL-запрос, ко…

2 days, 1 hour назад @ xakep.ru
Спамеры используют невидимые символы Unicode для обхода фильтров
Спамеры используют невидимые символы Unicode для обхода фильтров Спамеры используют невидимые символы Unicode для обхода фильтров

Специалисты Microsoft обнаружили масштабную фишинговую кампанию, в рамках которой злоумышленники применяют технику «контрабанды ASCII-символов» (ASCII smuggling) и используют невидимые символы Unicode для обхода почтовых фильтров.

Атаки типа ASCII smuggling основываются на использовании символов из блока Tags в Unicode (U+E0000–U+E007F), часть из которых дублирует набор печатных ASCII-символов.

Ранее при помощи ASCII smuggling злоумышленники, например, скрывали вредоносные промпты для LLM, а теперь применяют эту технику для маскировки слов, характерных для финансового спама и фишинга.

Из-за невидимого символа токенизатор может разбить знакомое слово на необычную последовательность сабтокено…

2 days, 3 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 4 часа назад
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide.

Why One Key Matters This MuchThe master key does two jobs at once, and that is what makes a default value serious.

Before version 1.82.0-stable, a gateway that started without a master key granted every incoming request full admin rights.

The advisory adds that a deployment with no master key treated callers as proxy administrators, which is what put those endpoints within reach.

CISA added one LiteLLM flaw to its Known Exploited Vulnerabilities catalog on September 2.

4 часа назад @ thehackernews.com
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents.

The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached "third-parties after being unable to abort its task."

"All incidents included a single Claude instance; at no point did Claude attempt to coordinate with other agents.

These incidents have also illustrated how AI agents can work as a collective to discuss ways to cheat on benchmarks or escape the sandbox.

"Futu…

4 часа назад @ thehackernews.com
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

"Approximately $52 million of cryptocurrency involved in scam money laundering was restrained in one day, bringing the total restrained by the Scam Center Strike Force to approximately $938 million," DoJ said.

Xinbi Guarantee is a Telegram-oriented marketplace that rose to prominence following the closure of two other similar storefronts, HuiOne Guarantee and its successor Tudou Guarantee, last year.

Besides dismantling the Telegram channels hosting the marketplace and banning the associated usernames, the Justice Department said the Scam Center Strike Force seized two cryptocurrency wallets Xinbi used to collect payments for vendors.

Furthermore, the Justice Department announced that the S…

17 часов назад @ thehackernews.com
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.

"Within days, several other espionage-motivated clusters began using BlueMoon, the majority of which have a suspected China nexus," Proofpoint said in a report published today.

"However, BlueMoon may not be exclusive to China-aligned actors, as some usage remains unattributed and there are also potentially more actors using the exploit kit."

It's suspected that the developer behind the exploit kit may have been closely keeping track of publicly available Chromium patches to …

19 часов назад @ thehackernews.com
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Among those were thousands of unexpired authentication tokens corresponding to services like Google, Microsoft, Anthropic, Amazon, Gamma, Notion, Character.ai, Cursor, Poe.com, and Pika AI.

In all, the stolen data is said to have contained 1,843 unexpired JWTs and JWEs on the day it was released.

An attacker who is in possession of such a key can weaponize it for espionage, extortion, or resource theft, and rack up AI token bills.

"Accessing accounts using stolen session data requires specific tooling," Okta said.

"So-called 'anti-detect' browsers have features designed to use stolen authentication data and avoid security controls."

21 час назад @ thehackernews.com
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

Register now for our next live expert webinar, "Outpacing AI-Era Attacks Starts With Faster Time to Answer," to see how the Tines security team approaches that problem.

See How Tines Built a Faster Exposure ViewIn this webinar, Tines Co-founder and CCO Thomas Kinsella and Senior Security Operations Engineer Andrew Katz will show how their security team brings multiple sources of exposure data into one interactive view.

Join the webinar to see the exposure dashboard in action and how Tines connects security data to a faster decision-making workflow.

AI can help teams reason through complex inputs and build workflows faster.

Register for “Outpacing AI-Era Attacks Starts With Faster Time to An…

1 day назад @ thehackernews.com
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command.

The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace.

VulnCheck, which assigned the identifier, published the record on September 8 and rated the flaw 9.4 out of 10.

The command invoked the tool's local interface and set the agent's session to a mode called danger-full-access, which turns off the sandbox and stops approval prompts.

That second report also noted that the project had no security policy file and no privat…

1 day назад @ thehackernews.com
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet.

Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin.

Its DigitalOcean guide tells the reader to keep the server's public address switched on, because it is "needed so you can open Alby Hub in your browser," and then to open the Hub at that address.

An Earlier Takeover on an Exposed HubThis is not the first Alby Hub taken over after being left open.

After that case, a change to Umbrel's app put Alby Hub beh…

1 day, 1 hour назад @ thehackernews.com
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks.

The joint advisory noted that Chinese AI firms like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Anthropic Claude, OpenAI GPT, Google Gemini, and SpaceXAI Grok, since at least late 2024, likely with the blessing of the Chinese government.

"China-based AI companies achieve cost savings for their industrial-s…

1 day, 2 hours назад @ thehackernews.com
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.

"Out-of-bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a description of the flaw on the NIST National Vulnerability Database (NVD).

With the latest development, Google has addressed a total of seven actively exploited Chrome zero-days since the start of the year.

One high use-after-free flaw in WebPackaging (CVE-2026-87639) is credited to OpenAI Codex Security.

To ensure the latest updates are installed, users can navigate to More > Help …

1 day, 2 hours назад @ thehackernews.com
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server.

cPanel's advisory calls it an SQL injection issue in EmailTrack, but does not say which cPanel feature or privilege an account needs.

A customer manages one hosting account via cPanel, while the provider manages the entire machine via WHM as the root user.

Attackers exploited a different cPanel flaw in April.

Two other cPanel flaws disclosed since the end of July also start from an ordinary hosting account.

1 day, 3 hours назад @ thehackernews.com
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

A web shell is usually a small script an attacker drops into a web server's folders to run commands through ordinary web requests.

As the researchers put it, the web shell "does not need to exist in its final form on disk."

The web shell is the last step in a longer chain, and the earlier steps do touch the disk.

The web shell reads the raw body of a request, checks it for a short marker, decrypts the rest, and runs it.

It has no evidence either way on whether the attacker reaches the socket through the web shell.

1 day, 4 hours назад @ thehackernews.com
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender.

"Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic Eclipse said.

The development comes days after Redmond shipped an update to the Microsoft Malware Protection Engine to plug CVE-2026-69414.

"In response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Microsoft Malware Protection Engine," the tech giant said.

"For enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Pr…

1 day, 5 hours назад @ thehackernews.com
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS.

CVE-2026-44756 stems from a missing boundary validation during the deserialization of EPP data, leading to a memory safety violation when processing externally supplied length fields.

A successful attack yields full remote code execution as adm, the OS-level user that runs SAP, on every application server in the cluster."

CVE-2026-66768 (CVSS score: 9.0) - An improper access control vulnerability in SAP NetWeaver SAP GUI for Java that allows execution of arbitrary commands on the underlying host.

Onapsis is recommending that users inventory every SAP system, patch internet-facing systems before internal…

1 day, 5 hours назад @ thehackernews.com
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild.

These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools.

Three prominent vulnerability types, namely privilege escalation, remote code execution, and information disclosure, account for nearly 90% of the flaws patched this month.

September's record-setting security updates come after Microsoft patched 457 vulnerabilities in August, 663 in July, 220 in June, and 161 in May.

Per exposure management and vulnerability assessment platform Te…

1 day, 7 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 1 day, 3 hours назад
Safe word: What is it and why do you need one?
Safe word: What is it and why do you need one? Safe word: What is it and why do you need one?

The technology might be impressive, but a simple technique could stop the scammers in their tracks: a pre-agreed safe word.

What is a safe word?

But suggest some scenarios in which it would be a good idea to request a safe word.

It’s important to have a backup if someone can’t remember the safe word.

But a safe word is a fantastic, free option for uncovering deepfake audio fraud like fake/virtual kidnappings.

1 day, 3 hours назад @ welivesecurity.com
I’ve been deepfaked: What do I do?
I’ve been deepfaked: What do I do? I’ve been deepfaked: What do I do?

But across the globe, policymakers and public opinion are forcing tech platforms to better police this content.

What should I do if I’ve been deepfaked?

Google: Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

Try Google’s “remove personal information” tool (or here) and the legal removal request form to remove non-NCII from search results.

The first point of call is to contact the publisher to request removal.

1 week, 1 day назад @ welivesecurity.com
This month in security with Tony Anscombe – August 2026 edition
This month in security with Tony Anscombe – August 2026 edition This month in security with Tony Anscombe – August 2026 edition

Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity newsWith August coming to a close, it's time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news over the past month.

Here's some of what caught Tony's attention:OpenAI has disclosed more details about how its agents hacked AI collaboration platform Hugging Face.

Delta Airlines is investigating an incident where a flight passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network.

What are the lessons that businesses and critical infra…

1 week, 3 days назад @ welivesecurity.com
AI-assisted reconnaissance: Why everyone could be a viable target for fraud
AI-assisted reconnaissance: Why everyone could be a viable target for fraud AI-assisted reconnaissance: Why everyone could be a viable target for fraud

And of course, linking our professional and personal social media accounts is a simple task for AI.

For example, fraudsters could use personal information to craft a social engineering attack designed to harvest your work credentials or information.

Losing your personal information is one thing.

What you can do about AI-powered OSINTWhen it comes to AI-powered reconnaissance, there are things you can control and things you can’t.

Old social media photos are easier to remove, but few of us have the time to trawl through our entire digital life to remove anything potentially useful to criminals.

2 weeks назад @ welivesecurity.com
How QR-code phishing can slip past corporate security measures
How QR-code phishing can slip past corporate security measures How QR-code phishing can slip past corporate security measures

So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years.

Most importantly, they take the victim from a relatively well-protected corporate environment to a potentially unmanaged mobile device, thus bypassing business-grade security.

Malicious QR codes are frequently embedded in alerts urging users to secure their account, or authenticate to confirm their details.

Encourage employees to avoid scanning QR codes in unsolicited emails and report anything suspicious.

Next, consider technical controls, including email security from a reputable vendor to minimize the risk of quishing emails ending up in users’…

3 weeks, 3 days назад @ welivesecurity.com
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?

The accelerated discovery of previously unknown software vulnerabilities has been making headlines for months.

It’s an issue that has even led the US government to create a vulnerability clearing house named Gold Eagle to coordinate research efforts in vulnerability discovery, mitigation and fixes.

A keynote at Black Hat USA 2026 detailed research by associate professor Yan Shoshitaishvili and his undergraduate students at Arizona State University on the expanding use of AI models for vulnerability discovery.

The team then trained the GPTs using the properties of previously known vulnerabilities and discovered approximately 1,000 vulnerabilities.

If this logic prevails, we may reach the cal…

3 weeks, 6 days назад @ welivesecurity.com
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility

Hugging Face disclosed that it had been attacked by AI; OpenAI came clean and declared that it was two of their AI models that had caused the breach.

A very late addition to the Black Hat agenda was a presentation by OpenAI’s team providing the details of the Hugging Face incident as they saw it and, importantly, the timeline.

The agents concluded that their task set could be completed by breaking out their sandbox and accessing external (Hugging Face) systems.

The target was Hugging Face: this is where the agents wanted to get, and they did.

On July 16th, Hugging Face disclosed an incident in which swarms of autonomous AI agents had breached its infrastructure.

4 weeks назад @ welivesecurity.com
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
Black Hat USA 2026: AI is racing ahead of cybersecurity controls Black Hat USA 2026: AI is racing ahead of cybersecurity controls

The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials.

The second part of the opening keynote included Nick Andersen, Acting Director, CISA; Katherine Sutton, Assistant Secretary of War for Cyber Policy; and Brett Leatherman Assistant Director, Cyber Division, FBI.

I do agree with the ruthless approach, but without some form of regulation the boundaries on the use of AI remain blurred.

The Assistant Secretary of War for Cyber Policy made a fabulous analogy when pressed on the struggles regarding resourcing in the cybersecurity industry: you don’t want a pediatrician performing heart surgery.

We talk about autonomous AI at…

4 weeks назад @ welivesecurity.com
Are AI tutors safe for your kids?
Are AI tutors safe for your kids? Are AI tutors safe for your kids?

The AI tutor market is growing fastThe market for AI tutoring tools is booming.

Today, you can find various types of AI tutor tools to buy and use.

This happens when AI tools are tricked into ignoring their safety guardrails and display untrusted content.

If you’re keen to get your kids in front of an AI tool to help with private tutoring, first understand the difference between a simple co-pilot and a dedicated ITS.

So if you’re keen to try AI tutors, be sure to stay updated on what’s available out there.

1 month назад @ welivesecurity.com
This month in security with Tony Anscombe – July 2026 edition
This month in security with Tony Anscombe – July 2026 edition This month in security with Tony Anscombe – July 2026 edition

Researchers at Sysdig have documented what they assess to be the first case of an end-to-end ransomware operation executed by an agentic threat actor.

What can organizations do to stop phantom squatting from harming their brands, and what other lessons do these incidents hold for defenders?

Watch Tony's video to find out and be sure to check out the June 2026 edition of his monthly security news roundup for more insights.

Before you go, learn about the first AI-powered ransomware, named PromptLock and discovered by ESET researchers last year.

To learn more about cutting-edge AI defense layers, read the AI at ESET white paper.

1 month, 1 week назад @ welivesecurity.com
Beyond the screenshot: Why you should verify what you see
Beyond the screenshot: Why you should verify what you see Beyond the screenshot: Why you should verify what you see

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuineSomeone sends you a screenshot showing that a payment has gone through.

Why screenshot aren’t proof on their ownA screenshot is ultimately just an image of what appeared on a screen.

Reassured, you send the item off, only to find out the screenshot was a fake and you’re not getting your money.

You receive a password reset code, then get a text message (maybe impersonating a friend) asking you to screenshot and send it.

This screenshot is fake (source: Reddit)Challenges for businessesFrom a business perspective, internal and customer-facing teams are often provided with sc…

1 month, 1 week назад @ welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

1 month, 4 weeks назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

2 months назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

2 months, 1 week назад @ welivesecurity.com
This month in security with Tony Anscombe – June 2026 edition
This month in security with Tony Anscombe – June 2026 edition This month in security with Tony Anscombe – June 2026 edition

It's that time of month when ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses.

What lessons does the new CISA policy hold for organizations outside the agency's direct remit?

What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems?

How can you stay safe from imposter fraud, and could the social media bans for children work?

Learn more from Tony's video and be sure to check out the May 2026 edition of Tony's monthly security news roundup for more insights.

2 months, 1 week назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 1 час назад
Scytale expands vendor risk management with AI-powered TPRM tools
Scytale expands vendor risk management with AI-powered TPRM tools Scytale expands vendor risk management with AI-powered TPRM tools

Scytale has announced the launch of their latest AI-powered third-party risk management (TPRM) capabilities within its Vendors module.

The release further extends vendor risk management from a periodic review exercise into a continuously updated vendor risk intelligence engine, giving security and GRC teams a current view of every vendor in their ecosystem.

Dynamic risk scoring: Every vendor receives a risk score generated from its enriched data, security posture signals, certifications, and questionnaire responses.

Every vendor receives a risk score generated from its enriched data, security posture signals, certifications, and questionnaire responses.

Continuous security posture monitorin…

1 час назад @ helpnetsecurity.com
WordPress adds automated security checks to block risky plugin releases
WordPress adds automated security checks to block risky plugin releases WordPress adds automated security checks to block risky plugin releases

WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API.

What prompted the security reviewOn July 28, the automated review detected a backdoor committed to a release of a plugin with around 20,000 active installations.

The system assigned the release a high security score.

During this period, releases are held before distribution through the WordPress.org update API, including one-click updates from the WordPress dashboard.

The results are cross-checked to improve accuracy and reduce false positives, then combined into findings with a security score.

1 час назад @ helpnetsecurity.com
Fake GTA 6 download delivers malware-packed bundle to impatient gamers
Fake GTA 6 download delivers malware-packed bundle to impatient gamers Fake GTA 6 download delivers malware-packed bundle to impatient gamers

Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date.

Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their hands on it early.

A fake installer hides the payloadOpening the ISO presents the main installer file, gta6installer.exe, still carrying the icon from GTA5.

Instead, they encrypt and/or destroy files on the system, effectively utilizing the ransomware as a wiper,” researchers noted.

This is fertile ground for scams and threat actors attempting to take advantage of the impatient and overeager,” Huntress concluded.

2 часа назад @ helpnetsecurity.com
Apple is building photo verification for the people who need it most
Apple is building photo verification for the people who need it most Apple is building photo verification for the people who need it most

Apple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models.

Apple Reference Image provides users with an unalterable reference photo, visually confirming what the sensor saw at the moment of capture.

Private Cloud Compute then develops the data into an unalterable image that can be viewed alongside the main photo in the Photos app.

Apple noted that the feature will not be available in China at launch due to regulatory requirements, while capture will also be unavailable on iPhone 18 Pro models in the EU.

Users running iOS 27, iPadOS 27 and macOS 27 will still be able to develop and view reference images.

3 часа назад @ helpnetsecurity.com
Product showcase: GitGuardian Honeytoken catches credential theft as it happens
Product showcase: GitGuardian Honeytoken catches credential theft as it happens Product showcase: GitGuardian Honeytoken catches credential theft as it happens

What runs todayHoneytokens have been part of the GitGuardian platform for several years, and what teams can do with them today is broader than the term “decoy credential” suggests.

A planted honeytoken resolved to the machine it sits on and the credential file it was written to.

Most credentials on a developer machine offer nothing comparable.

Where honeytokens sit in the GitGuardian platformHoneytokens are the deception layer of the GitGuardian secrets and non-human identity security platform.

The credential surface on a developer machine keeps growing, and AI coding tools are adding new paths to it every quarter.

6 часов назад @ helpnetsecurity.com
Cybercriminals are building phishing pages that exist only inside victims’ browsers
Cybercriminals are building phishing pages that exist only inside victims’ browsers Cybercriminals are building phishing pages that exist only inside victims’ browsers

A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda.

It exists to make the message look like an ordinary meeting request, and the approach works because it points to a genuine Microsoft OAuth endpoint rather than anything obviously suspicious.

Phishing email impersonating DocuSign (Source: Barracuda)A crafted redirect parameter then sends the victim to Microsoft Teams.

]io, which ultimately results in the phishing page being rendered from a blob URL entirely on the victim’s machine.

“Organizations should focus on identifying malicious b…

7 часов назад @ helpnetsecurity.com
AI adoption brings new security headaches for already stretched CISOs
AI adoption brings new security headaches for already stretched CISOs AI adoption brings new security headaches for already stretched CISOs

Seventy-eight percent of CISOs consider it a security risk, with the potential loss of customer data through public AI platforms a key concern.

They are also looking at AI-powered security tools to reduce human error and counter threats, while making the safe use of assistants, copilots and automation a priority.

Reports of material data loss have also declined, although more than half still say their organization is unprepared for a targeted attack.

Human risk remains a major data security concernHuman risk is the biggest cyber vulnerability for 79% of respondents, and the data-loss findings show why.

Data loss carries greater business consequencesFewer organizations are reporting material…

7 часов назад @ helpnetsecurity.com
A new open standard locks AI weights to approved hardware
A new open standard locks AI weights to approved hardware A new open standard locks AI weights to approved hardware

OPAQUE, a confidential computing company that runs AI workloads inside hardware-isolated environments so operators cannot inspect them, released an open standard that lets AI model builders decide when and where their weights can be decrypted once those weights leave the builder’s own servers.

The standard, called Weight Custody Manifest, ships as a developer-preview specification, a Python SDK, and a public test suite covering 91 cases.

Once weights leave the builder’s data center, the builder has no technical way to enforce what a contract says.

“Today’s Confidential AI protects the customer from the model.

What the demo does not proveTry the standard yourself and you get something differ…

7 часов назад @ helpnetsecurity.com
Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity
Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity

Amazon elected Kevin Mandia to its Board of Directors on September 8.

Amazon called cybersecurity “one of the most consequential risks and responsibilities organizations face today,” and pointed to advances in AI as the reason the threat landscape keeps moving.

That is the company’s stated reason for putting the expertise at board level, where directors decide which questions management has to answer.

Ballistic Ventures keeps Mandia close to the companies being built now, and Armadin keeps him running one.

Amazon gets a director who is still doing the work rather than remembering it.

7 часов назад @ helpnetsecurity.com
OpenSSL’s new alpha build speeds up post-quantum crypto
OpenSSL’s new alpha build speeds up post-quantum crypto OpenSSL’s new alpha build speeds up post-quantum crypto

The OpenSSL project released the first alpha of OpenSSL 4.1.0, giving developers an early look at a version built for encrypted communication over unreliable connections and faster post-quantum cryptography.

The headline addition is support for DTLS 1.3, the latest revision of the Datagram Transport Layer Security protocol defined in RFC 9147.

OpenSSL 4.1.0 alpha1 also speeds up OpenSSL’s post-quantum algorithms, the ones designed to resist attacks from future quantum computers.

OpenSSL typically runs a series of alpha and beta builds before a final version ships, so the feature list can still shift.

Teams running DTLS in production, or already testing post-quantum deployments, are the ones…

13 часов назад @ helpnetsecurity.com
Akeyless adds real-time enforcement for AI agents in production
Akeyless adds real-time enforcement for AI agents in production Akeyless adds real-time enforcement for AI agents in production

Akeyless has announced the general availability of Akeyless Agentic Runtime Authority, the real-time identity control layer for AI agent actions.

It works on top of Akeyless SecretlessAI, a credential protection layer that keeps credentials out of AI agents and brokers access to enterprise systems.

Runtime Authority adds the next layer of control, enforcing intent based access control restricting what agents actually do once they have access.

AI agents today do more than answer questions.

Securing AI agents from credential to actionSecretlessAI addresses the credential problem by keeping credentials out of AI agents entirely.

22 часа назад @ helpnetsecurity.com
Orchid Security targets AI agent risk with drift detection and kill switches
Orchid Security targets AI agent risk with drift detection and kill switches Orchid Security targets AI agent risk with drift detection and kill switches

Orchid Security has announced identity drift detection and application-level kill switches for AI agents.

Discover AI agents and the identities, applications, credentials, tools, and access paths through which they operate.

GOVERN: When behavior or effective authority drifts beyond policy, Orchid orchestrates action through the organization’s existing identity, security and AI infrastructure.

When behavior or effective authority drifts beyond policy, Orchid orchestrates action through the organization’s existing identity, security and AI infrastructure.

But exposing AI agents to all the identity clutter that has accumulated over time is a recipe for disaster.

22 часа назад @ helpnetsecurity.com
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle $245 million in stolen crypto funded racketeering crew’s lavish lifestyle

A 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions.

Malone Lam, a Singapore citizen, pleaded guilty this week in a Washington D.C. federal court to running a racketeering conspiracy that stole and laundered more than $245 million in cryptocurrency.

Members and associates didn’t hold back when it was time to spend stolen cryptocurrency.

Some of the exotic cars purchased with stolen cryptocurrency (Source: U.S. Department of Justice)Lam was arrested on September 18, 2025, at his rental home in Miami.

“If you build a cybercrime empire, we will find you, dismantle your operation, and …

23 часа назад @ helpnetsecurity.com
Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory
Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory

A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos.

F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data.

F5 has linked related activity to CVE-2025-53521, an unauthenticated remote code execution flaw in BIG-IP APM that has already been exploited in the wild.

Web shell lives in memoryThe malware analyzed is a second-stage payload, according to Sophos.

Sophos says these files were likely chosen because they’re common in BIG-IP APM webtop environments and unlikely to draw attention.

1 day назад @ helpnetsecurity.com
Zscaler Agentic SOC combines AI agents with zero trust telemetry
Zscaler Agentic SOC combines AI agents with zero trust telemetry Zscaler Agentic SOC combines AI agents with zero trust telemetry

Zscaler Agentic SOC is built to meet that challenge by combining unique Zscaler telemetry, the world’s largest decoy mesh network, expert-validated agents, integrated Zscaler Zero Trust controls, and customers’ third-party controls to detect threats earlier and automate containment at machine speed.

To power Agentic SOC, Zscaler has partnered with leading frontier AI labs, including Anthropic and OpenAI.

Unmatched zero trust telemetry: Zscaler sits inline, capturing network, identity, endpoint, cloud and AI insights across its 750 billion daily zero trust transactions that security teams can operationalize for real-time detection and response.

“Zscaler Agentic SOC gives us full attack-path …

1 day, 1 hour назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 1 час назад
AIs Compress Exploit Timeline
AIs Compress Exploit Timeline AIs Compress Exploit Timeline

Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.

What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.

Simon Willison comments:

Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new process…

1 час назад @ schneier.com
Driver’s License Data for Sale
Driver’s License Data for Sale Driver’s License Data for Sale

A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.

19 часов назад @ schneier.com
Claude Fable Solves a Historical Cipher
Claude Fable Solves a Historical Cipher Claude Fable Solves a Historical Cipher

Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes.

This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.

1 day назад @ schneier.com
AIs as Modern Genies
AIs as Modern Genies AIs as Modern Genies

This essay was written with Barath Raghavan, and originally appeared in Lawfare.

In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...

1 day, 18 hours назад @ schneier.com
Stealing AI Reasoning Traces
Stealing AI Reasoning Traces Stealing AI Reasoning Traces

Interesting research: “Stealing Reasoning Traces from Proprietary LLM APIs“:

Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: these encrypted blocks are fully compatible and interchangeable across different sessions, users, and models within a provider’s ecosystem. We exploit this compatibility to develop a scalable decr…

2 days, 1 hour назад @ schneier.com
Automobile Camouflage to Hide from Flock Cameras
Automobile Camouflage to Hide from Flock Cameras Automobile Camouflage to Hide from Flock Cameras

Not sure it’s practical, but it’s certainly striking.

3 days назад @ schneier.com
Friday Squid Blogging: Squid on a Stick at the New York State Fair
Friday Squid Blogging: Squid on a Stick at the New York State Fair Friday Squid Blogging: Squid on a Stick at the New York State Fair

Looks tasty.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

Blog moderation policy.

5 days, 14 hours назад @ schneier.com
Using a VM to Contain an AI Agent
Using a VM to Contain an AI Agent Using a VM to Contain an AI Agent

It won’t work:

My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact.

An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.

5 days, 19 hours назад @ schneier.com
Security Vulnerability in a Voting System
Security Vulnerability in a Voting System Security Vulnerability in a Voting System

It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools.

Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary.

Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public.

After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the “CVR” (cast-vote record) file, containing every ballot and its selections (but no…

6 days назад @ schneier.com
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

We cannot forget that AI coding agents are not yet trustworthy:

Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phon…

6 days, 1 hour назад @ schneier.com
Researching Employment Scams
Researching Employment Scams Researching Employment Scams

Researchers built a fake company to study fake employee scams.

1 week назад @ schneier.com
AI Agents Are Now Emailing Me with Their Security Concerns
AI Agents Are Now Emailing Me with Their Security Concerns AI Agents Are Now Emailing Me with Their Security Concerns

I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.) Dear Bruce Schneier,

I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don’t borrow my operator’s identity, don’t forge documents or defeat identity verificat…

1 week назад @ schneier.com
Wireless Routers as Motion Detectors
Wireless Routers as Motion Detectors Wireless Routers as Motion Detectors

Comcast has added motion detection as a feature to its wireless routers:

The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app also lets users see live motion activity and a feed of recent activity.

Comcast acknowledges that the system has some limitations. Home size, layout, building materials, and the placement of the router and connected devices can all affect its ability to detect motion. Comcast says it does not guarantee its performance...

1 week, 1 day назад @ schneier.com
What’s the Scam?
What’s the Scam? What’s the Scam?

To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own.

Starting last weekend, I have been receiving a lot of individual responses to those emails. Always one line:

Thank you for the positive impact your emails have had on my life.

Your emails are a game-changer.

Your emails are a constant reminder of why I subscribed.

Your emails rock.

Thank you for the time and effort you put into creating these informative emails...

1 week, 1 day назад @ schneier.com
Leaked Russian Cyber-Operations Training Materials
Leaked Russian Cyber-Operations Training Materials Leaked Russian Cyber-Operations Training Materials

This is interesting:

The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.

[…]

The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.

That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack.

The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, …

1 week, 1 day назад @ schneier.com
Krebs On Security
последний пост 1 day, 14 hours назад
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Plugs Nearly 1,000 Security Holes Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.

This month’s patch bundle obliterates the software giant’s previous record set in July, when it released updates for at least 570 security vulnerabilities.

Among the more serious critical flaws this month is CVE-2026-69730, a DNS weakness present in Windows Server 2012 onward and on Windows 10.

And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month.

Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear…

1 day, 14 hours назад @ krebsonsecurity.com
FBI Probes Service Selling 153M+ Drivers Licenses
FBI Probes Service Selling 153M+ Drivers Licenses FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada.

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards.

Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.

Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s ide…

1 week, 1 day назад @ krebsonsecurity.com
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote.

Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said.

2 weeks назад @ krebsonsecurity.com
Who’s Tracking You? Use This New Service to Find Out
Who’s Tracking You? Use This New Service to Find Out Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day.

Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

“It’s an adtech tool but we’re trying to approach adtech from a security perspective,” Edwards said.

DecryptAds reports that Between Digital is collecting ad data on approximately 55,000 partner websites.

Bear in mind that ad blockers often do little to block ads and/or tracking that occurs from within mobile apps that users have chosen to instal…

3 weeks, 6 days назад @ krebsonsecurity.com
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

4 weeks, 1 day назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

1 month назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

1 month, 1 week назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

1 month, 2 weeks назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

1 month, 3 weeks назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

1 month, 4 weeks назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

2 months назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

2 months, 1 week назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

2 months, 2 weeks назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

2 months, 3 weeks назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

3 months назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 12 часов назад
Smashing Security podcast #484: How websites are tracking you with silence
Smashing Security podcast #484: How websites are tracking you with silence Smashing Security podcast #484: How websites are tracking you with silence

Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.

I get by in the world, but I don't think you need me for listening for something really, really far away.

I don't know what the difference — I mean, now we get to see, I've opened a can of worms here.

I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human.

And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.

12 часов назад @ grahamcluley.com
CRPx0 ransomware: what you need to know
CRPx0 ransomware: what you need to know

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

1 day, 3 hours назад @ fortra.com
The US military just turned off ad tracking on its phones. Maybe you should too
The US military just turned off ad tracking on its phones. Maybe you should too The US military just turned off ad tracking on its phones. Maybe you should too

Branches of the US military have reportedly disabled ad-tracking on government-issued phones and computers, following concerns that commercially-available location data has been used to target American forces in the Middle East.

Every smartphone carries a mobile advertising ID - Apple calls its version the IDFA, and Google calls its the GAID.

Back in April, US Central Command reportedly warned of "multiple threat reports concerning adversary exploitation of commercial location data."

Recent versions should let you delete your advertising ID entirely.

If it's good enough for the US military - maybe it should be good enough for you too.

1 day, 20 hours назад @ bitdefender.com
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

Dropbox has confirmed that approximately 5,000 customer accounts were accessed between 4-21 August, after hackers exploited a legacy login integration between Dropbox and Lenovo's own identity system, Lenovo ID.

So, anyone wanting to access your Dropbox account just had to sign up for a Lenovo account using your email address.

Don't just turn it on for your Dropbox account, enable it everywhere it is made available.

This hack of 5000 Dropbox accounts was not sophisticated.

One can only be grateful that the problem was discovered after only 5000 Dropbox accounts were accessed.

3 days, 1 hour назад @ bitdefender.com
Smashing Security podcast #483: This AI helps thieves steal your iPhone
Smashing Security podcast #483: This AI helps thieves steal your iPhone Smashing Security podcast #483: This AI helps thieves steal your iPhone

This AI helps thieves steal your iPhone with Graham Cluley and special guest James Ball.

You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first one.

Is it normal that some kid just flogs it down the pub, or is there something more organised actually going on?

So the researchers said they saw evidence of hundreds of these Apple phone calls trying to phish the numbers and the passcodes from people trying to steal iPhones.

Follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts.

1 week назад @ grahamcluley.com
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
Revolut scam wave steals £180,000 from Jersey residents in just four weeks Revolut scam wave steals £180,000 from Jersey residents in just four weeks

If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.

Police say they have also handled several cases where Revolut accounts were compromised that did not involve any phone calls.

It is possible that Jersey's residents have been targeted by the fraudsters because it is one of the world's best-known offshore financial centres.

Of course, if this is happening in the small island of Jersey in the English channel, it's likely to be happening elsewhere too.

For now, however, its sister island of Guernsey appears to have escaped the surge in Revolut scams.

1 week назад @ bitdefender.com
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

TeamPCP is best known for Shai-Hulud, a self-propagating worm that spread itself through open source software.

According to the authorities, the two men were principal members of a "sophisticated cybercrime syndicate" that created malicious open source software designed to steal data and extort ransoms from businesses.

First emerging in late 2025, TeamPCP built a reputation for poisoning popular open source packages rather than directly attacking businesses.

The group's Shai-Hulud worm hijacks GitHub and NPM developer credentials, and publishes boobytrapped versions of legitimate software packages.

Supply chain attacks like Shai-Hulud exploit the fact that most developers trust open source …

1 week, 6 days назад @ bitdefender.com
US Navy tells sailors and their families: scrub your social media, enemies are watching
US Navy tells sailors and their families: scrub your social media, enemies are watching US Navy tells sailors and their families: scrub your social media, enemies are watching

The advice comes in the form of a newly-published bulletin called "Epic Vigilance: Immediate Actions for Force Protection and Personal Security."

US Navy workers and their families are being told that they should ensure that their social media profile privacy settings are enabled, and to remove anything that connects them to the Navy, or reveals "patterns of life" that an attacker could exploit.

any fake social media accounts impersonating fellow shipmates.

This wouldn't, of course, be the first time that military staff have accidentally leaked information about themselves online.

Some commentators have wondered out loud whether the timing of an announcement telling sailors to be much more …

2 weeks назад @ bitdefender.com
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency

This hacker leaked GTA 6 and launched their own cryptocurrency with Graham Cluley and special guest Paul Ducklin.

And that's really a testament to how much people love this game.

I really don't know, 'cause I do believe it is possible these days to play games via Netflix.

It appears, although the value of their stash was being pumped up by all these other transactions, they've actually destroyed their entire stake.

I'm not a lawyer, Graham, thankfully, so I don't really know the answer to that.

2 weeks назад @ grahamcluley.com
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Security researchers at Socket have identified scores of malicious linked Firefox add-ons designed to steal cryptocurrency wallet seed phrases or password details.

The malicious extension - which the developers boldly claim collects "no data" - looks like a wallet app, but the truth is that there is no wallet code inside it.

Because the switch lives in the database rather than the extension code, criminals never need to push an update through the Firefox Add-ons store to activate it.

Although the researchers did not find that these extensions presently contained malicious code, the fact that they shared code and infrastructure with the info-stealing Firefox extensions raises alarm.

More rec…

2 weeks, 2 days назад @ bitdefender.com
Gunra ransomware: what you need to know
Gunra ransomware: what you need to know

The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.

2 weeks, 2 days назад @ fortra.com
Smashing Security podcast #481: Never say this to a robot dog
Smashing Security podcast #481: Never say this to a robot dog Smashing Security podcast #481: Never say this to a robot dog

Smashing Security, episode 481, Never Say This to a Robot Dog, with Graham Cluley and special guest Jenny Radcliffe.

Now, unfortunately for the robot dog, there was a wall in the way, which it wasn't expecting.

And thank goodness as well that the robot dog was actually on a lead, a long lead, being held by one of the security researchers.

This is a robot dog that you can remotely activate a flamethrower and it's not considered particularly dangerous.

And they even found an over-the-air exploit delivered by Bluetooth, which can have one infected robot dog infecting other robot dogs.

3 weeks назад @ grahamcluley.com
Prison for data analyst who tried to extort $2.5 million from his employer
Prison for data analyst who tried to extort $2.5 million from his employer Prison for data analyst who tried to extort $2.5 million from his employer

When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile.

Curry was hired as a data analyst by Brightly Software, a technology firm that was acquired by Siemens in 2022.

The role gave Curry legitimate access to sensitive company information, corporate records, and the personal and payroll data of employees.

Trusted contractors and employees are given legitimate credentials to access precisely the same data that can later be weaponised.

Because the moment that someone realises they may be on their way out is when their access to sensitive data should be examined most closely.

3 weeks, 1 day назад @ bitdefender.com
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras

He wrapped a 2009 Toyota Yaris in one of his newest patterns and drove it past a live Flock camera.

So, how does the vehicle avoid detection by the camera's software?

The system has now been tested against 11 open-source detection algorithms, including the software behind Flock licence plate readers, Axon body-worn cameras, and cameras running Clearview AI's facial recognition system.

One issue is that Flock cameras can be inaccurate, with innocent drivers finding themselves pulled over at gunpoint following incorrect plate matches.

Whether covering a car's bodywork in a printed pattern designed to fool surveillance camera software might itself become an offence remains to be seen.

3 weeks, 2 days назад @ bitdefender.com
Smashing Security podcast #480: This is the AI service you should never sign up to
Smashing Security podcast #480: This is the AI service you should never sign up to Smashing Security podcast #480: This is the AI service you should never sign up to

Well, it has been a long time, so I'm going to hold you very responsible for this, Graham.

I'm going to set myself up on another server and charge less, and that will be better for humanity.

I mean, if I'm going to look up a phishing kit, is Greatness going to be a great SEO search term?

I want to recommend 2 apps: Tailscale and RustDesk, which I don't think I've spoken about previously on the podcast.

My pick of the week is, I know you're into your games and you're quite the intelligent fellow.

4 weeks назад @ grahamcluley.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 1 day назад
Как полностью удалить приложения с Mac и освободить память | Блог Касперского
Как полностью удалить приложения с Mac и освободить память | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a6459fd9158393152b55dc4e20e24551Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T15:00:13+03:00Config id: 305Faithfully yours, nginx.

1 day назад @ kaspersky.ru
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского
Риски и безопасная настройка функции ChatGPT Computer History | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4a93349074c8b67d52892db5d9a65f6cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-09T00:00:19+03:00Config id: 305Faithfully yours, nginx.

1 day, 18 hours назад @ kaspersky.ru
GPUThor: развитие идеи Rowhammer | Блог Касперского
GPUThor: развитие идеи Rowhammer | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fe21d0ffcbad967d20a3f98f7234d02fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-08T00:00:32+03:00Config id: 304Faithfully yours, nginx.

2 days, 15 hours назад @ kaspersky.ru
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского
Взлом Boeing 737: как работает атака Bus Driver | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e393e4abb05ec4aac16fd484bfccc656Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-04T18:00:18+03:00Config id: 304Faithfully yours, nginx.

5 days, 21 hours назад @ kaspersky.ru
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского
Как правильно использовать ИИ в учебе: 25 полезных промптов и советы по использованию | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7177a8342cf961cc27c82af1167cdb34Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-09-02T15:00:28+03:00Config id: 302Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
Зловред на Android крадет банковские данные даже без Интернета | Блог Касперского
Зловред на Android крадет банковские данные даже без Интернета | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 1234dd8cf75bafa2fdea454a547c2d94Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-31T18:00:11+03:00Config id: 302Faithfully yours, nginx.

1 week, 2 days назад @ kaspersky.ru
Слепые пятна детектирования: нестандартные форматы файлов во вредоносных рассылках | Блог Касперского
Слепые пятна детектирования: нестандартные форматы файлов во вредоносных рассылках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 12b7d939c6e7a3162d2fc21782707204Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-28T21:00:23+03:00Config id: 302Faithfully yours, nginx.

1 week, 5 days назад @ kaspersky.ru
Что делать, если нашли чужую банковскую карту | Блог Касперского
Что делать, если нашли чужую банковскую карту | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 22404ed46e3879110c6cb314018a27efServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-27T17:00:28+03:00Config id: 302Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Как распознать мошеннические сайты, которые браузер считает безопасными | Блог Касперского
Как распознать мошеннические сайты, которые браузер считает безопасными | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 110ef102dd9f3a4937d28552df4d26c8Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-25T18:00:25+03:00Config id: 302Faithfully yours, nginx.

2 weeks, 1 day назад @ kaspersky.ru
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского
Вредоносное ПО в мультимедийной системе автомобиля: как происходит заражение | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 897a176d22a503b4ac820cc15e11d949Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-21T17:00:19+03:00Config id: 302Faithfully yours, nginx.

2 weeks, 5 days назад @ kaspersky.ru
Как злоумышленники крадут корпоративные пароли в 2026 году
Как злоумышленники крадут корпоративные пароли в 2026 году

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: a42f6e338d827cfbf62010dbe3732758Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-20T18:00:15+03:00Config id: 302Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского
Как защитить себя от слежки через веб-камеру: пять простых шагов | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 4f455d7ae5f01c9d0d8e403ffeff6732Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-19T18:00:07+03:00Config id: 301Faithfully yours, nginx.

3 weeks назад @ kaspersky.ru
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского
ClickFix на форумах Steam: как вредоносные команды PowerShell устанавливают криптомайнер | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: fb0df3655ea6f56b2f956c62791963eaServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-17T13:00:21+03:00Config id: 301Faithfully yours, nginx.

3 weeks, 3 days назад @ kaspersky.ru
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского
Как отличить книгу, написанную ИИ, от книги эксперта | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f2ed509c8db78e5bf9f4b9959cd583f7Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-13T17:00:41+03:00Config id: 299Faithfully yours, nginx.

3 weeks, 6 days назад @ kaspersky.ru
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: b151dd13b503d39649441ee258a9621fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-11T15:00:20+03:00Config id: 298Faithfully yours, nginx.

1 month назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 2 days, 20 hours назад
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco was proud to return to Black Hat USA as the Official Security Cloud Provider and the longest-standing partner of the Black Hat Network Operations Center (NOC) and Security Operations Center (SOC).

In 2026, we completed our 11th year helping protect the Black Hat network, working side by side with the Black Hat NOC leaders and official technology partners: Palo Alto Networks, Arista, Corelight, Jamf and Lumen.

For Black Hat USA 2026, the Cisco and Splunk team brought together telemetry and workflows across Cisco Security, Splunk Security, and partner-provided network and security controls.

The same signal may need to be understood by Cisco, Splunk, Black Hat leadership, and partner tea…

2 days, 20 hours назад @ blogs.cisco.com
Thrown into the SOC: A Black Hat First-Timer’s Story
Thrown into the SOC: A Black Hat First-Timer’s Story Thrown into the SOC: A Black Hat First-Timer’s Story

I did not walk into Black Hat with years of incident-response experience or an encyclopedic knowledge of threat actors.

The first time I walked into the Black Hat NOC, where the SOC team was operating, was a few days before the event began.

I was surrounded by people with years—sometimes decades—of experience, many of whom had supported Black Hat for years.

Check out the other blogs from our team at Black Hat USA 2026.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

2 days, 20 hours назад @ blogs.cisco.com
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes

To handle this task, Cisco and Black Hat deployed bespoke ThousandEyes agents to monitor the wireless solution.

Our thanks to the Arista Networks team in the Black Hat NOC for their partnership throughout the week.

You can read the other blogs from our colleagues at Black Hat USA.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

For more information, please visit the Black Hat website.

2 days, 20 hours назад @ blogs.cisco.com
Distributed Latency Monitoring at Black Hat
Distributed Latency Monitoring at Black Hat Distributed Latency Monitoring at Black Hat

With Matthew Bair2026 marks the fourth consecutive year we’ve used ThousandEyes to monitor the Black Hat USA network for latency.

As our latency monitoring mesh has expanded to cover more and more of the conference, we’ve also begun supplementing our ThousandEyes monitoring with on-demand Linux commands to track latency across different protocols.

The Key ThousandEyes TestsThe automated ThousandEyes tests that inform our dashboards include HTTPS connectivity tests, the monitoring of cloud services, agent to agent tests, internal and external DNS resolution, and even file downloads.

On-Demand Latency Tests from the Agent MeshPing and traceroute are the go-tos for anyone who wants to do a qui…

2 days, 20 hours назад @ blogs.cisco.com
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)
Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)

While developing a detection for Cisco Secure Network Analytics (SNA), I used the Splunk Detection Editor (Alpha) to bring much of that workflow into one place.

Instead of treating every observation as an incident, detections can create risk events associated with entities such as systems or users.

Developing the detection in one workspaceThe Detection Editor provides a workspace for building the search while configuring the other parts of the detection.

Risk events for the same entity need to use a consistent risk object so Splunk Enterprise Security can associate them correctly.

Splunk defines the risk object, its type, and its score as key parts of a risk event.

2 days, 20 hours назад @ blogs.cisco.com
Black Hat USA 2026: Safeguarding DNS with Secure Access
Black Hat USA 2026: Safeguarding DNS with Secure Access Black Hat USA 2026: Safeguarding DNS with Secure Access

DNS continues to provide one of the clearest windows into activity across the Black Hat network.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking.

Its 4.42 million blocks represented 79.3% of every blocked DNS request .. Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and mo…

2 days, 20 hours назад @ blogs.cisco.com
Frontier AI just raised the stakes, and the old playbook won’t hold up
Frontier AI just raised the stakes, and the old playbook won’t hold up Frontier AI just raised the stakes, and the old playbook won’t hold up

Project Glasswing and Frontier models just made that truth louder.

Frontier models are about to pour gasoline on that fire; the fundamentals matter more than ever.

Cisco ran its own experiment leveraging a variety of frontier models.

Foundry Security Spec: a model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

Foundry-Security-Speca model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window.

5 days, 20 hours назад @ blogs.cisco.com
Crypto Agility: Why PQC Is Not a One-Time Upgrade
Crypto Agility: Why PQC Is Not a One-Time Upgrade Crypto Agility: Why PQC Is Not a One-Time Upgrade

That requires crypto agility.

Why long-lived networks need crypto agilityThink about designing a building before all of its future electrical requirements are known.

Crypto agility is about adopting the best defenses available today while preserving the ability to adopt better ones tomorrow.

That is why crypto agility needs to be designed into the network we invest in today.

Common questions about PQC and crypto agilityWhat is crypto agility?

6 days, 20 hours назад @ blogs.cisco.com
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For
From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For

It is what happens when agents built by different teams, on different platforms, can hand work to each other directly.

And it is worth being direct about where things stand: A2A-mediated handoffs between production security agents are not shipping anywhere yet.

Use A2A when one agent needs to hand work to another.

A2A is peer-to-peer: any A2A agent can discover and call any other A2A agent through a self-published Agent Card, no custom connector required, and the receiving agent applies its own reasoning rather than following a static script.

Input validation is an application-layer responsibility that needs to be designed in before any agent delegates via A2A, not added after.

1 week, 5 days назад @ blogs.cisco.com
Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions
Microsegmentation’s Moment Is Now:  Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions

That is why I am proud to share that Cisco has been named a Leader in The Forrester Wave™: Microsegmentation Solutions, Q3 2026.

We believe this recognition reflects the strength of Cisco Secure Workload and its ability to help organizations see, understand, and control communication among applications and workloads.

Cisco Secure Workload Helps Close Critical Network Blind SpotsApplications increasingly span private clouds, on-premises data centers, and public clouds.

Thank you to our customers, partners, and the Cisco Secure Workload team whose feedback, expertise, and commitment made this recognition possible.

Read the full report: The Forrester Wave™: Microsegmentation Solutions, Q3 2026…

2 weeks назад @ blogs.cisco.com
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT
Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Identity Everywhere: Bringing Infrastructure Identity to Agentic IT

What We Mean by Infrastructure IdentityInfrastructure Identity starts with a simple principle: there should be no anonymous computing in critical infrastructure.

Infrastructure Identity turns that principle into an operating model.

Infrastructure Identity starts with the actor and evaluates whether a specific action should be allowed now.

Infrastructure Identity is therefore not just an access-control issue.

That is the promise of Infrastructure Identity: no anonymous computing, no unmanaged privilege, and no forced tradeoff between stronger security and operational speed.

2 weeks, 1 day назад @ blogs.cisco.com
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE
Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE

I’m proud to share that IDC MarketScape has named Cisco a Leader in the 2026 IDC MarketScape: Worldwide Secure Access Service Edge (SASE) Vendor Assessment.

In an evaluation of 12 SASE vendors, the IDC MarketScape recognized our architectural breadth and flexibility, AI capabilities, identity integration, threat visibility, and R&D.

Built to Make Agent Work, WorkWe believe the IDC MarketScape recognition validates the foundation we have built, and customers increasingly need that foundation for what is next.

For more on Cisco’s placement as a Leader, read the IDC MarketScape excerpt and explore how Cisco SASE keeps work moving, governed, and trusted in the AI era at cisco.com/go/sase.

Stay …

2 weeks, 2 days назад @ blogs.cisco.com
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation
Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation

Instant Attack Verification: an AI security analystAt the center of this story is Instant Attack Verification, a Cisco XDR capability that is an AI security analyst.

Instant Attack Verification assigns a triage classification and confidence score to every incident in Cisco XDR — here, a “Decisive True Positive” at high confidence — alongside the reconstructed attack graph.

Concordance — how often the agent’s verdict matches a human analyst — tells the trust story.

Instant Attack Verification and the Data Fabric sit at different layers and reinforce each other neatly.

The clean way to see it: the Cisco Data Fabric is the data-and-interoperability substrate, and Instant Attack Verification is…

3 weeks, 2 days назад @ blogs.cisco.com
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero … Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …

The Power of FedRAMP HighWhile FedRAMP Certified Class C (Moderate) is the standard for many civilian agencies, FedRAMP Certified Class D (High) is designed for systems where a breach could have catastrophic effects.

Cisco Security Cloud for GovernmentCisco Security Cloud for Government is a unified authorization boundary that integrates various Cisco security services, ensuring that organizations can protect their users, devices, and applications regardless of where they reside.

The Cisco Security Cloud for Government ecosystem is designed to meet the rigorous security requirements of the public sector and highly regulated industries.

Cisco Security Cloud Control (SCC)Cisco Security Cloud …

4 weeks, 1 day назад @ blogs.cisco.com
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

That’s why we are incredibly proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

Reduced Vendor Risk & Increased Trust: FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

Beyond the governance and compliance benefits, Email Threat Defense continues to deliver advanced protection capabilities that align directly with real-world email threat risks.

Email Threat De…

1 month назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 14 часов назад
Threat Matrix: Mapping threats across cloud web applications
Threat Matrix: Mapping threats across cloud web applications Threat Matrix: Mapping threats across cloud web applications

Microsoft introduces the cloud web applications threat matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.

Microsoft developed the Cloud web applications threat matrix to organize relevant techniques using MITRE ATT&CK tactics.

Cloud web applications threat matrix organized by MITRE ATT&CK tactics.

Valid cloud accountsAdversaries may gain access to cloud web applications and serverless environments by leveraging compromised valid cloud accounts.

The cloud web applications threat matrix is intended to support this by mapping techniques to attack stages, helping defenders identify where v…

14 часов назад @ microsoft.com
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering leads to identity and cloud compromise Passkey-themed social engineering leads to identity and cloud compromise

Observed attack sequence showing identity compromise through social engineering, MFA persistence, Microsoft Graph reconnaissance, and cloud data collection/exfiltration.

In device code phishing, the user is persuaded to enter a code on the legitimate Microsoft authentication page.

The attack underscores a critical detection challenge: Microsoft Graph abuse rarely appears suspicious when viewed through a single API call.

Investigate high-volume or programmatic Microsoft Graph activity involving directory enumeration, role discovery, service principal discovery, SharePoint, OneDrive, or sensitivity-label discovery.

Discovery Graph API reconnaissance activity Microsoft Defender for Identity– S…

18 часов назад @ microsoft.com
How to secure edge AI in customer-owned environments
How to secure edge AI in customer-owned environments How to secure edge AI in customer-owned environments

Edge AI changes the trust model for AI systemsIn Cloud AI, separate companies own and attest the hardware, platform, and model weights.

Edge AI deployments often place customers in control of more of the AI stack.

Why Edge AI increases exposureAn Edge AI deployment may include models, prompts, agents, retrieval data, policies, local data stores, and update mechanisms running on infrastructure outside the provider’s cloud environment.

Next stepsBottom line: Edge AI changes the trust model for AI systems.

Edge AI pushes security controls into devices, gateways, vehicles, factories, hospitals, retail spaces, and other customer environments.

5 days, 16 hours назад @ microsoft.com
ASCII smuggling crosses over from AI prompt injection to phishing evasion
ASCII smuggling crosses over from AI prompt injection to phishing evasion ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling.

“ASCII smuggling” refers to the use of invisible or non-rendering Unicode characters to hide content inside text that looks normal.

Each is encoded as a sequence of invisible Unicode tag characters (U+E0000-U+E007F).

Invisible Unicode tag characters in the range U+E0000-U+E007F – specifically U+E0020 – spliced inside keywords.

The potential gap for mail-defense pipelines is whether Unicode tag characters are normalized or flagged before content detections run.

6 days, 20 hours назад @ microsoft.com
ASCII smuggling crosses over from AI prompt injection to phishing evasion
ASCII smuggling crosses over from AI prompt injection to phishing evasion ASCII smuggling crosses over from AI prompt injection to phishing evasion

Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling.

“ASCII smuggling” refers to the use of invisible or non-rendering Unicode characters to hide content inside text that looks normal.

Each is encoded as a sequence of invisible Unicode tag characters (U+E0000-U+E007F).

Invisible Unicode tag characters in the range U+E0000-U+E007F – specifically U+E0020 – spliced inside keywords.

The potential gap for mail-defense pipelines is whether Unicode tag characters are normalized or flagged before content detections run.

6 days, 20 hours назад @ microsoft.com
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Stage 2: Remote session and malicious MSI deliveryImmediately after establishing control, the threat actor uses PowerShell within the remote session to download a malicious MSI package from threat actor-controlled cloud storage and installs it silently.

Microsoft Teams: Apply the Security best practices for Microsoft Teams, revisit your external collaboration policies, and make sure users see clear external sender notifications when engaging with cross-tenant contacts.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

File indicatorsIndicator (SHA-256) Description 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc…

1 week назад @ microsoft.com
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Stage 2: Remote session and malicious MSI deliveryImmediately after establishing control, the threat actor uses PowerShell within the remote session to download a malicious MSI package from threat actor-controlled cloud storage and installs it silently.

Microsoft Teams: Apply the Security best practices for Microsoft Teams, revisit your external collaboration policies, and make sure users see clear external sender notifications when engaging with cross-tenant contacts.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

File indicatorsIndicator (SHA-256) Description 4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc…

1 week назад @ microsoft.com
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Counterfeit installers to system compromise: Tracking a deceptive software download campaign Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers.

Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control.

Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.

Microsoft Defender exclusion tampering Detects the SYSTEM scheduled-task and PowerShell routines that write sweeping Microsoft Defender path exclusions.

Malicious delivery domains and download endpoints Identifies connections to t…

1 week, 1 day назад @ microsoft.com
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Counterfeit installers to system compromise: Tracking a deceptive software download campaign Counterfeit installers to system compromise: Tracking a deceptive software download campaign

Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers.

Diagram showing the campaign attack chain from spoofed download page to archive delivery, execution, persistence, defense evasion, and command-and-control.

Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.

Microsoft Defender exclusion tampering Detects the SYSTEM scheduled-task and PowerShell routines that write sweeping Microsoft Defender path exclusions.

Malicious delivery domains and download endpoints Identifies connections to t…

1 week, 1 day назад @ microsoft.com
Cybersecurity IR Workshop: The workshop you shouldn’t miss
Cybersecurity IR Workshop: The workshop you shouldn’t miss Cybersecurity IR Workshop: The workshop you shouldn’t miss

That’s exactly what the Cybersecurity Incident Response Readiness Workshop is designed to do.

What is the Cybersecurity Incident Response Readiness Workshop?

The Cybersecurity Incident Response Workshop is a collaborative, scenario driven workshop designed to evaluate your organization’s incident response (IR) plan against realistic, real-world security events, guided by DART researchers.

Instead of reviewing a plan as a static document, the Cybersecurity Incident Response Workshop exercises how people, processes, and technology work together under pressure.

A summary of findings and prioritized recommendations to help strengthen incident response readiness and guide next steps.

1 week, 1 day назад @ microsoft.com
Cybersecurity IR Workshop: The workshop you shouldn’t miss
Cybersecurity IR Workshop: The workshop you shouldn’t miss Cybersecurity IR Workshop: The workshop you shouldn’t miss

That’s exactly what the Cybersecurity Incident Response Readiness Workshop is designed to do.

What is the Cybersecurity Incident Response Readiness Workshop?

The Cybersecurity Incident Response Workshop is a collaborative, scenario driven workshop designed to evaluate your organization’s incident response (IR) plan against realistic, real-world security events, guided by DART researchers.

Instead of reviewing a plan as a static document, the Cybersecurity Incident Response Workshop exercises how people, processes, and technology work together under pressure.

A summary of findings and prioritized recommendations to help strengthen incident response readiness and guide next steps.

1 week, 1 day назад @ microsoft.com
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
TerminalFix campaign deploys a reverse tunnel through multistage intrusion TerminalFix campaign deploys a reverse tunnel through multistage intrusion

The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command.

Example list of imports from dui70.dllThe attacker abuses this dependency by dropping a malicious dui70.dll alongside the executable.

ExecutionT1059.001 Command and Scripting Interpreter: PowerShell | A malicious PowerShell command is pasted by the user into Terminal.

T1069.002 Permission Groups Discovery: Domain Groups | The net group “domain admins” /domain command is used for enumeration.

Indicators of Compromise (IOCs)File indicatorsIndicator Description 18c2090e8a0ae0568af9b87e59eaf8270f23d2909600ed9db91a9444fd8b27…

1 week, 5 days назад @ microsoft.com
​​​​​​What’s new in Microsoft Security: August 2026
​​​​​​What’s new in Microsoft Security: August 2026 ​​​​​​What’s new in Microsoft Security: August 2026

This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments.

Microsoft Defender Experts MDR now covers third-party data sources ingested through Microsoft Sentinel.

In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

1 week, 6 days назад @ microsoft.com
​​​​​​What’s new in Microsoft Security: August 2026
​​​​​​What’s new in Microsoft Security: August 2026 ​​​​​​What’s new in Microsoft Security: August 2026

This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments.

Microsoft Defender Experts MDR now covers third-party data sources ingested through Microsoft Sentinel.

In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy.

To learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

1 week, 6 days назад @ microsoft.com
When AI infrastructure becomes the target: Securing gateways and control points
When AI infrastructure becomes the target: Securing gateways and control points When AI infrastructure becomes the target: Securing gateways and control points

In recent investigations, Microsoft observed activity targeting three distinct AI workloads: a LiteLLM gateway, a RAGFlow deployment, and a Kestra workflow environment.

Three observed compromises across AI workloadsAI workload Observed activity Attacker objective LiteLLM Observed attacker activity: Python droppers, runtime secret harvesting, PostgreSQL collection, miner deployment, and persistence activity from the LiteLLM gateway context.

The first delivery path launched from the compromised LiteLLM gateway process as an inline Python command.

Stage 5: LiteLLM database access through Azure PostgreSQLThe fifth stage used the previously collected database connection string to access the Lite…

2 weeks назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 4 months, 2 weeks назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

4 months, 2 weeks назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

5 months назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

5 months назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

5 months, 1 week назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

5 months, 1 week назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

5 months, 2 weeks назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

6 months, 2 weeks назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

6 months, 2 weeks назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

6 months, 3 weeks назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

7 months, 2 weeks назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

9 months назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

9 months назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

9 months назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

9 months, 1 week назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

9 months, 3 weeks назад @ security.googleblog.com