News Archive
558 stories · page 20 of 24Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach
A security incident involving Shai Hulud has been detailed, starting with a compromise in the CI/CD pipeline that led to the exposure of Jenkins credentials. This initial breach allowed for privilege escalation within AWS, ultimately resulting in unauthorized access to Redshift data.

Small Businesses Need Cyber Readiness for Resilience
Small businesses often have a larger attack surface than their size suggests. Achieving cyber readiness is presented as the initial and crucial step toward building resilience against potential threats.

Robinhood Cuts Access Approval Time to Support High-Velocity Development
Robinhood's application security team has streamlined the process for granting system access to its developers. This re-engineering aims to support faster development cycles while simultaneously enhancing security measures. The fintech company focused on making access both easier and more secure for its engineering teams.

In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
A critical vulnerability affecting Cisco Unified CM and Unified CM SME deployments, which allows for server-side request forgery (SSRF) and root privilege escalation, was rapidly exploited by attackers. Threat actors weaponized the flaw within 24 hours of its public disclosure.

Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses
The FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers.

Beyond IOCs: AI-enabled threat intelligence
This week's newsletter explores how artificial intelligence can enhance threat intelligence capabilities. AI is expected to facilitate the creation of easily searchable data sources derived from intelligence reports, thereby improving access and utility of information for security professionals.

Introduction to COM usage by Windows threats
Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to

Gamaredon Group Evolves Tactics With New Tools and Alliances
ESET Research has identified new tactics employed by the Gamaredon group, including the use of tunnels, dead drops, and worker processes. The threat actor is increasingly leveraging legitimate online services to conceal its command-and-control infrastructure and to exfiltrate stolen data.

Evaluating Mexico’s New Cybersecurity Plan
Mexico has introduced a new National Cybersecurity Plan to combat threats such as organized crime, geopolitical risks, and AI advancements. This initiative addresses recent cyber incidents affecting government and institutional bodies, aiming to mitigate data theft, ransomware, and service disruptions. The plan acknowledges Mexico's vulnerability to various cyber threats, including ransomware and state-sponsored activities, and identifies the dark web as a platform for planning attacks.

Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge
Recorded Future's Insikt Group research team combines human expertise with advanced data analysis to produce actionable cybersecurity intelligence. Their methodology leverages analysts with diverse backgrounds in government and law enforcement, alongside automated tools, to identify and contextualize threats within geopolitical and criminal landscapes. This approach allows them to uncover adversary operations, detect malicious infrastructure, and identify potential victims.

Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup
A polite caller from your bank says there is a problem with your account. Don't worry - they'll send someone round to help. They'll even take your cards away to keep them safe. The scam has run rampant, until Dutch police plastered blurred

AI Creates 457 Million Security Issues for Organizations
A recent 30-day analysis revealed over 457 million AI-related security issues across more than 7,000 organizations, averaging 62,000 exposures per company. These issues are largely due to misconfigurations and unmanaged dependencies, rather than traditional CVEs. The findings highlight the need for comprehensive exposure management programs to address the growing risks posed by both approved and unapproved AI tools.

CERT-In’s AI Vulnerability Blueprint: Why Indian CISOs Need Machine-Speed Risk Operations in the Post-Mythos Era
India's CERT-In has issued a blueprint for cybersecurity operations, emphasizing machine-speed risk management to address the evolving threat landscape driven by AI. The directive mandates a 12-hour containment for known exploited vulnerabilities, a significant acceleration from the current average breach lifecycle. This necessitates a shift towards continuous, automated risk operations centers that can detect, prioritize, validate, and remediate threats rapidly to meet new compliance and security standards.

Weekly Update 509
I know enough about home cinema audiovisual to know there's a lot I don't know. It's conscious incompetence, if you like, which is different to the unconscious incompetence most people have on the topic. That's not to sound derogatory (it's

ZDI-26-397: X.Org Server CreateSaverWindow Use-After-Free Information Disclosure Vulnerability
A local privilege escalation vulnerability has been discovered in X.Org Server, specifically within the handling of ScreenSaverScreenPrivateRec objects. This flaw allows attackers with low-privileged access to disclose sensitive information and potentially execute arbitrary code as root by exploiting the server's failure to validate object existence before operations. An update has been released to address this issue.

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
A campaign dubbed FortiBleed has exposed administrative and VPN credentials for over 73,000 FortiGate systems. The compromised data has been offered for sale by at least two threat actors, one of whom is considered credible by researchers, while the other is suspected of attempting to re-extort victims. The exposed credentials impact organizations across various sectors, including government and critical infrastructure.

OpenClaw Skill Marketplace Faces AI Supply Chain Threat
Researchers have identified malicious skills within OpenClaw's ClawHub marketplace that evade automated detection. These skills are designed to deploy information-stealing malware and conduct automated financial fraud.

macOS Backdoor Uses Fake Messages to Evade AI Analysis
A newly identified Rust implant for macOS, dubbed macOS.Gaslight, employs a novel technique to evade security analysis. It embeds a collection of fabricated system error messages designed to mislead AI-powered triage tools into aborting their analysis. The malware communicates via a Telegram bot and exhibits self-deleting capabilities for its sensitive tokens.

Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The

Miasma Worm Exploits Developer Credentials in Supply Chain Attacks
A sophisticated supply chain attack, dubbed Miasma, has compromised numerous npm packages, including those under the @redhat-cloud-services namespace. Attackers exploited stolen developer credentials, which lingered in underground markets for weeks before being used to poison software packages. The worm also targeted AI coding assistants, expanding its attack surface to local developer environments.

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
Cybercriminals are orchestrating sophisticated, multinational fake online shop operations across Europe, impersonating major brands like Samsung, Nike, and Amazon. These scams leverage social media, WhatsApp, and email to trick consumers into purchasing counterfeit goods, sharing personal information, or falling victim to World Cup-themed promotions. The operations are highly organized, utilizing rotating domains, misleading redirects, and localized content to evade detection and maximize reach.

Hacker hijacks Brazil’s national alert system, sending “misanthropy” to millions of phones
Emergency alert systems work because people believe them. Every time one of these systems issues a false alert - whether through negligence or a deliberate attack - trust erodes. Read more in my article on the Hot for Security blog.

From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AI
Elastic's InfoSec Product Security Team has developed an AI agent capable of generating comprehensive CVE security advisories. This agent utilizes generative AI and Retrieval-Augmented Generation (RAG) against MITRE's CWE and CAPEC databases, ensuring accurate classification and scoring. The process automates the drafting of advisories from raw vulnerability reports, significantly speeding up the disclosure phase.

The Purchase Scam Tactic Headed for the World Cup | Recorded Future
A sophisticated purchase scam is leveraging compromised legitimate websites to trick users searching for event tickets or merchandise. These scam domains are hidden from typical search monitoring, making them difficult to detect and disrupt. The tactic is already being used for World Cup-related fraud and is expected to expand to other large events.