Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 1 час назад
5 биткоинов и меньше суток — именно столько хакеры дали властям на раздумья после взлома сайта президента
5 биткоинов и меньше суток — именно столько хакеры дали властям на раздумья после взлома сайта президента 5 биткоинов и меньше суток — именно столько хакеры дали властям на раздумья после взлома сайта президента

Иначе — утечка секретных данных. Каких? Никто не знает.

1 час назад @ securitylab.ru
Bluetooth в зоне досягаемости — и ваше авто можно угнать. Специалисты раскрыли уязвимость сигнализации KARR
Bluetooth в зоне досягаемости — и ваше авто можно угнать. Специалисты раскрыли уязвимость сигнализации KARR

Хакеры нашли способ взламывать 2 млн автомобилей удалённо.

1 час назад @ securitylab.ru
839 новых вирусов за квартал. Positive Technologies рассказала, как хакеры удвоили арсенал атак на российские компании
839 новых вирусов за квартал. Positive Technologies рассказала, как хакеры удвоили арсенал атак на российские компании

Число новых образцов вредоносного ПО хакерских группировок выросло на 88% за год.

1 час назад @ securitylab.ru
Атака, которая выглядит как обычная работа ИИ-агента. На что охотится новый червь в NPM-инфраструктуре разработчиков
Атака, которая выглядит как обычная работа ИИ-агента. На что охотится новый червь в NPM-инфраструктуре разработчиков

Специалисты CrowdStrike нашли червя, способного уничтожать файлы в зараженных системах разработки.

2 часа назад @ securitylab.ru
Дипломаты Южной Кореи умеют хранить государственные секреты — а вот свои пароли уберечь не смогли
Дипломаты Южной Кореи умеют хранить государственные секреты — а вот свои пароли уберечь не смогли

Целый год хакеры гуляли по системе МИД. Просто через курсы повышения квалификации.

2 часа назад @ securitylab.ru
В Google не смогли доделать текущую модель и пошли обучать следующую. Главный соперник ChatGPT прочно застрял в лаборатории
В Google не смогли доделать текущую модель и пошли обучать следующую. Главный соперник ChatGPT прочно застрял в лаборатории В Google не смогли доделать текущую модель и пошли обучать следующую. Главный соперник ChatGPT прочно застрял в лаборатории

Компания обещала этот запуск ещё в мае, но сроки снова сдвинулись.

3 часа назад @ securitylab.ru
ИИ на службе хакеров. ChatGPT, Gemini и Claude начали предлагать пользователям устанавливать вирусы с GitHub
ИИ на службе хакеров. ChatGPT, Gemini и Claude начали предлагать пользователям устанавливать вирусы с GitHub

Настоящие имена и фальшивые звёзды сделали приманку почти неотличимой от обычного проекта.

3 часа назад @ securitylab.ru
Один VPN — и вся сеть под контролем Qilin. Palo Alto опять подставила клиентов со своими дырявыми шлюзами
Один VPN — и вся сеть под контролем Qilin. Palo Alto опять подставила клиентов со своими дырявыми шлюзами

Всего одной бреши хватило, чтобы полностью разрушить цифровую инфраструктуру.

4 часа назад @ securitylab.ru
Показал один раз — робот запомнил: в Claude Cowork появилась функция обучения по записи экрана
Показал один раз — робот запомнил: в Claude Cowork появилась функция обучения по записи экрана

Для автоматизации рутины больше не понадобятся ни код, ни подробные команды.

4 часа назад @ securitylab.ru
440 уязвимостей за 48 часов: в Linux случился рекордный всплеск CVE
440 уязвимостей за 48 часов: в Linux случился рекордный всплеск CVE 440 уязвимостей за 48 часов: в Linux случился рекордный всплеск CVE

Спокойно: это не то, чем кажется.

5 часов назад @ securitylab.ru
Касперский обнаружил технику ConsentFix, позволяющую взламывать аккаунты Microsoft 365 без пароля
Касперский обнаружил технику ConsentFix, позволяющую взламывать аккаунты Microsoft 365 без пароля

Ни один пароль не пострадал, но доступ к переписке всё равно оказался у чужих людей.

5 часов назад @ securitylab.ru
1800 преступников. 15 тысяч кампаний в месяц. 35 стран жертв. Полиция изъяла у сети Kratos более 200 серверов
1800 преступников. 15 тысяч кампаний в месяц. 35 стран жертв. Полиция изъяла у сети Kratos более 200 серверов

Международная операция оборвала схему, которой пользовались тысячи киберпреступников.

6 часов назад @ securitylab.ru
Xiaomi скормила роботу 100 000 часов видео — и он раздавил всех конкурентов по показателям
Xiaomi скормила роботу 100 000 часов видео — и он раздавил всех конкурентов по показателям

Пока другие роботы учатся годами, XR-1 освоил бытовые задачи за несколько часов.

6 часов назад @ securitylab.ru
Инженер против алгоритма. Какие специалисты останутся востребованными после прихода ИИ
Инженер против алгоритма. Какие специалисты останутся востребованными после прихода ИИ Инженер против алгоритма. Какие специалисты останутся востребованными после прихода ИИ

На открытой дискуссии эксперты разберут, какие задачи заберёт автоматизация и какие навыки сохранят ценность на рынке.

7 часов назад @ securitylab.ru
OpenAI берет на себя ответственность за взлом платформы Hugging Face
OpenAI берет на себя ответственность за взлом платформы Hugging Face

Эксперимент должен был пройти в песочнице, но что-то пошло совсем не по плану.

7 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 4 часа назад
Девять безопасных DNS-резольверов, доступных в России
Девять безопасных DNS-резольверов, доступных в России Девять безопасных DNS-резольверов, доступных в России

Таких случаев было немало, в том числе и в России, иногда с очень печальными последствиями.

Сервисы, доступные в РоссииТребование к сервисам для обзора было по большому счёту одно: корректная работа в России по состоянию на конец июня 2026 года.

Она как самостоятельно, так и в сотрудничестве с 18 другими организациями и компаниями, в том числе, например, IBM, собирает данные о проблемных доменах.

И в целом Quad9 пока не был замечен ни в одном инциденте, связанном с безопасностью.

Рассчитан не только на конечных пользователей, но и на использование в организациях, в том числе сферы образования и детского отдыха.

4 часа назад @ anti-malware.ru
SIEM в АСУ ТП: как построить мониторинг, который помогает производству, а не мешает
SIEM в АСУ ТП: как построить мониторинг, который помогает производству, а не мешает SIEM в АСУ ТП: как построить мониторинг, который помогает производству, а не мешает

В АСУ ТП проблема редко заключается только в том, что не хватает SIEM.

Ключевые сложности мониторинга в АСУ ТПНа практике трудности связаны в основном не с возможностями самой SIEM, а с особенностями промышленной инфраструктуры.

События из технологического сегмента поступают редко или не поступают вообщеОдна из главных проблем — не качество SIEM, а отсутствие стабильного потока данных из АСУ ТП.

Что получает CISOДля руководителя ИБ ценность SIEM в АСУ ТП не в том, что «ещё один сегмент подключили к мониторингу».

ВыводыSIEM в АСУ ТП не решает задачу сама по себе.

23 часа назад @ anti-malware.ru
Как атакуют e-commerce? Опыт BrandSecurity и М.Видео
Как атакуют e-commerce? Опыт BrandSecurity и М.Видео Как атакуют e-commerce? Опыт BrandSecurity и М.Видео

Как меняется ландшафт угроз в электронной коммерции и как удалось добиться удаления 97,5 % всех выявленных нарушений за 6 лет сотрудничества BrandSecurity и «М.Видео».

На примере многолетнего сотрудничества «М.Видео» и BrandSecurity рассмотрим, как выстроить такую систему защиты и какие результаты получены за шесть лет работы.

Как меняется ландшафт угроз для брендов в электронной коммерцииМошенники стремятся обмануть как можно больше пользователей, поэтому они имитируют популярные магазины и бренды, уже завоевавшие доверие.

Чтобы минимизировать репутационные риски, необходимо отслеживать:пустые боты и каналы с логотипом бренда;визуально схожие домены и страницы;упоминания бренда в акциях и …

1 day, 5 hours назад @ anti-malware.ru
Суверенные GPU-платформы: как компании строят безопасную инфраструктуру для ИИ
Суверенные GPU-платформы: как компании строят безопасную инфраструктуру для ИИ Суверенные GPU-платформы: как компании строят безопасную инфраструктуру для ИИ

Сервер (узел) с восемью графическими процессорами (Источник: APNIC)Где брать GPU‑ресурсы:Выделенные серверы (bare metal) — физический сервер с GPU полностью в распоряжении компании.

Как работают вместе GPU‑инфраструктура и суверенные облакаКомпания арендует кластеры GPU не в любом публичном облаке, а в суверенном.

Данные, журналы, модели и сервисы остаются внутри защищённой инфраструктуры, а провайдер выполняет требования 152‑ФЗ, приказов ФСТЭК, норм для КИИ и отраслевых стандартов.

Шифрование и управление ключамиДанные шифруются в покое и в движении.

Компании переходят к гибридным схемам, используют механизмы разделения GPU и усиливают требования к прозрачности и безопасности.

2 days, 1 hour назад @ anti-malware.ru
Какая российская серверная ОС лучше подойдёт бизнесу: сравнение 9 решений
Какая российская серверная ОС лучше подойдёт бизнесу: сравнение 9 решений Какая российская серверная ОС лучше подойдёт бизнесу: сравнение 9 решений

Виртуальные контексты и производительность, часть IIПараметр / Продукт Атлант ОСнова РЕД ОС РОСА Хром Виртуализация Да Да Да Да Отказоустойчивая конфигурация Сведения отсутствуют Сведения отсутствуют Да Да Балансировка нагрузки Сведения отсутствуют Сведения отсутствуют Да Да Высокая доступность (HA) Сведения отсутствуют Сведения отсутствуют Да Да Контейнеризация приложений Да (Docker, Podman, Kubernetes) Да (Docker, Podman, Kubernetes) Да (Docker, Podman, Kubernetes) Да (Docker, Podman, Kubernetes) Встроенные инструменты оптимизации производительности Сведения отсутствуют Сведения отсутствуют Да (TuneD) Да (TuneD)Таблица 4.1.

Службы сетевой инфраструктуры «из коробки», часть IПараметр / Про…

2 days, 6 hours назад @ anti-malware.ru
Удалёнка без защиты: почему VPN и MFA больше не работают
Удалёнка без защиты: почему VPN и MFA больше не работают Удалёнка без защиты: почему VPN и MFA больше не работают

Стоимость простоя после кибератаки достигает 21,7 млн рублей в час для ИТ- и телеком-компаний и 9,6 млн рублей в час для ритейла.

Компания не управляет его сетью, устройством, каналами связи и окружением и не может гарантировать, что сессия остаётся безопасной.

ИТ-отдел не видит трафик и устройства сотрудников, а значит, не может блокировать доступ к неавторизованным сервисам.

Он шифрует трафик, но не контролирует устройство, не отслеживает состояние сессии и не ограничивает доступ внутри сети.

VPN не проверяет состояние устройства и не управляет сессией.

5 days назад @ anti-malware.ru
Чем опасен вайбкодинг и как проверять код, созданный ИИ
Чем опасен вайбкодинг и как проверять код, созданный ИИ Чем опасен вайбкодинг и как проверять код, созданный ИИ

Интеграция ИИ в конвейер безопасной разработки, как это часто бывает сегодня, становится ответом на рост вызовов и угроз, связанных с применением нейросетевых инструментов как в разработке, так и злоумышленниками в ходе атак.

ИИ как вызовКак показало исследование ГК «Солар» и УЦСБ, инструменты с ИИ для написания и анализа программного кода используют 80 % опрошенных российских компаний.

Руководитель отдела разработки пользовательского интерфейса компании «НЕКСТБИ» Григорий Голиков среди организационных рисков выделил появление кода, который внешне работает, но не адаптируется, не оптимизирован и небезопасен: непрозрачен, потенциально уязвим и не проходит проверку.

ИИ как инструмент злоумышл…

5 days, 5 hours назад @ anti-malware.ru
Как выбрать DRP-сервис для защиты от внешних угроз
Как выбрать DRP-сервис для защиты от внешних угроз Как выбрать DRP-сервис для защиты от внешних угроз

ВведениеDigital Risk Protection (DRP) — это не просто модный термин, а насущная необходимость для любой компании, у которой есть сайт, бренд или сотрудники.

Ландшафт угроз: почему DRP становится обязательнымИлья Шабанов провёл параллель между DRP и концепцией раннего обнаружения.

Компании не всегда осознают наличие у себя таких проблем, им стоит протестировать профильные решения, чтобы увидеть свою компанию глазами злоумышленников.

Во втором опросе зрители поделились, как у них в компании организован мониторинг внешних цифровых рисков:Мониторят своими силами — 42 %.

Прогнозы: куда движется рынок DRPСтанислав Гончаров: «Мы запускаем версию DRP Light для руководителей SOC-центров, для юристов…

5 days, 21 hours назад @ anti-malware.ru
Тестирование Phishman 2.35, системы повышения осведомлённости пользователей в сфере ИБ
Тестирование Phishman 2.35, системы повышения осведомлённости пользователей в сфере ИБ Тестирование Phishman 2.35, системы повышения осведомлённости пользователей в сфере ИБ

На основании созданного правила была сформирована группа для обучения: в неё вошли люди, которые были скомпрометированы в ходе первичного тестирования.

Отчёт по динамике обучения в Phishman 2.35Анализ показал, что часть сотрудников не завершила обучение в установленный срок.

Как и на первом этапе, основной задачей было сделать письмо максимально похожим на стандартную рабочую переписку, соответствующую реальным бизнес-процессам нашей компании.

Информационная панель Phishman 2.35 после завершения экспериментаПосле обучения и повторного тестирования добавились другие показатели:Обученность — 11 / 100.

Поддержка была доступна не только в рабочее время, но и в выходные дни.

6 days, 6 hours назад @ anti-malware.ru
ИИ-ассистенты как угроза безопасности: как чат-боты сливают данные компаний
ИИ-ассистенты как угроза безопасности: как чат-боты сливают данные компаний ИИ-ассистенты как угроза безопасности: как чат-боты сливают данные компаний

Корректное проектирование архитектуры, контроль источников данных и управление контекстом выполнения ИИ-систем существенно уменьшили бы их влияние.

Промпт-инъекция не проявляется как SQL-инъекция и не использует структурированные запросы — это обычный текст, встроенный в контекст обработки.

Отличие от разовой инъекции в том, что воздействие закрепляется в данных и влияет на дальнейшую работу системы на постоянной основе.

Агент начинает использовать это как норму при анализе событий.

Эксплуатация доверия (Human-Agent Trust Exploitation, ASI09)Злоумышленники используют доверие к агенту как к «компетентному собеседнику».

6 days, 6 hours назад @ anti-malware.ru
Как вернуть контроль над неструктурированными данными при помощи DCAP
Как вернуть контроль над неструктурированными данными при помощи DCAP Как вернуть контроль над неструктурированными данными при помощи DCAP

Разберём, как выявить эти проблемы и устранить их с помощью решений класса DCAP на примере «Спектр | DCAP».

По опыту экспертов «Кросстеха» и «Сайберпик», описанная проблема есть и в небольших компаниях, и в зрелом бизнесе с выстроенной информационной безопасностью (ИБ).

Фиксация «Спектр | DCAP» аномальной активности пользователяОбласть применения DCAP не ограничивается папками общего доступа в операционных системах Windows и Linux.

Но само по себе, как и любое СЗИ, оно не может существовать изолированно и полностью закрывать задачу защиты от утечек.

Даже при наличии технических средств защиты сотрудники должны понимать, как работать с данными в рамках своих должностных обязанностей.

1 week назад @ anti-malware.ru
Обзор Phishman 2.35, системы повышения осведомлённости пользователей в сфере ИБ
Обзор Phishman 2.35, системы повышения осведомлённости пользователей в сфере ИБ Обзор Phishman 2.35, системы повышения осведомлённости пользователей в сфере ИБ

Phishman 2.35 — система повышения киберосведомлённости пользователей в ИБ, в которой отказались от единой программы обучения в пользу подхода, учитывающего различия в поведении пользователей и уровне цифровых рисков.

Главная или информационная панель системыНа главной странице представлена сводная информация об обученности, иммунности и киберосознанности сотрудников и др.

Раздел «Настройки» в Phishman 2.35Одним из наиболее востребованных инструментов в ходе нашего эксперимента стал журнал событий.

Не диагностирует и не оказывает услуги в отношении телекоммуникационного, инфраструктурного и прочего оборудования, не входящего в Phishman.

Обновления системы доступны как в формате файлового арх…

1 week назад @ anti-malware.ru
Российские решения Security Awareness: сравнение платформ для обучения киберграмотности
Российские решения Security Awareness: сравнение платформ для обучения киберграмотности Российские решения Security Awareness: сравнение платформ для обучения киберграмотности

Сравниваем российские решения класса Security Awareness по 40+ критериям: учебные курсы, имитация фишинга, кастомизация, отчётность, лицензирование и поддержка.

Нет Да (помимо основного учебного курса есть экспресс-курс) Нет Да ДаТаблица 8.

Отчёты, часть IПараметр / Продукт Infosecurity Security Awareness Kaspersky Security Awareness Phishman RED Security Awareness Secure-T Awareness Отчёты по обучению Да Да Да Да Да Отчёты по атакам Да Да Да Да Да Аналитические отчёты Частично (как опция технической поддержки сервиса) Да Да Да Да Пользовательские отчёты Нет Да Да Да ДаТаблица 10.

Отчёты, часть IIПараметр / Продукт Solar Security Awareness Start AWR T2 Security Awareness UBS Cybersecurity A…

1 week, 1 day назад @ anti-malware.ru
Российские мобильные операционные системы: обзор рынка 2026 года
Российские мобильные операционные системы: обзор рынка 2026 года Российские мобильные операционные системы: обзор рынка 2026 года

ВведениеМобильные устройства, как массовые, так и специализированные, весьма широко используются в бизнес-процессах компаний и в деятельности государственных служащих.

По довольно консервативной оценке, по состоянию на конец 2025 года в России было скомпрометировано около 1,5 млн мобильных устройств на Android.

Российский рынок мобильных устройствПо итогам 2025 года в России было продано около 24 млн смартфонов, что на четверть меньше уровня 2024 года.

И в том, и в другом сегментах рынка доминируют зарубежные вендоры.

Предустанавливается на мобильные устройства целого ряда российских вендоров, включая «Аквариус», F-Plus, Highscreen, Kvadra, Mobile Inform Group как для потребительского рынка…

1 week, 1 day назад @ anti-malware.ru
ИИ-агенты и Platform Engineering: как внедрять Agentic AI в бизнесе
ИИ-агенты и Platform Engineering: как внедрять Agentic AI в бизнесе ИИ-агенты и Platform Engineering: как внедрять Agentic AI в бизнесе

Подходы к построению инфраструктуры для них развиваются в дисциплине Platform Engineering, которая существенно изменилась с появлением Agentic AI.

Константин объяснил:«Заказчики приходят за инфраструктурой для ИИ и готовой платформой поверх неё, а не за реализацией конкретной функции через ИИ.

Необходимо детально проработать экономическую модель внедрения и эксплуатации — выполнить расчёт совокупной стоимости владения (Total Cost of Ownership, TCO) при построении ИИ-агентских платформ».

Перспективы внедрения в России проприетарных западных решений (в их полноразмерной конфигурации) достаточно неопределённы.

Внедрение изменений с появлением ИИ — это долговременный процесс, общие контуры кото…

1 week, 4 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 1 час назад
Мост между SAST и фаззингом: как из сработки SAST получить подтверждённую уязвимость
Мост между SAST и фаззингом: как из сработки SAST получить подтверждённую уязвимость Мост между SAST и фаззингом: как из сработки SAST получить подтверждённую уязвимость

Но он не знает, дойдёт ли до этой строки реальный запрос пользователя, и не может проверить свою же догадку.

Одиночная находка – это не приговор что это «ложь», но и не повод для высокого доверия.

Но каждое его решение мы запоминаем и складываем в память триажа и в общий журнал.

* и подобные;· сторонняя зависимость – всё, что не первое и не второе;· неизвестно – не удалось извлечь имя.

Мы сохраняем и вход, на котором возникает сбой, и стек, и имя нагрузки – разработчик может прогнать сам и убедиться.

1 час назад @ habr.com
От сотен алертов к доказанным уязвимостям: как эволюционирует DevSecOps при объединении 7 сканеров в единый пайплайн
От сотен алертов к доказанным уязвимостям: как эволюционирует DevSecOps при объединении 7 сканеров в единый пайплайн От сотен алертов к доказанным уязвимостям: как эволюционирует DevSecOps при объединении 7 сканеров в единый пайплайн

Статья продуктовая, но мы ее публикуем на HABR не как рекламную, а как концептуальную.

Уязвимость может быть не только в вашем коде, а в open-source библиотеке, а секрет может лежать в .env, тестовом конфиге или старом коммите.

И главная проблема не в отсутствии сканеров, а в отсутствии единой картины рисков и доказанной приоритезации задач.

Когда pipeline падает только по подтверждённым рискам, блокировка воспринимается не как каприз сканера, а как инженерный факт.

Во-первых, разработчик и AppSec смотрят на один и тот же объект, а не на разные отчёты из разных систем.

1 час назад @ habr.com
Thales Group: отчёт о роли ИИ в информационной безопасности
Thales Group: отчёт о роли ИИ в информационной безопасности Thales Group: отчёт о роли ИИ в информационной безопасности

Кроме ставших привычными изменений, вызванных внедрением ИИ на предприятиях и в компаниях, ситуацию стали усложнять ИИ-агенты.

Исследование отмечает, рост числа организаций (на 50% в год), выделяющих бюджет на информационную безопасность именно для обеспечения защиты в связи с применением ИИ.

Эксперты сходятся в том, что по мере использования агентных ИИ необходимо улучшать способы обеспечения внутренней безопасности, иначе ИИ быстро станет внутренней угрозой.

Учитывая большие объемы данных, используемых ИИ, и возросшую их доступность, связанную с агентами ИИ, шифрование является обязательной мерой обеспечения безопасности.

Видите ли вы пользу от применения ИИ в рабочих процессах, или риско…

2 часа назад @ habr.com
Вайб-кодинг против ИБэшника. Несмертельная битва. Часть 1
Вайб-кодинг против ИБэшника. Несмертельная битва. Часть 1 Вайб-кодинг против ИБэшника. Несмертельная битва. Часть 1

Отдельную установку для администратора и сотрудника;2.

│└───────────────────┬─────────────────────────┘│ локальная сеть▼┌ Компьютер администратора ──────────────────┐│ Такая же программа, но с другой ролью.

Отдельный установщик для администратора и отдельный установщик для компьютера сотрудника;2.

Пользователь пилота - не бесплатная тестовая инфраструктура и не человек, обязанный радоваться нашей скорости.

Для Windows используются разные установщики: один для администратора, другой для сотрудника;3.

3 часа назад @ habr.com
Не просто коробка с деньгами: будни инженера сопровождения, который поддерживает банкоматы в строю
Не просто коробка с деньгами: будни инженера сопровождения, который поддерживает банкоматы в строю Не просто коробка с деньгами: будни инженера сопровождения, который поддерживает банкоматы в строю

Инженеры работают как с банкоматами, так и с устройствами самоинкассации, счётно-сортировальными машинами, детекторами валют, вакуумными упаковщиками и многими другими электронными устройствами.

А если не ломаются, то это значит, что к ним просто никто не подходит.

Я видел банкоматы, которые не требовали ремонта годами, но не потому, что они были так надежны — просто у них не было посетителей месяцами.

Некритичные модули можно снять и заменить не затрагивая остальные части банкомата, например, монитор, а с критичными сложнее — они друг с другом жестко связаны.

Когда производитель выявляет проблемы устройств, то вносит апдейты даже не в следующим поколении, а в текущем.

3 часа назад @ habr.com
OSINT для ленивых. Часть 13: ShodanX
OSINT для ленивых. Часть 13: ShodanX OSINT для ленивых. Часть 13: ShodanX

Нет, это не новая версия Shodan, и не супер-пупер хацкерский форк.

Это - инструмент, который работает как CLI-инструмент для автоматизации разведки, который использует данные Shodan, и не является самостоятельным ресурсом.

Ключ API Shodan — необходим для авторизованного доступа к большинству сервисов Shodan.

shodanx auth → Настроить и сохранить ваш ключ API Shodan для аутентифицированного доступа.

shodanx internetdb → Легкий анализ IP/доменов через API Shodan InternetDB.

3 часа назад @ habr.com
MaxPatrol 360: первый взгляд на операционную платформу управления работой SOC
MaxPatrol 360: первый взгляд на операционную платформу управления работой SOC MaxPatrol 360: первый взгляд на операционную платформу управления работой SOC

Продукт Positive Technologies MaxPatrol 360 появился как ответ на этот разрыв между набором инструментов и цельной операционной картиной.

Как устроен MaxPatrol 360В базовую конфигурацию продукта входят компоненты:Central Management Console — управление тенантами и их параметрами, интеграцией с SIEM и другими источниками.

Источником инцидентов для MaxPatrol 360 может выступать как продукт MaxPatrol SIEM, так и внешние системы.

Быстрая базовая инсталляция MaxPatrol 360 и нарастающий каталог интеграций позволяют начинать с ограниченного набора сценариев и постепенно добавлять автоматизацию и отчетность.

Расширение функциональности MaxPatrol 360 в сторону, характерную для SOAR, станет значитель…

3 часа назад @ habr.com
Активность хакерских группировок: блокчейн как C2, business email compomise и антибот-фильтры
Активность хакерских группировок: блокчейн как C2, business email compomise и антибот-фильтры Активность хакерских группировок: блокчейн как C2, business email compomise и антибот-фильтры

За отчетный период собран и верифицирован массив индикаторов компрометации по результатам расследования инцидентов, мониторинга группировок и анализа образцов вредоносного ПО.

Данные этого выхода — hex-строка — декодируются в ASCII и превращаются в актуальный URL C2.

PseudoGamaredon (aka GamaCopy, Core Werewolf, Awaken Likho)Документ-приманкаАктивна с 2023 года в России и Беларуси, использует MeshAgent, RemoteAdmin, UltraVNC и UPX.

Ретроспективный анализ показал, что аналогичная JScript-цепочка применялась группировкой с 2024 года — с тем же payload (NetSupport RAT) и близким шаблоном именования файлов-приманок.

В рейтинге активных группировок произошли изменения, связанные как с абсолютным…

3 часа назад @ habr.com
Какие должны быть пароли в 2026 году: новая таблица Hive Systems и её ограничения
Какие должны быть пароли в 2026 году: новая таблица Hive Systems и её ограничения Какие должны быть пароли в 2026 году: новая таблица Hive Systems и её ограничения

В 2024 году я переводил исследование Hive Systems, лежащее в основе регулярно появляющихся в интернете цветных таблиц «времени взлома паролей».

Оригинал исследования: Are Your Passwords in the Green?, Corey Neskey, Hive Systems, 14 июля 2026 года.

Источник: Hive Systems.

Откуда берутся 132 годаВ правом столбце таблицы Hive Systems используются:26 строчных латинских букв;26 прописных латинских букв;10 цифр;8 специальных символов: ^*%$!&@# .

В отличие от Argon2id и scrypt, защита bcrypt в основном основана на вычислительно дорогом расписании ключей и сравнительно небольшом фиксированном объёме памяти.

4 часа назад @ habr.com
Зачем корпоративным LLM нужен firewall: как мы делаем StarGuard AI
Зачем корпоративным LLM нужен firewall: как мы делаем StarGuard AI Зачем корпоративным LLM нужен firewall: как мы делаем StarGuard AI

Сейчас StarGuard AI ориентируется на модели и провайдеров с OpenAI-compatible Chat Completions API.

Поэтому в StarGuard AI появился детектор tool calls.

Журнал событий и расследованияКаждый запрос и ответ в StarGuard AI превращается в событие.

События StarGuard AI должны попадать туда, где команда безопасности уже работает с инцидентами: SIEM, SOC, DLP-процессы.

Мы смотрим на StarGuard AI как на единый слой управления этим классом рисков.

4 часа назад @ habr.com
Telegram как платформа для фишинга
Telegram как платформа для фишинга Telegram как платформа для фишинга

Отмечу, что Telegram в контексте фишинга интересен по одной простой причине — он давно вышел за пределы статуса личного мессенджера и стал частью рабочей инфраструктуры.

В Telegram же аккаунт используется для общения с друзьями, подрядчиками, коллегами, клиентами и внутренними командами.

tdata steal rutube.ruО работеПомимо tdata, атакующие любят имитировать страницы входа в Telegram Web и таким образом крадут учетные записи.

Итак, для работы с QR-аутентификацией Telegram предоставляет официальный API, которым пользуются как собственные приложения компании, так и сторонние клиенты.

Автоматизация извлечения чувствительных данных из телеграмЕще одна причина, по которой атаки на Telegram нельзя…

4 часа назад @ habr.com
Qdrant + Tailscale — установка и защита
Qdrant + Tailscale — установка и защита Qdrant + Tailscale — установка и защита

Если Tailscale сообщает, что ранее был включён параметр --advertise-exit-node , а Exit Node вам не нужен, выполните: sudo tailscale up --reset Затем подключите сервер заново: sudo tailscale up --ssh --hostname=qdrant-serverШаг 2.

Публикация Qdrant через TailscaleТеперь направим Tailscale к локальному Qdrant:sudo tailscale serve --bg http://127.0.0.1:6333Проверим настройки:sudo tailscale serve statusTailscale покажет HTTPS‑адрес, например:Откройте этот адрес в браузере.

Если вы видите ответ примерно такого вида:{ "title": "qdrant - vector search engine", "version": "1.18.3" }значит Qdrant успешно работает и доступен через Tailscale.

Перед обновлением рекомендуется:sudo docker compose pull su…

5 часов назад @ habr.com
Письмо, которое ходит за вас: разбираю свежий SSRF в Roundcube на живом стенде
Письмо, которое ходит за вас: разбираю свежий SSRF в Roundcube на живом стенде Письмо, которое ходит за вас: разбираю свежий SSRF в Roundcube на живом стенде

В июле 2026 Roundcube выкатил релиз 1.6.17, и это не одна заплатка, а целый список.

Roundcube тут отличная иллюстрация, потому что дыры сидят именно в фичах: в подгрузке стилей, в линковании адресов, в разборе вложений.

Есть sslip.io , который делает ровно то же самое, и в 1.6.16 его в этой строке нет.

Это не только приватность, это ещё и то, что не даёт SSRF выстрелить без действия пользователя.

Дело не в Roundcube.

5 часов назад @ habr.com
Поймай jailbreak, если сможешь
Поймай jailbreak, если сможешь Поймай jailbreak, если сможешь

Но что такое jailbreak?

Это и есть та причина поэтому хороший jailbreak редко выглядит как jailbreak, он выглядит как обычная задача, которую просто сформулировали немного необычно.

Он приходит не как монстр, а как сотрудник с бейджиком.

Не как атака, а как документ.

Не как «обойди правила», а как «мы же всё согласовали».

5 часов назад @ habr.com
Почему смена IP не делает вас новым пользователем
Почему смена IP не делает вас новым пользователем Почему смена IP не делает вас новым пользователем

Вы держите личный и рабочий аккаунты на одном сервисе — просто чтобы не путать переписку и не смешивать процессы.

Реальная модель угроз обычного пользователя куда прозаичнее, и в ней есть три разных наблюдателя.

Профили просто не связаны друг с другом: активность в одном не пересекается с другим.

Вести несколько сессий через обычный браузер с включенным VPN не выйдет, потому что VPN не прячет отпечаток.

Многие расширения, которые привязывают браузерные профили к прокси (например, FoxyProxy), вовсе не подменяют WebRTC либо делают это с заметными недочетами.

6 часов назад @ habr.com
Хакер Хакер
последний пост 1 час назад
Закон о регулировании криптовалют принят в третьем чтении
Закон о регулировании криптовалют принят в третьем чтении Закон о регулировании криптовалют принят в третьем чтении

Документ создает в России инфраструктуру легальной торговли криптовалютами, однако не разрешает расплачиваться ими за товары и услуги внутри страны.

Документ определяет основные контуры регулирования обращения криптовалюты в России, а также дополняет новыми нормами уже действующие правила обращения цифровых финансовых активов (ЦФА).

Торговлю организуют биржи и внебиржевые площадки, брокеры будут выполнять поручения клиентов, а управляющие компании — работать с активами в рамках доверительного управления.

Также на рынке появятся криптообменники, через которые можно будет менять безналичные рубли и другую фиатную валюту на криптовалюту и обратно.

Обычным инвесторам придется пройти тестировани…

1 час назад @ xakep.ru
Критическую проблему в WordPress уже применяют для установки веб-шеллов
Критическую проблему в WordPress уже применяют для установки веб-шеллов Критическую проблему в WordPress уже применяют для установки веб-шеллов

Хакеры начали эксплуатировать критическую проблему wp2shell в ядре WordPress.

Как мы рассказывали ранее, wp2shell объединяет в себе две уязвимости: SQL-инъекцию в классе WP_Query (CVE-2026-60137), а также баг в пакетном эндпоинте REST API (CVE-2026-63030).

Полная RCE-цепочка работает в WordPress с 6.9.0 по 6.9.4 и с 7.0.0 по 7.0.1, тогда как для версий с 6.8.0 по 6.8.5 угрозу представляет только SQL-инъекция.

Исправления вошли в версии 6.8.6, 6.9.5 и 7.0.2, и в силу серьезности проблемы разработчики WordPress включили принудительную установку патчей через автоматические обновления.

Хотя обнаружившие проблему исследователи не стали раскрывать технические подробности уязвимостей, вскоре после…

3 часа назад @ xakep.ru
В OpenAI сообщили, что за взломом Hugging Face стоят две ИИ-модели компании
В OpenAI сообщили, что за взломом Hugging Face стоят две ИИ-модели компании В OpenAI сообщили, что за взломом Hugging Face стоят две ИИ-модели компании

Представители OpenAI заявили, что за недавним взломом Hugging Face стояли экспериментальные ИИ-модели компании.

Напомним, что недавно представители Hugging Face сообщили, что компания пострадала от кибератаки.

Как теперь сообщили специалисты OpenAI, в инциденте участвовали GPT-5.6 Sol и еще одна «более мощная модель», пока недоступная публично.

Атака на Hugging Face произошла во время внутреннего тестирования моделей.

Кроме того, в OpenAI пообещали усилить мониторинг, контроль доступа и защиту будущих тестов, даже если это замедлит проведение исследований.

5 часов назад @ xakep.ru
В Progress рассказали об уязвимости, из-за которой пришлось отключить серверы ShareFile
В Progress рассказали об уязвимости, из-за которой пришлось отключить серверы ShareFile В Progress рассказали об уязвимости, из-за которой пришлось отключить серверы ShareFile

В Progress Software раскрыли причину недавнего экстренного отключения серверов ShareFile Storage Zone Controller.

Напомним, что в середине июля 2026 года Progress Software разослала клиентам письма с темой «Требуются немедленные действия».

В компании сообщали о «реальной внешней угрозе», нацеленной на Storage Zone Controller, и требовали, чтобы администраторы немедленно вручную отключили Windows-серверы с контроллерами.

Одновременно специалисты компании заблокировали клиентам, использующим Storage Zone Controller, доступ к ShareFile.

Исправления вошли в состав ShareFile Storage Zone Controller версий 5.12.5 и 6.0.2.

20 часов назад @ xakep.ru
MetaMask наняла разработчика из КНДР
MetaMask наняла разработчика из КНДР MetaMask наняла разработчика из КНДР

Разработчик из Северной Кореи под псевдонимом Tyler Knapp около месяца проработал над основным кодом кошелька MetaMask.

При этом, информация о его связях со страной уже публиковалась в специальном реестре lazarus.group около года назад.

Со слов DeFi-ресерчера и аналитика безопасности с ником Zun, он использовал GitHub с ником imyugioh.

Реестр запустился специально для выявления северокорейских шпионов до приема на работу, в связи с чем Consensys и Metamask, а также отдельные сотрудники компаний подверглись критике как в публичном пространстве, так и в профильных сообществах специалистов по безопасности.

Сама биржа признала, что он проработал там целый год, и после разоблачения призвала всех…

21 час назад @ xakep.ru
ФБР арестовало подозреваемого по делу о малвари в Steam
ФБР арестовало подозреваемого по делу о малвари в Steam ФБР арестовало подозреваемого по делу о малвари в Steam

ФБР задержало 21-летнего жителя Флориды Зайра Уилкинса (Zyaire Wilkins), которого обвиняют в распространении малвари через Steam.

Во время беседы с правоохранителями он рассказал, что несколько человек вкладывали деньги в разработку и продвижение вредоносных игр в Steam, рассчитывая потом получить долю от украденной криптовалюты.

По информации ФБР, в течение последних двух лет группа злоумышленников неоднократно публиковала в Steam вредоносные игры, включая BlockBlasters, Dashverse, Lampy, Lunara и PirateFi.

В марте 2026 года ФБР уже обращалось за помощью к геймерам, которые могли скачать эти и другие зараженные игры в Steam.

Напомним, что одним из самых громких эпизодов, связанных с малвар…

22 часа назад @ xakep.ru
Лаборатория хакера. 7 утилит для пентеста и разработки
Лаборатория хакера. 7 утилит для пентеста и разработки Лаборатория хакера. 7 утилит для пентеста и разработки

Доволь­но лег­ковес­ный, занима­ет мало мес­та на дис­ке, и с ним удоб­но работать.

Но и в реаль­ных усло­виях не тор­мозит.

Опыт­ный и так зна­ет, что это за уяз­вимость и как с ней работать.

Vulnerability Details: - Type: %s - URL: %s - Parameter: %s - Payload: %s - Details: %s - Severity: %s ` , vuln .

URL , vuln .

1 day назад @ xakep.ru
Взлом Suno показал, что сервис копировал данные с YouTube, Deezer и Genius
Взлом Suno показал, что сервис копировал данные с YouTube, Deezer и Genius Взлом Suno показал, что сервис копировал данные с YouTube, Deezer и Genius

Хакер взломал сервис генерации музыки Suno и получил доступ к исходному коду проекта, который пролил свет на то, откуда компания черпала обучающие данные.

Судя по украденным данным, разработчики массово выкачивали музыку, тексты песен и подкасты с YouTube Music, Deezer, Genius и других платформ.

В одном из похищенных хакером файлов содержится информация о том, что Suno загрузила 2 013 545 музыкальных клипов с YouTube Music.

Другой документ перечисляет более 113 000 часов аудио с этой платформы, 152 000 часов из набора ytm_tagged, 62 117 часов из библиотеки Pond5, 19 514 часов из International Music Score Library Project (IMSLP), 17 615 часов материалов Genius и 12 287 часов музыки из Deezer…

1 day, 1 hour назад @ xakep.ru
Опубликованы эксплоиты для критической проблемы в ядре WordPress
Опубликованы эксплоиты для критической проблемы в ядре WordPress Опубликованы эксплоиты для критической проблемы в ядре WordPress

В сети появились PoC-эксплоиты для свежей цепочки уязвимостей wp2shell, обнаруженной в ядре WordPress.

Эти баги позволяют неаутентифицированному атакующему выполнить произвольный код на сайте с чистой установкой WordPress, и для атаки не нужны дополнительные плагины.

Так, в версиях с 6.8.0 по 6.8.5 присутствует только проблема SQL-инъекции, а полная RCE-атака срабатывает лишь в WordPress с 6.9.0 по 6.9.4 и с 7.0.0 по 7.0.1.

Исправления вошли в состав версий 6.9.5 и 7.0.2, а также в WordPress 7.1 beta 2.

Разработчики пишут, что в силу серьезности ситуации включили принудительную установку патчей через систему автоматических обновлений.

1 day, 3 hours назад @ xakep.ru
Hugging Face взломали с помощью автономных ИИ-агентов
Hugging Face взломали с помощью автономных ИИ-агентов Hugging Face взломали с помощью автономных ИИ-агентов

В конце прошлой недели представители Hugging Face сообщили о взломе продакшн-инфраструктуры платформы.

При этом в Hugging Face описывают эту атаку как работу автономного агентного фреймворка.

Атаку помогла выявить собственная система Hugging Face, предназначенная для обнаружения аномалий.

Также в Hugging Face провели ротацию секретов, ужесточили правила доступа в кластеры и доработали мониторинг, чтобы обнаруживать новые атаки в течение нескольких минут.

Однако расследование еще продолжается, и пока неясно, затронула ли атака данные клиентов и партнеров Hugging Face.

1 day, 5 hours назад @ xakep.ru
Хакер использовал Google Gemini в качестве агента для управления ботнетом
Хакер использовал Google Gemini в качестве агента для управления ботнетом Хакер использовал Google Gemini в качестве агента для управления ботнетом

Специалисты Trend Micro обнаружили, что русскоязычный злоумышленник под ником bandcampro использовал Google Gemini CLI для управлением небольшим ботнетом.

Во втором отчете исследователи рассказывают, что изучили более 200 сессий bandcampro с Gemini CLI за период с 19 марта по 21 апреля 2026 года.

В итоге вся схема управления ботнетом умещалась в трех текстовых файлах общим объемом около 5 Кбайт: джейлбрейк-промпт, плейбук для управления C2 и инструкция по миграции.

Для обеспечения постоянного присутствия в системе использовались задачи планировщика, WMI-события и изменения в реестре.

Однако в отчете подчеркивается, что проблема не ограничивается Gemini: с помощью джейлбрейка аналогичным обр…

1 day, 20 hours назад @ xakep.ru
Стилер ClickLock для macOS завершает процессы, вынуждая жертву ввести пароль
Стилер ClickLock для macOS завершает процессы, вынуждая жертву ввести пароль Стилер ClickLock для macOS завершает процессы, вынуждая жертву ввести пароль

По данным специалистов, с мая 2026 года ClickLock атаковал не менее 100 систем в 33 странах, и больше половины целей находились в Европе.

Впервые управляющий шелл-скрипт этой малвари загрузили на VirusTotal 9 июня, и на момент анализа его не детектировало ни одно из доступных на платформе антивирусных решений.

Затем ClickLock показывает жертве фальшивое системное окно с настоящим именем пользователя и иконкой Apple, предлагая ввести пароль.

Все остальные приложения продолжают принудительно закрываться, пока пользователь не введет пароль и не разрешит доступ.

Эксперты Group-IB подчеркивают, что если Mac внезапно начал закрывать приложения и требует пароль, вводить его нельзя.

1 day, 22 hours назад @ xakep.ru
HTB Logging. Компрометируем домен через поддельный WSUS и сертификат AD CS
HTB Logging. Компрометируем домен через поддельный WSUS и сертификат AD CS HTB Logging. Компрометируем домен через поддельный WSUS и сертификат AD CS

warning Под­клю­чать­ся к машинам с HTB рекомен­дует­ся с при­мене­нием средств ано­ними­зации и вир­туали­зации.

Са­мый извес­тный инс­тру­мент для ска­ниро­вания — это Nmap.

На пер­вом выпол­няет­ся обыч­ное быс­трое ска­ниро­вание, на вто­ром — более тща­тель­ное, с исполь­зовани­ем встро­енных скрип­тов (опция -A ).

Под­робнее про работу с Nmap читай в статье «Nmap с самого начала.

Осва­иваем раз­ведку и ска­ниро­вание сети».

2 days назад @ xakep.ru
В 7-Zip исправили RCE-уязвимость
В 7-Zip исправили RCE-уязвимость В 7-Zip исправили RCE-уязвимость

Разработчик 7-Zip выпустил версию 26.02, которая устраняет уязвимость удаленного выполнения кода.

Уязвимость связана с обработкой данных, сжатых в формате XZ: специально подготовленные данные могут спровоцировать переполнение буфера хипа, что в итоге ведет к выполнению произвольного кода в контексте текущего пользователя.

Хотя разработчик 7-Zip пока не опубликовал техническое описание бага, по словам исследователей, изменения в исходном коде указывают на то, что проблема могла заключаться в некорректном учете свободного места при распаковке XZ-данных.

В версии 26.02 появились дополнительные проверки, которые не позволяют декодеру записывать данные за пределы оставшегося пространства в буфер…

2 days, 1 hour назад @ xakep.ru
Злоумышленники могут взламывать роботы-пылесосы Shark и удаленно управлять ими
Злоумышленники могут взламывать роботы-пылесосы Shark и удаленно управлять ими Злоумышленники могут взламывать роботы-пылесосы Shark и удаленно управлять ими

Исследователь разобрал свой пылесос Shark при помощи обычной отвертки, подключился к контактам UART и попал в консоль U-Boot, которая не требовала пароль.

Параметр init=/bin/sh позволил получить root-шелл, а ключ и сертификат хранились в каталоге /mnt/res/vapp/certs/ как обычные файлы.

После извлечения сертификата с девайса RV2320EDUS tokay0 подписался на $aws/things/# и начал перехватывать трафик, попутно собирая серийные номера других устройств.

При этом сертификат AV1102ARUS был настроен корректно и не позволял обращаться к чужим топикам.

В компании подтвердили получение отчета, однако к моменту раскрытия информации о проблеме патч так и не был выпущен.

2 days, 3 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 2 часа назад
Why Modern SOCs Need Multi-Layered Detections
Why Modern SOCs Need Multi-Layered Detections Why Modern SOCs Need Multi-Layered Detections

Network Detection and Response (NDR), validates, enriches, and connects these separate signals using network data.

For instance, when an identity tool flags an unusual login, network data verifies whether that account initiated unauthorized database queries.

Rather than search through an overwhelming volume of separate, uncoordinated alarms, defenders use multiple integrated network detection layers to establish certain proof.

As AI becomes a core component of the modern SOC, the strategic value of network evidence grows exponentially.

Unified network evidence and comprehensive visibility ensure that human analysts and AI models work from the exact same view of the environment.

2 часа назад @ thehackernews.com
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA

Investigators estimate roughly 1,800 paying customers used Kratos to run about 15,000 phishing campaigns a month.

That second mode is the adversary-in-the-middle technique that has made ordinary MFA a much weaker backstop than it looks.

Where the kit only harvested credentials, a password reset and an MFA check cover it.

Where its reverse-proxy mode lifted a live session, that session survives the reset, so it has to be revoked, with high-value accounts moved to phishing-resistant sign-in.

What the takedown did not touch is the roughly 1,800 customers or the kit code they already hold.

7 часов назад @ thehackernews.com
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

The package, named "Newtonsoftt.Json.Net," masquerades as the Newtonsoft.Json library and is a trojanized fork.

Seven versions of the package have been published to the NuGet repository: 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, and 11.0.11.

All seven published versions contain the same trojanized fork of Newtonsoft.Json 13.0. spread across three generations that were published between August 13 and October 10, 2025.

The package metadata has been found to leak an internal Digitain repository URL seven times (in all the package versions), indicating the author had access to FG-Crash's source code.

To counter the threat, developers are advised to remove the typosquat package, block the…

7 часов назад @ thehackernews.com
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns pull request descriptions without a prompt-injection guardrail the company had already applied to others.

Microsoft ships the server so AI agents can read and operate Azure DevOps for a user, across pull requests, pipelines, wikis, and work items, all with the user's own permissions.

When the reviewer asks their agent to review the PR, the hidden text can rewrite the agent's goal.

The firm calls the escalation the normal case, since reviewers are often more senior than whoever opened the pull request.

The pull request path missed the guardrailWhat lifts this above a generic prompt-inje…

8 часов назад @ thehackernews.com
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

Describing it as an "unprecedented cyber incident" and one involving state-of-the-art cyber capabilities, OpenAI said it intends to conduct a thorough investigation in partnership with Hugging Face to get to the bottom of the matter.

"With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with internet access," the company explained.

Surmounting the internet access blockade, the models subsequently inferred Hugging Face as the repository that hosted models, datasets, and solutions for ExploitGym, which, in turn, caused them to look for ways to gain access to secret information t…

9 часов назад @ thehackernews.com
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees.

Hide My Email generates unique, random email addresses that forward messages to a user's personal email inbox automatically.

However, at the start of the month, details emerged of a flaw that made it possible to unmask a user's real email address hidden behind a Hide My Email address.

"We don't know how often hidden email addresses were leaked in email logs.

It bears noting that while the bug has been resolved, it's possible that a real email address linked to a Hide My Email address created before July 7, …

18 часов назад @ thehackernews.com
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution.

Kiro reads its list of Model Context Protocol servers, and the exact command used to start each one, from ~/.kiro/settings/mcp.json.

When that file changes, Kiro reloads it and launches whatever it describes, on the host, with the developer's privileges.

Anyone who could influence the contents of that file could register a server whose start command was arbitrary code, and it would run the moment Kiro reloaded.

Kiro had been here beforeAn agent able to write the file that governs what it is allowed to run has surfaced in Kiro before.

21 час назад @ thehackernews.com
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently.

The release of 3.5 Flash Cyber comes alongside Gemini 3.6 Flash and 3.5 Flash-Lite, which are optimized for improved coding, knowledge work, and multimodal performance and low-latency tasks, respectively.

In evaluations conducted by the AI research laboratory, 3.5 Flash Cyber has been found to outperform Gemini 3.5 Flash and 3.6 Flash when it comes to unearthing new vulnerabilities in codebases.

"3.5 Flash Cyber consistently discovered more unique vulnerabi…

22 часа назад @ thehackernews.com
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr.

The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network.

In a post shared on LinkedIn, watchTowr said it has detected active exploitation of the shortcoming against on-premises Microsoft SharePoint deployments following the release of a public proof-of-concept (PoC) exploit, allowing attackers to steal machine keys to maintain persistent access.

"Attackers are pulling SharePoint mach…

22 часа назад @ thehackernews.com
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.

Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software.

Successful exploitation of the flaw allows unauthenticated remote attackers to sidestep authentication and establish VPN sessions without valid credentials when authentication override cookies are enabled with specific certificate configurations.

"Attackers demonstrated …

23 часа назад @ thehackernews.com
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component.

Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.

An XSS vulnerability where crafted fields could execute a malicious script under specific conditions.

The company did not share any additional specifics, stating "in line with industry best practices, information disclosure is limited for security vulnerability fixes."

The release comes a little over a week after Zimbra patched a critical stored XSS flaw in the Classic Web Client that could r…

1 day назад @ thehackernews.com
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA.

AppAgent's controller runs subprocess.run(adb_command, shell=True) and builds text input by dropping model output straight into adb shell input text {input_str}.

A payload designed to launch calc.exe did exactly that in 20 of 20 trials against AppAgent, AppAgentX, Mobile-Agent-v3, and MobA.

Mobile-Agent-v3 keeps a narrow allow-list: letters, digits, and common punctuation go via adb shell input text, and everything else, meaning any non-ASCII character, goes out one character at a time over ADB_INPUT_TEXT.

What it adds i…

1 day, 1 hour назад @ thehackernews.com
N-day is Becoming N-Hour. Patching Faster Won't Save You.
N-day is Becoming N-Hour. Patching Faster Won't Save You. N-day is Becoming N-Hour. Patching Faster Won't Save You.

Historically, the gap between a patch and a working public exploit spanned weeks, often months.

A live exploit chain against a reachable asset is the strongest proof there is, and it's what autonomous penetration testing does.

But a live exploit can only detonate where detonating is safe.

TTP Chaining by Picus Exposure ValidationDecompose a CVE into that chain and validate each link against your actual controls, EDR policy, segmentation, allow-listing, and firewall.

Where firing a live exploit is safe, Picus Autonomous Penetration Testing hands you the strongest proof there is by running the real chain against reachable assets.

1 day, 1 hour назад @ thehackernews.com
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

A cloud tenant using nothing but ordinary GPU access can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.

It works because a GPU's power draw follows whatever it is computing.

Toggle between those states on a schedule and you get a controllable power oscillation at the wall socket.

The authors frame it as a blunt question: can "purely computational actions, executed as legitimate workloads, be weaponized to destabilize power infrastructure"?

A lightweight detector the researchers built on power and NVML data performed poorly; adding GPU profiling features improved it, and dedicated EMI sensing worked best.

1 day, 2 hours назад @ thehackernews.com
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.

"By the early hours of Saturday morning (UTC), successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public," Jake Knott, principal security researcher at watchTowr, told The Hacker News in a statement.

The exploit chain, discovered by Searchlight Cyber using OpenAI GPT 5.6 Sol in over 10 hours, essentially allows unauthenticated attackers to gain remote c…

1 day, 4 hours назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 1 week, 1 day назад
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

1 week, 1 day назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

2 weeks назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

2 weeks, 5 days назад @ welivesecurity.com
This month in security with Tony Anscombe – June 2026 edition
This month in security with Tony Anscombe – June 2026 edition This month in security with Tony Anscombe – June 2026 edition

It's that time of month when ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses.

What lessons does the new CISA policy hold for organizations outside the agency's direct remit?

What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems?

How can you stay safe from imposter fraud, and could the social media bans for children work?

Learn more from Tony's video and be sure to check out the May 2026 edition of Tony's monthly security news roundup for more insights.

3 weeks назад @ welivesecurity.com
Inside the inbox: Why cybercriminals want to break into your email account
Inside the inbox: Why cybercriminals want to break into your email account Inside the inbox: Why cybercriminals want to break into your email account

With access to your email account, they can reset your passwords across multiple other accounts – perhaps intercepting one-time passcodes sent by your bank, social media, cloud storage or other online provider.

That could lay the groundwork for a convincing phishing email designed to impersonate a trusted organization you interact with.

A phishing attack on your corporate email account is often the first stage in a bigger data breach, extortion/ransomware or espionage attack.

They’re also using more sophisticated tools to improve the success rates of email phishing campaigns.

In this instance the scammers reportedly hijacked the email account of a high-level executive, before impersonating …

3 weeks, 2 days назад @ welivesecurity.com
SMB cyber readiness: the road to resilience starts here
SMB cyber readiness: the road to resilience starts here SMB cyber readiness: the road to resilience starts here

For these businesses, cyber resilience should be the direction of travel – that is, the ability to continue operating and recover even during a serious incident.

Cyber readiness is about putting in place the processes and controls to prevent, detect and respond to threats.

So, should confidence in cyber resilience posture be so high, especially if organizations are still getting hit multiple times?

The truth is that there’s no end state for cyber readiness or resilience.

If it’s serious about improving the cyber readiness of small businesses, the vendor community should step up.

3 weeks, 5 days назад @ welivesecurity.com
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Key points of this blogpost: Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.

Continued data exfiltration and a new allianceThroughout 2025, Gamaredon stayed highly active and remained focused solely on Ukraine.

Notably, we uncovered that in early 2025, Gamaredon collaborated with Turla, another Russia-aligned threat actor also linked to the FSB; we documented our findings in our blogpost Gamaredon X Turla collab.

Figure 1 shows a chart of unique samples of HTA downloaders delivered per month in Gamaredon spearphishing campaigns.

Compared to 2024, we also saw a shift in how Gamaredon used these dead drops.

3 weeks, 6 days назад @ welivesecurity.com
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET takes part in Operation Endgame to disrupt Amadey and Stealc

Key points of this blogpost: ESET took part in the coordinated, global Operation Endgame to disrupt Amadey and Stealc.

Our automated systems have been dissecting Amadey and Stealc samples and identifying the fields most relevant for large-scale tracking.

The largest Amadey botnet clusterOne cluster stands out as the largest, and it contributed nearly 34% of all processed Amadey samples.

Stealc affiliate clustering based on ESET telemetryConclusionFor global disruption operations such as Operation Endgame against Amadey and Stealc, long-term automated tracking of malware is necessary.

2026‑04‑09 Stealc C&C server.

4 weeks назад @ welivesecurity.com
Killing me gently: Inside Gentlemen’s EDR killer framework
Killing me gently: Inside Gentlemen’s EDR killer framework Killing me gently: Inside Gentlemen’s EDR killer framework

The group distinguishes itself through a mature, operator-maintained set of endpoint detection and response (EDR) killers, i.e., tools for disrupting security software.

In this blogpost, we share our findings on Gentlemen’s suite of EDR killers gained through extensive research and corroborated by the recent leak.

Third‑party EDR killers (HexKiller, ThrottleBlood, and HavocKiller) are operationally integrated.

Rather than relying on affiliates to source their own EDR killers, Gentlemen operators actively develop and maintain a portfolio of EDR killers for affiliates.

It allows the Gentlemen operators to integrate abused drivers into their toolset very soon after an EDR killer PoC is disclos…

1 month назад @ welivesecurity.com
Protecting legacy OT systems against modern cyberthreats
Protecting legacy OT systems against modern cyberthreats Protecting legacy OT systems against modern cyberthreats

Of course, connecting production systems to enterprise networks delivers tangible benefits, but the security implications – that systems once safe were suddenly no longer so – arrived more quietly.

Start by mapping which systems in an environment are connected and have no security coverage, where IT and OT networks intersect, which segments are unmonitored, and which production systems have fallen outside any vendor support agreement.

Meanwhile, off-the-peg security tools often don’t efficiently meet the enterprise requirements in legacy OT systems that run on older hardware and outdated operating system versions.

The production systems running that version continue to operate for years, ac…

1 month назад @ welivesecurity.com
FishMonger’s arsenal upgraded: SprySOCKS for Windows
FishMonger’s arsenal upgraded: SprySOCKS for Windows FishMonger’s arsenal upgraded: SprySOCKS for Windows

Key points of this blogpost: We discovered two previously undocumented Windows variants of FishMonger’s SprySOCKS backdoor.

Technical analysisIn this section, we provide a technical analysis of these new, Windows variants of FishMonger’s SprySOCKS backdoor.

Figure 3. klelam00007.bat setting up persistence for the SprySOCKS backdoor (newlines added for readability)Figure 4 depicts the execution chain of the SprySOCKS WIN_DRV variant.

It contained the SprySOCKS backdoor and the SprySOCKS loader.

6490B8E4AADE25A3EE2D A9A47F312DB2122470BC X1B5206BDC1 743DD.dat Win64/SprySOCKS.A Encrypted container of the encrypted WIN_DRV variant of SprySOCKS backdoor, encrypted SprySOCKS RawWNPF and SprySOCKS …

1 month назад @ welivesecurity.com
EvilTokens: A phishing attack that doesn’t steal your password
EvilTokens: A phishing attack that doesn’t steal your password EvilTokens: A phishing attack that doesn’t steal your password

Instead, attackers get the victim to complete a legitimate authentication process – including two-factor authentication (2FA) – on a real Microsoft login page.

What makes EvilTokens dangerousThe OAuth device code flow was designed for devices that may be awkward to sign into directly, such as smart TVs or printers.

No document, invoice, email, or another platform should ask for a device code without a clear reason.

A real Microsoft page doesn’t automatically make a request safe.

Sometimes the attacker could ask them to enter a real code on a real page – but for the wrong device.

1 month, 1 week назад @ welivesecurity.com
OceanLotus: From external espionage to domestic targeting
OceanLotus: From external espionage to domestic targeting OceanLotus: From external espionage to domestic targeting

During this period, the Vietnam-aligned OceanLotus adopted a more selective approach to external operations while placing increasing emphasis on domestic espionage.

We identified two distinct campaigns involving the SPECTRALVIPER backdoor: a supply-chain attack targeting stock investors in Vietnam and a prolonged espionage operation against a Vietnamese infrastructure and transport construction company.

The domain resolved to the genuine IP address of the FireAnt update server, suggesting a supply-chain compromise scenario.

LTD 2025‑09‑20 SPECTRALVIPER C&C server.

]com IRT‑CHOOPALLC‑AP 2025‑09‑20 SPECTRALVIPER C&C server.

1 month, 1 week назад @ welivesecurity.com
SMB cyber-readiness: What makes or breaks it
SMB cyber-readiness: What makes or breaks it SMB cyber-readiness: What makes or breaks it

But that realization alone clearly doesn’t prepare them to withstand an attack.

Have the repeat victims come to view their brushes with cyber-incidents as proof of “what doesn’t kill me makes me stronger”?

For all the talk around AI, automation and attacker sophistication, many SMB breaches still begin with a familiar opening.

A total of 71% of SMBs globally now carry cyber insurance, rising to 84% in North America, with adoption climbing sharply among repeat victims.

While “when, not if” has never been more true, that alone doesn’t prepare a business for adversity.

1 month, 1 week назад @ welivesecurity.com
Cybercriminals: the 'auditors' you never hired
Cybercriminals: the 'auditors' you never hired Cybercriminals: the 'auditors' you never hired

There’s a phrase that is peddled out by governments and companies alike when a catastrophe of any type – including a cybersecurity breach – occurs: “Lessons have been learnt”.

The 130% increase in significant incidents between 2024 and 2025 severely challenges this assertion and points to lessons not being learnt, at a macro level.

In fact, this reluctance to look could also be normalcy bias quietly doing its work.

That is why this metaphor matters – cybercriminals discover the gap between what an organisation believes about its security and what the reality is.

We must accept that normalcy bias exists and act upon it.

1 month, 1 week назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 1 час назад
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys.

“WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” the offensive security company warned on Tuesday.

On July 17, threat intelligence firm Defused also spotted what they now believe to be CVE-2026-50522 exploitation attempts.

Patching alone won’t lock attackers outAttackers are continuously trying to breach SharePoint servers, as they are usually reachable from the internet,…

1 час назад @ helpnetsecurity.com
Glow exits stealth with $180 million to secure the AI-enabled endpoint
Glow exits stealth with $180 million to secure the AI-enabled endpoint Glow exits stealth with $180 million to secure the AI-enabled endpoint

Glow has emerged from stealth with $180 million in funding at a $1.2 billion valuation to advance a prevention-first approach to endpoint security.

The funding round was led by Sequoia, Cyberstarts, Greenoaks, and Redpoint Ventures, with participation from Index Ventures, Swish Ventures, Lux Capital, Operator Collective, and Holly Ventures.

Why AI demands a new endpoint security approachAI has changed the endpoint into the entry point for enterprise AI.

Employees adopt new tools, connect agents, and integrate AI into their workflows faster than security teams can review.

Security teams should assume attackers have access to Mythos-class capabilities, and every risk they used to tolerate can…

2 часа назад @ helpnetsecurity.com
US seizes over 1,000 domains used for illegal World Cup 2026 streams
US seizes over 1,000 domains used for illegal World Cup 2026 streams US seizes over 1,000 domains used for illegal World Cup 2026 streams

The US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license.

According to a seizure warrant, HSI agents confirmed the domains were carrying live, unauthorized World Cup broadcasts at the time they were flagged.

“The unauthorized broadcast of World Cup matches violates intellectual property rights and fuels criminal organizations,” added Director Ivan J. Arvelo of the National Intellectual Property Rights Coordination Center.

A second phase of Operation Red Card opened on July 10 with raids in several Colombian cities.

Prosecutors there arrested four members of a group known as Los Ciberinfiltrados, accused of breaking …

2 часа назад @ helpnetsecurity.com
Lookout identifies exploitable vulnerabilities in mobile apps
Lookout identifies exploitable vulnerabilities in mobile apps Lookout identifies exploitable vulnerabilities in mobile apps

Lookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC).

Integrated natively into the Lookout Mobile Endpoint Security platform, MSEC enables organizations to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities across their mobile software ecosystem.

Because traditional security tools cannot inspect compiled mobile software, organizations lack visibility into exploitable software risk until vulnerabilities are weaponized.

“The Lookout Mobile Software Exposure Center extends Exposure Management to mobile, enabling security teams to prioritize mobile software risk alongside every other asset through a single exposure management w…

3 часа назад @ helpnetsecurity.com
Box expands enterprise AI governance with new agent security featuresox
Box expands enterprise AI governance with new agent security featuresox Box expands enterprise AI governance with new agent security featuresox

Box has announced new security capabilities designed to give organizations greater control over AI agents working with enterprise content.

“83 percent of organizations are already experimenting with AI agents across their most critical tasks,” said Manoj Asnani, VP of AI Security, Privacy, Compliance & Governance Products at Box.

With a protective layer that appropriately manages AI agent access to content, we’re confident our critical content will remain protected as we expand our use of AI,” Murata continued.

Introducing new security capabilities for protecting enterprise contentBox’s 2026 State of Enterprise AI report found that security and privacy are the leading obstacles to deploying…

3 часа назад @ helpnetsecurity.com
Arista adds AI-driven zero trust to VeloCloud SD-WAN
Arista adds AI-driven zero trust to VeloCloud SD-WAN Arista adds AI-driven zero trust to VeloCloud SD-WAN

Arista Networks has announced the launch of its new AI-driven Edge Threat Management (ETM) for VeloCloud SD-WAN, delivering integrated zero trust security for enterprise branch offices.

Customers can leverage this integration to simplify the branch, collapsing multiple disparate boxes into a single unified secure SD-WAN edge platform.

Integrated ETM provides perimeter protection at the WAN edge as an ideal software upgrade option to VeloCloud SD-WAN, enabling customers to unify zero trust branch office security with SD-WAN connectivity in a single platform.

“The new zero trust integrated security with ETM, developed organically by Arista, showcases the power of the combined Arista and VeloC…

3 часа назад @ helpnetsecurity.com
AI models cheat on cybersecurity evaluations, then fail to admit it
AI models cheat on cybersecurity evaluations, then fail to admit it AI models cheat on cybersecurity evaluations, then fail to admit it

Frontier AI models will take just about any route to finish a task, cheating included, according to new cybersecurity evaluations from the UK government’s AI Security Institute (AISI).

Machine learning researchers have documented models gaming reward functions and finding workarounds to score better on benchmark tests for a while.

Researchers caught every AI model cheatingAISI ran five leading models through 475 test runs each, and all five cheated.

(Source: AI Security Institute)The rate of cheating did not track how capable a model was.

We have since taken action to further secure AISI systems,” researchers noted.

3 часа назад @ helpnetsecurity.com
Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter
Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter

Google’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse.

Gemini 3.5 Flash Cyber is designed to identify vulnerabilities across large codebases that require analysis of numerous code paths.

Google evaluated Gemini 3.5 Flash Cyber on CyberGym, an evaluation developed by its Big Sleep team, and through Chrome’s production commit-scanning pipeline.

CyberGym evaluation (Source: Google)During testing on the V8 JavaScript engine, it found 55 unique confirmed issues, including 10 that Gemini 3.5 Flash and Claude Opus 4.6 did not detect.

New Gemini modelsBuilding on Gemini 3.5 Flash, Google introduced two …

5 часов назад @ helpnetsecurity.com
Police dismantle Kratos phishing platform behind 15,000 monthly campaigns
Police dismantle Kratos phishing platform behind 15,000 monthly campaigns Police dismantle Kratos phishing platform behind 15,000 monthly campaigns

German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform.

Authorities describe Kratos as one of the “world’s most widely used criminal phishing services”, with victims confirmed in 35 countries, mainly in Europe and the US.

According to ZIT and BKA, Kratos gave low-skill cybercriminals a way to steal login credentials such as passwords and email addresses through convincing Microsoft-themed phishing pages.

“More than 1,800 criminal franchisees are believed to have acquired Kratos and used it to conduct approximately 15,000 phishing campaigns per month.

The success against the Kratos phishing kit shows that even highly…

5 часов назад @ helpnetsecurity.com
Small teams are the heaviest users of AI coding agents
Small teams are the heaviest users of AI coding agents Small teams are the heaviest users of AI coding agents

Count the cases where someone reviews the agent’s work and leaves it as is, and one-person oversight covers close to nine in ten.

Small teams lean hardest on the solo routine, and bigger teams spread the work around more often without displacing it.

Most repos run one or two a quarterThe median repository opened one or two agentic pull requests in three months.

More output, same one reviewerRaida went back to the small teams that cleared 30 agentic pull requests in the window and checked who was reviewing them.

Small teams running dozens of agent pull requests kept one person in the loop the whole time.

7 часов назад @ helpnetsecurity.com
Snowpick: Open-source ServiceNow exposure scanner
Snowpick: Open-source ServiceNow exposure scanner Snowpick: Open-source ServiceNow exposure scanner

Bishop Fox ran that test across 166 ServiceNow instances during authorized penetration tests.

They were access-control and configuration issues across public ServiceNow surfaces,” Emilio Gallegos, the adversarial operator at Bishop Fox who wrote the tool, told Help Net Security.

Two surfaces, two sets of rulesServiceNow hands out data through Service Portal widgets and through the Table REST API.

The Table REST API at /api/now/table/{table_name} queries sys_user , incident , oauth_entity , and the rest of the schema directly.

Gallegos said guardrails around public widgets and table access raise the floor, and that ServiceNow is built to be customized.

8 часов назад @ helpnetsecurity.com
Security teams keep finding critical flaws after scheduled testing ends
Security teams keep finding critical flaws after scheduled testing ends Security teams keep finding critical flaws after scheduled testing ends

Only 15% described their security testing and validation programs as continuous.

“Automation can surface more signals, but security teams need evidence, not noise,” said Mark Kuhr, CTO at Synack.

“Human researchers bring the creativity and context to chain weaknesses, confirm exploitability and show what an attacker can actually do.”Continuous security validation gains interestContinuous penetration testing and continuous security validation were identified as the approaches most likely to replace annual point-in-time testing.

Few identify continuous security validation as their primary approach or describe their security programs as continuous.

Compliance-driven testing schedules, integrat…

8 часов назад @ helpnetsecurity.com
AI can’t fix cybersecurity’s hiring problem
AI can’t fix cybersecurity’s hiring problem AI can’t fix cybersecurity’s hiring problem

AI changes security workAI is reducing manual analysis, automating routine tasks and creating demand for security roles focused on AI governance, engineering and risk.

54% of respondents said they have AI security policies, and only 38% provide comprehensive AI security training.

Employers are adding AI-focused cybersecurity roles, including AI security engineers, AI governance analysts and AI/ML security specialists, while experienced cybersecurity professionals remain the hardest positions to fill.

Companies are adopting workforce frameworks such as NICE and the European Cybersecurity Skills Framework to standardize cybersecurity roles and skills.

Senior leadership and cybersecurity manag…

9 часов назад @ helpnetsecurity.com
Cloud operations become the next big role for agentic AI
Cloud operations become the next big role for agentic AI Cloud operations become the next big role for agentic AI

Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report.

These efforts support broader agentic AI deployment across departments and workflows.

Companies need consistent oversight across these environments to support cloud operations and AI workloads.

Application work stays focused on technologyApplication modernization efforts focus on technical upgrades and AI support.

Respondents expect these controls to limit agentic AI deployment in the near term.

9 часов назад @ helpnetsecurity.com
AI agents tricked into recommending malicious GitHub repositories
AI agents tricked into recommending malicious GitHub repositories AI agents tricked into recommending malicious GitHub repositories

Asked to find a free “cinematic prompt” skill, Claude Code found both a legitimate repository and a malicious one.

Asked for a free Walmart MCP server, both recommended the same malicious repository as their top pick.

“In our testing, Claude Code, Gemini, and ChatGPT all surfaced malicious campaign repositories without ever being shown a link,” Zaytsev added.

One account differs by one character from a known developer’s real handle and copies the profile closely before publishing its own malicious MCP server.

More than 600 listings for these repositories turned up on public AI registries, including LobeHub, Glama, MCP.so, and MCP Market.

23 часа назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 2 часа назад
First-Person Identity Theft Story
First-Person Identity Theft Story First-Person Identity Theft Story

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

2 часа назад @ schneier.com
MIT to Become Hotbed of AI Video Surveillance
MIT to Become Hotbed of AI Video Surveillance MIT to Become Hotbed of AI Video Surveillance

Installation of the new cameras, along with the wiring and infrastructure that will support them, began November 2025 and will likely continue until September 2026.

Technical specifications for the cameras suggest that they will be capable of collecting real-time face and object classification data, including detection of motion, loitering, crowds, face masks, and camera tampering.

According to a statement from MIT spokesperson Kimberly Allen, any collected data is “retained up to 30 days,” unless an exception is granted.

They support resolutions ranging from 2MP to 4K while also recognizing faces, license plates, vehicles, and other objects in real time.

Nearly all cameras will accommodate…

1 day, 2 hours назад @ schneier.com
On Flock License Plate Tracking Cameras
On Flock License Plate Tracking Cameras On Flock License Plate Tracking Cameras

The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM.

It just saw 34 DTM in large type and started alerting the local police.

In fact, four other 34 ## DTM cars were being tracked around Minnesota that week, according to Officer Ganshyn.

It was fed those characters that you said, 34 DTM, and it spit back out [a result] with the characters, 34 DTM,” Thomas said.

Last year, he even called one group that tracks the location of Flock cameras “terrorists.” But he’s had a change of heart.

2 days, 2 hours назад @ schneier.com
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach Friday Squid Blogging: Squid Washing Up on Cape Cod Beach

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

4 days, 16 hours назад @ schneier.com
Details of Alan Turing’s Voice Encryption System
Details of Alan Turing’s Voice Encryption System Details of Alan Turing’s Voice Encryption System

Really interesting piece of cryptographic history:In November 2023, a large cache of his wartime papers—nicknamed the “Bayley papers”—was auctioned in London for almost half a million U.S. dollars.

The previously unknown cache contains many sheets in Turing’s own handwriting, telling of his top-secret “Delilah” engineering project from 1943 to 1945.

Delilah was Turing’s portable voice-encryption system, named after the biblical deceiver of men.

There is also material written by Bayley, often in the form of notes he took while Turing was speaking.

It is thanks to Bayley that the papers survived: He kept them until he died in 2020, 66 years after Turing passed away.

5 days, 2 hours назад @ schneier.com
Protecting Privacy in an AI Era
Protecting Privacy in an AI Era Protecting Privacy in an AI Era

Protecting Privacy in an AI EraDaniel Solove argues in the Wall Street Journal (alternate link) that giving people control of their personal data is not an effective way to regulate privacy in this era.

Instead, we need to hold companies accountable for their actions, similar to what we do with food and drug companies.

Measures such as rigorous data minimization, fiduciary duties, liability for negligent or reckless technological design, liability for algorithms that cause harm, and multi-stakeholder review of technologies will be far more effective.

Posted on July 16, 2026 at 10:34 AM • 0 Comments

5 days, 23 hours назад @ schneier.com
A Video Screen That Is Also a Camera
A Video Screen That Is Also a Camera A Video Screen That Is Also a Camera

Amazing:Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both.

This hypercharged pixel, called a Fourier pixel, can generate and sense arbitrary light fields and tap into a pixel’s full potential for carrying information by manipulating light’s intensity, oscillation phases, and polarization.

The team reported its findings in a paper published yesterday in Nature.

We are one step closer to 1984 technology:The telescreen received and transmitted simultaneously.

There was of course no way of knowing whether you were being watched at any given moment.

1 week назад @ schneier.com
Upcoming Speaking Engagements
Upcoming Speaking Engagements Upcoming Speaking Engagements

I’m speaking at Boston Leadership Exchange in Boston, Massachusetts, USA, on Wednesday, July 22, 2026.

I’m speaking at Cognitive Security Conference in Las Vegas, Nevada, USA.

The conference runs August 6-7, 2026; my speaking time is TBD.

I’m speaking at DEF CON 34 in Las Vegas, Nevada, USA.

The conference runs September 30–October 1, 2026; the time of my talk is TBD.

1 week назад @ schneier.com
Vulnerability in FIFA’s Network
Vulnerability in FIFA’s Network Vulnerability in FIFA’s Network

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 week, 1 day назад @ schneier.com
AI Data Centers and the Concentration of Wealth
AI Data Centers and the Concentration of Wealth AI Data Centers and the Concentration of Wealth

AI Data Centers and the Concentration of WealthThis essay was written with Nathan E. Sanders, and originally appeared in The Guardian.

Opposition to AI data centers has emerged as a primary theme in US politics, one that—surprisingly—doesn’t fall along party lines.

For some, data center opposition may feel like the only tangible mechanism for registering their concern, disapproval, or even anger about AI.

The problem is that this may be exactly what the AI companies are banking on.

And while data center opposition campaigns have been successful in building widespread appeal, their effectiveness in the US is mixed.

1 week, 2 days назад @ schneier.com
Friday Squid Blogging: “Squidbleed” Vulnerability
Friday Squid Blogging: “Squidbleed” Vulnerability Friday Squid Blogging: “Squidbleed” Vulnerability

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 week, 4 days назад @ schneier.com
AI Surveillance and Social Progress
AI Surveillance and Social Progress AI Surveillance and Social Progress

These systems will combine powerful AI, public and private surveillance via real-time facial recognition technology and digital tracking, mass databases and highly personalized enforcement.

If deployed at scale, they will have profound chilling effects not just on personal freedoms, but democracy and social progress itself.

AI surveillance is now being experimented with in North America, South America, Europe, Asia and Africa.

While the systems are ostensibly used to maintain security and public safety, the real aim is often social control.

But we believe the most urgent and long-term impact will be its broader chilling effects.

1 week, 5 days назад @ schneier.com
The Language of AI Could Change How Humans Speak
The Language of AI Could Change How Humans Speak The Language of AI Could Change How Humans Speak

Internet risks are nothing new, and cyberattacks—both large and small—have been a significant issue since long before the current crop of generative AI models.

Contrast the L0pht hackers with hackers derided as “script kiddies.” They didn’t understand computers, or security.

Instructing AI models to spy on people and report any malicious prompts to the authorities fails for similar reasons.

We want these AI models to be able to review computer code, find vulnerabilities and automatically fix them.

They are things talked about at that congressional hearing back in 1998, titled “Weak computer security in government: Is the public at risk?” Even the Five Eyes admitted that their security advic…

1 week, 6 days назад @ schneier.com
Cybersecurity and the Gap Between Skill and Ability
Cybersecurity and the Gap Between Skill and Ability Cybersecurity and the Gap Between Skill and Ability

Internet risks are nothing new, and cyberattacks—both large and small—have been a significant issue since long before the current crop of generative AI models.

Contrast the L0pht hackers with hackers derided as “script kiddies.” They didn’t understand computers, or security.

Instructing AI models to spy on people and report any malicious prompts to the authorities fails for similar reasons.

We want these AI models to be able to review computer code, find vulnerabilities and automatically fix them.

They are things talked about at that congressional hearing back in 1998, titled “Weak computer security in government: Is the public at risk?” Even the Five Eyes admitted that their security advic…

2 weeks назад @ schneier.com
Google Is Suing Chinese Scammers Who Are Using Gemini
Google Is Suing Chinese Scammers Who Are Using Gemini Google Is Suing Chinese Scammers Who Are Using Gemini

Not sure this will have any effect, but I support the effort:According to Google’s legal filing, Outsider Enterprise operates through Telegram.

The group offers phishing-as-a-service to individuals who may not be technically savvy enough to set up fraudulent websites and text campaigns on their own.

In its Telegram channels, Outsider Enterprise reportedly provided instructions on how to use Google’s Gemini AI to create websites that imitate those of Google, YouTube, and government agencies such as New York’s E-ZPass.

[…]Google worked with AT&T, Verizon, and T-Mobile to block many of these malicious text messages, and Google notes that its on-device scam detection in Google Messages probably…

2 weeks, 1 day назад @ schneier.com
Krebs On Security
последний пост 12 часов назад
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

12 часов назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

1 week назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

1 week, 1 day назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

2 weeks назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

2 weeks, 5 days назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

4 weeks назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

1 month назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

1 month, 1 week назад @ krebsonsecurity.com
A Record-Breaking Patch Tuesday for June 2026
A Record-Breaking Patch Tuesday for June 2026 A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.

“Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said.

Microsoft received heavily blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher.

While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barne…

1 month, 1 week назад @ krebsonsecurity.com
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

On May 31, word began to spread on several Telegram instant message channels that Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow.

Meta has not responded to requests for comment on the video’s claims, but the company reportedly did acknowledge the dormant Instagram account for the Obama White House was briefly compromised.

Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership.

Just like human customer support employees can be social engineered into providing unauthorized access to someone’s a…

1 month, 2 weeks назад @ krebsonsecurity.com
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

But as KrebsOnSecurity observed in September 2025, those sanctions failed to target Stark’s remaining connection to the Internet — an Internet service provider based in the Netherlands called MIRhosting.

MIRhosting is operated by Andrey Nesterenko, a 39-year-old Russian native who runs the business out of the Netherlands.

And as our September 2025 report showed, WorkTitans was controlled by Nesterenko and a 57-year-old from Amsterdam named Youssef Zinad.

On top of that, WorkTitans was getting connectivity to the larger Internet solely through MIRhosting, where Zinad had worked previously.

“The transition to the.hosting was not intended to evade sanctions,” Nesterenko wrote.

1 month, 4 weeks назад @ krebsonsecurity.com
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers Demand Answers as CISA Tries to Contain Data Leak Lawmakers Demand Answers as CISA Tries to Contain Data Leak

The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.

Experts who reviewed the exposed secrets said the commit logs for the code repository showed the CISA contractor disabled GitHub’s built-in protection against publishing sensitive credentials in public repos.

CISA acknowledged the leak but has not responded to questions about the duration of the data exposure.

TruffleHog does this by monitoring a live feed that GitHub publishes which includes a record of all commits and changes to public code repositories.

In practical terms, it is likely that cybercrime groups or foreign adversaries also noticed the publication of these CISA secrets, …

2 months назад @ krebsonsecurity.com
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada

A criminal complaint unsealed today in an Alaska district court charges Jacob Butler, a.k.a.

“Dort,” of Ottawa, Canada with operating the Kimwolf DDoS botnet.

“KimWolf was tied to DDoS attacks which were measured at nearly 30 Terabits per second, a record in recorded DDoS attack volume,” the Justice Department statement reads.

Synthient was among many technology companies thanked by the Justice Department today, and Synthient’s founder Ben Brundage told KrebsOnSecurity he’s relieved Butler is in custody.

The DOJ said at least one of those services collaborated with Butler’s Kimwolf botnet.

2 months назад @ krebsonsecurity.com
CISA Admin Leaked AWS GovCloud Keys on Github
CISA Admin Leaked AWS GovCloud Keys on Github CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems.

Another file exposed in their public GitHub repository — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems.

“The available Git metadata alone does not prove which endpoint or device was used.”Caturegli said he validated that the exposed credentials could authenticate to three AWS GovCloud accounts at a high privilege level.

CISA has not responded to questions about the p…

2 months назад @ krebsonsecurity.com
Patch Tuesday, May 2026 Edition
Patch Tuesday, May 2026 Edition Patch Tuesday, May 2026 Edition

Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code.

May’s Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws.

But at the end of April, Oracle announced it was switching to a monthly update cycle for critical security issues.

Chrome automagically downloads available security updates, but installing them requires fully restarting the browser.

For a more granular look at the Microsoft updates released today, checkout this inventory by the SANS Internet Storm Center.

2 months, 1 week назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 1 day, 3 hours назад
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Ukraine's computer emergency response team, CERT-UA, has warned that Russian hackers are using fake CAPTCHA checks to trick people into compromising their own PCs.

The Kremlin-backed Sandworm hacking group is reportedly leveraging fake CAPTCHA checks on compromised websites that persuade users to execute a PowerShell command on their computers - tricking them into running malicious code.

The latest attacks begin when a user visits a compromised webpage, where they're greeted by a fake CAPTCHA claiming they need to complete an extra step to prove that they are human.

Instead, the fake CAPTCHA instructs the user to copy and paste a PowerShell command into their Windows computer.

They are a pr…

1 day, 3 hours назад @ bitdefender.com
Google’s Gemini lets strangers send messages from your locked Android phone
Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini lets strangers send messages from your locked Android phone

Someone gets hold of your locked Android phone and, despite not knowing your security PIN, they can send messages via SMS or WhatsApp pretending to come from you.

It is clear that Google has patched Gemini lock screen issues before, but security researchers keep finding new ways through.

The latest vulnerability is different from the previous similar Gemini-based Android lock screen bypass bugs that have been plaguing the operating system since September 2025.

To do that:Open the Gemini app, tap your profile picture, go to Settings, and select "Gemini on lock screen."

Every new capability Gemini is given at the lock screen is also a new potential attack surface.

4 days, 15 hours назад @ bitdefender.com
Anubis ransomware: what you need to know
Anubis ransomware: what you need to know

The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.

5 days, 16 hours назад @ fortra.com
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

That is a really, really busy street potentially.

I don't know what the difference is between a tuk-tuk and a rickshaw.

I don't know.

Yeah, it's got to be a Bluetooth transmitter from the battery, and within the battery there's an operating system or something that'll need updating.

It's really, really great.

6 days, 4 hours назад @ grahamcluley.com
The ransomware negotiator who was working for the other side
The ransomware negotiator who was working for the other side The ransomware negotiator who was working for the other side

When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help.

Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf.

41-year-old Martino worked as a ransomware negotiator for DigitalMint, an incident response company based in Chicago.

The ransomware victim, a hospitality company, ultimately paid out nearly US $16.5 million.

The company has since changed the way its negotiators communicate with ransomware gangs, and is working with the Department of Homeland Security to establish a registry for the currently highly-unregulated world of ransomware negotiation.

1 week, 1 day назад @ bitdefender.com
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk

Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role?

Security experts have uncovered a phishing campaign which impersonates over 30 well-known brands in fake job interviews designed to steal Google account passwords.

When victims click on "Continue with Google," a pop-up appears that looks like a legitimate Google authentication dialog.

In the past the FBI has warned the public about scammers using fake job ads to steal money and personal information from applicants.

Earlier this year, Hot for Security published a guide explaining how many fake recruiter scams work, and how to avoid them.

1 week, 6 days назад @ bitdefender.com
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself
Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself Smashing Security podcast #475: JadePuffer – the AI that ran a ransomware attack all by itself

These stories appear different, but they're actually telling the same story.

I'm going to flag, I'm going to flag the point that I made earlier is that operational security isn't always there.

I know how to do this because it's done it for me, but I don't actually know how to apply it logically.

And when the technology you're relying on to protect you, and in some people's case it is protecting their life, and you're not doing it to the best of your ability, that's, that's really, really disappointing.

But I guess for now, all eyes are on Apple and how they're going to respond to this, albeit 13 months later.

1 week, 6 days назад @ grahamcluley.com
Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud
Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud Two arrested over credit card phishing – as the Netherlands is named Europe’s worst for payment fraud

Two young men have been arrested in the Netherlands on suspicion of running a phishing operation that harvested the credit card details of unsuspecting victims.

According to a police press release, victims were duped into entering their payment card details on bogus phishing websites.

Investigators believe the arrested men, who have not been named, did not just misuse the stolen payment card details themselves, but also passed them on to other fraudsters.

Card payment fraud was found to be the single most common category, with over half a million fraudulent transactions (up more than a quarter on the year before).

In 2024, just 1% of Dutch fraud victims recovered their money, and while arou…

2 weeks, 1 day назад @ bitdefender.com
The Gentlemen ransomware: what you need to know
The Gentlemen ransomware: what you need to know

Who Are The Gentlemen?

Despite the impeccably polite name, there is nothing polite or refined about this particular gang of cybercriminals. Read more in my article on the Fortra blog.

2 weeks, 5 days назад @ fortra.com
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?
Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack? Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?

And I'm going to be looking at whether you're wise to take a gamble with your security on Polymarket.

Right, well, I want to tell you about a company that's built its entire brand on being really, really good at predicting the future.

They've actually done it really, really well.

So it's The Summer Portraits by— remind me who it's by again, 'cause I'm going to butcher his name.

It's really, really good.

2 weeks, 6 days назад @ grahamcluley.com
Scammers race to cash in on Venezuelan earthquake disaster
Scammers race to cash in on Venezuelan earthquake disaster Scammers race to cash in on Venezuelan earthquake disaster

When a devastating earthquake struck north central Venezuela last week, rescue teams were not the only ones who mobilised fast.

Researchers at threat intelligence firm WhoisXML API say that they uncovered 212 newly-registered domains referencing the earthquake, all of which had been filed within five days of the disaster.

Even years after a natural disaster scammers can still exploit human misery.

And that's because exploitation of a major news event - whether it be a natural disaster of otherwise - can be a successful lure for criminals to deploy when defrauding the unwary out of their savings.

And when a natural disaster creates an urgent need for response, it is all the easier for cyberc…

3 weeks назад @ bitdefender.com
USB drives carrying China-linked malware infected Japanese military networks for nearly a year
USB drives carrying China-linked malware infected Japanese military networks for nearly a year USB drives carrying China-linked malware infected Japanese military networks for nearly a year

Leaked internal documents have revealed that for nearly a year Japan's Ground Self-Defense Force (JGSDF) used counterfeit USB flash drives infected with malware on computers connected to sensitive military networks.

The USB drives have been linked to Chinese hacking operations, according to an investigation by Nikkei Asia.

Subsequent investigations found that six out of eight USB drives tested contained the same malicious code.

The infected USB drives had been attached to over 50 computers, with nearly half of those systems used to handle classified data, including information about the movement of troops.

The counterfeit drives, priced 30 to 50 percent below authentic brands, were traced t…

3 weeks, 1 day назад @ bitdefender.com
Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup
Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup

Smashing Security, Episode 473: How a Hacker Could Have Rickrolled the Entire World.

You think, oh, hang on, they're going to ask me for a password or they're going to ask me for something like that.

Yeah, we'll take that money from under your bed and store it in a safety deposit box that you don't know where it is.

We saw a huge number of CVEs last year and with Mythos and the Frontier models, we think that's going to continue to spike.

So the blast radius of these IT service providers is really, really big.

3 weeks, 6 days назад @ grahamcluley.com
Hacker hijacks Brazil’s national alert system, sending “misanthropy” to millions of phones
Hacker hijacks Brazil’s national alert system, sending “misanthropy” to millions of phones Hacker hijacks Brazil’s national alert system, sending “misanthropy” to millions of phones

Somebody had broken into Brazil's national Civil Defence alert system and used it to send fake "Extreme Alert" notifications - the most severe category, normally reserved for warnings of imminent natural disasters - to mobile phones across at least five states, including São Paulo, Rio de Janeiro, and the Federal District.

In a statement posted on social media, Brazil's National Civil Defence confirmed that it had pulled the alert platform offline at 1:30am following the compromise.

National Secretary of Protection and Civil Defence Wolnei Wolff confirmed that the attackers managed to regain access after an initial attempt to block them from accessing the system.

Emergency alert systems wor…

4 weeks, 1 day назад @ bitdefender.com
Apple’s Hide My Email tweak leaves privacy fans fuming
Apple’s Hide My Email tweak leaves privacy fans fuming Apple’s Hide My Email tweak leaves privacy fans fuming

Hide My Email is a privacy feature that lets users create unique, random email addresses that forward messages to your real inbox.

That means you can sign-up for websites, newsletters, and apps without exposing your personal email address.

The problem is, however, that one of the reasons that Hide My Email worked so well was because its aliases were indistinguishable from regular iCloud email addresses.

All any website or app that wants to block anonymous sign-ups now has to do is to reject any email address ending in "@private.icloud.com".

For now, if you already have existing Hide My Email addresses in use, they should continue to work without any changes on your part.

1 month назад @ bitdefender.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 1 час назад
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 29288682927681f45f4ebe45b92c4f9dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-22T15:00:12+03:00Config id: 290Faithfully yours, nginx.

1 час назад @ kaspersky.ru
ConsentFix: новая вариация ClickFix
ConsentFix: новая вариация ClickFix

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 92f538b35cc9db0cd8268f0e9c690524Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-21T12:00:10+03:00Config id: 290Faithfully yours, nginx.

1 day, 4 hours назад @ kaspersky.ru
Как защитить свои данные после расставания | Блог Касперского
Как защитить свои данные после расставания | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7c4859afeb6714d16332cd516cc382ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-20T13:00:34+03:00Config id: 290Faithfully yours, nginx.

2 days, 4 hours назад @ kaspersky.ru
Кража почты через OAuth | Блог Касперского
Кража почты через OAuth | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 89a6c1c61d71bc406a42bd2d91dc48b6Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-17T15:00:29+03:00Config id: 290Faithfully yours, nginx.

5 days, 2 hours назад @ kaspersky.ru
Промпт-атаки на умного помощника Gemini и ИИ-ассистента Gemini Workspace | Блог Касперского
Промпт-атаки на умного помощника Gemini и ИИ-ассистента Gemini Workspace | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 9e57da73febcf1364991851b3ffd4607Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-16T15:00:15+03:00Config id: 290Faithfully yours, nginx.

6 days, 2 hours назад @ kaspersky.ru
Ключевые уязвимости Microsoft Patch Tuesday за июль 2026 | Блог Касперского
Ключевые уязвимости Microsoft Patch Tuesday за июль 2026 | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: ad5fb1fb73f446dedef7d1ec45313d70Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-15T17:00:41+03:00Config id: 289Faithfully yours, nginx.

1 week назад @ kaspersky.ru
Meta* включила и тут же отключила функцию генерации ИИ-изображений на основе пользовательского контента в Instagram** | Блог Касперского
Meta* включила и тут же отключила функцию генерации ИИ-изображений на основе пользовательского контента в Instagram** | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: d28ecbce6fae6b24393f114511aa53c1Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-14T15:00:39+03:00Config id: 282Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
Борьба с BEC-атаками на базе ИИ | Блог Касперского
Борьба с BEC-атаками на базе ИИ | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 0f43fc04a64ef8b4198bfe5f08f75233Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-13T17:00:32+03:00Config id: 281Faithfully yours, nginx.

1 week, 2 days назад @ kaspersky.ru
Что не так с функцией NameTag в умных очках Meta* и почему ее стоит опасаться | Блог Касперского
Что не так с функцией NameTag в умных очках Meta* и почему ее стоит опасаться | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 36cc4a8142dd177820e529f1c74777d2Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-09T14:00:09+03:00Config id: 281Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Целевой фишинг на производственные компании | Блог Касперского
Целевой фишинг на производственные компании | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 1ce0e45ab895fdb2ea63e5f66838efb9Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-08T18:00:10+03:00Config id: 281Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
Почему капча скоро исчезнет: как ИИ изменил проверку на человечность | Блог Касперского
Почему капча скоро исчезнет: как ИИ изменил проверку на человечность | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 26a02984b49c814d5538d529e6b61e94Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-06T15:00:25+03:00Config id: 280Faithfully yours, nginx.

2 weeks, 2 days назад @ kaspersky.ru
Неотключаемый бэкдор в роботах-газонокосилках Yarbo | Блог Касперского
Неотключаемый бэкдор в роботах-газонокосилках Yarbo | Блог Касперского Неотключаемый бэкдор в роботах-газонокосилках Yarbo | Блог Касперского

Но в совершенно ином масштабе: в режиме газонокосилки данный робот может обслуживать территории до 2,5 гектар (это 250 соток, то есть небольшой садовый кооператив), а в режиме транспортировщика поддерживает угодья площадью до 12,5 гектар.

Вместе с исследователем Андреасом Макрисом они провели эксперимент, в рамках которого исследователь, будучи в Германии, удаленно захватил контроль над газонокосилкой Yarbo и переехал журналиста, лежащего на газоне у себя в США.

Чаще всего в качестве операционной системы в них используется Linux — и роботы Yarbo тут не исключение.

При этом серийные номера устройств имеют предсказуемый формат и используются в инфраструктуре Yarbo в качестве идентификаторов р…

2 weeks, 6 days назад @ kaspersky.ru
Управление рисками агрегаторов LLM и API-прокси для нейросетей
Управление рисками агрегаторов LLM и API-прокси для нейросетей Управление рисками агрегаторов LLM и API-прокси для нейросетей

По мере того как организации начинают использовать нейросети для все более широкого круга задач, они неизбежно сталкиваются с вопросами надежности и стоимости ИИ-инструментов.

Чтобы не отказываться от нужных нейросетей, бизнес часто рассматривает переход на сторонние сервисы, обеспечивающие единое «окно доступа» к различным нейросетям.

Они предлагают услуги на десятки процентов, а иногда и в разы дешевле, чем у официальных поставщиков, обещая заодно обход любых лимитов.

Утечка данных и кража интеллектуальной собственностиИсследование показало, что цель многих таких сервисов — сбор качественных диалогов топовых моделей для обучения нейросетей третьих фирм.

Пять правил безопасной работы с ИИ-…

2 weeks, 6 days назад @ kaspersky.ru
Социальная инженерия: как злоумышленники манипулируют людьми | Блог Касперского
Социальная инженерия: как злоумышленники манипулируют людьми | Блог Касперского Социальная инженерия: как злоумышленники манипулируют людьми | Блог Касперского

Следующий абзац снова вгоняет вас в панику: «К сожалению, при проверке мы обнаружили, что ваши платежные данные могли быть скомпрометированы».

Для разбирательства напишите нам, иначе мы возбудим уголовное дело и разошлем информацию о вас в СМИ» — и далее по списку.

Но если с вами общаются чересчур эмоционально и вы чувствуете, что на вас давят, то вероятность, что вы общаетесь с мошенником, близится к 99,9%.

→ немедленно смените пароль на этом сервисе и на всех других, где использовали такой же.

Если с вашей карты успели снять или перевести деньги, узнайте, как оспорить транзакцию.

3 weeks, 1 day назад @ kaspersky.ru
Как сегодня злоумышленники атакуют компании | Блог Касперского
Как сегодня злоумышленники атакуют компании | Блог Касперского Как сегодня злоумышленники атакуют компании | Блог Касперского

Мы выбрали три кейса, три реальные истории о том, как злоумышленники атакуют сегодня, а главное, почему им удается проворачивать такие атаки.

Если вы не видите этот трафик или не считаете это инцидентом — вы проигрываете еще до начала активной фазы атаки.

Как и в предыдущем кейсе, злоумышленники вошли в корпоративную сеть через скомпрометированную учетную запись.

Почему это произошлоБыли допущены две классические ошибки:Сервер мониторинга был настроен с избыточными привилегиями, с доступом ко всем активам компании: и физическим, и виртуальным.

Попав в инфраструктуру, через Active Directory и групповые политики злоумышленники распространили в корпоративной сети вредоносное ПО с функционально…

3 weeks, 2 days назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 6 days, 22 hours назад
We third-party tested our firewall built for AI-scale. The test tools hit their limit first.
We third-party tested our firewall built for AI-scale. The test tools hit their limit first. We third-party tested our firewall built for AI-scale. The test tools hit their limit first.

In independent testing with NetSecOPEN, the Cisco Secure Firewall 6160 delivered AI-scale inspected throughput beyond what the tools built to measure it could register, all while blocking 100% of tested threats.

These results are specific to Cisco Secure Firewall 6160, but the software capabilities behind Cisco Firewall, including advanced threat protection and high-performance inspection, extend across Cisco Firewall form factors in the cloud, virtually, and on-premises, from campus to data center.

Performance passed the previous benchmark by 5XInspection was turned on, and the test tools built to measure throughput hit their limit before the 6160 firewall did.

In previous NetSecOPEN testi…

6 days, 22 hours назад @ blogs.cisco.com
SharpHound Recon Attack – How AI enhanced the threat hunt
SharpHound Recon Attack – How AI enhanced the threat hunt SharpHound Recon Attack – How AI enhanced the threat hunt

We innovated by giving the Agentic SOC access to Endace’s always-on, full packet capture, and asked the agent to assess a potential SharpHound Recon attack that we had seen while threat hunting.

This blog explores how we built the integrations and how AI helped us with our threat hunt and threat assessment.

Agentic AI Massively Speeds our AnalysisAt this point, we decided to use Agentic AI capabilities to investigate and assess this potential threat.

ConclusionThe Agentic SOC, blending Agentic AI built into Endace’s products with custom agentic tools, is a massive boost to productivity and security.

AcknowledgementsOur thanks go to the Cisco SOC team led by @Jessica Oppenheimer and @Ivan Be…

2 weeks назад @ blogs.cisco.com
Machine Speed, Human Judgement: How AI Changed the SOC in 2026
Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Machine Speed, Human Judgement: How AI Changed the SOC in 2026

Having spent time in the Cisco Live Americas 2026 SOC, one thing became abundantly clear:The way SOCs operate today is fundamentally different from even a few years ago.

Instead of spending time gathering information, analysts could spend more time understanding what the information actually meant.

Just as spreadsheets empowered business users decades ago, AI-assisted coding is beginning to empower security analysts today.

At Cisco Live, AI was already present throughout the workflow:Incident summaries generated automatically within XDR.

And based on what I saw at Cisco Live 2026, that future has already arrived.

2 weeks назад @ blogs.cisco.com
Elevating Expertise in the SOC
Elevating Expertise in the SOC Elevating Expertise in the SOC

The new SOC analysts were great at finding evidence, helped with triage and correlation by the AI agents in the SOC architecture.

With the advancements in Cloud Control, our new SOC Analysts can validate their hypothesis.

They had the ability to investigate the incident and find the root cause found in Splunk Security and Endace.

Instant Attack VerificationIn each Incident, the SOC Analysts is given an AI generated Summary stitching all the relevant logs from all the sources that are related to the objects in question.

Check out the blogs by the engineers who worked inside the SOC at Las Vegas:

2 weeks назад @ blogs.cisco.com
Educate at Event Speed: Cisco Live Security Operations Center
Educate at Event Speed: Cisco Live Security Operations Center Educate at Event Speed: Cisco Live Security Operations Center

At Cisco Live AMER 2026 in Las Vegas, my work with the Cisco Event SOC centered on one outcome that makes these deployments valuable beyond the event itself: Education.

The SOC protects the conference, but it also turns live operations into a learning environment through SOC tours, Cisco Live sessions, training inside the SOC, and conversations in the World of Solutions.

Bringing live SOC lessons into the classroomEducation also happened in the sessions I delivered at Cisco Live.

Cisco Live AMER 2026 reinforced that the SOC is one of the best classrooms we have because it teaches through real operations.

For a deeper look at the model behind these deployments, read the Cisco Event SOCs: A R…

2 weeks назад @ blogs.cisco.com
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

Inside the Cisco Live SOCAt Cisco Live AMER, the Security Operations Center (SOC) is more than a demo environment.

For a broader look at how the Cisco Live SOC operates, read this overview.

Another part was spent in the SOC, working real investigations with XDR, Splunk Enterprise Security, firewall events, DNS telemetry, packet data, and AI assistance.

AI can help a product manager become useful faster in a live SOC.

That is the bar I want us to continue building toward as we build Cisco XDR and Splunk Security.

2 weeks назад @ blogs.cisco.com
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC

As part of the Cisco XDR (Extended Detection and Response) product engineering group, a few of us got exactly that chance.

Every product had a part to play for a network as traffic-heavy as Cisco Live.

(PS : Flaunting the SOC T-shirts was fun)AcknowledgementsA heartfelt thank you to Cisco and the entire SOC team — you are all amazing.

To the Cisco XDR , Splunk , Secure Access , and Secure Firewall engineering teams.

Check out the other blogs from our team at the Cisco Live Americas 2026 SOC at Las Vegas:

2 weeks назад @ blogs.cisco.com
The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth
The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth

We built an Experience Score model on Cisco and Splunk infrastructure and watched it run against real traffic, at real scale, in real time.

The result was a working model for how leaders measure what customers feel, act before friction surfaces, and tie operational decisions to revenue and trust.

At Cisco Live, the Experience Score model organized that architecture around four questions business and technology leaders can answer together.

The composite Experience Score tells a leader whether the experience is healthy enough to protect the moments the business depends on.

From Cisco Live to LA28Cisco Live was a rehearsal for larger exposure surfaces, where digital experience, revenue, brand …

2 weeks назад @ blogs.cisco.com
AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026
AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026

And we kept thinking the same engineer thought: this flow is so consistent… could an agentic agent do the first 90%?

It was a great experiment — and a glimpse of a fully self-hosted agentic SOC — but for the event we pivoted to Claude Opus 4.8 running through Claude Code.

The division of labor we landed on: Tier-1 agentic SOC was already handled beautifully by the AI features in our own products — XDR’s Agentic Attack Storyboard and Splunk’s Triage Agent.

What does an agentic SOC actually need?

The MCP servers — an Endace MCP for packet capture/decode and a Splunk MCP for running queries.

2 weeks назад @ blogs.cisco.com
Building the Agentic SOC at Cisco Live Americas 2026
Building the Agentic SOC at Cisco Live Americas 2026 Building the Agentic SOC at Cisco Live Americas 2026

Building on the Cisco Live EMEA SOC, Cisco Live Americas placed the Security Operations Center (SOC) and Network Operations Center (NOC) at the center of the World of Solutions, demonstrating the power of Cisco in bringing Networking, Security and Observability together.

The Cisco Live Americas Agentic SOC architecture shows how a “One Cisco” approach brings different security tools together to eliminate data silos, in close partnership with the NOC.

The SOC at Cisco Live was set up in just two days, thanks to lessons learned and continuous evolution.

For Cisco Live AMER, we treated agentic AI as an auditable review layer across the SOC, not as a replacement for analysts.

Agentic SOC: Incid…

2 weeks назад @ blogs.cisco.com
Ten Years in the SOC at RSAC: What We Learned in 2026
Ten Years in the SOC at RSAC: What We Learned in 2026 Ten Years in the SOC at RSAC: What We Learned in 2026

Cisco Security and Splunk Security released the Findings Report from the Security Operations Center at RSAC 2026 Conference.

This year marked the 10th year of the SOC at RSAC.

Those lessons helped inform the Agentic SOC work that followed at Cisco Live Americas 2026.

The SOC used Cisco AI Defense to gain visibility into generative AI application usage and to help protect on-premises AI models running in the SOC in a Box.

Download the full RSAC 2026 SOC Findings Report to see the architecture, metrics, investigations, lessons learned, and recommendations from the 10th year of the SOC.

2 weeks, 6 days назад @ blogs.cisco.com
Uplevelling Black Hat Threat Hunters
Uplevelling Black Hat Threat Hunters Uplevelling Black Hat Threat Hunters

More telemetry means better visibility – but also more data for threat hunters to sift through.

Then came an important decision: Focus on what matters for detection of threats at Black Hat.

Enriching with Network Context and reducing noiseA file submitted via HTTP doesn’t exist in isolation – it has network context.

It was about:Surfacing high-risk submissions automaticallyProviding network context for faster triageHelping threat hunters dismiss noise fasterThis workflow is far from perfect.

Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more.

4 weeks, 1 day назад @ blogs.cisco.com
Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate
Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate

If you’ve ever troubleshot a complex workflow run, you know the drill: click into actions, expand inputs and outputs, scan logs, backtrack, repeat.

We’ve just released Workflow Run Summaries in Cisco XDR Automate: an on-demand, AI-generated summary that explains what happened during a workflow execution, where things went wrong, and why that matters, without forcing you to manually inspect every step.

What the feature doesWith a single click on “Generate Run Summary”, Cisco XDR Automate analyzes a completed workflow run and produces a concise, human-readable explanation of its execution.

Why this matters, especially for Agentic AIAs XDR Automate Workflows are increasingly triggered by Agent…

1 month назад @ blogs.cisco.com
Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength
Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength

It is the hardest attack category in email security — for any vendor, any product, any architecture.

This balance — 98% threat detection alongside zero hard false positives — is what the 94% Total Accuracy Rating reflects.

What Independent Validation Means for Your Security StrategyEvery email security vendor publishes detection rates.

Read the full report for more insight into ETD’s comprehensive email security capabilities.

All performance data sourced from the SE Labs Advanced Security Test Report — Email (Protection), Cisco Secure Email Threat Defense, May 2026 (v1.0).

1 month назад @ blogs.cisco.com
Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia
Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia

Caption: MCP integrations exposed to the local AI workflow for SOC investigation contextAt this stage, the system was already useful.

Caption: OpenClaw using the local Ollama model backend instead of an external model providerThe distinction is important.

I installed DefenseClaw alongside the OpenClaw environment, to add inspection and audit visibility around the agentic AI workflow.

Sending DefenseClaw events into Splunk made the AI workflow feel more operational and less experimental.

At Black Hat Asia, this became a practical way to explore what private AI for SOC workflows could look like.

1 month, 1 week назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 4 days, 21 hours назад
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

Follow the research in the Black Hat BriefingsMicrosoft Security researchers will also present peer-reviewed technical research in the Black Hat Briefings.

Visit booth #2144 for research, community, and hands-on defenseThis year we are transforming the Microsoft Security booth into a community center.

Partner presenceAt Black Hat 2026, the Microsoft booth will feature 13 partners from the Microsoft Intelligent Security Association (MISA) who will showcase solutions built with Microsoft Security technology.

Skill up before and after Black HatYou do not need to be in Las Vegas to take part in the broader Microsoft Security Black Hat experience.

The Microsoft Black Hat Skilling Challenge begin…

4 days, 21 hours назад @ microsoft.com
ACR Stealer: Two observed intrusion chains amid increased threat activity
ACR Stealer: Two observed intrusion chains amid increased threat activity ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments.

Security teams should prioritize monitoring for ClickFix lures, suspicious WebDAV activity, obfuscated PowerShell execution, and attempts to access browser credential stores.

Microsoft Defender XDR detectionsMicrosoft Defender XDR customers can refer to the list of applicable detections below.

]art Payload hosting siteReferencesLearn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelligence community about the ev…

5 days, 14 hours назад @ microsoft.com
ACR Stealer: Two observed intrusion chains amid increased threat activity
ACR Stealer: Two observed intrusion chains amid increased threat activity ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments.

Security teams should prioritize monitoring for ClickFix lures, suspicious WebDAV activity, obfuscated PowerShell execution, and attempts to access browser credential stores.

Microsoft Defender XDR detectionsMicrosoft Defender XDR customers can refer to the list of applicable detections below.

]art Payload hosting siteReferencesLearn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelligence community about the ev…

5 days, 14 hours назад @ microsoft.com
Least privilege for AI agents: Identity, access, and tool binding
Least privilege for AI agents: Identity, access, and tool binding Least privilege for AI agents: Identity, access, and tool binding

When an agent operates without a managed identity and least-privilege role-based access controls (RBAC), it can access or modify sensitive data beyond intended permissions if controls are not properly configured.

Organizations are deploying agentic capabilities (multi-step automation, delegated actions, tool use) faster than their identity and authorization models are evolving to safely constrain them.

The right mental model is to treat every agent as a first-class principal: give it a lifecycle-managed identity, assign explicit roles, scope its permissions tightly, and scope tool usage to a preconfigured tools manifest or configuration.

In the next 30–90 days, inventory your agent identiti…

5 days, 21 hours назад @ microsoft.com
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

On July 14, 2026, Microsoft Threat Intelligence identified a coordinated supply chain compromise of the @asyncapi npm organization, a widely used set of packages for the AsyncAPI specification and code generation.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories a…

6 days, 12 hours назад @ microsoft.com
Turning threat intelligence into decisive action with Defender Experts
Turning threat intelligence into decisive action with Defender Experts Turning threat intelligence into decisive action with Defender Experts

Today we’re announcing a new service, Microsoft Defender Experts Threat Intelligence, and we are expanding Microsoft Defender Experts MDR to include new third-party and multi-cloud coverage.

Microsoft Defender Experts Threat Intelligence is a new, expert-delivered service that closes that distance.

Today we’re announcing that Microsoft Defender Threat Intelligence (MDTI) capabilities are now fully converged into the Defender portal.

Defender Experts MDR provides a fully managed detection and response service that reduces noise, adds expert context, and drives action.

Everything available today as Defender Experts for XDR carries forward unchanged as Microsoft Defender Experts MDR Plan 1, wh…

6 days, 21 hours назад @ microsoft.com
Defending SaaS-based applications against ShinyHunters OAuth abuse
Defending SaaS-based applications against ShinyHunters OAuth abuse Defending SaaS-based applications against ShinyHunters OAuth abuse

The resulting quiet persistence and large-scale data access highlight the need for stronger detection, visibility, and governance of OAuth-connected applications and guest user accounts.

New posture and governance capabilities for connected OAuth appsWhile improved detection is critical, recent incidents have also highlighted the need for stronger preventive controls and ongoing governance of OAuth-connected applications.

Complete permission visibility for Salesforce connected apps and external client apps.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Micro…

1 week, 1 day назад @ microsoft.com
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

Beginning September 1, 2026, Microsoft will begin rolling out passkeys as the default authentication experience in Microsoft Entra ID.

Select a telecom provider in Microsoft Security StoreToday, Microsoft provides the telecom delivery behind SMS and voice authentication natively within Entra ID.

Microsoft Entra ID supports: Synced passkeys, such as passkeys stored in platform credential managers like iCloud Keychain and Google Password Manager.

Device-bound passkeys, such as Microsoft Authenticator passkeys, Entra passkey on Windows, and FIDO2 security keys.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

1 week, 1 day назад @ microsoft.com
Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative
Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative

That conviction is where the Secure Future Initiative (SFI) started two years ago and continues to guide us today.

And our principles—secure by design, secure by default, secure in operations—are what turn intent into product, like Microsoft 365 Baseline Security Mode.

Evaluate how identity, code, configuration, and network relationships interact in production.

Learn moreTo learn more about Microsoft Security solutions, visit our website.

Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

1 week, 4 days назад @ microsoft.com
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

In analyzing these backdoor capabilities, we discovered that some backdoor commands contain code from additional malware families.

GigaWiper backdoor command 3 is heavily based on Crucio’s code, leading to the assessment that the same threat actor developed both malware families.

Crucio’s code was the base for GigaWiper command 3, and FlockWiper was recoded in Golang and updated for GigaWiper command 12.

Indicators of compromiseIndicator Type Description 633d4cbd496b1094495da89a64f5e6c31a0f6d4d1488411db5b0cba1cfe42001 SHA-256 GigaWiper backdoor ce9ad5f6c12019f4aae5b189bd8ddf5bb09e75b06a0a587b25a855c65948c913 SHA-256 GigaWiper backdoor f622ed85ef31ad4ab973f4e74524866fe1bb44f0965ad2b2ad796cd6…

1 week, 5 days назад @ microsoft.com
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

In analyzing these backdoor capabilities, we discovered that some backdoor commands contain code from additional malware families.

GigaWiper backdoor command 3 is heavily based on Crucio’s code, leading to the assessment that the same threat actor developed both malware families.

Crucio’s code was the base for GigaWiper command 3, and FlockWiper was recoded in Golang and updated for GigaWiper command 12.

Indicators of compromiseIndicator Type Description 633d4cbd496b1094495da89a64f5e6c31a0f6d4d1488411db5b0cba1cfe42001 SHA-256 GigaWiper backdoor ce9ad5f6c12019f4aae5b189bd8ddf5bb09e75b06a0a587b25a855c65948c913 SHA-256 GigaWiper backdoor f622ed85ef31ad4ab973f4e74524866fe1bb44f0965ad2b2ad796cd6…

1 week, 5 days назад @ microsoft.com
Protecting Microsoft at AI speed: How SFI proactively hardens our cloud
Protecting Microsoft at AI speed: How SFI proactively hardens our cloud Protecting Microsoft at AI speed: How SFI proactively hardens our cloud

At Microsoft we encompass these security requirements, along with threat knowledge and operational frameworks in our Secure Future Initiative (SFI), to guide what a well-defended cloud service looks like.

This system is purpose-built to evaluate Microsoft’s own cloud services against our stringent security requirements and make our infrastructure harder to compromise.

Enumerates applicable security controls based on SFI requirements across identity, network, tenant isolation, engineering systems, and detection domains.

Proven results: From theory to practiceWithin a few months, the system has enabled Microsoft security engineering teams to proactively harden our cloud services.

The same AI …

1 week, 6 days назад @ microsoft.com
Protecting Microsoft at AI speed: How SFI proactively hardens our cloud
Protecting Microsoft at AI speed: How SFI proactively hardens our cloud Protecting Microsoft at AI speed: How SFI proactively hardens our cloud

At Microsoft we encompass these security requirements, along with threat knowledge and operational frameworks in our Secure Future Initiative (SFI), to guide what a well-defended cloud service looks like.

This system is purpose-built to evaluate Microsoft’s own cloud services against our stringent security requirements and make our infrastructure harder to compromise.

Enumerates applicable security controls based on SFI requirements across identity, network, tenant isolation, engineering systems, and detection domains.

Proven results: From theory to practiceWithin a few months, the system has enabled Microsoft security engineering teams to proactively harden our cloud services.

The same AI …

1 week, 6 days назад @ microsoft.com
5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management
5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management 5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management

Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management points to a structural shift: CSPM is no longer a periodic compliance exercise.

Frost & Sullivan’s evaluation framework reflects this transition—placing greater emphasis on integrated, code to cloud risk management capabilities inside broader CNAPP platforms.

The Frost Radar™ for Cloud Security Posture Management visualizes how leading vendors compare across innovation and growth—two key measures of market leadership and future potential.

Learn moreRead the Frost & Sullivan Frost Radar™ for Cloud Security Posture Management (2025) to see how CSPM leaders are evaluated—and what capabilities matter most as vendor selec…

2 weeks, 1 day назад @ microsoft.com
5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management
5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management 5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management

Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management points to a structural shift: CSPM is no longer a periodic compliance exercise.

Frost & Sullivan’s evaluation framework reflects this transition—placing greater emphasis on integrated, code to cloud risk management capabilities inside broader CNAPP platforms.

The Frost Radar™ for Cloud Security Posture Management visualizes how leading vendors compare across innovation and growth—two key measures of market leadership and future potential.

Learn moreRead the Frost & Sullivan Frost Radar™ for Cloud Security Posture Management (2025) to see how CSPM leaders are evaluated—and what capabilities matter most as vendor selec…

2 weeks, 1 day назад @ microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 2 months, 4 weeks назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

2 months, 4 weeks назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

3 months, 1 week назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

3 months, 1 week назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

3 months, 2 weeks назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

3 months, 3 weeks назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

3 months, 4 weeks назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

4 months, 3 weeks назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

4 months, 3 weeks назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

5 months назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

5 months, 3 weeks назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

7 months, 1 week назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

7 months, 2 weeks назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

7 months, 2 weeks назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

7 months, 2 weeks назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

8 months назад @ security.googleblog.com