LIVE · cybersecurity feed
Live wire

News Archive

561 stories · page 18 of 24

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

cloud security

Microsoft named a leader in the Frost Radar for cloud and application runtime security

A new report from Frost & Sullivan identifies Microsoft as a leader in cloud and application runtime security. The report highlights a market shift towards contextual risk reduction, focusing on how exposures combine across infrastructure and applications to create exploitable attack paths. Microsoft's position is attributed to its extensive ecosystem, the capabilities of Microsoft Defender for Cloud integrated with Defender XDR, and its large customer base.

security

When Too Much Security Data Becomes the Risk

Rapid growth turned routine firewall logs into a security and budget liability. One CISO used artificial intelligence to filter what data truly belongs in the SIEM.

ai

5 Myths About AI in the SOC Security Teams Need to Rethink

Security operations teams are increasingly adopting AI, but common assumptions about its role need reevaluation. Experts suggest AI should augment, not replace, human analysts by handling repetitive tasks and data processing. While automation is beneficial for enrichment and triage, critical actions still require human oversight. Transparency and explainability are crucial for building trust and ensuring analysts can confidently use AI outputs.

ai

'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat

LLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector.

cybersecurity

Safe Events Start With Threat Intel & Digital Security

Proactive cybersecurity measures are essential for ensuring the smooth operation of events. By anticipating potential digital threats, organizers can prevent disruptions and maintain a secure environment.

banking trojanhigh

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula

Cybersecurity researchers have identified a new campaign by the banking Trojan Ousaban, primarily targeting users in Spain and Portugal. The malware, previously active in Brazil, is distributed via a sophisticated phishing PDF that leads victims to a malicious webpage. This page employs environmental and geo-fencing checks to ensure only intended targets download the payload, which includes a VBS script and the Ousaban executable. The Trojan then establishes persistence, decrypts banking-related strings using a custom algorithm, and communicates with command-and-control servers through dynamically generated hostnames.

cni

Building more resilient CNI: what industry pen testers told us

Penetration testers have shared insights into how organizations can enhance the resilience of their Container Network Interface (CNI) deployments. Their recommendations aim to make it harder for attackers to exploit vulnerabilities within containerized environments.

CVE-2026-20245high

Texas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches

Several organizations experienced significant security incidents this week. The Texas Parks and Wildlife Department suffered a data breach affecting over 3 million customers due to a vendor compromise, exposing personal information but not financial or social security data. Additionally, a supply chain attack on WordPress plugin vendor ShapedPlugin delivered malicious updates, leading to credential theft and website modifications. AI-powered threats are also on the rise, with a new phishing service called EvilTokens exploiting device-code authentication to steal Microsoft 365 tokens.

security

Papa Johns Surveillance-Based Advertising

Papa Johns is spying on people’s buying activities to predict when they are low on food: The pizza chain recently tapped NBCUniversal, Instacart and the dentsu-owned media agency Carat for help reaching consumers when they’re low on groceri

ransomwarehigh

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

Researchers have demonstrated a novel ransomware technique that operates entirely within a web browser, bypassing the need for native installations or exploits. By leveraging the File System Access API in Chrome, specifically on Android, malicious websites can trick users into granting access to sensitive photo directories. This method, inspired by AI-generated concepts, uses social engineering tactics like fake image-enhancement tools to prompt users for permissions, enabling the browser-based ransomware to potentially encrypt or modify files.

security

Martin Lee: Running through the Arctic (and the threat landscape)

Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? In this Humans of Talos, we’re joined by Martin Lee, EMEA Lead, to talk about his journey into the industry.

screenconnecthigh

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign

Threat actors are distributing malicious installer archives that masquerade as popular freeware, such as OBS Studio and Bandicam. These installers contain a legitimate Microsoft binary alongside a rogue DLL that enables DLL sideloading. This process deploys the ScreenConnect remote access tool, which attackers use to maintain control over compromised systems and potentially execute further payloads like AsyncRAT.

phishing

ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoi

ai

OpenClaw: risks for the users and how to mitigate them

OpenClaw, an AI agent ecosystem formerly known as Clawdbot and Moltbot, offers flexibility and task automation but introduces security risks to users and organizations. The system's 'skills' feature, which allows for natural language instructions and easy creation of extensions, can be exploited by attackers. The article aims to explore these security aspects, known vulnerabilities, and mitigation strategies.

phishing

Phishing Attack Targets MetaMask Users with Fake Credentials

This morning, an interesting phishing email hit my mailbox. It targets Metamask[1], a cryptocurrency wallet, available as a browser extension and a mobile app, that lets users store, send, and receive crypto money. It's pretty popular, so a

aihigh

AI Hallucinations Create Phantom Domains for Supply Chain Attacks

Artificial intelligence models can generate domain names that do not actually exist, a phenomenon known as "phantom squatting." Attackers are leveraging this AI hallucination to create malicious domains that mimic legitimate ones, thereby posing a significant threat to software supply chains. This tactic allows them to potentially intercept or manipulate software development processes.

securitycritical

China-Linked Group Targets Southeast Asia Critical Systems

The group compromised at least 10 regional organizations, including two state-owned entities, and deployed a new backdoor.

iranhigh

Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool

A threat group linked to Iran, known as TAG-182, is actively distributing a surveillance tool called MarkiRAT. This malware is being spread through fake applications disguised as VPNs and download tools, primarily targeting Iranian citizens both within and outside the country. The operations appear to be conducted via social media platforms and are likely part of Iran's intensified cyber surveillance efforts.

ai

Fake Bug Report Hijacks AI Coding Agents at Scale

"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent's inability to differentiate between content and instructions.

security

Scammers race to cash in on Venezuelan earthquake disaster

Scammers wasted no time exploiting Venezuela's devastating earthquake, with researchers uncovering 212 newly-registered relief-themed domains in just five days. Read more in my article on the Hot for Security blog.

breach

Attackers Seize Exposed AI Endpoints to Power Offensive Ops

Threat actors don't need any special authentication to reach a target endpoint — they just need to know where it is.

ai

Why Identity Security Is Your Cyber Career Entry Point

In this "Heard it From a CISO" video, Silverfort CISO John Paul Cunningham explains that AI in cybersecurity workflows is creating opportunities rather than eliminating jobs — and there are more ways than ever to break into this essential f

quantum computinghigh

Accelerating the quantum-safe timeline

Microsoft is accelerating its timeline for transitioning to post-quantum cryptography (PQC) due to advancements in quantum research and government guidance. The company aims to have its products and services ready for PQC by 2029, encouraging organizations to begin their transition sooner to mitigate risks and costs associated with this multi-year engineering effort.

phishing

Phishers Gain Persistence at EU, Asia Hospitality Orgs

Separate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse.