Aggregator
Please support the site operations by clicking ads.
IDScan confirms breach tied to 153 million stolen driver’s licenses
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
ИИ собрал цифровую клетку и начал тестировать лекарства без пробирок
PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector
Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited […]
The post PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector appeared first on Check Point Research.
Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cybercriminals are exploiting intense interest in Grand Theft Auto VI by pushing fake game downloads that install several types of malware instead of a playable game. The campaign targets people looking for an early build, leaked copy, or unofficial demo before the title’s release. The malicious downloads are distributed through poisoned search results, gaming forums, […]
The post Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware appeared first on Cyber Security News.
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites
WordPress has rolled out an automated, AI-driven security review that screens every plugin release before it reaches the WordPress.org update API, adding a critical checkpoint to a distribution pipeline that had previously lacked one. The move follows a real-world incident in which a backdoor was slipped into an update for a plugin with roughly 20,000 […]
The post WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites appeared first on Cyber Security News.
Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
A new phishing campaign is moving fake login pages into victims’ browsers. Rather than sending people to a malicious website, its operators use browser-generated blob URLs to assemble the page in local memory, leaving less for security tools to inspect before it appears. The operation starts with a DocuSign-themed email carrying a calendar invitation. Its […]
The post Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers appeared first on Cyber Security News.
The Top 4 Threats We Found by Investigating Every Alert for a Quarter
AI供应链安全工程
CISA Updates Insider Threat Guide With New Mitigation Advice
$52 млн за день. США ударили по китайскому маркетплейсу для фабрик мошенничества
Governments ‘buying time’ in race between innovation, security, national cyber director says
Sean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones.
The post Governments ‘buying time’ in race between innovation, security, national cyber director says appeared first on CyberScoop.
[Control systems] Advantech security advisory (AV26-907)
微信,悄悄迈出 AI 社交的第一步
Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cisco Talos has confirmed active exploitation of two vulnerabilities affecting Cisco Secure Firewall Management Center (FMC) Software, with state-sponsored hacking groups and a ransomware affiliate leveraging the flaws to seize root access, plant malware, and stage attacks on enterprise networks. The disclosure marks one of the year’s more serious enterprise security incidents, given FMC’s role […]
The post Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware appeared first on Cyber Security News.
Каждый четвертый вредоносный файл в корпоративных сетях — документ Word или Excel
Attackers call employees’ personal phones to break into Microsoft 365 accounts
Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email from Microsoft 365 apps, SharePoint, OneDrive, and inboxes, for weeks at a time, according to Microsoft Security Research. (Source: Microsoft) Researchers have been tracking the campaign since May 2026. Because the initial contact often happens on a … More →
The post Attackers call employees’ personal phones to break into Microsoft 365 accounts appeared first on Help Net Security.
CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks
CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must apply vendor mitigations by September 12, 2026. CVE-2026-19490 affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as an Authentication, Authorization and Auditing virtual server or as a […]
The post CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks appeared first on Cyber Security News.