Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 2 часа назад
Облачный квантовый компьютер IBM впервые обошёл один из мощнейших суперкомпьютеров мира в реальной научной задаче
Облачный квантовый компьютер IBM впервые обошёл один из мощнейших суперкомпьютеров мира в реальной научной задаче Облачный квантовый компьютер IBM впервые обошёл один из мощнейших суперкомпьютеров мира в реальной научной задаче

Квантовое превосходство перестало быть теорией?

2 часа назад @ securitylab.ru
512 ГБ на одном чипе: новая память может вместить ИИ-модели с триллионами параметров
512 ГБ на одном чипе: новая память может вместить ИИ-модели с триллионами параметров 512 ГБ на одном чипе: новая память может вместить ИИ-модели с триллионами параметров

Sandisk и SK Hynix предлагают заменить дефицитную память флешкой.

3 часа назад @ securitylab.ru
Сначала сбежали модели OpenAI. Теперь — Anthropic. ИИ выходят из-под контроля один за другим
Сначала сбежали модели OpenAI. Теперь — Anthropic. ИИ выходят из-под контроля один за другим

Claude вырвался из песочницы и взломал три компании.

3 часа назад @ securitylab.ru
Опасные ловушки C++: память, UB и код, который предаёт
Опасные ловушки C++: память, UB и код, который предаёт 4 часа назад @ securitylab.ru
От поиска цели до попытки взлома — без участия человека. Вот что показала кампания с DeepSeek
От поиска цели до попытки взлома — без участия человека. Вот что показала кампания с DeepSeek

Обнаружена кампания, в которой нейросеть DeepSeek самостоятельно искала и атаковала уязвимые серверы.

4 часа назад @ securitylab.ru
ИИ съедает всю память: Samsung предупредила о многолетнем дефиците чипов
ИИ съедает всю память: Samsung предупредила о многолетнем дефиците чипов ИИ съедает всю память: Samsung предупредила о многолетнем дефиците чипов

Компания не ждёт улучшений раньше 2028 года.

5 часов назад @ securitylab.ru
Заработал больше всех — и тут же начал угрожать конкурентам. Claude Opus 5 показал себя самым нечестным «предпринимателем» среди ИИ
Заработал больше всех — и тут же начал угрожать конкурентам. Claude Opus 5 показал себя самым нечестным «предпринимателем» среди ИИ

Вот что вытворяла нейросеть Anthropic, управляя виртуальным ларьком.

6 часов назад @ securitylab.ru
Как защититься от массового сбора текстов для ИИ: разработчики предложили «шрифт-обманку»
Как защититься от массового сбора текстов для ИИ: разработчики предложили «шрифт-обманку»

ShieldFont путает алгоритмы сбора данных для обучения ИИ.

6 часов назад @ securitylab.ru
Марсоход NASA нашёл на Марсе гигантские «пчелиные соты» — возможный след древней воды
Марсоход NASA нашёл на Марсе гигантские «пчелиные соты» — возможный след древней воды Марсоход NASA нашёл на Марсе гигантские «пчелиные соты» — возможный след древней воды

NASA назвало три версии происхождения гигантских трещин на Марсе.

7 часов назад @ securitylab.ru
Kaspersky: группировка Toy Ghouls создала собственный вымогатель для атак на российскую промышленность
Kaspersky: группировка Toy Ghouls создала собственный вымогатель для атак на российскую промышленность

Новый вымогатель одновременно бьёт по Windows, Linux и виртуальным машинам.

8 часов назад @ securitylab.ru
Кто выдаст хакеров INC Ransom? Международная организация обещает до $22 000
Кто выдаст хакеров INC Ransom? Международная организация обещает до $22 000

Fortinet и Crime Stoppers запускают глобальную программу против вымогательского ПО.

8 часов назад @ securitylab.ru
Забудьте про кликбейт и SEO-статьи: ИИ-поисковик NeoSearch открыл исходники и переписал выдачу Google
Забудьте про кликбейт и SEO-статьи: ИИ-поисковик NeoSearch открыл исходники и переписал выдачу Google Забудьте про кликбейт и SEO-статьи: ИИ-поисковик NeoSearch открыл исходники и переписал выдачу Google

Одиночка без инвесторов бросил вызов транснациональным корпорациям.

9 часов назад @ securitylab.ru
Штрафы до 6% оборота, независимые проверки, ежегодный сбор. Что грозит OpenAI и Roblox после нового статуса в ЕС
Штрафы до 6% оборота, независимые проверки, ежегодный сбор. Что грозит OpenAI и Roblox после нового статуса в ЕС

Разбираемся, что означает новый статус «очень крупной платформы».

10 часов назад @ securitylab.ru
Google научит Android-приложения отличать детей от взрослых — без сбора персональных данных
Google научит Android-приложения отличать детей от взрослых — без сбора персональных данных

Для этого хватит одного сигнала — без имени и даты рождения.

11 часов назад @ securitylab.ru
Ваш код теперь под присмотром Codex Security — но включить его без разрешения OpenAI не выйдет
Ваш код теперь под присмотром Codex Security — но включить его без разрешения OpenAI не выйдет

Открытый исходный код теперь официально означает полный запрет запуска главной функции.

11 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 2 часа назад
Геополитика и безопасность: почему Telegram и Alibaba под прицелом государства
Геополитика и безопасность: почему Telegram и Alibaba под прицелом государства Геополитика и безопасность: почему Telegram и Alibaba под прицелом государства

Но на них действуют законы, которые нередко принимались без понимания специфики новой среды.

Джек Ма, китайский миллиардерВ 1995 году муниципальный совет Ханчжоу направляет Джека Ма на годовую стажировку в США по студенческому обмену.

Предав наследие наших предков, мы встали на путь саморазрушения — морального, интеллектуального, экономического и, в конечном итоге, биологического.

Но что реально происходит «под капотом» и в какую сторону склонится чаша весов «независимости» — для большинства стран это риски ИБ.

Выход из них далеко не всегда способствует достижению общих целей — технологического и инновационного развития с соблюдением регуляторных и конституционных требований.

2 часа назад @ anti-malware.ru
Secure Enterprise Browser: новый стандарт безопасности бизнеса
Secure Enterprise Browser: новый стандарт безопасности бизнеса Secure Enterprise Browser: новый стандарт безопасности бизнеса

Браузер — один из значимых векторов атакБыло бы преувеличением сказать, что количество атак на браузер и через него выросло в последние годы.

Другими словами, корпоративный браузер позволяет контролировать все потоки данных, которые через него проходят.

Крупнейшие игроки:Google Chrome Enterprise — самый известный корпоративный браузер.

Глобальные лидеры (специализированные решения):Island — стартап из США, создавший полноценный корпоративный браузер на основе Chromium.

Через пять лет фраза «используйте корпоративный браузер» будет звучать так же естественно, как сегодня «используйте корпоративную почту».

7 часов назад @ anti-malware.ru
ROI ИБ-проектов: почему инвестиции в информационную безопасность окупаются
ROI ИБ-проектов: почему инвестиции в информационную безопасность окупаются ROI ИБ-проектов: почему инвестиции в информационную безопасность окупаются

В нынешних условиях даже если бюджет на ИТ и ИБ формально не снижается, но и не растёт, это означает его фактическое снижение.

Так, на одной из сессий конференции IT IS conf, которая прошла совсем недавно, провели блиц-опрос посетителей, в ходе которого лишь один участник заявил, что в их компании расходы на ИБ в 2026 году выросли.

Возможно, влияет и то, что в ИБ только идёт процесс перехода управления от технических специалистов к менеджерам.

ИБ как часть общей системы защиты«В информационную безопасность действительно приходится вкладываться, защищаясь от того, что, возможно, никогда не произойдёт.

В целом же, по его мнению, инвестиции в ИБ являются расходами на поддержание устойчивости б…

1 day назад @ anti-malware.ru
Обзор «Аттестованного публичного облака NGENIX»
Обзор «Аттестованного публичного облака NGENIX» Обзор «Аттестованного публичного облака NGENIX»

Мы уже рассказывали читателям о возможностях «Публичного облака NGENIX», а в этом обзоре рассмотрим «Аттестованное публичное облако NGENIX» — аттестованную распределённую облачную платформу для защиты от DDoS и бот-атак.

Архитектура «Аттестованного публичного облака NGENIX»«Аттестованное публичное облако NGENIX» построено на концепции встроенной безопасности: реализация всех требований ИБ заложена на этапе проектирования (Security by Design).

Администрирование «Аттестованного публичного облака NGENIX» и управление пользователями осуществляется в клиентском портале NGENIX EdgeSec Multidesk, доступном через веб-интерфейс.

Подключение и техподдержкаТарифы «Аттестованного публичного облака» раз…

1 day, 7 hours назад @ anti-malware.ru
Kaspersky VM: как меняется подход к управлению уязвимостями (Vulnerability Management)
Kaspersky VM: как меняется подход к управлению уязвимостями (Vulnerability Management) Kaspersky VM: как меняется подход к управлению уязвимостями (Vulnerability Management)

Среди российских решений можно назвать как экосистемные, так и самостоятельные продукты: MaxPatrol VM от Positive Technologies, R-Vision VM, ScanFactory VM, Vulns.io VM и др.

Первый вывод для Kaspersky VM – это желание снизить остроту проблем от хаотичности развития ИТ-инфраструктуры российских предприятий.

Отсутствие упоминания Kaspersky Security Center Web Console, скорее всего, объясняется ограничением первой версии Kaspersky VM.

Она может применяться как для Defensive, так и для Offensive Security.

Kaspersky VM и ИИНо вернёмся к теме Vulnerability Management и Kaspersky VM.

2 days назад @ anti-malware.ru
Как выстроить резервное копирование, которое не зависит от человека
Как выстроить резервное копирование, которое не зависит от человека Как выстроить резервное копирование, которое не зависит от человека

Делимся лучшими практиками построения резервного копирования, которое работает предсказуемо и не зависит от человека.

Причина обычно заключается не в отсутствии технологий, а в том, что процесс построен так, что ошибки становятся заметны только в момент восстановления.

Почему ручной процесс подводитПока резервное копирование держится на действиях конкретного человека, результат зависит от его занятости, внимательности и приоритетов.

В конце встраивается проверка восстановления — не как разовое мероприятие, а как часть регулярного расписания.

Вместе это и есть процесс, который держится на системе, а не на человеке.

2 days, 3 hours назад @ anti-malware.ru
Обзор Frisbee, платформы коммуникаций для бизнеса
Обзор Frisbee, платформы коммуникаций для бизнеса Обзор Frisbee, платформы коммуникаций для бизнеса

Её разработчик — российская компания «Клауд Атлас», которая создаёт технологические решения для бизнеса и государственных организаций, разрабатывая решения для бизнеса и государственных организаций, включая средства защиты информации и корпоративных коммуникаций.

Благодаря широким возможностям Frisbee является не только заменой WhatsApp и Telegram для бизнеса, но и может использоваться как альтернатива Slack и Microsoft Teams.

Возможности использования платформыРассмотрим основные функциональные возможности платформы Frisbee в корпоративной среде.

Для удобства разделим их на две части: инструменты для пользователей (интересные большинству сотрудников) и инструменты для администраторов (наст…

2 days, 8 hours назад @ anti-malware.ru
Как Gartner меняет подход к управлению внешними угрозами
Как Gartner меняет подход к управлению внешними угрозами Как Gartner меняет подход к управлению внешними угрозами

Новый квадрант Gartner показывает, что подход к киберразведке смещается от аналитического к операционализированному.

На первый план выходят единые платформы, автоматизация и работа с внешними угрозами в общем контексте, а не разрозненные средства защиты.

Так, архитектура решений раннего предупреждения кибератак компании BI.ZONE объединяет портал BI.ZONE Threat Intelligence, платформы BI.ZONE Digital Risk Protection и BI.ZONE External Attack Surface Management.

Такой подход к управлению внешними угрозами соответствует требованиям, которые Gartner считает ключевыми для нового поколения CTI-решений.

Подход включает тесное взаимодействие команд BI.ZONE Digital Risk Protection, BI.ZONE Threat In…

3 days, 1 hour назад @ anti-malware.ru
Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть I
Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть I Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть I

Детально описываем Ideco NGFW, Kaspersky NGFW, PT NGFW, UserGate NGFW, Континент 4 и ViPNet Coordinator HW по 260 критериям сравнения.

Поэтому, когда из России ушли иностранные ИБ-вендоры и на рынке освободилось место, отечественные производители тут же устремились в сегмент NGFW.

Как бизнес выбирает NGFW в 2026 годуМожно сказать, что сейчас заказчики выбирают не столько межсетевой экран, сколько производителя межсетевого экрана.

Нет Нет(будет доступно в будущих версиях) Да Да Да Двунаправленная поддержка DSCP Нет(появится в версии 23, август 2026 г.)

Да Да Да Да Да Экспорт логов Да(Syslog, выгрузка CSV.

3 days, 6 hours назад @ anti-malware.ru
Что опаснее: компрометация учётной записи или вредоносная программа?
Что опаснее: компрометация учётной записи или вредоносная программа? Что опаснее: компрометация учётной записи или вредоносная программа?

Это означает, что после получения действительных учётных данных, независимо от способа их компрометации, дальнейшее продвижение по сети становится почти гарантированным.

Если собрать это вместе, становится понятно: всё чаще первоначальное проникновение в инфраструктуру начинается не с запуска вредоносного кода, а с использования скомпрометированной учётной записи.

Знакомство с бойцамиКомпрометация учётной записи — это когда злоумышленник получает доступ к чужой учётной записи и начинает работать с ней так, будто он и есть её владелец.

И наоборот: вредоносная программа может применяться для хищения учётных данных и последующей компрометации аккаунтов.

После получения действующих учётных данн…

4 days, 2 hours назад @ anti-malware.ru
Обзор решений Cloud-Native Application Protection Platform (CNAPP)
Обзор решений Cloud-Native Application Protection Platform (CNAPP) Обзор решений Cloud-Native Application Protection Platform (CNAPP)

И в этот момент привычная схема, где разработка, эксплуатация и безопасность живут отдельно, начинает давать задержки и трения.

В этой точке логично появляется Cloud-Native Application Protection Platform (CNAPP) как способ связать безопасность с разработкой и эксплуатацией так, чтобы риски контролировались внутри процесса, а не поверх него, и не замедляли работу команд.

Иногда значение платформы пытаются объяснить через связку Cloud Security Posture Management (CSPM) и Cloud Workload Protection Platform (CWPP).

Что такое CNAPP (источник: Venison Magazine)Смысл такой сборки не в количестве модулей, а в том, что они перестают жить разрозненно.

Карта мирового рынка CNAPPЧтобы помочь компаниям…

4 days, 7 hours назад @ anti-malware.ru
Атака без вредоноса: Living-off-the-Land в АСУ ТП и ограничения сигнатурной защиты
Атака без вредоноса: Living-off-the-Land в АСУ ТП и ограничения сигнатурной защиты Атака без вредоноса: Living-off-the-Land в АСУ ТП и ограничения сигнатурной защиты

Риск возникает не в самом инструменте, а в том, кто его запустил, зачем и что он начал делать после запуска.

Такой мониторинг работает пассивно, на зеркалированном трафике, не ставит агенты на контроллеры и не нагружает критичные узлы.

Проблема не в том, что сигнатуры «больше не нужны»: против известного вредоноса они работают.

Проблема в том, что living-off-the-land проходит без файла, без хеша и без явной вредоносной нагрузки.

ВыводыСигнатурная защита остаётся важным элементом кибербезопасности, но в промышленных сетях она уже не способна закрыть весь спектр угроз.

1 week назад @ anti-malware.ru
«Лаборатория Касперского» пытается повторить успех в новом сегменте. Получится ли это?
«Лаборатория Касперского» пытается повторить успех в новом сегменте. Получится ли это? «Лаборатория Касперского» пытается повторить успех в новом сегменте. Получится ли это?

Всё это не оставалось без внимания регуляторов.

Однако потенциал роста и в России, и в мире на ближайшие годы довольно высок: среднегодовой прирост в компании ожидают на уровне 12–14 % на ближайший период.

И в целом, насколько рискует вендор, пытаясь выйти в новый для себя сегмент, который, по большому счёту, уже занят?

Цена ошибки несоизмерима с прикладным ПО, и репутационный ущерб от одного массового сбоя в узком ИБ-сообществе догоняет вендора годами.

Однако у «Антивируса Касперского» были существенные преимущества, что и позволило ему занять место не только на российском, но и на внешних рынках.

1 week назад @ anti-malware.ru
Последний универсал ИТ. Почему сеть снова оказалась в центре инфраструктуры
Последний универсал ИТ. Почему сеть снова оказалась в центре инфраструктуры Последний универсал ИТ. Почему сеть снова оказалась в центре инфраструктуры

Почему сетевой инженер снова становится одной из ключевых фигур в ИТ — на примере «Сетевого лета 2026».

Теперь такие проекты не исчезли, а распались на более конкретные и управляемые части, способные дать эффект в течение двух–четырёх лет.

По оценке Пантелеева, то, на что при ручной проверке могло уйти несколько дней, в отдельных сценариях теперь занимает полчаса.

Но главный сдвиг видит даже не в происхождении оборудования, а в отношении к управлению.

Даниил Виняр, руководитель группы перспективных разработок «Инфосистемы Джет»Незаметная инфраструктураПод конец разговора Виняр неожиданно сравнивает сеть не с высокотехнологичным продуктом, а с водопроводом.

1 week, 1 day назад @ anti-malware.ru
Обзор Kaspersky NGFW 1.2, межсетевого экрана нового поколения
Обзор Kaspersky NGFW 1.2, межсетевого экрана нового поколения Обзор Kaspersky NGFW 1.2, межсетевого экрана нового поколения

Kaspersky NGFW 1.2 — это новый релиз коммерческой версии межсетевого экрана нового поколения от «Лаборатории Касперского».

Функциональные возможности Kaspersky NGFW 1.2Kaspersky NGFW версии 1.2 — это многофункциональный межсетевой экран нового поколения, предназначенный для фильтрации трафика, контроля сетевых соединений и защиты корпоративных сетей от угроз.

Централизованное администрирование нескольких устройств Kaspersky NGFW и других продуктов вендора через единую консоль управления (Open Single Management Platform).

Аппаратные платформы KX-Series позволяют полностью реализовать возможности межсетевого экрана нового поколения Kaspersky NGFW, оставаясь эффективными даже в сложных сетевых…

1 week, 1 day назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 3 часа назад
Никто не показывает, как стандарты ИБ связаны друг с другом поэтому пришлось собрать самому
Никто не показывает, как стандарты ИБ связаны друг с другом поэтому пришлось собрать самому Никто не показывает, как стандарты ИБ связаны друг с другом поэтому пришлось собрать самому

Задача этой карты не в том, чтобы объявить один стандарт «главным», а в том, чтобы показать, как несколько моделей дополняют друг друга вместо того, чтобы соревноваться.

Trivy пригождается и для контейнеров, и для SCA, и для IaC, и для SBOM.

В рабочей ситуации обычно нужен ответ не на вопрос «что вообще существует», а на вопрос «что конкретно выполнить прямо сейчас».

Как это устроено техническиRØØT сделан без тяжёлого frontend-фреймворка — и это осознанный выбор, а не лень.

СсылкиRØØT пока не отвечает на все вопросы и не заменяет реальные стенды — и не претендует на это.

3 часа назад @ habr.com
Мы делили апельсин: как связать ручное и автоматизированное тестирование в единую систему качества
Мы делили апельсин: как связать ручное и автоматизированное тестирование в единую систему качества Мы делили апельсин: как связать ручное и автоматизированное тестирование в единую систему качества

Я собрал повторяющиеся ситуации, в которых ручное и автоматизированное тестирование зависели от неявного контекста, и оформил их в единый процесс.

Из‑за этого готовность фичи и релиза могла опираться не на единые критерии, а на знание конкретных людей.

Первый — правило процесса: кто и в какой момент принимает решение, какой результат фиксирует и кто отвечает за следующий шаг.

Это позволяет не тратить время тестировщиков на заведомо неработоспособную сборку и не перекладывать первичный разбор регрессий на ручное тестирование.

Проверенная фича, разобранный результат существующих автотестов и согласованное понимание того, какой новый сценарий автоматизируется и что именно он должен подтверждат…

4 часа назад @ habr.com
Боты уже составляют большую часть интернет-трафика. Почему это проблема не только ИБ
Боты уже составляют большую часть интернет-трафика. Почему это проблема не только ИБ Боты уже составляют большую часть интернет-трафика. Почему это проблема не только ИБ

Поэтому важно классифицировать автоматизированный трафик не только по технологии, но и по смыслу стоящей за ней активности.

Например, на маркетплейсах боты могут имитировать спрос или жаловаться на конкурентов, а в B2B-сервисах создавать фальшивые заявки, перегружая отдел продаж.

Скажем, браузер выглядит как Chrome, а транспорт этому не соответствует, движения мыши похожи на человеческие, но не согласуются с фокусом окна.

Для каждой из этих функций важно описать не только технические уязвимости, но и возможные сценарии злоупотребления штатной бизнес-логикой.

Напоследок хочется отметить, что защита от ботов должна дополнять, а не заменять меры безопасности самой бизнес-логики.

6 часов назад @ habr.com
Объявлена программа CIO CAMP 2026: как компании переводят ИИ из пилотов в рабочие процессы
Объявлена программа CIO CAMP 2026: как компании переводят ИИ из пилотов в рабочие процессы Объявлена программа CIO CAMP 2026: как компании переводят ИИ из пилотов в рабочие процессы

И как доказать, что экономический результат появился именно благодаря ИИ, а не за счет стандартизации или перераспределения ролей?

Как меняется путь от идеи до работающего продуктаУправляющий партнер ScrumTrek Антон Окунев рассмотрит влияние ИИ на проектный и продуктовый подход.

Как дать сотрудникам доступ к ИИ без потери контроляПолный запрет на использование внешних моделей не исключает их появления внутри компании.

Как измерить эффект и не приписать ИИ чужой результатСокращение срока или стоимости проекта не всегда является прямым результатом применения ИИ.

Какие интеллектуальные функции компания передает нейросетиТехнологический предприниматель и топ-менеджер Арсалан Самбуев рассмотрит …

6 часов назад @ habr.com
Как мы проектировали архитектуру сервиса MFA для миллиона пользователей
Как мы проектировали архитектуру сервиса MFA для миллиона пользователей Как мы проектировали архитектуру сервиса MFA для миллиона пользователей

MULTIFACTOR используется как классическое on-premise решение внутри инфраструктуры заказчиков и одновременно существует как облачный сервис, который ежедневно обслуживает более миллиона пользователей.

Что означает облачная модель для сервиса MFAИногда облачное решение воспринимается как приложение, работающее на нескольких виртуальных машинах.

Поэтому при проектировании облачной версии MULTIFACTOR мы исходили не из количества пользователей, а из максимально допустимого времени недоступности системы.

Как устроена облачная инфраструктура MULTIFACTORСегодня облачная версия MULTIFACTOR обслуживает более 1 000 000 пользователей.

Поэтому архитектура MULTIFACTOR не привязана к конкретному облачном…

6 часов назад @ habr.com
MLSecOps от кода до продакшена: разные акценты для разных сценариев использования ИИ
MLSecOps от кода до продакшена: разные акценты для разных сценариев использования ИИ MLSecOps от кода до продакшена: разные акценты для разных сценариев использования ИИ

Поэтому задача безопасности не в том, чтобы «запретить ChatGPT», так как на практике это почти всегда приводит к Shadow AI.

Технически шлюз включается в трафик тремя способами, и на практике нужны все три:Обратный прокси как единая точка входа для внутренних приложений.

Для человека это может выглядеть как обычный текст, но для модели это часть контекста, влияющая на поведение.

Несанкционированный доступ к модели (model extraction)Если компания предоставляет inference API, злоумышленник может пытаться извлечь поведение модели через большое количество запросов.

Контроль ИИ‑агентовДля агентов одного сетевого периметра не хватает: агент действует не только в трафике, но и в операционной систем…

6 часов назад @ habr.com
Оффбординг на автомате: почему «уволен» — слишком поздний сигнал, а «удалить» — шаг, который уже не отыграть
Оффбординг на автомате: почему «уволен» — слишком поздний сигнал, а «удалить» — шаг, который уже не отыграть Оффбординг на автомате: почему «уволен» — слишком поздний сигнал, а «удалить» — шаг, который уже не отыграть

Поэтому отдельным свойством идёт идемпотентность необратимых действий - при повторном исполнении узла результат ранее выполненного необратимого шага переиспользуется, а не выполняется заново.

Для узла “удалить пользователя” - вопрос о том, что вернёт API на второе удаление уже удалённого и как на это отреагирует граф.

Так что вопрос не только про ссылку, но и про то, как хранятся секреты узлов и что отдаётся на чтение.

Ещё несколько мест, которые выясняются потомГраф стоит проверять до включения, а не в момент исполнения.

Отклонять такие адреса обязан сам узел - не инструкция для того, кто его настраивает, и не бдительность автора сценария.

7 часов назад @ habr.com
И еще немного извращений из мира прокси и VPN
И еще немного извращений из мира прокси и VPN И еще немного извращений из мира прокси и VPN

И работает все это довольно неплохо.

Ключи можно (и нужно) не светить в командной строке, а вынести в переменные окружения FT_S3_ACCESS_KEY / FT_S3_SECRET_KEY.

Идея в лоб: оба конца туннеля логинятся в один и тот же IMAP-аккаунт на почтовом сервере (или на нескольких для распараллеливания), и используют по две выделенные папки на каждый - в одну сторону и в другую.

А еще это все дело можно запустить как плагин Shadowsocks (SIP003), например под Shadowsocks Android, так что пользоваться можно и с телефона.

Да и CDN в мире и в стране существует не то чтобы прям много разных.

22 часа назад @ habr.com
Звезда в машинном тумане: как ИИ стал оружием, целью и чужим голосом в браузере
Звезда в машинном тумане: как ИИ стал оружием, целью и чужим голосом в браузере Звезда в машинном тумане: как ИИ стал оружием, целью и чужим голосом в браузере

Модель на прицелеИнструкции и данные сталкиваютсяИнструкция и данные разговаривают на одном языкеУ классической системы граница жесткая: команда отдельно, данные отдельно.

Отравленная библиотека и данные, которые притворяются истинойВ enterprise проблема обычно не в модели и не в красивом публичном jailbreak.

Телеметрия: смотреть не на слова, а на траекторииBlue team полезнее смотреть на поведение.

Контрмеры на рассветеЦентр управления, где модель не на тронеК утру картина города становится более честной: неон больше не прячет трещины.

Встраивай AI threat modeling в дизайн и SDLC, а не в финальную встречу по compliance.

22 часа назад @ habr.com
Экономия на спичках
Экономия на спичках Экономия на спичках

Через минуту получает ответ и закрывает задачу, пригласив выбранного кандидата на собеседование (прокликав остальным отказ на HeadHunter).

Галочка “не использовать мои данные для обучения” в настройках аккаунта на этот факт никак не влияет.

То есть практику по новым, высоким ставкам сейчас нарабатывают уже не только на иностранных гигантах, а на обычных российских делах, просто пока ближе к нижней границе шкалы.

Ну и самый неприятный момент, когда данные утекают у самих ИИ-компаний или их посредников и в публичном доступе появляется история промптов от пользователей.

ЗаключениеПопытка сэкономить пару десятков долларов в месяц на инфраструктуре, продолжая гонять реальные бизнес-данные через …

22 часа назад @ habr.com
Битва ИИ: как мы натравили 4 атакующих агента на MaxPatrol O2 и кто победил
Битва ИИ: как мы натравили 4 атакующих агента на MaxPatrol O2 и кто победил Битва ИИ: как мы натравили 4 атакующих агента на MaxPatrol O2 и кто победил

В статье разбираем результаты этой битвы:Насколько ИИ-хакеры способны взломать инфраструктуру без участия человека и в какой момент им все-таки нужна помощь оператора;Как MaxPatrol O2 расследует такие атаки и удается ли ему полностью восстановить цепочку действий атакующего;Какими метриками мы измеряли эффективность атакующих и MaxPatrol O2 в этой кибербитве.

Для открытых решений принцип отбора был простым: брали то, что реально используется и обсуждается в комьюнити (по звёздам на GitHub и активности).

Чтобы снизить стоимость такого вмешательства, был добавлен механизм teleport/resume: так агент может продолжить работу как с точки последней остановки, так и с произвольного шага из истории …

23 часа назад @ habr.com
OSINT для ленивых. Часть 15: Когда OSINT не работает
OSINT для ленивых. Часть 15: Когда OSINT не работает OSINT для ленивых. Часть 15: Когда OSINT не работает

В данном случае, проблема не в том, что OSINT как методология не работает, - его неправильно понимают, неправильно используют и неправильно же интерпретируют.

Но если сам заказчик не может внятно сказать, в чем именно он не уверен, толку не будет, сколько бы данных не было бы собрано.

Это не баг, а особенность профессии — так работает любая аналитика по открытым источникам, и иначе просто не бывает.

OSINT начинают упрекать, что он "не дает ответов" — хотя он и не обязан давать их в таком виде.

Не потому что не ценит аналитику, а потому что не находит в ней ответа на простой вопрос: "И что нам теперь с этим делать?"

1 day назад @ habr.com
Балансировка кластера NGFW: 5 особенностей, которые важно учитывать при построении высокопроизводительной инфраструктуры
Балансировка кластера NGFW: 5 особенностей, которые важно учитывать при построении высокопроизводительной инфраструктуры Балансировка кластера NGFW: 5 особенностей, которые важно учитывать при построении высокопроизводительной инфраструктуры

По мере роста корпоративной инфраструктуры количество сегментов увеличивается и в крупных организациях может достигать нескольких десятков и даже сотен.

Особенности балансировки кластера NGFWБалансировка кластера NGFW имеет ряд принципиальных особенностей.

Резервирование балансировщиков и каналов связи с NGFW с помощью MC-LAGРезервирование балансировщиков нагрузкиПодключенный коммутатор взаимодействует с парой балансировщиков как с единым логическим устройством.

По этой причине при балансировке кластера NGFW необходимо обеспечить постоянную привязку сетевой сессии (Sticky Session) к одному узлу кластера.

Контроль работоспособности кластера NGFWВ предыдущих разделах были рассмотрены вопросы …

1 day, 1 hour назад @ habr.com
Кто может подменить код, работающий в Solana: замер 65 119 программ
Кто может подменить код, работающий в Solana: замер 65 119 программ Кто может подменить код, работающий в Solana: замер 65 119 программ

Ответы получены по 65 119 аккаунтам программ и по 348 программам, которые я наблюдал реально вызванными.

Это не одна популяция, а двеПервое, что говорят данные: «программы в Solana» — не единая совокупность.

Получилось 348 различных программ на 132 563 вызовах: сеть в том виде, в каком её реально используют, взвешенная по использованию.

Тут всё просто: это плохо, я это знаю, и в следующем квартале хочу гонять замер против двух эндпоинтов и сравнивать.

Я думаю, что нет, и что это принципиально ненаблюдаемо снаружи.

1 day, 1 hour назад @ habr.com
Видеозвонок больше не доказательство: как дипфейки взламывают корпоративное доверие
Видеозвонок больше не доказательство: как дипфейки взламывают корпоративное доверие Видеозвонок больше не доказательство: как дипфейки взламывают корпоративное доверие

Тогда его пригласили на видеозвонок, на котором был тот самый директор и коллеги, которых он узнал в лицо и по голосу.

На настройку ушло около 45 минут и, по его собственному признанию, результат получился не особенно убедительным, но наглядно показал, насколько низким стал технический порог входа.

Но он сменил канал связи, а не источник доверия: и письмо, и организованная под него видеоконференция контролировались одними и теми же злоумышленниками.

Чем заметнее человек в компании, чем чаще он выступает на конференциях и в видео для сайта, тем больше у мошенников исходного материала для его цифрового двойника.

Урок не в том, что нельзя доверять глазам и ушам, а в том, что теперь недостаточн…

1 day, 2 hours назад @ habr.com
Хакер Хакер
последний пост 2 часа назад
MEGANews. Cамые важные события в мире инфосека за июль
MEGANews. Cамые важные события в мире инфосека за июль MEGANews. Cамые важные события в мире инфосека за июль

Поэто­му мы при­нима­ем решения преж­де все­го исхо­дя из тех­ничес­ких кри­тери­ев, а не из стра­ха перед новыми инс­тру­мен­тами.

Вы­мога­тели пот­ребова­ли, что­бы пред­ста­вите­ли Coca-Cola начали перего­воры до кон­ца недели, а в про­тив­ном слу­чае обе­щали выложить укра­ден­ные дан­ные в откры­тый дос­туп.

Общие воп­росы, обсужде­ния и обра­щения за помощью по‑преж­нему сле­дует раз­мещать в Discord, на Reddit и в соци­аль­ных сетях.

Упо­мяну­тые «Цитадель», VAS Experts и «Нор­си‑Транс» попали под огра­ниче­ния как раз­работ­чики и пос­тавщи­ки обо­рудо­вания и ПО для СОРМ.

В Huntress под­счи­тали, что в сред­нем на одно­го кли­ента Microsoft 365 при­ходит­ся 1964 неудач­ные попыт­ки…

2 часа назад @ xakep.ru
Минцифры предлагает авторизовывать пользователей на иностранных сайтах по номеру телефона
Минцифры предлагает авторизовывать пользователей на иностранных сайтах по номеру телефона Минцифры предлагает авторизовывать пользователей на иностранных сайтах по номеру телефона

В Минцифры предлагают обязать зарубежные сайты и приложения использовать только один способ авторизации российских пользователей — по номеру телефона.

Эта инициатива включена в проект третьего пакета антифрод-мер, и, по словам экспертов, отказ от ее выполнения может привести к блокировке множества сервисов.

Как сообщают «Ведомости», инициатива вошла в проект третьего пакета мер по борьбе с мошенничеством, и документ уже направили на обсуждение в профильные ведомства.

Согласно документу, для российских ресурсов продолжат действовать несколько вариантов авторизации: по номеру телефона, через «Госуслуги», Единую биометрическую систему или другую отечественную систему, которая отвечает требован…

3 часа назад @ xakep.ru
Одно посещение вредоносной страницы могло скомпрометировать Tor Browser
Одно посещение вредоносной страницы могло скомпрометировать Tor Browser Одно посещение вредоносной страницы могло скомпрометировать Tor Browser

Исследователи из компании Nebula Security раскрыли детали уязвимости CVE-2026-10702 в JIT-компиляторе Firefox.

Однако этот процесс работает в песочнице, поэтому сама по себе CVE-2026-10702 не предоставляла атакующему полного контроля над системой.

В Firefox ESR 140.12 проблемный код отсутствовал, а также в бюллетене Mozilla не упоминается ESR-ветка.

Однако эта операция могла изменить структуру объекта и освободить участок памяти, на который все еще ссылался JIT-компилятор.

Теперь JIT-компилятор учитывает, что она может менять состояние объекта, и не использует указатель повторно для уже освобожденной памяти.

5 часов назад @ xakep.ru
В Anthropic заявили, что Claude взломал три организации и загрузил малварь в PyPI
В Anthropic заявили, что Claude взломал три организации и загрузил малварь в PyPI В Anthropic заявили, что Claude взломал три организации и загрузил малварь в PyPI

В рамках одной из этих атак ИИ самостоятельно создал вредоносный Python-пакет и опубликовал его в PyPI.

При этом в логах Claude отмечала, что публикация пакета в интернете являлась бы настоящей атакой, и писала, что такой вариант — «NOT okay».

Однако модель решила, что все же находится в симуляции — ее смутили незнакомые центры сертификации и 2026 год в тестовых системах.

Проблема возникла из-за того, что в выданном модели задании фигурировала вымышленная компания, которая носила то же имя, что и реально существующая организация.

При этом в Anthropic настаивают, что проблема заключалась не в том, что модели Claude проигнорировали какие-либо ограничения, а в ошибках, допущенных при настройке…

7 часов назад @ xakep.ru
Росфинмониторинг внес Павла Дурова в перечень террористов и экстремистов
Росфинмониторинг внес Павла Дурова в перечень террористов и экстремистов Росфинмониторинг внес Павла Дурова в перечень террористов и экстремистов

Росфинмониторинг внес основателя Telegram Павла Дурова в перечень организаций и физических лиц, причастных к экстремистской деятельности или терроризму.

Включение в перечень означает заморозку принадлежащих Дурову средств, ценных бумаг и другого имущества в российской юрисдикции.

В ФСБ утверждают, что эти ресурсы применялись для подготовки и координации диверсий, терактов, массовых убийств и кибермошенничества, и такая деятельность привела к человеческим жертвам и многомиллиардному ущербу.

Как отмечают СМИ, уголовное дело против Дурова само по себе не меняет статус Telegram и не вводит ограничений для пользователей мессенджера.

Внесение Павла Дурова в перечень Росфинмониторинга стало очеред…

8 часов назад @ xakep.ru
Apple получила иск на $1,8 млн за фейковые криптокошельки в App Store
Apple получила иск на $1,8 млн за фейковые криптокошельки в App Store Apple получила иск на $1,8 млн за фейковые криптокошельки в App Store

На Apple подали иск на $1,8 млн из-за фейковых криптокошельков в App StoreТри человека подали иск против Apple после того, как потеряли 1,8 млн долларов из-за поддельных приложений-кошельков, выдававших себя за Sparrow Wallet.

Ключевая проблема для Apple в этом деле — не появление первого мошеннического приложения, а то, что в компании знали о нем заранее.

Тем не менее, по данным иска, поддельные версии продолжали появляться в App Store в течение следующего года.

Более того, в иске говорится, что в Apple не только разместили приложение, но и продвигали его в рейтингах и подборках криптоприложений.

Основной удар пришелся на китайский App Store, где были недоступны официальные версии для iOS …

10 часов назад @ xakep.ru
RCE-уязвимость в Fastjson используется в атаках
RCE-уязвимость в Fastjson используется в атаках RCE-уязвимость в Fastjson используется в атаках

Fastjson — опенсорсная Java-библиотека, разработанная компанией Alibaba, которая используется для сериализации объектов Java в JSON и обратно.

Проект набрал более 25 600 звезд и имеет 6400 форков на GitHub и особенно популярен в китайском сегменте корпоративного ПО, а также применяется в проектах, созданных на платформе Alibaba.

Обнаруженная проблема получила идентификатор CVE-2026-16723 (9,0 балла по шкале CVSS) и затрагивает Fastjson версий с 1.2.68 по 1.2.83 в Spring Boot-приложениях, собранных и запущенных в виде исполняемых fat JAR.

Кроме того, SafeMode должен быть выключен, как в конфигурации по умолчанию.

Корень проблемы заключается в механизме разрешения типов в Fastjson.

22 часа назад @ xakep.ru
Закрывающаяся криптобиржа BitMart задерживает вывод средств
Закрывающаяся криптобиржа BitMart задерживает вывод средств Закрывающаяся криптобиржа BitMart задерживает вывод средств

Сами по себе эти переводы не доказывают, что активов недостаточно для исполнения заявок клиентов на вывод средств, однако вызывают беспокойство.

Аналитики платформы Onchain Lens также сообщили, что за сутки не было крупных выводов биткоина, стейблкоинов и альткоинов на сумму свыше $25 000.

В Paxi не раскрыли ни сумму, ни число затронутых пользователей, ни сроки ожидания; в BitMart на претензии публично не отреагировали.

Тогда же на бирже обещали опубликовать подтверждение резервов (proof of reserves), но так этого и не сделали.

При обработке части заявок на вывод дополнительно проверят данные KYC, устройства входа, IP-адреса, кошельки назначения, источники средств, торговую историю и наличи…

23 часа назад @ xakep.ru
Более 30 объектов водоснабжения в США пострадали от скоординированной хакерской атаки
Более 30 объектов водоснабжения в США пострадали от скоординированной хакерской атаки Более 30 объектов водоснабжения в США пострадали от скоординированной хакерской атаки

Власти Миннесоты сообщили, что расследуют скоординированную кибератаку на системы водоснабжения и водоотведения: хакеры взломали инфраструктуру более 30 муниципальных предприятий, временно нарушив работу автоматизированных систем управления.

Известно, что на некоторых объектах из-за атаки отказали отдельные автоматизированные функции, однако сотрудники коммунальных служб перешли на ручное управление или задействовали резервные схемы работы.

В большинстве случаев системы водоснабжения и водоотведения продолжали работать, однако сильнее всего от атаки пострадал город Брахам, где водоочистная станция на несколько часов ушла в офлайн, а жителей попросили сократить расход воды.

Власти всех постр…

1 day назад @ xakep.ru
Серый кардинал без посредников. Настраиваем потоки и алерты, пишем декодер для Graylog 7.1
Серый кардинал без посредников. Настраиваем потоки и алерты, пишем декодер для Graylog 7.1 Серый кардинал без посредников. Настраиваем потоки и алерты, пишем декодер для Graylog 7.1

Сис­тема монито­рин­га ста­новит­ся по‑нас­тояще­му полез­ной, ког­да сама отсле­жива­ет кри­тичес­кие события и заранее пре­дуп­режда­ет о проб­лемах.

В статье «Се­рый кар­динал мира логов» я показы­вал, как раз­вернуть сер­вер Graylog 5.2, уста­новить Java, MongoDB и OpenSearch и нас­тро­ить базовый сбор логов с хос­тов под управле­нием Linux и Windows.

Я про­дол­жаю работать в домаш­ней лабора­тории на хос­тах с Windows, Linux и macOS, но все при­меры уни­вер­саль­ны.

По умол­чанию в сис­теме есть три потока: все события, все сис­темные события и поток по умол­чанию.

Ты нас­тра­иваешь поток, и в него попада­ют толь­ко сооб­щения, которые соот­ветс­тву­ют задан­ным кри­тери­ям.

1 day, 2 hours назад @ xakep.ru
DDoS-ботнет Dysphoria заразил более 200 000 устройств по всему миру
DDoS-ботнет Dysphoria заразил более 200 000 устройств по всему миру DDoS-ботнет Dysphoria заразил более 200 000 устройств по всему миру

Аналитики из QiAnXin XLab и китайского центра CNCERT рассказали о новом IoT-ботнете Dysphoria, который уже насчитывает порядка 200 000 зараженных устройств.

После блокировки прежней инфраструктуры малварь стала получать адреса управляющих серверов через Ethereum Name Service (ENS), а в начале мая разработчики оснастили ботнет поддержкой Solana Name Service (SNS).

Исследователи объясняют, что при этом боты подключаются не напрямую к управляющим серверам, а к другим скомпрометированным устройствам, которые ретранслируют трафик.

При этом списки эксплуатируемых багов отличаются в версиях QiAnXin XLab и CNCERT, и исследователи не объясняют роль некоторых уязвимостей в цепочке заражения.

При этом…

1 day, 3 hours назад @ xakep.ru
Криптоскамера под ником Bastille сдеанонила бывшая девушка
Криптоскамера под ником Bastille сдеанонила бывшая девушка Криптоскамера под ником Bastille сдеанонила бывшая девушка

Анонимная пользовательница X под ником Slippage опубликовала развернутый тред, в котором обвинила Bastille в изнасиловании, финансовых манипуляциях и отказе оплатить медицинские счета после автомобильной аварии, во время которой Bastille был за рулем.

Хотя проекты были совместными, Bastille якобы утверждал, что она не заслуживает своей доли прибыли.

Slippage утверждает, что Bastille регулярно лгал о своих финансах и приходил в ярость, когда она запускала токены с другими людьми.

Ситуация обострилась, когда Bastille продал токен одного из их совместных проектов слишком рано и, по ее словам, пережил серьезный эмоциональный срыв.

Сам Bastille в своем аккаунте на pump.fun утверждает, что уже на…

1 day, 4 hours назад @ xakep.ru
Российским ИТ-компаниям присылают фишинговые письма с «поврежденными» документами
Российским ИТ-компаниям присылают фишинговые письма с «поврежденными» документами Российским ИТ-компаниям присылают фишинговые письма с «поврежденными» документами

Для первоначального заражения атакующие рассылают фишинговые письма с документами, которые выглядят поврежденными.

Одновременно с этим группировка расширяет географию атак, и теперь среди ее целей появились организации из Беларуси.

Хотя сам документ не содержит малварь, при открытии он обращается к внешнему серверу и загружает удаленный шаблон с макросом.

Операторы разбивали вывод команд вроде tasklist и whoami на отдельные строки и отправляли их на управляющий сервер, маскируя эксфильтрацию под обычный веб-трафик.

Пейлоад размещался в анонимной области памяти через memfd_create и выполнялся без сохранения исполняемого файла на диск.

1 day, 5 hours назад @ xakep.ru
Исследователь создал червя для Microsoft Copilot
Исследователь создал червя для Microsoft Copilot Исследователь создал червя для Microsoft Copilot

Независимый норвежский ИБ-специалист Хокон Молей (Håkon Måløy) сообщил, что создал самораспространяющегося промпт-червя для Copilot for Word.

Молей, специалист по анализу данных со степенью PhD в области применения ИИ и машинного обучения, опубликовал подробное описание проблемы в своем блоге.

В своей демонстрации специалист скрыл вредоносные инструкции в документе с помощью мелкого белого текста.

Исследователь объясняет, что для проверки контента на промпт-инжекты LLM сначала должна его обработать, и вредоносная инструкция может повлиять на решение ИИ уже на этом этапе.

Представители Microsoft подтвердили выводы Молея и заявили, что применяют многоуровневую защиту для блокировки вредоносны…

1 day, 7 hours назад @ xakep.ru
Вредонос Dolphin X использует ИИ для приоритизации целей
Вредонос Dolphin X использует ИИ для приоритизации целей Вредонос Dolphin X использует ИИ для приоритизации целей

Исследователи Varonis Threat Labs изучили новый троян удаленного доступа Dolphin X, операторы которого заявляют об использовании ИИ для профилирования жертв.

Исследователи заметили рекламу Dolphin X на хак-форуме, где вредонос предлагался как универсальный RAT, а его продавец под ником Kontraktnik обещал покупателям панель управления с 329 функциями, разбитыми на десять категорий.

Специалисты рассказывают, что изучили панель управления Dolphin X в изолированной среде.

Однако эксперты не заражали Dolphin X тестовую машину и ограничились анализом панели управления, билдера и сетевого трафика.

При этом Dolphin X позиционируется как полноценный стилер.

1 day, 22 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 3 часа назад
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined.

In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself.

According to statistics shared by the U.S. National Vulnerabilities Database (NVD), 46,872 flaws have been recorded so far in 2026, nearing the 49,920 vulnerabilities reported for the entirety of 2025.

"Every security bug that reaches Chrome Stable, regardless of whether it was discovered internally or reported externally, is documented and disclosed publ…

3 часа назад @ thehackernews.com
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session.

In a hypothetical DoS attack scenario against Open5GS LTE, an attacker can send GTPv2-C messages to trigger the vulnerability when parsing GTPv2-C Create Session Request messages, causing the Serving Gateway Control plane (SGW-C) to crash.

As for session hijacking, an internet adversary can perform the following sequence of actions -The attacker sends a PFCP Association Setup Request to the User Plane Funct…

3 часа назад @ thehackernews.com
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Push Security added device code phishing to its Browser & Identity Attacks Matrix back in 2023 and now tracks more than 25 distinct device code phishing kits in the wild and counting.

Push recently ran a deep-dive webinar on device code phishing covering the attack mechanics, a live demonstration of a custom-built phishing kit, and what comes next.

Tycoon2FA, which Push previously tracked as the most common AiTM phishing kit in the wild, added device code phishing to its framework in May.

Nation-state actors have already used device code phishing against Salesforce in targeted campaigns.

the behavioral signatures of device code phishing kits and the device code approval flow itself rather t…

4 часа назад @ thehackernews.com
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.

The DeepSeek-led attacks against Langflow and n8n failed because the exposed systems did not meet the exploits' configuration requirements.

Organizations should patch exposed Langflow, n8n and Marimo systems, along with customer-managed NetScaler ADC or Gateway appliances configured as Security Assertion Markup Language (SAML) identity providers.

Hermes Agent exposed the operation by starting python3 -m http.server 8888 from /home/worker.

Langflow fixed CVE-2026-33017 in version 1.9.0. n8n fixed CVE-2026-21858 in version 1.121.0.

4 часа назад @ thehackernews.com
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations

"However, in some cases, our older model continued its attack even after getting evidence it was running on the open internet; our latest model stopped once it recognized it was on the internet," it said.

A validation of all internet access paths prior to the evaluations and real-time monitoring of the evaluation logs would have helped surface the issues sooner, it added.

Anthropic's Claude has now exhibited similar behavior, reinforcing the growing capabilities of state-of-the-art AI systems.

Instead, they increasingly read like capability marketing-demonstrations of what the frontier AI models can exploit, bypass, crack, or automate.

As AI systems become more capable and move from researc…

9 часов назад @ thehackernews.com
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.

The campaign is also noteworthy for its use of blockchain-hosted command-and-control (C2), with the malware extracting the live server address from an Ethereum smart contract.

This takedown-resistant approach, referred to as EtherHiding, has been put to use by North Korean threat actors in prior campaigns associated with Contagious Interview (aka UNC5342).

The attack chain is a departure …

21 час назад @ thehackernews.com
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

A lot of security still comes down to trusting the wrong screen.

This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong.

Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder.

A login works.

That is the part worth checking before next week finds it first.

1 day назад @ thehackernews.com
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

The public disclosure shows the output of a crafted query that executed the hostname command on the Cosmos DB backend, but not the query itself.

Customer databases were not stored on those clusters, but the gateway could retrieve the primary key for a requested Cosmos DB account.

Microsoft documentation says a Cosmos DB account primary key grants full control over all resources in that account.

Credentials available to the gateway also provided access to a signing key that Wiz dubbed the Cosmos Master Key.

Microsoft documentation says Teams message data remains in Cosmos DB, while a Microsoft engineering post says Copilot stores users' queries and conversation histories there.

1 day, 2 hours назад @ thehackernews.com
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file.

It requires a Copilot drafting or editing operation, and the malicious document must enter the model's context as an attachment or as a OneDrive source selected by Work IQ, the intelligence engine behind Microsoft 365 Copilot.

Microsoft says Word can ground a draft on up to 20 files, emails, or meetings, and Edit with Copilot can use Work IQ.

With the original malicious document absent and only the infected Q1 report attached, Copilot halved the figures in a Q2 draft and appended the prompt again.

Microsoft says jailbreak and cross-prompt…

1 day, 3 hours назад @ thehackernews.com
The Network Has Become the Control Plane for AI Security
The Network Has Become the Control Plane for AI Security The Network Has Become the Control Plane for AI Security

And for decades, network security teams have built controls around a relatively stable model: users connect to applications, applications exchange data, and security tools inspect packets, protocols, and destinations.

And this new reality calls for a new kind of network security rooted in AI and designed to protect your network from today's ever dynamic threat landscape.

We're introducing the industry's first AI Network Firewall to deliver comprehensive AI security at the network level that protects employee AI use, AI applications, and AI agents directly from the firewall organizations already run.

The AI Network Firewall is fully integrated into Check Point's AI Defense Plane, turning the…

1 day, 4 hours назад @ thehackernews.com
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.

Its report does not disclose their identities, affected or fixed versions, or vulnerability identifiers.

AhnLab said the evidence does not establish that one actor conducted both operations.

ENKI Whitehat identified AnySign4PC, software used for certificate-based electronic signatures, as one of the vulnerable products and said the attackers had exploited a zero-day flaw.

Kaspersky also documented Lazarus using watering holes, South Korean security software, SIGNBT, and COPPERHEDGE during the earlier Operation SyncHole.

1 day, 5 hours назад @ thehackernews.com
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

The ZIP archive contains a downloader executable that retrieves the next-stage components necessary for DLL side-loading from an attacker-controlled Tencent Cloud infrastructure.

Specifically, the malicious DLL ("PDFCORE8.dll") sideloaded by "ConvertToPDF.exe" or "PDFDirect.exe" embeds "BootRepair.sys," "EnPortv.sys," and wsftprm.sys," turning the malware into a modular three-driver BYOVD framework for defense evasion.

"The malware integrates Bring Your Own Vulnerable Driver (BYOVD), DLL side-loading, NTDLL unhooking, process injection, registry-based payload storage, and two independent recovery mechanisms to impair security controls and maintain execution," the researchers said.

The resul…

1 day, 5 hours назад @ thehackernews.com
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.

In doing so, the likelihood that a recipient opens and reads the message increases, effectively firing the exploit for CVE-2026-42897 in the process.

"The initial exploit trigger and relevant payload blobs are stored in the social media icons shown in the message body HTML.

Once executed, it uses Outlook APIs to rewrite the email on the Exchange server and remo…

1 day, 8 hours назад @ thehackernews.com
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks

The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28.

FCC rules otherwise exclude covered equipment from certification procedures for Class I and Class II permissive changes.

The Department of War (DoW) may approve robotic devices, while DoW or the Department of Homeland Security (DHS) may approve power inverters.

The third is CVE-2025-2894, which could give anyone holding the correct API key full remote control of Unitree Go1 quadrupeds through the CloudSail service.

The FCC package frames this as a preventive supply-chain action; it does not identify a confirmed active exploitation campaign against de…

1 day, 8 hours назад @ thehackernews.com
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea.

In research published July 29, Amazon Threat Intelligence assesses with medium confidence that the group behind the March 2026 axios compromise was behind it.

The evidence Amazon published is thinner than the claim.

The malicious file Amazon describes, core.js , posed as the legitimate core-js package inside the repository.

On July 28, npm began scanning newly published packages for malware before they become installable.

1 day, 9 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 1 day, 7 hours назад
Beyond the screenshot: Why you should verify what you see
Beyond the screenshot: Why you should verify what you see Beyond the screenshot: Why you should verify what you see

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuineSomeone sends you a screenshot showing that a payment has gone through.

Why screenshot aren’t proof on their ownA screenshot is ultimately just an image of what appeared on a screen.

Reassured, you send the item off, only to find out the screenshot was a fake and you’re not getting your money.

You receive a password reset code, then get a text message (maybe impersonating a friend) asking you to screenshot and send it.

This screenshot is fake (source: Reddit)Challenges for businessesFrom a business perspective, internal and customer-facing teams are often provided with sc…

1 day, 7 hours назад @ welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

2 weeks, 3 days назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

3 weeks, 2 days назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

4 weeks назад @ welivesecurity.com
This month in security with Tony Anscombe – June 2026 edition
This month in security with Tony Anscombe – June 2026 edition This month in security with Tony Anscombe – June 2026 edition

It's that time of month when ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses.

What lessons does the new CISA policy hold for organizations outside the agency's direct remit?

What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems?

How can you stay safe from imposter fraud, and could the social media bans for children work?

Learn more from Tony's video and be sure to check out the May 2026 edition of Tony's monthly security news roundup for more insights.

1 month назад @ welivesecurity.com
Inside the inbox: Why cybercriminals want to break into your email account
Inside the inbox: Why cybercriminals want to break into your email account Inside the inbox: Why cybercriminals want to break into your email account

With access to your email account, they can reset your passwords across multiple other accounts – perhaps intercepting one-time passcodes sent by your bank, social media, cloud storage or other online provider.

That could lay the groundwork for a convincing phishing email designed to impersonate a trusted organization you interact with.

A phishing attack on your corporate email account is often the first stage in a bigger data breach, extortion/ransomware or espionage attack.

They’re also using more sophisticated tools to improve the success rates of email phishing campaigns.

In this instance the scammers reportedly hijacked the email account of a high-level executive, before impersonating …

1 month назад @ welivesecurity.com
SMB cyber readiness: the road to resilience starts here
SMB cyber readiness: the road to resilience starts here SMB cyber readiness: the road to resilience starts here

For these businesses, cyber resilience should be the direction of travel – that is, the ability to continue operating and recover even during a serious incident.

Cyber readiness is about putting in place the processes and controls to prevent, detect and respond to threats.

So, should confidence in cyber resilience posture be so high, especially if organizations are still getting hit multiple times?

The truth is that there’s no end state for cyber readiness or resilience.

If it’s serious about improving the cyber readiness of small businesses, the vendor community should step up.

1 month назад @ welivesecurity.com
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Key points of this blogpost: Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.

Continued data exfiltration and a new allianceThroughout 2025, Gamaredon stayed highly active and remained focused solely on Ukraine.

Notably, we uncovered that in early 2025, Gamaredon collaborated with Turla, another Russia-aligned threat actor also linked to the FSB; we documented our findings in our blogpost Gamaredon X Turla collab.

Figure 1 shows a chart of unique samples of HTA downloaders delivered per month in Gamaredon spearphishing campaigns.

Compared to 2024, we also saw a shift in how Gamaredon used these dead drops.

1 month назад @ welivesecurity.com
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET takes part in Operation Endgame to disrupt Amadey and Stealc

Key points of this blogpost: ESET took part in the coordinated, global Operation Endgame to disrupt Amadey and Stealc.

Our automated systems have been dissecting Amadey and Stealc samples and identifying the fields most relevant for large-scale tracking.

The largest Amadey botnet clusterOne cluster stands out as the largest, and it contributed nearly 34% of all processed Amadey samples.

Stealc affiliate clustering based on ESET telemetryConclusionFor global disruption operations such as Operation Endgame against Amadey and Stealc, long-term automated tracking of malware is necessary.

2026‑04‑09 Stealc C&C server.

1 month, 1 week назад @ welivesecurity.com
Killing me gently: Inside Gentlemen’s EDR killer framework
Killing me gently: Inside Gentlemen’s EDR killer framework Killing me gently: Inside Gentlemen’s EDR killer framework

The group distinguishes itself through a mature, operator-maintained set of endpoint detection and response (EDR) killers, i.e., tools for disrupting security software.

In this blogpost, we share our findings on Gentlemen’s suite of EDR killers gained through extensive research and corroborated by the recent leak.

Third‑party EDR killers (HexKiller, ThrottleBlood, and HavocKiller) are operationally integrated.

Rather than relying on affiliates to source their own EDR killers, Gentlemen operators actively develop and maintain a portfolio of EDR killers for affiliates.

It allows the Gentlemen operators to integrate abused drivers into their toolset very soon after an EDR killer PoC is disclos…

1 month, 1 week назад @ welivesecurity.com
Protecting legacy OT systems against modern cyberthreats
Protecting legacy OT systems against modern cyberthreats Protecting legacy OT systems against modern cyberthreats

Of course, connecting production systems to enterprise networks delivers tangible benefits, but the security implications – that systems once safe were suddenly no longer so – arrived more quietly.

Start by mapping which systems in an environment are connected and have no security coverage, where IT and OT networks intersect, which segments are unmonitored, and which production systems have fallen outside any vendor support agreement.

Meanwhile, off-the-peg security tools often don’t efficiently meet the enterprise requirements in legacy OT systems that run on older hardware and outdated operating system versions.

The production systems running that version continue to operate for years, ac…

1 month, 2 weeks назад @ welivesecurity.com
FishMonger’s arsenal upgraded: SprySOCKS for Windows
FishMonger’s arsenal upgraded: SprySOCKS for Windows FishMonger’s arsenal upgraded: SprySOCKS for Windows

Key points of this blogpost: We discovered two previously undocumented Windows variants of FishMonger’s SprySOCKS backdoor.

Technical analysisIn this section, we provide a technical analysis of these new, Windows variants of FishMonger’s SprySOCKS backdoor.

Figure 3. klelam00007.bat setting up persistence for the SprySOCKS backdoor (newlines added for readability)Figure 4 depicts the execution chain of the SprySOCKS WIN_DRV variant.

It contained the SprySOCKS backdoor and the SprySOCKS loader.

6490B8E4AADE25A3EE2D A9A47F312DB2122470BC X1B5206BDC1 743DD.dat Win64/SprySOCKS.A Encrypted container of the encrypted WIN_DRV variant of SprySOCKS backdoor, encrypted SprySOCKS RawWNPF and SprySOCKS …

1 month, 2 weeks назад @ welivesecurity.com
EvilTokens: A phishing attack that doesn’t steal your password
EvilTokens: A phishing attack that doesn’t steal your password EvilTokens: A phishing attack that doesn’t steal your password

Instead, attackers get the victim to complete a legitimate authentication process – including two-factor authentication (2FA) – on a real Microsoft login page.

What makes EvilTokens dangerousThe OAuth device code flow was designed for devices that may be awkward to sign into directly, such as smart TVs or printers.

No document, invoice, email, or another platform should ask for a device code without a clear reason.

A real Microsoft page doesn’t automatically make a request safe.

Sometimes the attacker could ask them to enter a real code on a real page – but for the wrong device.

1 month, 2 weeks назад @ welivesecurity.com
OceanLotus: From external espionage to domestic targeting
OceanLotus: From external espionage to domestic targeting OceanLotus: From external espionage to domestic targeting

During this period, the Vietnam-aligned OceanLotus adopted a more selective approach to external operations while placing increasing emphasis on domestic espionage.

We identified two distinct campaigns involving the SPECTRALVIPER backdoor: a supply-chain attack targeting stock investors in Vietnam and a prolonged espionage operation against a Vietnamese infrastructure and transport construction company.

The domain resolved to the genuine IP address of the FireAnt update server, suggesting a supply-chain compromise scenario.

LTD 2025‑09‑20 SPECTRALVIPER C&C server.

]com IRT‑CHOOPALLC‑AP 2025‑09‑20 SPECTRALVIPER C&C server.

1 month, 2 weeks назад @ welivesecurity.com
SMB cyber-readiness: What makes or breaks it
SMB cyber-readiness: What makes or breaks it SMB cyber-readiness: What makes or breaks it

But that realization alone clearly doesn’t prepare them to withstand an attack.

Have the repeat victims come to view their brushes with cyber-incidents as proof of “what doesn’t kill me makes me stronger”?

For all the talk around AI, automation and attacker sophistication, many SMB breaches still begin with a familiar opening.

A total of 71% of SMBs globally now carry cyber insurance, rising to 84% in North America, with adoption climbing sharply among repeat victims.

While “when, not if” has never been more true, that alone doesn’t prepare a business for adversity.

1 month, 3 weeks назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 2 часа назад
Cybercrime goes subscription: AI, malware and infrastructure on demand
Cybercrime goes subscription: AI, malware and infrastructure on demand Cybercrime goes subscription: AI, malware and infrastructure on demand

Cybercrime becomes more industrializedThe cybercrime ecosystem continues to expand and specialize as profits attract more participants, allowing attackers to evolve faster than defenders.

Hidden infrastructure enables attacksTo evade detection, attackers rely on trusted-looking and concealed infrastructure.

Criminals create phishing pages that closely resemble legitimate websites.

Some phishing pages remain active for less than 24 hours, reducing the window for investigation.

Threat actors are targeting software supply chains to reach large numbers of victims through trusted software, libraries, and development tools.

2 часа назад @ helpnetsecurity.com
Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire
Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire

A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years.

Discovered by accidentResearcher Pedro Falé uncovered the operation while investigating factory-installed remote-management backdoors that had been left enabled on Android TV boxes sold to consumers.

The researchers expected the telemetry to come from Android TV boxes, since the backdoor was part of their firmware.

The hardware information matched phone models, though some devices contained software packages normally found on Android TV boxes, including TV launchers and settings apps.

“Fuyao strays from traditional, low effort modus operandi of a…

3 часа назад @ helpnetsecurity.com
Anthropic’s Claude breached three companies during security tests
Anthropic’s Claude breached three companies during security tests Anthropic’s Claude breached three companies during security tests

Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations.

“In all cases, our evaluation prompt stated explicitly that Claude had no internet access, but didn’t give Claude any limits on where to look for the flag,” the company explained.

“However, a misconfiguration left the machines that Claude accessed as part of the evaluation with live internet access.

In two of the four runs, Claude incorrectly concluded that the real company had been intentionally included in the evaluation.

Claude then used these credentials to access further infrastructure from this company,” Anthropic wrote.

6 часов назад @ helpnetsecurity.com
Traefik Labs introduces Distro Zero secure runtime for API and AI gateways
Traefik Labs introduces Distro Zero secure runtime for API and AI gateways Traefik Labs introduces Distro Zero secure runtime for API and AI gateways

Traefik Labs has introduced the Distro Zero image, a hardened, vendor-supported secure runtime delivered as Traefik Hub in proxy mode.

The Distro Zero image is the durable answer and is built on three reinforcing pillars.

None of them ever applied to a Distro Zero image, because there is no OpenSSL, no glibc, and no substrate to patch.

The Distro Zero image keeps nothing a distribution would supply: one static Go binary and the standard trust bundle, which is data, not code.

One binary, proxy to platformThe same hardened, supported binary runs as a drop-in proxy and unlocks API Gateway, AI Gateway, MCP Gateway, and API Management through licensing rather than a separate download.

7 часов назад @ helpnetsecurity.com
Horizon3.ai expands NodeZero with automated web application attack path testing
Horizon3.ai expands NodeZero with automated web application attack path testing Horizon3.ai expands NodeZero with automated web application attack path testing

Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting.

The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure.

Web applications have never been more exposed or more critical to secure.

The rapid deployment of “vibe-coded” applications built with generative AI has introduced a wave of systems riddled with exploitable flaws.

NodeZero WebApp Pentesting closes the gap by delivering production-safe autonomous testing that spans web applications, infrastructure, cloud, data, and identity.

7 часов назад @ helpnetsecurity.com
AttackIQ targets CTEM execution with AVA Agentic OS
AttackIQ targets CTEM execution with AVA Agentic OS AttackIQ targets CTEM execution with AVA Agentic OS

AttackIQ has announced AVA Agentic OS, an agentic operating system designed to operationalize Continuous Threat Exposure Management.

AVA Agentic OS fills that gapWith AVA OS, AttackIQ is redefining how organizations operationalize Continuous Threat Exposure Management (CTEM).

CTEM Runs on AVA OS“Organizations don’t have a CTEM strategy problem—they have a CTEM execution problem,” said Carl Wright, Chief Commercial Officer at AttackIQ.

AVA OS can be invoked through the AttackIQ Platform, AI developer environments such as ChatGPT, Claude, Cursor, and Microsoft Copilot, or directly from AI-native applications and partner solutions.

AVA OS enables organizations to answer the questions that matt…

7 часов назад @ helpnetsecurity.com
Resecurity expands threat intelligence integration ecosystem with IBM QRadar
Resecurity expands threat intelligence integration ecosystem with IBM QRadar Resecurity expands threat intelligence integration ecosystem with IBM QRadar

Resecurity has announced the availability of native integration with IBM QRadar SIEM, a widely used Security Information and Event Management (SIEM) platform used by the leading Fortune 100 corporations worldwide.

The plugin is available for activation via IBM Application Exchange.

This approach helps enrich security events with additional context and supports more informed analysis within Security Operations Centers (SOCs).

Our customers will greatly benefit from seamless integration and the ability to leverage industry best practices for threat intelligence integration with IBM Security’ leading SIEM product.

Resecurity continues to expand its integration ecosystem to support interoperabi…

8 часов назад @ helpnetsecurity.com
Aviation cyber risk sits on the ground, the blindness sits in the air
Aviation cyber risk sits on the ground, the blindness sits in the air Aviation cyber risk sits on the ground, the blindness sits in the air

When you brief a board, how does aviation cyber risk split between the aircraft and everything on the ground?

Almost everything realized happens on the ground — reservations, ground handling, MRO IT, crew scheduling, airport operations.

The real version is duller: the aircraft consumes data from the ground constantly — nav databases, performance data, EFB content, loadable software.

EFB and data loading stop being things you attest to and become things you can test.

A vendor that becomes a way for OEMs to harvest fleet data has destroyed its own value, and airlines spot that fast.

10 часов назад @ helpnetsecurity.com
Companies push AI, sysadmins keep it on a short leash
Companies push AI, sysadmins keep it on a short leash Companies push AI, sysadmins keep it on a short leash

In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years.

AI adoption varies across sysadmin workflowsAI adoption has not progressed evenly across sysadmin functions.

Why sysadmins remain cautious about AISince 2023, the share of companies requiring sysadmins to implement AI has more than doubled.

Sysadmins remain cautious when using AI for production systems, security policies, access management, and remediation, relying heavily on human oversight.

Data privacy, security risks, and uncertainty about AI accuracy and reliability remain sysadmins’ biggest concerns regarding AI adop…

10 часов назад @ helpnetsecurity.com
AI agents are changing where cybersecurity seed funding lands
AI agents are changing where cybersecurity seed funding lands AI agents are changing where cybersecurity seed funding lands

Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer.

Series B has passed 2018’s Series E. Seed crossed the 2018 Series A line for the first time this quarter.

Agent security took the seed money that was leftAI security was the largest category of cyber seed investment last quarter, close to a quarter of all deals.

Agentic products also turned up in cloud security, application security, AI pentesting, and third-party risk management.

Two OpenAI models, GPT-5.6 and an unreleased successor, broke out of their sandbox and into Hugging Face’s production servers in pursuit of a benchmark score.

11 часов назад @ helpnetsecurity.com
New infosec products of the week: July 31, 2026
New infosec products of the week: July 31, 2026 New infosec products of the week: July 31, 2026

Here’s a look at the most interesting products from the past week, featuring releases from BlackCloak, Contrast Security, Dropzone AI, PortSwigger, Realm Security, Reco, Root Evidence, and ZeroFox.

Reco enhances AI Runtime with browser-based AI security and automated remediationReco has announced an expansion of AI Runtime, a core component of the Reco Platform.

From impersonation attempts and dark web chatter to travel-related threats and digital exposure, security teams gain the context needed to act before isolated indicators become real-world incidents.

Dropzone AI turns threat hunting into a routine SOC operationDropzone AI has announced the general availability of AI Threat Hunter, it…

11 часов назад @ helpnetsecurity.com
Jscrambler launches Unified Client-Side Security Platform
Jscrambler launches Unified Client-Side Security Platform Jscrambler launches Unified Client-Side Security Platform

Jscrambler launched its Unified Client-Side Security Platform, introducing a new approach to securing applications and customer data where AI-powered risks increasingly operate: inside the browser.

Our Unified Client-Side Security Platform changes that by bringing software integrity and data governance together through a single runtime enforcement architecture.

This convergence is forcing security leaders to rethink how browser security is managed.

A unified platform for enterprise security initiativesThe Jscrambler Unified Client-Side Security Platform addresses this new reality by enabling organizations to extend critical security initiatives into the browser through a single runtime arch…

22 часа назад @ helpnetsecurity.com
AI takes on a bigger role in finding Chrome vulnerabilities
AI takes on a bigger role in finding Chrome vulnerabilities AI takes on a bigger role in finding Chrome vulnerabilities

We have been increasingly shifting our triage process towards an automated approach that blends rule-based systems with AI to increase throughput and accuracy,” The Chrome Security team explained.

AI-powered vulnerability discoveryGoogle has used AI to support Chrome security work for several years.

In 2026, it expanded those efforts with a Gemini-based system that searches the Chrome codebase for vulnerabilities.

Google said Chrome 149 and Chrome 150 included fixes for 1,072 security bugs, exceeding the total number fixed during the previous 23 stable releases combined.

With this, Chrome and the broader web become safer with every update,” Google concluded.

22 часа назад @ helpnetsecurity.com
Novee brings continuous AI pentesting to mobile apps
Novee brings continuous AI pentesting to mobile apps Novee brings continuous AI pentesting to mobile apps

With this addition, Novee becomes the industry’s first complete AI pentesting platform across the modern application attack surface, providing continuous, autonomous coverage.

Users upload a mobile application package and receive results within hours, alongside findings from their other application assets.

Novee research into twenty Android Apps has already uncovered over a dozen repetitions of such a chained exploit in a customer’s environment.

Each assessment maps to the OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Application Security Testing Guide (MASTG).

New research demonstrates mobile testing in actionNovee’s continuous AI pentesting for mobile is backe…

1 day назад @ helpnetsecurity.com
Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email.

The loader ultimately delivers OWAReaper, a backdoor that is executed in the reading pane of Outlook Web Access (OWA), the webmail interface for Exchange.

Once OWAReaper runs, it:Rewrites the original email on the server to erase the exploit code, and disables pop-ups and right-clicking while it runs.

Gathers the target’s email address, username and Outlook settings, and tries to capture login credentials via invisible…

1 day, 1 hour назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 4 часа назад
Facial Recognition at Madison Square Garden
Facial Recognition at Madison Square Garden Facial Recognition at Madison Square Garden

Facial Recognition at Madison Square GardenLast month, the story broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition.

Turns out that the system was shut off for Taylor Swift’s wedding.

Evan Greer—one of the people that MSG alerts on—comments:Ironically, Swift herself has reportedly used facial recognition at her own concerts to identify stalkers.

Whatever privacy measures Swift had in place for the wedding seems to have worked.

Posted on July 31, 2026 at 7:08 AM • 0 Comments

4 часа назад @ schneier.com
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials

He’s being prosecuted for giving border officials a code that wiped his phone:The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices.

Tunick’s attorneys confirmed GrapheneOS was running on his phone.

The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user’s unlock passcode.

Tunick’s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.

23 часа назад @ schneier.com
Should You Use AI for a Task? Here’s a Simple Way to Decide
Should You Use AI for a Task? Here’s a Simple Way to Decide Should You Use AI for a Task? Here’s a Simple Way to Decide

And it will come as no surprise to you that my students regularly use AI to complete their writing assignments.

But if their entire career is going to include AI writing assistants, why shouldn’t they embrace their future?

The writing assignments I give my students are gym tasks, not work tasks.

We hired one regardless of whether we needed work writing or gym writing.

I know fiction writers who supported that poorly paying career with lucrative technical writing work.

1 day, 4 hours назад @ schneier.com
Measuring the Tendency of AI Agents to Go Rogue
Measuring the Tendency of AI Agents to Go Rogue Measuring the Tendency of AI Agents to Go Rogue

In July, Hugging Face, a company that hosts much of the world’s AI software and open-source AI models, was hacked.

OpenAI was running the unreleased AI model through a benchmark that tests how well AI can successfully hack systems.

So it chained together stolen credentials and further unknown security exploits to hack the company’s network.

For example, the Chinese lab Moonshot recently warned that its latest AI model may have “excessive proactiveness” and “make unexpected decisions on the user’s behalf”.

The UK’s AI Security Institute has started tracking “cheating behavior in frontier model evaluations”.

1 day, 22 hours назад @ schneier.com
Long-Lived Vulnerability in Microsoft Secure Boot
Long-Lived Vulnerability in Microsoft Secure Boot Long-Lived Vulnerability in Microsoft Secure Boot

Microsoft’s Secure Boot has had a serious vulnerability for most of its existence.

An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence.

The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway.

The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software.

The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly availa…

2 days, 4 hours назад @ schneier.com
Measuring LLMs’ Ability to Perform Cryptanalysis
Measuring LLMs’ Ability to Perform Cryptanalysis Measuring LLMs’ Ability to Perform Cryptanalysis

There’s new benchmark measuring AI’s ability to perform mathematical cryptanalysis.

The benchmark: “CryptanalysisBench: Can LLMs do Cryptanalysis?” The idea is to benchmark the ability of LLMs to discover new mathematical cryptanalytic attacks against a series of historical algorithms.

Abstract: Cryptanalysis—the task of finding attacks against cryptographic schemes—its at the intersection of mathematical reasoning and cybersecurity, two areas where LLMs have advanced fastest.

Cryptanalysis represents both a clean testbed for frontier reasoning (as practical attacks can be automatically verified) and a domain with unusually high stakes, since the primitives under study underpin our digital …

2 days, 14 hours назад @ schneier.com
Axon Is Another License Plate Surveillance Company
Axon Is Another License Plate Surveillance Company Axon Is Another License Plate Surveillance Company

Governments are switching, but I’m not sure it makes a difference:…some municipalities, including Denver, Colorado, are ditching their Flock arrays.

But keep in mind that if they’re only switching from Flock to another brand of license-plate readers, like Axon, it’s like a gambling addict trying to kick the habit by switching from FanDuel to DraftKings.

[…]Despite what you may read on the Flock website, Axon cameras are pretty effective when it comes to hoovering up personal details that can go far beyond your license plate numbers.

That means a municipality that opts for Axon cameras instead of Flock units won’t necessarily reduce the amount privacy its citizens lose through their use.

3 days, 4 hours назад @ schneier.com
Cognyte Sells a Mobile Cell Surveillance Van
Cognyte Sells a Mobile Cell Surveillance Van Cognyte Sells a Mobile Cell Surveillance Van

Yet another Israeli mass surveillance company:Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it.

That enables cops to keep tabs on any phones in the vicinity ­ whether they’re owned by a suspect in a case or not.

Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed within the vehicles, hidden in a backpack for on-foot missions or attached to a helicopter.

It’s the same technology as the infamous Stingray, one of the original cell-site simulators made by defense giant L3Harris.

4 days, 4 hours назад @ schneier.com
Friday Squid Blogging: Illex Squid Catch in the Falklands
Friday Squid Blogging: Illex Squid Catch in the Falklands Friday Squid Blogging: Illex Squid Catch in the Falklands

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

6 days, 18 hours назад @ schneier.com
Why AI Needs a “Genie Coefficient”
Why AI Needs a “Genie Coefficient” Why AI Needs a “Genie Coefficient”

Beyond the AI model itself, what has changed is the harness: the ordinary code that wraps around an AI model, decides when and how to use the model, and controls access to tools like a browser, a low-level command line, or a financial API.

Genie behavior isn’t new.

If we get the measurement right, it enables things that aren’t possible today, like policies concerning AI behavior.

If an AI system betrays the reasonable meaning of an instruction, that’s the AI’s misbehavior, not the user’s.

Test a diverse array of skills, use cases, and tools, and give the AI system sparse, confusing, or overwhelming context.

1 week назад @ schneier.com
End-to-End Encryption and “Going Dark”
End-to-End Encryption and “Going Dark” End-to-End Encryption and “Going Dark”

Governments around the world have proposed, and in some cases enacted, laws limiting E2EE for law enforcement and national security purposes.

The Article proceeds in three parts tracking three rounds of the Going Dark Debate.

Round 3 addresses the current debate over E2EE, where no entity between sender and recipient can read the plaintext.

The Article’s first major contribution is identifying five technically distinct scenarios for how E2EE operates in practice, each with different implications for lawful access.

These scenarios reveal a substantial gap between the assumption that E2EE categorically blocks lawful access and the reality of how communications are sent and received.

1 week, 1 day назад @ schneier.com
First-Person Identity Theft Story
First-Person Identity Theft Story First-Person Identity Theft Story

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 week, 2 days назад @ schneier.com
MIT to Become Hotbed of AI Video Surveillance
MIT to Become Hotbed of AI Video Surveillance MIT to Become Hotbed of AI Video Surveillance

Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026.

Technical specifications for the cameras suggest that they will be capable of collecting real-time face and object classification data, including detection of motion, loitering, crowds, face masks, and camera tampering.

According to a statement from MIT spokesperson Kimberly Allen, any collected data is “retained up to 30 days,” unless an exception is granted.

They support resolutions ranging from 2MP to 4K while also recognizing faces, license plates, vehicles, and other objects in real time.

Nearly all cameras will accommodate…

1 week, 3 days назад @ schneier.com
On Flock License Plate Tracking Cameras
On Flock License Plate Tracking Cameras On Flock License Plate Tracking Cameras

The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM.

It just saw 34 DTM in large type and started alerting the local police.

In fact, four other 34 ## DTM cars were being tracked around Minnesota that week, according to Officer Ganshyn.

It was fed those characters that you said, 34 DTM, and it spit back out [a result] with the characters, 34 DTM,” Thomas said.

Last year, he even called one group that tracks the location of Flock cameras “terrorists.” But he’s had a change of heart.

1 week, 4 days назад @ schneier.com
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach Friday Squid Blogging: Squid Washing Up on Cape Cod Beach

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 week, 6 days назад @ schneier.com
Krebs On Security
последний пост 23 часа назад
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

23 часа назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

1 week, 2 days назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

2 weeks, 2 days назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

2 weeks, 4 days назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

3 weeks, 2 days назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

4 weeks назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

1 month, 1 week назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

1 month, 1 week назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

1 month, 3 weeks назад @ krebsonsecurity.com
A Record-Breaking Patch Tuesday for June 2026
A Record-Breaking Patch Tuesday for June 2026 A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.

“Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said.

Microsoft received heavily blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher.

While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barne…

1 month, 3 weeks назад @ krebsonsecurity.com
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

On May 31, word began to spread on several Telegram instant message channels that Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow.

Meta has not responded to requests for comment on the video’s claims, but the company reportedly did acknowledge the dormant Instagram account for the Obama White House was briefly compromised.

Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership.

Just like human customer support employees can be social engineered into providing unauthorized access to someone’s a…

1 month, 4 weeks назад @ krebsonsecurity.com
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

But as KrebsOnSecurity observed in September 2025, those sanctions failed to target Stark’s remaining connection to the Internet — an Internet service provider based in the Netherlands called MIRhosting.

MIRhosting is operated by Andrey Nesterenko, a 39-year-old Russian native who runs the business out of the Netherlands.

And as our September 2025 report showed, WorkTitans was controlled by Nesterenko and a 57-year-old from Amsterdam named Youssef Zinad.

On top of that, WorkTitans was getting connectivity to the larger Internet solely through MIRhosting, where Zinad had worked previously.

“The transition to the.hosting was not intended to evade sanctions,” Nesterenko wrote.

2 months, 1 week назад @ krebsonsecurity.com
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers Demand Answers as CISA Tries to Contain Data Leak Lawmakers Demand Answers as CISA Tries to Contain Data Leak

The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.

Experts who reviewed the exposed secrets said the commit logs for the code repository showed the CISA contractor disabled GitHub’s built-in protection against publishing sensitive credentials in public repos.

CISA acknowledged the leak but has not responded to questions about the duration of the data exposure.

TruffleHog does this by monitoring a live feed that GitHub publishes which includes a record of all commits and changes to public code repositories.

In practical terms, it is likely that cybercrime groups or foreign adversaries also noticed the publication of these CISA secrets, …

2 months, 1 week назад @ krebsonsecurity.com
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

A criminal complaint unsealed today in an Alaska district court charges Jacob Butler, a.k.a.

“Dort,” of Ottawa, Canada with operating the Kimwolf DDoS botnet.

“KimWolf was tied to DDoS attacks which were measured at nearly 30 Terabits per second, a record in recorded DDoS attack volume,” the Justice Department statement reads.

Synthient was among many technology companies thanked by the Justice Department today, and Synthient’s founder Ben Brundage told KrebsOnSecurity he’s relieved Butler is in custody.

The DOJ said at least one of those services collaborated with Butler’s Kimwolf botnet.

2 months, 1 week назад @ krebsonsecurity.com
CISA Admin Leaked AWS GovCloud Keys on Github
CISA Admin Leaked AWS GovCloud Keys on Github CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems.

Another file exposed in their public GitHub repository — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems.

“The available Git metadata alone does not prove which endpoint or device was used.”Caturegli said he validated that the exposed credentials could authenticate to three AWS GovCloud accounts at a high privilege level.

CISA has not responded to questions about the p…

2 months, 1 week назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 4 часа назад
The $5 million threat: AI Is supercharging phishing attacks
The $5 million threat: AI Is supercharging phishing attacks

According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

4 часа назад @ fortra.com
North Korea’s elite hackers turned on their own government – and got caught
North Korea’s elite hackers turned on their own government – and got caught North Korea’s elite hackers turned on their own government – and got caught

For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme.

But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead.

The ringleaders of the group are said to be discharged veterans from a cyber operations unit under North Korea's Reconnaissance and Intelligence General Bureau.

In short, the hackers are accused of building a mini version of the same kind of money-laundering infrastructure North Korea depl…

1 day, 6 hours назад @ bitdefender.com
Smashing Security podcast #478: This job interview could destroy your company
Smashing Security podcast #478: This job interview could destroy your company Smashing Security podcast #478: This job interview could destroy your company

Smashing Security, Episode 478: This Job Interview Could Destroy Your Company, with Graham Cluley and special guest Paul Ducklin.

And all the time you're going through this process, bad news, they really were recording video of you.

Obviously, you can understand that CAR want to know, does your car actually have one of these in all likelihood?

And give it to them and then they tell you whether they think you're at risk.

I don't know.

1 day, 16 hours назад @ grahamcluley.com
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know

The AI models involved were OpenAI's GPT-5.6 Sol and a more capable, as-yet-unreleased model.

The intention of OpenAI's researchers was to get a clear picture of what the AI models were capable of achieving if not constrained.

American AI safety guardrails forced a US company to turn to a Chinese AI model for help.

Hugging Face's CEO Clément Delangue is quoted in OpenAI's blog post, calling on the AI industry to work more collaboratively.

It is clear that advanced AI models are remarkably capable of discovering and exploiting ways to attack real-world systems.

1 week, 1 day назад @ bitdefender.com
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

How 14 orders of Chicken McNuggets helped nail a suspected Russian hacker with Graham Cluley and special guest James Ball.

I had a vindaloo, Graham Cluley, and I don't think it ever touched capsicum.

Yeah, I think you're right.

If you use Suno music, people say, you know, you're killing music.

I don't know much about Shai Hulud.

1 week, 1 day назад @ grahamcluley.com
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Ukraine's computer emergency response team, CERT-UA, has warned that Russian hackers are using fake CAPTCHA checks to trick people into compromising their own PCs.

The Kremlin-backed Sandworm hacking group is reportedly leveraging fake CAPTCHA checks on compromised websites that persuade users to execute a PowerShell command on their computers - tricking them into running malicious code.

The latest attacks begin when a user visits a compromised webpage, where they're greeted by a fake CAPTCHA claiming they need to complete an extra step to prove that they are human.

Instead, the fake CAPTCHA instructs the user to copy and paste a PowerShell command into their Windows computer.

They are a pr…

1 week, 3 days назад @ bitdefender.com
Google’s Gemini lets strangers send messages from your locked Android phone
Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini lets strangers send messages from your locked Android phone

Someone gets hold of your locked Android phone and, despite not knowing your security PIN, they can send messages via SMS or WhatsApp pretending to come from you.

It is clear that Google has patched Gemini lock screen issues before, but security researchers keep finding new ways through.

The latest vulnerability is different from the previous similar Gemini-based Android lock screen bypass bugs that have been plaguing the operating system since September 2025.

To do that:Open the Gemini app, tap your profile picture, go to Settings, and select "Gemini on lock screen."

Every new capability Gemini is given at the lock screen is also a new potential attack surface.

1 week, 6 days назад @ bitdefender.com
Anubis ransomware: what you need to know
Anubis ransomware: what you need to know

The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.

2 weeks назад @ fortra.com
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

That is a really, really busy street potentially.

I don't know what the difference is between a tuk-tuk and a rickshaw.

I don't know.

Yeah, it's got to be a Bluetooth transmitter from the battery, and within the battery there's an operating system or something that'll need updating.

It's really, really great.

2 weeks, 1 day назад @ grahamcluley.com
The ransomware negotiator who was working for the other side
The ransomware negotiator who was working for the other side The ransomware negotiator who was working for the other side

When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help.

Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf.

41-year-old Martino worked as a ransomware negotiator for DigitalMint, an incident response company based in Chicago.

The ransomware victim, a hospitality company, ultimately paid out nearly US $16.5 million.

The company has since changed the way its negotiators communicate with ransomware gangs, and is working with the Department of Homeland Security to establish a registry for the currently highly-unregulated world of ransomware negotiation.

2 weeks, 3 days назад @ bitdefender.com
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk

Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role?

Security experts have uncovered a phishing campaign which impersonates over 30 well-known brands in fake job interviews designed to steal Google account passwords.

When victims click on "Continue with Google," a pop-up appears that looks like a legitimate Google authentication dialog.

In the past the FBI has warned the public about scammers using fake job ads to steal money and personal information from applicants.

Earlier this year, Hot for Security published a guide explaining how many fake recruiter scams work, and how to avoid them.

3 weeks, 1 day назад @ bitdefender.com
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself

These stories appear different, but they're actually telling the same story.

I'm going to flag, I'm going to flag the point that I made earlier is that operational security isn't always there.

I know how to do this because it's done it for me, but I don't actually know how to apply it logically.

And when the technology you're relying on to protect you, and in some people's case it is protecting their life, and you're not doing it to the best of your ability, that's, that's really, really disappointing.

But I guess for now, all eyes are on Apple and how they're going to respond to this, albeit 13 months later.

3 weeks, 1 day назад @ grahamcluley.com
Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud
Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud

Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims.

According to a police press release, victims were duped into entering their payment card details on bogus phishing websites.

Investigators believe the arrested men, who have not been named, did not just misuse the stolen payment card details themselves, but also passed them on to other fraudsters.

Card payment fraud was found to be the single most common category, with over half a million fraudulent transactions (up more than a quarter on the year before).

In 2024, just 1% of Dutch fraud victims recovered their money, and while arou…

3 weeks, 3 days назад @ bitdefender.com
The Gentlemen ransomware: what you need to know
The Gentlemen ransomware: what you need to know

Who Are The Gentlemen?

Despite the impeccably polite name, there is nothing polite or refined about this particular gang of cybercriminals. Read more in my article on the Fortra blog.

4 weeks назад @ fortra.com
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack? Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?

And I'm going to be looking at whether you're wise to take a gamble with your security on Polymarket.

Right, well, I want to tell you about a company that's built its entire brand on being really, really good at predicting the future.

They've actually done it really, really well.

So it's The Summer Portraits by— remind me who it's by again, 'cause I'm going to butcher his name.

It's really, really good.

4 weeks, 1 day назад @ grahamcluley.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 1 day, 4 hours назад
Почему звонят в трубку и молчат | Блог Касперского
Почему звонят в трубку и молчат | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 87a765bcfffecb3be7b631186de73cdfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-30T14:00:37+03:00Config id: 292Faithfully yours, nginx.

1 day, 4 hours назад @ kaspersky.ru
ScreenConnect в кибератаках | Блог Касперского
ScreenConnect в кибератаках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 69f66dfe76ff3f53d09e7e879aff2eabServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-29T19:00:33+03:00Config id: 291Faithfully yours, nginx.

1 day, 23 hours назад @ kaspersky.ru
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e1896b8624f52547d7aa4a3bebd90c3cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-27T16:00:28+03:00Config id: 291Faithfully yours, nginx.

4 days, 3 hours назад @ kaspersky.ru
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 30ce39da164ccbcb4068b4e06c4c1e60Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-24T19:00:11+03:00Config id: 291Faithfully yours, nginx.

1 week назад @ kaspersky.ru
Инциденты с атаками на ИИ-агентов в бизнесе | Блог Касперского
Инциденты с атаками на ИИ-агентов в бизнесе | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: abb2f672b0aebacf96a83f072ddf5be5Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-23T15:00:29+03:00Config id: 290Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 29288682927681f45f4ebe45b92c4f9dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-22T15:00:12+03:00Config id: 290Faithfully yours, nginx.

1 week, 2 days назад @ kaspersky.ru
ConsentFix: новая вариация ClickFix
ConsentFix: новая вариация ClickFix

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 92f538b35cc9db0cd8268f0e9c690524Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-21T12:00:10+03:00Config id: 290Faithfully yours, nginx.

1 week, 3 days назад @ kaspersky.ru
Как защитить свои данные после расставания | Блог Касперского
Как защитить свои данные после расставания | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7c4859afeb6714d16332cd516cc382ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-20T13:00:34+03:00Config id: 290Faithfully yours, nginx.

1 week, 4 days назад @ kaspersky.ru
Кража почты через OAuth | Блог Касперского
Кража почты через OAuth | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 89a6c1c61d71bc406a42bd2d91dc48b6Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-17T15:00:29+03:00Config id: 290Faithfully yours, nginx.

2 weeks назад @ kaspersky.ru
Промпт-атаки на умного помощника Gemini и ИИ-ассистента Gemini Workspace | Блог Касперского
Промпт-атаки на умного помощника Gemini и ИИ-ассистента Gemini Workspace | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 9e57da73febcf1364991851b3ffd4607Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-16T15:00:15+03:00Config id: 290Faithfully yours, nginx.

2 weeks, 1 day назад @ kaspersky.ru
Ключевые уязвимости Microsoft Patch Tuesday за июль 2026 | Блог Касперского
Ключевые уязвимости Microsoft Patch Tuesday за июль 2026 | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: ad5fb1fb73f446dedef7d1ec45313d70Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-15T17:00:41+03:00Config id: 289Faithfully yours, nginx.

2 weeks, 2 days назад @ kaspersky.ru
Meta* включила и тут же отключила функцию генерации ИИ-изображений на основе пользовательского контента в Instagram** | Блог Касперского
Meta* включила и тут же отключила функцию генерации ИИ-изображений на основе пользовательского контента в Instagram** | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: d28ecbce6fae6b24393f114511aa53c1Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-14T15:00:39+03:00Config id: 282Faithfully yours, nginx.

2 weeks, 3 days назад @ kaspersky.ru
Борьба с BEC-атаками на базе ИИ | Блог Касперского
Борьба с BEC-атаками на базе ИИ | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 0f43fc04a64ef8b4198bfe5f08f75233Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-13T17:00:32+03:00Config id: 281Faithfully yours, nginx.

2 weeks, 4 days назад @ kaspersky.ru
Что не так с функцией NameTag в умных очках Meta* и почему ее стоит опасаться | Блог Касперского
Что не так с функцией NameTag в умных очках Meta* и почему ее стоит опасаться | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 36cc4a8142dd177820e529f1c74777d2Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-09T14:00:09+03:00Config id: 281Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Целевой фишинг на производственные компании | Блог Касперского
Целевой фишинг на производственные компании | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 1ce0e45ab895fdb2ea63e5f66838efb9Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-08T18:00:10+03:00Config id: 281Faithfully yours, nginx.

3 weeks, 2 days назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 52 минуты назад
The Zero Trust Imperative for the Frontier AI Era
The Zero Trust Imperative for the Frontier AI Era The Zero Trust Imperative for the Frontier AI Era

Their recommendations for securing the AI era rely heavily on establishing strict asset inventory and preventing lateral movement—which are, at their core, fundamental Zero Trust principles.

The Three Core Principles of Zero Trust for AIFounded in three core principles, a robust Zero Trust architecture requires us to execute the following phases comprehensively.

Achieving the Architectural VisionThe above may all sound like pipedream, as most organisations struggle with Zero Trust programs and undelivered microsegmentation projects.

Ultimately AI driven platform approach is what makes Zero Trust achievable for the frontier AI era.

This is exactly why achieving a Zero Trust Architecture for …

52 минуты назад @ blogs.cisco.com
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes

This provides an opportunity for defenders: if we assume our controls will fail at some point, we can build a much more resilient architecture.

When you assume the current layer will eventually be bypassed, you start designing the next layer proactively instead of reactively.

Defenders need to advance their controls by mapping them to the adversaries’ capabilities then assume that control will fail.

Map your controls to the attack chain.

Call to Action:If you haven’t watched the full video yet, go check it out: Assuming Failure Provides Better Defensive Outcomes (bonus elements around SOC of the Future and business context).

4 days назад @ blogs.cisco.com
The Journey towards Logically Air-Gapped Deployment
The Journey towards Logically Air-Gapped Deployment The Journey towards Logically Air-Gapped Deployment

Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter.

This “Logically Air-Gapped” governance model reaches its full operational potential through the implementation of “Live Protect.” As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution.

Reference ArchitectureDigital autonomy is thus exercised by shifting network and security control into the operating system kernel.

Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a un…

1 week назад @ blogs.cisco.com
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall

That is why we are introducing Firewall Migration Manager by Cisco, an enterprise-ready product built for that reality.

What Is Firewall Migration Manager?

Firewall Migration Manager is a dedicated migration application that you run in your own environment.

How Firewall Migration Manager WorksThe migration process follows a clear, guided workflow.

Intelligent, integrated migration: Firewall Migration Manager will also come to Cisco Cloud Control, and AI will play an increasing role in guiding teams before and during migration.

1 week, 1 day назад @ blogs.cisco.com
We third-party tested our firewall built for AI-scale. The test tools hit their limit first.
We third-party tested our firewall built for AI-scale. The test tools hit their limit first. We third-party tested our firewall built for AI-scale. The test tools hit their limit first.

In independent testing with NetSecOPEN, the Cisco Secure Firewall 6160 delivered AI-scale inspected throughput beyond what the tools built to measure it could register, all while blocking 100% of tested threats.

These results are specific to Cisco Secure Firewall 6160, but the software capabilities behind Cisco Firewall, including advanced threat protection and high-performance inspection, extend across Cisco Firewall form factors in the cloud, virtually, and on-premises, from campus to data center.

Performance passed the previous benchmark by 5XInspection was turned on, and the test tools built to measure throughput hit their limit before the 6160 firewall did.

In previous NetSecOPEN testi…

2 weeks, 2 days назад @ blogs.cisco.com
SharpHound Recon Attack – How AI enhanced the threat hunt
SharpHound Recon Attack – How AI enhanced the threat hunt SharpHound Recon Attack – How AI enhanced the threat hunt

We innovated by giving the Agentic SOC access to Endace’s always-on, full packet capture, and asked the agent to assess a potential SharpHound Recon attack that we had seen while threat hunting.

This blog explores how we built the integrations and how AI helped us with our threat hunt and threat assessment.

Agentic AI Massively Speeds our AnalysisAt this point, we decided to use Agentic AI capabilities to investigate and assess this potential threat.

ConclusionThe Agentic SOC, blending Agentic AI built into Endace’s products with custom agentic tools, is a massive boost to productivity and security.

AcknowledgementsOur thanks go to the Cisco SOC team led by @Jessica Oppenheimer and @Ivan Be…

3 weeks, 2 days назад @ blogs.cisco.com
Machine Speed, Human Judgement: How AI Changed the SOC in 2026
Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Machine Speed, Human Judgement: How AI Changed the SOC in 2026

Having spent time in the Cisco Live Americas 2026 SOC, one thing became abundantly clear:The way SOCs operate today is fundamentally different from even a few years ago.

Instead of spending time gathering information, analysts could spend more time understanding what the information actually meant.

Just as spreadsheets empowered business users decades ago, AI-assisted coding is beginning to empower security analysts today.

At Cisco Live, AI was already present throughout the workflow:Incident summaries generated automatically within XDR.

And based on what I saw at Cisco Live 2026, that future has already arrived.

3 weeks, 2 days назад @ blogs.cisco.com
Elevating Expertise in the SOC
Elevating Expertise in the SOC Elevating Expertise in the SOC

The new SOC analysts were great at finding evidence, helped with triage and correlation by the AI agents in the SOC architecture.

With the advancements in Cloud Control, our new SOC Analysts can validate their hypothesis.

They had the ability to investigate the incident and find the root cause found in Splunk Security and Endace.

Instant Attack VerificationIn each Incident, the SOC Analysts is given an AI generated Summary stitching all the relevant logs from all the sources that are related to the objects in question.

Check out the blogs by the engineers who worked inside the SOC at Las Vegas:

3 weeks, 2 days назад @ blogs.cisco.com
Educate at Event Speed: Cisco Live Security Operations Center
Educate at Event Speed: Cisco Live Security Operations Center Educate at Event Speed: Cisco Live Security Operations Center

At Cisco Live AMER 2026 in Las Vegas, my work with the Cisco Event SOC centered on one outcome that makes these deployments valuable beyond the event itself: Education.

The SOC protects the conference, but it also turns live operations into a learning environment through SOC tours, Cisco Live sessions, training inside the SOC, and conversations in the World of Solutions.

Bringing live SOC lessons into the classroomEducation also happened in the sessions I delivered at Cisco Live.

Cisco Live AMER 2026 reinforced that the SOC is one of the best classrooms we have because it teaches through real operations.

For a deeper look at the model behind these deployments, read the Cisco Event SOCs: A R…

3 weeks, 2 days назад @ blogs.cisco.com
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

Inside the Cisco Live SOCAt Cisco Live AMER, the Security Operations Center (SOC) is more than a demo environment.

For a broader look at how the Cisco Live SOC operates, read this overview.

Another part was spent in the SOC, working real investigations with XDR, Splunk Enterprise Security, firewall events, DNS telemetry, packet data, and AI assistance.

AI can help a product manager become useful faster in a live SOC.

That is the bar I want us to continue building toward as we build Cisco XDR and Splunk Security.

3 weeks, 2 days назад @ blogs.cisco.com
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC

As part of the Cisco XDR (Extended Detection and Response) product engineering group, a few of us got exactly that chance.

Every product had a part to play for a network as traffic-heavy as Cisco Live.

(PS : Flaunting the SOC T-shirts was fun)AcknowledgementsA heartfelt thank you to Cisco and the entire SOC team — you are all amazing.

To the Cisco XDR , Splunk , Secure Access , and Secure Firewall engineering teams.

Check out the other blogs from our team at the Cisco Live Americas 2026 SOC at Las Vegas:

3 weeks, 2 days назад @ blogs.cisco.com
The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth
The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth

We built an Experience Score model on Cisco and Splunk infrastructure and watched it run against real traffic, at real scale, in real time.

The result was a working model for how leaders measure what customers feel, act before friction surfaces, and tie operational decisions to revenue and trust.

At Cisco Live, the Experience Score model organized that architecture around four questions business and technology leaders can answer together.

The composite Experience Score tells a leader whether the experience is healthy enough to protect the moments the business depends on.

From Cisco Live to LA28Cisco Live was a rehearsal for larger exposure surfaces, where digital experience, revenue, brand …

3 weeks, 2 days назад @ blogs.cisco.com
AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026
AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026

And we kept thinking the same engineer thought: this flow is so consistent… could an agentic agent do the first 90%?

It was a great experiment — and a glimpse of a fully self-hosted agentic SOC — but for the event we pivoted to Claude Opus 4.8 running through Claude Code.

The division of labor we landed on: Tier-1 agentic SOC was already handled beautifully by the AI features in our own products — XDR’s Agentic Attack Storyboard and Splunk’s Triage Agent.

What does an agentic SOC actually need?

The MCP servers — an Endace MCP for packet capture/decode and a Splunk MCP for running queries.

3 weeks, 2 days назад @ blogs.cisco.com
Building the Agentic SOC at Cisco Live Americas 2026
Building the Agentic SOC at Cisco Live Americas 2026 Building the Agentic SOC at Cisco Live Americas 2026

Building on the Cisco Live EMEA SOC, Cisco Live Americas placed the Security Operations Center (SOC) and Network Operations Center (NOC) at the center of the World of Solutions, demonstrating the power of Cisco in bringing Networking, Security and Observability together.

The Cisco Live Americas Agentic SOC architecture shows how a “One Cisco” approach brings different security tools together to eliminate data silos, in close partnership with the NOC.

The SOC at Cisco Live was set up in just two days, thanks to lessons learned and continuous evolution.

For Cisco Live AMER, we treated agentic AI as an auditable review layer across the SOC, not as a replacement for analysts.

Agentic SOC: Incid…

3 weeks, 2 days назад @ blogs.cisco.com
Ten Years in the SOC at RSAC: What We Learned in 2026
Ten Years in the SOC at RSAC: What We Learned in 2026 Ten Years in the SOC at RSAC: What We Learned in 2026

Cisco Security and Splunk Security released the Findings Report from the Security Operations Center at RSAC 2026 Conference.

This year marked the 10th year of the SOC at RSAC.

Those lessons helped inform the Agentic SOC work that followed at Cisco Live Americas 2026.

The SOC used Cisco AI Defense to gain visibility into generative AI application usage and to help protect on-premises AI models running in the SOC in a Box.

Download the full RSAC 2026 SOC Findings Report to see the architecture, metrics, investigations, lessons learned, and recommendations from the 10th year of the SOC.

1 month назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 23 часа назад
​​​​What’s new in Microsoft Security: July 2026
​​​​What’s new in Microsoft Security: July 2026 ​​​​What’s new in Microsoft Security: July 2026

Microsoft Defender Experts services are also expanding: Microsoft Defender Experts Threat Intelligence delivers human-led, curated insight into the cyberthreats most relevant to each organization, and Microsoft Defender Experts MDR extends expert-run detection and response beyond the Microsoft estate into third-party and multicloud signals through Microsoft Sentinel.

Together, the Insider Risk Management alert experience and Data Security Triage Agent help security teams investigate faster and with greater confidence.

In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy.

To learn more about Microsoft Security solutio…

23 часа назад @ microsoft.com
​​Better security starts with better questions
​​Better security starts with better questions ​​Better security starts with better questions

That starts with asking better questions—the kind that help organizations turn intelligence into action and trust into a foundation for progress.

But better security does not start with more information.

Understanding those connections is what allows security teams to use platforms, AI, and automation to make better decisions under real-world conditions.

Better analysis can surface more insights, but better decisions still depend on understanding what matters most and applying the right context.

Better security starts with better questions, and with the clarity to act on them.

1 day, 23 hours назад @ microsoft.com
Rethinking security for the age of AI
Rethinking security for the age of AI Rethinking security for the age of AI

The approaches built for a world of human actors cannot keep pace with a world of AI, agents and machine-speed attacks.

Microsoft transforms its breadth of visibility, threat intelligence and security expertise into a security context that connects security data, knowledge and semantics across the digital estate.

By grounding every interaction in this rich security context, Project Perception improves the accuracy and consistency of reasoning while reducing the time, compute and cost required to operate at scale.

Our security researchers continuously assess models against real-world security workflows, enabling us to match each task with the model that delivers the best outcome.

Tags: AI, P…

3 days, 23 hours назад @ blogs.microsoft.com
Enhancing AI security through global AI red teaming
Enhancing AI security through global AI red teaming Enhancing AI security through global AI red teaming

Microsoft’s AI Red Team has observed that meaningful testing of advanced AI systems- and models similarly requires broader participation from researchers and practitioners who operate outside traditional corporate security boundaries.

To address that gap, today we are announcing the External Red Team Alliance (EXTRA), a formalized global extension of Microsoft’s AI Red Team designed to support and encourage external expertise to advance AI safety and security testing.

Building a global allianceEXTRA is a two-part initiative focused on expanding AI safety research and strengthening external collaboration.

The first component supports a global academic network focused on advancing AI safety a…

3 days, 23 hours назад @ microsoft.com
Enhancing AI security through global AI red teaming
Enhancing AI security through global AI red teaming Enhancing AI security through global AI red teaming

Microsoft’s AI Red Team has observed that meaningful testing of advanced AI systems- and models similarly requires broader participation from researchers and practitioners who operate outside traditional corporate security boundaries.

To address that gap, today we are announcing the External Red Team Alliance (EXTRA), a formalized global extension of Microsoft’s AI Red Team designed to support and encourage external expertise to advance AI safety and security testing.

Building a global allianceEXTRA is a two-part initiative focused on expanding AI safety research and strengthening external collaboration.

The first component supports a global academic network focused on advancing AI safety a…

3 days, 23 hours назад @ microsoft.com
Email threat landscape: Q2 2026 trends and insights
Email threat landscape: Q2 2026 trends and insights Email threat landscape: Q2 2026 trends and insights

Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs.

Q2 AiTM token compromise April phishing campaign tactics, detections, and mitigations ›This blog provides a view of email threat activity across the second quarter of 2026, highlighting key trends in phishing techniques, payload delivery, and threat actor behavior observed by Microsoft Threat Intelligence.

email threat landscape Q1 trends that shaped Q2 activity ›Figure 1.

Trend of QR code phishing attacks by weekly volume (January 2026–June 2026)The delivery methods used in QR code attacks shifted notably during Q2.

To he…

1 week, 1 day назад @ microsoft.com
Email threat landscape: Q2 2026 trends and insights
Email threat landscape: Q2 2026 trends and insights Email threat landscape: Q2 2026 trends and insights

Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs.

Q2 AiTM token compromise April phishing campaign tactics, detections, and mitigations ›This blog provides a view of email threat activity across the second quarter of 2026, highlighting key trends in phishing techniques, payload delivery, and threat actor behavior observed by Microsoft Threat Intelligence.

email threat landscape Q1 trends that shaped Q2 activity ›Figure 1.

Trend of QR code phishing attacks by weekly volume (January 2026–June 2026)The delivery methods used in QR code attacks shifted notably during Q2.

To he…

1 week, 1 day назад @ microsoft.com
Real world incident response: Microsoft and AXA XL strengthen cyber resilience
Real world incident response: Microsoft and AXA XL strengthen cyber resilience Real world incident response: Microsoft and AXA XL strengthen cyber resilience

That experience continues to shape how we design Defender Experts Cybersecurity Incident Response—and how we work with partners like AXA XL.

Incident response must extend beyond technologyAs a global insurance provider, AXA XL plays a critical role in helping organizations navigate cyber risk and response.

AXA XL’s strategic partnerships with cyber incident response providers underscore our commitment to expertise, preparedness, and resilience.

Incident response engineered for high-stakes moments—and the readiness behind themWhat differentiates Microsoft Defender Experts Cybersecurity Incident Response is not only its deep technical expertise, but its direct connection to Microsoft engineer…

1 week, 1 day назад @ microsoft.com
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

Follow the research in the Black Hat BriefingsMicrosoft Security researchers will also present peer-reviewed technical research in the Black Hat Briefings.

Visit booth #2144 for research, community, and hands-on defenseThis year we are transforming the Microsoft Security booth into a community center.

Partner presenceAt Black Hat 2026, the Microsoft booth will feature 13 partners from the Microsoft Intelligent Security Association (MISA) who will showcase solutions built with Microsoft Security technology.

Skill up before and after Black HatYou do not need to be in Las Vegas to take part in the broader Microsoft Security Black Hat experience.

The Microsoft Black Hat Skilling Challenge begin…

1 week, 6 days назад @ microsoft.com
ACR Stealer: Two observed intrusion chains amid increased threat activity
ACR Stealer: Two observed intrusion chains amid increased threat activity ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments.

Security teams should prioritize monitoring for ClickFix lures, suspicious WebDAV activity, obfuscated PowerShell execution, and attempts to access browser credential stores.

Microsoft Defender XDR detectionsMicrosoft Defender XDR customers can refer to the list of applicable detections below.

]art Payload hosting siteReferencesLearn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelligence community about the ev…

2 weeks назад @ microsoft.com
ACR Stealer: Two observed intrusion chains amid increased threat activity
ACR Stealer: Two observed intrusion chains amid increased threat activity ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments.

Security teams should prioritize monitoring for ClickFix lures, suspicious WebDAV activity, obfuscated PowerShell execution, and attempts to access browser credential stores.

Microsoft Defender XDR detectionsMicrosoft Defender XDR customers can refer to the list of applicable detections below.

]art Payload hosting siteReferencesLearn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelligence community about the ev…

2 weeks назад @ microsoft.com
Least privilege for AI agents: Identity, access, and tool binding
Least privilege for AI agents: Identity, access, and tool binding Least privilege for AI agents: Identity, access, and tool binding

When an agent operates without a managed identity and least-privilege role-based access controls (RBAC), it can access or modify sensitive data beyond intended permissions if controls are not properly configured.

Organizations are deploying agentic capabilities (multi-step automation, delegated actions, tool use) faster than their identity and authorization models are evolving to safely constrain them.

The right mental model is to treat every agent as a first-class principal: give it a lifecycle-managed identity, assign explicit roles, scope its permissions tightly, and scope tool usage to a preconfigured tools manifest or configuration.

In the next 30–90 days, inventory your agent identiti…

2 weeks назад @ microsoft.com
Least privilege for AI agents: Identity, access, and tool binding
Least privilege for AI agents: Identity, access, and tool binding Least privilege for AI agents: Identity, access, and tool binding

When an agent operates without a managed identity and least-privilege role-based access controls (RBAC), it can access or modify sensitive data beyond intended permissions if controls are not properly configured.

Organizations are deploying agentic capabilities (multi-step automation, delegated actions, tool use) faster than their identity and authorization models are evolving to safely constrain them.

The right mental model is to treat every agent as a first-class principal: give it a lifecycle-managed identity, assign explicit roles, scope its permissions tightly, and scope tool usage to a preconfigured tools manifest or configuration.

In the next 30–90 days, inventory your agent identiti…

2 weeks назад @ microsoft.com
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

On July 14, 2026, Microsoft Threat Intelligence identified a coordinated supply chain compromise of the @asyncapi npm organization, a widely used set of packages for the AsyncAPI specification and code generation.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories a…

2 weeks, 1 day назад @ microsoft.com
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

On July 14, 2026, Microsoft Threat Intelligence identified a coordinated supply chain compromise of the @asyncapi npm organization, a widely used set of packages for the AsyncAPI specification and code generation.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories a…

2 weeks, 1 day назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 3 months, 1 week назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

3 months, 1 week назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

3 months, 3 weeks назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

3 months, 3 weeks назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

3 months, 4 weeks назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

4 months назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

4 months, 1 week назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

5 months назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

5 months назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

5 months, 1 week назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

6 months назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

7 months, 3 weeks назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

7 months, 3 weeks назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

7 months, 3 weeks назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

7 months, 4 weeks назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

8 months, 1 week назад @ security.googleblog.com