Aggregator
Descope enhances AI identity security with Agentic Identity Control Plane
Descope launched Agentic Identity Control Plane, a solution that enables security teams to institute policy-based governance, auditing, and identity management for their AI agent and Model Context Protocol (MCP) ecosystems. The Agentic Identity Control Plane builds on top of the existing Descope Agentic Identity Hub to mark a huge step forward in Descope’s vision of becoming the identity provider for AI agents. As AI agents, LLMs, and MCP servers continue gaining rapid adoption, security leaders … More →
The post Descope enhances AI identity security with Agentic Identity Control Plane appeared first on Help Net Security.
【安全圈】Bing搜索投毒攻击:窃取域控权限的“IT管理软件陷阱”
【安全圈】Trend Micro Apex One 关键 RCE 漏洞遭在野利用,企业需紧急修复
【安全圈】黑客伪造企业应用骗取微软365账户权限,Tycoon钓鱼工具包成幕后黑手
【安全圈】Dell百万笔记本重大漏洞:恶意攻击者可永久控制设备并窃取生物识别数据
AI Slashes Workloads for vCISOs by 68% as SMBs Demand More – New Report Reveals
How Top SOCs Defend Against Emerging Threats with Live Attack Data
Adobe 紧急修复 AEM Forms 中的两个0day漏洞
LegalPwn:利用法律免责条款,操纵ChatGPT等主流AI工具执行恶意代码
WhatsApp adds new security feature to protect against scams
MIND launches autonomous DLP platform to put data protection on autopilot
MIND announced the general availability of the first autonomous DLP platform, enabling security teams to safely use GenAI, go beyond compliance, and automate data protection across all IT environments by reducing manual work and preventing sensitive data leaks. Built from the ground up as an AI-native DLP platform to automate the entire lifecycle of data protection, MIND delivers: Data discovery: Automated and continuous inventory of sensitive data at rest and user/agentic AI/non-human activities to remove … More →
The post MIND launches autonomous DLP platform to put data protection on autopilot appeared first on Help Net Security.
Атака началась. И если D-Link не обновлён — хакеры уже следят за тобой
CVE-2025-8667 | SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75bb97ff7dacc3fa3bbf2 src/tools/tools.py from_code/from_dict/from_mcp os command injection (EUVD-2025-23865)
Microsoft Launches Project Ire to Autonomously Classify Malware Using AI Tools
Submit #621324: SkyworkAI DeepResearchAgent main OS Command Injection [Accepted]
New Black Kite tool identifies which vendors are most vulnerable to targeted threat groups
Black Kite has unveiled the Adversary Susceptibility Index (ASI), a tool designed for TPRM teams to proactively identify which vendors are most vulnerable to specific threat actors before threats escalate into breaches. “With high-profile threats like Volt Typhoon, Black Basta, and APT29, security teams cannot wait for weeks to respond,” said Ferhat Dikbiyik, Chief Research and Intelligence Officer, Black Kite. “As threat actors become more targeted and sophisticated, third-party risk teams need tools that reflect the … More →
The post New Black Kite tool identifies which vendors are most vulnerable to targeted threat groups appeared first on Help Net Security.
PyLangGhost RAT: Rising Stealer from Lazarus Group Striking Finance and Technology
Editor’s note: The current article is authored by Mauro Eldritch, offensive security expert and threat intelligence analyst. You can find Mauro on X. North Korean state-sponsored groups, such as Lazarus, continue to target the financial and cryptocurrency sectors with a variety of custom malware families. In previous research, we examined strains like InvisibleFerret, Beavertail, and OtterCookie, often […]
The post PyLangGhost RAT: Rising Stealer from Lazarus Group Striking Finance and Technology appeared first on ANY.RUN's Cybersecurity Blog.
Ransomware Actors Expand Tactics Beyond Encryption and Exfiltration
Threat Actors Poison Bing Search Results to Distribute Bumblebee Malware via ‘ManageEngine OpManager’ Queries
Threat actors leveraged SEO poisoning techniques to manipulate Bing search results, directing users querying for “ManageEngine OpManager” to a malicious domain, opmanager[.]pro. This site distributed a trojanized MSI installer named ManageEngine-OpManager.msi, which covertly deployed the Bumblebee malware loader while installing legitimate software. Bumblebee, first identified in late 2021 as an initial access tool associated with […]
The post Threat Actors Poison Bing Search Results to Distribute Bumblebee Malware via ‘ManageEngine OpManager’ Queries appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.