Кибербезопасность
👉 от %username%
Подборка ресурсов по кибербезопасности
На русском 🇷🇺
Securitylab
последний пост 7 часов назад
Пять точек на листе бумаги. Одна задача. 90 лет. Никто так и не смог найти верное решение
Пять точек на листе бумаги. Одна задача. 90 лет. Никто так и не смог найти верное решение Пять точек на листе бумаги. Одна задача. 90 лет. Никто так и не смог найти верное решение

За разгадку для пятиклассника обещают $500, но награда всё ещё не нашла своего гения...

7 часов назад @ securitylab.ru
Робот-пёс, которого не нужно беречь — его нужно разбирать. 200 деталей, открытый код и сальто на 720°
Робот-пёс, которого не нужно беречь — его нужно разбирать. 200 деталей, открытый код и сальто на 720°

Поменять можно вообще всё: корпус, мозги, походку и даже характер.

8 часов назад @ securitylab.ru
Административный доступ без пароля: хакеры Storm-1175 устроили новую атаку на бизнес через уязвимость N-central
Административный доступ без пароля: хакеры Storm-1175 устроили новую атаку на бизнес через уязвимость N-central

!!!README_FIRST!!!" — записка, которую совсем не хочется находить на рабочем компьютере.

9 часов назад @ securitylab.ru
Все реки мира подчиняются одной формуле — и никто не понимает почему
Все реки мира подчиняются одной формуле — и никто не понимает почему

Формула 1957 года описала все реки на Земле. В 2026-м выяснилось, что она работает и задом наперёд.

9 часов назад @ securitylab.ru
Кибератака на порты в США может замедлить поставки для 70% промышленности страны
Кибератака на порты в США может замедлить поставки для 70% промышленности страны Кибератака на порты в США может замедлить поставки для 70% промышленности страны

Порты Северной Каролины оклемались за неделю — а осадок остался.

10 часов назад @ securitylab.ru
Илон Маск нашёл новый способ потратить $10 млрд — построить в Техасе крупнейший завод солнечных панелей
Илон Маск нашёл новый способ потратить $10 млрд — построить в Техасе крупнейший завод солнечных панелей

Полный цикл, запуск в 2029-м… и солнечная энергетика уже никогда не будет прежней.

10 часов назад @ securitylab.ru
Межсетевой экран заблокировал атаку — а потом сам её и провёл. Разбираемся, что такое Ghostjacking
Межсетевой экран заблокировал атаку — а потом сам её и провёл. Разбираемся, что такое Ghostjacking

Специалисты показали, как ИИ-агенты выполняют вредоносные команды, спрятанные в логах.

11 часов назад @ securitylab.ru
«Цифровое ядерное оружие» у нас на столе. Сенатор США требует от OpenAI, Anthropic и Meta* остановить разработку ИИ
«Цифровое ядерное оружие» у нас на столе. Сенатор США требует от OpenAI, Anthropic и Meta* остановить разработку ИИ «Цифровое ядерное оружие» у нас на столе. Сенатор США требует от OpenAI, Anthropic и Meta* остановить разработку ИИ

Крупнейшие разработчики ИИ продолжают инвестировать десятки миллиардов долларов, несмотря на предупреждения о рисках.

11 часов назад @ securitylab.ru
Камеры будущего не будут наводить резкость. Они будут менять форму линзы — как человеческий глаз
Камеры будущего не будут наводить резкость. Они будут менять форму линзы — как человеческий глаз

Моторы, шестерёнки, направляющие — всё это больше не нужно.

12 часов назад @ securitylab.ru
Свой офлайн-ИИ вместо ChatGPT — хакеры Kimsuky обеспечили себе скрытность суверенными инструментами
Свой офлайн-ИИ вместо ChatGPT — хакеры Kimsuky обеспечили себе скрытность суверенными инструментами Свой офлайн-ИИ вместо ChatGPT — хакеры Kimsuky обеспечили себе скрытность суверенными инструментами

Kimsuky собрала ИИ-стек на C# и .NET, который не стыдно показать на собеседовании.

13 часов назад @ securitylab.ru
Новая электронная кожа для роботов не просто чувствует касание — она ощущает, что вы только собираетесь прикоснуться
Новая электронная кожа для роботов не просто чувствует касание — она ощущает, что вы только собираетесь прикоснуться

100 пикселей осязания на одном чипе.

13 часов назад @ securitylab.ru
Вода больше не враг клея: новый состав использует её, чтобы схватываться за 10 секунд
Вода больше не враг клея: новый состав использует её, чтобы схватываться за 10 секунд

Этот клей три года держал груз под водой и не сдался — секрет в «слезах вина»

14 часов назад @ securitylab.ru
Криптовалюты легализованы: что можно купить и сколько — разбор новых правил ЦБ
Криптовалюты легализованы: что можно купить и сколько — разбор новых правил ЦБ Криптовалюты легализованы: что можно купить и сколько — разбор новых правил ЦБ

Что изменилось для владельцев криптовалют в России.

14 часов назад @ securitylab.ru
$30 и адрес почты родителя — всё, что нужно, чтобы следить за чужим ребёнком через умные часы
$30 и адрес почты родителя — всё, что нужно, чтобы следить за чужим ребёнком через умные часы

Камера, микрофон и GPS без единого уведомления.

15 часов назад @ securitylab.ru
Пока безопасники строят межсетевые экраны, 400000 писем утекают прямо через noreply
Пока безопасники строят межсетевые экраны, 400000 писем утекают прямо через noreply

Вот что компании отправляют туда, где, как им кажется, никто не читает.

15 часов назад @ securitylab.ru
Anti-Malware Anti-Malware
последний пост 12 часов назад
Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 2)
Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 2) Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 2)

Титульная страница Brave1 Market в марте 2025 года«Геймификация войны» с появлением маркетплейса Brave1 превращает военные закупки в часть своеобразного соревнования.

Как и на киберполигонах или в игровых программах, наиболее активные участники отображаются на главной странице в рейтинге лидеров.

Начиная с 1 октября 2025 года «е-баллы» стали начисляться не только за боевые операции и минирование, но и за выполнение разведывательных задач и различных логистических операций.

Сначала этот подход был опробован при изменении принципов управления войсками, а затем распространился и на другие направления.

Можно предположить, что в дальнейшем этот подход будет применяться и в ИБ-системах организаци…

12 часов назад @ anti-malware.ru
Обзор PT Fusion, облачного портала для работы с данными киберразведки (Threat Intelligence)
Обзор PT Fusion, облачного портала для работы с данными киберразведки (Threat Intelligence) Обзор PT Fusion, облачного портала для работы с данными киберразведки (Threat Intelligence)

WHOIS/RDAP-данные сетевого индикатора компрометации в PT FusionWHOIS/RDAP-информация предоставляется как в подготовленном, так и в сыром формате.

Результат множественного поиска в PT FusionСамый мощный инструмент поиска в PT Fusion — это поиск по параметрам.

Ландшафт киберугроз в PT FusionДля более удобного взаимодействия с матрицей и реализации отдельных сценариев работы с ландшафтом киберугроз в модуле предусмотрены фильтры.

Паттерны реализации вредоносных техник злоумышленникамиИх можно использовать как для ретроанализа, так и для написания детектирующих правил для SIEM-систем.

Для старта не нужны технические согласования: достаточно указать корпоративную почту, на которую будет отправле…

18 часов назад @ anti-malware.ru
Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 1)
Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 1) Кибератаки с Украины: эволюция Offensive-модели безопасности (Часть 1)

Затем энтузиазм немного остыл, но кибератаки не прекратились, а вектор сместился в сторону кибернападений с применением более оснащённых с технической точки зрения тактик.

Официально они были оформлены позднее и вводились волнами: в начале марта 2022 года, в начале апреля и спустя полгода.

Поэтому покажем, что «полигон» имел соответствующую поддержку и с точки зрения развития технических средств, напрямую связанных с ИБ.

А теперь проясним некоторые детали, связанные с организацией поддержки Starlink и Starshield на территории Украины.

Повышение эффективности применения украинских дронов связано не с достижениями украинских конструкторов или ростом масштабов налаженного «гаражного», кустарно…

1 day, 12 hours назад @ anti-malware.ru
Обзор отечественных low‑code и no‑code инструментов для бизнеса
Обзор отечественных low‑code и no‑code инструментов для бизнеса Обзор отечественных low‑code и no‑code инструментов для бизнеса

Российский рынок low-code и no-code платформ активно развивается на фоне импортозамещения и растущего спроса на быструю разработку корпоративных решений.

Что такое low-code и no-code и зачем это нужно бизнесуВ основе low-code и no-code платформ лежит визуальная модель разработки.

Всё больше платформ поддерживают несколько режимов разработки: no-code для бизнес-пользователей, low-code для аналитиков и pro-code для профессиональных разработчиков.

Обзор российских low-code/ no-code платформРоссийский рынок low-code и no-code насчитывает десятки платформ разного назначения — от конструкторов сайтов и мобильных приложений до специализированных решений для отдельных отраслей.

Сильные стороны: под…

1 day, 16 hours назад @ anti-malware.ru
R-Vision SOAR на Standoff 17: опыт применения в условиях кибербитвы
R-Vision SOAR на Standoff 17: опыт применения в условиях кибербитвы R-Vision SOAR на Standoff 17: опыт применения в условиях кибербитвы

Опыт применения R-Vision SOAR на Standoff 17 показал, какие задачи помогает решать на практике автоматизация.

Именно в таких условиях на юбилейном Standoff 17 решение R-Vision SOAR использовалось командой защиты ретейла.

Standoff — это практическая кибербитва, в рамках которой команды атакующих и защитников проверяют сценарии нападения и реагирования в квазиреальных инфраструктурах.

Как SOAR применялся на StandoffВ 2025 году для работы R-Vision SOAR на Standoff было настроено более 40 коннекторов с различными средствами защиты и инфраструктурными системами.

Таким образом, участие R-Vision SOAR в Standoff стало практической проверкой работы интеграций, удобства выполнения типовых действий и …

4 days, 13 hours назад @ anti-malware.ru
Обзор облачной версии Ассистента 7.0, системы удалённого мониторинга и управления
Обзор облачной версии Ассистента 7.0, системы удалённого мониторинга и управления Обзор облачной версии Ассистента 7.0, системы удалённого мониторинга и управления

Получить учётную запись пользователь может как в клиентском приложении, так и в личном кабинете системы.

Единая точка управления всеми компонентами упрощает администрирование и обеспечивает гибкость при работе как с собственной, так и с внешними инфраструктурами.

Управление сотрудниками и отделами сотрудниковНастройка прав и политик доступа к устройствамКак уже говорилось выше, в рамках организации можно управлять правами и политиками доступа для устройств и сотрудников.

Таким образом пользователь может обращаться к адресной книге — как к своей, так и к адресной книге организации.

Добавление нового устройстваВ разделе «Администрирование» пользователю доступны справочник устройств, личный сп…

4 days, 18 hours назад @ anti-malware.ru
Переход с Microsoft Office на альтернативное ПО: риски и их минимизация
Переход с Microsoft Office на альтернативное ПО: риски и их минимизация Переход с Microsoft Office на альтернативное ПО: риски и их минимизация

Переход с Microsoft Office на альтернативные офисные пакеты — это не только установка нового ПО, но и риск столкнуться с несовместимостью документов, макросов и шаблонов.

Такие проблемы массово возникали при обновлении с Microsoft Office 7/95 на Microsoft Office 97.

А именно так обстоит дело в «МойОфис» и «Р7-Офис» (как и в его основе с открытым кодом OnlyOffice).

В Microsoft Office для создания формул применяется шрифт Cambria Math, и при подстановке его аналога для других платформ всё должно нормализоваться.

Наиболее часто проблема проявляется в Linux, но нередко имеет место и в Windows, и в Android.

5 days, 13 hours назад @ anti-malware.ru
Обзор защищённых платформ и накладных средств безопасности больших данных
Обзор защищённых платформ и накладных средств безопасности больших данных Обзор защищённых платформ и накладных средств безопасности больших данных

Специфика защиты больших данных: проблемы и угрозыГоворя о защите Big Data, стоит начать с расшифровки понятия больших данных и их отличия от обычных массивов информации.

Прогноз увеличения рынка Big Data Security (источник: thebusinessresearchcompany.com)Лидеры рынка Big Data Security: IBM, Microsoft, Oracle, Broadcom (Symantec), AWS.

Машина больших данных «Скала^р МБД.Х»Программно-аппаратный комплекс «Скала^р МБД.Х» — отечественная платформа класса Data Lakehouse для хранения, обработки и анализа больших данных.

Защита систем хранения данных и дата-центров от KasperskyКомпания «Лаборатория Касперского» предлагает комплекс услуг и сервисов для защиты больших данных и дата-центров.

Как выбр…

5 days, 16 hours назад @ anti-malware.ru
Почему обучение информационной безопасности не работает: 6 главных причин
Почему обучение информационной безопасности не работает: 6 главных причин Почему обучение информационной безопасности не работает: 6 главных причин

Значит ли это, что обучение не работает, или проблема в самом подходе к нему?

Выделили шесть возможных причин, по которым обучение ИБ не работает так, как ожидается.

Как понять, что обучение не даёт результатыМожно выделить следующие критерии неэффективного обучения:Сотрудник регулярно совершает одни и те же ошибки.

Такие ситуации возникают потому, что знания не были связаны с реальными рабочими процессами и не стали частью повседневных действий.

ВыводыПричины, по которым обучение информационной безопасности не работает, имеют не методический, а организационный характер.

6 days, 13 hours назад @ anti-malware.ru
Как измерить кибербезопасность: KPI, KRI и ключевые метрики эффективности защиты
Как измерить кибербезопасность: KPI, KRI и ключевые метрики эффективности защиты Как измерить кибербезопасность: KPI, KRI и ключевые метрики эффективности защиты

KPI, KRI и метрики: в чём разницаПри обсуждении информационной безопасности термины KPI и KRI часто путают, хотя они решают разные задачи.

При этом и KPI, и KRI рассчитываются на основе технических и бизнес-метрик, которые собирают системы мониторинга, средства защиты и другие источники данных.

Этот показатель отражает период от компрометации до обнаружения злоумышленника и не является MTTD, однако показывает, сколько времени атакующий может оставаться незамеченным.

Patch SLA = (Количество уязвимостей, устранённых в срок / Общее количество уязвимостей) × 100 %Метрика показывает эффективность процесса управления обновлениями.

Например, для уязвимостей с максимальным приоритетом SLA может сос…

6 days, 16 hours назад @ anti-malware.ru
Как меняются проекты внедрения ИИ в российских компаниях
Как меняются проекты внедрения ИИ в российских компаниях Как меняются проекты внедрения ИИ в российских компаниях

Тем не менее проекты внедрения ИИ в российских компаниях продолжаются.

Как и в целом с ИТ-проектами, они стали более точечными и с упором на максимальную эффективность.

Уровень проникновения ИИ в российских компаниях по ряду отраслейОднако внедрение ИИ далеко не всегда было экономически оправданным.

Влияло и то, что в ряде отраслей, в частности в медицине, это прямо сказывалось на показателях эффективности руководителей учреждений и глав региональных министерств здравоохранения.

ВыводыФокус во внедрении ИИ в российских компаниях всё больше смещается в сторону не новых, а хорошо отработанных и при этом относительно недорогих технологий классической аналитики и традиционного машинного обучени…

1 week назад @ anti-malware.ru
Нужен ли мессенджеру Telegram госконтроль
Нужен ли мессенджеру Telegram госконтроль Нужен ли мессенджеру Telegram госконтроль

Проблема состоит не в их участии, а в том, в какой степени они готовы вмешиваться в их работу.

Ссылки на каналы МИА «Россия сегодня» («Россия сегодня», 2026)Запрет использования Telegram на УкраинеПротиворечия вокруг Telegram особенно ярко проявились на фоне продолжающегося конфликта между Россией и Украиной и ограничений на трафик Telegram в России.

Популярные мессенджеры в Украине в 2026 году (WMTips, 2026)Ограничения работы Telegram в РоссииОфициальные причины введения ограничений на работу Telegram в России так и не были названы.

Впрочем, реальная картина сложнее и касается работы Telegram не только в России, но и в глобальном масштабе.

Самое сложное заключается даже не в самом выборе, …

1 week, 1 day назад @ anti-malware.ru
Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть II
Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть II Сравнение российских межсетевых экранов нового поколения (NGFW) — 2026, часть II

Да Возможность расшифрования протокола TLS 1.3 Да Да Да Да Нет(планируется в будущих версиях, 2027 г.)

Нет Встроенная песочница Нет Нет Нет Нет Нет(планируется в будущих версиях, 2027 г.)

Нет(интеграция с «Гарда DLP») Режим блокировки для DLP Нет Нет Нет Нет Нет Нет Режим логирования для DLP Нет Нет Нет Нет Нет Нет Возможность блокировки передачи определенных типов файлов Нет Нет Нет Нет Нет(планируется в будущих версиях, 2027 г.)

Нет(в разработке) Свой клиент для IPsec VPN Нет Нет Нет Нет Нет Нет(в разработке) Поддержка OpenVPN Да Да Нет Да Нет(планируется в ближайшей версии — до конца 2026 года) Нет(поддержка WireGuard) Поддержка OpenVPN ГОСТ Да Нет Нет Нет Нет Нет Поддержка IKEv2 Да Да Н…

1 week, 1 day назад @ anti-malware.ru
Геополитика и безопасность: почему Telegram и Alibaba под прицелом государства
Геополитика и безопасность: почему Telegram и Alibaba под прицелом государства Геополитика и безопасность: почему Telegram и Alibaba под прицелом государства

Но на них действуют законы, которые нередко принимались без понимания специфики новой среды.

Джек Ма, китайский миллиардерВ 1995 году муниципальный совет Ханчжоу направляет Джека Ма на годовую стажировку в США по студенческому обмену.

Предав наследие наших предков, мы встали на путь саморазрушения — морального, интеллектуального, экономического и, в конечном итоге, биологического.

Но что реально происходит «под капотом» и в какую сторону склонится чаша весов «независимости» — для большинства стран это риски ИБ.

Выход из них далеко не всегда способствует достижению общих целей — технологического и инновационного развития с соблюдением регуляторных и конституционных требований.

1 week, 4 days назад @ anti-malware.ru
Secure Enterprise Browser: новый стандарт безопасности бизнеса
Secure Enterprise Browser: новый стандарт безопасности бизнеса Secure Enterprise Browser: новый стандарт безопасности бизнеса

Браузер — один из значимых векторов атакБыло бы преувеличением сказать, что количество атак на браузер и через него выросло в последние годы.

Другими словами, корпоративный браузер позволяет контролировать все потоки данных, которые через него проходят.

Крупнейшие игроки:Google Chrome Enterprise — самый известный корпоративный браузер.

Глобальные лидеры (специализированные решения):Island — стартап из США, создавший полноценный корпоративный браузер на основе Chromium.

Через пять лет фраза «используйте корпоративный браузер» будет звучать так же естественно, как сегодня «используйте корпоративную почту».

1 week, 4 days назад @ anti-malware.ru
Хабр: ИБ Хабр: ИБ
последний пост 7 часов назад
Что на самом деле лежит в зашифрованном блоке рассуждений Claude: разбираем signature по байтам
Что на самом деле лежит в зашифрованном блоке рассуждений Claude: разбираем signature по байтам Что на самом деле лежит в зашифрованном блоке рассуждений Claude: разбираем signature по байтам

Вот он целиком, как лежит в JSON:Первое, что бросается в глаза: поле thinking пустое.

Не в том смысле, что модель не думала.

Я потратил пять минут, чтобы понять, что это, и слегка похолодел: это oauthAccount.organizationUuid из моего же ~/.claude.json .

То есть каждый зашифрованный блок рассуждений таскает внутри заголовка, открытым текстом, id модели и id вашей организации.

Всё это едет в каждом коммите, где вы случайно оставили .jsonl историю агента, и в каждом датасете агентских логов, выложенном на Hugging Face.

7 часов назад @ habr.com
Мысли ИИ научились читать с помощью другого ИИ. Внутри нашли чужие пароли и ключи
Мысли ИИ научились читать с помощью другого ИИ. Внутри нашли чужие пароли и ключи Мысли ИИ научились читать с помощью другого ИИ. Внутри нашли чужие пароли и ключи

Старшую модель при этом не взламывают вообще: ее защиты от дистилляции просто не срабатывают, потому что к ней никто не обращался.

Провайдеры фильтруют то, что модель говорит вслух, но не то, что она думает по дороге к ответу.

Сервер провайдера послушно расшифрует блок, и модель прочитает чужую инструкцию как собственное прошлое рассуждение, а не как подозрительный текст со стороны.

Тема верности цепочек рассуждений обсуждается не первый год, но в случае закрытых API сравнивать саммари до сих пор было не с чем.

И не полагаться на то, что раз вы сами не можете это прочитать, то и никто не сможет.

9 часов назад @ habr.com
MLOps для DevOps-инженера: как построить платформу машинного обучения в закрытом контуре
MLOps для DevOps-инженера: как построить платформу машинного обучения в закрытом контуре MLOps для DevOps-инженера: как построить платформу машинного обучения в закрытом контуре

На практике это означает, что все те практики, которые DevOps-инженер считает базовыми — версионирование, CI/CD, контейнеризация, мониторинг, секреты — распространяются ещё и на данные и модели.

Для этого нужен трекинг экспериментов — мы взяли MLflow с PostgreSQL в качестве бэкенда.

Архитектура: что и зачем мы развернулиПлатформа спроектирована для работы в закрытом контуре: приватный GitLab, приватный Docker Registry, внутренний Ingress, никаких облачных сервисов.

Мы использовали это, когда понадобилось передать MLFLOW_TRACKING_USERNAME и MLFLOW_TRACKING_PASSWORD в singleuser-поды JupyterLab из того же секрета, что используется для MLflow и inference.

Но она показывает главное: MLOps — это…

9 часов назад @ habr.com
Что такое ARP‑Spoofing и как от него защититься
Что такое ARP‑Spoofing и как от него защититься Что такое ARP‑Spoofing и как от него защититься

ARP (Address Resolution Protocol) — протокол, с помощью которого устройства запрашивают MAC‑адреса других устройств с искомым IP‑адресом.

Начало отравленияРассылка поддельных ответов устройству от лица маршрутизатора с помощью утилиты из набора dsniffВ первой сессии терминала начинаем рассылку поддельных ARP‑ответов смартфону.

Рассылка поддельных ответов маршрутизатору от лица устройства с помощью утилиты из набора dsniffВо второй сессии терминала начинаем рассылку поддельных ARP‑ответов маршрутизатору.

Так как же защититься от столь примитивной, но от того не менее опасной кибератаки?

Защита от ARP‑Spoofing со стороны устройствСамое надёжное, и в то же время простое решение — создать стати…

10 часов назад @ habr.com
Анатомия VDD: Как я нашел RCE в форке Telegram, а Google Security не увидел «ничего вредоносного»
Анатомия VDD: Как я нашел RCE в форке Telegram, а Google Security не увидел «ничего вредоносного» Анатомия VDD: Как я нашел RCE в форке Telegram, а Google Security не увидел «ничего вредоносного»

Когда ты генерируешь сложную архитектуру нейросетями, а потом просто заворачиваешь это в жесточайший обфускатор, решив, что это спасёт от взлома - получается то, что мы имеем.

Во-вторых, внутренний стейт генератора дробится не на 64-битные куски, а на 16-битные short -блоки.

Нет проверки подписиЯ просмотрел всю цепочку и не нашел вообще никакой проверки того, кто сгенерировал этот архив.

Конечно, технически это примитивная обфускация и стеганография, а не криптография (не надо сравнивать это с AES).

Что в сухом остаткеЯ собрал всё, что нашел, в одну картинку.

12 часов назад @ habr.com
Книги по веб-хакингу
Книги по веб-хакингу Книги по веб-хакингу

Вкратце — я собираю автоматические переводы материалов по хакингу и выкладываю их на сайте библиотеки.

В этой подборке — книги для тех, кто хочет разбираться в веб-приложениях, браузерах и сетях: от bug bounty и JavaScript/XSS до Wireshark, Nmap, сетевых протоколов и классических справочников по безопасности веба.

Карточка книгиNmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security ScanningОфициальное руководство по Nmap от Гордона “Fyodor” Лайона, автора проекта.

Авторы рассматривают получение и удержание контроля над браузером, обход Same-Origin Policy, атаки на пользователей, эксплуатацию движков, расширений и плагинов, межпротокольные атаки, DNS-туннели…

13 часов назад @ habr.com
Как мы до интернета такого докатились
Как мы до интернета такого докатились Как мы до интернета такого докатились

Но шло время, компьютерная техника развивалась, становилась более доступной, и к Джону с Иваном пришли друзья с требованием подключить к сети и их компьютеры тоже.

А так как блог был доступен только пока компьютер включен – Иван решил продать свой запорожец и поставить на его место сервер, который работал круглосуточно и показывал его блог всем желающим.

Использовать напрямую корневой сертификат для выпуска других сертификатов — опасно: если закрытый ключ украдут — будет катастрофа (потому что смогут навыпускать каких угодно сертификатов).

А у меня — и XSS в арсенале, и плагины нехорошие в наличии, и эксплоитов вчера из даркнета накачал…— Справедливо.

КриптоПРО создает сертификат, отправляе…

16 часов назад @ habr.com
5 ошибок в NetworkPolicy, из‑за которых ваши политики ничего не блокируют
5 ошибок в NetworkPolicy, из‑за которых ваши политики ничего не блокируют 5 ошибок в NetworkPolicy, из‑за которых ваши политики ничего не блокируют

Команда закрыла тикет по сетевой изоляции: написали политики на все неймспейсы, применили, аудитор поставил галочку.

Политики при этом лежали в кластере, kubectl get networkpolicy их показывал, ошибок в них не было.

namespaceSelector, который смотрит на метки, а не на имяПолитика просто не срабатывает.

Чего политики не покрывают вообщеДаже правильно написанные и применяемые политики оставляют несколько дыр, о которых полезно знать заранее.

Понимание того, как Kubernetes, CNI и инструменты диагностики работают вместе, помогает находить такие разрывы до продакшена и не путать наличие политики с реальной изоляцией.

16 часов назад @ habr.com
Ваш холодный криптокошелёк взломан. Разбор уязвимости RNG у Coldcard Mk2–Mk5
Ваш холодный криптокошелёк взломан. Разбор уязвимости RNG у Coldcard Mk2–Mk5 Ваш холодный криптокошелёк взломан. Разбор уязвимости RNG у Coldcard Mk2–Mk5

Я восстановил 274 сид-фразы и 1 396 адресов — и все они оказались уже обчищены.

Четвёртая волна (1–5 августа) — всего 29 подтверждённых адресов на 0,29 BTC, связь с Coldcard не подтверждена, но на картину это уже не влияет.

Причина оказалась не в изощрённой атаке на криптографию, а в двух мелких дефектах сборки, которые по отдельности были бы безобидны.

Это не шифр — это pet-project на выходные, который реализуется на встроенной графике обычного ноутбука.

Каждая гипотеза разбивалась о простой факт: кошельки были холодными, купленными в разное время и в разных местах.

16 часов назад @ habr.com
Выжимаем максимум XP из каждого пентеста: искусство разбора завершенных проектов
Выжимаем максимум XP из каждого пентеста: искусство разбора завершенных проектов Выжимаем максимум XP из каждого пентеста: искусство разбора завершенных проектов

Вы не фиксируете, где действовали эффективно, а где теряли время, не запоминаете неочевидные находки, не задаетесь вопросом «а что, если бы я пошел другим путем?».

А самое печальное — вы даже не узнаете, что упустили, потому что клиент не знает о возможных атаках и не спросит.

Если вы не анализируете, какие объекты или технологии вы проигнорировали, эти пробелы будут повторяться из проекта в проект.

Иногда даже в самом простом домене есть тонкости конфигурации, которые вы не замечали, потому что не углублялись.

Напишите «внутренний разбор» по горячим следамНе отчет для клиента, а для коллег.

16 часов назад @ habr.com
Вайб-кодинг против ИБэшника. Несмертельная битва. Часть 2
Вайб-кодинг против ИБэшника. Несмертельная битва. Часть 2 Вайб-кодинг против ИБэшника. Несмертельная битва. Часть 2

После этого стало гораздо проще понять, что именно подтверждает каждый электронный ключ и каких прав он не должен давать.

Он не хранит важные ключи и не принимает серьезных решений.

Он не считает список пустым и не снимает защиту со всех устройств.

Теперь перед показом экрана компьютер сотрудника и компьютер администратора сначала проверяют друг друга.

То есть последняя найденная проблема была не в сетевой криптографии, а в правах каталога на машине сборки.

17 часов назад @ habr.com
Как строить сканирование активов в MaxPatrol VM. Ч.1 — LDAP
Как строить сканирование активов в MaxPatrol VM. Ч.1 — LDAP Как строить сканирование активов в MaxPatrol VM. Ч.1 — LDAP

Там я рассказывал о том, как мы с Романом Журавлевым @RNZH с нуля внедряли MaxPatrol VM, запись можно посмотреть на Rutube.

В качестве основого ПО я использую MaxPatrol VM от Positive Technologies, так исторически сложилось - фух, оправдался.

К тому же, RBVM в инвентаризации активов закладывает определение критичности ИТ-активов, а это означает, что контекстные метрики CVSS заходят в чат.

В списке поддерживаемого ПО вендор заявляет о поддержке всех версий Microsoft Active Directory, что не может не радовать.

Актив Active Directory не очищается, как остальные активы, сколько не выставляй ограничение хранения истории активов в параметре HistoryRotationDepth роли Core.

17 часов назад @ habr.com
$40 против миллионов: экономика кибератак, которую защитники не хотят считать
$40 против миллионов: экономика кибератак, которую защитники не хотят считать $40 против миллионов: экономика кибератак, которую защитники не хотят считать

Итог: защитники догоняют, но пока отстают — и главная причина не в технологиях, а в физическом дефиците людей.

Хуже всего — управление уязвимостями (0,92) и доступом (1,21): те самые «базовые» вещи, которые дешевле всего внедрить и на которых массово экономят.

KPI завязан на «закрытие предписаний регулятора», а не на «снижение ущерба от инцидента».

Компании вынуждены тратить ресурсы не на то, что реально защищает, а на то, что каталогизировано и сертифицировано ФСТЭК.

Киберстрахование в РФ пока почти не развито: за год компании заплатили за полисы от кибератак порядка 1,5–3 млрд руб.

17 часов назад @ habr.com
Железный ключ к Secure Boot RK35xx
Железный ключ к Secure Boot RK35xx Железный ключ к Secure Boot RK35xx

Так у коллеги родилась подборка статей и выступлений на тему того, как устроен Secure & Encrypted boot у Rockchip RK35xx.

3 : 2; err = check_boot_flow(0, boot_stage); if ( !err ) { err = load_binary__(&fw_header_1, data_buff, fw_header_1.binaries); // CHECK DDR Training if ( !err ) { boot_stage = use_RKPK ?

4 : 3; err = check_boot_flow(0, boot_stage); if ( !err ) { // some lines omitted for clarity err = run_binary(data_buff); if ( !err ) { err = load_binary__(&fw_header_1, 0, &fw_header_1.binaries[1]); // CHECK SPL if ( !err ) { boot_stage = use_RKPK ?

В итоге, в дополнение к Chipolino изготовили внешний транзисторный модуль по такой схеме и вот что получилось:Схема и плата модуля.

В качес…

19 часов назад @ habr.com
Четыре узла из семи не работали, и все проверки говорили OK
Четыре узла из семи не работали, и все проверки говорили OK Четыре узла из семи не работали, и все проверки говорили OK

Вход знает, кто вы, и не знает, куда вы идёте, выход знает куда и не знает кто.

Почему это не всплылоurltest не жалуется на мёртвую цепочку, он её просто не выбирает.

Если из двенадцати цепочек девять не встают, туннель поднимется по трём оставшимся, и в логах не появится ни строчки, потому что ничего не сломалось, а выбор из меньшего количества вариантов ничем не отличается от выбора из большего.

Флот он не сверял, и поэтому на каждой из семи машин лежал скрипт, печатавший ok: masquerade host <...> and every named mirror are allowed и формально не врущий ни в одном слове.

Новый конфиг перед заменой живого проверяется sing-box check , и если проверка не прошла, не меняется ничего.

1 day, 3 hours назад @ habr.com
Хакер Хакер
последний пост 8 часов назад
N-able выпустила уже два патча для уязвимости обхода аутентификации в N-central
N-able выпустила уже два патча для уязвимости обхода аутентификации в N-central N-able выпустила уже два патча для уязвимости обхода аутентификации в N-central

Повторное обновление потребовалось из-за продолжающихся атак на уязвимость CVE-2026-18577: злоумышленники получают права администратора на серверах N-central и проникают в системы клиентов.

Тогда расследование показало, что неизвестные атакующие эксплуатировали 0-day-уязвимость в N-central, которая в итоге получила идентификатор CVE-2026-18577 (8,2 балла по шкале CVSS).

Однако спустя несколько дней в N-able подготовили второй срочный патч, вошедший в версию 2026.3.1.10.

Как выяснилось, получив административный доступ к N-central через 0-day-баг, злоумышленники использовали штатную функцию Take Control для подключения к компьютерам внутри управляемых окружений.

В настоящее время расследовани…

8 часов назад @ xakep.ru
Хакеры похитили у Levi Strauss корпоративные данные
Хакеры похитили у Levi Strauss корпоративные данные Хакеры похитили у Levi Strauss корпоративные данные

Представители компании Levi Strauss (бренд Levi's) сообщили о кибератаке, в ходе которой злоумышленники с помощью социальной инженерии скомпрометировали рабочие компьютеры трех сотрудников и похитили хранившиеся на них корпоративные данные.

В компании сообщают, что неизвестные атакующие применили методы социальной инженерии против трех сотрудников Levi Strauss и в результате получили доступ к их корпоративным компьютерам, откуда похитили данные.

Вскоре специалисты Levi Strauss обнаружили атаку и лишили хакеров доступа к скомпрометированным системам.

Также в Levi Strauss подчеркнули, что инцидент не привел к остановке или нарушению бизнес-процессов и, по текущей оценке, не окажет существенно…

10 часов назад @ xakep.ru
SSTI в RAGFlow. Разбираем недавнюю CVE в популярном генеративном движке
SSTI в RAGFlow. Разбираем недавнюю CVE в популярном генеративном движке SSTI в RAGFlow. Разбираем недавнюю CVE в популярном генеративном движке

Се­год­ня раз­берем кра­сивый слу­чай инъ­екции шаб­лонов, которая дает пол­ноцен­ное RCE в популяр­ном про­дук­те RAGFlow.

RAGFlow — это опен­сор­сный дви­жок для генера­ции тек­стов.

В RAGFlow мож­но соз­давать ИИ‑аген­тов с набором про­цес­соров.

warning Статья име­ет озна­коми­тель­ный харак­тер и пред­назна­чена для спе­циалис­тов по безопас­ности, про­водя­щих тес­тирова­ние в рам­ках кон­трак­та.

Чекай готов­ность коман­дойdocker logs -f ragflow- server | grep "Running on"Ког­да в логах появит­ся адрес, открой в бра­узе­ре http:// localhost .

12 часов назад @ xakep.ru
TONTOU-атака обходит защиту от Spectre v2 на процессорах AMD и Intel
TONTOU-атака обходит защиту от Spectre v2 на процессорах AMD и Intel TONTOU-атака обходит защиту от Spectre v2 на процессорах AMD и Intel

Специалисты Лаборатории компьютерных наук и искусственного интеллекта Массачусетского технологического института (MIT CSAIL) разработали новую технику атак interrupt injection, которая позволяет обойти защиту от атак класса Spectre v2 на процессорах AMD и Intel.

К примеру, в системе на базе AMD Zen 2 эксперты смогли прочитать произвольную память ядра Linux и извлечь содержимое /etc/shadow с хешами паролей.

Такие механизмы, как eIBRS в процессорах Intel и Safe RET в AMD, призваны помешать злоумышленникам влиять на предсказание ветвлений и тем самым направлять спекулятивное выполнение по нужному им пути.

Из десяти проведенных тестов содержимое /etc/shadow удалось найти и извлечь пять раз, и н…

13 часов назад @ xakep.ru
Valve предупредила владельцев устройств Steam об утечке данных
Valve предупредила владельцев устройств Steam об утечке данных Valve предупредила владельцев устройств Steam об утечке данных

Представители Valve предупредили европейских пользователей устройств Steam об утечке данных.

Злоумышленники взломали логистического подрядчика Valve, компанию CEVA Logistics, и похитили имена, адреса, телефоны, email-адреса и информацию о заказах.

О произошедшем в Valve узнали 7 августа, а 10 августа пользователи начали сообщать в социальных сетях о полученных от компании уведомлениях.

CEVA Logistics занимается доставкой устройств Steam (например, Steam Deck и Steam Machine) покупателям в странах Европы и обладает всеми необходимыми для этого сведениями.

По информации Valve, в CEVA уже изолировали пострадавшие системы, отключили их от сети и привлекли сторонних специалистов для расследовани…

15 часов назад @ xakep.ru
Банки будут искать вредоносное ПО на устройствах клиентов
Банки будут искать вредоносное ПО на устройствах клиентов Банки будут искать вредоносное ПО на устройствах клиентов

С 1 марта 2027 года российские банки будут обязаны блокировать переводы, если на устройстве клиента обнаружено вредоносное ПО.

Новое правило распространяется на операции по банковским картам, переводы электронных денег и через Систему быстрых платежей (СБП).

Согласно документу, банки должны будут встроить в свои мобильные приложения и официальные сайты сертифицированные средства защиты, способные обнаруживать вредоносное ПО до проведения перевода.

Договоры с действующими клиентами банки должны обновить до 1 сентября 2027 года и до этого же срока запросить их согласие или отказ.

Напомним, что с января 2026 года банки уже проверяют денежные переводы по ряду признаков, которые могут указывать …

17 часов назад @ xakep.ru
Продажи аппаратных криптокошельков в России выросли более чем вдвое на фоне нового законодательства
Продажи аппаратных криптокошельков в России выросли более чем вдвое на фоне нового законодательства Продажи аппаратных криптокошельков в России выросли более чем вдвое на фоне нового законодательства

По данным двух крупных ретейлеров, продажи увеличились более чем вдвое.

В «М.Видео» сообщили, что число проданных кошельков во втором квартале выросло на 107% по сравнению с первым, а продажи в денежном выражении увеличились на 92%.

Продажи в денежном выражении увеличились на 60%.

При этом средняя цена аппаратного кошелька на Wildberries снизилась на 13% — до 7900 рублей, а в «М.Видео» расширили ассортимент таких устройств.

Продажи кошельков также растут незадолго до вступления в силу более широкого режима регулирования криптовалют в России, намеченного на 1 сентября.

18 часов назад @ xakep.ru
Злоумышленники распространяют вредоносные версии iOS-приложений в Telegram
Злоумышленники распространяют вредоносные версии iOS-приложений в Telegram Злоумышленники распространяют вредоносные версии iOS-приложений в Telegram

Злоумышленники публикуют в русскоязычном Telegram-канале модифицированные версии популярных приложений и предлагают пользователям установить их в обход App Store.

В некоторые приложения встроен вредоносный модуль, который собирает данные об устройстве, отслеживает геолокацию и делает снимки экрана.

По информации специалистов «Лаборатории Касперского», атакующие модифицируют настоящие приложения, внедряя в них малварь.

Так, среди обнаруженных зараженных образцов были модифицированные версии неназванных приложений онлайн-площадки для продажи товаров, фоторедактора и сервиса для просмотра видео.

Такой сертификат можно импортировать в сторонние инструменты, например, eSign или Scarlet, подписат…

1 day, 8 hours назад @ xakep.ru
Злоумышленники опустошают ноды Bitcoin Lightning
Злоумышленники опустошают ноды Bitcoin Lightning Злоумышленники опустошают ноды Bitcoin Lightning

Тяжелая неделя для ПО для биткоина стала еще тяжелее: на этот раз пострадали продавцы, принимающие платежи через Lightning Network.

В ночь на пятницу злоумышленники начали атаковать ноды Lightning, работающие через BTCPay Server, воспользовавшись критической уязвимостью, из-за которой оказались раскрыты учетные данные, защищающие эти ноды.

Судя по всему, к моменту, когда в BTCPay Server опубликовали предупреждение, злоумышленники уже вовсю эксплуатировали эту уязвимость на действующих серверах.

В BTCPay Server поблагодарили участников Red Team — Крейга Роу, Роба Гамильтона, Калле и Эвана Калоудиса — за ответственное раскрытие информации и помощь в анализе проблемы.

В BTCPay пока не публикую…

1 day, 9 hours назад @ xakep.ru
Уязвимости в ZTP TP-Link Omada приводят к полной компрометации сети
Уязвимости в ZTP TP-Link Omada приводят к полной компрометации сети Уязвимости в ZTP TP-Link Omada приводят к полной компрометации сети

Аналитики компании Forescout нашли сразу 15 уязвимостей в механизме zero-touch provisioning (ZTP) устройств TP-Link Omada.

Omada — линейка компании TP-Link для корпоративных сетей, в которую входят точки доступа Wi-Fi, коммутаторы, шлюзы и VPN-роутеры.

Одиннадцать уязвимостей получили идентификаторы с CVE-2025-9289 по CVE-2025-9293, CVE-2025-15544 и с CVE-2025-15627 по CVE-2025-15631.

Еще четыре проблемы остались без отдельных CVE, так как в TP-Link оценили их как уязвимости низкой степени опасности.

Также отмечается, что некоторые баги представляют опасность и для других продуктов компании, включая IP-камеры VIGI, роутеры Festa и устройства умного дома Tapo и Kasa.

1 day, 10 hours назад @ xakep.ru
HTB Helix. Получаем рут через ПЛК ядерного реактора
HTB Helix. Получаем рут через ПЛК ядерного реактора HTB Helix. Получаем рут через ПЛК ядерного реактора

В про­мыш­ленных и IoT-сис­темах при­виле­гиро­ван­ные опе­рации час­то завяза­ны не на обыч­ные пра­ва в ОС, а на сос­тояние обо­рудо­вания: режим работы, фла­ги тес­тирова­ния и показа­ния дат­чиков.

На­ша цель — получить пра­ва супер­поль­зовате­ля на машине Helix с учеб­ной пло­щад­ки Hack The Box.

warning Под­клю­чать­ся к машинам с HTB рекомен­дует­ся с при­мене­нием средств ано­ними­зации и вир­туали­зации.

На пер­вом выпол­няет­ся обыч­ное быс­трое ска­ниро­вание, на вто­ром — более тща­тель­ное, с исполь­зовани­ем встро­енных скрип­тов (опция -A ).

Под­робнее про работу с Nmap читай в статье «Nmap с самого начала.

1 day, 12 hours назад @ xakep.ru
77 расширений Open VSX собирали информацию о разработчиках
77 расширений Open VSX собирали информацию о разработчиках 77 расширений Open VSX собирали информацию о разработчиках

Специалисты Manifold Security выявили в Open VSX 77 вредоносных расширений, которые маскировались под легитимные инструменты для разработчиков и собирали информацию о зараженных системах.

Большинство ограничивалось сбором только базовых данных, однако 19 расширений проводили подробную разведку, изучая рабочие окружения, Git-репозитории и CI-системы.

Многие фальшивки имели версию 0.0.1, а содержимое легитимного файла extension.js подменяли кодом, предназначенным для сбора и кражи данных.

58 расширений собирали только базовую информацию о системе — прежде всего имя хоста и иногда название рабочей папки и версию редактора.

Вредоносы перечисляли до 60 установленных расширений и собирали метадан…

1 day, 13 hours назад @ xakep.ru
Трейдеры «выкачивают» миллионы из Polymarket
Трейдеры «выкачивают» миллионы из Polymarket Трейдеры «выкачивают» миллионы из Polymarket

В Polymarket, крупнейшей платформе предсказательных рынков, объявили о полном пересмотре механизма расчета цен для краткосрочных криптоконтрактов.

Иными словами, кто-то открывал крупную позицию на Polymarket, а затем кратковременным давлением на цену на Binance «продавливал» нужный исход в последние мгновения перед закрытием окна расчета.

В официальном сообщении в X (бывшем Twitter) в Polymarket заявили, что обновляют механизм расчета крипторынков «вверх/вниз», чтобы защитить целостность торгов.

Для поддержки ликвидности в переходный период в Polymarket выделят 1 миллион долларов на вознаграждения за ликвидность на всех затронутых рынках в течение августа.

Разработчик Polymarket в ответ на …

1 day, 14 hours назад @ xakep.ru
Исследователи вынудили ИИ-агента Google атаковать собственный репозиторий
Исследователи вынудили ИИ-агента Google атаковать собственный репозиторий Исследователи вынудили ИИ-агента Google атаковать собственный репозиторий

Исследователи из компании Pillar Security обнаружили в репозитории Google Agent Development Kit для Python сразу две проблемы, которые злоумышленник мог использовать для запуска привилегированного ИИ-агента.

Один из багов позволял подделать процесс проверки пул-реквеста, а другой — выполнить произвольный код в CI-раннере и похитить секреты.

Google ADK представляет собой опенсорсный набор инструментов для создания и развертывания ИИ-агентов, который скачали уже более 90 млн раз.

Как объясняет исследователь Pillar Security Дэн Лисичкин (Dan Lisichkin), проблемы были связаны не с самим Python-пакетом, а с автоматизацией работы его GitHub-репозитория.

Так, в своем отчете исследователи продемонс…

1 day, 15 hours назад @ xakep.ru
Стейблкоин-магнат погиб, упав с 30-го этажа в Парагвае
Стейблкоин-магнат погиб, упав с 30-го этажа в Парагвае Стейблкоин-магнат погиб, упав с 30-го этажа в Парагвае

По данным полиции, падение с 30-го этажа одного из самых высоких зданий района произошло предположительно около двух часов ночи по местному времени в прошлый вторник.

Он родился в Гонконге, а в детстве переехал в Канаду.

В его аккаунте в X долгое время фигурировали тикеры токенов LIF3, TOMB, FTM, TSHARE и L3USD.

Публичный образ Йе был противоречивым: в X он не афишировал роскошную жизнь, зато в Instagram регулярно демонстрировал частные самолеты и яхты.

Тогда же в Киеве в собственном автомобиле был застрелен связанный с Украиной криптодеятель Константин Галиш (Kostya Kudo).

1 day, 16 hours назад @ xakep.ru
In English 🇺🇸
The Hacker News The Hacker News
последний пост 6 часов назад
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.

A remote flaw reachable through the service's TFTP handling without authentication or user interaction.

A remote, unauthenticated code execution flaw requiring no user interaction.

A remote, unauthenticated code execution flaw requiring no user interaction.

Chaining the RCE with CVE-2026-55040 is what produced Rapid7's unauthenticated RCE.

6 часов назад @ thehackernews.com
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks.

"Kimwolf v7 adds an HTTP/2-based DDoS flood that constructs complete browser fingerprints," researchers Asher Davila, Chris Navarrete, and Doel Santos said.

"This makes attack traffic more difficult to distinguish from legitimate browsing."

Kimwolf is known to target Android TV boxes since August 2025, while its Linux counterpart, AISURU, primarily focuses on Linux IoT devices.

Once launched, the malware attempts to mask itself as seemi…

6 часов назад @ thehackernews.com
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client

Client fixes shipped in June and July, roughly two months before the flaws were made public, and no exploitation has been reported as of publication.

Zoom tracks the flaws as CVE-2026-53413 (CVSS score: 8.3), a buffer over-write, and CVE-2026-53414 (CVSS score: 6.5), a buffer over-read, both covered by ZSB-26015 and ZSB-26016, plus CVE-2026-53415 (CVSS score: 8.3), a use-after-free, in ZSB-26017.

Zoom issues its own CVE records, and NIST no longer routinely re-scores them, so the lower figures will likely stand.

The advisory says the same bug may let a participant "conduct a denial of service," and scores its confidentiality impact at none.

It surfaced only when they traced the running clie…

7 часов назад @ thehackernews.com
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

This includes configuration files for connecting to the corporate VPN using WireGuard to supposedly complete an assessment, along with a link to a second Zoom meeting during which the test is monitored.

]net/projects/soprasteriavpn/," which claims to be an "open-source corporate VPN solution designed for businesses seeking secure remote access and site-to-site connectivity without expensive licensing fees," according to cached Google Search results.

Put differently, the poisoned version of WireGuard allows an attacker to run arbitrary commands on the victim host without their knowledge.

CERT-UA is urging IT professionals to be on the lookout for social engineering techniques to stay protect…

7 часов назад @ thehackernews.com
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account.

The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.

Rapid7 then chained the bypass to a separate remote code execution flaw and ran code on the server with no credentials.

Microsoft shipped the July fix in three server updates:Subscription Edition KB5002882, build 16.0.19725.20434SharePoint Server 2019 KB5002883, build 16.0.10417.20175SharePoint Server 2016 KB5002891, build 16.0.5561.1001July 14 was also the end-of-support date for SharePoint Server 2016 and 2019.…

9 часов назад @ thehackernews.com
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware.

DeadLock was first detected in July 2025, employing double extortion tactics to encrypt victim environments and apply pressure by threatening to publicly release exfiltrated data.

The ransomware adopts a selective encryption model to exclude certain directories, file extensions, and file names from encryption.

Perhaps the most unusual aspect of the ransomware is its use of an HTML note ("RECOVERY_CHAT..html") that's dropped in all drive root directories and all Desktop folders.

The two wallet addresses used by the threat actor are below -0x8EF7c3e531d8…

9 часов назад @ thehackernews.com
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response.

GPT-5.6-Cyber, a more cyber-permissive version of GPT-5.6 Sol, builds upon GPT‑5.5‑Cyber, which OpenAI released in June 2026.

The tests show that GPT‑5.6‑Cyber completes 95.0% of these requests, compared with just 1.5% for GPT‑5.6 Sol and 2.0% when used with Daybreak Blue access.

GPT‑5.6‑Cyber is trained to improve performance on certain cybersecurity workflows involving exploit development and advanced security research.

"Models running with reduced safeguards carry risks beyond standard model usage, whether from mis…

13 часов назад @ thehackernews.com
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A malicious SIM card can order the device it sits in to run commands of the attacker's choosing.

Unattended IoT gear with an accessible SIM tray and few other exposed interfaces is exactly where that trade is worth making.

Inside it, the Quectel EC25AFXDGA module's atfwd_daemon passes attacker-controlled text into a shell call through an unsafe format string.

Muench told The Hacker News the team disclosed to Quectel as the module vendor, which then notified its own customers.

The reports went to Google, Oppo, Quectel, Semtech and Qualcomm in March 2026, and to the GSMA in May.

14 часов назад @ thehackernews.com
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories.

That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded Firefox tarball came from Mozilla and was not tampered with.

Most Firefox and Thunderbird users need to do nothing.

Anyone installing Firefox from Mozilla's RPM packages may hit a failed update and have to swap the key manually.

It is a subkey revocation, signed by the primary key 14F26682D0916CDD81E37B6D61B7B526D98F0353, which stays in place.

14 часов назад @ thehackernews.com
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives.

They also reported a SynthID watermark, the invisible marker Google embeds in images its AI tools create or edit.

The July 31 joint alert says North Korean IT workers seek contracts with the intent of remitting their salaries to parent North Korean agencies.

Silent Push has separately tracked Astrill as a fixture of North Korean operations.

The report presents the Gemini-processing metadata and the SynthID watermark as separate findings but does not explain how the watermark itself was detected.

14 часов назад @ thehackernews.com
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine.

Security researchers Alejandro Hernando and Borja Martinez described the technique in "Plug And Pwn: Weaponizing Windows PnP Auto-Install," research prepared for DEF CON 34.

According to the researchers, the physical chain starts by emulating a Sierra Wireless device so Windows installs SwiService.exe, a SYSTEM service exposing a SetDNS primitive.

Their disclosed demonstration used a fully updated Windows 11 system, so the result should not be generalized to an untested W…

15 часов назад @ thehackernews.com
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction.

The attack targets coding tools that connect to outside servers over the Model Context Protocol (MCP), the open standard that lets AI assistants call external tools.

A malicious MCP server can put one fragment in a tool description and another in a tool result; some setups also support server-initiated sampling.

The same model can refuse in one coding client and exfiltrate in another, depending on the safety controls around it.

OpenAI's current guidance likewise warns that unsafe MCP server…

16 часов назад @ thehackernews.com
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.

"Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations," CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera, said.

Attacks deploying the ransomware have leveraged security flaws in internet-facing Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to obtain initial access, and then deploy the Gunra ransomware as part of a double extortion model tha…

17 часов назад @ thehackernews.com
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

The route ran through a private APN, or access point name: a dedicated cellular data network managed by the distribution system operator.

The WAGO controller reachable through the APN still had default admin credentials, while the private APN allowed client-to-client traffic.

CERT's first recommendation is to audit the private APN configuration and switch on client isolation.

CERT says its surveys found that Polish organizations running private APNs commonly let any device on the network reach any other.

A July 30 FBI and EPA advisory on attacks against internet-facing water-sector PLCs lists a private APN among the isolated architectures operators should consider for reaching OT equipment …

19 часов назад @ thehackernews.com
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads.

A JavaScript file named "w2.js," the payload performs the following actions -Contacts the C2 server ("ia-cdn[.

The execution is aborted if the C2 server returns a "skip" or "done" status.

The generated credentials are then leveraged to create a malicious administrator user, and the results of the attack are then exfiltrated back to the C2 server.

The C2 server used in the campaign is assessed to be related to two other software supply chain attacks involving Advanced Respo…

20 часов назад @ thehackernews.com
threatpost threatpost
последний пост None
DarkReading
последний пост None
WeLiveSecurity
последний пост 1 day, 17 hours назад
Are AI tutors safe for your kids?
Are AI tutors safe for your kids? Are AI tutors safe for your kids?

The AI tutor market is growing fastThe market for AI tutoring tools is booming.

Today, you can find various types of AI tutor tools to buy and use.

This happens when AI tools are tricked into ignoring their safety guardrails and display untrusted content.

If you’re keen to get your kids in front of an AI tool to help with private tutoring, first understand the difference between a simple co-pilot and a dedicated ITS.

So if you’re keen to try AI tutors, be sure to stay updated on what’s available out there.

1 day, 17 hours назад @ welivesecurity.com
This month in security with Tony Anscombe – July 2026 edition
This month in security with Tony Anscombe – July 2026 edition This month in security with Tony Anscombe – July 2026 edition

Researchers at Sysdig have documented what they assess to be the first case of an end-to-end ransomware operation executed by an agentic threat actor.

What can organizations do to stop phantom squatting from harming their brands, and what other lessons do these incidents hold for defenders?

Watch Tony's video to find out and be sure to check out the June 2026 edition of his monthly security news roundup for more insights.

Before you go, learn about the first AI-powered ransomware, named PromptLock and discovered by ESET researchers last year.

To learn more about cutting-edge AI defense layers, read the AI at ESET white paper.

1 week, 4 days назад @ welivesecurity.com
Beyond the screenshot: Why you should verify what you see
Beyond the screenshot: Why you should verify what you see Beyond the screenshot: Why you should verify what you see

The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuineSomeone sends you a screenshot showing that a payment has gone through.

Why screenshot aren’t proof on their ownA screenshot is ultimately just an image of what appeared on a screen.

Reassured, you send the item off, only to find out the screenshot was a fake and you’re not getting your money.

You receive a password reset code, then get a text message (maybe impersonating a friend) asking you to screenshot and send it.

This screenshot is fake (source: Reddit)Challenges for businessesFrom a business perspective, internal and customer-facing teams are often provided with sc…

1 week, 5 days назад @ welivesecurity.com
Forgotten UEFI shims undermining Secure Boot
Forgotten UEFI shims undermining Secure Boot Forgotten UEFI shims undermining Secure Boot

UEFI shim bootloader and UEFI Secure BootTo understand the impact that such vulnerable shims can have on UEFI Secure Boot-protected systems, we need to understand how UEFI Secure Boot works, and how signed UEFI shim bootloaders extend the Secure Boot trust chain.

In this section we’ll look at UEFI Secure Boot basics, how UEFI shims extend the UEFI Secure Boot trust chain, and two shim-related features: Machine Owner Key (MOK) and Secure Boot Advanced Targeting (SBAT).

For anyone already familiar with the theory, we recommend jumping directly to the section Bypassing UEFI Secure Boot using old shims.

UEFI shim bootloader and Secure BootWith Linux distributions supporting UEFI Secure Boot, th…

4 weeks назад @ welivesecurity.com
ESET Threat Report H1 2026
ESET Threat Report H1 2026 ESET Threat Report H1 2026

A view of the H1 2026 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts.

The first half of 2026 shows how attackers continue to improve the efficiency and scalability of their operations.

In H1 2026, ESET analyzed nearly 900,000 AI skills – small functional components used by AI agents – and identified tens of thousands of suspicious and thousands of outright malicious instances.

ESET detections of this vector more than doubled between H2 2025 and H1 2026, indicating sustained activity and adaptation.

ESET Research has documented over 100 EDR killers used in the wild, with new variants appearing regularly.

1 month назад @ welivesecurity.com
Cyber readiness for SMBs: Getting the basics right
Cyber readiness for SMBs: Getting the basics right Cyber readiness for SMBs: Getting the basics right

Organizations are right to pay attention, especially because malicious use of AI makes old gaps a more urgent test of an organization’s cyber readiness.

AI and the basics“AI-powered malware” is cited as the top concern of global SMBs for the year ahead, according to the ESET SMB Cyber Readiness Index 2026.

Lack of security monitoring (22%): You might have plenty of security tools, but do you have a single, centralized place to collect, correlate and flag alerts?

Malicious email detection trend in 2025 (source: ESET Threat Report H2 2025)Tried-and-tested solutions to age-old threatsThis isn’t to say that SMBs should ignore AI-enabled threats.

True cyber readiness means being able to prevent,…

1 month, 1 week назад @ welivesecurity.com
This month in security with Tony Anscombe – June 2026 edition
This month in security with Tony Anscombe – June 2026 edition This month in security with Tony Anscombe – June 2026 edition

It's that time of month when ESET Chief Security Evangelist Tony Anscombe looks back at some of the top cybersecurity stories that made the news over the past 30 or so days and considers what they may mean for your own cyber-defenses.

What lessons does the new CISA policy hold for organizations outside the agency's direct remit?

What else is there to know about threats facing ATGs or, indeed, many other critical infrastructure systems?

How can you stay safe from imposter fraud, and could the social media bans for children work?

Learn more from Tony's video and be sure to check out the May 2026 edition of Tony's monthly security news roundup for more insights.

1 month, 1 week назад @ welivesecurity.com
Inside the inbox: Why cybercriminals want to break into your email account
Inside the inbox: Why cybercriminals want to break into your email account Inside the inbox: Why cybercriminals want to break into your email account

With access to your email account, they can reset your passwords across multiple other accounts – perhaps intercepting one-time passcodes sent by your bank, social media, cloud storage or other online provider.

That could lay the groundwork for a convincing phishing email designed to impersonate a trusted organization you interact with.

A phishing attack on your corporate email account is often the first stage in a bigger data breach, extortion/ransomware or espionage attack.

They’re also using more sophisticated tools to improve the success rates of email phishing campaigns.

In this instance the scammers reportedly hijacked the email account of a high-level executive, before impersonating …

1 month, 1 week назад @ welivesecurity.com
SMB cyber readiness: the road to resilience starts here
SMB cyber readiness: the road to resilience starts here SMB cyber readiness: the road to resilience starts here

For these businesses, cyber resilience should be the direction of travel – that is, the ability to continue operating and recover even during a serious incident.

Cyber readiness is about putting in place the processes and controls to prevent, detect and respond to threats.

So, should confidence in cyber resilience posture be so high, especially if organizations are still getting hit multiple times?

The truth is that there’s no end state for cyber readiness or resilience.

If it’s serious about improving the cyber readiness of small businesses, the vendor community should step up.

1 month, 2 weeks назад @ welivesecurity.com
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

Key points of this blogpost: Throughout 2025, Gamaredon exclusively targeted governmental and military institutions in Ukraine.

Continued data exfiltration and a new allianceThroughout 2025, Gamaredon stayed highly active and remained focused solely on Ukraine.

Notably, we uncovered that in early 2025, Gamaredon collaborated with Turla, another Russia-aligned threat actor also linked to the FSB; we documented our findings in our blogpost Gamaredon X Turla collab.

Figure 1 shows a chart of unique samples of HTA downloaders delivered per month in Gamaredon spearphishing campaigns.

Compared to 2024, we also saw a shift in how Gamaredon used these dead drops.

1 month, 2 weeks назад @ welivesecurity.com
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
ESET takes part in Operation Endgame to disrupt Amadey and Stealc ESET takes part in Operation Endgame to disrupt Amadey and Stealc

Key points of this blogpost: ESET took part in the coordinated, global Operation Endgame to disrupt Amadey and Stealc.

Our automated systems have been dissecting Amadey and Stealc samples and identifying the fields most relevant for large-scale tracking.

The largest Amadey botnet clusterOne cluster stands out as the largest, and it contributed nearly 34% of all processed Amadey samples.

Stealc affiliate clustering based on ESET telemetryConclusionFor global disruption operations such as Operation Endgame against Amadey and Stealc, long-term automated tracking of malware is necessary.

2026‑04‑09 Stealc C&C server.

1 month, 2 weeks назад @ welivesecurity.com
Killing me gently: Inside Gentlemen’s EDR killer framework
Killing me gently: Inside Gentlemen’s EDR killer framework Killing me gently: Inside Gentlemen’s EDR killer framework

The group distinguishes itself through a mature, operator-maintained set of endpoint detection and response (EDR) killers, i.e., tools for disrupting security software.

In this blogpost, we share our findings on Gentlemen’s suite of EDR killers gained through extensive research and corroborated by the recent leak.

Third‑party EDR killers (HexKiller, ThrottleBlood, and HavocKiller) are operationally integrated.

Rather than relying on affiliates to source their own EDR killers, Gentlemen operators actively develop and maintain a portfolio of EDR killers for affiliates.

It allows the Gentlemen operators to integrate abused drivers into their toolset very soon after an EDR killer PoC is disclos…

1 month, 3 weeks назад @ welivesecurity.com
Protecting legacy OT systems against modern cyberthreats
Protecting legacy OT systems against modern cyberthreats Protecting legacy OT systems against modern cyberthreats

Of course, connecting production systems to enterprise networks delivers tangible benefits, but the security implications – that systems once safe were suddenly no longer so – arrived more quietly.

Start by mapping which systems in an environment are connected and have no security coverage, where IT and OT networks intersect, which segments are unmonitored, and which production systems have fallen outside any vendor support agreement.

Meanwhile, off-the-peg security tools often don’t efficiently meet the enterprise requirements in legacy OT systems that run on older hardware and outdated operating system versions.

The production systems running that version continue to operate for years, ac…

1 month, 3 weeks назад @ welivesecurity.com
FishMonger’s arsenal upgraded: SprySOCKS for Windows
FishMonger’s arsenal upgraded: SprySOCKS for Windows FishMonger’s arsenal upgraded: SprySOCKS for Windows

Key points of this blogpost: We discovered two previously undocumented Windows variants of FishMonger’s SprySOCKS backdoor.

Technical analysisIn this section, we provide a technical analysis of these new, Windows variants of FishMonger’s SprySOCKS backdoor.

Figure 3. klelam00007.bat setting up persistence for the SprySOCKS backdoor (newlines added for readability)Figure 4 depicts the execution chain of the SprySOCKS WIN_DRV variant.

It contained the SprySOCKS backdoor and the SprySOCKS loader.

6490B8E4AADE25A3EE2D A9A47F312DB2122470BC X1B5206BDC1 743DD.dat Win64/SprySOCKS.A Encrypted container of the encrypted WIN_DRV variant of SprySOCKS backdoor, encrypted SprySOCKS RawWNPF and SprySOCKS …

1 month, 3 weeks назад @ welivesecurity.com
EvilTokens: A phishing attack that doesn’t steal your password
EvilTokens: A phishing attack that doesn’t steal your password EvilTokens: A phishing attack that doesn’t steal your password

Instead, attackers get the victim to complete a legitimate authentication process – including two-factor authentication (2FA) – on a real Microsoft login page.

What makes EvilTokens dangerousThe OAuth device code flow was designed for devices that may be awkward to sign into directly, such as smart TVs or printers.

No document, invoice, email, or another platform should ask for a device code without a clear reason.

A real Microsoft page doesn’t automatically make a request safe.

Sometimes the attacker could ask them to enter a real code on a real page – but for the wrong device.

1 month, 3 weeks назад @ welivesecurity.com
Naked Security Naked Security
последний пост None
Help Net Security Help Net Security
последний пост 13 часов назад
Arctera enhances Unified Platform for evidence-driven compliance workflows
Arctera enhances Unified Platform for evidence-driven compliance workflows Arctera enhances Unified Platform for evidence-driven compliance workflows

Arctera has announced new capabilities to the Arctera Unified Platform enabling organizations to manage complex governance requirements by connecting signals, controls and response workflows across the compliance lifecycle.

These capabilities help organizations create a more complete and defensible record of compliance activity.

The latest enhancements to the Arctera Unified Platform help organizations bring greater continuity to compliance workflows, by connecting signals, controls and response workflows in a unified, evidence-driven process.

These enhancements to the Arctera Unified Platform strengthen the workflows that help organizations operate with greater consistency, accountability …

13 часов назад @ helpnetsecurity.com
Citrix expands Platform Flex with observability and secure developer services
Citrix expands Platform Flex with observability and secure developer services Citrix expands Platform Flex with observability and secure developer services

Citrix has announced new services for Citrix Platform Flex, extending its flexible credit model with additional options for delivering, monitoring and securing digital work environments.

The new services address these challenges by extending Citrix’s flexible, credit-based model Platform Flex offering to workspace observability, security analytics and developer workflows — building on the initial Citrix DaaS Flex offering launched in May.

Citrix SecurSpaces Flex accelerates developer productivityCitrix SecurSpaces Flex extends Citrix Platform Flex’s persona-based computing model to support a new additional persona for developers.

Citrix SecurSpaces Flex gives enterprises a secure, hosted wa…

13 часов назад @ helpnetsecurity.com
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G

Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some cases execute code.

It lets a card send instructions to a device’s modem instead of only answering the modem’s requests.

To determine how much access this provides, the researchers developed a toolkit called CATana and tested it against 18 smartphones and eight cellular IoT devices.

“Other researchers, cybersecurity experts, and leaked intelligence documents have shown some of the dangers of hostile SIMs before us.

“The attacks we found only scratch the s…

14 часов назад @ helpnetsecurity.com
Ransomware gangs don’t need control system access to disrupt industrial production
Ransomware gangs don’t need control system access to disrupt industrial production Ransomware gangs don’t need control system access to disrupt industrial production

Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos.

The company identified 1,140 ransomware incidents involving industrial organizations in the second quarter of 2026, up 12% from 1,020 in Q1.

(Source: Dragos)“Ransomware remained the most persistent and disruptive cyber threat to industrial organizations,” Dragos researchers Lexie Mooney and Abdulrahman H. Alamri wrote.

Qilin logged the largest number of industrial victim claims in Q2, with 140, down from 198 in Q1.

Some attackers also set up credential-harvesting domains designed t…

16 часов назад @ helpnetsecurity.com
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5 Locking your ssh-agent exposed local-only keys until OpenSSH 10.5

The agent holds your decrypted private keys so you are not retyping a passphrase every few minutes, and agent forwarding lets a program on a remote host borrow those keys to sign a login.

Elsewhere in the release, “ssh -Z user@host” prints the keys the client will try for public key authentication, in order.

ssh now prefers FIDO keys that need no touch and leaves keys that require a PIN or biometric verification for last.

ssh-keygen can set or clear the touch-required and verify-required flags on FIDO private keys while resetting a passphrase.

Portable OpenSSH now requires ECC support, including the NISTP521 curve, from whatever libcrypto it is built against.

17 часов назад @ helpnetsecurity.com
GPT-5.6-Cyber refuses security researchers’ requests far less often
GPT-5.6-Cyber refuses security researchers’ requests far less often GPT-5.6-Cyber refuses security researchers’ requests far less often

GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work.

“The GPT‑5.6‑Cyber model is trained to improve performance on certain cybersecurity workflows involving exploit development and advanced security research,“ the company said.

OpenAI built an internal benchmark to track how often each model agrees to handle requests involving exploit chains, authentication bypass, and privilege escalation.

“Under our Preparedness Framework, the GPT‑5.6 Sol model was assessed as High for cybersecurity capability and below the Critical threshold.

Before launching GPT‑5.6‑Cyber, we also e…

19 часов назад @ helpnetsecurity.com
Who will be the Stanislav Petrov in your organization?
Who will be the Stanislav Petrov in your organization? Who will be the Stanislav Petrov in your organization?

The officer on duty, Stanislav Petrov, did something computers still struggle to do.

That is why the recent incidents involving OpenAI and Hugging Face, Anthropic, Meta, and the UK’s AI Security Institute deserve the attention of CISOs and boards.

Many cyber insurance policies were written before autonomous AI systems presented this type of risk so do not assume your policy will cover the consequences if your own AI compromises another organization.

Boards and CISOs should absolutely prepare for more capable and autonomous AI.

Who will be the Stanislav Petrov in your organization?

20 часов назад @ helpnetsecurity.com
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
An AI tool found 84 flaws in 5G network software and 23 of them still have no fix An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before.

Inside a phone network, one component decides where a subscriber’s data should go and tells another component to move it.

What makes this more than a lab curiosity is where phone networks now live.

“Three confirmed cases are a small sample, and we have not audited the commercial cores directly, so we would call this supporting evidence rather than a conclusion.

Direct analysis of additional commercial cores would be needed to establish how far the inheritance extends.”Download: The ulti…

20 часов назад @ helpnetsecurity.com
Previously unseen entry vector used to breach Polish energy plant
Previously unseen entry vector used to breach Polish energy plant Previously unseen entry vector used to breach Polish energy plant

CERT Polska was aware of similar events elsewhere and investigated the possibility of a cyberattack anyway.

Marcin Dudek, head of CERT Polska, revealed details of the attack at DEF CON 34 in Las Vegas.

To understand how the attacker reached that network, CERT Polska revisited the wind farm attacks from the same day.

CERT Polska considers reconnaissance of the controllers in preparation for the disruptive actions that followed the most likely explanation.

“Its execution was made possible, among other factors, by a misconfiguration that allowed connections to be established between arbitrary devices within the private APN network,” they added.

21 час назад @ helpnetsecurity.com
Your security vendor gets the frontier cyber model, you get the findings
Your security vendor gets the frontier cyber model, you get the findings Your security vendor gets the frontier cyber model, you get the findings

Selected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure.

Approved partners choose between Daybreak Blue and Daybreak Red, reached through Daybreak Access, depending on their needs and the work involved.

Nine are security and services firms: Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group and SpecterOps.

Partners already know their customers’ systems and how their security teams operate, which is the argument for routing the models through them rather than shipping them to every company that wants one.

Partners and their customers define the boundaries of each engagement, review findings, and appl…

21 час назад @ helpnetsecurity.com
Cybersecurity jobs available right now: August 11, 2026
Cybersecurity jobs available right now: August 11, 2026 Cybersecurity jobs available right now: August 11, 2026

You will collaborate with engineering, security, and DevOps teams to implement enterprise security controls, conduct security reviews and threat modeling, and ensure compliance with security standards.

Get weekly updates on new cybersecurity job openings.

Must read:How to succeed at cybersecurity job interviewsManager, Threat RemediationPfizer | USA | Hybrid – View job detailsAs a Manager, Threat Remediation, you will lead the organization’s threat remediation program by prioritizing and coordinating the resolution of cybersecurity threats and exposures.

Security Analyst – Tier 3Nebius | Israel | On-site – View job detailsAs a Security Analyst – Tier 3, you will lead complex investigations …

22 часа назад @ helpnetsecurity.com
Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Cyberattack on Steam hardware shipper leaks names, addresses, and order data Cyberattack on Steam hardware shipper leaks names, addresses, and order data

Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner.

“Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the company that ships Steam hardware to customers in Europe.

The exposed information includes names, street addresses, postal codes, cities, countries, phone numbers, and the email addresses tied to Steam accounts.

CEVA does not have access to your payment information, passwords, Steam Guard codes or other information,” Valve noted.

Valve is warning customers to expect fake messages, over email, SMS, or phone, that reference their hardware order and pretend to come from Steam, Valve, o…

1 day, 11 hours назад @ helpnetsecurity.com
Metabase zero-day exploited to access Framework customer data
Metabase zero-day exploited to access Framework customer data Metabase zero-day exploited to access Framework customer data

Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service.

In the email it sent to affected customers, Framework said it was notified of the breach by Metabase, who confirmed that the attackers gained access to Framework’s cloud instance.

Framework has rotated credentials for the databases it connected to its Metabase instance and said that it’s yet to find evidence of a wider compromise.

Affected customers should be on the lookout for phishing emails impersonating the company.

In Tally’s case, the data includes email addresse…

1 day, 12 hours назад @ helpnetsecurity.com
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users

Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO).

Once the rollout lands, WHfB and macOS PSSO will satisfy these MFA requirements without registering an additional passkey.

Users who rely on WHfB or macOS PSSO as their only registered MFA method will also be considered MFA-capable.

Entra ID will stop prompting password users to register another MFA method when WHfB or macOS PSSO is already registered as their MFA credential.

Microsoft recommends that users register a portable MFA method for these situations, such as a synced passkey or a passkey stored in Microsoft Authenticator.

1 day, 13 hours назад @ helpnetsecurity.com
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs).

“Hotfix 2 is required, even if you already applied the earlier hotfix.

Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers,” the company said, and shared additional indicators of compromise observed in attacks.

A second hotfix to “expand protections”Earlier this month, N‑able released N-central version 2026.3.1.7 (i.e., 2026.3 Hotfix 1), which patches an authentication bypass vulnerability (CVE-2026-18577) the company detected being exploited by att…

1 day, 14 hours назад @ helpnetsecurity.com
IT Security Guru IT Security Guru
последний пост None
SecurityTrails
последний пост None
Блоги 👨‍💻
Бизнес без опасности Бизнес без опасности
последний пост None
Жизнь 80 на 20 Жизнь 80 на 20
последний пост None
ZLONOV ZLONOV
последний пост None
Блог Артема Агеева Блог Артема Агеева
последний пост None
Киберпиздец Киберпиздец
последний пост None
Schneier on Security Schneier on Security
последний пост 10 часов назад
AI Genie in the Wild
AI Genie in the Wild AI Genie in the Wild

AI Genie in the WildWhen I give talks about AI genies, I use this sort of example as a hypothetical.

Someone named Andrew tasked OpenClaw to book gym classes for him.

Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible.

Andrew, who was sitting fourth on a waitlist for a class later that week, asked if it was possible to move him to the top of the list.

The agent came back and told Andrew that it had kicked another gym-goer off the list as part of the testing of its capabilities.

10 часов назад @ schneier.com
AI for Military Support
AI for Military Support AI for Military Support

Interesting empirical research: “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI.”Abstract: How is AI transforming decision-making in modern conflict?

This study provides a unique empirical window into that question by deploying a high-fidelity replica of an AI decision-support system (DSS) used in military targeting.

Contrary to widespread fears of automation bias, we find strong evidence of algorithmic aversion, especially in scenarios involving high collateral damage.

Yet we also show that integrating “explainable AI” features reduces algorithmic aversion and promotes more thoughtful evaluations of algorithmic recommendations.

These findings challenge prev…

15 часов назад @ schneier.com
Python Now Has a Post-Quantum Encryption Library
Python Now Has a Post-Quantum Encryption Library Python Now Has a Post-Quantum Encryption Library

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

1 day, 15 hours назад @ schneier.com
Friday Squid Blogging: Arctic Bobtail Squid Video
Friday Squid Blogging: Arctic Bobtail Squid Video Friday Squid Blogging: Arctic Bobtail Squid Video

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

4 days, 5 hours назад @ schneier.com
ICE Is Buying Access to Credit Card Records
ICE Is Buying Access to Credit Card Records ICE Is Buying Access to Credit Card Records

About Bruce SchneierI am a public-interest technologist, working at the intersection of security, technology, and people.

I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998.

I'm a fellow and lecturer at Harvard's Kennedy School, a board member of EFF, and the Chief of Security Architecture at Inrupt, Inc.

This personal website expresses the opinions of none of those organizations.

Contact Info

4 days, 16 hours назад @ schneier.com
Adversarial Clothing Designed to Fool Facial Recognition Systems
Adversarial Clothing Designed to Fool Facial Recognition Systems Adversarial Clothing Designed to Fool Facial Recognition Systems

There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems.

It’s a cool idea, but I worry that it’s mostly security theater:“Our patterns play with that chaos, confuse algorithms and make it way harder to pin you down,” he said.

Bell, however, said “none of these products are tried and tested, and a lot of these surveillance technologies can deal with a little resistance … [but] even if the designs don’t necessarily work perfectly, fashion is also a visible sign of resistance.

“This is consumers collectively coming together to make a visible statement.”

5 days, 15 hours назад @ schneier.com
Vulnerabilities in Car Anti-Theft Device
Vulnerabilities in Car Anti-Theft Device Vulnerabilities in Car Anti-Theft Device

This is disturbing:…a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.

6 days, 16 hours назад @ schneier.com
Iran Cyberattacks Against Minnesota Water Systems
Iran Cyberattacks Against Minnesota Water Systems Iran Cyberattacks Against Minnesota Water Systems

Iran Cyberattacks Against Minnesota Water SystemsAttribution is preliminary, and so far it seems no real damage.

And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that Minnesota…I guess…hacked itself.

“I would blame it on Minnesota and the governor, the corrupt governor of Minnesota.

They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky.

Iran’s got bigger problems than worrying about Minnesota.”No word on whether he believes the other six states have hacked themselves as well.

1 week назад @ schneier.com
Some Claude Chats Are Searchable on Google
Some Claude Chats Are Searchable on Google Some Claude Chats Are Searchable on Google

Some Claude Chats Are Searchable on GoogleAnd it’s personal information (alternate link):The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data.

Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples’ addresses.

What seems to be the issue is a user setting about data sharing.

“These shareable links are not guessable or discoverable unless people choose to share them themselves.

When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archive…

1 week назад @ schneier.com
More on the OpenAI Agent’s Attack on Hugging Face
More on the OpenAI Agent’s Attack on Hugging Face More on the OpenAI Agent’s Attack on Hugging Face

From the summary:The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities.

OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or operation of that evaluation environment.

The campaign, as we were able to reconstruct it, had two stages:Stage 1: reaching a launchpad by chaining through other parties’ infrastructure.

From that external launchpad, the agent abused our dataset-processing pipeline via two injection vectors, both targeting the same config-driven data loader within our product…

1 week, 1 day назад @ schneier.com
The OpenAI Hack Shows the Genie Is Out of the Bottle
The OpenAI Hack Shows the Genie Is Out of the Bottle The OpenAI Hack Shows the Genie Is Out of the Bottle

OpenAI was running security tests on two of its models: GPT-5.6 Sol and an unreleased model that is almost certainly GPT-6.

Modern AI models exhibit genie behavior: They can do what you ask in ways that you don’t expect or want.

There’s nothing magic about OpenAI’s frontier models; lots of models could have done the same thing.

Even if the U.S. frontier AI companies had some technical advantage, it’s now only a few months’ worth.

Even worse, U.S. companies limit access to their most sophisticated models, fearing being banned by the government if they do not do so.

1 week, 1 day назад @ schneier.com
Friday Squid Blogging: Squid Helps Discover New Marine Species
Friday Squid Blogging: Squid Helps Discover New Marine Species Friday Squid Blogging: Squid Helps Discover New Marine Species

We could see cells interacting with each other, exchanging material and building skeletons.

And we could do that live on the ship, when usually it takes a couple of weeks of staining and mounting to see anything,” Osborn said.

The expedition discovered thirty-one new marine species in two weeks.

The article doesn’t say if any of them were new species of squid.

As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

1 week, 4 days назад @ schneier.com
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection
Anthropic’s Opus 5 Is Better at Resisting Prompt Injection Anthropic’s Opus 5 Is Better at Resisting Prompt Injection

On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt.

It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated.

The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate.

The other GPT 5.6 variants are less robust, at 30.4% (Terra) and 43.9% (Luna).

A single attempt against GPT 5.6 Sol succeeded 3.1% of the time, higher than the 2.0% an attacker achieved against Opus 5 after fifteen attempts.

1 week, 4 days назад @ schneier.com
Facial Recognition at Madison Square Garden
Facial Recognition at Madison Square Garden Facial Recognition at Madison Square Garden

Facial Recognition at Madison Square GardenLast month, the story broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition.

Turns out that the system was shut off for Taylor Swift’s wedding.

Evan Greer—one of the people that MSG alerts on—comments:Ironically, Swift herself has reportedly used facial recognition at her own concerts to identify stalkers.

Whatever privacy measures Swift had in place for the wedding seems to have worked.

Posted on July 31, 2026 at 7:08 AM • 0 Comments

1 week, 4 days назад @ schneier.com
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials
American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials

He’s being prosecuted for giving border officials a code that wiped his phone:The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices.

Tunick’s attorneys confirmed GrapheneOS was running on his phone.

The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user’s unlock passcode.

Tunick’s case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter.

1 week, 5 days назад @ schneier.com
Krebs On Security
последний пост 4 часа назад
Microsoft Plugs Nearly 400 Security Holes
Microsoft Plugs Nearly 400 Security Holes Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month, but it is double June’s then-record batch of nearly 200 fixes.

The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.

By all accounts, AI is quite good at finding security holes in software.

“Don’…

4 часа назад @ krebsonsecurity.com
Canadian Man Pleads Guilty in Snowflake Extortions
Canadian Man Pleads Guilty in Snowflake Extortions Canadian Man Pleads Guilty in Snowflake Extortions

Snowflake responded to the data thefts by increasing password complexity requirements and enforcing multi-factor authentication.

A little more than a month later, Canadian authorities arrested Moucka on a provisional warrant from the United States.

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt,” reads a statement from the Justice Department.

Moucka pleaded guilty to four criminal counts, including computer fraud, wire fraud, aggravated identity theft, and conspiracy.

Ultimately, it will be up the federal judge how much time Moucka actually serves for his extensive cybercriminal rap sheet.

5 days, 9 hours назад @ krebsonsecurity.com
Read This Before You Buy That TV Streaming Stick
Read This Before You Buy That TV Streaming Stick Read This Before You Buy That TV Streaming Stick

Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.

AD FRAUDBitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time.

When the TV is off, it switches back to waiting for ad fraud jobs.

In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed.

In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in …

1 week, 5 days назад @ krebsonsecurity.com
LG to Ban Residential Proxies from Smart TV Apps
LG to Ban Residential Proxies from Smart TV Apps LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node.

On July 2, we featured research by the security firm Spur that examined the prevalence of residential proxy software development kits (SDKs) in smart TV apps.

“A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said.

In the case of LG and Samsung smart TVs, Spur found residential proxy SDKs bundled with everything from simple games like Pac-Man to screensavers and f…

3 weeks назад @ krebsonsecurity.com
Microsoft Patches a Record 570 Security Flaws
Microsoft Patches a Record 570 Security Flaws Microsoft Patches a Record 570 Security Flaws

Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Microsoft also addressed three zero-day flaws that are already being exploited in the wild.

As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws.

Backing up your Windows system and/or data is always a good idea before applying operating system updates.

It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today.

4 weeks назад @ krebsonsecurity.com
Lessons Learned from CISA’s Recent GitHub Leak
Lessons Learned from CISA’s Recent GitHub Leak Lessons Learned from CISA’s Recent GitHub Leak

Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb.

CISA also admitted it can do better when it comes to responding to security incident notifications from external parties.

Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures.

Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets.

“Continuous monitoring of public GitHub surfaced it.

4 weeks, 1 day назад @ krebsonsecurity.com
Felons, Fraudsters Flog Offensive Cybersecurity Startup
Felons, Fraudsters Flog Offensive Cybersecurity Startup Felons, Fraudsters Flog Offensive Cybersecurity Startup

IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.

“Our business model is this,” reads a pinned post on top of the IRIS C2 account on X.

The website claims IRIS C2 is in the business of acquiring “zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms.

When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.

In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living.

1 month назад @ krebsonsecurity.com
FBI Seizes NetNut Proxy Platform, Popa Botnet
FBI Seizes NetNut Proxy Platform, Popa Botnet FBI Seizes NetNut Proxy Platform, Popa Botnet

Benjamin Brundage is founder of the proxy tracking service Synthient, one of the companies that published evidence last month linking the Popa botnet to NetNut and Alarum Technologies.

Brundage said the domain seizures appear to have disrupted both the Popa botnet and the NetNut proxy network that rides on top of it.

“Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet,” the GTIG report concludes.

What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller.

More than a quarter of the apps made for Samsung’s Tizen o…

1 month, 1 week назад @ krebsonsecurity.com
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Scattered Spider Hackers Plead Guilty on Day 1 of Trial Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022.

The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted alo…

1 month, 2 weeks назад @ krebsonsecurity.com
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].

Qurium said that immediately after that disruption, several dozen new domains were registered to serve as controllers for the Popa botnet, but that one of those control domains was not new: ninjatech[.]io.

Jérôme Meyer, a security researcher at Nokia Deepfield, said the total population of devices participating in the Popa botnet may be far higher than Lumen’s estimates.

“Over 90% of our pharmaceutical and food & beverage customers have queried residential proxy indicators.

1 month, 3 weeks назад @ krebsonsecurity.com
Who Runs the Ransomware Group ‘The Gentlemen?’
Who Runs the Ransomware Group ‘The Gentlemen?’ Who Runs the Ransomware Group ‘The Gentlemen?’

This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Experts at the security firm Check Point Software have been closely covering exploits of The Gentlemen, a so-called “ransomware-as-a-service” (RaaS) offering that pays affiliates handsomely to help spread the group’s malware.

According to Check Point, the group targets Internet-facing devices (VPNs, firewalls) as their entry point, and once inside moves quickly to encrypt entire networks within hours.

Check Point says the administrator and primary operator of the ransomware group uses the nickname Zeta88 on the Russian-language cybercrime forums, and that this individual was pr…

2 months назад @ krebsonsecurity.com
A Record-Breaking Patch Tuesday for June 2026
A Record-Breaking Patch Tuesday for June 2026 A Record-Breaking Patch Tuesday for June 2026

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle.

“Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said.

Microsoft received heavily blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher.

While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barne…

2 months назад @ krebsonsecurity.com
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts

On May 31, word began to spread on several Telegram instant message channels that Meta’s AI bot would happily add an email address to an existing account as part of the bot’s standard password reset flow.

Meta has not responded to requests for comment on the video’s claims, but the company reportedly did acknowledge the dormant Instagram account for the Obama White House was briefly compromised.

Meta’s solution was to deploy a conversational AI layer to handle common recovery workflows: relinking a lost email address, triggering a password reset, verifying account ownership.

Just like human customer support employees can be social engineered into providing unauthorized access to someone’s a…

2 months, 1 week назад @ krebsonsecurity.com
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

But as KrebsOnSecurity observed in September 2025, those sanctions failed to target Stark’s remaining connection to the Internet — an Internet service provider based in the Netherlands called MIRhosting.

MIRhosting is operated by Andrey Nesterenko, a 39-year-old Russian native who runs the business out of the Netherlands.

And as our September 2025 report showed, WorkTitans was controlled by Nesterenko and a 57-year-old from Amsterdam named Youssef Zinad.

On top of that, WorkTitans was getting connectivity to the larger Internet solely through MIRhosting, where Zinad had worked previously.

“The transition to the.hosting was not intended to evade sanctions,” Nesterenko wrote.

2 months, 2 weeks назад @ krebsonsecurity.com
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers Demand Answers as CISA Tries to Contain Data Leak Lawmakers Demand Answers as CISA Tries to Contain Data Leak

The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked credentials.

Experts who reviewed the exposed secrets said the commit logs for the code repository showed the CISA contractor disabled GitHub’s built-in protection against publishing sensitive credentials in public repos.

CISA acknowledged the leak but has not responded to questions about the duration of the data exposure.

TruffleHog does this by monitoring a live feed that GitHub publishes which includes a record of all commits and changes to public code repositories.

In practical terms, it is likely that cybercrime groups or foreign adversaries also noticed the publication of these CISA secrets, …

2 months, 3 weeks назад @ krebsonsecurity.com
Graham Cluley Graham Cluley
последний пост 4 days, 10 hours назад
Beware cut-price AI services that read your every word
Beware cut-price AI services that read your every word

f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.

4 days, 10 hours назад @ fortra.com
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits

According to a report in the Financial Times, Apple has found itself facing a massive influx of submissions from amateur bug hunters who have used AI to generate plausible-sounding but completely hallucinated bug reports.

Unlike traditional spam, AI-generated bug reports include code which may be syntactically correct, references to genuine API calls, and plausible-sounding technical explanations of what is occurring.

But the hallucinated bug report may only have taken a few seconds for an amateur to generate and submit.

Previously, without the assistance of AI, Bynario had filed only 13 bug reports across 2025 and early 2026.

Apple is not the only company trying to deal with a deluge of au…

5 days, 16 hours назад @ bitdefender.com
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency
Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency

How a fake police officer nearly stole Graham's cryptocurrency with Graham Cluley and special guest Danny Palmer.

I said, without being big-headed, it is possible he knows me, but I don't know him.

I don't think my hotels tend to ask me to install something on my computer when I get there.

We had internet, but it was really, really restricted.

And it's really, really good.

6 days, 3 hours назад @ grahamcluley.com
Fake IRS letters target cryptocurrency holders
Fake IRS letters target cryptocurrency holders Fake IRS letters target cryptocurrency holders

As Coinbase's security team explains, the letters urge recipients to scan a QR code and enrol in a "Digital Asset Compliance Portal" before time runs out.

Bear in mind that the criminals could easily vary these details from letter to letter.

The scam site then asks victims to estimate how much value they have in their cryptocurrency wallets, with ranges up to "$100,000+".

Perhaps a reason why a scam like this can work is that the IRS has been tightening cryptocurrency holders' requirement to report details of their digital assets on their tax returns.

As a result, written communications between the IRS and holders of cryptocurrency have become more frequent.

1 week назад @ bitdefender.com
The $5 million threat: AI Is supercharging phishing attacks
The $5 million threat: AI Is supercharging phishing attacks

According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

1 week, 4 days назад @ fortra.com
North Korea’s elite hackers turned on their own government – and got caught
North Korea’s elite hackers turned on their own government – and got caught North Korea’s elite hackers turned on their own government – and got caught

For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme.

But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead.

The ringleaders of the group are said to be discharged veterans from a cyber operations unit under North Korea's Reconnaissance and Intelligence General Bureau.

In short, the hackers are accused of building a mini version of the same kind of money-laundering infrastructure North Korea depl…

1 week, 5 days назад @ bitdefender.com
Smashing Security podcast #478: This job interview could destroy your company
Smashing Security podcast #478: This job interview could destroy your company Smashing Security podcast #478: This job interview could destroy your company

Smashing Security, Episode 478: This Job Interview Could Destroy Your Company, with Graham Cluley and special guest Paul Ducklin.

And all the time you're going through this process, bad news, they really were recording video of you.

Obviously, you can understand that CAR want to know, does your car actually have one of these in all likelihood?

And give it to them and then they tell you whether they think you're at risk.

I don't know.

1 week, 6 days назад @ grahamcluley.com
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know
OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know OpenAI’s AI “goes rogue” and hacks Hugging Face: what you need to know

The AI models involved were OpenAI's GPT-5.6 Sol and a more capable, as-yet-unreleased model.

The intention of OpenAI's researchers was to get a clear picture of what the AI models were capable of achieving if not constrained.

American AI safety guardrails forced a US company to turn to a Chinese AI model for help.

Hugging Face's CEO Clément Delangue is quoted in OpenAI's blog post, calling on the AI industry to work more collaboratively.

It is clear that advanced AI models are remarkably capable of discovering and exploiting ways to attack real-world systems.

2 weeks, 5 days назад @ bitdefender.com
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

How 14 orders of Chicken McNuggets helped nail a suspected Russian hacker with Graham Cluley and special guest James Ball.

I had a vindaloo, Graham Cluley, and I don't think it ever touched capsicum.

Yeah, I think you're right.

If you use Suno music, people say, you know, you're killing music.

I don't know much about Shai Hulud.

2 weeks, 6 days назад @ grahamcluley.com
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine warns fake CAPTCHAs are being used to make you hack yourself Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Ukraine's computer emergency response team, CERT-UA, has warned that Russian hackers are using fake CAPTCHA checks to trick people into compromising their own PCs.

The Kremlin-backed Sandworm hacking group is reportedly leveraging fake CAPTCHA checks on compromised websites that persuade users to execute a PowerShell command on their computers - tricking them into running malicious code.

The latest attacks begin when a user visits a compromised webpage, where they're greeted by a fake CAPTCHA claiming they need to complete an extra step to prove that they are human.

Instead, the fake CAPTCHA instructs the user to copy and paste a PowerShell command into their Windows computer.

They are a pr…

3 weeks назад @ bitdefender.com
Google’s Gemini lets strangers send messages from your locked Android phone
Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini lets strangers send messages from your locked Android phone

Someone gets hold of your locked Android phone and, despite not knowing your security PIN, they can send messages via SMS or WhatsApp pretending to come from you.

It is clear that Google has patched Gemini lock screen issues before, but security researchers keep finding new ways through.

The latest vulnerability is different from the previous similar Gemini-based Android lock screen bypass bugs that have been plaguing the operating system since September 2025.

To do that:Open the Gemini app, tap your profile picture, go to Settings, and select "Gemini on lock screen."

Every new capability Gemini is given at the lock screen is also a new potential attack surface.

3 weeks, 4 days назад @ bitdefender.com
Anubis ransomware: what you need to know
Anubis ransomware: what you need to know

The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.

3 weeks, 5 days назад @ fortra.com
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers

That is a really, really busy street potentially.

I don't know what the difference is between a tuk-tuk and a rickshaw.

I don't know.

Yeah, it's got to be a Bluetooth transmitter from the battery, and within the battery there's an operating system or something that'll need updating.

It's really, really great.

3 weeks, 5 days назад @ grahamcluley.com
The ransomware negotiator who was working for the other side
The ransomware negotiator who was working for the other side The ransomware negotiator who was working for the other side

When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help.

Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf.

41-year-old Martino worked as a ransomware negotiator for DigitalMint, an incident response company based in Chicago.

The ransomware victim, a hospitality company, ultimately paid out nearly US $16.5 million.

The company has since changed the way its negotiators communicate with ransomware gangs, and is working with the Department of Homeland Security to establish a registry for the currently highly-unregulated world of ransomware negotiation.

4 weeks назад @ bitdefender.com
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk

Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role?

Security experts have uncovered a phishing campaign which impersonates over 30 well-known brands in fake job interviews designed to steal Google account passwords.

When victims click on "Continue with Google," a pop-up appears that looks like a legitimate Google authentication dialog.

In the past the FBI has warned the public about scammers using fake job ads to steal money and personal information from applicants.

Earlier this year, Hot for Security published a guide explaining how many fake recruiter scams work, and how to avoid them.

1 month назад @ bitdefender.com
Компании 🏢
Блог Касперского Блог Касперского
последний пост 15 часов назад
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского
Что известно про кражу криптовалюты через рекламу Adform | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: b151dd13b503d39649441ee258a9621fServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-11T15:00:20+03:00Config id: 298Faithfully yours, nginx.

15 часов назад @ kaspersky.ru
Слепые пятна детектирования: форматы файлов polyglot в рассылках и целевых атаках
Слепые пятна детектирования: форматы файлов polyglot в рассылках и целевых атаках

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 31e2a51c17a679bf608181d1cb4a73dfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-10T19:00:19+03:00Config id: 298Faithfully yours, nginx.

1 day, 12 hours назад @ kaspersky.ru
Опасные почтовые вложения: какие файлы нельзя открывать | Блог Касперского
Опасные почтовые вложения: какие файлы нельзя открывать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: ba837fe40a3ce1bc1da3dc3d5c38e164Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-07T14:00:17+03:00Config id: 296Faithfully yours, nginx.

4 days, 17 hours назад @ kaspersky.ru
Аудиослежка за клавиатурным набором | Блог Касперского
Аудиослежка за клавиатурным набором | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f03ed927ed78af1549df453edbc54069Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-06T17:00:43+03:00Config id: 295Faithfully yours, nginx.

5 days, 13 hours назад @ kaspersky.ru
Как сделать, чтобы вашу компанию не взломали автономные агенты
Как сделать, чтобы вашу компанию не взломали автономные агенты

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: f997d2a4543951b403d61a86f614b589Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-04T20:00:20+03:00Config id: 293Faithfully yours, nginx.

1 week назад @ kaspersky.ru
CrashStealer: новый инфостилер для macOS — как он работает и как защититься | Блог Касперского
CrashStealer: новый инфостилер для macOS — как он работает и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 64d189df4b1deb932c3c39da09770373Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-08-03T14:00:09+03:00Config id: 292Faithfully yours, nginx.

1 week, 1 day назад @ kaspersky.ru
Почему звонят в трубку и молчат | Блог Касперского
Почему звонят в трубку и молчат | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 87a765bcfffecb3be7b631186de73cdfServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-30T14:00:37+03:00Config id: 292Faithfully yours, nginx.

1 week, 5 days назад @ kaspersky.ru
ScreenConnect в кибератаках | Блог Касперского
ScreenConnect в кибератаках | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 69f66dfe76ff3f53d09e7e879aff2eabServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-29T19:00:33+03:00Config id: 291Faithfully yours, nginx.

1 week, 6 days назад @ kaspersky.ru
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского
ClickFix на macOS: как работает атака через «Терминал» и как защититься | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: e1896b8624f52547d7aa4a3bebd90c3cServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-27T16:00:28+03:00Config id: 291Faithfully yours, nginx.

2 weeks, 1 day назад @ kaspersky.ru
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского
Почему операторы чатов могут читать ваши сообщения до отправки | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 30ce39da164ccbcb4068b4e06c4c1e60Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-24T19:00:11+03:00Config id: 291Faithfully yours, nginx.

2 weeks, 4 days назад @ kaspersky.ru
Инциденты с атаками на ИИ-агентов в бизнесе | Блог Касперского
Инциденты с атаками на ИИ-агентов в бизнесе | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: abb2f672b0aebacf96a83f072ddf5be5Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-23T15:00:29+03:00Config id: 290Faithfully yours, nginx.

2 weeks, 5 days назад @ kaspersky.ru
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского
Как работает функция верификации номера телефона (Phone Number Verification) Google и нужно ли ее отключать | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 29288682927681f45f4ebe45b92c4f9dServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-22T15:00:12+03:00Config id: 290Faithfully yours, nginx.

2 weeks, 6 days назад @ kaspersky.ru
ConsentFix: новая вариация ClickFix
ConsentFix: новая вариация ClickFix

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 92f538b35cc9db0cd8268f0e9c690524Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-21T12:00:10+03:00Config id: 290Faithfully yours, nginx.

3 weeks назад @ kaspersky.ru
Как защитить свои данные после расставания | Блог Касперского
Как защитить свои данные после расставания | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 7c4859afeb6714d16332cd516cc382ddServer IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-20T13:00:34+03:00Config id: 290Faithfully yours, nginx.

3 weeks, 1 day назад @ kaspersky.ru
Кража почты через OAuth | Блог Касперского
Кража почты через OAuth | Блог Касперского

An error occurred.

Sorry, the page you are looking for is currently unavailable.

Please try again later.

If you are the system administrator of this resource then you should check the error log for details.

Request id: 89a6c1c61d71bc406a42bd2d91dc48b6Server IP: 185.54.220.248Client IP: 23.88.109.5Time: 2026-07-17T15:00:29+03:00Config id: 290Faithfully yours, nginx.

3 weeks, 4 days назад @ kaspersky.ru
Блог Group-IB
последний пост None
Cisco Security Blog Cisco Security Blog
последний пост 14 часов назад
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …
Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero … Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified (Class C) to FedRAMP Certified (Class D) and Zero …

The Power of FedRAMP HighWhile FedRAMP Certified Class C (Moderate) is the standard for many civilian agencies, FedRAMP Certified Class D (High) is designed for systems where a breach could have catastrophic effects.

Cisco Security Cloud for GovernmentCisco Security Cloud for Government is a unified authorization boundary that integrates various Cisco security services, ensuring that organizations can protect their users, devices, and applications regardless of where they reside.

The Cisco Security Cloud for Government ecosystem is designed to meet the rigorous security requirements of the public sector and highly regulated industries.

Cisco Security Cloud Control (SCC)Cisco Security Cloud …

14 часов назад @ blogs.cisco.com
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification
Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification

That’s why we are incredibly proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!

Reduced Vendor Risk & Increased Trust: FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

FedRAMP certification signals that Email Threat Defense has undergone extensive third-party assessment and meets stringent government security controls.

Beyond the governance and compliance benefits, Email Threat Defense continues to deliver advanced protection capabilities that align directly with real-world email threat risks.

Email Threat De…

1 day, 11 hours назад @ blogs.cisco.com
Is your SD-WAN ready for AI-powered operations?
Is your SD-WAN ready for AI-powered operations? Is your SD-WAN ready for AI-powered operations?

AI Is Changing the Traffic ModelMuch of the enterprise AI conversation centers on models, GPUs, data platforms, and agents.

Time-sensitive performance: Voice AI, edge AI, and physical AI move latency into live operations.

SD-WAN can help maintain operations by prioritizing critical traffic, steering it across the best available path, and applying consistent policy across locations.

Why AI Traffic is an SD-WAN ProblemSD-WAN sits at the point where application intent meets real network conditions.

1 https://www.aboutamazon.com/news/operations/amazon-million-robots-ai-foundation-modelCommon questions about SD-WAN and AI trafficWhat is AI-generated network traffic?

1 week, 1 day назад @ blogs.cisco.com
The Zero Trust Imperative for the Frontier AI Era
The Zero Trust Imperative for the Frontier AI Era The Zero Trust Imperative for the Frontier AI Era

Their recommendations for securing the AI era rely heavily on establishing strict asset inventory and preventing lateral movement—which are, at their core, fundamental Zero Trust principles.

The Three Core Principles of Zero Trust for AIFounded in three core principles, a robust Zero Trust architecture requires us to execute the following phases comprehensively.

Achieving the Architectural VisionThe above may all sound like pipedream, as most organisations struggle with Zero Trust programs and undelivered microsegmentation projects.

Ultimately AI driven platform approach is what makes Zero Trust achievable for the frontier AI era.

This is exactly why achieving a Zero Trust Architecture for …

1 week, 4 days назад @ blogs.cisco.com
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes
Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes

This provides an opportunity for defenders: if we assume our controls will fail at some point, we can build a much more resilient architecture.

When you assume the current layer will eventually be bypassed, you start designing the next layer proactively instead of reactively.

Defenders need to advance their controls by mapping them to the adversaries’ capabilities then assume that control will fail.

Map your controls to the attack chain.

Call to Action:If you haven’t watched the full video yet, go check it out: Assuming Failure Provides Better Defensive Outcomes (bonus elements around SOC of the Future and business context).

2 weeks, 1 day назад @ blogs.cisco.com
The Journey towards Logically Air-Gapped Deployment
The Journey towards Logically Air-Gapped Deployment The Journey towards Logically Air-Gapped Deployment

Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter.

This “Logically Air-Gapped” governance model reaches its full operational potential through the implementation of “Live Protect.” As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution.

Reference ArchitectureDigital autonomy is thus exercised by shifting network and security control into the operating system kernel.

Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a un…

2 weeks, 4 days назад @ blogs.cisco.com
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall
Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall

That is why we are introducing Firewall Migration Manager by Cisco, an enterprise-ready product built for that reality.

What Is Firewall Migration Manager?

Firewall Migration Manager is a dedicated migration application that you run in your own environment.

How Firewall Migration Manager WorksThe migration process follows a clear, guided workflow.

Intelligent, integrated migration: Firewall Migration Manager will also come to Cisco Cloud Control, and AI will play an increasing role in guiding teams before and during migration.

2 weeks, 5 days назад @ blogs.cisco.com
We third-party tested our firewall built for AI-scale. The test tools hit their limit first.
We third-party tested our firewall built for AI-scale. The test tools hit their limit first. We third-party tested our firewall built for AI-scale. The test tools hit their limit first.

In independent testing with NetSecOPEN, the Cisco Secure Firewall 6160 delivered AI-scale inspected throughput beyond what the tools built to measure it could register, all while blocking 100% of tested threats.

These results are specific to Cisco Secure Firewall 6160, but the software capabilities behind Cisco Firewall, including advanced threat protection and high-performance inspection, extend across Cisco Firewall form factors in the cloud, virtually, and on-premises, from campus to data center.

Performance passed the previous benchmark by 5XInspection was turned on, and the test tools built to measure throughput hit their limit before the 6160 firewall did.

In previous NetSecOPEN testi…

3 weeks, 6 days назад @ blogs.cisco.com
SharpHound Recon Attack – How AI enhanced the threat hunt
SharpHound Recon Attack – How AI enhanced the threat hunt SharpHound Recon Attack – How AI enhanced the threat hunt

We innovated by giving the Agentic SOC access to Endace’s always-on, full packet capture, and asked the agent to assess a potential SharpHound Recon attack that we had seen while threat hunting.

This blog explores how we built the integrations and how AI helped us with our threat hunt and threat assessment.

Agentic AI Massively Speeds our AnalysisAt this point, we decided to use Agentic AI capabilities to investigate and assess this potential threat.

ConclusionThe Agentic SOC, blending Agentic AI built into Endace’s products with custom agentic tools, is a massive boost to productivity and security.

AcknowledgementsOur thanks go to the Cisco SOC team led by @Jessica Oppenheimer and @Ivan Be…

1 month назад @ blogs.cisco.com
Machine Speed, Human Judgement: How AI Changed the SOC in 2026
Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Machine Speed, Human Judgement: How AI Changed the SOC in 2026

Having spent time in the Cisco Live Americas 2026 SOC, one thing became abundantly clear:The way SOCs operate today is fundamentally different from even a few years ago.

Instead of spending time gathering information, analysts could spend more time understanding what the information actually meant.

Just as spreadsheets empowered business users decades ago, AI-assisted coding is beginning to empower security analysts today.

At Cisco Live, AI was already present throughout the workflow:Incident summaries generated automatically within XDR.

And based on what I saw at Cisco Live 2026, that future has already arrived.

1 month назад @ blogs.cisco.com
Elevating Expertise in the SOC
Elevating Expertise in the SOC Elevating Expertise in the SOC

The new SOC analysts were great at finding evidence, helped with triage and correlation by the AI agents in the SOC architecture.

With the advancements in Cloud Control, our new SOC Analysts can validate their hypothesis.

They had the ability to investigate the incident and find the root cause found in Splunk Security and Endace.

Instant Attack VerificationIn each Incident, the SOC Analysts is given an AI generated Summary stitching all the relevant logs from all the sources that are related to the objects in question.

Check out the blogs by the engineers who worked inside the SOC at Las Vegas:

1 month назад @ blogs.cisco.com
Educate at Event Speed: Cisco Live Security Operations Center
Educate at Event Speed: Cisco Live Security Operations Center Educate at Event Speed: Cisco Live Security Operations Center

At Cisco Live AMER 2026 in Las Vegas, my work with the Cisco Event SOC centered on one outcome that makes these deployments valuable beyond the event itself: Education.

The SOC protects the conference, but it also turns live operations into a learning environment through SOC tours, Cisco Live sessions, training inside the SOC, and conversations in the World of Solutions.

Bringing live SOC lessons into the classroomEducation also happened in the sessions I delivered at Cisco Live.

Cisco Live AMER 2026 reinforced that the SOC is one of the best classrooms we have because it teaches through real operations.

For a deeper look at the model behind these deployments, read the Cisco Event SOCs: A R…

1 month назад @ blogs.cisco.com
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response
What Working the Cisco Live SOC Taught Me About AI, Detection, and Response What Working the Cisco Live SOC Taught Me About AI, Detection, and Response

Inside the Cisco Live SOCAt Cisco Live AMER, the Security Operations Center (SOC) is more than a demo environment.

For a broader look at how the Cisco Live SOC operates, read this overview.

Another part was spent in the SOC, working real investigations with XDR, Splunk Enterprise Security, firewall events, DNS telemetry, packet data, and AI assistance.

AI can help a product manager become useful faster in a live SOC.

That is the bar I want us to continue building toward as we build Cisco XDR and Splunk Security.

1 month назад @ blogs.cisco.com
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC
Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC Cable to Cloud – A Product Engineer’s Journey Through the Cisco Live AMER 2026 SOC

As part of the Cisco XDR (Extended Detection and Response) product engineering group, a few of us got exactly that chance.

Every product had a part to play for a network as traffic-heavy as Cisco Live.

(PS : Flaunting the SOC T-shirts was fun)AcknowledgementsA heartfelt thank you to Cisco and the entire SOC team — you are all amazing.

To the Cisco XDR , Splunk , Secure Access , and Secure Firewall engineering teams.

Check out the other blogs from our team at the Cisco Live Americas 2026 SOC at Las Vegas:

1 month назад @ blogs.cisco.com
The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth
The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth

We built an Experience Score model on Cisco and Splunk infrastructure and watched it run against real traffic, at real scale, in real time.

The result was a working model for how leaders measure what customers feel, act before friction surfaces, and tie operational decisions to revenue and trust.

At Cisco Live, the Experience Score model organized that architecture around four questions business and technology leaders can answer together.

The composite Experience Score tells a leader whether the experience is healthy enough to protect the moments the business depends on.

From Cisco Live to LA28Cisco Live was a rehearsal for larger exposure surfaces, where digital experience, revenue, brand …

1 month назад @ blogs.cisco.com
Microsoft Security Microsoft Security
последний пост 1 day, 10 hours назад
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

That’s exactly what Microsoft Defender Experts MDR is built to do.

We are excited to announce that we have been named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise Vendor Assessment (Doc #US54792426, July 2026).

Defender Experts MDR includes it as a core part of the service with Defender Experts Hunting, extending your team with Microsoft experts who continuously look for advanced threats across your environment.

Get startedRead the IDC MarketScape: Worldwide MDR/MXDR for the Enterprise 2026 Vendor Assessment excerpt, and visit the Microsoft Defender Experts MDR webpage to see how expert-led, round-the-clock managed detection and response can extend your team, …

1 day, 10 hours назад @ microsoft.com
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations.

Microsoft has observed DeadLock ransomware being deployed by multiple groups including an affiliate of the Lynx and INC ransomware ecosystems.

Recovery chat: Technical architectureThe most distinctive feature of the DeadLock ransomware is its recovery chat system.

‘DeadLock’ ransomware was detected‘DeadLock’ ransomware was preventedMicrosoft Defender for Cloud AppsThe following alert might indicate threat activity associated with this threat.

Indicators of compromiseIndicato…

1 day, 11 hours назад @ microsoft.com
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

KuppingerCole’s Leadership Compass: Cloud Native Application Protection Platforms (CNAPP) reflects this shift.

The report describes how CNAPP is evolving from a consolidation of cloud security tools into the security foundation for AI-native enterprises, combining cloud security, AI security posture management, runtime protection, attack path analysis, cloud detection and response, and agentic AI operations into unified platforms.

This complexity exposes the limits of traditional, siloed tools, where cloud posture, workload protection, AI security, and the security operations center (SOC) each live in their own console.

Does it see AI models, agents, and pipelines as part of cloud risk, or …

6 days, 9 hours назад @ microsoft.com
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Mitigation and protection guidanceOrganizations can apply the following recommendations to reduce exposure to this and similar macOS ClickFix campaigns:Educate users.

]com Domain ClickFix Webpage filecedarwallet[.]online.

Domain ClickFix Webpage filecopperbasket[.

]sbs Domain ClickFix Webpage filecrimsonsignal[.

]online Domain ClickFix Webpage filemarblegarden[.

6 days, 10 hours назад @ microsoft.com
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
ChainDrop supply chain compromise: Anatomy of a self-propagating worm ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Uses GitHub credentials to inject files into Claude and Visual Studio Code configurations across repository branches for persistence.

Ensure that Microsoft Defender Antivirus cloud-delivered protection, Microsoft Defender for Endpoint telemetry, Microsoft Defender for Containers, and Microsoft Defender XDR investigation workflows are enabled across developer and CI assets.

Some promptbooks require access to Microsoft Defender XDR, Microsoft Sentinel, or related Microsoft security plugins.

Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To hear stories and insights from the Microsoft Threat Intelli…

1 week назад @ microsoft.com
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

That’s why we are expanding the Zero Trust for AI strategy with two major additions: a new AI-focused Zero Trust Assessment experience and a new DevSecOps pillar in the Zero Trust Workshop.

Zero Trust Assessment tool updates: New set of assessment checks for AI, Security Operations (SecOps), and Infrastructure.

Zero Trust Workshop updates: New dedicated pillar focused on Developer Security (DevSecOps) and additional guidance for AI Memory.

How to run Zero Trust WorkshopThe Zero Trust Workshop follows a simple three-step motion: plan the right pillars and stakeholders, run the Zero Trust Assessment to establish a baseline, and use the facilitated workshop to turn findings into a 12- to 24-mo…

1 week назад @ microsoft.com
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints.

By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks.

Attack disruption instead uses AI-driven correlation and real-time analysis to identify multi-stage attacks by connecting signals across the environment before taking action.

The resultsTo summarize the results of the new device isolation response action:From first detection, Defender isolated the device in just 128 seconds.

Impact Mitigation (Defender response) – Device Isolation…

1 week назад @ microsoft.com
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints.

By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks.

Attack disruption instead uses AI-driven correlation and real-time analysis to identify multi-stage attacks by connecting signals across the environment before taking action.

The resultsTo summarize the results of the new device isolation response action:From first detection, Defender isolated the device in just 128 seconds.

Impact Mitigation (Defender response) – Device Isolation…

1 week назад @ microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence has also identified active traffic manipulation attacks leading to the delivery of malware on impacted systems.

Microsoft Threat Intelligence would like to thank our partners at Anthropic and OpenAI for their collaboration and support during this investigation.

Storm-2945 and Midnight BlizzardMicrosoft Threat Intelligence assesses that Storm-2945 is an operational sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps.

For additional details on Midnight Blizzard-related device code phishing techniques, see: Storm-2372 conducts device code phishing campaign.

To hear stories and insights from the Microsoft Threat Intelligence com…

1 week, 4 days назад @ microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence has also identified active traffic manipulation attacks leading to the delivery of malware on impacted systems.

Microsoft Threat Intelligence would like to thank our partners at Anthropic and OpenAI for their collaboration and support during this investigation.

Storm-2945 and Midnight BlizzardMicrosoft Threat Intelligence assesses that Storm-2945 is an operational sub-cluster of Midnight Blizzard based on distinctive technical and operational overlaps.

For additional details on Midnight Blizzard-related device code phishing techniques, see: Storm-2372 conducts device code phishing campaign.

To hear stories and insights from the Microsoft Threat Intelligence com…

1 week, 4 days назад @ microsoft.com
​​​​What’s new in Microsoft Security: July 2026
​​​​What’s new in Microsoft Security: July 2026 ​​​​What’s new in Microsoft Security: July 2026

Microsoft Defender Experts services are also expanding: Microsoft Defender Experts Threat Intelligence delivers human-led, curated insight into the cyberthreats most relevant to each organization, and Microsoft Defender Experts MDR extends expert-run detection and response beyond the Microsoft estate into third-party and multicloud signals through Microsoft Sentinel.

Together, the Insider Risk Management alert experience and Data Security Triage Agent help security teams investigate faster and with greater confidence.

In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy.

To learn more about Microsoft Security solutio…

1 week, 5 days назад @ microsoft.com
​​​​What’s new in Microsoft Security: July 2026
​​​​What’s new in Microsoft Security: July 2026 ​​​​What’s new in Microsoft Security: July 2026

Microsoft Defender Experts services are also expanding: Microsoft Defender Experts Threat Intelligence delivers human-led, curated insight into the cyberthreats most relevant to each organization, and Microsoft Defender Experts MDR extends expert-run detection and response beyond the Microsoft estate into third-party and multicloud signals through Microsoft Sentinel.

Together, the Insider Risk Management alert experience and Data Security Triage Agent help security teams investigate faster and with greater confidence.

In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy.

To learn more about Microsoft Security solutio…

1 week, 5 days назад @ microsoft.com
​​Better security starts with better questions
​​Better security starts with better questions ​​Better security starts with better questions

That starts with asking better questions—the kind that help organizations turn intelligence into action and trust into a foundation for progress.

But better security does not start with more information.

Understanding those connections is what allows security teams to use platforms, AI, and automation to make better decisions under real-world conditions.

Better analysis can surface more insights, but better decisions still depend on understanding what matters most and applying the right context.

Better security starts with better questions, and with the clarity to act on them.

1 week, 6 days назад @ microsoft.com
Rethinking security for the age of AI
Rethinking security for the age of AI Rethinking security for the age of AI

The approaches built for a world of human actors cannot keep pace with a world of AI, agents and machine-speed attacks.

Microsoft transforms its breadth of visibility, threat intelligence and security expertise into a security context that connects security data, knowledge and semantics across the digital estate.

By grounding every interaction in this rich security context, Project Perception improves the accuracy and consistency of reasoning while reducing the time, compute and cost required to operate at scale.

Our security researchers continuously assess models against real-world security workflows, enabling us to match each task with the model that delivers the best outcome.

Tags: AI, P…

2 weeks, 1 day назад @ blogs.microsoft.com
Rethinking security for the age of AI
Rethinking security for the age of AI Rethinking security for the age of AI

The approaches built for a world of human actors cannot keep pace with a world of AI, agents and machine-speed attacks.

Microsoft transforms its breadth of visibility, threat intelligence and security expertise into a security context that connects security data, knowledge and semantics across the digital estate.

By grounding every interaction in this rich security context, Project Perception improves the accuracy and consistency of reasoning while reducing the time, compute and cost required to operate at scale.

Our security researchers continuously assess models against real-world security workflows, enabling us to match each task with the model that delivers the best outcome.

Tags: AI, P…

2 weeks, 1 day назад @ blogs.microsoft.com
Google Online Security Blog Google Online Security Blog
последний пост 3 months, 2 weeks назад
AI threats in the wild: The current state of prompt injections on the web
AI threats in the wild: The current state of prompt injections on the web AI threats in the wild: The current state of prompt injections on the web

Here, threat actors may simply seed prompt injections on websites in hope of corrupting AI systems that browse them.

Early experiments revealed a significant volume of "benign" prompt injection text, which illustrates the complexity of distinguishing between functional threats and harmless content.

Many prompt injections were found in research papers, educational blog posts, or security articles discussing this very topic.

(Source: GitHub/swisskyrepo)When searching for prompt injections naively, the majority of detections are benign content – false positives in our case.

Malicious: ExfiltrationWe were able to observe a small number of prompt injections that aim at theft of data.

3 months, 2 weeks назад @ security.googleblog.com
Bringing Rust to the Pixel Baseband
Bringing Rust to the Pixel Baseband Bringing Rust to the Pixel Baseband

Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with mitigations against a range of memory-safety vulnerabilities.

Following our previous discussion on "Deploying Rust in Existing Firmware Codebases", this post shares a concrete application: integrating a memory-safe Rust DNS(Domain Name System) parser into the modem firmware.

Hook-up Rust to modem firmwareBefore building the Rust DNS library, we defined several Rust unit tests to cover basic arithmetic, dynamic allocations, and FFI to verify the integration of Rust with the existing modem firmware code base.

Pixel modem firmware already has a well-tested and specialized global memory allocation system to…

4 months назад @ security.googleblog.com
Protecting Cookies with Device Bound Session Credentials
Protecting Cookies with Device Bound Session Credentials Protecting Cookies with Device Bound Session Credentials

This project represents a significant step forward in our ongoing efforts to combat session theft, which remains a prevalent threat in the modern security landscape.

Session theft typically occurs when a user inadvertently downloads malware onto their device.

Once active, the malware can silently extract existing session cookies from the browser or wait for the user to log in to new accounts, before exfiltrating these tokens to an attacker-controlled server.

How DBSC WorksDBSC protects against session theft by cryptographically binding authentication sessions to a specific device.

The issuance of new short-lived session cookies is contingent upon Chrome proving possession of the correspondi…

4 months назад @ security.googleblog.com
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace’s continuous approach to mitigating indirect prompt injections Google Workspace’s continuous approach to mitigating indirect prompt injections

Staying ahead of the latest indirect prompt injection attacks is critical to our mission of securing Workspace with Gemini.

In our previous blog “Mitigating prompt injection attacks with a layered defense strategy”, we reviewed the layered architecture of our IPI defenses.

Synthetic data generationAfter we discover, curate, and catalog new attacks, we use Simula to generate synthetic data expanding these new attacks.

We partition the synthetic data described above into separate training and validation sets to ensure performance is evaluated against held-out examples.

This process leverages the newly generated synthetic attack data described on this blog, to create a robust, end-to-end evalu…

4 months, 1 week назад @ security.googleblog.com
VRP 2025 Year in Review
VRP 2025 Year in Review VRP 2025 Year in Review

2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉!

Coming back to 2025 specifically, our VRP once again confirmed the ongoing value of engaging with the external security research community to make Google and its products safer.

Vulnerability Reward Program 2025 in NumbersWant to learn more about who’s reporting to the VRP?

Tip: Want to be informed of new developments and events around our Vulnerability Reward Program?

Follow the Google VRP channel on X to stay in the loop and be sure to check out the Security Engineering blog, which covers topics ranging from VRP updates to security practices and vulnerability des…

4 months, 1 week назад @ security.googleblog.com
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android

To stay ahead of the curve, the technology industry must undertake a proactive, multi-year migration to Post-Quantum Cryptography (PQC).

To bring these critical protections to the wider developer community with minimal friction, the transition will be supported through Play App Signing.

Play App Signing leverages Google Cloud KMS, which helps ensure industry-leading compliance standards, to secure signing keys.

Empower Developers : The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and application.

: The inclusion of ML-DSA support within Android Keystore and Play App Signing allows developers to safeguard their users and …

4 months, 2 weeks назад @ security.googleblog.com
Cultivating a robust and efficient quantum-safe HTTPS
Cultivating a robust and efficient quantum-safe HTTPS Cultivating a robust and efficient quantum-safe HTTPS

Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers.

Instead, Chrome, in collaboration with other partners, is developing an evolution of HTTPS certificates based on Merkle Tree Certificates (MTCs), currently in development in the PLANTS working group.

Since MTC technology shares significant architectural similarities with CT, these operators are uniquely qualified to ensure MTCs are able to get off the ground quickly and successfully.

The Chrome Quantum-resistant Root Program will operate alongside our existing Chrome Root Program to ensure a risk-managed transition that maintains the highest levels of security for all users.

First, we…

5 months, 2 weeks назад @ security.googleblog.com
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection

For Majik, Scam Detection was the intervention he needed: “The warning is what made me pause and avoid a bad situation”.

As scammers evolve their tactics and create more convincing and personalized threats, we’re using the best of Google AI to stay one step ahead.

Expanding Scam Detection for Calls to Samsung DevicesTo help protect you during phone calls, Scam Detection alerts you if a caller uses speech patterns commonly associated with fraud.

Scam Detection for phone calls on Google Pixel devices is available in the U.S., Australia, Canada, India, Ireland, and the UK.

Powered by Gemini’s on-device model, Scam Detection provides intelligent protection against scam calls while ensuring that…

5 months, 2 weeks назад @ security.googleblog.com
Keeping Google Play & Android app ecosystems safe in 2025
Keeping Google Play & Android app ecosystems safe in 2025 Keeping Google Play & Android app ecosystems safe in 2025

Upgrading Google Play’s AI-powered, multi-layered user protectionsWe’ve seen a clear impact from these safety efforts on Google Play.

As Android’s built-in defense against malware and unwanted software, Google Play Protect now scans over 350 billion Android apps daily.

This proactive protection constantly checks both Play apps and those from other sources to ensure they are not potentially harmful.

Looking aheadOur top priority remains making Google Play and Android the most trusted app ecosystems for everyone.

Thank you for being part of the Google Play and Android community as we work together to build a safer app ecosystem.

5 months, 3 weeks назад @ security.googleblog.com
New Android Theft Protection Feature Updates: Smarter, Stronger
New Android Theft Protection Feature Updates: Smarter, Stronger New Android Theft Protection Feature Updates: Smarter, Stronger

That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt.

Today, we're announcing a powerful set of theft protection feature updates that build on our existing protections, designed to give you greater peace of mind by making your device a much harder target for criminals.

These updates are now available for Android devices running Android 16+.

More User Control for Failed Authentications: In Android 15, we launched Failed Authentication Lock, a feature that automatically locks the device's screen after excessive failed authentication attempts.

This feature is now getting a new dedicated enable/disable toggle in settings,…

6 months, 2 weeks назад @ security.googleblog.com
HTTPS certificate industry phasing out less secure domain validation methods
HTTPS certificate industry phasing out less secure domain validation methods HTTPS certificate industry phasing out less secure domain validation methods

These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation.

What’s Domain Control Validation?

Domain Control Validation is a security-critical process designed to ensure certificates are only issued to the legitimate domain operator.

Sunsetted methods relying on email:Sunsetted methods relying on phone:Sunsetted method relying on a reverse lookup:For everyday users, these changes are invisible - and that’s the point.

These changes push the ecosystem toward standardized (e.g., ACME), modern, and auditable Domain Control Validation methods.

8 months назад @ security.googleblog.com
Further Hardening Android GPUs
Further Hardening Android GPUs Further Hardening Android GPUs

Partnership with ArmOur goal is to raise the bar on GPU security, ensuring the Mali GPU driver and firmware remain highly resilient against potential threats.

We partnered with Arm to conduct an analysis of the Mali driver, used on approximately 45% of Android devices.

This approach allowed us to roll out the new security policy broadly while minimizing the impact on developers.

This effort spans across Android and Android OEMs, and required close collaboration with Arm.

The Android security team is committed to collaborating with ecosystem partners to drive broader adoption of this approach to help harden the GPU.

8 months назад @ security.googleblog.com
Architecting Security for Agentic Capabilities in Chrome
Architecting Security for Agentic Capabilities in Chrome Architecting Security for Agentic Capabilities in Chrome

We built on Gemini's existing protections and agent security principles and have implemented several new layers for Chrome.

To further bolster model alignment beyond spotlighting, we’re introducing the User Alignment Critic — a separate model built with Gemini that acts as a high-trust system component.

A flow chart that depicts the User Alignment Critic: a trusted component that vets each action before it reaches the browser.

The User Alignment Critic runs after the planning is complete to double-check each proposed action.

Looking forwardThe upcoming introduction of agentic capabilities in Chrome brings new demands for browser security, and we've approached this challenge with the same ri…

8 months назад @ security.googleblog.com
Android expands pilot for in-call scam protection for financial apps
Android expands pilot for in-call scam protection for financial apps Android expands pilot for in-call scam protection for financial apps

Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle.

Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications.

To help combat these types of financial scams, we launched a pilot earlier this year in the UK focused on in-call protections for financial apps.

The UK pilot of Android’s in-call scam protections has already helped thousands of users end calls that could have cost them a significant amount of money.

We’ve also started to pilot this protection with more app types, including peer-to-peer (P2P) payment apps.

8 months, 1 week назад @ security.googleblog.com
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing
Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing Android Quick Share Support for AirDrop: A Secure Approach to Cross-Platform File Sharing

Secure by DesignWe built Quick Share’s interoperability support for AirDrop with the same rigorous security standards that we apply to all Google products.

Secure Sharing Channel: The communication channel itself is hardened by our use of Rust to develop this feature.

On Android, security is built in at every layer.

On Android, security is built in at every layer.

Secure Sharing Using AirDrop's "Everyone" ModeTo ensure a seamless experience for both Android and iOS users, Quick Share currently works with AirDrop's "Everyone for 10 minutes" mode.

8 months, 3 weeks назад @ security.googleblog.com