Aggregator
Mandiant flags fake AI video generators laced with malware
A Vietnam-based group has spread thousands of advertisements, fake websites and social media posts promising access to popular prompt-to-video AI generation tools, delivering infostealers and backdoors instead.
The post Mandiant flags fake AI video generators laced with malware appeared first on CyberScoop.
CVE-2001-1549 | Tiny Personal Firewall 1.0 TCP Packet privileges management (EDB-21169 / XFDB-7671)
Understanding the Cookie-Bite MFA Bypass Risk
The Cookie-Bite attack is an advanced evolution of Pass-the-Cookie exploits. This tactic bypasses Multi-Factor Authentication (MFA) by leveraging stolen authentication cookies—such as Azure Entra ID’s ESTSAUTH and ESTSAUTHPERSISTENT—to impersonate users.
The post Understanding the Cookie-Bite MFA Bypass Risk appeared first on Security Boulevard.
CVE-2010-4884 | Hinnendahl Gaestebuch 1.2 script_pfad code injection (EDB-14810 / OSVDB-76115)
Alleged Sale of Data from an Unidentified Company in Hong Kong
Red Canary to join Zscaler
DragonForce Ransomware Strikes MSP in Supply Chain Attack
Google Chrome security advisory (AV25-299)
Akira
You must login to view this content
Qilin
You must login to view this content
Qilin
You must login to view this content
Naughty AI: OpenAI o3 Spotted Ignoring Shutdown Instructions
Toggling a misbehaving device's power button to forcibly turn it off and on again remains a trusted IT tactic since the dawn of the digital age. Enter a new challenge: artificial intelligence tools that refuse to comply with shutdown requests when they conflict with goals they've set.
NATO Countries Targeted By New Russian Espionage Group
Dutch intelligence agencies and Microsoft say a novel Russian state intelligence hacking group is likely buying stolen credentials from criminal marketplaces to gain entry to North American and European networks. It has "a specific interest in European Union and NATO member states."
Meta Begins AI Training Using EU Personal Data
Meta can use the public posts of European Instagram and Facebook users to train its artificial intelligence models starting Tuesday after a German court rejected an injunction against the company. The court said Meta has a "legitimate interest" in processing the data.
Fake AI Tools Lure Users in Year-Long Malware Campaign
Online scammers are converting excitement over generative artificial intelligence into fraudulent sites that infect victims with malware, says threat intel firm Google Mandiant in a report exposing a year-long campaign to distribute infostealers and backdoors.
New Russian state-sponsored APT quickly gains global reach, hitting expansive targets
Laundry Bear, a group recently identified by Dutch intelligence and security services, stole work-related contact details on the Netherlands’ national police force in September 2024, Microsoft researchers said.
The post New Russian state-sponsored APT quickly gains global reach, hitting expansive targets appeared first on CyberScoop.