> TODAY'S SUMMARY (101 articles)
Today's cybersecurity news highlights several significant threats and trends. OpenAI has partnered with Ukraine to enhance the cybersecurity of critical infrastructure amid ongoing conflict with Russia. A member of the Ryuk ransomware gang received a two-year prison sentence for extorting over $1.2 million. The ShinyHunters group claims to have breached the FBI, demanding the retraction of a report criticizing their methods. Vulnerabilities in multiple platforms, including GitHub and WordPress, continue to pose risks, with leaked GitHub App keys still being exploited. Additionally, a new Windows malware, CLOSEDQUORUM, utilizes AI models to determine its actions, showcasing the evolving landscape of AI in cyberattacks.
|
// AI-powered summary generated at 16:00
A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as part of a contactless payment fraud scheme.
The purpose-built malware, according to Group-IB, is designed to ca...
Join Rich Frawley of ADF Solutions as he shares practical strategies for managing complex ICAC scenes, prioritizing the devices most likely to contain probative evidence, and making faster, more informed decisions in the field.
WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]
One expert called it a “pretty big shift in U.S. cyber policy,” and there have been reservations in the past about opening the door to private sector involvement in cyber offense.
The post Trump turns to private sector in offensive hacking operations memo appeared first on CyberScoop.
Companies are used to thinking about attackers as outsiders trying to break in.
North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate credentials, and can end up inside the same systems companies spend millions trying to protect.
That risk is no longer t...
The Israeli company has nearly $2 billion in total assets under management since 2014.
The post Venture Firm Team8 Secures Additional $365 Million appeared first on SecurityWeek.
CRM provider confirms customer database was copied and probably downloaded in readable form
Social engineering, a Remote Access Trojan (RAT), and NFC relay malware walk up to an ATM. It's no joke. Together, they can empty your bank account.
This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press.
AI represents the first time we humans can do cognitive work outside of our bodies at scale. The only comparable moment is the early years of the industrial revolution, when new technologies like the steam e...
In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addre...
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance.
The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek.
Searchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to be exploited. Security for the real-time era For decades, security te...
A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attribu...
A step-by-step guide to Google privacy settings on Google Account, Android, and Chrome – and where they have fallen short, cited in lawsuits.
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor North Korea’s Lazarus Group exploited a Windows zero-day in the AFD.sys driver as part of a fresh wave of its long-running Dream Job campaign, targeting defense and aerospace firms in France, Germany, Brazil, and India with...
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
It's the biggest legal challenge yet to addictive social media design and its impact on children.
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements.
The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek.
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests and track colleagues’ cell phones.