Posts of last few hours
Please support the site operations by clicking ads.
https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651157556&idx=1&sn=2270fffcb3f0dc5890c6a239c2d02a4f
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]
https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]
https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators — separate from another administration-proposed pilot program.
The post After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program appeared first on CyberScoop.
https://cyberscoop.com/gottheimer-ai-cyber-defense-act-cisa-pilot/
More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.
https://www.darkreading.com/cyber-risk/relays-masking-chinese-access-frontier-ai-models
ShinyHunters hacks the FBI Jobs portal, claims data on FBI agents, and says it stole substantial job applicant records in a PeopleSoft zero-day attack.
https://hackread.com/shinyhunters-hacks-fbi-jobs-portal-fbi-agents-data/
Cybersecurity and brand reputation are inextricably linked. Security and marketing leaders who establish regular touchpoints, develop joint crisis communications plans, and translate security risks into their brand impact position their organizations to significantly outperform those treating security as an operational IT concern.
https://www.darkreading.com/cybersecurity-operations/how-ciso-cmo-alliance-builds-trust-before-crisis
Партнёры делают ставку на совместимые инструменты для моря, воздуха и инфраструктуры.
https://www.securitylab.ru/news/577750.php
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]
https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-multiple-technologies-to-steal-govt-data/
Explore F5 Labs’ 2026 PQC report: adoption trends, CDN dependence, TLS technical debt, certificate risks, and steps toward quantum resilience.
https://www.f5.com/labs/articles/2026-state-of-pqc-on-the-web
https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-902
Даже современные ИИ-модели повторяют старую версию о зрительных иллюзиях, хотя математический анализ ставит её под сомнение.
https://www.securitylab.ru/news/577757.php
https://cyber.gc.ca/en/alerts-advisories/f5-security-advisory-av26-949
https://cyber.gc.ca/en/alerts-advisories/arista-networks-security-advisory-av26-947
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
https://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service
The Cybersecurity and Infrastructure Security Agency (CISA) is going old school to help organizations with limited resources set traps for hackers.
https://www.darkreading.com/cybersecurity-operations/deception-by-design-cisa-s-guide-to-tricking-cybercriminals
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release.
https://therecord.media/canadian-regulator-opens-probe-of-idscan-following-data-breach
Учёные подняли тревогу после штурма открытых задач.
https://www.securitylab.ru/news/577721.php
Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. Attackers can abuse the flaw without logging in to upload malicious scripts and execute them on vulnerable […]
https://securityaffairs.com/199549/security/check-point-fixes-a-new-actively-exploited-critical-security-flaw.html
Latest Blog Posts
- 1 month ago
- 3 months ago
- 3 months ago
- 3 months ago
- 3 months ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago