News Archive
1938 stories · page 25 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full […] The post

Grok chat duped into swallowing injected instructions
A spoonful of encryption helps the malware go down

Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)
Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s not all that new, but it&#;x26;#;39;s new enough that lots of folks (and commercial tools) aren&#;x26;#;39;t using it yet.&#;x26;#;xc2;&#;x26;#;xa0; &#;x26;#;xc2;&#;x26;#;xa0;It allows you to Get and Set info from/to M365, Entra Users and Entra

NCSC Urges Stronger Controls for Agentic AI Systems
NCSC urged sandboxing, oversight and tight access controls for autonomous AI agents

Your Mac already has a built-in firewall. Here’s how to get more from it
Malwarebytes Firewall gives you a clearer, more intuitive way to manage your Mac's inbuilt firewall.

US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate
Defense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time high

French tax authority says break-in exposed data of 600K, including some private messages
Stolen details range from contact information to household finances and withholding rates

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek.

Citrix urges admins to patch new NetScaler flaws as soon as possible
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]

MLflow Vulnerability Exploited for Cloud Credential Theft
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek.

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Researchers have developed a 'Zombie Card' attack that can enable the use of expired Visa contactless cards for in-store payments. The attack involves a man-in-the-middle relay that rewrites the expiration date read by the point-of-sale terminal, while leaving the card's cryptography intact. This method was successful against some major US banks, though not universally, and highlights potential vulnerabilities in how expiration dates are handled during transactions.

Managing the cyber risk of agentic AI
Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.

9 million images of people’s faces exposed by reverse lookup service
A researcher found an exposed database containing 9 million images that belonged to people finder service ClarityCheck.

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek.

Why "Shady AI" is Security's Next Big Governance Problem
A recent incident at Meta involving an approved AI agent exposing sensitive data highlights the growing challenge of "shady AI." Unlike "shadow AI" (unapproved tools), shady AI involves approved tools being used in unexpected or poorly governed ways within an organization's visibility. This presents a significant governance problem for security teams, as traditional methods struggle to keep pace with the rapid evolution of AI capabilities and usage patterns.

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Researchers have identified two denial-of-service (DoS) attack methods, dubbed "CDN Tsunami," that exploit the translation process between HTTP/3 and HTTP/1.1 used by major content delivery networks. These attacks can amplify low-bandwidth requests into significant loads on origin servers, with amplification factors up to 350x observed on some CDNs. The vulnerabilities affect services like Alibaba, Baidu, Cloudflare, Amazon CloudFront, Fastly, and Tencent, though mitigation strategies are being developed and deployed by some vendors.

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
A new Android malware strain named Manic has been identified, exhibiting capabilities of both banking Trojans and spyware. It targets financial institutions, government services, and messaging applications across Ukraine, Russia, and Europe. A unique feature allows infected devices to relay stolen data through other compromised devices via Wi-Fi Direct, Bluetooth, or BLE, even if the initial device lacks internet access.

Corero brings cloud-based AI threat analysis to SmartWall ONE
Corero Network Security has announced AI-Augmented Cloud-Assist for SmartWall ONE, extending its automated DDoS protection with cloud-delivered AI analysis, threat intelligence, and policy optimization. As cybercriminals increasingly leverage AI to develop and evolve attack campaigns, defenders must respond with equal speed and precision. Cloud-based AI analysis enables Corero’s DoS/DDoS solutions

AWS limits AI agents’ data access, even when manipulated
AWS has detailed an approach for propagating user authorization context through AI agents, allowing access controls to be enforced by infrastructure and downstream services rather than relying on the agent itself. Customers using Amazon Bedrock AgentCore can build AI agents that pull information from Amazon DynamoDB tables, document repositories, SaaS platforms, and internal knowledge bases to ans

AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking
Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network. The post AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking appeared first on SecurityWeek.

CISA warns of hackers exploiting critical MLflow vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI

ICS Operators Warned of AI-Driven Attacks on Siemens PLCs
A US government advisory warned that attackers are deploying AI-generated exploitation scripts against exposed Siemens S7 Series PLCs

Fake Gemini installer delivers Vidar infostealer via Google Colab lure
A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was noted that the top search result for the suspicious filename associated pointed to a file hosted on Google Colab, a cloud-based Jupyter notebook plat