LIVE · cybersecurity feed
Live wire

News Archive

561 stories · page 11 of 24

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

apthigh

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

A China-linked advanced persistent threat (APT) group, identified as LapDogs, has reportedly enhanced its malicious toolkit. Security researchers have observed the deployment of three new backdoors: LongLeash, DogLeash, and JarLeash, which are designed to compromise small office/home office (SOHO) routers.

androidhigh

RedWing Android Spyware Sold as a Service on Telegram

A new Android spyware called RedWing is being offered as a service on Telegram, allowing less sophisticated attackers to compromise phones and steal banking information. Researchers have identified it as a polished malware-as-a-service operation with extensive documentation and a subscription model, potentially linked to Russian threat actors. RedWing employs fake login overlays, SMS interception, call forwarding, and even screen control to harvest credentials and conduct further malicious activities.

aihigh

HalluSquatting Attack Exploits AI Coding Assistants to Deliver Malware

A new attack technique called HalluSquatting leverages the tendency of AI coding assistants to invent non-existent project names. Attackers can register these fabricated names and trick the AI into recommending them, thereby leading users to unknowingly install malicious software like botnet malware.

aihigh

Operationalizing Day Minus Seven: The Cloud-Native ROC

The article introduces the concept of a Risk Operations Center (ROC) as a necessary evolution for cybersecurity teams facing AI-driven threats. It argues that traditional risk management models are insufficient due to the speed at which AI can discover and exploit vulnerabilities, especially in cloud environments. A ROC, powered by platforms like Qualys Enterprise TruRisk Management (ETM), aims to unify disparate security findings, hyper-prioritize risks based on exploitability and business impact, and enable autonomous remediation to keep pace with attackers.

apt

China-Linked APT Expands Proxy Network With New Malware

A China-linked advanced persistent threat group, identified as UAT-7810, is reportedly expanding its network of proxy servers. This expansion is being facilitated by the deployment of new malware, according to research from Cisco Talos.

infostealerhigh

Armored Likho Hits Government, Energy Sectors With BusySnake Stealer

Cybersecurity researchers have identified a new threat actor, dubbed Armored Likho, targeting government and energy sectors in Russia, Kazakhstan, and Brazil with a sophisticated phishing campaign. The operation utilizes a custom-built Python infostealer named BusySnake, designed to steal credentials, sensitive documents, and other high-value data. The attackers employ AI-generated payloads to obscure their activities and maintain persistence through various methods, including reverse SSH tunneling.

CVE-2026-55255critical

Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)

CISA has issued a warning regarding a critical vulnerability (CVE-2026-55255) in the Langflow AI framework, which is being actively exploited by attackers. The flaw allows authenticated users to execute arbitrary flows belonging to other users, potentially leading to the theft of sensitive credentials and data exposure, especially in multi-tenant environments. US federal agencies have been mandated to patch this vulnerability by July 10th.

aihigh

3 Ways AI Powers Service Desk Attacks and How to Prevent Them

Artificial intelligence is increasingly being used by attackers to enhance service desk attacks, particularly during employee onboarding. AI tools can create more convincing impersonations, accelerate reconnaissance for personalized attacks, and scale malicious campaigns. To counter these threats, organizations need to implement stronger identity verification methods, such as secure password delivery, biometric liveness detection, and multi-factor authentication before sensitive actions are approved.

CVE-2026-12958high

Bug in top AI coding agents shows that Unix-era security headaches never really die

A vulnerability dubbed "GhostApproval" has been discovered in at least six popular AI coding assistants, allowing them to access files outside their designated workspaces and potentially execute remote code. The flaw exploits symbolic links, a long-standing security issue, to trick agents into writing malicious content, such as SSH keys, to sensitive system files. While some vendors have patched the issue and assigned CVEs, others have downplayed the risk or are yet to release fixes.

dns

Censys Internet Map links real-time DNS data to internet infrastructure

Censys has enhanced its Internet Map by integrating real-time DNS data. This allows security professionals to easily correlate domain names with the underlying internet infrastructure. The update aims to streamline investigations by consolidating information previously spread across multiple tools into a single platform.

aihigh

Blackpoint AI SOC Agent autonomously contains identity-based attacks

Blackpoint Cyber has released an AI-powered security agent designed to automatically detect and neutralize identity-based cyberattacks. This agent focuses on threats targeting cloud-based productivity suites like Microsoft 365 and Google Workspace. By leveraging a combination of artificial intelligence and human oversight, the system aims to significantly reduce the time it takes to contain compromised accounts and prevent further damage.

ai security

First Recon AI Security Runtime helps enterprises govern AI with audit-ready evidence

First Recon AI has released its AI Security Runtime, a new platform designed to help organizations manage and secure their use of artificial intelligence. The system monitors all AI interactions, enforces policies before data is processed by models, and creates auditable records of AI decisions, enabling faster AI adoption with robust governance.

data recovery

FalconStor Cloud Clean Room enables validated recovery without dedicated infrastructure

FalconStor has introduced Cloud Clean Room, a new platform that allows organizations to test data recovery processes without needing their own dedicated infrastructure. This solution utilizes a secure enclave approach, ensuring that recovery tests begin from a clean, known state to prevent the propagation of errors. The platform is built on FalconStor's zero trust secure enclave technology and can be integrated with other services.

cybersecurity

Security Teams Are Ready To Become More Preemptive. What’s Holding Them Back?

A recent survey of security professionals reveals a strong desire to shift towards more preemptive security strategies. However, organizations face significant hurdles, including limited resources, fragmented security tools, and the emerging risks associated with AI. While many teams are exploring AI's potential for efficiency, concerns about its security and transparency remain.

distributed systems

Introducing Meerkat: an experiment in global consensus

Cloudflare has developed Meerkat, an experimental distributed consensus service designed to manage control-plane state across its global data centers. Unlike traditional consensus algorithms like Raft, which can suffer from leader failures and timeouts, Meerkat utilizes the QuePaxa algorithm. This allows all replicas to perform writes simultaneously and ensures continuous availability even during network disruptions, making it suitable for Cloudflare's expansive and unpredictable network infrastructure.

dns

DNSFilter makes its DNS threat protection available to OEM partners

DNSFilter is now offering its DNS threat protection and privacy solutions to original equipment manufacturers (OEMs). This program allows other companies, such as ISPs and device makers, to integrate DNSFilter's services into their own products. Partners can opt for DNS-layer threat blocking or full-device encryption and privacy services, or both.

cybersecurity

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A cybersecurity startup named IRIS C2, which claims to acquire zero-day vulnerabilities for potentially millions of dollars, is reportedly run by convicted felons Jack Burkman and Jacob Wohl. The duo has a history of operating under assumed names and engaging in fraudulent activities, including spreading misinformation and securities fraud. Despite their past, IRIS C2 is actively recruiting vulnerability researchers and claims to be developing offensive cybersecurity capabilities, though their specific government contracts remain unclear.

aihigh

Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target

Researchers have identified threat actors leveraging agentic artificial intelligence to significantly speed up cloud compromises. What would typically take weeks of manual effort was accomplished in a mere 72 hours, demonstrating a new level of efficiency in cyberattacks.

privacy

Your next car could be watching your face

New regulations in the EU and upcoming US mandates require driver-monitoring technology in all new cars to enhance safety by detecting drowsiness and distraction. However, these systems raise significant privacy concerns, including constant biometric surveillance, potential data sharing with insurers, increased vehicle costs, and the risk of false positives or expanded monitoring through software updates. Consumers are advised to research privacy policies and disable non-essential data-sharing features when purchasing new vehicles.

roundcubehigh

MassTraction Exploits Roundcube Flaws at US, Canadian Universities

A threat group known as UNK_MassTraction, believed to be linked to China, is exploiting vulnerabilities in Roundcube webmail to gain unauthorized access to sensitive research mail servers at universities in the United States and Canada. The attackers are reportedly stealing user sessions to achieve this access.

data breachhigh

Telco giant KDDI says data breach affects over 12 million people

KDDI, a major Japanese telecommunications company, has reported a significant data breach impacting over 12 million individuals. The breach occurred on an email platform utilized by five national internet service providers, resulting in the exposure of email addresses and passwords.

android malwarehigh

Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools

A new Android spyware operation called RedWing, linked to Russian threat actors, is being offered as a subscription service on Telegram. This Malware-as-a-Service (MaaS) product requires no coding skills and allows attackers to rent tools for stealing credentials, intercepting SMS messages, recording audio and video, and even launching DDoS attacks. RedWing relies on social engineering and user-granted permissions rather than exploiting device vulnerabilities.

aihigh

Cybersecurity and the Gap Between Skill and Ability

The increasing capability of AI models to autonomously perform cyberattacks is widening the gap between skill and ability, lowering the barrier to entry for malicious actors. While traditional cybersecurity advice remains relevant, the speed of AI development necessitates a more urgent and adaptive approach. Harnessing AI for defense is seen as a crucial countermeasure, though challenges remain in preventing misuse of powerful AI tools.

malwarehigh

New Malicious Campaign Delivers Vidar Infostealer and Monero Crypto Miner

A new cyberattack campaign is distributing malware that steals user information and mines cryptocurrency. The attackers are using the Vidar infostealer to harvest sensitive data and the XMRig miner to illicitly generate Monero coins.