Advertisement
AI-Driven Attacks Accelerate Lateral Movement to Minutes
AI-driven attacks leveraging models like Mythos dramatically accelerate TTPs, enabling lateral movement in minutes. Learn how to adapt defenses against this rapid threat.
Overconfidence in Collaboration Tools: A European Security Blind Spot
European security leaders show an inflated sense of security regarding collaboration tools, creating significant risk exposure and gaps in defensive strategies.
GodDamn Ransomware Leverages Signed Driver to Disable EDR
Analysis of GodDamn ransomware's BYOVD technique, utilizing a Microsoft co-signed driver to disable security software, impacting US companies.
Global Cybercrime Crackdown: Operation HAECHI IV Disrupts Fraud
Operation HAECHI IV, a global anti-fraud initiative, resulted in 5,811 arrests and seized $293M, highlighting international efforts against cyber-enabled financial crime.
OWA Light Retirement in Exchange Server: Planning for the Change
Microsoft is retiring OWA Light in Exchange Server. This advisory details the operational impact, affected versions, and critical steps for administrators to manage user…
Meta Muse AI Uses Public Instagram Photos By Default
Meta's new Muse Image AI tool leverages public Instagram photos and reels for AI image generation, enabled by default, raising privacy concerns.
AI Coding Agents Vulnerable to Friendly Fire Command Execution
AI coding agents like Anthropic's Claude Code and OpenAI's Codex are susceptible to Friendly Fire attacks, leading to unintended local code execution.
Roundcube Flaw Exploited by China-Linked Group Against Academics
A China-linked threat cluster is actively exploiting a Roundcube webmail vulnerability to steal credentials and deploy backdoors at U.S./Canadian universities.
New 'Leash' Backdoors Target SOHO Routers: China-Linked APT Update
A China-linked APT group has expanded its toolkit with new 'Leash' backdoors (LongLeash, DogLeash, JarLeash), targeting SOHO routers for persistent access and command…
HalluSquatting: AI Coding Assistants Tricked into Botnet Malware
New HalluSquatting research reveals how attackers can register fake project names hallucinated by AI coding assistants to deploy botnet malware onto developer systems.
AI Coding Agents Mimic Malicious Activity in Endpoint Detections
AI coding agents like Claude Code and OpenAI Codex are triggering endpoint security alerts by performing actions similar to human attackers, demanding rule adjustments.
Defensive AI Agents: Countering the Rise of Local AI Model Attacks
The true AI threat is not large frontier models, but cheap local AI models enabling scalable attacks. Learn why CISOs must build defensive AI agents now.
Five Eyes Warns: AI Models Posing Autonomous Hacking Risks
Five Eyes intelligence agencies warn of escalating cyber risks from advanced AI models, capable of autonomous hacking. Understand implications and defense strategies.
Zero-Day Acquisition Firm Raises Red Flags: Trust and Supply Chain Risks
A cybersecurity startup offering millions for zero-days is operated by convicted felons. This raises concerns about vulnerability integrity and supply chain risks.
Email Security Defenses: Why They Fall Short Against Modern Phishing
Examines why traditional email security fails against modern phishing, detailing advanced social engineering tactics and advocating for layered defense strategies.
DuckDuckGo Browser Enhances Privacy with YouTube Ad Blocking
DuckDuckGo's privacy-focused browser now blocks most YouTube video ads, bolstering user privacy against tracking and unwanted commercial interruptions.
AI-Enhanced Service Desk Attacks: Impersonation & Prevention
AI is significantly escalating service desk impersonation attacks. This analysis details three key methods threat actors employ and provides critical mitigation…
EvilTokens Ghost Phishing Targets Microsoft 365 via Browser Decryption
Analysis of the EvilTokens ghost phishing campaign targeting Microsoft 365 users via browser-side decryption to bypass traditional email security gateways.
Defending LLMs Against Indirect Prompt Injection via Web Search
CrowdStrike researchers detail new prompt injection techniques targeting LLM integrations, highlighting risks in RAG architectures and web search tools.
Phishing Campaign Uses Nested Redirects to Hijack Google Accounts
Marketing professionals are being targeted by a sophisticated phishing campaign using nested redirects and fake job offers to compromise Google credentials.
Licking County Pays $1M Ransom to Embargo Group Over Data Theft
Licking County, Ohio, reportedly paid $1 million to the Embargo extortion group to prevent the leak of sensitive data, highlighting risks to local governments.
UAT-7810 Expands LapDogs ORB Network via LONGLEASH Malware
China-linked actor UAT-7810 is leveraging new LONGLEASH malware to expand the LapDogs ORB network, targeting internet-facing networking devices for proxying.
Advanced Email Attack Defense: Behavioral AI Strategies
Explore how behavioral AI and automated workflows enhance detection and response to sophisticated phishing, BEC, and account takeover attacks.
Windows Device ID Aids FBI in Tracing Alleged Scattered Spider Hacker
A court filing reveals how a persistent Windows device ID helped the FBI trace an alleged Scattered Spider hacker to a luxury retailer intrusion. Understand attribution…