Aggregator
Please support the site operations by clicking ads.
CVE-2026-63375
CVE-2026-63444
CVE-2026-85706
CVE-2026-42018
CVE-2026-42016
CVE-2026-84869
CVE-2026-81963
CVE-2026-82329
CVE-2026-82078
Turn it off and on again, but for critical infrastructure
Researchers at KTH Royal Institute of Technology built a container replica of a segmented industrial network, attacked it repeatedly across 14 days of running time, and used the captured traffic to train a defense agent that decides on its own when to intervene. The agent sees six numbers per interval: packet counts crossing the network’s segments and moving to and from individual machines. From those counts it infers how far an intruder has progressed, and … More →
The post Turn it off and on again, but for critical infrastructure appeared first on Help Net Security.
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates […]
The post Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Permify: Open-source authorization as a service
Permify is an open-source authorization service that answers access questions at run time: can user X view document Y, which posts can members of team Y edit. It keeps those rules in one place, apart from the application code that would otherwise carry them. Permify follows the design of Google Zanzibar, the authorization system Google runs across its own products. Teams reach for something like it when permissions get specific and start nesting inside each … More →
The post Permify: Open-source authorization as a service appeared first on Help Net Security.
AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoice Details.bat”, which relies on user interaction to trigger execution. While the precise delivery method […]
The post AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected
The Dutch National Cyber Security Center (NCSC) has issued an urgent warning over two critical vulnerabilities in Check Point VPN products, saying it expects large-scale exploitation attempts in the near term. Organizations using affected Check Point gateways, management systems, or Spark Firewall products should deploy the available fixes immediately. Tracked as CVE-2026-85102 and CVE-2026-85103, both […]
The post NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected appeared first on Cyber Security News.
伊朗关联组织借虚假招聘和编程测试投放跨平台远控木马,我科技企业海外招聘及开发者终端面临渗透风险
美国国家安全局将进行彻底重组,设立五个“任务中心”,包括网络安全和人工智能中心
追觅四大赛道 IFA 首秀:一套技术,四个出口
Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories
This week’s roundup covers a massive Microsoft Patch Tuesday with two exploited zero-days, active FortiGate exploitation, a critical PAN-OS root-level RCE flaw, the Revolut KYC data breach, and more than 20 other stories spanning AI-driven cyberattacks, browser and firewall zero-days, and enterprise breach disclosures. Massive Microsoft Patch Tuesday September 2026 Microsoft’s September 2026 Patch Tuesday […]
The post Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ Stories appeared first on Cyber Security News.
K17 CTF 2026
Date: Sept. 11, 2026, 10 a.m. — 13 Sept. 2026, 10:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://scoreboard.k17ctf.secso.cc/
Rating weight: 24.83
Event organizers: K17