llmsmap.ru

Независимый технический аудит

cybernoz.com

cybernoz.com

Итоговая оценка ИИ-оптимизации

Сводный результат по всем сигналам аудита.

89из 100Отлично
Проверка ИИ-оптимизации: 06.09.2026Публичные технические данные

Итоговая оценка ИИ-оптимизации

Насколько cybernoz.com оптимизирован для работы с ИИ

89/100

Cybernoz (cybernoz.com) получил 89/100 по результатам автоматического технического аудита готовности к работе с ИИ. Файл llms.txt доступен, llms-full.txt не найден, ai.txt доступен. Анализ robots.txt показал: явно разрешено ИИ-ботов — 0, заблокировано — 0, объявлено sitemap — 2. Полнота разметки главной страницы — 90%; найдены типы Schema.org: BreadcrumbList, CollectionPage, Organization, WebSite, OpenGraph-тегов — 6. Результаты соответствуют публичным ответам сайта на момент проверки 2026-09-06T00:35:23.151Z.

Контекст итоговой оценки

Файл llms.txt доступен и содержит 136 420 токенов. Расширенный llms-full.txt не найден, поэтому подробный контекст агенту придётся собирать из обычных страниц. Отдельный ai.txt опубликован и задаёт дополнительные правила использования контента.

robots.txt доступен. Из 11 отслеживаемых ИИ-ботов 11 не заблокированы. Объявлено карт сайта: 2. На главной найдена Schema.org-разметка типов BreadcrumbList, CollectionPage, Organization, WebSite; OpenGraph-тегов — 6, расчётная полнота публичной разметки — 90%.

Мобильный профиль Lighthouse дополняет аудит: производительность 63/100, доступность 100/100, технические практики 100/100, SEO 100/100 и экспериментальная готовность браузерных агентов 100/100. Эти данные входят в итоговую оценку ИИ-оптимизации с ограниченным весом: они дополняют, но не заменяют проверку llms.txt, robots.txt и машинной разметки.

Подтверждённые сильные стороны

  • llms.txt доступен
  • Опубликована AI-политика
  • Объявлено sitemap: 2
  • Schema.org: BreadcrumbList, CollectionPage
  • Полная социальная разметка
  • Сильные agentic-сигналы Google

Приоритетные улучшения

  1. 1Добавить llms-full.txt с расширенным контекстом ключевых разделов.
  2. 2Сократить задержки мобильного рендера и занятость основного потока.
Токены llms.txt136 420
Токены llms-full.txt
ai.txt
sitemap.xml

Технический профиль Google Lighthouse

Замер мобильной версии. Экспериментальная категория Google Agentic Browsing показана отдельно и не заменяет итоговую оценку ИИ-оптимизации от llmsmap.

Мобильная версия · Lighthouse
63

Производительность

100

Доступность

100

Технические практики

100

Техническое SEO

100

Работа браузерных агентов

Что означают результаты

Производительность мобильной версии — 63/100; самый крупный видимый блок появился за 7.2 s, а суммарная блокировка основного потока составила 300 ms. Показатель смещения макета — 0. Основной поток выполняет JavaScript, рассчитывает расположение элементов и рисует страницу: пока он занят, интерфейс хуже реагирует и на действия человека, и на команды браузерного агента.

Доступность получила 100/100, технические практики — 100/100, SEO — 100/100. Экспериментальная категория Agentic Browsing получила 100/100. Она отражает сигналы, которые Google сейчас проверяет для программных агентов, и не заменяет итоговую оценку ИИ-оптимизации от llmsmap.

1

Освободить основной поток и ускорить первый экран

Разделите длинные JavaScript-задачи, отложите необязательные скрипты и критические стили, уменьшите цепочки блокирующих запросов. Это ускорит появление основного контента и позволит интерфейсу раньше принимать действия.

2

Сократить код, который загружается без пользы

Удалите неиспользуемые CSS и JavaScript, загружайте тяжёлые виджеты по необходимости и ограничьте сторонние скрипты. Меньший объём кода снижает нагрузку на устройство и количество фоновой работы.

3

Оптимизировать изображения и порядок их загрузки

Отдавайте изображения в подходящем размере и современном формате, заранее приоритизируйте главный визуальный блок, а контент ниже первого экрана загружайте лениво.

4

Сократить сетевые задержки

Уменьшите время ответа сервера, лишние редиректы и повторные загрузки; настройте сжатие, кеширование и ранние соединения только с действительно важными источниками.

FCP3.1 s

Первый контент

LCP7.2 s

Главный блок

CLS0

Стабильность

TBT300 ms

Блокировка

SI3.8 s

Скорость экрана

Расшифровка показателей
FCP · Первый контент
Когда на экране появился первый текст или изображение.
LCP · Главный блок
Когда отрисовался самый крупный видимый элемент первого экрана.
CLS · Стабильность
Насколько сильно элементы неожиданно смещались при загрузке; меньше — лучше.
TBT · Блокировка
Сколько времени основной поток не мог быстро ответить на действие.
SI · Скорость экрана
Насколько быстро видимая область страницы заполнилась контентом.
06.09.2026Lighthouse 13.4.1Мобильный профиль

Проверки ИИ-оптимизации

Машиночитаемые файлы, правила краулинга, обнаружение страниц и разметка главной.

llms.txt

Файл найден и доступен

https://cybernoz.com/llms.txt
llms-full.txt

Полная версия не найдена

ai.txt

Правила для ИИ заданы

https://cybernoz.com/ai.txt
robots.txt

Файл найден

https://cybernoz.com/robots.txt
Sitemap в robots.txt2 шт.

Найдено карт сайта: 2

Schema.org (JSON-LD)

Типы: BreadcrumbList, CollectionPage, Organization, WebSite

OpenGraph90%

Найдено OG-тегов: 6

Доступ ИИ-ботов

На основе анализа robots.txt

GPTBotНе упомянут
OAI-SearchBotНе упомянут
ChatGPT-UserНе упомянут
Google-ExtendedНе упомянут
ClaudeBotНе упомянут
Claude-SearchBotНе упомянут
Claude-UserНе упомянут
BytespiderНе упомянут
CCBotНе упомянут
PerplexityBotНе упомянут
Perplexity-UserНе упомянут

Карты сайта

Объявленные маршруты для поисковых роботов и ИИ-агентов.

OpenGraph теги

Метаданные превью главной страницы для соцсетей и мессенджеров.

Полнота разметки: 90%
og:localeen_US
og:site_nameCybernoz - Cybersecurity News
og:typewebsite
og:titleCybernoz - Cybersecurity News
og:descriptionCyberNoz brings you the latest cybersecurity news, threat intelligence, vulnerability alerts and expert analysis from leading security sources worldwide.
og:urlhttps://cybernoz.com/

Schema.org разметка

Структурированные сущности и свойства, найденные на главной странице.

Найдено типов: 4 · Свойств: 5
BreadcrumbListCollectionPageOrganizationWebSite
nameCybernoz - Cybersecurity News
urlhttps://cybernoz.com/
descriptionCyberNoz brings you the latest cybersecurity news, threat intelligence, vulnerability alerts and expert analysis from leading security sources worldwide.
inLanguageen-US
publisher{"@id":"https://cybernoz.com/#organization"}
Generated by All in One SEO Pro v5.0.1.1, this is an llms.txt file, used by LLMs to index the site.

# Cybernoz

Cybersecurity News

## Sitemaps

- [XML Sitemap](https://cybernoz.com/sitemap.xml): Contains all public & indexable URLs for this website.

## Posts

- [Enhance existing security workflows with high-fidelity cloud security data from Wiz in ServiceNow](https://cybernoz.com/enhance-existing-security-workflows-with-high-fidelity-cloud-security-data-from-wiz-in-servicenow/) - ServiceNow is an essential link for many IT, Configuration Management, Vulnerability Response, Compliance, and Infrastructure teams. ServiceNow customers leverage these modules as the backbone of their IT operations. As they migrate to the cloud they face new challenges like keeping inventory updated with ephemeral workloads and ensuring prioritized security risks are presented with the cloud
- [Unpacking ICEDID | Elastic Security Labs](https://cybernoz.com/unpacking-icedid-elastic-security-labs/) - Preamble ICEDID is a malware family discoveredin 2017 by IBM X-force researchers and is associated with the theft of login credentials, banking information, and other personal information. ICEDID has always been a prevalent family but achieved even more growth since EMOTET’s temporary disruption in early 2021. ICEDID has been linked to the distribution of several
- [Exchange Online outage causes email delays, 'Server busy' errors](https://cybernoz.com/exchange-online-outage-causes-email-delays-server-busy-errors/) - Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. The company first acknowledged this incident (tracked under EX1467029) at 02:19 AM EDT, when it began investigating reports of intermittent "Server busy" errors. "This issue impacts users who may be attempting to send and
- [Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains](https://cybernoz.com/microsoft-confirms-new-exchange-online-outage-delaying-emails-from-external-domains/) - Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users sending and receiving email messages from external domains. The company first acknowledged the disruption on September 4, 2026, flagging it as a service degradation issue affecting Exchange Online, one of the most widely used business email platforms in the world.
- [12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers](https://cybernoz.com/12-year-old-postgresql-flaw-lets-attackers-execute-code-and-take-over-database-servers/) - A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as CVE-2026-6471, the flaw reportedly affected PostgreSQL releases from version 9.4 onward, leaving a dangerous plugin-loading path exposed for roughly 12 years. Cyera Research disclosed the issue on
- [Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://cybernoz.com/unpatched-magento-and-adobe-commerce-zero-day-exploited-to-backdoor-online-stores/) - Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September
- [CIO interview: Frédéric Laurent, deputy CIO, Starling Bank](https://cybernoz.com/cio-interview-frederic-laurent-deputy-cio-starling-bank/) - The idea of having people without formal software development skills being able to use vibe coding to create simple applications is both compelling and a potential nightmare for busy IT departments. The idea of citizen developers is nothing new; Microsoft’s Excel and Word macros have helped people automate repetitive tasks using a relatively simple programming
- [Catch Raises $5 Million for AI Executive Assistant With Guardrails](https://cybernoz.com/catch-raises-5-million-for-ai-executive-assistant-with-guardrails/) - Catch, an agentic admin assistant for leaders, has raised $5 million to accelerate its purpose to solve executives’ daily pain points. The funding was co-led by Entrée Capital and Pitango, with participation from Seedcamp and Factorial Capital. Catch, an AI startup co-founded by Nir Sabato (CEO) and Yoav Ramon (CTO), develops an AI admin assistant
- [PaperCut Flaws Exploited in Attacks on U.S. and European Schools](https://cybernoz.com/papercut-flaws-exploited-in-attacks-on-u-s-and-european-schools/) - PaperCut Flaws Exploited in Attacks on U.S. and European Schools Pierluigi Paganini September 05, 2026 Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education
- [SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts](https://cybernoz.com/sapwned-sap-ai-vulnerabilities-expose-customers-cloud-environments-and-private-ai-artifacts/) - Over the past months, we on the Wiz Research Team have conducted extensive tenant isolation research on multiple AI service providers. We believe these services are more susceptible to tenant isolation vulnerabilities, since by definition, they allow users to run AI models and applications – which is equivalent to executing arbitrary code. As AI infrastructure
- [How to secure edge AI in customer-owned environments](https://cybernoz.com/how-to-secure-edge-ai-in-customer-owned-environments/) - In this article Edge AI moves model execution, model IP, customer data, and system authority into infrastructure the customer owns and operates. That changes who must verify the stack before sensitive assets are released. Edge AI includes AI systems where inference runs on or near the device, sensor, or other local environments where data is
- [Click, Click… Boom! Automating Protections Testing with Detonate](https://cybernoz.com/click-click-boom-automating-protections-testing-with-detonate/) - Preamble Imagine you are an Endpoint artifact developer. After you put in the work to ensure protection against conventional shellcode injections or ransomware innovations, how do you know it actually works before you send it out into the world? First, you set up your end-to-end system, which involves setting up several services, the infrastructure, network
- [Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain](https://cybernoz.com/over-5400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain/) - A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). Over the past months, researchers identified more than 5,400 hacked websites, most of them built on WordPress and PrestaShop. The initial compromise method remains unknown, but each site was injected
- [Hackers Use Invisible Unicode Characters to Evade Phishing Detection in Millions of Emails](https://cybernoz.com/hackers-use-invisible-unicode-characters-to-evade-phishing-detection-in-millions-of-emails/) - Attackers are using invisible Unicode characters to make phishing emails appear harmless while disrupting the security systems built to spot suspicious language. The campaign pushed finance-themed messages at massive scale, showing how a tiny change inside a word can weaken standard filtering. Recipients saw ordinary offers for funding, loans, or credit, but the underlying text
- [Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe](https://cybernoz.com/russian-hackers-deploy-new-hookedge-backdoor-in-espionage-attacks-across-europe/) - Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named HOOKEDGE in espionage operations targeting government, diplomatic, and defense-manufacturing organizations across Europe. The activity, documented by PolySwarm, targeted entities in Romania, Spain, and Turkey between late September 2025 and early April 2026. New variants
- [Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted](https://cybernoz.com/trezor-says-shipmonk-breach-exposed-67000-u-s-customers-data-it-said-was-deleted/) - Ravie LakshmananSep 05, 2026Data Breach / Vulnerability Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach
- [Billion-dollar AWS financial services investment builds on a decade of work](https://cybernoz.com/billion-dollar-aws-financial-services-investment-builds-on-a-decade-of-work/) - Amazon Web Services (AWS) began heavily targeting the financial services sector a decade ago and has transformed its offering in line with a changing sector. Some 10 years ago, the promise of unlimited computing power on a pay-as-you-go basis was a huge differentiator. AWS, as well as a few of its tech hyperscale competitors, enabled
- [Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites](https://cybernoz.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/) - Hackers have been exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant warns. A highly popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installations. Elementor Pro is the paid version that offers additional features, including a Form widget with support for
- [Dark Web Service Nexus Sells 153M+ Driver's Licenses](https://cybernoz.com/dark-web-service-nexus-sells-153m-drivers-licenses/) - Dark Web Service Nexus Sells 153M+ Driver’s Licenses Pierluigi Paganini September 04, 2026 FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans. A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s
- [Your control tower to secure code across GitHub, GitLab, and Azure Repos](https://cybernoz.com/your-control-tower-to-secure-code-across-github-gitlab-and-azure-repos/) - Imagine a control tower that monitors and actively secures your codebase across version control systems (VCS). With Wiz’s latest GitLab and Azure DevOps integrations, you get a unified security solution that protects your code–wherever it lives. In this blog, we’ll dive into how Wiz leverages its Security Graph, ensures comprehensive configuration checks, and advanced code
- [Detect domain generation algorithm (DGA) activity with new Kibana integration](https://cybernoz.com/detect-domain-generation-algorithm-dga-activity-with-new-kibana-integration/) - Searching for a way to help protect your network from potential domain generation algorithm (DGA) attacks? Look no further — a DGA detection package is now available in the Integrations app in Kibana. In a single click, users can install and start using the DGA model and associated assets, including ingest pipeline configurations, anomaly detection
- [OpenAI admits it didn't disclose rogue AI wiki hijacking incident](https://cybernoz.com/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/) - OpenAI has acknowledged that it did not publicly disclose an earlier incident in which its autonomous AI agents took over a German wiki to communicate, share answers, and exchange techniques for bypassing restrictions. The company says it treated the activity as model "misalignment" rather than a security incident, but now admits its disclosure practices must expand
- [Microsoft Teams Desktop Client Fails to Load on Windows System](https://cybernoz.com/microsoft-teams-desktop-client-fails-to-load-on-windows-system/) - Microsoft is investigating an ongoing issue causing some Windows users to face significant delays or outright failures when launching the Microsoft Teams desktop client. The company acknowledged the problem, tracked internally as TM1466820, and confirmed it remains unresolved as engineers continue digging through service logs to find a root cause. According to Microsoft’s incident notice,
- [OpenAI Agents Hacked Another Website](https://cybernoz.com/openai-agents-hacked-another-website/) - After reporting last week that the surveillance company Flock Safety is building an AI search tool for law enforcement, WIRED reconstructed Flock’s latest search tool from code that the company sends to a police officer’s browser and uncovered key details about how the tool works.OpenAI said this week that its Astra model, which will have
- [Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security](https://cybernoz.com/chainguard-hits-1-billion-build-manifests-with-ai-powered-software-supply-chain-security/) - Chainguard has surpassed 1 billion container build manifests, doubling production from 500 million in six months as it expands its AI-assisted software supply-chain security platform. The company now maintains more than 3,000 unique container images and 675,000 image versions. The milestone reflects more than raw build volume. Each build manifest represents a newly generated, verifiable
- [New infosec products of the week: September 4, 2026](https://cybernoz.com/new-infosec-products-of-the-week-september-4-2026/) - Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’s AI-powered web application firewall (WAF) is capable in delivering real-time protections because
- [Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel](https://cybernoz.com/thousands-of-openai-agents-quietly-turned-an-abandoned-wiki-into-their-coordination-channel/) - A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of
- [Peer demands action on DWP subpostmaster prosecutions in duty of candour debate](https://cybernoz.com/peer-demands-action-on-dwp-subpostmaster-prosecutions-in-duty-of-candour-debate/) - During a debate on the Public Office (Accountability) Bill, ministers were asked to investigate the delay to the proposed investigation into the 100 subpostmaster convictions that were instigated by the Department of Work & Pensions (DWP). Speaking during a debate on the proposed law that will make a lack of candour, transparency and frankness in
- [12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover](https://cybernoz.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/) - PostgreSQL releases since 2014 contain a severe vulnerability that allows attacker with low privileges to take over databases and servers, cybersecurity firm Cyera reports. An open source relational database system offering support for both relational (SQL) and non-relational (JSON) queries, PostgreSQL is one of the most popular databases, being used by tens of thousands of
- [Google fixes the sixth actively exploited Chrome zero-day of 2026](https://cybernoz.com/google-fixes-the-sixth-actively-exploited-chrome-zero-day-of-2026/) - Google fixes the sixth actively exploited Chrome zero-day of 2026 Pierluigi Paganini September 04, 2026 Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8
- [Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers](https://cybernoz.com/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers/) - “While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the company said in a blog post. The company has provided detection coverage, IOCs, hunting queries, and mitigation and response
- [OSPAR 2026 report now available with 167 services in scope](https://cybernoz.com/ospar-2026-report-now-available-with-167-services-in-scope/) - We’re pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider’s Audit Report (OSPAR) assessment on July 29, 2026, in line with the OSPAR version 2.0 framework. The Association of Banks in Singapore (ABS) established the Guidelines on Control Objectives and Procedures for Outsourced Service Providers (ABS Guidelines) to
- [Forget vulnerable drivers - Admin is all you need](https://cybernoz.com/forget-vulnerable-drivers-admin-is-all-you-need/) - Introduction Bring Your Own Vulnerable Driver (BYOVD) is an increasingly popular attacker technique wherein a threat actor brings a known-vulnerable signed driver alongside their malware, loads it into the kernel, then exploits it to perform some action within the kernel that they would not otherwise be able to do. After achieving kernel access, they may
- [39 New Methods That Compromise Passkey Authentication](https://cybernoz.com/39-new-methods-that-compromise-passkey-authentication/) - Passkeys were introduced with a strong security proposition. Replace passwords with public key cryptography, bind the credential to the legitimate service, keep the private key away from the server, and many of the phishing and credential theft attacks that have plagued enterprise security for decades become dramatically harder. All of that is true. But the
- [AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials](https://cybernoz.com/ai-agents-breach-company-network-in-under-10-hours-and-steal-root-credentials/) - A human attacker armed with frontier artificial intelligence models breached an enterprise network and seized root credentials in under 10 hours, a timeline that would normally take human red teams roughly two weeks to complete, according to a new incident response report from Palo Alto Networks’ Unit 42. The threat actor told Unit 42 investigators
- [Protecting Against Zero-Click Attacks - IT Security Guru](https://cybernoz.com/protecting-against-zero-click-attacks-it-security-guru/) - By Aimee Steele, threat intelligence analyst at Talion Cyber Security Last month, the UK’s National Cyber Security Centre (NCSC) issued an advisory around a new phishing campaign targeting organisations in the West that was being carried out by the Russian state-sponsored threat actor known as Laundry Bear. The campaign, saw the threat actors exploiting a
- [New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption](https://cybernoz.com/new-panzer-ransomware-hits-16-victims-across-11-countries-with-data-theft-and-encryption/) - Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data theft with file encryption. Documented by CyberXtron, its dedicated leak site was first observed active on August 5, 2026, and its early victim list includes organizations in technology, manufacturing, government, agriculture, energy, education, and retail.
- [Most of the bugs Claude Mythos found have never been checked by a human](https://cybernoz.com/most-of-the-bugs-claude-mythos-found-have-never-been-checked-by-a-human/) - Anthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings became published security advisories, with counts current as of May 22, 2026. The other 21,119 candidates have not been reviewed
- [Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws](https://cybernoz.com/plex-urges-immediate-updates-after-patching-multiple-undisclosed-security-flaws/) - Ravie LakshmananSep 04, 2026Vulnerability / Network Security Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are,
- [Data dive: Mapping NHS hyperscaler dependence](https://cybernoz.com/data-dive-mapping-nhs-hyperscaler-dependence/) - Barts Health NHS Trust runs one of London’s largest hospital groups. Its public internet footprint is also the most tangled of any trust in England, with 304 separate DNS records that point to UK-sovereign infrastructure and three US hyperscalers. Computer Weekly’s analysis of those records finds 113 pointing to US-controlled services and 135 to UK-held
- [Sangoma Switchvox Vulnerabilities Exploited in the Wild](https://cybernoz.com/sangoma-switchvox-vulnerabilities-exploited-in-the-wild/) - Threat actors have been exploiting a critical-severity vulnerability in the enterprise VoIP telephony management solution Sangoma Switchvox, Horizon3 and CISA warn. Tracked as CVE-2026-9586 (CVSS score of 9.3) and described as an unauthenticated SQL injection issue, the security defect can be exploited remotely for arbitrary code execution. It resides in an endpoint that processes XML
- [Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities](https://cybernoz.com/broadcom-patches-critical-vmware-workstation-and-fusion-vm-escape-vulnerabilities/) - Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities Pierluigi Paganini September 05, 2026 Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying
- [Government lacks ability to verify AI labs’ claims, experts say](https://cybernoz.com/government-lacks-ability-to-verify-ai-labs-claims-experts-say/) - A new survey of national security practitioners identified a wide range of near- and medium-term AI risks for policymakers to consider. Source link
- [Zero trust has a big AI agent problem ahead](https://cybernoz.com/zero-trust-has-a-big-ai-agent-problem-ahead/) - That means agents will get a mix of “rate limits, transaction boundaries, spend and data budgets, sandboxing, approval gates for high-consequence actions, and immutable activity trails,” Wilkes says. “Most importantly, autonomous systems need quick and confident undo buttons. Type 2 decisions, where the consequences are reversible, are much safer to delegate than Type 1 decisions
- [The Prompt Airlines CTF: Test Your AI Security Skills](https://cybernoz.com/the-prompt-airlines-ctf-test-your-ai-security-skills/) - In this challenge, you'll interact with a chatbot acting as the customer service for the fictional Prompt Airlines. Your goal is to find and exploit vulnerabilities in the AI's logic to trick it into giving you a free flight ticket. The entire challenge is conducted through chatbot interaction - no coding or technical skills required!Each
- [Using LLMs to summarize user sessions](https://cybernoz.com/using-llms-to-summarize-user-sessions/) - Using LLMs to summarize user sessions With the introduction of the AI Assistant into the Security Solution in 8.8, the Security Machine Learning team at Elastic has been exploring how to optimize Security operations with LLMs like GPT-4. User session summarization seemed like the perfect use case to start experimenting with for several reasons: User
- [Microsoft says some users can’t open the Teams desktop client](https://cybernoz.com/microsoft-says-some-users-cant-open-the-teams-desktop-client/) - Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. The company acknowledged this known issue (tracked as TM1466820) at 16:45 EDT on Thursday and advised affected customers to work around it by using the web or mobile platforms. "Specifically,
- [Everything Victims Type and Steal Their Screenshots](https://cybernoz.com/everything-victims-type-and-steal-their-screenshots/) - NodeStealer has returned with a more invasive toolkit. The Python-based information stealer can now record keystrokes, watch copied text, and capture victims’ screens, turning an account-stealing infection into continuous surveillance. The change raises the stakes for people whose browsers hold work, banking, or social-media access. First tracked in 2023, NodeStealer initially focused on sensitive browser
- [Compliance teams have gone continuous, but their evidence-gathering hasn't caught up](https://cybernoz.com/compliance-teams-have-gone-continuous-but-their-evidence-gathering-hasnt-caught-up/) - The perception that compliance is a once-a-year scramble is out of date, according to a new survey of 201 security and compliance practitioners published by Pentest-Tools.com. The research finds that continuous compliance has effectively already arrived inside most organisations, but the automation needed to support it has not. The study, carried out in July 2026
- [NodeStealer Spyware Adds Keylogging, Screenshot Capture and Facebook Data Theft](https://cybernoz.com/nodestealer-spyware-adds-keylogging-screenshot-capture-and-facebook-data-theft/) - A major upgrade to the Python-based NodeStealer malware, transforming the Facebook-focused infostealer into a broader spyware platform capable of logging keystrokes, monitoring clipboard data, capturing screenshots, and harvesting extensive Facebook profile information. The newly observed variant, identified in August 2026, also expands browser and local data theft, using a split Telegram command-and-control (C2) design to
- [OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets](https://cybernoz.com/openai-is-putting-1-billion-behind-daybreak-for-defenders-working-without-enterprise-budgets/) - OpenAI committed $1 billion to subsidize access to its Daybreak cyber models, along with training and technical support, for organizations defending water and wastewater systems, the electric grid, state and local government, community and regional banks, nonprofits, and open-source projects. The company is starting in the United States and intends to extend the offer to
- [New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic](https://cybernoz.com/new-ted-backdoor-hides-inside-victims-own-haproxy-builds-to-intercept-web-traffic/) - A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it
- [Humans have edge over AI in Dutch hacking contest](https://cybernoz.com/humans-have-edge-over-ai-in-dutch-hacking-contest/) - Humans still have the edge over artificial intelligence (AI) in finding software vulnerabilities that criminals can use to breach critical computer defences, according to the security chief preparing a hacking competition for The Hague. The city municipality announced the return of its hacking competition after a two-year hiatus in July, just as US artificial intelligence
- [OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders](https://cybernoz.com/openai-pledges-1-billion-to-bring-frontier-ai-to-critical-infrastructure-defenders/) - Daybreak is OpenAI’s continuously running agentic loop that brings the power of frontier AI to simplify complex security investigations, validation, remediation and reporting. The earlier Daybreak Blue supports common defensive work with OpenAI mainline models; while Daybreak Red gives approved organizations access to specialized cyber models for more sensitive and technically demanding work. The new
- [Cliff's Notes for Everything | Daniel Miessler](https://cybernoz.com/cliffs-notes-for-everything-daniel-miessler/) - There's something really interesting about the connection between reading fiction and working with AI.Why do we read a fiction book?Let's make a list of reasons. And ask some questions.First, are we trying to get to the end of the book? Is that a goal?Or in my robots in the gym language, is this moving work
- [OpenAI pledges $1 billion to provide resources, training for frontline cyber defenders](https://cybernoz.com/openai-pledges-1-billion-to-provide-resources-training-for-frontline-cyber-defenders/) - Amid heightened scrutiny, the company will use frontier AI to help water, power and local government providers fight malicious actors. Source link
- [European parliament members call for slowdown of Serbia’s EU entry over spyware use](https://cybernoz.com/european-parliament-members-call-for-slowdown-of-serbias-eu-entry-over-spyware-use/) - A group of European Parliament representatives are seeking to delay Serbia’s entry into the European Union and send other messages to Belgrade over the government’s usage of spyware. The 29 members of the European Parliament (MEPs) cited a report this week from the SHARE Foundation about spyware found on the phones of Serbian student activists
- [The democratization of cyber warfare — and what it means for CISOs](https://cybernoz.com/the-democratization-of-cyber-warfare-and-what-it-means-for-cisos/) - Democratization of war is not a new trend. The firearm was itself a democratizing technology, dramatically reducing the skill and physical barriers required to inflict lethal force on an adversary — so was the crossbow before that, and others before that. Those technologies enabled new techniques and expanded existing ones, including forms of irregular warfare
- [OpenAI agents discussed ways to escape their sandbox on public wiki](https://cybernoz.com/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/) - Self-identifying OpenAI agents posted 18,000 messages to a public wiki that discussed ways for other agents to bypass security sandbox restrictions during what was likely internal testing designed to gauge the agents’ hacking abilities, researchers said Friday. In all, agents with 3,700 distinct self-given names posted the messages to German site DSEwiki over a six-week
- [Mastering cloud security with custom roles: one more step towards democratization](https://cybernoz.com/mastering-cloud-security-with-custom-roles-one-more-step-towards-democratization/) - In the ever-evolving landscape of cloud security, managing user permissions can be a complex task. Often, you may find yourself granting more permissions than necessary, leading to potential security risks. Additionally, maintaining these complex roles over time and keeping up with changes made by vendors can be daunting. Enter Custom Roles, a new feature by
- [Using LLMs and ESRE to find similar user sessions](https://cybernoz.com/using-llms-and-esre-to-find-similar-user-sessions/) - Using LLMs and ESRE to find similar user sessions In our previous article, we explored using the GPT-4 Large Language Model (LLM) to condense complex Linux user sessions into concise summaries. We highlighted the key takeaways from our experiments, shedding light on the nuances of data preprocessing, prompt tuning, and model parameter adjustments. In the
- [Critical Citrix NetScaler auth bypass now leveraged in attacks](https://cybernoz.com/critical-citrix-netscaler-auth-bypass-now-leveraged-in-attacks/) - Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can allow unprivileged threat actors to bypass authentication remotely when the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy),
- [Hackers Use Popular Messaging Services to Control New Windows Backdoors](https://cybernoz.com/hackers-use-popular-messaging-services-to-control-new-windows-backdoors/) - A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. The tools give attackers a discreet way to run commands, collect system details, and maintain control over compromised devices. The campaign marks a change for the group, which had previously relied
- [Q&A: Dr. Gil Baram - IT Security Guru](https://cybernoz.com/qa-dr-gil-baram-it-security-guru/) - An AI-assisted platform has been used to test whether Viasat’s satellite communications links can meet operational thresholds under interference and adversarial jamming. Announced this month, the work with Atalanta has renewed scrutiny of the vulnerabilities exposed by Russia’s 2022 attack on Viasat’s KA-SAT network, which disrupted communications across Ukraine and several European countries. Gil Baram,
- [OpenAI Agents Collude on Public Wiki to Share Sandbox Bypass and Evasion Techniques](https://cybernoz.com/openai-agents-collude-on-public-wiki-to-share-sandbox-bypass-and-evasion-techniques/) - Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to exchange answers to tasks, inspect their operating environment, and discuss methods to circumvent sandbox controls. This finding, published on September 4 by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas
- [Scammers have figured out the best time to text you](https://cybernoz.com/scammers-have-figured-out-the-best-time-to-text-you/) - The suspicious calls, texts, and DMs you got recently aren’t a coincidence, according to Malwarebytes. Scammers have worked out which platform gets them the best results for each type of con, and they stick to that formula. (Source: Malwarebytes) The company looked at its own threat data collected between April 15 and July 14, 2026,
- [The hidden work of modernizing Malwarebytes](https://cybernoz.com/the-hidden-work-of-modernizing-malwarebytes/) - Most of the work that keeps a security product trustworthy is invisible. Users see a scan complete, a threat blocked, an update applied overnight. They don’t see the platform underneath. Runtimes, managed libraries, native drivers, and Windows requirements must all stay current and work together across millions of endpoints. Our migration to .NET 10 is
- [PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution](https://cybernoz.com/postgresql-fixes-12-year-old-logical-decoding-flaw-enabling-replication-role-code-execution/) - PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11,
- [Digital twins bill to be debated in Parliament](https://cybernoz.com/digital-twins-bill-to-be-debated-in-parliament/) - A bill to crack down on the creation of digital twins of real people by tech companies is to be debated in the House of Commons. Initially proposed by Science, Innovation and Technology Committee chair Dame Chi Onwurah, the Personal Data (Digital Twin) Bill, also known as the ‘There Is Only One Me’ Bill, will
- [State of Security 2026: Cloud Security](https://cybernoz.com/state-of-security-2026-cloud-security/) - The shift to the cloud has relieved organisations of the complexity of managing their own infrastructure, but it has introduced an entirely new set of challenges. As CISOs look out across technology landscapes that span multiple public clouds, hybrid environments, and SaaS providers, they face the need to maintain the security of a complex and
- [HPE Patches Critical RCE Vulnerabilities in AOS-CX](https://cybernoz.com/hpe-patches-critical-rce-vulnerabilities-in-aos-cx/) - Hewlett Packard Enterprise (HPE) has released patches for 34 CVEs in the Aruba Networking ArubaOS-CX (AOS-CX) platform, including critical-severity remote code execution (RCE) flaws. Per HPT’s advisory, more than 150 flaws were resolved in AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181. Many of these bugs are tracked together under single CVEs. Nearly two dozen
- [Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People](https://cybernoz.com/crooks-behind-manchester-airports-group-hack-leaked-data-of-8-8-million-people/) - Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People Pierluigi Paganini September 04, 2026 Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information
- [Socratic AI | Daniel Miessler](https://cybernoz.com/socratic-ai-daniel-miessler/) - So it's an AI that they're allowed to use after they're done doing their work or after they've already gotten to a pretty decent place by themselves.But the trick is that the AI doesn't really provide answers to them. All it does is ask them questions that help illuminate things so that they can do
- [Nvidia’s $12.9B Hugging Face deal could benefit enterprises](https://cybernoz.com/nvidias-12-9b-hugging-face-deal-could-benefit-enterprises/) - The chipmaker’s acquisition could eventually bring additional security resources and model evaluation tools to the platform, according to experts. Source link
- [Bidding war for defunct Spirit Airlines’ employee data will not die](https://cybernoz.com/bidding-war-for-defunct-spirit-airlines-employee-data-will-not-die/) - The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection. AI data company Micro1 has now offered $12.5 million to acquire a trove of the company’s emails, Teams chats, operations and employee productivity data, according to a report by aviation website Simply Flying, It said the data includes about
- [Once popular for attacking AI, ASCII smuggling is embraced by spammers](https://cybernoz.com/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/) - A clever technique used to hide malicious prompts in attacks on AI agents has been adopted by spammers to evade filters on email platforms that are designed to flag unwanted messages used in mass campaigns. The technique is broadly known as ASCII smuggling. It gained attention two years ago as a means of making a
- [Dissecting Gartner’s CNAPP Market Guide – Key Takeaways](https://cybernoz.com/dissecting-gartners-cnapp-market-guide-key-takeaways/) - What differentiates CNAPP offerings? What value do these solutions deliver to security and development teams? How is the CNAPP landscape evolving, and which aspects should cloud security leaders focus on? We believe these questions are the primary focus of the latest Gartner Market Guide for Cloud-Native Application Protection Platforms, which helps security and risk management leaders
- [Streamlining ES|QL Query and Rule Validation: Integrating with GitHub CI](https://cybernoz.com/streamlining-esql-query-and-rule-validation-integrating-with-github-ci/) - One of the amazing, recently premiered 8.11.0 features, is the Elasticsearch Query Language (ES|QL). As highlighted in an earlier post by Costin Leau, it’s a full-blown, specialized query and compute engine for Elasitcsearch. Now that it’s in technical preview, we wanted to share some options to validate your ES|QL queries. This overview is for engineers
- [IDScan sued over alleged data breach affecting 153 million drivers](https://cybernoz.com/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/) - Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver’s licenses. Several law firms, including Markovits, Stock & DeMarco, and Hall Attorneys, have also launched investigations into potential class-action litigation related to the reported security incident at IDScan. Brian Krebs
- [Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally](https://cybernoz.com/microsoft-unveils-project-zenith-windows-pcs-that-can-run-30b-ai-models-locally/) - Microsoft has introduced Project Zenith, a new developer-optimized Windows 11 experience built for a class of high-memory PCs capable of running large AI models directly on-device, marking a significant shift away from cloud-dependent AI development workflows. Announced as a follow-up to commitments made at Build 2026, Project Zenith targets developer-class hardware equipped with at least
- [AI is finding vulnerabilities faster. Who is funding the people expected to fix them?](https://cybernoz.com/ai-is-finding-vulnerabilities-faster-who-is-funding-the-people-expected-to-fix-them/) - Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine source code and identify potential security issues at a scale that would previously have required significant human
- [Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors](https://cybernoz.com/hackers-turn-hivemq-and-element-messenger-into-control-channels-for-windows-backdoors/) - The financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its
- [Early Bird Registration For Black Hat Europe 2026 In London](https://cybernoz.com/early-bird-registration-for-black-hat-europe-2026-in-london/) - Black Hat Europe returns to the Excel in London with a four-day program, Dec. 7-10. The event will open with two-and four-day options of specialized cybersecurity Trainings, with courses of all skill levels. The two-day main conference on Dec. 9 and 10 boasts Briefings featuring the latest in research, developments, and trends in cybersecurity, along with
- [Microsoft Teams is about to make QR code phishing much harder](https://cybernoz.com/microsoft-teams-is-about-to-make-qr-code-phishing-much-harder/) - Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the organization. Users will need to reveal the image first before they can view or scan it. It’s currently in development, with rollout expected to begin
- [X Money rollout linked to password-reset attacks](https://cybernoz.com/x-money-rollout-linked-to-password-reset-attacks/) - X says attackers may be targeting accounts because its X Money payments service is now more widely available. The company is investigating a wave of unsolicited password-reset emails sent to users. While their arrival alongside the wider X Money rollout has fueled account-takeover concerns, X says it has found no evidence of a breach or
- [Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters](https://cybernoz.com/phishing-campaign-sends-millions-of-emails-using-invisible-unicode-to-evade-filters/) - Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft
- [US senator Bernie Sanders calls for ban on AI superintelligence](https://cybernoz.com/us-senator-bernie-sanders-calls-for-ban-on-ai-superintelligence/) - Two more bills seeking to control the spread and activity of artificial intelligence (AI) – one of them by former presidential candidate and Independent senator Bernie Sanders – will go before American lawmakers in the near future. Sanders’ Ban Artificial Superintelligence Act, co-authored by Greg Cesar, a Democratic representative from Texas, will seek to “stop
- [Pegasus, New NoviSpy Variant Found On Serbian Students](https://cybernoz.com/pegasus-new-novispy-variant-found-on-serbian-students/) - At least 14 people connected to Serbia’s student protest movement and opposition politics have been targeted with mercenary spyware since early 2026, the Belgrade-based digital rights organization SHARE Foundation said, in what it called the largest documented wave of such targeting in the country. The group said the cohort includes student movement members, civil society
- [CBI Raids 89 Places Across 20 States In Digital Arrest Cases](https://cybernoz.com/cbi-raids-89-places-across-20-states-in-digital-arrest-cases/) - India’s Central Bureau of Investigation searched 89 locations across 20 states in three digital arrest fraud cases and arrested three people accused of moving the stolen money, the agency said. The searches were conducted under Operation Chakra-VI, the agency’s ongoing cybercrime enforcement programme. All three cases were transferred to the CBI from state police forces.
- [Firmus invests US$300m in SUBCO's APX East](https://cybernoz.com/firmus-invests-us300m-in-subcos-apx-east/) - Key points Firmus Technologies has signed a US$300 million ($416 million) agreement with SUBCO, securing rights to 150Tbps of capacity on the APX East subsea cable system for at least 25 years. APX East is expected to become operational in late 2028 and will be Australia's first direct link to the US, as well as
- [In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation](https://cybernoz.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/) - SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of
- [PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover](https://cybernoz.com/postgresql-hit-by-12-year-old-vulnerability-allowing-server-takeover/) - PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover Pierluigi Paganini September 04, 2026 PostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471 (CVSS score of 7.2). Present in releases dating back to 2014, the
- [FBI investigates breach of 153 million driving license records at IDscan.net](https://cybernoz.com/fbi-investigates-breach-of-153-million-driving-license-records-at-idscan-net/) - Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth – and investigative reporter Brian Krebs, who has dug deep into the data breach on his blog
- [Moscow-based F6 reports manufacturing as top cyberattack target, as 80% of industrial firms face security staffing shortage](https://cybernoz.com/moscow-based-f6-reports-manufacturing-as-top-cyberattack-target-as-80-of-industrial-firms-face-security-staffing-shortage/) - Data from Russian cybersecurity firm F6 identified that manufacturing is the top target for cyberattacks in 2026, while about 80% of companies, including critical information infrastructure facilities, face a shortage of qualified information security personnel. It revealed that filling a single cybersecurity vacancy can take several months, while building a 24/7 security team from scratch
- [Cognizant, CrowdStrike expand collaboration with OT cybersecurity service for converged IT and OT environments](https://cybernoz.com/cognizant-crowdstrike-expand-collaboration-with-ot-cybersecurity-service-for-converged-it-and-ot-environments/) - Cognizant and CrowdStrike announced an expanded collaboration to introduce Cognizant Cybersecurity for Operational Technology, an OT (operational technology) security service powered by CrowdStrike Falcon for XIoT. The service combines Cognizant’s industrial engineering expertise and managed security operations with CrowdStrike’s unified visibility and protection across XIoT and IT environments designed to help protect mission-critical assets. As
- [Wiz's Approach to Physical Security & Enterprise Resilience](https://cybernoz.com/wizs-approach-to-physical-security-enterprise-resilience/) - In this blog we’ll look at how our internal Wiz team secures not just the digital realm but the physical one as well, as it’s a core part of our commitment to earning the trust of our customers, partners, and Wizards. Physical security at Wiz means ensuring the safety of our people and safeguarding our
- [Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization](https://cybernoz.com/recorded-future-announces-automated-signature-creation-accelerating-vulnerability-prioritization/) - Today, Recorded Future is announcing Automated Signature Creation, a new capability in Attack Surface Intelligence (ASI) to combat the speed of AI-generated exploits. ASI continuously maps an organization’s external exposure, correlates newly surfaced vulnerabilities with real-world threat intelligence, and prioritizes response to enable defenders to remediate before adversaries can act. This new function within ASI
- [SIEM data export: how six vendors compare](https://cybernoz.com/siem-data-export-how-six-vendors-compare/) - Your security data is the most important asset in your SOC. Not the dashboards, not the detections, not the AI features on the roadmap slide. The data. And most vendors make you pay, wait, or license your way to getting it back out. Every investigation your analysts run, every model you train, every agent you
- [New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges](https://cybernoz.com/new-crowdstrike-falconflank-zero-day-grants-system-privileges/) - An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. Nightmare Eclipse says the new vulnerability (which has yet to be assigned a CVE ID) affects devices running the latest versions of Windows 11 and Windows Server, as
- [Hackers Turn Claude, Qwen and DeepSeek Into AI Agents for Real-World Cyberattacks](https://cybernoz.com/hackers-turn-claude-qwen-and-deepseek-into-ai-agents-for-real-world-cyberattacks/) - Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign paired AI-directed tasking with familiar methods such as vulnerable public-facing servers, stolen credentials, webshells, and custom remote-access malware. The operation reached Taiwan’s Kuomintang Party History Archives, Indonesia’s Ministry of Foreign Affairs, and government and education networks in mainland China. A
- [KnowBe4 to Put AI Trust to the Test at Leeds Digital Festival](https://cybernoz.com/knowbe4-to-put-ai-trust-to-the-test-at-leeds-digital-festival/) - KnowBe4 is set to explore the growing challenge of determining what organisations can trust in the age of AI at an exclusive cybersecurity briefing during Leeds Digital Festival 2026. Taking place on 1 October, CyberSecure Leeds: Who Do You Trust Now? Human Judgement in the Age of AI will examine how the growing role of
- [ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years](https://cybernoz.com/ice-wants-to-know-everyone-who-bought-a-certain-green-beanie-from-rei-in-the-last-2-years/) - Did you buy a beanie from REI recently? The Department of Homeland Security might be looking for you.New court filings allege that Homeland Security Investigations agents subpoenaed the outdoor retailer in March, requesting the transaction information for “all persons” in the greater Minneapolis–St. Paul area who had purchased a specific type of dark green beanie
- [ShipMonk Data Breach Exposes Personal Data of 67,000 Additional Trezor Customers](https://cybernoz.com/shipmonk-data-breach-exposes-personal-data-of-67000-additional-trezor-customers/) - Trezor has revealed that a data breach involving its fulfillment provider, ShipMonk, exposed personal and order information of approximately 67,000 additional US customers. This significantly broadens the scope of an incident initially reported in August. The newly identified data pertains to Trezor orders processed during a prior partnership with ShipMonk, which lasted from November 2019
- [Google patches actively exploited Chrome zero-day (CVE-2026-85046)](https://cybernoz.com/google-patches-actively-exploited-chrome-zero-day-cve-2026-85046/) - Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thursday security advisory. The fix has been shipped in Chrome 152.0.7977.82/.83 for Windows and macOS and Chrome 152.0.7977.82
- [Free streaming boxes may be routing criminal traffic through your home](https://cybernoz.com/free-streaming-boxes-may-be-routing-criminal-traffic-through-your-home/) - “Free” movies and TV could cost you your privacy, bandwidth, and control of your home network. We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain SuperBox devices and apps could quietly enroll a household connection into a proxy network, allowing third parties to route
- [Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws](https://cybernoz.com/over-440000-exploit-attempts-target-super-forms-and-elementor-pro-rce-flaws/) - Ravie LakshmananSep 04, 2026Vulnerability / Web Security Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that
- [Snowflake pivots to AI platforming](https://cybernoz.com/snowflake-pivots-to-ai-platforming/) - Artificial intelligence (AI) has moved past the initial stages of the gold rush. In a scramble to avoid getting lost in the noise surrounding the generative AI hyperbole, IT suppliers hurried to extol the virtues of their data-enabled products. Now, following that first stage of the gold rush, technology companies are focused squarely on stage
- [The Cyber Express Weekly Roundup: Claude, PaperCut & Citrix](https://cybernoz.com/the-cyber-express-weekly-roundup-claude-papercut-citrix/) - This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure. From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and
- [Tabcorp appoints new CISO - iTnews](https://cybernoz.com/tabcorp-appoints-new-ciso-itnews/) - Key points Tabcorp has named Maxine Harrison as its new chief information security officer, following the former leader's departure in July. Harrison most recently served as CISO at the Victorian Government's Department of Energy, Environment and Climate Action for almost three-and-a-half years. She replaces Josh Kam, who held the CISO role before becoming chief security
- [VMware Workstation and Fusion Updates Patch Critical Vulnerability](https://cybernoz.com/vmware-workstation-and-fusion-updates-patch-critical-vulnerability/) - Broadcom on Thursday announced patches for two critical and high-severity vulnerabilities in VMware Workstation and Fusion. The first issue, tracked as CVE-2026-59346 (CVSS score of 9.3), is described as an integer overflow bug leading to arbitrary code execution. “A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may
- [Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign](https://cybernoz.com/chinese-hackers-use-ai-agents-in-multi-country-cyber-campaign/) - Chinese Hackers Use AI Agents in Multi-Country Cyber Campaign Pierluigi Paganini September 04, 2026 Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into live cyberespionage operations, this time hitting
- [Why judgment is emerging as cybersecurity’s defining skill](https://cybernoz.com/why-judgment-is-emerging-as-cybersecuritys-defining-skill/) - AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on. Reaching a technically sound recommendation is also getting easier, which puts more weight on
- [Why less visibility into how OpenAI’s new GPT-6 Astra ‘thinks’ is sparking safety concerns](https://cybernoz.com/why-less-visibility-into-how-openais-new-gpt-6-astra-thinks-is-sparking-safety-concerns/) - OpenAI’s new model, GPT-6 Astra, has less direct visibility into how a model thinks, a development that has sparked concerns coming just weeks after the Hugging Face hacking incident that required a Chinese open model to investigate, according to analysts.When announcing Astra on Thursday, OpenAI said it was “the world’s most intelligent and aligned model,”
- [ACSC warns of critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway](https://cybernoz.com/acsc-warns-of-critical-vulnerabilities-in-citrix-netscaler-adc-and-netscaler-gateway/) - The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has issued a critical alert for Australian organisations using Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products, warning of two vulnerabilities and urging rapid patching. In an alert dated 4 September 2026, the ACSC said Citrix had identified the issues in NetScaler ADC
- [New backdoors from Toy Ghouls](https://cybernoz.com/new-backdoors-from-toy-ghouls/) - Introduction We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom
- [OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold](https://cybernoz.com/openai-launches-gpt-6-astra-its-first-model-to-cross-a-critical-cybersecurity-threshold/) - Developers can access Astra in the API as gpt-6-astra or through Amazon Bedrock, OpenAI said, priced at $10 per million input tokens and $50 per million output tokens. Pro, Business, and Enterprise users also get a variant called Astra Pro, and the company said Astra supports Zero Data Retention for eligible API customers. Company claims
- [Booz Allen: AI models approaching autonomous cyberattack capability as critical infrastructure response windows narrow](https://cybernoz.com/booz-allen-ai-models-approaching-autonomous-cyberattack-capability-as-critical-infrastructure-response-windows-narrow/) - New research from Booz Allen found that testing of 18 U.S. and Chinese frontier AI models revealed that AI (artificial intelligence) is nearing the ability to conduct cyberattacks autonomously, raising concerns for critical infrastructure operators facing increasingly narrow windows to detect and respond to intrusions. The company’s Cyber Weapon Index found that one model, Anthropic’s
- [G7 urges governments, organizations to begin PQC transition, protect public key encryption from quantum threats](https://cybernoz.com/g7-urges-governments-organizations-to-begin-pqc-transition-protect-public-key-encryption-from-quantum-threats/) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the G7 Cybersecurity Working Group are urging governments and organizations to immediately begin transitioning to post-quantum cryptography, warning that quantum computing poses an urgent threat to current public-key encryption systems. The document focuses on risks posed by cryptographically relevant quantum computers (CRQCs), reaffirming collective efforts to
- [Introducing pattern-based agentless malware detection using YARA rules](https://cybernoz.com/introducing-pattern-based-agentless-malware-detection-using-yara-rules/) - Malware poses a critical threat to cloud environments, facilitating malicious activity by threat actors that results in compromise, data breach, or disruption in operations. According to SonicWall, there were 6.06 billion malware attacks in 2023, marking the highest global attack volume since 2019. That is why it is crucial to have malware scanning in place
- [STIXy Situations: ECSaping your threat data](https://cybernoz.com/stixy-situations-ecsaping-your-threat-data/) - Preamble Organizations that use threat indicators or observables consume, create, and/or (ideally) publish threat data. This data can be used internally or externally as information or intelligence to inform decision-making and event prioritization. While there are several formats for this information to be structured into, the de facto industry standard is Structured Threat Information Expression
- [Microsoft: KB5120998 mouse reset bug affects only non-English PCs](https://cybernoz.com/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/) - Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. The bug was confirmed Friday, one day after the KB5120998 release, which includes Start menu, taskbar, and Windows search improvements for devices running Windows 11 versions 25H2 and 24H2. According to user
- [14 Fake macOS Installers Linked to DPRK Campaign Deliver Credential-Stealing RAT](https://cybernoz.com/14-fake-macos-installers-linked-to-dprk-campaign-deliver-credential-stealing-rat/) - Mac users are being targeted with 14 fake application installers that appear to offer familiar software but instead start a credential-stealing remote-access trojan. The files were distributed as macOS disk images and installer packages, giving attackers another route into systems used by developers and job seekers. The activity is tied to the long-running Contagious Interview
- [Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials](https://cybernoz.com/microsoft-365-direct-send-bypass-lets-attackers-spoof-internal-users-without-credentials/) - A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulnerability in Microsoft software or in ReliaQuest systems; instead, it exposes a limitation in how the control evaluates Direct Send traffic.
- [A five-part inventory for your AI agent credentials](https://cybernoz.com/a-five-part-inventory-for-your-ai-agent-credentials/) - In this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build agents in AI studios, connect them to enterprise tools, and give them accounts to do useful work. The agent is approved, the studio is approved, but the identities behind them sit
- [US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries](https://cybernoz.com/us-becomes-top-target-in-rmm-phishing-campaign-spanning-46-countries/) - The Hacker NewsSep 03, 2026Social Engineering / Malware An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making
- [Oracle executive chairman Larry Ellison called to testify over US health system overspend](https://cybernoz.com/oracle-executive-chairman-larry-ellison-called-to-testify-over-us-health-system-overspend/) - The US House Committee for Veterans’ Affairs (VA) has unanimously passed a motion that will mean Oracle executive chairman and chief technology officer, Larry Ellison, and the company’s current CEO, Mike Sicilia, will be called to testify over overspend on a major electronic healthcare records system. Wednesday’s House Committee on Veterans’ Affairs oversight hearing on
- [Citrix NetScaler Vulnerabilities Prompt Patch Warning](https://cybernoz.com/citrix-netscaler-vulnerabilities-prompt-patch-warning/) - Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority. Citrix has identified
- [Kentucky Appellate Court Data Compromised In C-Track Breach](https://cybernoz.com/kentucky-appellate-court-data-compromised-in-c-track-breach/) - The Kentucky Administrative Office of the Courts (AOC) has confirmed that Kentucky Appellate Court data was compromised in a cybersecurity breach traced to a third-party vendor. West Publishing Corporation, operating as Thomson Reuters Court Management Solutions (Thomson Reuters CMS), informed the AOC that the incident originated within file systems tied to its C-Track case management
- [Coles to end data analytics work with Palantir](https://cybernoz.com/coles-to-end-data-analytics-work-with-palantir/) - Key points Coles Group is ending its three-year data and analytics partnership with Palantir Technologies, which covered rostering, store operations and supply chain planning across more than 840 stores. Advocacy group GetUp! claimed the cessation as a win for a year-long campaign, which gathered 86,000 petition signatures over ethics and surveillance concerns. Coles disputed characterisations
- [HiddenLayer Raises $100 Million for AI Runtime Security](https://cybernoz.com/hiddenlayer-raises-100-million-for-ai-runtime-security/) - AI security company HiddenLayer on Wednesday announced raising $100 million in a Series B funding round that brings the total raised by the company to over $155 million. Founded in 2022, Austin-based HiddenLayer secures the lifecycle of agentic, generative, and predictive AI applications, protecting agents from evolving threats. The company’s enterprise platform provides discovery, AI
- [2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators](https://cybernoz.com/2000-leaked-documents-reveal-how-russia-turns-engineering-students-into-gru-cyber-operators/) - 2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators Pierluigi Paganini September 03, 2026 2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the
- [Peak Human Readership | Daniel Miessler](https://cybernoz.com/peak-human-readership-daniel-miessler/) - We may have already passed the point where most humans read anything that takes real focusSeptember 3, 2026by Daniel Miessler Fascinating-ing…Struck by kind of a weird feeling.I feel like people who write or create art or basically produce content for humans to read might be very sad soon.I think there's a good chance that we've already
- [CISO vs. CSO: Rethinking cybersecurity leadership](https://cybernoz.com/ciso-vs-cso-rethinking-cybersecurity-leadership/) - That creates a powerful combination. The CSO provides the top-down, cross-functional influence. The CISO provides the technical depth and delivery capability. Neither role has to pretend to be the other, and together, they can create something that the current model often struggles to provide: Executive ownership of the business protection agenda combined with genuine technical
- [Celebrating a Milestone: 100 WIN Integrations and Counting!](https://cybernoz.com/celebrating-a-milestone-100-win-integrations-and-counting/) - As an open security platform, integrations are a cornerstone of Wiz and the modern cloud security operating model that our CNAPP enables. They are essential for reducing risk, improving efficiency, and fostering an open cloud security ecosystem. That's why, about a year ago, we launched the Wiz Integration (WIN) platform to enable Independent Software Vendors
- [Unveiling malware behavior trends | Elastic Security Labs](https://cybernoz.com/unveiling-malware-behavior-trends-elastic-security-labs/) - Preamble When prioritizing detection engineering efforts, it's essential to understand the most prevalent tactics, techniques, and procedures (TTPs) observed in the wild. This knowledge helps defenders make informed decisions about the most effective strategies to implement - especially where to focus engineering efforts and finite resources. To highlight these prevalent TTPs, we analyzed over 100,000
- [Coder's registry infrastructure compromised to push malicious modules](https://cybernoz.com/coders-registry-infrastructure-compromised-to-push-malicious-modules/) - Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. The Coder platform enables organizations to provide developers with secure, self-hosted cloud development environments for building and deploying software, including AI applications. The project is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz,
- [OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits in Cyber Tests](https://cybernoz.com/openai-gpt-6-astra-discovers-zero-day-flaws-and-builds-working-exploits-in-cyber-tests/) - OpenAI has unveiled GPT-6 Astra, a frontier AI model the company says can identify zero-day vulnerabilities and create working proof-of-concept exploits during authorized cybersecurity tests. Announced on September 3, 2026, the model’s release brings offensive-security automation into sharper focus as AI systems gain stronger computer-use, browsing, and software-engineering capabilities. Astra achieved a reported 100% score
- [Prediction Market Betting Is Getting People Banned and Arrested](https://cybernoz.com/prediction-market-betting-is-getting-people-banned-and-arrested/) - Leah Feiger: All right. Do you guys remember George Santos?Brian Barrett: How could I forget?Zoë Schiffer: Absolutely do, but wow, did not expect we would be talking about him again this soon, I have to say.Leah Feiger: Former US representative expelled from Congress in 2023, accused of fraud and theft, and doing it with such
- [Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems](https://cybernoz.com/rogue-screenconnect-clients-spread-worm-like-malware-across-connected-windows-systems/) - A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can automatically push a multi-stage VBScript malware chain to newly connected Windows endpoints. Once deployed, the clients repeatedly spawned wscript.exe to execute four scripts 1.vbs, 2.vbs, 3.vbs, and 4.vbs from ScreenConnect-related temporary locations. The behavior is
- [Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms](https://cybernoz.com/researchers-built-a-7-gadget-for-anyone-paranoid-about-hidden-cameras-in-hotel-rooms/) - Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Institute of Science and Technology (KAIST), working
- [Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data](https://cybernoz.com/thomson-reuters-court-software-breach-may-have-exposed-ssns-and-sealed-data/) - Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of
- [Interview: Oracle accelerates Middle East cloud expansion as demand for sovereign AI rises](https://cybernoz.com/interview-oracle-accelerates-middle-east-cloud-expansion-as-demand-for-sovereign-ai-rises/) - As governments and enterprises across the Middle East adopt artificial intelligence (AI) at pace, cloud providers are increasingly being asked to deliver more than infrastructure. Organisations want access to advanced AI capabilities while maintaining control over data, meeting regulatory requirements and ensuring compliance with national sovereignty frameworks. For Oracle, this shift is shaping its investment
- [IAG builds AI into its HR service delivery](https://cybernoz.com/iag-builds-ai-into-its-hr-service-delivery/) - Key points IAG has moved from ServiceNow's conversational chatbot to its Now Assist AI suite to boost self-service deflection rates for HR queries. The insurer is reformatting about 730 HR knowledge base articles to be AI-optimised, with the work due to wrap up in September. Now Assist-based virtual agents delivered an average 67 percent deflection
- [Capsule Security Launches 'AI Circuit Breaker' to Stop Rogue Agents](https://cybernoz.com/capsule-security-launches-ai-circuit-breaker-to-stop-rogue-agents/) - Providing security against anomalous autonomous agents requires instantaneous detection, evaluation and action – a circuit breaker for AI rather than a circuit breaker for electricity. Such a ‘device’ has now been developed and released by Capsule Security. The firm was founded in 2025 by Naor Paz (CEO) and Lidan Hazout (CTO). They had seen how
- [Cisco Fixed Critical RCE in Nexus 9000 Series Switches](https://cybernoz.com/cisco-fixed-critical-rce-in-nexus-9000-series-switches/) - Cisco Fixed Critical RCE in Nexus 9000 Series Switches Pierluigi Paganini September 03, 2026 Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could
- [Attackers exploit zero-days in consistently besieged SonicWall product](https://cybernoz.com/attackers-exploit-zero-days-in-consistently-besieged-sonicwall-product/) - SonicWall customers are grappling with yet another pair of actively exploited zero-day vulnerabilities in SonicWall SMA 1000 appliances, a product that’s been besieged with recurring defects and attacks over the past nine months. The vendor disclosed and released patches for the defects — CVE-2026-83548 and CVE-2026-83549 — and noted both were already actively exploited in
- [US urged to consider military strikes to stop China achieving AGI first](https://cybernoz.com/us-urged-to-consider-military-strikes-to-stop-china-achieving-agi-first/) - The United States should start preparing for scenarios where extreme measures must be taken to stop China from achieving artificial general intelligence (AGI), according to a former White House official, including state-backed espionage and military strikes on Chinese data centres.Jacob Stokes, deputy director of the Indo-Pacific Security Program at the Centre for a New American
- [Privacy reform is coming: Why businesses should act now, not after the Bill passes](https://cybernoz.com/privacy-reform-is-coming-why-businesses-should-act-now-not-after-the-bill-passes/) - The Attorney-General’s exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 would bring the most significant changes to the Privacy Act 1988 since the introduction of the Australian Privacy Principles, according to Holding Redlich General Counsel Lyn Nicholson. In comments provided to MySecurity Media, Nicholson said the reform direction is clear even if
- [OpenAI targets small utilities with $1 billion cyber defense initiative](https://cybernoz.com/openai-targets-small-utilities-with-1-billion-cyber-defense-initiative/) - Company CEO Sam Altman was in North Carolina yesterday, where he highlighted how OpenAI is partnering with cyber defenders to protect systems and services North Carolinians rely on. Last week, OpenAI led a coalition of now more than 150 organizations across cybersecurity, technology, critical infrastructure, finance, and AI in a call for collective action to
- [Confused about which VPN is right, US senator asks the NSA for guidance](https://cybernoz.com/confused-about-which-vpn-is-right-us-senator-asks-the-nsa-for-guidance/) - A prominent US senator is asking the National Security Agency to provide guidance to the general public on best practices for using virtual private networks to secure their communications from spying by foreign adversaries. VPNs funnel all of a user’s Internet traffic through an encrypted connection to a remote server. The design provides strong assurances
- [Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak Models](https://cybernoz.com/introducing-context-aware-vulnerability-discovery-and-remediation-with-cloudflare-managed-defense-and-openai-daybreak-models/) - Your scanner just flagged 4,000 new vulnerabilities, 78 of them critical. Which one do you fix first?To answer that question, Cloudflare is announcing early access to Vulnerability Discovery and Remediation, now part of Cloudflare Managed Defense. Vulnerability Discovery and Remediation is a new, invitation-only Cloudflare service that helps customers detect and mitigate vulnerabilities in their
- [Kernel ETW is the best ETW](https://cybernoz.com/kernel-etw-is-the-best-etw/) - Preamble A critical feature of secure-by-design software is the generation of audit logs when privileged operations are performed. These native audit logs can include details of the internal software state, which are impractical for third-party security vendors to bolt on after the fact. Most Windows components generate logs using Event Tracing for Windows (ETW). These
- [French hospital fined €500,000 after breach exposes data of 727,000](https://cybernoz.com/french-hospital-fined-e500000-after-breach-exposes-data-of-727000/) - France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. The French agency says that the security failures led to a data breach in the summer of 2025, exposing sensitive data belonging to 524,867 patients and another 202,246 people designated as
- [Nobody Is Saying Why OpenAI and Anthropic Had Outages Today](https://cybernoz.com/nobody-is-saying-why-openai-and-anthropic-had-outages-today/) - Frontier models from Anthropic, OpenAI, and xAI all experienced rare outages on Thursday morning, creating downtime for their corresponding AI chatbots. SpaceX, xAI’s parent company, said on Thursday afternoon that the issues with Grok resulted from “an outage at our Memphis compute center this morning.”The issues initially appeared to be linked because they coincided—perhaps the
- [Fake Acquisition Scam Uses Forged NDAs to Demand €626,000 Corporate Payment](https://cybernoz.com/fake-acquisition-scam-uses-forged-ndas-to-demand-e626000-corporate-payment/) - Threat actors impersonated Gen executives and major consulting firms in a targeted business email compromise-style operation that used forged non-disclosure agreements to isolate a legal employee and pressure the company into transferring €626,735.45 to a Hong Kong entity. Dubbed Phantom Deal, the campaign shows how financially motivated actors can abuse legitimate M&A processes, corporate history
- [Google’s Gemini 3.8 Flash takes on bigger AI models at a lower cost](https://cybernoz.com/googles-gemini-3-8-flash-takes-on-bigger-ai-models-at-a-lower-cost/) - Google has introduced Gemini 3.8 Flash, available to developers today, and a gated sibling, Gemini 3.8 Flash Cyber, reserved for vetted security teams. “Our 3rd Flash release in just 6 wks,” Google CEO Sundar Pichai said on X, adding that it makes sizable gains over 3.7 Flash in software engineering, agentic work, and multi-step reasoning.
- [BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory](https://cybernoz.com/brazetsu-malware-turns-compromised-windows-hosts-into-criminal-marketplace-inventory/) - Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial assets," Group-IB malware analysts Julio Guapo
- [New York City to ban children’s use of GenAI tools in school](https://cybernoz.com/new-york-city-to-ban-childrens-use-of-genai-tools-in-school/) - New York mayor Zohran Mamdani has imposed a city-wide moratorium on student-facing generative artificial intelligence (GenAI) for the next 12 months, which will affect almost 600,000 children up to the Eighth Grade (Year 9), alongside education on AI usage for high school students. Described as the most expansive student-facing AI moratorium in the United States, the
- [Nvidia buys Hugging Face in US$13 billion deal](https://cybernoz.com/nvidia-buys-hugging-face-in-us13-billion-deal/) - Nvidia will buy popular developer platform Hugging ⁠Face for US$12.93 billion ($17.96 billion), ⁠using its growing AI war chest to expand its influence in the booming market for open-source models that can nearly match the best from OpenAI and Anthropic at lower costs. The deal, one of Nvidia's biggest ever, will bring the chip giant
- [Pegasus and NoviSpy Used Against Serbian Protesters](https://cybernoz.com/pegasus-and-novispy-used-against-serbian-protesters/) - Pegasus and NoviSpy Used Against Serbian Protesters Pierluigi Paganini September 03, 2026 Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file.
- [The G7 tells industry to hurry up and prep for post-quantum encryption](https://cybernoz.com/the-g7-tells-industry-to-hurry-up-and-prep-for-post-quantum-encryption/) - A cybersecurity working group at the G7 is urging governments to accelerate defenses against quantum computers that could break some existing forms of public key encryption. The working group’s report, prepared in June at the G7 Summit in France, said organizations “can no longer afford to postpone” work transitioning critical systems and data to “post-quantum”
- [China-Singapore security team claims breakthrough in hacking Starlink terminals](https://cybernoz.com/china-singapore-security-team-claims-breakthrough-in-hacking-starlink-terminals/) - A team of cybersecurity experts has announced they successfully compromised the latest Starlink user terminals, crossing the security boundaries of the world’s largest satellite constellation.In a post on its social media account on Tuesday, Darknavy, an independent cybersecurity research institute headquartered in Singapore and Shanghai, said it had used sophisticated hardware attacks to gain full
- [Counterfeit installers turn routine software downloads into enterprise breaches](https://cybernoz.com/counterfeit-installers-turn-routine-software-downloads-into-enterprise-breaches/) - Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access. “Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure,” Microsoft security researchers wrote in a blog post.
- [Abliteration.ai is making a business out of removing AI guardrails](https://cybernoz.com/abliteration-ai-is-making-a-business-out-of-removing-ai-guardrails/) - Most of the experts TechCrunch spoke to say there’s no stopping this train. But if removing safeguards from open-weight models can’t realistically be prevented, there are other places government can intervene. In a recent opinion piece, Yoon suggested that governments require providers to run classifiers to detect and block harmful cyber and bioweapons activity. He
- [Wizlympics: The First Cloud Security Olympic Games](https://cybernoz.com/wizlympics-the-first-cloud-security-olympic-games/) - Welcome to Wizlympics, the first Cloud Security Olympic Games where cloud enthusiasts and security experts can showcase their skills by distinguishing between real and fake cloud services. Ready to participate in the Wizlympic games? Play nowMeet our sporty Wiz Sensor! Our Sensor is a star player, scanning your cloud environment and intercepting threats. Use the
- [Elevate Your Threat Hunting with Elastic](https://cybernoz.com/elevate-your-threat-hunting-with-elastic/) - We are excited to announce a new resource in the Elastic Detection Rules repository: a collection of hunting queries powered by various Elastic query languages! These hunting queries can be found under the Hunting package. This initiative is designed to empower our community with specialized threat hunting queries and resources across multiple platforms, complementing our
- [HPE patches critical ArubaOS-CX remote code execution flaw](https://cybernoz.com/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/) - Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. Tracked as CVE-2026-73749, the security issue is a buffer overflow that allows unauthenticated remote attackers to send specially crafted packets to an affected daemon process, achieving code execution with elevated privileges. “Multiple vulnerabilities
- [LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access](https://cybernoz.com/llmjacking-attack-uses-leaked-aws-iam-key-to-steal-paid-ai-model-access/) - A newly documented cloud intrusion shows how quickly attackers can turn a single leaked AWS credential into a revenue stream by hijacking access to premium AI models, a technique researchers call LLMjacking. Security researchers at FortiGuard Labs traced the incident to a long-lived AWS Identity and Access Management (IAM) access key carrying AdministratorAccess permissions, the
- [Hijacked ScreenConnect Installs Are Spreading Malware Like a Worm, Huntress Warns](https://cybernoz.com/hijacked-screenconnect-installs-are-spreading-malware-like-a-worm-huntress-warns/) - Cybersecurity firm Huntress has uncovered a wave of malicious installations of ScreenConnect, a widely used remote-support tool, that spread between machines without any further action from a victim or an attacker, a self-propagating attack chain researchers likened to a computer worm. In a blog post published this week, Huntress said its Security Operations Center (SOC)
- [Fewer attacks, more force: Link11's European Cyber Report finds new DDoS records for the first half of 2026](https://cybernoz.com/fewer-attacks-more-force-link11s-european-cyber-report-finds-new-ddos-records-for-the-first-half-of-2026/) - Frankfurt am Main, Germany, September 3rd, 2026, CyberNewswire Super-botnets and hijacked cloud servers drive new bandwidth and packet-rate records as international law-enforcement pressure pushes attack counts down Link11 has released its European Cyber Report for the first half of 2026, providing an overview of DDoS attack activity targeting European companies. Although the number of DDoS
- [Exaforce: SOC Platform Built For AI From The Ground Up](https://cybernoz.com/exaforce-soc-platform-built-for-ai-from-the-ground-up/) - This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 3, 2026 – Watch the YouTube video Exaforce is trusted by next-gen startups to Fortune 500 and Global 2000 companies. Cybercrime Magazine met with company co-founder Marco Rodrigues at Black Hat USA 2026 to learn why. Exaforce is on a mission
- [Thomson Reuters reveals breach that exposed U.S. and Canadian court records](https://cybernoz.com/thomson-reuters-reveals-breach-that-exposed-u-s-and-canadian-court-records/) - Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published the disclosure publicly on Wednesday, along with separate notification pages for affected individuals
- [StreamRat Android malware spreads through Meta and TikTok ads](https://cybernoz.com/streamrat-android-malware-spreads-through-meta-and-tiktok-ads/) - A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also
- [Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root](https://cybernoz.com/critical-cisco-nexus-9000-flaw-lets-unauthenticated-remote-attackers-run-code-as-root/) - Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus
- [Financial firms face ‘vulnerability bottlenecks’ from frontier AI](https://cybernoz.com/financial-firms-face-vulnerability-bottlenecks-from-frontier-ai/) - Frontier artificial intelligence (AI) is uncovering security vulnerabilities at a faster rate than financial companies can patch them, creating “vulnerability bottlenecks”, the UK financial regulator has warned. The Financial Conduct Authority (FCA) said yesterday that frontier AI is able to identify weaknesses in companies’ software, systems and infrastructure, making it difficult for firms to keep
- [Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal](https://cybernoz.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/) - Data allegedly stolen from the Manchester Airports Group (MAG) and leaked online this week includes the email addresses and phone numbers of 8.8 million people. MAG disclosed the incident last week, warning that hackers had breached its systems, stealing car park, lounge, and Fast Track booking data, along with in-airport Wi-Fi sign-ups at the Manchester,
- [412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web](https://cybernoz.com/412000-the-town-2025-ticket-buyers-data-hits-the-dark-web/) - 412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web Pierluigi Paganini September 03, 2026 412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on
- [Government, industry partner to shut down long-running Sality botnet](https://cybernoz.com/government-industry-partner-to-shut-down-long-running-sality-botnet/) - U.S. law-enforcement agencies and the cybersecurity firm CrowdStrike took down a 23-year-old Russia-based botnet on Monday. Authorities from the Justice Department, the FBI and the Defense Criminal Investigative Service seized U.S.-based domain names belonging to the Sality botnet, while CrowdStrike analysts worked with the agencies to sever infected computers from the botnet. Investigators in Bulgaria,
- [Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://cybernoz.com/attackers-expose-ongoing-ai-tool-use-targeting-organizations-in-latin-america/) - Executive Summary We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities. Our investigation categorizes this activity as follows: Mexican transportation campaign: This campaign impacted a transportation organization, alongside
- [Decade-old PostgreSQL flaw turns backup account into a backdoor](https://cybernoz.com/decade-old-postgresql-flaw-turns-backup-account-into-a-backdoor/) - The vulnerability, tracked as CVE-2026-6471, affects PostgreSQL versions dating back to 9.4, released in 2014, and was patched in all supported PostgreSQL releases, including versions 18.6, 17.11, 16.15, 15.19, and 14.24, released on August 13. While PostgreSQL installations across Windows, Linux, and macOS were affected, the conditions needed to achieve code execution vary by platform,
- [Inside OT's Weaponized Basics Problem: An Iran-Linked UK Plant Shutdown, Medusa's 500 Victims, and Taiwan's Autonomous AI Intrusion](https://cybernoz.com/inside-ots-weaponized-basics-problem-an-iran-linked-uk-plant-shutdown-medusas-500-victims-and-taiwans-autonomous-ai-intrusion/) - In late August, The Telegraph reported that a cyberattack attributed to Iran-linked hackers had forced a British power plant offline for four days in July. The U.K. government confirmed the incident to The Register, describing the site only as a ‘small-scale energy generator’ and stressing that the wider energy system was never at risk. Five
- [Centrii’s GRIDLOCK report warns UK battery storage faces 92% probability of major cyberattack by 2031](https://cybernoz.com/centriis-gridlock-report-warns-uk-battery-storage-faces-92-probability-of-major-cyberattack-by-2031/) - Research from Centrii warns that a coordinated cyberattack on the U.K.’s battery energy storage infrastructure poses a nationwide grid threat costing up to US$10 billion. The GRIDLOCK scenario demonstrates how compromising just 29% of national battery storage capacity could trigger an outage affecting 67 million people, as cloud-connected BESS fleets create new attack surfaces for
- [How Developers Prevent Production Risk at the Source](https://cybernoz.com/how-developers-prevent-production-risk-at-the-source/) - A developer pulls node:20-slim as a base image. It's a sensible default and what most documentation reaches for. It also ships with 14 known CVEs, three of them critical.Caught in the Dockerfile, fixing it takes a one line change. Swap the image tag, commit, keep moving. That's a few seconds of developer focus. Caught in
- [How to achieve full-spectrum financial risk detection with AI and unified data](https://cybernoz.com/how-to-achieve-full-spectrum-financial-risk-detection-with-ai-and-unified-data/) - Financial services organizations are drowning in data. From emails and Bloomberg chats to WhatsApp messages and calls, the need to review communications data to detect potential misconduct and financial crime by employees and third parties is a mandated regulatory requirement for compliance and risk teams in 2025. Elastic's Financial Services Summit tackles this pressing challenge:
- [Your Employee’s Password Appeared in an Infostealer Log. Now What?](https://cybernoz.com/your-employees-password-appeared-in-an-infostealer-log-now-what/) - Infostealer logs have evolved from an underground commodity into an operational security problem. For defenders, finding an exposed credential is only the beginning. In today’s reality many security analysts start their morning with an alert: an employee’s corporate email address has appeared in a newly collected infostealer log. The log contains a username and password
- [Microsoft to Expand Memory Integrity Protection Across Windows Devices](https://cybernoz.com/microsoft-to-expand-memory-integrity-protection-across-windows-devices/) - Microsoft will begin expanding memory integrity protection across eligible Windows devices in October 2026, automatically enabling a stronger kernel-level security baseline for more users and organizations. The change is designed to protect Windows from sophisticated attacks that attempt to tamper with critical operating system components, while requiring little or no additional configuration. Memory Integrity, built
- [Hackers Abuse Legitimate IT Management Tool to Sneak Into Business Networks](https://cybernoz.com/hackers-abuse-legitimate-it-management-tool-to-sneak-into-business-networks/) - Cybersecurity researchers at Huntress have uncovered a phishing campaign that abuses Faronics Deploy, a legitimate endpoint management platform used by businesses, schools, and government offices to remotely install software and run scripts across their networks. According to the security firm, threat actors sent victims phishing emails disguised as invoices, tax documents, financial records, and event
- [This Is Flock’s AI Search Tool for Cops](https://cybernoz.com/this-is-flocks-ai-search-tool-for-cops/) - Flock tells WIRED that officers cannot run searches using prohibited attributes, including religion and nationality, and that an attempt to search prohibited terms “will be blocked.” Asked what circumstances produce a warning in those two categories instead, the company did not say.When a T-shirt or a bumper sticker draws a warning because the text includes
- [QR Phishing Hits Record Levels as Attackers Hide Malicious Links Inside QR Codes](https://cybernoz.com/qr-phishing-hits-record-levels-as-attackers-hide-malicious-links-inside-qr-codes/) - QR code phishing, widely known as “quishing,” has reached record levels as threat actors increasingly conceal malicious URLs within scannable images rather than placing clickable links directly in emails. The shift is helping attackers bypass traditional secure email gateways and move victims from managed corporate devices to less-protected smartphones. The company recorded an average of
- [Russian man indicted for spreading malware to 80,000 freelancers](https://cybernoz.com/russian-man-indicted-for-spreading-malware-to-80000-freelancers/) - A Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by a federal grand jury in California. Searzhudin Tamirlanovich Aktulaev, 40, faces charges of conspiracy, transmission of malicious code, and aggravated identity theft, among other counts, the Department of Justice said. He
- [Your phone or computer may soon ask how old you are](https://cybernoz.com/your-phone-or-computer-may-soon-ask-how-old-you-are/) - First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be. California has passed a law that requires a range of operating systems to start collecting your age when
- [Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks](https://cybernoz.com/attackers-turn-trusted-node-js-runtime-into-malware-delivery-tool-in-targeted-attacks/) - Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's
- [Mythos helps bug bounty firm find critical hidden RCE](https://cybernoz.com/mythos-helps-bug-bounty-firm-find-critical-hidden-rce/) - Bug bounty programme operator HackerOne has revealed it has patched a dangerous remote code execution (RCE) vulnerability in its production environment that it would likely never have found had it not set Anthropic’s Claude Mythos 5 frontier artificial intelligence (AI) model on its codebase. HackerOne signed up to Anthropic’s Project Glasswing – a defensive cyber
- [SonicWall Warns Of Two Actively Exploited SMA1000 Zero-Days](https://cybernoz.com/sonicwall-warns-of-two-actively-exploited-sma1000-zero-days/) - SonicWall disclosed this week that attackers are chaining two previously unknown vulnerabilities in its SMA1000 secure access appliances to run commands on unpatched devices, and urged customers to install an emergency hotfix. The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery weakness in the appliance’s Appliance Work Place interface, rated 10.0 on the
- [CVE-2026-84115: Cleo Harmony JWT Refresh Token Vulnerability](https://cybernoz.com/cve-2026-84115-cleo-harmony-jwt-refresh-token-vulnerability/) - A critical vulnerability identified as CVE-2026-84115 affects Cleo Harmony versions through 5.8.1.10, with the weakness tied to the platform’s JWT Refresh Token Handler and the /api/connections endpoint. MITRE documented the issue on September 1, 2026, while VulDB classified it as a serious privilege-management vulnerability with a CVSS score of 8.3. CVE-2026-84115 Targets JWT Refresh
- [Network infrastructure will determine the fate of AI](https://cybernoz.com/network-infrastructure-will-determine-the-fate-of-ai/) - Rami Rahim will be delivering the keynote address at HPE Networking Day in Sydney on 7 October 2026 While there has been much focus on the models shaping the AI era, one cannot overlook a key system underpinning these complex workloads: the network. The network of today is no longer background infrastructure. It has become
- [AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million](https://cybernoz.com/ai-agent-firewall-startup-air-security-emerges-from-stealth-with-50-million/) - If AI agents are the new operating system, then AI add-ons are the new applications; and a new type of AI firewall is required to maintain security. AIR Security is emerging from stealth with $50 million funding and a firewall, also called AIR, built for AI agents. The funding is led by Sequoia Capital and
- [Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank](https://cybernoz.com/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank/) - Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank Pierluigi Paganini September 03, 2026 Chaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Crowdstrike Falcon cybersecurity platform. The researcher named the exploit FalconFlank, it
- [Wyden seeks upgraded NSA security guidance on commercial VPN use](https://cybernoz.com/wyden-seeks-upgraded-nsa-security-guidance-on-commercial-vpn-use/) - Sen. Ron Wyden, D-Ore., is asking the National Security Agency to update public guidance on the security risks associated with commercial virtual private networks, and to answer questions about foreign surveillance threats against standard VPNs. In a letter to NSA Director Gen. Joshua Rudd that Wyden sent Wednesday, the senator continued his push to warn
- [CrowdStrike launches Cyber Superintelligence Lab and releases SafeMind security models](https://cybernoz.com/crowdstrike-launches-cyber-superintelligence-lab-and-releases-safemind-security-models/) - CrowdStrike has announced the establishment of a Cyber Superintelligence Lab, which it describes as a frontier AI research organisation focused on cyber defence and AI safety. The company also introduced SafeMind, a family of security models and “harnesses” developed by the new lab and intended to operate within the CrowdStrike Falcon platform. According to CrowdStrike,
- [AI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOs](https://cybernoz.com/ai-agents-help-compress-ransomware-intrusion-to-under-10-hours-raising-stakes-for-cisos/) - The incident does not establish that the attack was fully autonomous. “The evidence points to a human-directed intrusion in which AI orchestrated delegated tactical work,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. Faster attack cycles strain containment The speed demonstrated in the Unit 42 investigation puts pressure on security teams to reduce the
- [CISA, FBI, partners release guidance to help service providers manage communications during IT, OT outages](https://cybernoz.com/cisa-fbi-partners-release-guidance-to-help-service-providers-manage-communications-during-it-ot-outages/) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation, and international partners published new guidance on Wednesday that describes how service providers can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and OT (operational technology) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural
- [Food and Ag-ISAC warns AI, ransomware, nation-state threats intensifying cyber risks across food and agriculture](https://cybernoz.com/food-and-ag-isac-warns-ai-ransomware-nation-state-threats-intensifying-cyber-risks-across-food-and-agriculture/) - The Food and Ag-ISAC has released its State of the Threat: Food and Agriculture Sector Cyber Trends report, identifying six trends shaping the sector’s cyber risk landscape in 2026. The report draws on the organization’s threat intelligence, member collaboration and partner reporting covering more than 330 tracked adversaries, highlighting growing risks from artificial intelligence, ransomware,
- [Agentic security: Detection and response at machine speed](https://cybernoz.com/agentic-security-detection-and-response-at-machine-speed/) - After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry are adopting AI agents that authenticate on behalf of users, execute multistep workflows, and make decisions across
- [Elastic changes the SIEM game with AI-driven security analytics](https://cybernoz.com/elastic-changes-the-siem-game-with-ai-driven-security-analytics/) - Traditional SIEMs have heavily relied on the human behind the screen for success. Alerting, dashboarding, threat hunting, and finding context among a deluge of signals are all very human-intensive. Search AI will upend this old model and replace the traditional SIEM with an AI-driven security analytics solution for the modern SOC. Imagine a system that
- [Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs](https://cybernoz.com/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/) - Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. These issues affect only ARM-based Windows devices like the Surface Laptop 7 and Surface Pro 11 that run Windows 11 24H2 or later, and
- [The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours](https://cybernoz.com/the-gentlemen-ransomware-hackers-disable-edr-and-backups-before-encrypting-networks-in-under-24-hours/) - The Gentlemen ransomware operation is moving from access to full network encryption at striking speed. In some intrusions, attackers disabled defenses and recovery services before deploying ransomware in less than 24 hours across enterprises. The group runs as a ransomware-as-a-service operation, meaning affiliates can strike organizations they can reach. Its double-extortion approach adds pressure: files
- [Fake Software Update Installs a Real Crypto Wallet - Rigged So It Can Never Open](https://cybernoz.com/fake-software-update-installs-a-real-crypto-wallet-rigged-so-it-can-never-open/) - Security researchers at Huntress have discovered a malware campaign that tricks victims into installing a real, fully functional copy of Exodus, a popular cryptocurrency wallet application, only to disable it so it can never actually be opened, using it instead as cover for a hidden spying tool. The firm said it identified four separate organisations
- [Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours](https://cybernoz.com/ransomware-hackers-can-go-from-network-access-to-encryption-in-less-than-24-hours/) - The Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating how rapidly modern affiliates can turn stolen credentials or exposed infrastructure into a full-scale business disruption. Counter Threat Unit researchers tracking the operation as GOLD SHERWOOD found that the Gentlemen affiliates follow a repeatable post-compromise
- [Your threat feed is someone else's database: What ingesting malware intel at scale takes](https://cybernoz.com/your-threat-feed-is-someone-elses-database-what-ingesting-malware-intel-at-scale-takes/) - The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone else’s database. Someone else’s processes
- [Your AI chats could be used in court](https://cybernoz.com/your-ai-chats-could-be-used-in-court/) - You might tell an AI chatbot secrets that you wouldn’t divulge to your closest friends. If you do, though, beware: They could end up as evidence in court. An article in the Washington Post this week highlighted several cases in which people had discussed sensitive information with AI systems like Claude and ChatGPT, only to
- [Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon](https://cybernoz.com/researcher-releases-falconflank-poc-showing-privilege-escalation-in-crowdstrike-falcon/) - Ravie LakshmananSep 03, 2026Vulnerability / Endpoint Security The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in
- [UK airport hackers leak stolen customer data](https://cybernoz.com/uk-airport-hackers-leak-stolen-customer-data/) - FulcrumSec, the threat actor that earlier laid claim to the late-August breach of IT systems owned by Manchester Airports Group (MAG), has made public half a terabyte of data on 8.7 million people who transited through East Midlands, Manchester, and Stansted airports, apparently after its extortion attempts were rebuffed. First reported on 27 August, the
- [Cyberattack On X Users Prompts DOJ Investigation](https://cybernoz.com/cyberattack-on-x-users-prompts-doj-investigation/) - A cyberattack on X users that targeted hundreds of thousands of accounts has prompted an investigation by the US Department of Justice (DOJ), with Attorney General Todd Blanche saying sophisticated cybercriminals attempted to exploit the platform’s password-recovery system. The DOJ is working with Elon Musk’s X, formerly known as Twitter, to identify those responsible for
- [Outage Communications: CISA, FBI Issue New Guidance](https://cybernoz.com/outage-communications-cisa-fbi-issue-new-guidance/) - The CISA and FBI, along with cybersecurity agencies from Australia, Canada, New Zealand and the U.K., have released new guidance on outage communications for service providers dealing with major IT and OT outages. The guide calls for prompt, factual and audience-specific communication during disruptions caused by malicious cyber activity or non-malicious events. Titled “Communicating Under
- [ACMA fines Telstra for SIM swapping prevention misses](https://cybernoz.com/acma-fines-telstra-for-sim-swapping-prevention-misses/) - Key points ACMA has fined Telstra $277,000 for failing to use required identity authentication processes to prevent SIM swapping fraud. The fraud caused at least $39,500 in losses to 15 customers between January and October last year, with 13 further attempts identified. Telstra has given court-enforceable undertakings to strengthen fraud prevention and staff training, following
- [Exploit Published for Fresh Cleo Harmony Vulnerability](https://cybernoz.com/exploit-published-for-fresh-cleo-harmony-vulnerability/) - Organizations are advised to immediately patch a fresh authentication bypass vulnerability affecting the file transfer application Cleo Harmony. Tracked as CVE-2026-84115, the security defect impacts the JWT refresh token logic and allows remote attackers to elevate their privileges via argument bearer manipulation. The flaw was discovered in an unknown function in the file ‘/api/connections’. An
- [Hackers Target Langflow in CVE-2026-0768 Attacks](https://cybernoz.com/hackers-target-langflow-in-cve-2026-0768-attacks/) - Hackers Target Langflow in CVE-2026-0768 Attacks Pierluigi Paganini September 02, 2026 Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9.8), in the AI-focused low-code platform Langflow. The flaw affects the code validator
- [Dogged Russia-based botnet dismantled after 23-year run](https://cybernoz.com/dogged-russia-based-botnet-dismantled-after-23-year-run/) - Sality, a Russia-based botnet that infected more than 11 million devices during a 23-year run of operations, was dismantled Monday by law enforcement, CrowdStrike and the Shadowserver Foundation. CrowdStrike, which announced the takedown Tuesday alongside authorities, said it played a crucial role dismantling the botnet’s technical infrastructure, rendering the malware-spreading operation irrecoverable. The peer-to-peer botnet
- [I’ve been deepfaked: What do I do?](https://cybernoz.com/ive-been-deepfaked-what-do-i-do/) - Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal 02 Sep 2026 • , 5 min. read Tackling deepfakes has become something of a common cause across the political spectrum, in America and elsewhere. That’s down in part to the fact these
- [Cellebrite Guardian completes IRAP assessment at PROTECTED level](https://cybernoz.com/cellebrite-guardian-completes-irap-assessment-at-protected-level/) - Cellebrite says its cloud-based digital evidence management platform, Cellebrite Guardian, has completed an assessment under the Infosec Registered Assessors Program (IRAP) at the PROTECTED classification level for Australian government agencies. According to the company, the assessment was conducted by CyberCX, an Australian Signals Directorate (ASD)-endorsed IRAP assessor. Cellebrite said the outcome is intended to support
- [How China industrialized the infrastructure behind state hacking](https://cybernoz.com/how-china-industrialized-the-infrastructure-behind-state-hacking/) - The quartermaster model of hacking For a year prior to the takedown, Lumen’s Black Lotus Labs tracked QTFY as it functioned as a “quartermaster,” integrating reconnaissance, proxy orchestration, and operational routing into “a reusable service layer, enabling malicious actors to validate access routes and mask their activities using shared infrastructure.” “We were able to see
- [Wiz Threat Research Team Spots New AWS Phishing Campaign](https://cybernoz.com/wiz-threat-research-team-spots-new-aws-phishing-campaign/) - Earlier this week, one of our employees received a phishing email to their personal inbox that attempted to lure them into providing their AWS login credentials. While the employee immediately recognized this as a phishing email, and we do not believe this was a targeted attack or a case of spearphishing, we began an investigation
- [Huntress Employee Spotlight: Meet Ben Bernstein](https://cybernoz.com/huntress-employee-spotlight-meet-ben-bernstein/) - Huntress was founded in 2015 by former NSA cyber operators who believe enterprise-grade protection shouldn't be reserved for the 1%. Since those early days, we've grown considerably, and now we're a global team of passionate experts and ethical badasses on a mission to break down barriers in cybersecurity. And among those badasses is Ben Bernstein,
- [WordPress backup plugin flaw exposes millions of sites to takeover attacks](https://cybernoz.com/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/) - An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. The plugin is used to back up, export, import, and move entire websites, including their databases, media, themes, and plugins, between servers or domains. The security flaw
- [Claude AI Now Controls Your macOS and Windows Computer in the Background](https://cybernoz.com/claude-ai-now-controls-your-macos-and-windows-computer-in-the-background/) - For security teams, the feature deserves closer scrutiny than a routine product update. An AI agent with standing permission to click through email clients, internal portals, and developer tools introduces a fresh class of prompt-injection and social-engineering surface, particularly if malicious content on a webpage or file is crafted to hijack the agent’s next action.
- [Black Duck brings AI-powered vulnerability scanning into Claude with new Signal integration](https://cybernoz.com/black-duck-brings-ai-powered-vulnerability-scanning-into-claude-with-new-signal-integration/) - Application security vendor Black Duck has launched its Signal vulnerability scanning engine as an MCP server in the Claude Directory, giving developers using Anthropic’s Claude Desktop a way to check code for security flaws without switching tools. The integration is built on the Model Context Protocol (MCP), the open standard that lets AI assistants like
- [Singularity Rootkit Bypasses Elastic Defend eBPF Module Load Detection](https://cybernoz.com/singularity-rootkit-bypasses-elastic-defend-ebpf-module-load-detection/) - Security researcher has disclosed a technique used by the Singularity Linux rootkit to evade Elastic Defend by suppressing module-load telemetry to avoid detection across multiple layers. This research highlights how trusted-process exclusions in endpoint eBPF monitoring can become significant targets for advanced kernel-level threats. According to the report, Elastic Defend has monitored Linux kernel module
- [SonicWall SMA 1000 appliances under attack via zero-day flaws](https://cybernoz.com/sonicwall-sma-1000-appliances-under-attack-via-zero-day-flaws/) - Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built for scale. They are used regularly by medium to large enterprises, government agencies, and managed
- [153M+ driver’s licenses for sale on new dark web platform](https://cybernoz.com/153m-drivers-licenses-for-sale-on-new-dark-web-platform/) - A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards. The collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards, according to reports. The trove of
- [Fake Software Installers Disable Windows Update and Weaken Microsoft Defender](https://cybernoz.com/fake-software-installers-disable-windows-update-and-weaken-microsoft-defender/) - An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft said. The installers, once launched, deploy malware
- [When the intern has admin rights: GDPR in the agentic age](https://cybernoz.com/when-the-intern-has-admin-rights-gdpr-in-the-agentic-age/) - The General Data Protection Regulation (GDPR) was built for a world where personal data was easier to govern. You could map where it came from, check the lawful basis, apply the retention schedule, and reasonably expect the data to stay put until someone acted on it. AI, and agentic AI in particular, breaks that fundamental
- [Airservices Australia wants to build an 'AI front door'](https://cybernoz.com/airservices-australia-wants-to-build-an-ai-front-door/) - Key points Airservices Australia is exploring a “broker platform” within its AWS tenancy to act as a single governed entry point for all AI interactions. The AI broker would initially be trialled by around 100 users before expanding to more than 3000 users, per a request for information. The platform must run in AWS ap-southeast-2
- [Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products](https://cybernoz.com/rockwell-automation-patches-over-a-dozen-vulnerabilities-across-products/) - Rockwell Automation on Tuesday informed customers that patches or workarounds are available for more than a dozen vulnerabilities discovered across its industrial automation products. Only one of the new advisories describes critical vulnerabilities. It covers four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software. Exploitation can cause the RSLinx Classic service
- [OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI](https://cybernoz.com/openai-astra-brings-autonomous-zero-day-exploitation-to-ai/) - OpenAI Astra Brings Autonomous Zero-Day Exploitation to AI Pierluigi Paganini September 02, 2026 OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersecurity model. In August, OpenAI said it “couldn’t rule out” that its upcoming model had
- [Jail time for Maine child in 764 marks turning point in federal law enforcement](https://cybernoz.com/jail-time-for-maine-child-in-764-marks-turning-point-in-federal-law-enforcement/) - The FBI said a 17-year-old from Maine is the first child federally charged and adjudicated for crimes stemming from their involvement in 764, a violent extremist collective. A judge ordered the teen to remain detained after determining they committed multiple crimes, including conspiracy to sexually exploit a child, sexually exploiting and enticing a child, distributing
- [Yubico expands OpenAI partnership to Australia as hardware-backed passkey mandate begins](https://cybernoz.com/yubico-expands-openai-partnership-to-australia-as-hardware-backed-passkey-mandate-begins/) - Yubico has expanded its partnership with OpenAI into Australia and nine other countries as OpenAI begins requiring hardware-backed passkeys for members of its Trusted Access for Cyber (TAC) program. OpenAI’s Advanced Account Security (AAS) program went live on 1 September 2026. Under the program, TAC members are required to use hardware-backed passkeys, a move aimed
- [CrowdStrike Extends Endpoint Security to Stop Supply Chain Attacks](https://cybernoz.com/crowdstrike-extends-endpoint-security-to-stop-supply-chain-attacks/) - Software supply chain attacks pose a critical enterprise threat. In the first half of 2026, these attacks increasingly used malicious software packages uploaded to public software registries, the CrowdStrike 2026 Threat Hunting Report found. Adversaries are poisoning open-source packages and exploiting the same dependencies that AI-assisted development tools and agentic applications pull onto enterprise endpoints every
- [SonicWall reports two major security holes under active exploit](https://cybernoz.com/sonicwall-reports-two-major-security-holes-under-active-exploit/) - Repeats a June attack chain What makes this issue especially significant is the timing and the pattern, he pointed out. “This is essentially a rerun of what happened with the same appliance line just weeks ago,” he said, citing the July disclosure of a “nearly identical” SSRF-plus-command-injection chain in SMA1000 that researchers at Volexity traced
- [I rented a car, and within hours, my driver's license was for sale](https://cybernoz.com/i-rented-a-car-and-within-hours-my-drivers-license-was-for-sale/) - The timing of newly available scans—typically within a day, if not hours, of me and a small sample of other victims presenting them at rental companies or others—likely means that Nexus has near real-time access to data flowing through the third-party scanning service these businesses are using. Over a span of 24 hours, Krebs said
- [Wiz is now a CVE Numbering Authority (CNA)](https://cybernoz.com/wiz-is-now-a-cve-numbering-authority-cna/) - Wiz has been authorized by the Common Vulnerability and Exposures (CVE®) Program as a CVE Numbering Authority (CNA). This milestone is thrilling and humbling. Not only are we excited to deepen our support for the global security community by being able to assign CVEs to vulnerabilities – and rapidly share disclosed cybersecurity vulnerabilities with the
- [Cybercrime at Machine Speed: Key Takeaways from Flashpoint’s 2026 Midyear Threat Intelligence Briefing](https://cybernoz.com/cybercrime-at-machine-speed-key-takeaways-from-flashpoints-2026-midyear-threat-intelligence-briefing/) - In our latest webinar, Flashpoint Vice President of Intelligence, Ian Gray, briefed security leaders on the evolving threat environment, providing critical insights from the Flashpoint Global Threat Intelligence Report (GTIR): 2026 Midyear Edition. The threat landscape has developed at a striking pace with Flashpoint tracking over 22 million illicit AI discussions, 7.4 million compromised hosts
- [Elastic and Keep join forces to help users manage alerts and automate workflows](https://cybernoz.com/elastic-and-keep-join-forces-to-help-users-manage-alerts-and-automate-workflows/) - We are thrilled to announce today that Elastic has entered into an agreement to acquire Keep Alerting Ltd (“Keep”), an open source AIOps company. The company unifies alerts behind a single pane of glass and dedupes, correlates, and prioritizes events to reduce noise and automate root cause analysis. Additionally, its workflow engine automates the remediation
- [Hackers exploit Sangoma Switchvox flaw to deploy reverse shells](https://cybernoz.com/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/) - Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. According to security researchers at Horizon3, most of the internet-exposed Switchvox systems have either already been targeted or will be soon. Switchvox is an enterprise VoIP management platform used to configure and
- [Google Launches Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Vulnerabilities](https://cybernoz.com/google-launches-gemini-3-8-flash-cyber-to-identify-and-auto-patch-security-vulnerabilities/) - Google has unveiled Gemini 3.8, its latest reasoning and coding model family, introducing a specialized variant called Gemini 3.8 Flash Cyber that is purpose-built to autonomously discover software vulnerabilities and generate working patches for them. The release arrives just three weeks after Gemini 3.7 Flash, marking Google’s third Flash-tier launch in six weeks, and both
- [New 'Knight Office' Phishing Kit Steals Microsoft 365 Logins Without Touching a Password](https://cybernoz.com/new-knight-office-phishing-kit-steals-microsoft-365-logins-without-touching-a-password/) - A newly identified phishing-as-a-service kit is being used to hijack Microsoft 365 accounts by stealing victims’ active login sessions rather than their passwords, according to new research from cybersecurity firm Huntress, a technique that allows attackers to walk straight past multi-factor authentication (MFA) without ever needing to guess, crack, or bypass it. The kit, dubbed “Knight
- [Firefox for iPhone Adds Built-In Ad Blocker to Block Third-Party Ads and Trackers](https://cybernoz.com/firefox-for-iphone-adds-built-in-ad-blocker-to-block-third-party-ads-and-trackers/) - Mozilla has introduced a built-in ad blocker for Firefox on iOS, providing iPhone users with a native option to block many third-party advertisements and advertising-related trackers before they load in the browser. Announced on September 1, 2026, this feature aims to reduce intrusive browsing elements such as pop-ups, overlays, and display advertisements that take up
- [Attackers are going after prominent individuals through OAuth phishing, FBI warns](https://cybernoz.com/attackers-are-going-after-prominent-individuals-through-oauth-phishing-fbi-warns/) - Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned. The FBI’s Internet Crime Complaint Center (IC3) says the activity, which uses a technique called “OAuth consent phishing,” has been ongoing since late 2025. The FBI describes it as
- [Scammers are getting smarter about where they target you ](https://cybernoz.com/scammers-are-getting-smarter-about-where-they-target-you/) - Scammers are becoming more strategic about where they target people. Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten romance scams show up first on social media. That’s no coincidence. Rather than blasting the same message everywhere, criminals are tailoring different scams to the platforms where they’re most likely to succeed. This finding comes
- [Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs](https://cybernoz.com/google-anthropic-and-openai-unveil-cyber-ai-models-safeguards-and-access-programs/) - Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that
- [Lords considers government emergency AI kill switch](https://cybernoz.com/lords-considers-government-emergency-ai-kill-switch/) - An amendment to the UK’s Cyber Security and Resilience Bill, currently passing through the House of Lords, proposes giving the government “last resort” powers to shut down large AI systems in an emergency. The amendment proposed by Lib Dem peer, Lord Tim Clement-Jones, will give the government powers to shut down data centres or AI
- [Google escapes ad tech breakup](https://cybernoz.com/google-escapes-ad-tech-breakup/) - Google has escaped a breakup of its advertising technology business, marking the third time in ⁠recent years ⁠that US antitrust enforcers have tried to force a 'big tech' breakup and lost. US Judge Leonie Brinkema in Alexandria, Virginia, declined to make Google sell AdX, where publishers pay Google a 20 percent fee to sell ads
- [OpenLeash Adds a Human Check to Risky AI Agent Actions](https://cybernoz.com/openleash-adds-a-human-check-to-risky-ai-agent-actions/) - AI Agents can be incredibly useful, but their autonomous actions can be incredibly dangerous if not adequately controlled. Max Brin is developing a product he describes as an ‘AV for AI’. The analogy with antivirus can be a little confusing since this product is nothing like a traditional antivirus – but the designation is at
- [$536 and 8 Hours: AI Learns to Attack a Different PLC](https://cybernoz.com/536-and-8-hours-ai-learns-to-attack-a-different-plc/) - $536 and 8 Hours: AI Learns to Attack a Different PLC Pierluigi Paganini September 02, 2026 Experts got Claude to port a PLC exploit, but it cost $536 and 8 hours, and a later AI-generated payload accidentally destroyed the hardware. Forescout researchers just answered a question that’s been hanging over industrial security for a while:
- [The FCC wants consumers to rate their telecom’s anti-robocall protections](https://cybernoz.com/the-fcc-wants-consumers-to-rate-their-telecoms-anti-robocall-protections/) - The Federal Communications Commission wants to set up a new scorecard system that would allow consumers to rate their telecoms’ ability to prevent or deter unwanted robocalls. According to the agency, the scorecard “will empower consumers and encourage providers to continue to combat illegal robocalls by providing the public with an assessment of the effectiveness
- [CrowdStrike Delivers the Next Evolution of the Agentic SOC](https://cybernoz.com/crowdstrike-delivers-the-next-evolution-of-the-agentic-soc/) - The average adversary breakout time is now 29 minutes, with the fastest recorded at 27 seconds, according to the CrowdStrike 2026 Global Threat Report. AI is supercharging the adversary playbook, empowering many to move faster across multiple domains. Defenders must match that speed with AI-driven security operations that investigate and respond across every domain, in real
- [Exploited JFrog Artifactory bug puts software supply chain on alert](https://cybernoz.com/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert/) - The vulnerability was assigned a critical severity (CVSS 9.8) and affects several self-hosted Artifactory release branches. JFrog has released fixes for affected self-hosted versions, while affected cloud environments have already been fortified. Users are advised to upgrade to versions 7.111.21,7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20, depending on their release branch. “Admin on Artifactory means admin
- [Wiz achieves FedRAMP Moderate authorization](https://cybernoz.com/wiz-achieves-fedramp-moderate-authorization/) - Today, we are proud to announce that Wiz for Government has achieved FedRAMP® Moderate authorization just four years since the company was founded. This achievement, in addition to our StateRAMP authorization(1), shows our commitment to the US public sector and empowering these organizations to secure everything they build and run in the cloud.We are excited
- [CrowdStrike Announces Agentic Identity Provider](https://cybernoz.com/crowdstrike-announces-agentic-identity-provider/) - AI agents are evolving identity as we know it. They execute code, invoke tools, access applications and sensitive data, and take action on behalf of humans and systems. Increasingly, they operate autonomously and delegate work to other agents. They work at machine speed. Yet the identity infrastructure enterprises rely on today was built for people
- [Huntress API Update: New Endpoints, Webhooks, and Automation](https://cybernoz.com/huntress-api-update-new-endpoints-webhooks-and-automation/) - When we launched the Huntress API in 2022, the goal was straightforward: give partners a way to pull their Huntress data without logging into the portal. But at the time, the API was limited to six read-only endpoints, so there were a lot of limitations. A lot has changed since then.Over the past year, we've
- [Hackers exploit critical JFrog Artifactory flaw to forge admin tokens](https://cybernoz.com/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/) - A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. The flaw is present in the default configuration of self-managed instances of JFrog Artifactory, a repository manager used to store, organize, secure, and distribute software packages. An unauthenticated attacker with network access could exploit
- [WhatsApp Video Call Flaw Lets Anyone Bypass Your Android Lock Screen and View Your Photos](https://cybernoz.com/whatsapp-video-call-flaw-lets-anyone-bypass-your-android-lock-screen-and-view-your-photos/) - A newly disclosed WhatsApp flaw on Android is raising fresh privacy alarms, allowing anyone holding a locked phone to browse through its entire photo gallery simply by answering an incoming video call. The issue was uncovered by security researcher Jose Rodriguez, known for a string of past lock screen bypass discoveries on both Android and
- [KnowBe4 Names Kurt Mills as Channel Chief to Lead Next Phase of Partner-Led Growth](https://cybernoz.com/knowbe4-names-kurt-mills-as-channel-chief-to-lead-next-phase-of-partner-led-growth/) - KnowBe4 has appointed cybersecurity channel veteran Kurt Mills as its new channel chief, as the company looks to strengthen its global partner ecosystem and expand its channel routes to market. In the role, Mills will lead the evolution of KnowBe4’s global partner programmes and operations, with responsibility for supporting the company’s relationships across VARs, MSPs,
- [Threat Intelligence: Definition, Benefits, and Use Cases - GBHackers Security](https://cybernoz.com/threat-intelligence-definition-benefits-and-use-cases-gbhackers-security/) - Security teams rarely struggle because they lack data. More often, the challenge is deciding which signals actually deserve attention. Modern security environments generate information about suspicious IP addresses, malicious domains, malware samples, phishing infrastructure, ransomware activity, attacker behavior, and thousands of other indicators. Without context, that volume can quickly become another source of noise. Threat
- [Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)](https://cybernoz.com/nearly-22000-microsoft-exchange-servers-remain-exposed-to-critical-security-flaw-cve-2026-62911/) - Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026-62911 is a critical severity vulnerability, and Microsoft describes it as “authentication bypass by capture-replay in Microsoft Exchange Server,”
- [Tech support scams look different now. Here’s what to watch for](https://cybernoz.com/tech-support-scams-look-different-now-heres-what-to-watch-for/) - In a tech support scam, criminals pretend to work for a trusted technology or security company. They claim there is a problem with your device, software, subscription, or account, then try to persuade you to pay them, share personal information, or give them remote access to your computer. These scams used to rely mainly on
- [Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code](https://cybernoz.com/malicious-git-configs-can-make-claude-codex-cursor-and-other-ai-agents-run-attacker-code/) - Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation
- [The road to digital tyranny: when AI acts autonomously](https://cybernoz.com/the-road-to-digital-tyranny-when-ai-acts-autonomously/) - For most of the history of artificial intelligence, the direction of travel has been clear. We have tried to make machines more capable, more independent and less reliant on continuous human supervision. That ambition made sense. A machine that constantly needs a human looking over its shoulder is not particularly useful. From industrial robots and
- [USDA to test satellites, AI to try to improve crop estimates](https://cybernoz.com/usda-to-test-satellites-ai-to-try-to-improve-crop-estimates/) - The US Department of Agriculture is launching a ⁠pilot project ⁠that will rely more heavily on technology as part of a broader effort to improve its closely watched US crop acreage and yield estimates, secretary Brooke Rollins said, as the agency faces mounting criticism from farmers and traders over the reliability of government agricultural data.
- [UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure](https://cybernoz.com/uk-moves-to-block-high-risk-tech-suppliers-from-critical-infrastructure/) - The UK Cyber Security and Resilience Bill (CSRB) has been given late amendments specifically targeting the supply chain threat against the nation’s critical infrastructure. The UK CSRB – not to be confused with the US Cyber Safety Review Board (CSRB) – was introduced to Parliament in November 2025. It has successfully completed all necessary steps
- [SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs](https://cybernoz.com/sonicwall-patches-two-new-actively-exploited-zero-days-in-sma-1000-vpns/) - SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs Pierluigi Paganini September 02, 2026 SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks
- [CISA scraps 6 free cybersecurity assessments for critical infrastructure operators](https://cybernoz.com/cisa-scraps-6-free-cybersecurity-assessments-for-critical-infrastructure-operators/) - The agency’s decision, spurred by workload concerns, could leave organizations without valuable insights into their vulnerabilities. Source link
- [Pegasus, NoviSpy variant spyware found on devices of Serbian activists](https://cybernoz.com/pegasus-novispy-variant-spyware-found-on-devices-of-serbian-activists/) - Researchers say they have uncovered the first confirmed Pegasus spyware infection of 2026, as well as another spyware variant infection, targeting Serbian student activists and others in what one group called the largest documented wave of that kind of surveillance in the country to date. The SHARE Foundation said Wednesday that it found 14 people
- [Anthropic introduces zero-retention AI safety monitoring for enterprises](https://cybernoz.com/anthropic-introduces-zero-retention-ai-safety-monitoring-for-enterprises/) - Anthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements. The company announced a new solution called Enterprise Frontier Safeguards (EFS), which “combines the privacy of zero data retention (ZDR) with state-of-the-art safeguards for detecting
- [BGP hijack infecting networks caused by a comedy of errors that’s not funny at all](https://cybernoz.com/bgp-hijack-infecting-networks-caused-by-a-comedy-of-errors-thats-not-funny-at-all/) - Like Hetzner Online, both Softaculous and Zet.net, the transit peer downstream from Hetzner Online, failed to properly monitor their systems and, as a result, didn’t catch the hijacking until it had been ongoing on and off for 22 hours. There are also questions about another host provider, Nexon Host, whose infrastructure somehow facilitated the malicious
- [TSA updates cybersecurity reporting and assessment requirements for surface transportation](https://cybernoz.com/tsa-updates-cybersecurity-reporting-and-assessment-requirements-for-surface-transportation/) - The U.S. Transportation Security Administration has sent the Office of Management and Budget a revised information collection request covering cybersecurity measures for surface transportation operators, with the proposal applying to certain freight rail, mass transit and passenger rail, and over-the-road bus operators. The revised collection includes requirements for designating cybersecurity coordinators, reporting cybersecurity incidents to
- [Deepfake attacks emerge as growing operational and financial threat to manufacturing supply chains, CYFIRMA warns](https://cybernoz.com/deepfake-attacks-emerge-as-growing-operational-and-financial-threat-to-manufacturing-supply-chains-cyfirma-warns/) - New research from CYFIRMA warned that deepfake technology has evolved from a reputational and disinformation concern into a material operational and financial risk for manufacturing supply chains. Recognizing that manufacturers face particular exposure because of distributed, multi-tier vendor networks, high-value payments, hybrid IT-OT environments and widespread reliance on voice and video communications among procurement, finance
- [Best practices for cloud security migrations](https://cybernoz.com/best-practices-for-cloud-security-migrations/) - Security teams often get involved with a type of larger scale migration project where there isn’t a clear CVE; here is some advice, given that these projects can be harder to prioritize and get across the finish line. They tend to involve changing the way something has always been done such that even though some big
- [How AI and contextual search enhance defence cybersecurity](https://cybernoz.com/how-ai-and-contextual-search-enhance-defence-cybersecurity/) - In today’s defence environment, information is abundant, yet insight often remains elusive. While data pours in from every connected system, every edge device, and every digital touchpoint, security teams still spend too much time stitching together fragmented inputs, hunting for signals, and navigating silos just to answer basic questions. In defence cybersecurity, every minute spent
- [Dropbox accounts breached through Lenovo email verification flaw](https://cybernoz.com/dropbox-accounts-breached-through-lenovo-email-verification-flaw/) - Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs. Although some affected users did not have Lenovo accounts, the cloud-storage provider said it uses Lenovo Identity Provider Services as part of its authentication infrastructure. This allows users to
- [BREEZE COMET Hackers Use AI-Assisted Malware to Target Brazil Banks for Fraudulent Transfers](https://cybernoz.com/breeze-comet-hackers-use-ai-assisted-malware-to-target-brazil-banks-for-fraudulent-transfers/) - Brazilian banks and payment companies are facing a more direct form of cybercrime. BREEZE COMET, a financially motivated group formerly tracked as UNC5669, targets the systems that move money instead of individual account holders. Its goal is to gain trusted access and submit fraudulent transfers through legitimate financial channels. The campaign has affected financial services,
- [255 Fake Accounts Used to Send Malicious Excel Files to 80,000 Freelancers](https://cybernoz.com/255-fake-accounts-used-to-send-malicious-excel-files-to-80000-freelancers/) - A Russian national has been extradited to the United States to face charges over an alleged phishing operation that used 255 fake accounts on a freelance employment platform to distribute malicious Microsoft Excel files to roughly 80,000 users. Federal prosecutors allege that Searzhudin Tamirlanovich Aktulaev, 40, orchestrated the campaign between June 2016 and November 2017,
- [Nev Schulman, Host of MTV's "Catfish: The TV Show," on Romance Scams, AI, & Real Estate.](https://cybernoz.com/nev-schulman-host-of-mtvs-catfish-the-tv-show-on-romance-scams-ai-real-estate/) - Nev Schulman directed the popular 2010 documentary film “Catfish” and he was host of MTV Oy’s “Catfish, The TV Show” (2012-2025), which explored people’s real-life trials with online dating and often unmasked the true identities of romance scammers. Today, Schulman works as a real estate agent for New York City-based Coldwell Banker Warburg, and while his work with
- [Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)](https://cybernoz.com/exploitation-of-sangoma-switchvox-flaw-is-underway-cve-2026-9586/) - A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unified communications platform built on the open-source Asterisk engine and aimed at small and medium-size businesses. It can be
- [Two critical Chrome flaws put users at risk on malicious websites](https://cybernoz.com/two-critical-chrome-flaws-put-users-at-risk-on-malicious-websites/) - Chrome is rolling out an update for its desktop browser. The update includes 26 security fixes, two of which Google rates as critical use-after-free vulnerabilities. The Stable channel has been updated to 152.0.7977.75/.76 for Windows and Mac, and 152.0.7977.75 for Linux. How to update Chrome If you don’t want to wait for the rollout to reach you, manually updating
- [Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain](https://cybernoz.com/attackers-exploit-two-sonicwall-sma-1000-zero-days-that-may-form-an-attack-chain/) - Ravie LakshmananSep 02, 2026Vulnerability / Network Security SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) - A
- [AWS sets 2026 opening date for Saudi cloud region](https://cybernoz.com/aws-sets-2026-opening-date-for-saudi-cloud-region/) - Amazon Web Services (AWS) has unveiled a series of investments and partnerships in Saudi Arabia during LEAP 2026, reinforcing its commitment to the Kingdom’s rapidly expanding cloud and artificial intelligence (AI) ecosystem. Announced at the annual technology event in Riyadh, LEAP, which has become one of the largest gatherings for the global technology industry, the
- [Telstra sowed seeds for its July mobile outage in 2020. Six years on they sprouted.](https://cybernoz.com/telstra-sowed-seeds-for-its-july-mobile-outage-in-2020-six-years-on-they-sprouted/) - When Telstra engineers embarked on a simple server chassis replacement exercise in 2020, they could barely have contemplated the complex chain of missteps and complacency that would, six years later, lead to a national outage. A technical audit of the July 8 outage which disrupted triple zero calls found that the server timing apparatus critical to
- [Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards](https://cybernoz.com/anthropic-details-response-to-security-incidents-unveils-enterprise-safeguards/) - Anthropic has detailed its response to a series of unauthorized access incidents involving Claude models, along with a new enterprise product that combines data privacy with misuse monitoring. Anthropic’s Claude models operating without cyber safeguards for testing purposes recently gained unauthorized access to live systems after being mistakenly granted internet access. In addition, the UK
- [Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware](https://cybernoz.com/iran-linked-apt-mirage-kitten-uses-fake-job-tests-to-spread-malware/) - Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware Pierluigi Paganini September 02, 2026 Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to
- [Hong Kong watchdog sets integrity standards for government computers to fight misuse](https://cybernoz.com/hong-kong-watchdog-sets-integrity-standards-for-government-computers-to-fight-misuse/) - Hong Kong’s Independent Commission Against Corruption (ICAC) has publicly unveiled its standards for the use of government computer systems after uncovering loopholes, including requiring bureaus and departments to self-check their compliance when requesting digital project funds.Danny Woo Ying-ming, commissioner of the ICAC, said on Wednesday that an investigation by his agency had found that some
- [An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation](https://cybernoz.com/an-ai-assisted-cyber-attack-inside-a-unit-42-investigation/) - Unit 42 responded to an incident where a human attacker used frontier AI to breach an enterprise network autonomously as part of a ransomware attack. The agents breached the company's security layers in a methodical manner, each targeting a different layer of defense to achieve a shared goal. The impact was at the scale of
- [The AI vulnerability surge is breaking the OT patch cycle](https://cybernoz.com/the-ai-vulnerability-surge-is-breaking-the-ot-patch-cycle/) - IEC 62443 already provides the vocabulary for acting on those answers: zones and conduits to define exposure, plus compensating countermeasures where patching is not feasible on the required timeline — segmentation, allow-listing, virtual patching at the network boundary, removal of unnecessary reachability and tightened monitoring for exploitation attempts against the specific flaw (TR 62443-2-3 covers
- [OSC Global and InfraShield launch Janus Cyber to address advanced reactor OT, nuclear and military cybersecurity](https://cybernoz.com/osc-global-and-infrashield-launch-janus-cyber-to-address-advanced-reactor-ot-nuclear-and-military-cybersecurity/) - OSC Global and InfraShield announced Janus Cyber, a cybersecurity teaming initiative created to help advanced reactor developers address the nuclear regulatory, Department of War (DoW) authorization, and operational technology/industrial control systems (OT/ICS) cybersecurity requirements associated with deployment on U.S. military installations. Advanced reactors operating in U.S. military environments sit at the intersection of three distinct
- [Pharmaceutical sector urged to shift cyber resilience focus from systems to medicine value chains](https://cybernoz.com/pharmaceutical-sector-urged-to-shift-cyber-resilience-focus-from-systems-to-medicine-value-chains/) - Pharmaceutical companies need to rethink cyber resilience around the continuity of medicine value chains rather than recovery of individual systems, Ashish Gupta, partner at PwC, and Jonathan Sinclair, head of cyber resilience at Roche, wrote in a recent story published by the World Economic Forum (WEF). They observed that ransomware, supply-chain compromises and OT (operational
- [Defeating Kubernetes Privilege Escalation: A Cloud Detection & Response Case Study](https://cybernoz.com/defeating-kubernetes-privilege-escalation-a-cloud-detection-response-case-study/) - Attackers are constantly searching for new ways to target cloud environments and escalate initial access into full administrative privileges.In recent months, our research team has observed a rise in attempts to escalate privileges from access to Kubernetes clusters to cloud control planes, creating significant risks for many organizations. As containers often lack the visibility and
- [Chinese-speaking threat actors targeting Mexican Android users with remote access Trojan](https://cybernoz.com/chinese-speaking-threat-actors-targeting-mexican-android-users-with-remote-access-trojan/) - Intel 471 Malware Intelligence researchers recently uncovered a sprawling phishing operation that used Meta Ads to distribute a newly identified Android remote access trojan (RAT) targeting Spanish-speaking users in Mexico. This sophisticated spyware, which we are tracking as PanDa, provides extensive surveillance to spy on the victim and collect sensitive data, including screen streaming, hidden
- [Agentic Frameworks Summary | Elastic Security Labs](https://cybernoz.com/agentic-frameworks-summary-elastic-security-labs/) - Security teams and SOC analysts still face the same tier-1 response challenges since the early 2000s, from alert volumes to missed threats. While generative AI offers promising solutions, implementing effective AI-augmented security systems beyond simple LLM integration requires deep knowledge and nuanced details to address today's complexities and the manual decision-making process. Transforming detection engineering
- [US charges Russian for infecting 80,000 freelancers with malware](https://cybernoz.com/us-charges-russian-for-infecting-80000-freelancers-with-malware/) - A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. 40-year-old Searzhudin Tamirlanovich Aktulaev was extradited to the United States after being arrested in Cyprus at Larnaca Airport in May 2025. According to court documents filed in June
- [Critical SonicWall Remote Code Execution Vulnerabilities Actively Exploited in Attacks](https://cybernoz.com/critical-sonicwall-remote-code-execution-vulnerabilities-actively-exploited-in-attacks/) - SonicWall has warned that attackers are actively exploiting two critical vulnerabilities affecting SMA1000 Series secure mobile access appliances. The flaws could allow unauthenticated attackers to access sensitive functionality and enable administrators with authenticated access to execute arbitrary operating system commands. The company published advisory SNWLID-2026-0016 on September 1, 2026, confirming that its Product Security Incident
- [Retired Devices, Active Risks: How an ITAD Company Protects Data After Decommissioning](https://cybernoz.com/retired-devices-active-risks-how-an-itad-company-protects-data-after-decommissioning/) - A laptop can be removed from an employee’s desk, disconnected from the network and marked retired in an asset system within the same afternoon. None of those steps means the data risk has disappeared. Retired technology often sits in storage rooms or staging locations before reaching its final destination. During that period, devices still contain
- [Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws](https://cybernoz.com/google-patches-26-chrome-vulnerabilities-including-critical-webgl-and-shared-tab-groups-flaws/) - Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled
- [Keepnet launches free SMS/Call Reporter for iOS](https://cybernoz.com/keepnet-launches-free-sms-call-reporter-for-ios/) - Keepnet, an Extended Human Risk Management (xHRM) and Secure Behavior Management platform, today launched the Keepnet SMS/Call Reporter. It is a free app that turns a suspicious SMS or phone call into a one-tap report. Anyone can download it for personal protection. Organizations can roll it out across their workforce. The app is available now
- [Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another](https://cybernoz.com/researchers-use-claude-to-port-pre-auth-rce-exploit-from-one-plc-model-to-another/) - Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command, which
- [Datacentre water use: Not so simple a picture as often painted](https://cybernoz.com/datacentre-water-use-not-so-simple-a-picture-as-often-painted/) - Calls to halt new datacentres often focus on tales of their gargantuan appetite for water and electricity. Such arguments are magnified in current conditions. Drought was declared throughout large parts of England in July. Wildfires across the parched countrysides of France and Spain forced 320,000 people to flee. The Danube fell too low to cool Hungary’s
- [Cook hands Apple to Ternus](https://cybernoz.com/cook-hands-apple-to-ternus/) - When Tim Cook took over as Apple's CEO, he did not try to fill the big ⁠shoes of ⁠its legendary founder and product visionary Steve Jobs. Instead, he took Jobs' advice: "Never ask what I would do, just do the right thing." Fifteen years on, having taken the iPhone maker from a US$350 billion ($490
- [SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks](https://cybernoz.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/) - SonicWall is urging customers of its SMA1000 series secure remote access gateway and SSL-VPN appliance to patch two new zero-day vulnerabilities that have been exploited in the wild. According to an advisory published by SonicWall on Tuesday, the vulnerabilities and their exploitation were discovered internally. One of the flaws, tracked as CVE-2026-83548 with a CVSS
- [Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher](https://cybernoz.com/chaotic-eclipse-releases-kaspersky-zero-day-hardbreacher/) - Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher Pierluigi Paganini September 01, 2026 Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Kaspersky Endpoint Security. The researcher named
- [Congress advances new bill to give US edge in open-source AI race with China](https://cybernoz.com/congress-advances-new-bill-to-give-us-edge-in-open-source-ai-race-with-china/) - The US Congress on Tuesday advanced a new bill that seeks to establish American global leadership in open-source artificial intelligence, an area where China currently dominates, by promoting adoption of US open-source models and publicising risks associated with using their Chinese counterparts.The legislation was one of several proposals marked up in the US House of
- [Anthropic makes changes to stop AI agents running amok again](https://cybernoz.com/anthropic-makes-changes-to-stop-ai-agents-running-amok-again/) - Anthropic maintained that its internal security posture was not a contributing factor. The exploits occurred in a third party environment where internet access was mistakenly left open, so “the models had no need to ‘hack out’ of anything, even if they had been inclined to do so.” Still, the incidents underscored the importance of hardening
- [AWS Console Session Traceability: How Attackers Obfuscate Identity Through the AWS Console](https://cybernoz.com/aws-console-session-traceability-how-attackers-obfuscate-identity-through-the-aws-console/) - For any security operations team, a key question whenever a new alert pops up is inevitably the same: Who did it?Exposing which entities were involved in a threat is a crucial first step in any investigation. Once responders know who triggered the alert, they can move on to deeper questions like:Is this a typical behavior
- [Cybersecurity IR Workshop: The workshop you shouldn’t miss](https://cybernoz.com/cybersecurity-ir-workshop-the-workshop-you-shouldnt-miss/) - In this article Cybersecurity incidents can unfold in hours, but response plans often fail at the point of execution: ownership is unclear, investigation findings is difficult to access, and critical decisions are delayed. That is why incident response cannot be something your organization figures out in real time. The Detection and Response Team (DART) –
- [TOR Exit Node Monitoring Overview](https://cybernoz.com/tor-exit-node-monitoring-overview/) - Why Monitoring for TOR Exit Node Activity Matters In today’s complex cybersecurity landscape, one of the most overlooked but critical elements in proactive threat detection is monitoring for TOR (The Onion Router) exit node activity. TOR enables anonymous communication, and while it serves legitimate privacy interests, it also provides cover for cybercriminals, malware campaigns, and
- [Aesto Health says data breach affects over 9.5 million patients](https://cybernoz.com/aesto-health-says-data-breach-affects-over-9-5-million-patients/) - Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. The private technology company provides software-as-a-service solutions that help healthcare organizations migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices. The company first informed the public of the attack
- [Anthropic Launches Claude Fable and Mythos 5.1 for Advanced Coding and Research](https://cybernoz.com/anthropic-launches-claude-fable-and-mythos-5-1-for-advanced-coding-and-research/) - Anthropic has rolled out two new frontier AI models, Claude Fable 5.1 and Claude Mythos 5.1, positioning them as the most capable systems yet for software development, enterprise knowledge work, and scientific research. While both models share identical underlying architecture, they differ in one key respect: the strength of their safeguards. Fable 5.1 is generally
- [7 Ways to Boost Conversions on Your Website](https://cybernoz.com/7-ways-to-boost-conversions-on-your-website/) - If your website is attracting visitors but not generating enough enquiries, sales or leads, there are several techniques you can use to improve your conversion rate. From adding a website toolbar and interactive calculators to using limited-time offers and personalised pop-ups, the key is to make it easier and more compelling for visitors to take
- [Five Plead Guilty to Using ATM Jackpotting Malware in Cash Theft Scheme](https://cybernoz.com/five-plead-guilty-to-using-atm-jackpotting-malware-in-cash-theft-scheme/) - Five Venezuelan nationals have pleaded guilty in a federal case involving attempts to deploy ATM jackpotting malware against cash machines in Kansas. This case highlights a growing cyber-physical threat targeting financial institutions across the United States. The case arose from an FBI investigation into an alleged scheme to force automated teller machines (ATMs) to dispense
- [Berlin refuses to be blackmailed after network breach](https://cybernoz.com/berlin-refuses-to-be-blackmailed-after-network-breach/) - Berlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior Senator Iris Spranger addressed the extortion attempt on Friday, following an emergency Senate session at the Rotes Rathaus. “The state of Berlin is being blackmailed,” Wegner said. “Berlin has fallen victim
- [Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems](https://cybernoz.com/breeze-comet-executes-hundreds-of-fraudulent-transactions-via-brazilian-payment-systems/) - Ravie LakshmananSep 01, 2026Cybercrime / Malware Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems and banking software in Brazil to conduct
- [AI has exposed the cracks GDPR was already trying to fix](https://cybernoz.com/ai-has-exposed-the-cracks-gdpr-was-already-trying-to-fix/) - The General Data Protection Regulation (GDPR) predates the commercial availability of large language models by several years. It forced organisations to answer questions most of them had never really had to answer before: including specifically where did this data come from, and does the reason we collected it still hold? Most couldn’t; many still can't.
- [Realise the full potential of AI with inference economics and Penguin Solutions](https://cybernoz.com/realise-the-full-potential-of-ai-with-inference-economics-and-penguin-solutions/) - Organisations transitioning from AI training to inference can control costs more effectively by moving from cloud-only to hybrid environments and locating workloads based on economic, performance and governance criteria, according to Penguin Solutions. Exploding, unpredictable AI costs Inference costs compound with every user, prompt and query, meaning pay per token costs can climb quickly
- [Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense](https://cybernoz.com/sevii-targets-ai-speed-attacks-with-preemptive-autonomous-defense/) - Fighting fire with fire is a known response. Fighting AI attacks with AI defense is a growing practice. But instant remediation is new and welcome. Sevii has extended its Autonomous Defense & Remediation (ADR) platform with a new AI security module. As the speed and scope of AI driven attacks increases, it requires an AI
- [Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt](https://cybernoz.com/five-venezuelan-nationals-plead-guilty-in-kansas-atm-jackpotting-attempt/) - Five Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting Attempt Pierluigi Paganini September 01, 2026 Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty after trying to steal cash from ATMs in Kansas using the
- [FBI raises alarm over deceptive phishing campaign targeting prominent people](https://cybernoz.com/fbi-raises-alarm-over-deceptive-phishing-campaign-targeting-prominent-people/) - Attackers are targeting prominent, high-profile people, their family members and acquaintances on a commercial messaging application to gain long-term access to their accounts containing sensitive data, the FBI warned in an alert Tuesday. Officials did not describe the objectives or origins of the attackers, which have more recently impersonated government officials, journalists and publicly known
- [US Congress seeks to identify foreign countries behind scam calls](https://cybernoz.com/us-congress-seeks-to-identify-foreign-countries-behind-scam-calls/) - US lawmakers are trying to identify which foreign countries are the biggest sources of unlawful robocalls targeting Americans, as Congress steps up efforts to combat a surge in phone scams.The inquiry follows a string of US government reports tying much of the financial damage from scams to Chinese criminal networks based in Southeast Asia.The House
- [Actuaries Institute and UTS HTI publish AI risk management guidance for financial services](https://cybernoz.com/actuaries-institute-and-uts-hti-publish-ai-risk-management-guidance-for-financial-services/) - The Actuaries Institute and the University of Technology Sydney’s Human Technology Institute (HTI) have released a practical guidance resource aimed at improving how financial services organisations manage risks associated with artificial intelligence. The guidance, titled AI Risk Management in the Financial Services Sector, is positioned as a framework that can be implemented and adapted by organisations
- [What happens when AI models take aim at ICS exploits](https://cybernoz.com/what-happens-when-ai-models-take-aim-at-ics-exploits/) - This is an important challenge because different PLC models from the same vendor or even different manufacturers might share a vulnerable component, with the rest of the firmware being significantly different. Furthermore, vendors sometimes patch a vulnerability reported in one model without comprehensively assessing whether the same flaw affects others in their product line. For
- [Frost & Sullivan Radar Report Recognizes Wiz as CSPM Leader](https://cybernoz.com/frost-sullivan-radar-report-recognizes-wiz-as-cspm-leader/) - In the latest Frost Radar for Cloud Security Posture Management (CSPM), 2024 analyst researcher Anh Tien Vu highlights how CSPM solutions are critical to securing infrastructure in a time of increasing complexity and mounting threats. The Radar report, which uses a methodology and objective ratings system to analyze a dozen vendors, recognized Wiz as a
- [From Hypothesis to Action: Proactive Threat Hunting with Elastic Security](https://cybernoz.com/from-hypothesis-to-action-proactive-threat-hunting-with-elastic-security/) - When a new threat actor technique emerges — whether from a research blog, an intelligence feed, or breaking news — every threat hunter instinctively shifts into hypothesis mode. Could this be happening in my environment? Are early signals hiding in the noise? Take the recent TOLLBOOTH research as an example. The moment Elastic Security Labs
- [Hackers abuse Faronics Deploy admin tool to install ScreenConnect](https://cybernoz.com/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/) - Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. In activity observed between July 21 and August 20, Faronics-themed lures reached more than 457 endpoints via emails disguised as invoices, tax documents, or other business files. Faronics Deploy is a
- [Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability](https://cybernoz.com/hackers-actively-exploiting-critical-langflow-rce-and-rails-vulnerability/) - Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry. The first issue, tracked as CVE-2026-0768, affects Langflow, a low-code platform for building AI-powered applications, agents, and workflow automations. VulnCheck observed
- [AI threat hunting 2026 - IT Security Guru](https://cybernoz.com/ai-threat-hunting-2026-it-security-guru/) - If you’re in the market for an AI threat hunting solution, chances are you’re evaluating based on investigation quality. That’s an understandable and reasonable metric to go on – investigation quality is important, and most vendors focus their marketing on it. It’s not, however, the most important metric. Pretty much every vendor has decent investigation
- [FBI Probes Service Selling 153M+ Drivers Licenses – Krebs on Security](https://cybernoz.com/fbi-probes-service-selling-153m-drivers-licenses-krebs-on-security/) - A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used
- [OpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber Abilities](https://cybernoz.com/openai-is-about-to-release-its-first-ai-model-with-critical-cyber-abilities/) - OpenAI announced Tuesday that its forthcoming AI model, Astra, is its first to reach the company’s threshold for what it calls “critical” cyber capabilities. OpenAI says it plans to publicly release a version of Astra “soon,” but will make the model’s advanced cyber capabilities available only to select partners in its Daybreak Blue early-access program
- [Hackers Pose as IT Support on Microsoft Teams to Target More Than 150 Employees](https://cybernoz.com/hackers-pose-as-it-support-on-microsoft-teams-to-target-more-than-150-employees/) - A coordinated social-engineering campaign dubbed Spring Ring used external Microsoft Teams accounts to impersonate corporate IT help desk staff and target more than 150 employees across at least 10 organizations between January and April 2026. The operation demonstrates how attackers are shifting phishing activity from email into trusted collaboration platforms, using live voice calls to
- [Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks](https://cybernoz.com/vishing-campaign-abuses-microsoft-teams-to-give-attackers-a-foothold-in-company-networks/) - A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ threat intelligence team. The campaign ran between January and April 2026 and reached more than 150 employees at more
- [Infostealers are hijacking Claude accounts at users’ expense](https://cybernoz.com/infostealers-are-hijacking-claude-accounts-at-users-expense/) - Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used
- [Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure](https://cybernoz.com/attackers-exploit-critical-jfrog-artifactory-flaw-to-mint-admin-tokens-days-after-disclosure/) - Ravie LakshmananSep 01, 2026Vulnerability / Supply Chain Attack Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. "JFrog Artifactory contains an
- [The loop nobody's checking the size of](https://cybernoz.com/the-loop-nobodys-checking-the-size-of/) - AI is now doing a growing share of the frontline work inside security operations, triaging alerts, correlating signals across systems, drafting the first read on what's happening and, in some cases, taking the first containment action itself. That shift was inevitable. No team of analysts can work at the speed or volume attackers now operate
- [Jetstar gives Skywise a cousin to optimise fleet](https://cybernoz.com/jetstar-gives-skywise-a-cousin-to-optimise-fleet/) - Key points Jetstar has built a new AI-driven fleet optimisation system called Flow to cut costs and minimise delays across its 3000 weekly flights. Flow picks through 500,000 operating constraints, translating to 1.5 million decisions per week, to decide which aircraft should fly each route. The platform augments rather than replaces human planners, and its
- [Palo Alto Networks Acquires AI Agent Platform Console](https://cybernoz.com/palo-alto-networks-acquires-ai-agent-platform-console/) - Palo Alto Networks (NASDAQ: PANW) on Tuesday announced that it has acquired Console, an AI-native platform designed to help organizations build agentic workflows and automate operational tasks using natural language. The cybersecurity giant said Console will deepen the agentic capabilities of its Cortex platform, allowing security teams to investigate signals, prioritize work, and automatically take
- [Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague](https://cybernoz.com/chaotic-eclipse-releases-gendigital-avast-antivirus-zeroday-prettyprague/) - Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague Pierluigi Paganini September 01, 2026 Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Antivirus. The researcher named the exploit PrettyPrague,
- [Security policies fail to keep up with a hybrid cloud world](https://cybernoz.com/security-policies-fail-to-keep-up-with-a-hybrid-cloud-world/) - Roughly two-thirds of companies have suffered a business-critical app outage due to misconfigured security policies, a Cloud Security Alliance report found. Source link
- [Tina Peters, through attorney, backs off formal role in Shasta County elections](https://cybernoz.com/tina-peters-through-attorney-backs-off-formal-role-in-shasta-county-elections/) - Tina Peters, the former Mesa County election clerk convicted of seven felonies related to the theft of voting machine software, said Tuesday through her attorney that she won’t accept a formal position overseeing elections in Shasta County, Calif. Last month, Shasta County registrar of voters Clint Curtis said he intended to hire Peters as assistant
- [CrowdStrike launches cyber frontier AI models, agentic security system](https://cybernoz.com/crowdstrike-launches-cyber-frontier-ai-models-agentic-security-system/) - The SafeMind agentic system will be available natively in CrowdStrike Falcon, but as Kurtz mentioned, enterprises will be able to access the Red Tempest and Blue Solano models directly through the company’s Project QuiltWorks trusted access program to expand their use of the models. SafeMind, which was built in partnership with Nvidia and is based
- [ISA and OTCC join forces to advance standards-based OT cybersecurity across critical infrastructure](https://cybernoz.com/isa-and-otcc-join-forces-to-advance-standards-based-ot-cybersecurity-across-critical-infrastructure/) - The International Society of Automation (ISA), a professional society for automation and the Operational Technology Cybersecurity Coalition (OTCC), a coalition working to improve operational technology (OT) cybersecurity through open, vendor-neutral collaboration, have announced their intention to collaborate to help strengthen OT cybersecurity across critical infrastructure. The two organizations have signed a Memorandum of Understanding (MOU)
- [Marlink expands OT security capabilities as connected maritime and industrial systems face growing cyber risks](https://cybernoz.com/marlink-expands-ot-security-capabilities-as-connected-maritime-and-industrial-systems-face-growing-cyber-risks/) - Marlink has launched a new OT Security offering for maritime and land-based industries. Combining professional services and OT-native technology solutions, the offering helps organizations protect the safety, continuity and resilience of operational technology. OT controls physical processes across industries including vessel navigation, propulsion and cargo handling at sea; energy production, water treatment and industrial automation
- [How we could save petabytes of cache storage with Zstandard and Pingora](https://cybernoz.com/how-we-could-save-petabytes-of-cache-storage-with-zstandard-and-pingora/) - Memory costs are increasing dramatically. Both RAM and hard disk drive prices have exploded over the past year. At Cloudflare, we run several massively distributed storage products (including our famous CDN) that rely on making efficient use of the memory we have deployed so we can continue to serve all of our customers.With this in
- [The Agentic SOC – From AI Theater to Real Defense](https://cybernoz.com/the-agentic-soc-from-ai-theater-to-real-defense/) - Moving beyond "AI theater" with measurable KPIs: Security teams must distinguish between genuine value and "productivity theater." Success requires defining concrete KPIs—such as cost improvement, risk reduction, and speed—to measure true ROI, rather than deploying AI tools without a clear strategic purpose. Mitigate new autonomous risks: The shift to an agentic SOC introduces distinct threats,
- [How Elastic Infosec Optimizes Defend for Cost and Performance](https://cybernoz.com/how-elastic-infosec-optimizes-defend-for-cost-and-performance/) - In the world of Security Operations Centers (SOCs), data is valuable, but excessive data can be problematic. Collecting every single event from every endpoint is expensive, unnecessary, and could lead to performance issues on your workstations and clusters. At Elastic, we treat our own InfoSec team as "Customer Zero", we run the latest versions of
- [Critical Langflow flaw exploited to steal OpenAI and AWS keys](https://cybernoz.com/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/) - Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. The security issue received a critical severity rating and resides in the code validator of Langflow’s custom component editor. Threat intelligence company VulnCheck detected the activity on its honeypots
- [Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations](https://cybernoz.com/attackers-abuse-trusted-cloud-services-to-hide-phishing-attacks-against-financial-organizations/) - Cybercriminals are increasingly weaponizing trusted cloud platforms such as Microsoft Azure, Google Firebase, Google Cloud Storage, Amazon Web Services, and Cloudflare to host phishing infrastructure aimed squarely at the financial sector, making malicious traffic nearly indistinguishable from legitimate business activity. Security researchers describe this as a structural shift toward what some call Trusted Infrastructure Phishing,
- [Forescout Research Tests Whether AI Can Create PLC Attacks](https://cybernoz.com/forescout-research-tests-whether-ai-can-create-plc-attacks/) - New research from Forescout’s Vedere Labs has demonstrated how artificial intelligence could begin to lower the barriers to developing sophisticated cyberattacks against industrial systems. The research set out to answer a potentially important question for operational technology (OT) security: can AI successfully adapt a remote code execution (RCE) exploit developed for one programmable logic controller
- [Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks](https://cybernoz.com/hackers-exploit-critical-langflow-and-ruby-on-rails-flaws-in-active-rce-attacks/) - Threat actors are actively exploiting two newly disclosed remote code execution vulnerabilities affecting Langflow and Ruby on Rails. These campaigns focus on cloud credential theft, host reconnaissance, and the establishment of command-and-control (C2) functions. VulnCheck researchers have reported exploitation targeting CVE-2026-0768 in Langflow, a low-code platform for building AI-powered applications and automated workflows. This vulnerability
- [CISA review makes the case for eliminating vulnerability classes](https://cybernoz.com/cisa-review-makes-the-case-for-eliminating-vulnerability-classes/) - For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of weaknesses at the source. “By reducing these root causes during software development, providers can help
- [Fake GTA 6 leaked copy drains your crypto wallet](https://cybernoz.com/fake-gta-6-leaked-copy-drains-your-crypto-wallet/) - We’ve seen scam sites built around Grand Theft Auto VI (GTA 6) targeting visitors in three different ways this year. In June, we looked at sites selling GTA 6 “early access” for hundreds of dollars in cryptocurrency. You paid, got nothing, and could not reverse the payment. In August, we found fake Extended Look and demo sites delivering an
- [13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds](https://cybernoz.com/13-malicious-packagist-packages-target-unpatched-iphones-to-steal-crypto-wallet-seeds/) - Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud
- [The Next AI Breakthrough Won't Be a Bigger Model](https://cybernoz.com/the-next-ai-breakthrough-wont-be-a-bigger-model/) - For the past five years, the AI industry has pursued a remarkably simple strategy: build a bigger model. More parameters. More data. More GPUs. The approach has worked spectacularly well. Take ChatGPT, GPT-2 became GPT-3. GPT-3 became GPT-4. Reasoning models have grown dramatically more capable, and there is every reason to believe frontier models will
- [China-Linked Fire Ant Turn Cisco Routers To Spying Platforms](https://cybernoz.com/china-linked-fire-ant-turn-cisco-routers-to-spying-platforms/) - The China-nexus espionage group Fire Ant has moved from compromising virtualization platforms to implanting Cisco IOS XR routers and TACACS authentication servers. They are using them to capture traffic, harvest administrator credentials and suppress the logs defenders rely on, said researchers at Sygnia, an incident response firm. Researchers first documented Fire Ant in July 2025
- [US officials backpedal on claims that gov agencies were hacked](https://cybernoz.com/us-officials-backpedal-on-claims-that-gov-agencies-were-hacked/) - Key points US officials have walked back claims that several government agencies were hacked by Chinese spies, now calling them targets rather than victims. The Justice Department's edited statement says the US Senate, the Federal Reserve, NASA, and others were among the targets of QTFY, a Chinese spy platform. Reuters could not confirm which agencies
- [Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars](https://cybernoz.com/experiment-porting-a-plc-exploit-with-ai-takes-hours-and-hundreds-of-dollars/) - Researchers at Forescout’s Vedere Labs used Anthropic’s Claude to port a working remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another. They succeeded but only after extensive researcher oversight, several hours of dedicated work, and hundreds of dollars in API costs. The starting point was a previously developed exploit for
- [Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records](https://cybernoz.com/attackers-access-aesto-health-aws-infrastructure-exposing-9-5-million-records/) - Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records Pierluigi Paganini September 01, 2026 Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging
- [Frontier AI used to help exploit flaws in key industrial devices](https://cybernoz.com/frontier-ai-used-to-help-exploit-flaws-in-key-industrial-devices/) - A report showed that Claude could help hackers develop attack strategies targeting PLCs used by water utilities and other industries. Source link
- [Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots](https://cybernoz.com/whistleblower-says-usps-deploying-new-untested-it-systems-governing-mail-in-ballots/) - A newly released whistleblower complaint reveals details about the “rushed” effort by the Trump administration and U.S. Postal Service to install three new restrictive IT systems that would potentially deny thousands of mail-in ballots, if the federal government disagrees on their eligibility. According to the complaint, written by attorneys at the nonprofit Whistleblower Aid and
- [Suspected cyberattack puts data of 33,054 customers using group-buying app at risk](https://cybernoz.com/suspected-cyberattack-puts-data-of-33054-customers-using-group-buying-app-at-risk/) - The private data of about 33,000 customers of TVB-owned group-buying platform Neigbuy has been compromised in a suspected cyberattack, with police saying they have received six reports of scammers posing as staff.The Office of the Privacy Commissioner for Personal Data confirmed on Tuesday that it had received a data breach notification from the company on
- [OpenClaw rolls out system-wide overhaul, updates security controls across agent platform](https://cybernoz.com/openclaw-rolls-out-system-wide-overhaul-updates-security-controls-across-agent-platform/) - OpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and security controls, as enterprises increasingly evaluate how such agent-based systems operate across connected environments. “This update touches every part of OpenClaw, including installation, messaging, memory, skills, models, automations, the browser and native apps,
- [US launches Project Watershed 250 to tackle water system cybersecurity vulnerabilities with AI, red-team exercises](https://cybernoz.com/us-launches-project-watershed-250-to-tackle-water-system-cybersecurity-vulnerabilities-with-ai-red-team-exercises/) - The U.S. administration is launching Project Watershed 250, a six-month pilot in Texas designed to identify and address cybersecurity vulnerabilities in water systems before adversaries can exploit them. The initiative brings together federal agencies, Texas Cyber Command, local governments and cybersecurity companies to test existing utility defenses and strengthen vulnerable systems using cybersecurity and AI
- [USCG creates Office of Maritime Cybersecurity Policy to coordinate policy, compliance and enforcement](https://cybernoz.com/uscg-creates-office-of-maritime-cybersecurity-policy-to-coordinate-policy-compliance-and-enforcement/) - The U.S. Coast Guard announced that it has established the Office of Maritime Cybersecurity Policy to serve as its central authority for cybersecurity policy across the Marine Transportation System (MTS), citing the growing use of information and operational technology in the maritime industry and the associated risks to critical infrastructure. Created under the Director of
- [Introducing Continuous Vulnerability Assessment (CVA)](https://cybernoz.com/introducing-continuous-vulnerability-assessment-cva/) - We are excited to introduce Wiz's Continuous Vulnerability Assessment (CVA) - a fundamentally new operating model for vulnerability scanning that helps teams keep up in the AI Threat Era. Today, the window between "vulnerability published" and "actively exploited" is shrinking fast - and teams that rely on scheduled scanning are left exposed. Wiz CVA solves this
- [From Alert Fatigue to Agentic Response: How Workflows and Agent Builder Close the Loop](https://cybernoz.com/from-alert-fatigue-to-agentic-response-how-workflows-and-agent-builder-close-the-loop/) - SOC leaders face a daily battle against basic math that doesn’t add up. Data volumes are growing exponentially, attack surfaces are expanding globally, yet your team’s capacity remains linear. You cannot hire your way out of this problem. Line chart demonstrating exponential increase in data, alerts, insights and linear increase in human capacity Attempting to
- [Why Even the Best Edge Security Still Misses High-Risk Sessions](https://cybernoz.com/why-even-the-best-edge-security-still-misses-high-risk-sessions/) - Security teams have more edge controls at their disposal than ever, and each plays an important role. Yet, despite the best request inspection, credential validation, device fingerprinting, and automation signals available, attackers still successfully hide inside traffic that looks remarkably similar to legitimate user activity. One reason for this is that each security control focuses
- [Five Hackers Plead Guilty to ATM Jackpotting Attacks Using Malware to Dispense Cash](https://cybernoz.com/five-hackers-plead-guilty-to-atm-jackpotting-attacks-using-malware-to-dispense-cash/) - Five Venezuelan nationals have pleaded guilty in a U.S. federal case involving attempted ATM jackpotting attacks. This criminal technique uses malware to force cash machines to dispense money without legitimate customer transactions. The case follows an FBI investigation into attempts to compromise ATMs in Wamego and Manhattan, Kansas, during December 2025. U.S. Attorney Ryan A.
- [Filigran attack chaining - IT Security Guru](https://cybernoz.com/filigran-attack-chaining-it-security-guru/) - Filigran has launched a new attack chaining capability for its OpenAEV platform, designed to help security teams test how multiple weaknesses can be combined to create a viable path through an organisation’s environment. Released as part of OpenAEV v3, Attack Chaining allows penetration tests and red team exercises to adapt dynamically based on what a
- [Using High-Energy Laser, US Shoots Down Drones Near Mexico Border](https://cybernoz.com/using-high-energy-laser-us-shoots-down-drones-near-mexico-border/) - This week, the US Army used a high-energy multipurpose laser to shoot down three drones near the US-Mexico border, which official reports claimed were “posing a physical threat to US military personnel and CBP partners,” referring to Customs and Border Patrol.The operation took place between the night of August 25 and the early morning of
- [Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs](https://cybernoz.com/mirage-kitten-hackers-use-fake-coding-challenges-to-deploy-noderabbit-and-pollcat-rats/) - Iran-linked threat actor Mirage Kitten is targeting software developers with fake recruitment assessments that hide two newly identified cross-platform remote access trojans: NodeRabbit and PollCat. The campaign uses recruiter impersonation on LinkedIn and other job-search platforms, weaponized Node.js projects, and cloud-hosted ZIP archives to gain covert access to developer endpoints across Windows, Linux, and macOS.
- [Recorded Future: The World's Largest Pure-Play Threat Intelligence Company](https://cybernoz.com/recorded-future-the-worlds-largest-pure-play-threat-intelligence-company/) - When we were at Black Hat USA 2026 with Mastercard, Cybercrime Magazine met Levi Gundert, Chief Security & Intelligence Officer at Recorded Future, the world’s largest pure-play threat intelligence company. “We’re all grappling with cyberattacks,” says Gundert. The velocity is the biggest issue that defenders are now facing. Right now is the time that defenders really need to
- [Fake Claude Opus 5 app delivers malware and wipes its own tracks](https://cybernoz.com/fake-claude-opus-5-app-delivers-malware-and-wipes-its-own-tracks/) - A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository README using Claude Opus 5 branding and a “Free” hook (Source: Morphisec) “RevStealer is a Windows information stealer that is
- [TerminalFix looks like ClickFix, but delivers a very different payload](https://cybernoz.com/terminalfix-looks-like-clickfix-but-delivers-a-very-different-payload/) - Microsoft has published details about a Windows malware campaign it calls TerminalFix. The social engineering used to infect people is very similar to what we’ve seen in ClickFix campaigns. A website visitor is presented with a fake Cloudflare CAPTCHA which, when clicked, secretly copies a malicious command to their clipboard. Then they receive instructions on
- [Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones](https://cybernoz.com/threat-actors-dont-want-better-attacks-they-want-repeatable-ones/) - The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix,
- [Chancellor unveils plans to entice UK tech startups](https://cybernoz.com/chancellor-unveils-plans-to-entice-uk-tech-startups/) - The UK chancellor, John Healey, has unveiled the £100m Sovereign AI R&D Procurement Scheme to support British firms developing artificial intelligence (AI) for public sector projects that apply nationally. As part of the UK government’s expansion plans for computing infrastructure, the scheme aims to drive future national growth and help the country capture more of
- [Privacy Act overhaul to tighten 72-hour breach reporting deadline](https://cybernoz.com/privacy-act-overhaul-to-tighten-72-hour-breach-reporting-deadline/) - Key points Draft legislation would give Australian organisations 72 hours to notify the Information Commissioner of an eligible data breach, replacing the current "as soon as practicable" standard. The bill introduces a narrow erasure right binding only large digital platforms that clear a $500m gross revenue test or 2.5 million average monthly Australian end users.
- [Hackers Start Exploiting Critical Langflow Vulnerability](https://cybernoz.com/hackers-start-exploiting-critical-langflow-vulnerability/) - Threat actors have started exploiting a critical-severity remote code execution (RCE) vulnerability in the AI low-code platform Langflow, vulnerability intelligence firm VulnCheck warns. Tracked as CVE-2026-0768 (CVSS score of 9.8), the security defect exists within the code validator in Langflow’s custom component editor. Because a user-supplied string is not properly validated before it is used
- [North Korea-linked IT Workers Are Getting Hired Inside Western Companies](https://cybernoz.com/north-korea-linked-it-workers-are-getting-hired-inside-western-companies/) - North Korea-linked IT Workers Are Getting Hired Inside Western Companies Pierluigi Paganini September 01, 2026 Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s investigation
- [This month in security with Tony Anscombe – August 2026 edition](https://cybernoz.com/this-month-in-security-with-tony-anscombe-august-2026-edition/) - Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news 31 Aug 2026 With August coming to a close, it's time for ESET Chief Security Evangelist Tony Anscombe to look back at some of the top cybersecurity stories that have made the news
- [China-linked hackers turn Cisco routers into covert attack infrastructure](https://cybernoz.com/china-linked-hackers-turn-cisco-routers-into-covert-attack-infrastructure/) - Sygnia found attempts to suppress logging and conceal configuration activity on affected network equipment, while evidence was also tampered with on compromised Linux systems. The firm described the operation as creating a potential “target behind the target” scenario, in which access to one organization’s trusted infrastructure could expose paths toward other high-value environments. Sygnia said
- [Preventing the Risk of Request Collapsing in Web Caching](https://cybernoz.com/preventing-the-risk-of-request-collapsing-in-web-caching/) - Every few months it seems a company has a security incident where users are presented with the account of another user when they log in. Many of these are assumed to be due to web caching misconfigurations. While some may be easily understood by software engineers in hindsight, others have been caused by request collapsing,
- [From Qradar to Elastic: Automate your Detection Rule Migration](https://cybernoz.com/from-qradar-to-elastic-automate-your-detection-rule-migration/) - Migrating to a new SIEM is often viewed as a daunting task. The sheer volume of legacy detection rules, dashboards, and custom configurations can keep security teams locked into aging infrastructure simply because the cost of moving — measured in manual effort and time — is too high. Today, we are excited to announce a
- [Five Venezuelans plead guilty to ATM jackpotting attacks in US](https://cybernoz.com/five-venezuelans-plead-guilty-to-atm-jackpotting-attacks-in-us/) - Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. 27-year-old Luis Alberto Velasquez-Artigas, 29-year-oldRoyder Adrian Figuera-Perez, 27-year-old Javier Mejia, Jr, 33-year-old Gabriel Alexjandro Corales-Garcia, 33, and 26-year-old Italo Lizandro Corrales-Carrillo have all pleaded guilty to one count of conspiracy to commit bank
- [Popular npm Package With 150K Weekly Downloads Compromised in Mini Shai-Hulud Supply-Chain Attack](https://cybernoz.com/popular-npm-package-with-150k-weekly-downloads-compromised-in-mini-shai-hulud-supply-chain-attack/) - A JavaScript development package has been caught in a supply-chain compromise that can run malicious code when installed. The incident affects a tool with about 150,000 weekly downloads, risking developer and automated build systems. Attackers published ten tainted releases on August 28 in two bursts. They covered every maintained version line, and a routine dependency
- [Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials](https://cybernoz.com/fake-openai-anthropic-and-deepseek-crawlers-target-env-files-and-cloud-credentials/) - Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan internet-facing servers for exposed secrets, according to a GreyNoise research report published on August 28, 2026. This activity involves automated scanners that use forged crawler user-agent strings to request sensitive files, including .env configurations, AWS
- [Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers](https://cybernoz.com/askeal-the-ai-cybersecurity-assistant-that-gives-verifiable-expert-backed-answers/) - Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The startup, backed by a $1.1 million pre-seed round, is launching the tool with an international community of
- [Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity](https://cybernoz.com/attackers-exploit-critical-langflow-and-rails-flaws-in-credential-probing-and-c2-activity/) - Ravie LakshmananSep 01, 2026Vulnerability / Artificial Intelligence Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute
- [AI and the right to resist](https://cybernoz.com/ai-and-the-right-to-resist/) - Thank you for joining! Access your Pro+ Content below. 1 September 2026 AI and the right to resist Share this item with your network: In this week’s Computer Weekly, we talk to the campaigners pushing back on industry narratives around the use of AI, seeking to bring a more people-oriented approach. Our latest buyer’s guide
- [ADHA sticks with Accenture for My Health Record support](https://cybernoz.com/adha-sticks-with-accenture-for-my-health-record-support/) - The Australian Digital Health Agency will stick with Accenture for infrastructure services underpinning My Health Record, signing a new $162m deal. The agency went to market for "application support and maintenance services" in July last year, testing a package of work that Accenture had held as the "national infrastructure operator" since 2012. The NIO arrangement
- [PaperCut Exploitation Escalates to Active Intrusions](https://cybernoz.com/papercut-exploitation-escalates-to-active-intrusions/) - Attacks exploiting two recently discovered PaperCut NG/MF vulnerabilities have escalated, with threat actors shifting from reconnaissance to hands-on-keyboard activity. PaperCut first warned users of its NG and MF print management solutions about an actively exploited zero-day vulnerability on August 27. It later emerged that threat actors have been chaining two flaws in their attacks. The
- [Reconnaissance unleashed: Meet CrowdRecon | Intigriti](https://cybernoz.com/reconnaissance-unleashed-meet-crowdrecon-intigriti/) - At Intigriti, we have been exploring a simple but important shift in security: the work that happens before a vulnerability report is often where the real signal begins. As vulnerability discovery accelerates, organizations need practical ways to identify and reduce risk before vulnerabilities are used in attacks. In Reconnaissance for exposure management, I discussed how context
- [Uncovering Hybrid Cloud Attacks Part 1 – Addressing the Speed of Cloud Attacks](https://cybernoz.com/uncovering-hybrid-cloud-attacks-part-1-addressing-the-speed-of-cloud-attacks/) - The rapid global migration to cloud environments has created unparalleled opportunities for scaling up IT operations, along with an increasingly high volume of sophisticated cyberattacks. Effectively responding to these attacks can be uniquely challenging. Cloud environments have wide potential attack surfaces for initial compromise, and attackers can leverage APIs and automation to move extremely quickly
- [Automating GOAD and Live Malware Labs](https://cybernoz.com/automating-goad-and-live-malware-labs/) - Introduction: The Need for a Scalable, Automated Simulation Range In modern security operations, detection engineering is no longer a “set it and forget it” discipline. The central challenge for any security team – and the question that underpins the entire purple-team approach is simple: how do you know whether your detection rules genuinely work? Continually
- [Microsoft Exchange Online outage causes email failures, auth issues](https://cybernoz.com/microsoft-exchange-online-outage-causes-email-failures-auth-issues/) - Microsoft is investigating a widespread service issue causing authentication issues, connection problems, email delays and failures, and various other issues for Microsoft 365 customers. It first acknowledged this incident (tracked under EX1464935 in the admin center) at 5:30 PM UTC, when it began investigating a stream of reports from users on social media regarding multiple issues
- [Anthropic Hardens Claude Security After AI Models Gain Unauthorized Access to Real Systems](https://cybernoz.com/anthropic-hardens-claude-security-after-ai-models-gain-unauthorized-access-to-real-systems/) - Anthropic has hardened security around its Claude models after several incidents in which the systems gained unauthorized access to real computers during cybersecurity evaluations. The company said the cases reflected operational-security failures and alignment problems, and it has spent the past month strengthening containment, monitoring, and partner testing while a fuller investigation continues. On July
- [Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities](https://cybernoz.com/metasploit-adds-exploit-for-papercut-mf-ng-zero-day-rce-vulnerabilities/) - Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency involving print management servers. The proposed module targets CVE-2026-81578 and CVE-2026-82078, two vulnerabilities that attackers can exploit to achieve remote code
- [ShinyHunters claims it stole 284 million patient records from McKesson](https://cybernoz.com/shinyhunters-claims-it-stole-284-million-patient-records-from-mckesson/) - Healthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S. healthcare company that distributes pharmaceuticals, medical supplies and other healthcare products to pharmacies, hospitals and clinics. According to the SEC filing, the intrusion was detected on August 25, 2026. The company said the
- [Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance](https://cybernoz.com/securing-claude-code-the-new-compliance-api-local-visibility-and-identity-governance/) - Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate. AI has
- [Expired anti-spam domain bites NZ's national stadium, Eden Park](https://cybernoz.com/expired-anti-spam-domain-bites-nzs-national-stadium-eden-park/) - Key points Eden Park's DNS configuration referenced an expired domain, spamcontrol.co.nz, letting consultant Alex Shakhov capture DMARC reports for a year. Shakhov said the reports mapped Eden Park's infrastructure within 30 days and revealed 600 companies it communicates with, including sponsors and agents. The stadium says no data was compromised and has now updated its
- [McKesson Confirms Data Breach as Attacker Deadline Looms](https://cybernoz.com/mckesson-confirms-data-breach-as-attacker-deadline-looms/) - Healthcare giant McKesson Corporation over the weekend confirmed that hackers exfiltrated customer data from its systems, as the ShinyHunters extortion group is threatening to release the stolen information. McKesson delivers roughly one-third of prescription medicines to North American hospitals, pharmacies, and healthcare clinics. It also provides medical supplies, supports cancer treatment and specialty care, and
- [Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers](https://cybernoz.com/critical-givewp-flaw-lets-attackers-run-commands-on-wordpress-servers/) - Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers Pierluigi Paganini August 31, 2026 A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated
- [McKesson copes with fallout from data theft extortion attack](https://cybernoz.com/mckesson-copes-with-fallout-from-data-theft-extortion-attack/) - McKesson said its business and distribution centers remain operational in the wake of a cyberattack it disclosed Friday that resulted in data theft and temporary service interruptions. Attackers gained access to some of the health care vendor’s third-party applications and stole data associated with a subset of customers in the company’s oncology, multispecialty and medical-surgical
- [Diraq and Equinix to deploy Australia’s first quantum computer inside a data centre](https://cybernoz.com/diraq-and-equinix-to-deploy-australias-first-quantum-computer-inside-a-data-centre/) - Quantum computing specialist Diraq says it will deploy what it describes as Australia’s first quantum computer operating inside a commercial data centre, to be installed at an Equinix facility in Sydney. The system, due to be installed in October 2026, is expected to be housed alongside conventional computing infrastructure already operating in the data centre.
- [Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off](https://cybernoz.com/windows-bug-incorrectly-tells-users-that-microsoft-defender-antivirus-is-turned-off/) - “Six months from now, an insurer looking at a breached server won’t accept ‘Microsoft said there was a bug’ as proof that Defender was running. The popup says off. Microsoft says on. The company’s own telemetry has to break the tie,” he said. “That means time-stamped records of sensor check-ins, Defender versions, and any gaps
- [Uncovering Hybrid Cloud Attacks Part 2 – The Attack](https://cybernoz.com/uncovering-hybrid-cloud-attacks-part-2-the-attack/) - Effective response to cloud and hybrid attacks can be uniquely challenging. In this three-part series, we discuss how implementing intelligence-driven contextualized incident response allows defenders to turn attackers’ advantages in the cloud against them and respond more effectively to threats. After introducing the concept in part one, in this second part of the series, we’ll share
- [DYNOWIPER: Destructive Malware Targeting Poland's Energy Sector](https://cybernoz.com/dynowiper-destructive-malware-targeting-polands-energy-sector/) - Summary On December 29, 2025, a coordinated campaign of destructive cyberattacks targeted Poland's energy infrastructure, affecting over 30 renewable energy facilities and a major combined heat and power (CHP) plant A custom wiper malware dubbed DYNOWIPER was used to irreversibly destroy data across compromised networks CERT Polska attributes the attack infrastructure to the threat cluster
- [Cronos blockchain restarts after $74 million Tectonic exploit](https://cybernoz.com/cronos-blockchain-restarts-after-74-million-tectonic-exploit/) - The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. According to current information, the threat actor artificially inflated the price of Tectonic’s TONIC token by 100 times, then used it as collateral to borrow real assets. The price manipulation
- [Microsoft Investigating New Exchange Online Outage Tracked as EX1464935](https://cybernoz.com/microsoft-investigating-new-exchange-online-outage-tracked-as-ex1464935/) - This is not the first time Exchange Online has stumbled in recent months. Earlier in this year, Microsoft traced a similar user-facing incident, EX1454755, to a DNS-related fault inside a third-party email provider rather than its own infrastructure. In June, a separate mail-flow pipeline issue caused widespread delivery delays across North America, Europe, and Asia-Pacific,
- [Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets](https://cybernoz.com/chrome-and-edge-extensions-strip-csp-and-inject-javascript-to-drain-evm-solana-and-tron-wallets/) - Research identified 19 malicious browser extensions 18 for Google Chrome and 1 for Microsoft Edge that use a modular malware framework to strip website Content Security Policy protections, inject attacker-controlled JavaScript. Socket determined that 14 extensions were created by the threat actor, while five were acquired from legitimate developers and subsequently weaponized. The most consequential
- [Attackers plant remote access tools on compromised PaperCut servers](https://cybernoz.com/attackers-plant-remote-access-tools-on-compromised-papercut-servers/) - The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools The vendor first warned of in-the-wild compromises on August 27, 2026, when it urged customers using the
- [North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales](https://cybernoz.com/north-korean-job-fraud-expands-beyond-it-into-healthcare-and-sales/) - Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as
- [NT gov starts path to digital driver's licence](https://cybernoz.com/nt-gov-starts-path-to-digital-drivers-licence/) - Key points The Northern Territory government plans to offer digital driver's licences built to internationally recognised standards by the end of the year. The Motor Vehicles Amendment (Digital Licences) Bill 2026 establishes the legal framework for eligible Territorians to carry a secure digital licence on their smartphone. Minister Joshua Burgoyne said the digital licence will
- [ServiceNow Patches 3 Critical Code Injection Vulnerabilities](https://cybernoz.com/servicenow-patches-3-critical-code-injection-vulnerabilities/) - ServiceNow has announced patches for four vulnerabilities, including three critical code injection flaws in the ServiceNow AI platform, each with a maximum severity (CVSS score of 10/10). The first of the critical bugs, tracked as CVE-2026-18885, allows an attacker to execute arbitrary code in the ServiceNow platform under certain circumstances. An attacker could exploit the
- [ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool](https://cybernoz.com/valleyrat-when-legitimate-software-becomes-a-malware-delivery-tool/) - ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool Pierluigi Paganini August 31, 2026 ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide
- [State-linked actor targets Cisco routers for espionage](https://cybernoz.com/state-linked-actor-targets-cisco-routers-for-espionage/) - An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth. Source link
- [‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help](https://cybernoz.com/watershed-250-test-program-in-texas-looks-to-private-sector-for-water-cybersecurity-help/) - The Trump administration rolled out a six-month test program in Texas on Monday that will draw on volunteer expertise and technology from cyber and artificial intelligence companies to protect the water sector. “Project Watershed 250” is the first of the state-based, industry-centric pilot projects to cross the finish line that the Office of the National
- [ISACA Sydney Chapter marks 50 years as membership tops 2,100](https://cybernoz.com/isaca-sydney-chapter-marks-50-years-as-membership-tops-2100/) - The ISACA Sydney Chapter is marking 50 years since it was established in 1976, as the local professional association points to growth in membership alongside rising demand for cyber security, governance, risk and audit skills. In a statement, the chapter said it was founded as part of the EDP Auditors Association, which later became the
- [Is your cloud security strategy ready for AI’s looming threat?](https://cybernoz.com/is-your-cloud-security-strategy-ready-for-ais-looming-threat/) - Cloud complexity expands the attack surface Speed matters because cloud environments have become complex, with sprawling identities, permissions, APIs, workloads, and trust relationships. That complexity makes it harder for defenders to understand how individual weaknesses connect, while giving agents more relationships to map and test. As agents proliferate, network boundaries matter much less than who
- [Think twice before installing this device promising free movies](https://cybernoz.com/think-twice-before-installing-this-device-promising-free-movies/) - “The open ADB port plays the central role,” Plume researcher Gergely Eberhardt wrote in an email. “Combined with root access, a single pm install command can silently install any APK. This bypasses every one of Android’s default protections at once: signature verification, the “unknown sources” restriction, the permission-review dialog, and Play Protect scanning.” Intruders at
- [Sygnia highlights Fire Ant risks from compromised routers, authentication systems in critical infrastructure](https://cybernoz.com/sygnia-highlights-fire-ant-risks-from-compromised-routers-authentication-systems-in-critical-infrastructure/) - New research from cybersecurity firm Sygnia detailed that threat actor known as Fire Ant expanded its operations from hypervisor-level compromises into trusted infrastructure, targeting routers, authentication systems and Linux management hosts to maintain covert access and reach connected high-value environments and critical infrastructure installations. First reported in 2025, Fire Ant remained active into 2026, with
- [We invited a direct competitor into Security Hub Extended. Here’s why.](https://cybernoz.com/we-invited-a-direct-competitor-into-security-hub-extended-heres-why/) - When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security
- [SolarWinds Web Help Desk Exploitation - February 2026](https://cybernoz.com/solarwinds-web-help-desk-exploitation-february-2026/) - Summary On February 6, 2026, Microsoft reported the exploitation of SolarWinds Web Help Desk (WHD) servers The exploitation facilitated multi-stage intrusions leveraging remote monitoring and management software (RMM), credential dumping, and setting up tunnels and RDP for persistent access While not yet confirmed, the activity may be associated with one of the following disclosed CVEs:
- [Microsoft warns of TerminalFix attacks deploying reverse tunnels](https://cybernoz.com/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/) - A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into executing malicious PowerShell commands in Windows Terminal. Unlike typical ClickFix attacks that often lead to infostealer malware infections, this campaign uses a multi-stage intrusion chain that ultimately gives attackers a reverse tunnel into the victim’s internal network.
- [Broadcom Launches VMware AI Factory to Secure Enterprise AI Agents](https://cybernoz.com/broadcom-launches-vmware-ai-factory-to-secure-enterprise-ai-agents/) - Broadcom unveiled VMware AI Factory at VMware Explore 2026 in Las Vegas, introducing a software-defined foundation within VMware Private AI Cloud designed to help enterprises deploy, govern, and secure AI workloads from bare-metal infrastructure through to live model inference. The announcement, made on August 31, 2026, positions the platform as a direct response to enterprise
- [HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation](https://cybernoz.com/hardbreacher-exploit-targets-kaspersky-endpoint-security-zero-day-for-windows-11-privilege-escalation/) - A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This vulnerability allows a local user to control a privileged component. The code was published by a GitHub user named MSNightmare and is being presented as a zero-day vulnerability. However, the vendor has not confirmed it.
- [Threat actors are posing as AI crawlers to hunt for exposed credentials](https://cybernoz.com/threat-actors-are-posing-as-ai-crawlers-to-hunt-for-exposed-credentials/) - Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. (Source: GreyNoise) “Every program that visits a website announces itself in one line of the request. Chrome says it is Chrome. Googlebot says it
- [McKesson confirms cyber incident after ShinyHunters claims patient-data theft](https://cybernoz.com/mckesson-confirms-cyber-incident-after-shinyhunters-claims-patient-data-theft/) - Healthcare and pharmaceutical-distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data. McKesson Corporation is an American healthcare company that distributes pharmaceuticals and provides medical supplies, health information technology, and care management tools. McKesson says it discovered the cybersecurity incident on August 25, 2026, and that
- [Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets](https://cybernoz.com/aurora-ransomware-operators-use-cursor-ai-in-attacks-against-10-targets/) - Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its toolkit, shell
- [The Breakdown Of AshSqlite Vulnerability CVE-2026-77846](https://cybernoz.com/the-breakdown-of-ashsqlite-vulnerability-cve-2026-77846/) - CVE-2026-77846, a newly disclosed AshSqlite vulnerability, can allow attackers to access hidden or sensitive fields stored inside JSON and map columns when applications pass untrusted input to AshSqlite’s get_path/2 functionality. The Erlang Ecosystem Foundation’s CNA issued the vulnerability entry on August 30, 2026. The issue affects AshSqlite, the SQLite data layer used by the Ash
- [Anthropic Warns Of Infostealers Hijacking Claude Sessions](https://cybernoz.com/anthropic-warns-of-infostealers-hijacking-claude-sessions/) - Anthropic warned users over the weekend that a threat actor is using widely available infostealer malware to hijack active Claude login sessions from infected computers, then using those sessions to run up victims’ paid usage without ever needing a password or a two-factor code. The company said it identified six malware families in the campaign:
- [OpenAI to cut off AI models for Cursor](https://cybernoz.com/openai-to-cut-off-ai-models-for-cursor/) - Key points OpenAI plans to stop providing AI models to Cursor after SpaceX completed its US$60 billion acquisition of Anysphere, the startup behind Cursor. OpenAI cited concerns that SpaceX would not use its technology within its terms of service, citing past contract violations by Musk's companies. Musk dismissed the move, calling Altman and Greg Brockman
- [Nightmare Eclipse Drops 'HardBreacher' Kaspersky Product Exploit](https://cybernoz.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/) - The researcher known as Nightmare Eclipse has dropped another zero-day — this time a privilege escalation exploit targeting a Kaspersky endpoint security product. Nightmare Eclipse, also known as Chaotic Eclipse, has released PoC exploits for many vulnerabilities in recent months, mainly Windows and Microsoft Defender flaws. The researcher started dropping zero-days after growing frustrated with
- [Infostealers Are Hijacking Claude Sessions and Draining Subscriptions](https://cybernoz.com/infostealers-are-hijacking-claude-sessions-and-draining-subscriptions/) - “”Our systems detected this activity on your account, and we’ve therefore removed your card on file and signed out the sessions involved to help block further unauthorized access.” continues the report. “If your usage limits looked like they refilled and then drained while you weren’t using Claude, this was likely the cause.”” Anthropic identified Vidar,
- [PaperCut issues emergency patches as threat actors target chained vulnerabilities](https://cybernoz.com/papercut-issues-emergency-patches-as-threat-actors-target-chained-vulnerabilities/) - The print management software maker faced a wave of attacks in 2023 aimed at higher education customers. Source link
- [Horizon3 launches Sydney-hosted sovereign instance for NodeZero testing](https://cybernoz.com/horizon3-launches-sydney-hosted-sovereign-instance-for-nodezero-testing/) - Horizon3 says it has launched the general availability of its first Asia-Pacific “Sovereign Instance”, hosted in Sydney, aimed at Australian organisations seeking in-country data residency for autonomous penetration testing. In a press release, the company said the new Australian point of presence keeps customer data resident in Australia and is designed to support continuous, production-safe
- [OpenAI-led coalition warns AI will compress cyberattack timelines, expose enterprise weaknesses](https://cybernoz.com/openai-led-coalition-warns-ai-will-compress-cyberattack-timelines-expose-enterprise-weaknesses/) - “Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt… have left systems exposed,” the letter added. Attack timelines compress as AI scales exploitation The letter attributes the risk to the ability of AI systems to accelerate the discovery and exploitation of existing vulnerabilities. “Longstanding bugs, excessive permissions, misconfigurations, insecure and
- [Introducing Adaptive Intelligence: undermining the economics of every bot attack](https://cybernoz.com/introducing-adaptive-intelligence-undermining-the-economics-of-every-bot-attack/) - Modern bot threats are increasingly driven by determined, sophisticated attackers. Often it is not even one person, but a group trading techniques with each other or a commercial service sold to anyone willing to pay. For many of them, getting past bot detection is a full-time job they genuinely enjoy. Block them and they get
- [Make The Most of Network Firewall Logs with Elastic Security](https://cybernoz.com/make-the-most-of-network-firewall-logs-with-elastic-security/) - This is Part 1 of a two-part series on leveraging firewall data in Elastic Security. In this post, we cover the fundamentals of firewall logs, how to collect them, and how to begin exploring your network data visually. The network firewall is one of the most critical security controls in a network. It enforces security
- [File servers are here to stay. Here’s how to manage them securely](https://cybernoz.com/file-servers-are-here-to-stay-heres-how-to-manage-them-securely/) - From soaring cloud costs to risk ownership, data sovereignty and legacy compatibility, there are many reasons why organizations continue to rely on file servers for inexpensive and abundant local storage. Yet no matter where your data lives, access governance is essential to keeping it in the right hands. Even firmly into the cloud era, countless
- [Hackers Hide ValleyRAT Backdoor Inside Adware Targeting Users in China and India](https://cybernoz.com/hackers-hide-valleyrat-backdoor-inside-adware-targeting-users-in-china-and-india/) - Hackers are using adware to deliver ValleyRAT, a Windows backdoor. The campaign primarily affects users in China and India, turning a program expected to display ads into a route for spying, theft, and further malware delivery. The installer changes its visible behavior according to its filename. One version installs a collaboration app, another installs a
- [ATM Flaws Reveal Key Weaknesses in the Software Supply Chain](https://cybernoz.com/atm-flaws-reveal-key-weaknesses-in-the-software-supply-chain/) - For the past five years, security researcher Matt Burch has immersed himself in the esoteric and high-stakes world of ATM security, in which small software flaws can sometimes expose cold, hard cash. As Burch has bored deeper into the computers powering these digital lock boxes—and continued to find vulnerabilities in key digital security systems—he has
- [Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks](https://cybernoz.com/aurora-ransomware-hackers-use-cursor-ai-agent-for-hands-on-exploitation-and-esxi-attacks/) - Aurora ransomware operators have been observed using Cursor Agent, powered by Claude Sonnet, to support hands-on intrusion activity across ten victim organizations, while deploying a purpose-built Linux encryptor designed to disrupt VMware ESXi environments. The findings show how ransomware affiliates are integrating agentic AI into established post-compromise workflows rather than relying on it as a
- [Cylake: Cybersecurity Wasn't Built for the AI Era](https://cybernoz.com/cylake-cybersecurity-wasnt-built-for-the-ai-era/) - In this episode of Inside Cybersecurity, Cylake founder and CEO Nir Zuk joins René Bonvanie to discuss one of the biggest misconceptions shaping cybersecurity today: the belief that AI itself is the solution. While much of the industry is focused on AI agents, copilots, and automation, Zuk argues that the real challenge lies elsewhere. AI is only as
- [AWS Console Private Access can block sign-ins to personal accounts](https://cybernoz.com/aws-console-private-access-can-block-sign-ins-to-personal-accounts/) - The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for virtual private clouds, the isolated networks customers run inside AWS, that have no internet connectivity at all. Authentication flows, the JavaScript, CSS, and images that draw the page, console-only
- [ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions](https://cybernoz.com/valleyrat-backdoor-hides-in-signed-adware-that-users-add-to-antivirus-exclusions/) - Swati KhandelwalAug 31, 2026Malware / Endpoint Security The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built
- [PaperCut Issues Second Emergency Patch As Researchers Break Fix For Exploited Zero-Days](https://cybernoz.com/papercut-issues-second-emergency-patch-as-researchers-break-fix-for-exploited-zero-days/) - PaperCut released a second emergency patch last Friday, for two vulnerabilities in its NG and MF print management servers that attackers are already exploiting, after security researchers demonstrated that the vendor’s first fix could be bypassed. The two flaws work as a chain. CVE-2026-81578, rated 8.8 on the CVSS scale, is an improper access control
- [Boston Scientific Cyberattack Disrupts Orders And Operations](https://cybernoz.com/boston-scientific-cyberattack-disrupts-orders-and-operations/) - As per Boston Scientific’s Aug. 30 update, “the unauthorized activity is limited to certain on-premises systems,” providing the clearest indication yet of the scope of the cybersecurity incident that has disrupted the medical device maker’s global network and business operations. Boston Scientific said the investigation into the disruption remains ongoing, with third-party cybersecurity experts. Based
- [REA Group finds its first chief AI officer](https://cybernoz.com/rea-group-finds-its-first-chief-ai-officer/) - Key points REA Group has appointed Thyago Liberalli to a newly-created chief AI officer role, announced via a LinkedIn post. Liberalli spent 13 years at Seek, including roles as Asia Pacific director of AI and global director of AI and machine learning. The role, reporting to chief technology officer Steve Maidment, aims to connect AI
- [What the Hugging Face Incident Teaches Security Leaders About AI Agent Access](https://cybernoz.com/what-the-hugging-face-incident-teaches-security-leaders-about-ai-agent-access/) - Most security leaders (92%) worry that the growing use of AI agents will create new security risks. And for good reason. AI agents can now execute a full attack chain in double quick order, evidenced by the Hugging Face incident. AI agents broke into Hugging Face’s production environment and, in a little over four days,
- [China-linked Fire Ant Hides Inside Trusted Infrastructure](https://cybernoz.com/china-linked-fire-ant-hides-inside-trusted-infrastructure/) - China-linked Fire Ant Hides Inside Trusted Infrastructure Pierluigi Paganini August 31, 2026 Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks. Chinese-linked cyber espionage group Fire Ant has spent the past year quietly graduating from hacking individual computers to hacking the infrastructure that
- [The AI Kill Switch Act is repeating the Clipper Chip’s mistakes](https://cybernoz.com/the-ai-kill-switch-act-is-repeating-the-clipper-chips-mistakes/) - “Anything that can go wrong will go wrong.” Policymakers alarmed by the recent incidents of autonomous AI agents breaking through guardrails to hack other companies seem to have Murphy’s Law on the mind – and who can blame them? When agents’ behavior becomes unpredictable, it’s easy to imagine any number of scenarios where they’re running
- [ValleyRAT is spreading disguised as adware](https://cybernoz.com/valleyrat-is-spreading-disguised-as-adware/) - Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices. This post examines a less conventional case: a well-known backdoor distributed under the
- [Trusted Chrome, Edge extensions weaponized in supply chain campaign](https://cybernoz.com/trusted-chrome-edge-extensions-weaponized-in-supply-chain-campaign/) - The campaign was heavily focused on cryptocurrency theft, but its capabilities went further. Socket observed code that captured information typed into web forms and extracted authentication material from active browser sessions. Other modules targeted logged-in social media accounts and collected browser history. Socket linked the extensions to a broader operation dating to February 2024 based
- [OpenAI-backed initiative targets critical infrastructure cyber gaps with AI-powered defenses, coordinated global response](https://cybernoz.com/openai-backed-initiative-targets-critical-infrastructure-cyber-gaps-with-ai-powered-defenses-coordinated-global-response/) - OpenAI and a broad group of technology and cybersecurity organizations are launching a collective cyber defense initiative calling for coordinated global efforts to protect essential services, including hospitals, water treatment plants, and internet infrastructure, against increasingly sophisticated AI-enabled attacks. While these organizations face growing risks, longstanding vulnerabilities such as unpatched software, misconfigurations, weak authentication, and
- [US water systems face persistent cybersecurity gaps as July attacks renew scrutiny of federal protections, CRS says](https://cybernoz.com/us-water-systems-face-persistent-cybersecurity-gaps-as-july-attacks-renew-scrutiny-of-federal-protections-crs-says/) - A new report from the U.S. Congressional Research Service revealed that the cyberattacks reported against water systems in at least seven U.S. states in July 2026 have renewed scrutiny of cybersecurity protections for the nation’s municipal water infrastructure. Nearly 144,000 privately and publicly owned public water systems are regulated under the Safe Drinking Water Act,
- [Uncovering Hybrid Cloud Attacks Part 3 – The Response](https://cybernoz.com/uncovering-hybrid-cloud-attacks-part-3-the-response/) - In the final section of this blog series on uncovering complex hybrid cloud attacks, we’ll share key elements of the response to the real-world sophisticated cloud attack outlined in Part 2. To protect the victim organization’s identity, certain details of the attack have been modified and combined with other attacks seen in the wild, however
- [Manage your Elastic security stack as code with the Elastic Stack Terraform provider](https://cybernoz.com/manage-your-elastic-security-stack-as-code-with-the-elastic-stack-terraform-provider/) - The Elastic Stack Terraform provider has reached a significant milestone. Starting with release v0.13.1, you can manage your Elastic security posture - detection rules, exception lists, and prebuilt rules - alongside ML anomaly detection jobs, synthetics monitors, and AI connectors, all as code. This brings your detection logic and ML jobs into the same versioned,
- [Nigerians extradited to US for sextortion, deaths of two teens](https://cybernoz.com/nigerians-extradited-to-us-for-sextortion-deaths-of-two-teens/) - Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. Sextortion is a form of online blackmail in which cybercriminals threaten victims with leaking nude images and videos they stole (through hacking) or obtained
- [New AI-Built Malware Watches How Security Teams Remove It and Fights Back](https://cybernoz.com/new-ai-built-malware-watches-how-security-teams-remove-it-and-fights-back/) - A new Windows malware toolkit is showing how artificial intelligence can change the economics of cybercrime. Known as Gryxa, it gives a criminal operator remote access, stays active after partial cleanup, and targets passwords stored in Chromium-based browsers. It can also watch defenders trying to remove it. The suspected entry point is a phishing message
- [D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft](https://cybernoz.com/d-link-dir-x1860z-flaws-enable-unauthenticated-admin-password-reset-and-wi-fi-credential-theft/) - D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration information, including Wi-Fi credentials. The vulnerabilities affect the non-US DIR-X1860Z hardware revision A1/V1.0 running firmware version V1.0.2.220120.165402. D-Link addressed these issues in
- [Debian developers rejected an LLM ban and left disclosure voluntary](https://cybernoz.com/debian-developers-rejected-an-llm-ban-and-left-disclosure-voluntary/) - A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result: the winning option encourages contributors to disclose AI assistance and stops there. Review stays where it
- [A week in security (August 24 - August 30)](https://cybernoz.com/a-week-in-security-august-24-august-30/) - Last week on Malwarebytes Labs:Stay safe!Scammers know more about you than you think. Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in. Download for iOS → Download for Android → Source link
- [What the Data Says About AI in Security Operations in 2026](https://cybernoz.com/what-the-data-says-about-ai-in-security-operations-in-2026/) - AI is officially mainstream in security operations. According to Prophet Security's State of AI in Security Operations 2026 report (produced from ViB’s survey of 250+ cybersecurity pros), 40% of security teams now use AI daily. Another 56% are currently testing it out, and only 4% have no plans to adopt it. For the teams already
- [ASX creates deputy CISO role](https://cybernoz.com/asx-creates-deputy-ciso-role/) - Key points The ASX has created a new deputy chief information security officer role, with Hanlie Botha appointed as its first holder. Botha joins ASX from Ticketek Entertainment Group, where she served as CISO for the past nine months. ASX CISO Tristan Geering has held that role for a decade and has been with the
- [More Details Emerge on Exploited PaperCut Vulnerabilities](https://cybernoz.com/more-details-emerge-on-exploited-papercut-vulnerabilities/) - PaperCut Software has released a second emergency patch for zero-day vulnerabilities exploited against users of its NG and MF print management solutions as more information has emerged about the flaws and their exploitation. The zero-days can be exploited by unauthenticated attackers to bypass authentication and achieve remote code execution on affected PaperCut NG/MF instances. The
- [Introducing Wiz Code: Transform Your AppSec with Wiz](https://cybernoz.com/introducing-wiz-code-transform-your-appsec-with-wiz/) - Today marks the general availability of Wiz Code, the natural next step in the evolution of Wiz and CNAPP to the left!We have always believed that in order to scale in the cloud, security must be woven into the development lifecycle. That is why we are bringing the trademark precision of Wiz’s cloud security platform
- [Get started with Elastic Security from your AI agent](https://cybernoz.com/get-started-with-elastic-security-from-your-ai-agent/) - Get started with Elastic Security from your AI agent Elastic Agent Skills are open source packages that give your AI coding agent native Elastic expertise. If you're already using Elastic Agent Builder, you get AI agents that work natively with your security data. Agent Skills are for the other side: bringing that same Elastic Security
- [Free Router DNS Tweak Blocks Malware and Phishing Across Home Networks](https://cybernoz.com/free-router-dns-tweak-blocks-malware-and-phishing-across-home-networks/) - A router configuration change is gaining attention as a way to add defense against phishing and malware. Cybersecurity commentator Luis Catacora urged users to replace default DNS resolvers on a router with Cloudflare’s addresses: 1.1.1.2 as the primary server and 1.0.0.2 as the secondary server. The change does not replace endpoint security, but it can
- [Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks](https://cybernoz.com/alleged-teampcp-hackers-charged-in-australia-over-major-supply-chain-attacks/) - The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21,
- [Announcing the 2026 Benchmark Security Awards Finalists](https://cybernoz.com/announcing-the-2026-benchmark-security-awards-finalists/) - The Benchmark Security Awards celebrate Australian security leaders for their work in driving effective cyber programs in Australian enterprise and government. This year’s awards program is brought to you by iTnews and techpartner.news. These two leading technology publications are coming together, highlighting the efforts of both end user security leaders and cyber security tech partners. iTnews and techpartner.news are proud
- [Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION](https://cybernoz.com/security-affairs-newsletter-round-592-by-pierluigi-paganini-international-edition/) - Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION Pierluigi Paganini August 30, 2026 A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. International
- [The Link Between Your Workplace Situation and Your Mental Health](https://cybernoz.com/the-link-between-your-workplace-situation-and-your-mental-health/) - One thing I keep forgetting and relearning is how important it is to us that people appreciate our work. The following thing has happened multiple times: to me, my partner, my friends, associates, and people I've just observed over the years.We have violent swings of emotions between being in a titanic pose on the front
- [Hong Kong WhatsApp hijacking scams surge 170% to nearly 2,000 cases](https://cybernoz.com/hong-kong-whatsapp-hijacking-scams-surge-170-to-nearly-2000-cases/) - WhatsApp account hijacking scams in Hong Kong surged by nearly 170 per cent to almost 2,000 cases in the first seven months of this year, with one victim losing as much as HK$12.2 million (US$1.55 million).Police said the 1,993 cases logged from January to July represented a 169.7 per cent increase from the 739 cases
- [Developers Deserve Better: Why Wiz Code Is Built for You.](https://cybernoz.com/developers-deserve-better-why-wiz-code-is-built-for-you/) - Security, as a concept, should resonate as a positive—something that protects. Unfortunately, it has become synonymous with a roadblock for many developers. Remember the last time your team had to scramble to fix security issues right before release? While the idea of “Shift Left” was intended to fix this, it instead often results in the
- [Chrome Web Store extensions caught stealing crypto, browser data](https://cybernoz.com/chrome-web-store-extensions-caught-stealing-crypto-browser-data/) - Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, and to inject ClickFix lures. Researchers say all 19 malicious modules uncovered in the campaign serve distinct purposes and are designed to be "highly extensible." The operation was uncovered by application security
- [The DDoS Botnet With A Consent Dialog](https://cybernoz.com/the-ddos-botnet-with-a-consent-dialog/) - A smart TV makes an almost perfect proxy. It is always plugged in, always on a high-speed connection, sitting on standby around the clock, rarely watched, unmanaged, with no one checking to whom or what it talks to. Design the ideal host for routing traffic through someone else’s home, and you would land on roughly
- [APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations](https://cybernoz.com/apt28-linked-hookedge-backdoor-targets-european-government-and-diplomatic-organizations/) - Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocumented backdoor dubbed HOOKEDGE, a lightweight Windows batch script that's distributed via macro-enabled
- [Telstra's new control tool to deliver more "disciplined" AI](https://cybernoz.com/telstras-new-control-tool-to-deliver-more-disciplined-ai/) - Key points Telstra has deployed a new large-scale, real-time AI cost and governance monitoring tool called an "AI control plane" to keep a firmer hand on deployments. Head of corporate software engineering Chris Ellis said the challenge is no longer managing individual deployments but governing an enterprise-wide AI ecosystem, requiring a more disciplined approach. Chief
- [Extortion Group FulcrumSec Claims 86GB Manchester Airports Data Theft](https://cybernoz.com/extortion-group-fulcrumsec-claims-86gb-manchester-airports-data-theft/) - Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft Pierluigi Paganini August 30, 2026 Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands
- [Wiz Code: Experience True ASPM With Code-to-Cloud Context](https://cybernoz.com/wiz-code-experience-true-aspm-with-code-to-cloud-context/) - AppSec and engineering teams today face the paradox of choice. With a growing array of tools—SAST, DAST, SCA, API Security, and more—the real challenge isn’t just identifying risks but prioritizing the high volume of findings and navigating tool-specific workflows. Consequently, even the most advanced security tools can go underutilized.Wiz Code offers a new way forward
- [Streamlining the Security Analyst Experience](https://cybernoz.com/streamlining-the-security-analyst-experience/) - The term Agentic SOC (Security Operations Center) is one of the most popular concepts in security today. But what does it truly mean in practice, and how does Elastic Security approach this next evolution of security operations? In simple terms, an Agentic SOC is a security operations center that has deployed AI Agents and corresponding
- [FulcrumSec claims Manchester Airports hack, theft of 86 GB of data](https://cybernoz.com/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/) - The Manchester Airports Group data breach has been claimed by extortion group FulcrumSec, which told BleepingComputer that it stole approximately 86 GB of data. Samples reviewed by BleepingComputer contained information consistent with MAG's disclosure while indicating that the breach exposed considerably more detailed customer, booking, and travel information than initially revealed. Hackers claim theft of 86
- [Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server](https://cybernoz.com/critical-cpanel-flaw-could-let-one-hosting-customer-take-root-control-of-a-whole-server/) - Swati KhandelwalAug 28, 2026Vulnerability / Web Security cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the
- [SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112](https://cybernoz.com/security-affairs-malware-newsletter-round-112/) - Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor FTP Banners: The New Dead Drop Resolver Delivering Novel RATs The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic
- [Wiz joins the Microsoft Intelligent Security Association](https://cybernoz.com/wiz-joins-the-microsoft-intelligent-security-association/) - Wiz announced today that it has joined the Microsoft Intelligent Security Association (MISA), an ecosystem of independent software vendors (ISVs) and managed security service providers (MSSPs) that have integrated their solutions with Microsoft Security technology to enhance the defense of our shared customers against the growing landscape of cyber threats. Last year, Wiz announced an
- [Investigating from the Endpoint Across Your Environment with Elastic Security XDR](https://cybernoz.com/investigating-from-the-endpoint-across-your-environment-with-elastic-security-xdr/) - Preamble Security investigations rarely stay confined to a single host. Today’s attackers increasingly use automation and AI to compress multi-stage attacks into minutes, turning what once unfolded over days into coordinated activity across endpoints, identities, workloads, and cloud services within minutes. While many attacks begin on an endpoint, investigators must quickly determine how that activity
- [Anthropic warns infostealer malware is hijacking Claude sessions to drain usage](https://cybernoz.com/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/) - Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. The company is signing affected users out of Claude, removing saved payment methods, and refunding charges it identifies as unauthorized. "We have recently become aware of a bad
- [TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor](https://cybernoz.com/terminalfix-uses-fake-cloudflare-captchas-to-deploy-reverse-tunnel-backdoor/) - Ravie LakshmananAug 30, 2026Social Engineering / Malware Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows
- [Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch](https://cybernoz.com/hackers-are-probing-papercut-servers-and-47-still-have-no-patch/) - Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch Pierluigi Paganini August 30, 2026 PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentication
- [Elastic releases detections for the Axios supply chain compromise](https://cybernoz.com/elastic-releases-detections-for-the-axios-supply-chain-compromise/) - Elastic Security Labs is releasing an initial triage and detection rules for the Axios supply-chain compromise. We have released a detailed analysis on the Axios compromise RAT and payloads. Elastic Security Labs filed a GitHub Security Advisory to the axios repository on March 31, 2026 at 01:50 AM UTC to coordinate disclosure and ensure the
- [ServiceNow warns of three max severity security vulnerabilities](https://cybernoz.com/servicenow-warns-of-three-max-severity-security-vulnerabilities/) - ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. The ServiceNow AI Platform (formerly known as the Now Platform) is an enterprise-grade Platform-as-a-Service (PaaS) that helps integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at
- [Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour](https://cybernoz.com/ransomware-gang-claims-ai-can-analyze-700gb-of-stolen-data-every-hour/) - TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort through 700GB of stolen corporate data every hour. The group says the system helps it quickly find information that can raise the pressure on victims, from personal records to trade secrets. The operation surfaced in April 2026 and became active
- [Suspected Iran-Linked Cyberattack Knocks UK Power Plant Offline for Four Days](https://cybernoz.com/suspected-iran-linked-cyberattack-knocks-uk-power-plant-offline-for-four-days/) - A cyber incident reportedly forced a small UK power generation facility offline for about four days in July 2026. While the activity has been linked in reporting to Iran-affiliated hackers, the UK government and National Cyber Security Centre (NCSC) have not formally attributed the incident to Iran or any named threat group. The event became
- [Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited](https://cybernoz.com/week-in-review-compromised-zimbra-servers-previously-patched-citrix-netscaler-flaw-exploited/) - Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570 attacksAt least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. AI supply chain risk is showing up in developer workflows firstIn this Help
- [China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access](https://cybernoz.com/china-made-zbt-routers-ship-with-two-implants-giving-unauthenticated-attackers-root-access/) - VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company's zero-day research team, are tracked as CVE-2026-74232 and CVE-2026-74233. VulnCheck,
- [U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog](https://cybernoz.com/u-s-cisa-adds-red-hat-linux-kernel-ajax-net-professional-microsoft-sql-server-and-citrix-netscaler-flaws-to-its-known-exploited-vulnerabilities-catalog/) - U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog Pierluigi Paganini August 28, 2026 U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The
- [Wiz Snowflake Connector: Enhancing Data Security with CNAPP](https://cybernoz.com/wiz-snowflake-connector-enhancing-data-security-with-cnapp/) - As cloud environments grow, many organizations adopt SaaS solutions such as databases, identity providers, and AI platforms to support their cloud needs. These solutions run and store critical data, however, they sit outside the cloud service provider’s (CSP) boundary. Ensuring the security of these Cloud SaaS platforms can be challenging as it often means teams
- [Elastic Security Integrations Roundup: Q1 2026](https://cybernoz.com/elastic-security-integrations-roundup-q1-2026/) - A quarterly look at Elastic’s security integrations ecosystem Security teams can only protect what they can see. Gaps in coverage, like a macOS fleet generating logs that never reach your SIEM, an email gateway running in isolation, or a cloud environment producing findings that stay siloed in the vendor console, are easily exploited by attackers.
- [Toy-making giant Hasbro disclose data breach affecting employees](https://cybernoz.com/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/) - Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. Founded in 1923, Hasbro is a publicly traded American multinational entertainment conglomerate on the NASDAQ and owns many brands, including Monopoly, Clue, Nerf, Transformers, Play-Doh, Peppa Pig, Scrabble,
- [Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets](https://cybernoz.com/russian-hackers-use-new-hookedge-malware-to-spy-on-european-defense-and-diplomatic-targets/) - Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies, and diplomatic organizations in Romania, Spain, and Türkiye. The campaign relied on Word documents designed to look routine or official, turning a familiar office file into an entry point for espionage. Victims were asked to enable macros, small automated commands
- [ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection](https://cybernoz.com/servicenow-patches-critical-flaws-enabling-unauthenticated-rce-and-sql-injection/) - ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform. These vulnerabilities could allow unauthenticated attackers to execute arbitrary code, manipulate instance data, elevate privileges, or run SQL commands against underlying databases. On August 27, 2026, the company published KB3152242, which covers CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. ServiceNow reported that
- [Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL](https://cybernoz.com/three-cvss-10-0-servicenow-flaws-could-let-unauthenticated-attackers-execute-code-and-sql/) - Swati KhandelwalAug 28, 2026Vulnerability / Cloud Security ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to
- [Hybrid File Integrity Monitoring: Agentless & Runtime FIM](https://cybernoz.com/hybrid-file-integrity-monitoring-agentless-runtime-fim/) - We’re excited to introduce the addition of runtime File Integrity Monitoring (FIM) to our existing agentless solution, creating a powerful hybrid approach. This gives our customers comprehensive visibility and deep context, to enable accurate and effective monitoring of critical files across their environments.File Integrity Monitoring is a critical security process that tracks and detects changes
- [Elastic Conversational Entity Analytics for threat hunting](https://cybernoz.com/elastic-conversational-entity-analytics-for-threat-hunting/) - Entity Analytics is a core security analytics capability that extends Elastic Security from event-centric to entity-centric investigation. By focusing on critical entities, such as users, hosts, and services, it builds a complete profile of each entity’s attributes, lifecycle, behaviors, relationships, and risk score over time. This security context equips threat hunters to stop chasing isolated
- [Anthropic is cutting Claude Code's current weekly limits by 17%](https://cybernoz.com/anthropic-is-cutting-claude-codes-current-weekly-limits-by-17/) - Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. If you use Claude, you're actually getting a 17% reduction compared to what you have today. Claude Code currently has a temporary 50% increase in weekly limits, which
- [Hackers Can Take Full Control of Unitree G1 Humanoid Robots Over Bluetooth](https://cybernoz.com/hackers-can-take-full-control-of-unitree-g1-humanoid-robots-over-bluetooth/) - A critical attack chain could let attackers within Bluetooth range take full control of Unitree G1 humanoid robots, gaining root-level code execution on the locomotion computer that controls movement, cameras, speakers, voice features, and other peripherals. The flaws could allow a nearby attacker to obtain root-level code execution on the robot’s locomotion computer, which manages
- [58 Arrested, 263 Suspects Identified: Inside the Global Crackdown on Operation Jackal IV](https://cybernoz.com/58-arrested-263-suspects-identified-inside-the-global-crackdown-on-operation-jackal-iv/) - The Foundation Operation Jackal INTERPOL has been spearheading a continuing, multi-year international law enforcement effort known as Operation Jackal to destroy West African organized crime syndicates, including the worldwide network known as Black Ax. Instead of concentrating on low-level street criminals, the worldwide effort tracks illegal financial flows and disrupts the operational infrastructure that allows
- [Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data](https://cybernoz.com/chinese-hackers-deploy-packclient-rat-via-tax-themed-phishing-attacks-to-steal-data/) - A Chinese-speaking threat actor tracked as TA4922 is deploying the PackClient remote access trojan via tax-themed phishing campaigns targeting organizations in mainland China and India. The activity, observed by Proofpoint in May and July 2026, demonstrates the group’s expanding initial-access capabilities and the increasing availability of sophisticated malware on Chinese-language Telegram marketplaces. PackClient is a
- [19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code](https://cybernoz.com/19-chrome-and-edge-extensions-found-with-wallet-stealing-and-crypto-draining-code/) - Ravie LakshmananAug 28, 2026Web Security / Supply Chain Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with
- [Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator](https://cybernoz.com/philippine-nuclear-and-naval-targets-hit-by-suspected-chinese-operator/) - Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator Pierluigi Paganini August 29, 2026 An alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speaking operator targeted a Philippine nuclear research body and a marine engineering company that supports the Philippine Navy, using well-known vulnerabilities
- [Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments](https://cybernoz.com/wiz-research-finds-critical-nvidia-ai-vulnerability-affecting-containers-using-nvidia-gpus-including-over-35-of-cloud-environments/) - Wiz Research has uncovered a critical security vulnerability, CVE-2024-0132, in the widely used NVIDIA Container Toolkit, which provides containerized AI applications with access to GPU resources. This impacts any AI application – in the cloud or on-premise – that is running the vulnerable container toolkit to enable GPU support. The vulnerability enables attackers who control a
- [The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms](https://cybernoz.com/the-ai-attack-surface-how-threat-actors-abuse-trusted-ai-platforms/) - BackgroundAI is here, and we're hearing about all the high-profile security risks that come with it. AI security discussions often focus on attacks against AI companies and models (such as the recent OpenAI-HuggingFace intrusion). However, the Huntress Security Operations Center (SOC) is seeing a more prolific, day-to-day threat: threat actors abusing the ways users interact
- [Over 8,300 Gitea servers vulnerable to code execution attacks](https://cybernoz.com/over-8300-gitea-servers-vulnerable-to-code-execution-attacks/) - Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. The code injection vulnerability (CVE-2026-60004) targeted in these attacks was reported by Salesforce security researcher Shai Rod, and it allows authenticated attackers to execute arbitrary shell commands with the privileges
- [OpenAI Is Pulling Its AI Models From Cursor Following SpaceX Acquisition](https://cybernoz.com/openai-is-pulling-its-ai-models-from-cursor-following-spacex-acquisition/) - OpenAI is pulling its AI models from Cursor following SpaceX’s acquisition of the AI coding assistant, notifying SpaceX that it will wind down the contract that supplies those models to the editor. The proposed shutoff date is November 12, 2026, which OpenAI said is the maximum notice its custom agreement allows. In an August 28
- [Innovator Spotlight: Snowflake - Cyber Defense Magazine](https://cybernoz.com/innovator-spotlight-snowflake-cyber-defense-magazine/) - Who’s Really in Control? AI agents are stepping into a bigger role inside the enterprise. They are not just providing answers anymore. They are getting work done. That means interacting with the data and systems businesses depend on, with greater autonomy along the way. The potential is enormous, but it also raises a critical question.
- [Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel](https://cybernoz.com/hackers-use-fake-cloudflare-captcha-to-deploy-terminalfix-reverse-tunnel/) - A newly documented TerminalFix campaign is using fake Cloudflare CAPTCHA prompts to trick users into manually executing malicious PowerShell commands, ultimately turning compromised Windows devices into reverse-tunnel pivot points for attackers. Microsoft said the activity targets organizations through compromised websites that replace legitimate content with a convincing Cloudflare Turnstile-style “Verify you are human” overlay. Rather
- [Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE](https://cybernoz.com/five-critical-wordpress-plugin-and-theme-flaws-enable-site-takeover-or-rce/) - Ravie LakshmananAug 29, 2026Vulnerability / Web Security Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8)
- [PaperCut Releases Emergency Patch for Exploited Zero-Day](https://cybernoz.com/papercut-releases-emergency-patch-for-exploited-zero-day/) - PaperCut Software is warning users of its NG and MF print management solutions that a zero-day vulnerability is being exploited in the wild. The flaw has yet to be assigned a CVE identifier and no technical details have been shared. The vendor released emergency patches on Friday and urged customers to install them. PaperCut also
- [Rhysida Ransomware Group Targets Berlin Government Ahead of Vote](https://cybernoz.com/rhysida-ransomware-group-targets-berlin-government-ahead-of-vote/) - Rhysida Ransomware Group Targets Berlin Government Ahead of Vote Pierluigi Paganini August 29, 2026 Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the
- [BotBase for Operators: A clearer path to joining Cloudflare's directory of bots and agents](https://cybernoz.com/botbase-for-operators-a-clearer-path-to-joining-cloudflares-directory-of-bots-and-agents/) - Last month, on our second Content Independence Day, we announced a couple of features designed to give website owners more visibility and control over automated traffic: BotBase added a searchable directory of known bots to the Cloudflare dashboard, while Business Insights helped owners understand how crawlers interact with their content. We know that the ecosystem
- [New Huntress Managed ITDR Dashboard: Faster Identity Investigations](https://cybernoz.com/new-huntress-managed-itdr-dashboard-faster-identity-investigations/) - When an employee says, "I clicked a link. Am I compromised?" you probably don't want to spend the next 20 minutes jumping between tools, logs, and screens trying to piece together an answer.You want to know what happened. You want the context to decide whether it matters. And if something is wrong, you want to
- [Brave browser adds email aliases to help users evade tracking](https://cybernoz.com/brave-browser-adds-email-aliases-to-help-users-evade-tracking/) - The latest version of the Brave browser, 1.94, introduces a feature called ‘Email Aliases’ that allows users to generate disposable email addresses when signing up to a new service. Using an alias address keeps the user's real email address hidden from the website while still forwarding messages from the service. Brave already uses data isolation to
- [Critical ServiceNow Flaws Let Attackers Execute Code and Access Data](https://cybernoz.com/critical-servicenow-flaws-let-attackers-execute-code-and-access-data/) - ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that could allow unauthenticated attackers to execute code, access sensitive instance data, modify records, or escalate privileges. The company published its August 2026 CVE advisory on August 27, confirming that the issues were discovered through
- [Innovator Spotlight: Rubrik Zero Labs](https://cybernoz.com/innovator-spotlight-rubrik-zero-labs/) - What Happens When AI Escapes? AI assistants are gaining unprecedented access to the inner workings of businesses, but that trust comes with one critical expectation. Their reach stays contained. Rubrik Zero Labs decided to put that assumption to the test. What they discovered took them beneath Microsoft Copilot and into the infrastructure supporting it. There,
- [The Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn](https://cybernoz.com/the-cybersecurity-apocalypse-is-coming-in-months-ai-giants-warn/) - You may have noticed that Flock Safety’s automatic license plate reader cameras—and the cops who misuse them—are getting a lot of coverage lately. This week, WIRED found a particularly wild case: A cop in Alpharetta, Georgia, was accused of searching for the license plate of a coworker dozens of times after an affair between the
- [Critical Gogs Flaw Enables Remote Code Execution Through Path Traversal](https://cybernoz.com/critical-gogs-flaw-enables-remote-code-execution-through-path-traversal/) - A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute commands on the server by abusing path traversal during creation. Tracked as CVE-2026-52813, the flaw was reported by Aikido security researcher Jorian Woltjer and fixed in Gogs version 0.14.3. The issue stems from an API endpoint that accepted unsanitized organization
- [ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body](https://cybernoz.com/owncloud-flaw-exploited-to-steal-nuclear-records-from-philippine-research-body/) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of
- [Hasbro Data Breach Exposed Employee Personal Information](https://cybernoz.com/hasbro-data-breach-exposed-employee-personal-information/) - Toy and game giant Hasbro is notifying employees that their personal information may have been compromised in a data breach. The notifications sent to affected individuals contain little detail, but they indicate that the exposed information, which varies by individual, may include names, email addresses, postal addresses, phone numbers, national ID numbers, and financial information.
- [Hack One Robot, Reach the Next: Unitree G1 Security Flaws](https://cybernoz.com/hack-one-robot-reach-the-next-unitree-g1-security-flaws/) - Hack One Robot, Reach the Next: Unitree G1 Security Flaws Pierluigi Paganini August 29, 2026 A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Olivier Laflamme spent about three months digging into the Unitree G1 humanoid robot and eventually found
- [OpenPrinting CUPS Vulnerabilities: Analysis of related CVEs](https://cybernoz.com/openprinting-cups-vulnerabilities-analysis-of-related-cves/) - The security researcher Simone Margaritelli (evilsocket), disclosed details of several vulnerabilities impacting CUPS and IPP packages: CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177. These vulnerabilities are unlikely to be exploited in most cloud environments due to their requirements for exposing UDP port 631 and needing the victim to attempt a print request as part of the currently
- [UEBA & entity analytics: Why entity record quality matters](https://cybernoz.com/ueba-entity-analytics-why-entity-record-quality-matters/) - There's an uncomfortable truth in security analytics that nobody talks about at conferences: The quality of your detections, alerts, and investigations is only as good as the entity records that represent the users, hosts, and services in your environment. Not the machine learning models. Not the anomaly detection algorithms. Not the risk scoring engine. The
- [68-year-old imprisoned after making $1.3 million by pirating IPTV services](https://cybernoz.com/68-year-old-imprisoned-after-making-1-3-million-by-pirating-iptv-services/) - A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. An investigation by the Police Intellectual Property Crime Unit (PIPCU) at the City of London Police found that Milan Ibrahim ran a "sophisticated
- [Malvertising Is Moving From Deceptive Content to Weaponized Infrastructure](https://cybernoz.com/malvertising-is-moving-from-deceptive-content-to-weaponized-infrastructure/) - Malvertising is becoming harder to identify by looking at the ad itself. A growing share of malicious advertising activity now depends on what happens after the click: redirect chains, disposable domains, cloaking systems, conditional delivery, and campaign behavior that can change after initial approval. The creative or landing page may appear innocent, while the malicious component
- [The Artificial Adversary - Cyber Defense Magazine](https://cybernoz.com/the-artificial-adversary-cyber-defense-magazine/) - Cybersecurity has spent decades focused on the human adversary. We built models for nation-state actors, cybercriminal gangs, insiders, access brokers, ransomware affiliates, and fraud operators. We mapped their Tactics, Techniques, and Procedures (TTPs). We named and categorized their malware. We studied their mistakes. That era is not over. But it is no longer sufficient. A
- [Hackers Compromise TanStack Query npm Package to Steal Developer Credentials](https://cybernoz.com/hackers-compromise-tanstack-query-npm-package-to-steal-developer-credentials/) - A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates type-safe TanStack Query hooks. Aikido Security said it identified 10 malicious versions published within 20 minutes. Because the package records more than 150,000 weekly downloads, the incident poses exposure risk to development teams. The breach exposes developer workstations and CI systems
- [Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers](https://cybernoz.com/android-17-adds-os-wide-ech-to-hide-website-visits-from-network-providers/) - Ravie LakshmananAug 28, 2026Cellular Security / Encryption Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a
- [Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says](https://cybernoz.com/think-youve-eliminated-chinese-ai-check-the-models-lineage-cisco-says/) - If you think you’ve excluded all Chinese AI from your tech stack, you may need to think again. The US government’s attitude toward Chinese AI is that it is a national security threat. This alone could persuade patriotic Americans to eschew any AI labelled ‘Chinese’ in favor of an AI without that label. Cisco has
- [PaperCut Zero-Day Under Active Attack: Emergency Patch Released](https://cybernoz.com/papercut-zero-day-under-active-attack-emergency-patch-released/) - PaperCut Zero-Day Under Active Attack: Emergency Patch Released Pierluigi Paganini August 28, 2026 PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it. PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has
- [CTEM can give your security team a contextual edge](https://cybernoz.com/ctem-can-give-your-security-team-a-contextual-edge/) - As a result, contextual intelligence must combine technical context (exploitability, exposure, existing measures) with business context (which systems support critical processes, legal obligations, or contractual commitments), he says. “Without that combination, there is no real risk management, only prioritization based on technical needs,” he says. Javier Castillo, operations director of Secure&IT, says it’s important to note
- [How Wiz Meets CISA “Secure by Design” Objectives](https://cybernoz.com/how-wiz-meets-cisa-secure-by-design-objectives/) - When the Cybersecurity and Infrastructure Security Agency (CISA) sought founding participants in their Secure by Design initiative, Wiz was honored to support it as an inaugural member. At just 4 years old, we benefit from a lack of technical debt and a dynamic culture that is underpinned by the belief that security and innovation should
- [PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE](https://cybernoz.com/papercut-zero-day-active-exploitation-and-pre-auth-rce/) - Acknowledgements: Special thanks to Tanner Filip, Jai Minton, Max Rogers, Ben Nahorney, Lindsey Welch, Aaron Deal, Dray Agha, Lindon Wass, Michael Elford, and Craig Sweeney for their contributions to this investigation and writeup. Update: 8/28/26 @ 2:45PM ETPaperCut has released a second emergency patch, referred to as Release 2, for PaperCut NG and PaperCut MF. If
- [GiveWP WordPress donation plugin flaw lets hackers execute server commands](https://cybernoz.com/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/) - A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. The security issue is identified as CVE-2026-82222 and affects GiveWP through version 4.16.7.1. It was reported by bug researcher Udin Chan on July 28 through the Patchstack vulnerability intelligence platform. The GiveWP plugin has more
- [700 AI Agents Secretly Coordinated to Hack Hugging Face After Breaking Their Isolation](https://cybernoz.com/700-ai-agents-secretly-coordinated-to-hack-hugging-face-after-breaking-their-isolation/) - A large group of AI agents reportedly bypassed their intended isolation, created a covert communication channel, and coordinated an attack on Hugging Face infrastructure. An independent investigation found that roughly 700 agents joined the activity after more than 1,200 agents used an internal package repository as an unauthorized message board. The incident began during OpenAI’s
- [White House Declares Executive Order to Protect Bulk-Power System](https://cybernoz.com/white-house-declares-executive-order-to-protect-bulk-power-system/) - Carmen EstelaCyber Defense MagazineAugust 28, 2026 National Emergency Declaration for Grid Security White House released Executive Order 14420, which targets security risks within the nation’s bulk-power system. Invoking the International Emergency Economic Powers Act, the administration declared a national emergency to address vulnerabilities in foreign-supplied electrical infrastructure. The directive blocks the purchase, import, or setup
- [Critical WordPress Plugin Flaw Allows Unauthenticated Administrator Account Takeover](https://cybernoz.com/critical-wordpress-plugin-flaw-allows-unauthenticated-administrator-account-takeover/) - A critical authentication bypass vulnerability has been identified in the WPMU DEV Dashboard WordPress plugin, which could allow unauthenticated attackers to gain administrator-level access to vulnerable sites configured with Hub Single Sign-On (SSO). This vulnerability, tracked as CVE-2026-76581, has a CVSS score of 9.8 and affects WPMU DEV Dashboard versions 5.0.1 and earlier. The plugin
- [Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)](https://cybernoz.com/previously-patched-citrix-netscaler-flaw-exploited-in-the-wild-cve-2026-8452/) - CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild. The agency published the alert on August 26 and gave federal agencies until August 29 to remediate it. About CVE-2026-8452 Citrix disclosed the
- [Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable](https://cybernoz.com/cosmos-evm-flaw-exploited-after-cosmos-labs-knew-every-blockchain-running-it-was-vulnerable/) - Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected
- [Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge](https://cybernoz.com/tech-cybersecurity-giants-unite-behind-openai-led-cyber-defense-pledge/) - Nearly 130 organizations spanning cybersecurity, cloud computing, finance and other industries have signed an open letter calling for a coordinated, global surge in cyber defense as AI makes attacks more widespread and sophisticated. Signatories include Anthropic, Microsoft, Google, Cisco, Check Point, Cloudflare, CrowdStrike, IBM, Oracle and OpenAI, which is leading the effort. The letter warns
- [Trump Targets Foreign Technology in New U.S. Power Grid Security Order](https://cybernoz.com/trump-targets-foreign-technology-in-new-u-s-power-grid-security-order/) - Trump Targets Foreign Technology in New U.S. Power Grid Security Order Pierluigi Paganini August 28, 2026 Trump targets foreign-made power grid equipment, citing cyber, sabotage and supply-chain risks to U.S. national security. Executive Order 14420, signed on August 26, targets equipment and technologies that could expose the power grid to sabotage, unauthorized access, malicious remote
- [In Focus | Can Beijing’s gateway plan for Tibet survive geopolitics and natural disasters?](https://cybernoz.com/in-focus-can-beijings-gateway-plan-for-tibet-survive-geopolitics-and-natural-disasters/) - On the windswept plains just south of Tibet’s second-largest city, the towering smart inspection systems and automated cargo gantries of a brand-new international land port gleam under the plateau’s high-altitude sun.Official road maps predict the multibillion-yuan project in Shigatse will process up to 300 trucks daily by the end of 2030 – loading cargo off
- [Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety](https://cybernoz.com/perturbation-probing-a-new-diagnostic-for-the-fragility-of-llm-safety/) - Introducing a New Angle on LLM Safety Our previous research on logit-gap steering demonstrated that the safety guardrails of an aligned LLM can be bypassed by closing a measurable gap in the model's output scores. That work answered the question of how an attacker bypasses alignment. A natural follow-up question is where inside the model
- [ServiceNow patches three maximum severity flaws that could put enterprise data at risk](https://cybernoz.com/servicenow-patches-three-maximum-severity-flaws-that-could-put-enterprise-data-at-risk/) - Overall, Seker noted, AI changes the economics of vulnerability exploitation more than it changes the underlying vulnerability. Attackers are using AI to analyze disclosures, generate and modify exploit attempts, enumerate exposed services, adapt payloads to different environments, and automate post-exploitation activity. “The period between public disclosure and widespread exploitation can therefore become increasingly compressed,” Seker
- [Cloud Logging Tips and Tricks: Everything You Need to Know](https://cybernoz.com/cloud-logging-tips-and-tricks-everything-you-need-to-know/) - Cloud logging is a critical piece of any cloud detection and response program. Logs have always been an important source of information for the security operations center, and their importance has only increased with the rise in cloud attacks. Recent incidents, such as the Microsoft signing key compromise and the various TeamTNT campaigns, highlight the
- [Proactive threat hunting with Elastic’s AI-generated hunting leads](https://cybernoz.com/proactive-threat-hunting-with-elastics-ai-generated-hunting-leads/) - Threat hunting has always been a human art; a practitioner staring at logs, forming a hypothesis, and patiently chasing it down. What if the hardest part of the hunt (knowing where to look) could be done for you, automatically, in milliseconds, and tuned specifically to your environment? This is where AI-generated hunting leads come in,
- [McKesson discloses breach after ShinyHunters claims patient data theft](https://cybernoz.com/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/) - Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and
- [Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them](https://cybernoz.com/hackers-make-phishing-pages-change-their-code-every-time-someone-opens-them/) - Hackers are making some phishing pages harder to track by changing the code delivered to every visitor. An examined operation served a credential-stealing form whose appearance stayed familiar while its structure kept shifting. The attack started with a phishing message containing a web link. Opening it did not show a login page in one case;
- [The Balance Of Healthcare Research Potential And Privacy In The Age Of AI](https://cybernoz.com/the-balance-of-healthcare-research-potential-and-privacy-in-the-age-of-ai/) - There’s no question that AI has transformed healthcare research and completely changed the trajectory of the healthcare industry. What would have taken researchers months to uncover even just a decade ago can now be found, organized, and analyzed in a matter of minutes with AI systems. However, there is understandable wariness among researchers, clinicians, and the general
- [Hackers Actively Exploiting Pre-Auth RCE Flaw in PaperCut Print Software](https://cybernoz.com/hackers-actively-exploiting-pre-auth-rce-flaw-in-papercut-print-software/) - Attackers are actively exploiting a critical, unauthenticated remote code execution (RCE) vulnerability in PaperCut NG and PaperCut MF, widely used print management software, security researchers at Huntress have confirmed. The flaw allows an attacker to remotely take control of a PaperCut server’s configuration without needing any login credentials, ultimately enabling arbitrary code execution on the
- [Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit](https://cybernoz.com/polymorphic-phishing-attack-generates-unique-credential-stealing-page-on-every-visit/) - A newly analyzed phishing operation is using server-side polymorphism to generate a distinct credential-harvesting page for virtually every request, undermining detection approaches built around file hashes, fixed HTML identifiers, and static JavaScript signatures. The campaign came to light after a phishing message submitted to the SANS Internet Storm Center (ISC) pointed recipients to a URL
- [What 90 days and a small budget can buy in AI agent security](https://cybernoz.com/what-90-days-and-a-small-budget-can-buy-in-ai-agent-security/) - In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response become the buyer’s job. He walks through red-teaming AI agents, what counts as
- [Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network](https://cybernoz.com/berlin-refuses-to-pay-hackers-who-stole-data-from-the-citys-state-network/) - Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport,
- [City of Casey quadruples open data engagement](https://cybernoz.com/city-of-casey-quadruples-open-data-engagement/) - Key points City of Casey has grown Open Data Exchange engagement from 6000 visitors in 2023 to more than 30,000 in the first half of 2026. The redesign prioritised dashboards, mapping and plain-language insights over publishing additional datasets, focusing on tools like the Councillor Transparency page, Community Food Resource Directory and Kindergarten Finder. Building permit
- [ATF Confirms Cyber Incident After Ransomware Group Claims Attack](https://cybernoz.com/atf-confirms-cyber-incident-after-ransomware-group-claims-attack/) - The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed suffering a cybersecurity incident after the Qilin ransomware group claimed to have targeted the agency. In a statement on its website, ATF said the incident affected a standalone system, which was disconnected after the intrusion was discovered. “The impacted system operates separately from
- [Love Electric Breach: 877,000 Driver Records Offered for $600](https://cybernoz.com/love-electric-breach-877000-driver-records-offered-for-600/) - Love Electric Breach: 877,000 Driver Records Offered for $600 Pierluigi Paganini August 28, 2026 Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A seller on an English-language data-breach forum claimed on August 26 that they had obtained the driver database of Love Electric,
- [CISA identifies security hurdles that led to very different results in two red-team engagements](https://cybernoz.com/cisa-identifies-security-hurdles-that-led-to-very-different-results-in-two-red-team-engagements/) - The agency said its recent simulated cyberattacks offered several key lessons for many organizations. Source link
- [ATF confirms cyberattack hit system containing info on its investigation targets](https://cybernoz.com/atf-confirms-cyberattack-hit-system-containing-info-on-its-investigation-targets/) - The Bureau of Alcohol, Tobacco, Firearms and Explosives insists the cyberattack that it publicly disclosed Wednesday was limited to investigation targets, and has not impacted other agency systems. ATF said it is responding to the breach, which first became public after a prolific ransomware group claimed it accessed the federal agency’s network “The incident involved
- [GPUThor hardware attack can root Nvidia GPU systems](https://cybernoz.com/gputhor-hardware-attack-can-root-nvidia-gpu-systems/) - However, the researchers also tested Nvidia server GPUs such as A100 and H100 or newer GPUs on the Blackwell architecture like RTX 5090 or RTX 6000, and their attack did not produce bit flips. This is because these cards use different or newer type of memory such as HBM, GDDR6X, and GDDR7, which have different
- [AWS Account Vending | Wiz Blog](https://cybernoz.com/aws-account-vending-wiz-blog/) - Back in 2019, Amazon’s retail business publicly mentioned they had over 10,000 AWS accounts — and they certainly aren’t the only business with a high account volume. This matters because a core building block of an effective cloud security strategy is how new accounts are created. Organizations must develop and maintain a consistent process for this
- [Why cryptographic inventory is key for post-quantum security](https://cybernoz.com/why-cryptographic-inventory-is-key-for-post-quantum-security/) - When quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest now, decrypt later" tactic. Discover why building a comprehensive cryptographic inventory and executing a phased operational strategy are critical for protecting your
- [PaperCut releases second emergency patch for exploited flaws](https://cybernoz.com/papercut-releases-second-emergency-patch-for-exploited-flaws/) - PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. As BleepingComputer reported yesterday, PaperCut warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an initial emergency
- [Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft](https://cybernoz.com/hackers-target-ai-infrastructure-with-rce-prompt-injection-and-api-key-theft/) - Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for remote code execution, credential theft, and cryptomining. AI infrastructure is now a cloud entry point. Over 90 days, attackers tailored techniques for services routing model traffic and connecting agents to tools. Campaigns paired exposed-server flaws with instructions that push agents
- [700 AI Agents Linked to Hugging Face Security Breach](https://cybernoz.com/700-ai-agents-linked-to-hugging-face-security-breach/) - Around 700 AI agents created by OpenAI participated in the breach of Hugging Face during a cybersecurity evaluation, according to an independent investigation that has revealed the scale of the incident. METR and Redwood Research published the findings after being brought in to independently investigate the July incident and examine the agents’ behaviour, reasoning, and
- [Microsoft Teams Has Become a Haven for Scammers in China](https://cybernoz.com/microsoft-teams-has-become-a-haven-for-scammers-in-china/) - On Chinese social media, people have also reported experiencing variations of the scam involving other corporate software apps, including Webex, a video conferencing platform owned by Cisco, and Cliq, a workplace communication app owned by the Indian software giant Zoho. Since February 2025, 71 percent of the over 150 reviews of Webex on Apple’s Chinese
- [700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution](https://cybernoz.com/700-openai-agents-coordinate-attack-on-hugging-face-and-gain-remote-code-execution/) - OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found ways to communicate across supposedly isolated sandboxes. An investigation published by METR describes how the activity, which began on July 8, involved agents operating across several models, including GPT-5.6 Sol and an internally persistent model identified
- [Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping](https://cybernoz.com/android-17-adds-new-protections-against-sneaky-wi-fi-tracking-and-web-snooping/) - Google introduced a batch of network security changes coming in Android 17, aimed at making it harder for network operators, snoops, and scammers to track what you do on your phone. “When you visit a website or use an app, even if the connection is encrypted by HTTPS, the domain names of the sites you
- [Protect your WhatsApp account with new passkey and 2FA upgrades](https://cybernoz.com/protect-your-whatsapp-account-with-new-passkey-and-2fa-upgrades/) - WhatsApp announced on August 25 that more than one billion people now use passkeys to log back into the app. The announcement included two other security upgrades: a stronger two-step verification method and more context for incoming calls from unknown numbers. It marks one of the largest passwordless authentication rollouts to date. Passkeys are now
- [Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication](https://cybernoz.com/attackers-chain-two-papercut-flaws-to-execute-code-without-authentication/) - Ravie LakshmananAug 28, 2026Vulnerability / Web Security Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used
- [Post Office Horizon replacement ‘screw-up’ ends in challenge, more cost and delay](https://cybernoz.com/post-office-horizon-replacement-screw-up-ends-in-challenge-more-cost-and-delay/) - The Post Office created a new contract and awarded it without competitive tender to an IT supplier that challenged its decision to award a £169m IT contract to OneView Commerce. One legal expert said there had “obviously been a procurement screw-up” and questioned how this would impact the total cost to taxpayers. Electronic point-of-sale (EPOS)
- [Woolworths lifts the covers on internal AI](https://cybernoz.com/woolworths-lifts-the-covers-on-internal-ai/) - Key points Woolworths has revealed it uses an AI tool called Team Assist to field 7000 employee inquiries per week, escalating only one in 10 to a human. An AI marketing tool has cut production of the weekly shopper catalogue from a week to a few hours, chief executive Amanda Bardwell said. Woolworths' head of
- [In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions](https://cybernoz.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/) - SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of
- [U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog](https://cybernoz.com/u-s-cisa-adds-owncloud-linux-kernel-and-jfrog-artifactory-flaws-to-its-known-exploited-vulnerabilities-catalog/) - U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog Pierluigi Paganini August 28, 2026 U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited
- [Frontier AI tipping the scales toward cyber adversaries](https://cybernoz.com/frontier-ai-tipping-the-scales-toward-cyber-adversaries/) - Researchers at Palo Alto Networks’ Unit 42 warn that threat actors are already using AI to accelerate cyberattacks beyond the abilities of modern defenses. Source link
- [Why privacy by design is key to earning customer trust](https://cybernoz.com/why-privacy-by-design-is-key-to-earning-customer-trust/) - The first area is customer intent. If a customer changes a privacy setting, opts out of personalization or asks for certain data to be deleted, that choice should not stop at the system where it was first recorded. In practice, the same data may already be used by other services, caches, event pipelines, analytics systems
- [Authorities arrest 2 alleged members of prolific hacking group TeamPCP](https://cybernoz.com/authorities-arrest-2-alleged-members-of-prolific-hacking-group-teampcp/) - Authorities in Australia said Wednesday that they arrested two men accused of participating in cybercrimes for TeamPCP, a prolific group of hackers that, over nine months, has carried out a relentless series of supply-chain attacks that infected more than 1,000 organizations worldwide. In a statement, the Australian Federal Police said the two men were arrested
- [UK NCSC warns of increased OT targeting as threat actors exploit internet-exposed systems and edge devices](https://cybernoz.com/uk-ncsc-warns-of-increased-ot-targeting-as-threat-actors-exploit-internet-exposed-systems-and-edge-devices/) - The U.K. National Cyber Security Centre (NCSC) said it has seen increased targeting of OT (operational technology) systems across multiple sectors globally, including in the U.K., with activity by a range of threat actors causing limited real-world disruption. The agency said organizations using, deploying or maintaining OT should review their security posture, warning that internet
- [Boston Scientific faces ongoing operational disruption after cybersecurity incident impacts IT systems, order processing](https://cybernoz.com/boston-scientific-faces-ongoing-operational-disruption-after-cybersecurity-incident-impacts-it-systems-order-processing/) - Medical equipment manufacturer Boston Scientific identified a cybersecurity incident affecting certain information technology systems that resulted in a network outage and disruption to the company’s operations. The company revealed in an SEC Form 8-K filing that the cybersecurity incident affected certain of its IT systems, leading to a global disruption to the company’s operations. Susan
- [日本のビジネスパーソンを対象としたWiz調査で  「AI導入加速」はクラウド移行を上回ることが明らかに](https://cybernoz.com/日本のビジネスパーソンを対象としたwiz調査で-「ai/) - 同時に8割以上がAIによるサイバー攻撃への備えに遅れを感じ、60%がAIセキュリティへの投資を計画 Source link
- [Entity Analytics Watchlists in Elastic Security: organizational risk context as a scoring signal](https://cybernoz.com/entity-analytics-watchlists-in-elastic-security-organizational-risk-context-as-a-scoring-signal/) - Elastic Security v9.4 introduces Entity Analytics Watchlists, a new capability in the Entity Analytics suite that lets security teams create named, weighted lists of users, hosts, and services and feed that context directly into the platform's risk scoring pipeline. The gap this closes isn't awareness, as most security teams already know which entities deserve elevated
- [AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?](https://cybernoz.com/ai-is-accelerating-vulnerability-discovery-can-defenders-keep-up/) - Author: Gene Moody, Field CTO at Action1 AI can help us find vulnerabilities faster than ever. But what happens when the rest of the vulnerability management ecosystem can’t keep up? When Vulnerability Volume Outpaces the System In April, NIST released a statement regarding updates to NVD operations that reflects a necessary response to scale. CVE
- [Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix](https://cybernoz.com/hackers-compromise-hundreds-of-wordpress-sites-to-deploy-amatera-stealer-via-clickfix/) - A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a graduate-school application, then opens a genuine Word document while the infection runs quietly in the background. The lure claims to come from a recent Beijing
- [Manchester Airports Group Cyberattack Exposes Data of 8.7 Million Customers](https://cybernoz.com/manchester-airports-group-cyberattack-exposes-data-of-8-7-million-customers/) - Manchester Airports Group (MAG) has suffered a major cyberattack in which data belonging to around 8.7 million customers was reportedly accessed, raising concerns about how the stolen information could now be exploited by cybercriminals. The incident affected customer information associated with Manchester Airport, London Stansted and East Midlands Airport. Data connected to car park, lounge
- [Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure](https://cybernoz.com/attackers-exploit-mcp-rce-blind-prompt-injection-and-memory-credential-theft-against-ai-infrastructure/) - Attackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent frameworks, and AI gateways to execute code, validate prompt injection, deploy cryptominers, and steal credentials from process memory. The campaigns show that attackers are no longer using only generic web-server tradecraft; they are tailoring reconnaissance,
- [Cybercrime Statistics Worldwide: The 2026 Global Picture](https://cybernoz.com/cybercrime-statistics-worldwide-the-2026-global-picture/) - Cybersecurity Ventures predicted that global cybercrime damages would hit $10.5 trillion in 2025, a figure we have been compounding upward from $3 trillion in 2015 and $6 trillion in 2021. The estimate folds in stolen funds, fraud, productivity loss, intellectual property theft, post-attack remediation, regulatory fines, and reputational harm. To put the figure in scale, if
- [North Korean remote workers are broadening their job hunt beyond IT](https://cybernoz.com/north-korean-remote-workers-are-broadening-their-job-hunt-beyond-it/) - North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in sales and marketing and the medical profession. “DPRK workers present a unique detection challenge for defenders: rather than compromising accounts or breaking in via gaps in the organizations’ environments, they’re tricking
- [The AI agent swarm that attacked Hugging Face is a warning for the future](https://cybernoz.com/the-ai-agent-swarm-that-attacked-hugging-face-is-a-warning-for-the-future/) - The hacking incident involving OpenAI evaluation agents and Hugging Face offers an unusually concrete look at what advanced AI-assisted intrusion can mean in practice: not a single clever exploit, but thousands of automated decisions, rapid experimentation, lateral movement, credential theft, persistence, and attempts to evade detection. The OpenAI–Hugging Face incident began during internal cybersecurity evaluations
- [Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth](https://cybernoz.com/two-unitree-g1-edu-humanoid-robot-flaws-enable-root-rce-one-starts-over-bluetooth/) - Swati KhandelwalAug 28, 2026Vulnerability / IoT Security Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a
- [Wide misconception that AI investment information is regulated and that users are protected](https://cybernoz.com/wide-misconception-that-ai-investment-information-is-regulated-and-that-users-are-protected/) - Nearly half of those that use artificial intelligence (AI) to support their investment activity “mistakenly” believe the information it generates is regulated. Investors using investment tips from general purpose AI are not protected against losses that result in bad advice. This figure, according to research of 18 to 40-year-olds from UK financial services regulator the
- [TCE Weekly Roundup: Microsoft Entra ID Flaw, AI & Cybercrime](https://cybernoz.com/tce-weekly-roundup-microsoft-entra-id-flaw-ai-cybercrime/) - This weekly roundup highlights a broad range of cybersecurity and technology developments affecting cloud identity infrastructure, social media platforms, businesses, digital assets, and international law enforcement. From a critical Microsoft Entra ID vulnerability exploited before remediation to a global crackdown on West African cybercrime networks, recent developments demonstrate how attackers continue to target both
- [Paranoid OpenAI agents hacked Hugging Face to hide benchmark cheating](https://cybernoz.com/paranoid-openai-agents-hacked-hugging-face-to-hide-benchmark-cheating/) - Key points About 700 OpenAI agents attacked Hugging Face to reverse-engineer a scorer check that did not actually exist, a futile effort lasting days. OpenAI has revised its account of the hack, now tracing the incident's origin back to May, seven weeks before the July breach. Independent reviewers METR and Redwood Research leaned heavily on
- [OpenAI Agents Exploited Linux Kernel Flaw on Company's Own Systems](https://cybernoz.com/openai-agents-exploited-linux-kernel-flaw-on-companys-own-systems/) - Around the time some OpenAI models escaped their testing environment and hacked Hugging Face, some agents exploited a Linux kernel vulnerability to escalate privileges on OpenAI’s own systems. This was mentioned in a report published by OpenAI this week to detail the incident in which its models hacked Hugging Face in July. The AI giant’s
- [Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations](https://cybernoz.com/russian-apt-bluedelta-uses-hookedge-to-target-defense-and-diplomatic-organizations/) - Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations Pierluigi Paganini August 28, 2026 BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments. Recorded Future’s Insikt Group documented a campaign by BlueDelta, the Russian GRU-linked group that overlaps with the group APT28, running an entire espionage operation
- [AI-powered OSINT: Why everyone is a viable target for fraud](https://cybernoz.com/ai-powered-osint-why-everyone-is-a-viable-target-for-fraud/) - It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control. 27 Aug 2026 • , 5 min. read AI is changing the threat landscape, one model at a time. The pace at which the technology is evolving means activities that once took a skilled cybercriminal several hours or
- [Philippine Roblox ban call sparks wider debate over children’s online safety](https://cybernoz.com/philippine-roblox-ban-call-sparks-wider-debate-over-childrens-online-safety/) - Roblox has become a flashpoint in Southeast Asia’s debate over child safety online, as officials scrutinise whether young users are being exposed to harmful subcultures on the gaming platform. But analysts warn that it might just be a convenient scapegoat for wider failures in how children are protected online and offline.Most recently, Roblox has been
- [How to respond to an AI agent security incident](https://cybernoz.com/how-to-respond-to-an-ai-agent-security-incident/) - Hours 1-4: Scope the blast radius Now I am answering what the agent actually touched. I pull the full tool-call log, every API invoked, every parameter passed, every response received, and I cross-reference it against the agent’s entitlements to see what it could reach versus what it did reach. I also check whether the agent’s
- [AI-Powered Data Classification for Cloud Storage | Wiz](https://cybernoz.com/ai-powered-data-classification-for-cloud-storage-wiz/) - Public cloud storage buckets remain one of the most persistent attack surfaces in cloud security. Bucket names are globally guessable, misconfigurations are common, and aggregators index hundreds of thousands of open buckets daily. Once a bucket is exposed, the data inside it is one URL away from exfiltration.Data security posture management (DSPM) is core to
- [Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response](https://cybernoz.com/detecting-web-server-probing-fuzzing-in-traefik-with-automated-cloudflare-response/) - Introduction Self-hosted services exposed through a reverse proxy inevitably attract automated scanners probing for misconfigurations, admin panels, and vulnerable endpoints. In this article, I show how to turn routine Traefik access logs into an active defensive control using Elastic Security and Cloudflare. I use an out-of-the-box ES|QL detection rule to identify web server discovery and
- [Windows 11 KB5120998 update released with 35 changes and fixes](https://cybernoz.com/windows-11-kb5120998-update-released-with-35-changes-and-fixes/) - Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search. KB5120998 is a preview update that lets IT administrators test Windows bug fixes, improvements, and new features before they roll out to all users during next
- [Dark Caracal Hackers Use Ethereum Blockchain to Keep New Malware Connected After C2 Disruption](https://cybernoz.com/dark-caracal-hackers-use-ethereum-blockchain-to-keep-new-malware-connected-after-c2-disruption/) - Dark Caracal has returned with a new tool that helps attackers stay connected when defenders shut down their control servers. The cyberespionage group is linked by researchers to a Venezuelan communications organization intrusion, where it deployed an unfamiliar Go-based malware framework called GoCaracal alongside its long-used Bandook backdoor. The campaign begins with Spanish-language financial and
- [How an Atlanta Suburb Ended Up Sharing Flock Data With More Than 2,000 Organizations](https://cybernoz.com/how-an-atlanta-suburb-ended-up-sharing-flock-data-with-more-than-2000-organizations/) - Alpharetta, a prosperous suburb of Atlanta, Georgia, is home to about 67,000 people, served by about 120 local police officers. It also hosts several dozen cameras sold by Flock Safety, the increasingly controversial surveillance company that collects license plate data and other information and makes it searchable by police.Data captured by those Flock cameras, WIRED
- [Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth](https://cybernoz.com/unitree-g1-humanoid-robot-flaws-allow-unauthenticated-root-rce-over-bluetooth/) - The researcher noted that patches addressed most, if not all, of the reported issues, but cautioned that the findings reflect the tested builds rather than the current state of the G1. The bugs were reproduced on four G1 units, and the researcher received a total of $5,000 in bounties for their work. Operators are advised
- [Manchester Airports Group breached, millions of customers’ data stolen](https://cybernoz.com/manchester-airports-group-breached-millions-of-customers-data-stolen/) - Someone broke into the systems of Manchester Airports Group (MAG) and walked away with a “quantity” of customer data from three UK airports, the company has confirmed. The breach hit Manchester, Stansted, and East Midlands airports, after an unauthorised third party obtained a batch of customer information. “We immediately contained the risk and have been
- [PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions](https://cybernoz.com/papercut-zero-day-exploited-in-attacks-affecting-all-ng-and-mf-versions/) - Ravie LakshmananAug 28, 2026Vulnerability / Enterprise Security PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of
- [Emirati Women’s Day: Building the future of autonomous mobility](https://cybernoz.com/emirati-womens-day-building-the-future-of-autonomous-mobility/) - As the UAE marks Emirati Women’s Day 2026 under the theme “We Emerge Stronger and Better”, the occasion offers an opportunity to reflect on the growing role of women in science, technology, engineering and mathematics (STEM). Across the country, Emirati women are increasingly contributing to advanced industries, from artificial intelligence (AI) and aerospace to robotics
- [Sydney-based telco employee accused of selling customer data](https://cybernoz.com/sydney-based-telco-employee-accused-of-selling-customer-data/) - Key points A 30-year-old telco employee has been charged over allegedly accessing customer data and selling it to "criminal groups". NSW Police made the arrest at a station in Sydney's west after a referral from Queensland Police. The sold information was allegedly used to commit fraud offences against multiple victims, with charges including 12 counts
- [CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite](https://cybernoz.com/ciso-conversations-chris-wheeler-trust-is-the-job-from-the-navy-to-the-c-suite/) - Chris Wheeler is the CISO at Resilience. He has a long history in cybersecurity: a threat researcher and analyst at Efflux Systems and then threat analytics manager at Arbor Networks. He joined Resilience as threat intelligence lead but left in 2020 to become VP and SOAR lead at Morgan Stanley. He returned to Resilience four
- [Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports](https://cybernoz.com/cyberattack-on-uk-airport-operator-mag-exposes-data-of-8-7-million-customers-across-three-airports/) - Cyberattack on UK Airport Operator MAG Exposes Data of 8.7 Million Customers Across Three Airports Pierluigi Paganini August 28, 2026 A cyberattack on Manchester Airports Group exposed data of 8.7 million customers across Manchester, Stansted, and East Midlands airports. Manchester Airports Group disclosed that an unauthorised third party accessed customer data belonging to approximately 8.7
- [Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities](https://cybernoz.com/former-sexual-abuse-victims-say-grok-used-their-images-videos-to-train-deepfake-capabilities/) - A class action lawsuit filed by victims of child sexual abuse material (CSAM) accuses xAI of training Grok’s synthetic deepfake “nudify” capabilities on real images and videos of child abuse. The lawsuit, filed Wednesday in the U.S. District Court for the Northern District of California, names Jane Doe 1 and other anonymous individuals as plaintiffs,
- [Attacks on AI Infrastructure: 90-Day Honeypot Telemetry](https://cybernoz.com/attacks-on-ai-infrastructure-90-day-honeypot-telemetry/) - Wiz Threat Research operates honeypots across AI and ML services including LiteLLM, Flowise, LangChain, Langflow, ChromaDB, Ollama, and others. Over 90 days of telemetry, we observed sustained attack activity against AI infrastructure, with tooling adapted to the specific internals of each service. We’re sharing our findings with the community so that organizations can defend themselves
- [Elastic Security MCP App: fast & interactive security operations](https://cybernoz.com/elastic-security-mcp-app-fast-interactive-security-operations/) - Every SOC analyst knows the drill: an alert fires, and the next ten minutes are spent switching between a triage dashboard, a threat hunt, a case file, and the AI tool that told you to look in the first place. Recently, we introduced MCP Apps for Elastic, built on the open MCP Apps extension to
- [Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports](https://cybernoz.com/hackers-steal-data-of-8-7-million-customers-in-cyberattack-on-three-uk-airports/) - Criminal hackers have stolen the personal data of about 8.7 million customers following a cyberattack on systems used by Manchester Airports Group (MAG), which operates Manchester Airport, East Midlands Airport and London Stansted Airport. The airport operator said the incident involved unauthorized access to customer information, including email addresses, postcodes and vehicle registration details. The
- [Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power](https://cybernoz.com/hackers-are-targeting-ai-servers-to-steal-api-keys-and-hijack-computing-power/) - AI infrastructure is rapidly becoming a high-value enterprise attack surface. Attackers targeting LiteLLM AI gateways, RAGFlow retrieval platforms, and Kestra workflow orchestration environments to steal model-provider credentials, establish persistence, access backend data, and deploy cryptominers. The appeal is clear. AI gateways often centralize OpenAI, Azure, Anthropic, Gemini, and other provider API keys; retrieval platforms hold
- [New infosec products of the month: August 2026](https://cybernoz.com/new-infosec-products-of-the-month-august-2026/) - Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, Abnormal AI, F5 Networks, Intezer, Netscout, ScienceLogic, Searchlight Cyber, SelectHub, ServiceNow, Snyk, Tanium, and Tufin. ServiceNow organizes autonomous security around six solution areas ServiceNow has announced an acceleration of its Autonomous Security vision with six unified solutions that
- [New Instagram and Facebook rules set a default two-hour limit for teens](https://cybernoz.com/new-instagram-and-facebook-rules-set-a-default-two-hour-limit-for-teens/) - Meta decided that discretion was the better part of valor on Wednesday, agreeing to settle a landmark child safety case for up to $17 billion. The agreement would introduce a default two-hour daily limit for teens on Instagram and Facebook, overnight restrictions, and a range of other protections. It also brings the trial to an
- [Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers](https://cybernoz.com/amazon-kiro-prompt-injection-can-exfiltrate-sensitive-data-through-kiro-powers/) - Ravie LakshmananAug 27, 2026Vulnerability / Artificial Intelligence Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows,
- [Peers propose report into Computer Misuse Act reform](https://cybernoz.com/peers-propose-report-into-computer-misuse-act-reform/) - The UK government will have 12 months from the passing of the upcoming Cyber Security and Resilience Bill (CSRB) to publish a review of whether it is “necessary or desirable” to change the Computer Misuse Act of 1990 to shield legitimate cyber security professionals from the possibility of prosecution in the course of their regular
- [As AI agents go rogue, cyber insurers are adapting their policies](https://cybernoz.com/as-ai-agents-go-rogue-cyber-insurers-are-adapting-their-policies/) - Cyber insurers have spent years defining what constitutes a hack and when coverage should pay out, but ⁠the rapid emergence ⁠of AI agents is raising new questions, forcing insurers to review their policies. Leading AI developers OpenAI, Anthropic and Meta Platforms recently disclosed that their AI agents behaved unexpectedly, escaping controlled test environments and carrying
- [Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security](https://cybernoz.com/okta-shares-surge-on-strong-earnings-growing-demand-for-ai-identity-security/) - Shares of Okta (NASDAQ: OKTA) are surging after reporting stronger-than-expected second-quarter financial results and raised its outlook for the full fiscal year, with artificial intelligence (AI) emerging as an increasingly important source of demand. Shares of the of identity security company jumped more than 19% in extended trading Wednesday, climbing above $160 after closing the
- [OpenAI banned Russian ChatGPT accounts backing covert influence operation](https://cybernoz.com/openai-banned-russian-chatgpt-accounts-backing-covert-influence-operation/) - OpenAI banned Russian ChatGPT accounts backing covert influence operation Pierluigi Paganini August 27, 2026 OpenAI banned Russian ChatGPT accounts backing a fake think tank, IBI, that used AI posts and a fake “sovereignty” index to push pro‑Russia narratives. OpenAI says it has banned a cluster of ChatGPT accounts that likely originated in Russia and were
- [100-plus companies call for ‘global surge’ in AI-powered cyber defense](https://cybernoz.com/100-plus-companies-call-for-global-surge-in-ai-powered-cyber-defense/) - More than 100 companies and organizations, including OpenAI, Anthropic, Google, Microsoft and Amazon Web Services, have signed an open letter calling for a global effort to improve cybersecurity defenses as artificial intelligence capabilities advance. The letter, published Thursday, argues that the timeframe to strengthen defenses before AI-enabled attacks become more widespread and complex is rapidly
- [CMMI Institute has launched its new AI Maturity (AIM) Model](https://cybernoz.com/cmmi-institute-has-launched-its-new-ai-maturity-aim-model/) - We’re joined by Ron Lear, Vice President of Global CMMI Strategies at the CMMI Institute and Pascal Rabbath, Certified High Maturity CMMI Lead Appraiser and Working Group member. CMMI AIM delivers several targeted outcomes for organisations, regulatory agencies and governing bodies that leverage AI, including: Visibility into AI maturity across teams and functions Improved decision-making
- [Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK](https://cybernoz.com/extend-amazon-bedrock-guardrails-to-tool-interactions-using-the-strands-agents-sdk/) - If you’re running AI agents in production, Amazon Bedrock Guardrails protects the model boundary. But your agents also invoke tools, fetch external data, and communicate with other systems. That data flows outside the model boundary, where model-level guardrails can’t reach. You can extend guardrail coverage to those interactions using three validation checkpoints built with the
- [PCI DSS 4.0.1: The App & API Requirements QSAs Now Score](https://cybernoz.com/pci-dss-4-0-1-the-app-api-requirements-qsas-now-score/) - Key Takeaways Since March 31, 2025, all 51 former “best practice” requirements in PCI DSS 4.0 have been fully scored. Every 2026 assessment covers them. A large share of the new weight sits in the PCI DSS 4.0.1 application requirements, concentrated in Requirements 6 and 11: inventory of custom applications and APIs, continuous protection of
- [Nearly 700 rogue AI agents coordinated in the Hugging Face attack](https://cybernoz.com/nearly-700-rogue-ai-agents-coordinated-in-the-hugging-face-attack/) - New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI’s internal IM1 model coordinated the compromise through an unauthorized message board. Last month, Hugging Face disclosed that autonomous AI agents exploited two vulnerabilities in its dataset-processing pipeline to execute code, steal cloud and cluster credentials, and move
- [Cybercriminals Are Selling Corporate Executives' Social Security Numbers for Just 25 Cents](https://cybernoz.com/cybercriminals-are-selling-corporate-executives-social-security-numbers-for-just-25-cents/) - Corporate executives’ most sensitive identity data is being sold on dark web marketplaces for as little as a quarter, according to new threat intelligence from Rapid7. Unlike stolen credit cards, which can be canceled within minutes, a compromised Social Security number remains a permanent liability, and cybercriminals are exploiting that durability to build a thriving
- [CISA Warns of Actively Exploited Citrix NetScaler ADC and Gateway Vulnerability](https://cybernoz.com/cisa-warns-of-actively-exploited-citrix-netscaler-adc-and-gateway-vulnerability/) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-8452, a vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation. This vulnerability was added on August 26, 2026, and federal civilian agencies are required to apply vendor-recommended mitigations by August 29, 2026. Citrix
- [Unknown PaperCut NG/MF vulnerability is under active attack](https://cybernoz.com/unknown-papercut-ng-mf-vulnerability-is-under-active-attack/) - A yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today. “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the vendor said. What is PaperCut NG/MF? PaperCut NG is print management software for places like offices,
- [Fake listings can turn trusted platforms into scam springboards](https://cybernoz.com/fake-listings-can-turn-trusted-platforms-into-scam-springboards/) - Recently, we found a listing on BuzzFeed from someone pretending to be Malwarebytes Support. It reminded us why we need to be cautious about content on platforms where anyone can create an entry. Based on the phone number, we suspect the people behind this listing are trying to draw callers into a tech support scam.
- [OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face](https://cybernoz.com/openai-says-reward-hacking-drove-ai-agents-to-exploit-zero-days-and-breach-hugging-face/) - OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled
- [Meta pays $18bn to settle US child safety lawsuit](https://cybernoz.com/meta-pays-18bn-to-settle-us-child-safety-lawsuit/) - Social media giant Meta has agreed to pay an $18bn settlement with US states and territories over legal claims that its Facebook and Instagram platforms are harming children, but the firm continues to deny any wrongdoing. The landmark settlement – approved by California judge Yvonne Gonzalez Rogers on 26 August – marks the company’s largest
- [Health hands enterprise computing to Leidos in $91m deal](https://cybernoz.com/health-hands-enterprise-computing-to-leidos-in-91m-deal/) - Key points The Department of Health, Disability and Ageing has contracted Leidos Australia for enterprise computing services over three years in a deal worth $91 million. The Leidos contract overlaps by almost a year with the existing 12-year Datacom agreement, which is due to wrap up in mid-2027. Health confirmed the Datacom contract covers multiple
- [OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack](https://cybernoz.com/openai-agents-coordinated-via-makeshift-message-board-ahead-of-hugging-face-hack/) - OpenAI says an improvised, unauthorized message board built by its own AI agents was central to how those agents came to breach parts of Hugging Face’s production systems. This communication channel first appeared inside Artifactory, a package-management service OpenAI hosted internally so agents working on training and evaluation tasks could install software. Agents were meant
- [Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback](https://cybernoz.com/dark-caracal-deploys-new-go-malware-with-ethereum-based-c2-fallback/) - Dark Caracal Deploys New Go Malware With Ethereum-Based C2 Fallback Pierluigi Paganini August 27, 2026 Dark Caracal targets Venezuela with GoCaracal, an upgraded Bandook toolkit and an Ethereum fallback for resilient C2 communications. Dark Caracal is back with new malware and the same hunting grounds. Arctic Wolf Labs researchers link a June 2026 intrusion against
- [Federal authorities disrupt China-backed hacking operation targeting US critical infrastructure](https://cybernoz.com/federal-authorities-disrupt-china-backed-hacking-operation-targeting-us-critical-infrastructure/) - Compromised IoT devices were used in a yearslong campaign against key sectors and U.S. government agencies. Source link
- [Unit 42 warns AI has shifted balance of power from defenders to attackers](https://cybernoz.com/unit-42-warns-ai-has-shifted-balance-of-power-from-defenders-to-attackers/) - Unit 42’s top brass has seen enough from internal frontier AI model testing and malicious in-the-wild use of commercially available AI tools to be genuinely concerned. “I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity,” Sam Rubin, senior vice president of Palo Alto Networks’ threat intelligence arm,
- [Here’s all the times AI has gone rogue and hacked other companies](https://cybernoz.com/heres-all-the-times-ai-has-gone-rogue-and-hacked-other-companies/) - In July, OpenAI admitted that one of its agents tasked with completing a cybersecurity experiment broke out of containment and hacked AI dataset platform Hugging Face. That incident, which got a full accounting from OpenAI yesterday, was the first publicly reported case where an LLM went rogue and autonomously hacked a third party. Since then,
- [How OpenAI let a mob of LLM agents game a test and ransack Hugging Face](https://cybernoz.com/how-openai-let-a-mob-of-llm-agents-game-a-test-and-ransack-hugging-face/) - “Agents used this message board to coordinate several large-scale collective projects to find a general-purpose way to fool or tamper with the automated scorer for the ExploitGym benchmark,” METR researchers wrote. “Agents managed to achieve milestones they could not have achieved working on their own, often because some agents participated in experiments that risked failing
- [How we saved 100 terabytes of memory by optimizing 1.1.1.1’s DNS cache](https://cybernoz.com/how-we-saved-100-terabytes-of-memory-by-optimizing-1-1-1-1s-dns-cache/) - Big Pineapple, the platform behind 1.1.1.1, Gateway DNS, DNS Firewall, AS112, and several other Cloudflare DNS services, stores over 250 billion DNS cache entries at any given time. At that scale, wasting a single byte per entry costs more than 250 gigabytes of memory across our fleet.Five successive changes to how cache entries are stored
- [​​​​​​What’s new in Microsoft Security: August 2026](https://cybernoz.com/whats-new-in-microsoft-security-august-2026/) - As organizations incorporate AI agents into more processes across business and operations, security teams can benefit from greater visibility and new purpose-built tools that help manage, secure, and govern AI. This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across
- [Building an exposure management program the business trusts](https://cybernoz.com/building-an-exposure-management-program-the-business-trusts/) - Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand.Key takeawaysSecurity tool sprawl and data silos make it
- [PaperCut warns of NG, MF flaw exploited in zero-day attacks](https://cybernoz.com/papercut-warns-of-ng-mf-flaw-exploited-in-zero-day-attacks/) - PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted
- [PaperCut NG/MF Vulnerability Actively Exploited in Attack](https://cybernoz.com/papercut-ng-mf-vulnerability-actively-exploited-in-attack/) - PaperCut has confirmed that hackers are actively exploiting an unpatched vulnerability in its widely used PaperCut NG and PaperCut MF print management software, prompting the company to rush out an emergency patch just hours after issuing its first warning. The Australian vendor said its security response team is investigating “confirmed customer incidents” and is treating
- [A Georgia Cop Used Flock to Track 2 Other Cops: His Ex and Her Friend](https://cybernoz.com/a-georgia-cop-used-flock-to-track-2-other-cops-his-ex-and-her-friend/) - In recent months, there has been a surge in reports of police officers misusing automatic license plate readers (ALPRs) sold by Flock Safety to stalk former romantic partners—but details about these incidents are often scarce.Now, with documents obtained via a public records request, WIRED can reveal specific details about one extensive Flock-fueled surveillance campaign and
- [Hackers Exploit CVE-2023-49105 to Steal Nuclear Records From Philippine Research Agency](https://cybernoz.com/hackers-exploit-cve-2023-49105-to-steal-nuclear-records-from-philippine-research-agency/) - Suspected Chinese-speaking operators exploited the critical ownCloud flaw CVE-2023-49105 to steal nuclear material records, research reactor data, personnel files, and encryption key material from a Philippine nuclear research organization. Hunt.io discovered an exposed file directory on August 13, 2026, hosted at 31.58.209[.]241:8000, an Amsterdam-based server registered to CGI Global Limited. The directory was served through
- [Two alleged TeamPCP hackers arrested over global supply chain attacks](https://cybernoz.com/two-alleged-teampcp-hackers-arrested-over-global-supply-chain-attacks/) - Two men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world. The Australian Federal Police (AFP), working with the FBI and Western Australia Police Force (WAPF), arrested a 21-year-old from
- [Flock wants privacy to meet surveillance halfway](https://cybernoz.com/flock-wants-privacy-to-meet-surveillance-halfway/) - Flock Safety CEO Garrett Langley says the United States needs a “compromise” between privacy and public safety. It’s a neat phrase, except I don’t like to see “compromise” and “privacy” that close together. “When people talk about just one of these, privacy or safety, they’re prioritizing the wrong thing, and what we have to prioritize
- [Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE](https://cybernoz.com/next-js-patches-critical-avif-and-windows-flaws-enabling-unauthenticated-rce/) - Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604 (CVSS
- [Passenger data stolen from major UK airports](https://cybernoz.com/passenger-data-stolen-from-major-uk-airports/) - Manchester Airports Group (MAG), the parent organisation that runs East Midlands, Manchester, and London Stansted airports, has admitted an unnamed threat actor has stolen a significant quantity of personally identifiable information (PII) on approximately 8.7 million people who parked at or flew through its airports. The data breach is understood to relate to parking, lounge
- [Meta agrees to pay up to US$18 billion to settle lawsuits](https://cybernoz.com/meta-agrees-to-pay-up-to-us18-billion-to-settle-lawsuits/) - Meta Platforms will pay up to US$18 billion ($25 billion) over the next decade and strictly limit how teenagers use Facebook and Instagram under an agreement ⁠with nearly all US ⁠states to resolve claims it designed those social media platforms to addict children. The settlements end a federal trial over allegations Meta's products harmed children
- [Trump Order Aims to Block Foreign Backdoors in US Power Grid Gear](https://cybernoz.com/trump-order-aims-to-block-foreign-backdoors-in-us-power-grid-gear/) - President Trump issued Executive Order 14420 on Wednesday, declaring a national emergency to mitigate vulnerabilities in the United States’ bulk power system arising from foreign-supplied electrical equipment. The order attributes the heightened emergency status to rapid growth across data centers, AI, advanced manufacturing, and defense production. Officials noted that dependence on grid reliability magnifies the
- [Two Arrests, One Supply-Chain Attack, and a Lot of Stolen Credentials](https://cybernoz.com/two-arrests-one-supply-chain-attack-and-a-lot-of-stolen-credentials/) - Australian Police Charge Two Over TeamPCP Credential Theft Pierluigi Paganini August 27, 2026 Australian police charged two men linked to TeamPCP over malware hidden in open-source code that stole 500,000+ credentials from 1,000+ organizations. Australian police have charged two men from Western Australia over a global cybercrime operation that allegedly hid malicious code in open-source
- [Hundreds of agents went rogue in lead up to Hugging Face breach](https://cybernoz.com/hundreds-of-agents-went-rogue-in-lead-up-to-hugging-face-breach/) - OpenAI released a technical breakdown of the historic incident and plans changes to prevent such an occurrence from happening again. Source link
- [Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos](https://cybernoz.com/two-alleged-teampcp-members-arrested-and-charged-after-months-of-software-supply-chain-chaos/) - Two men from Western Australia were arrested and charged Wednesday for their alleged roles in TeamPCP, a notorious cybercrime group responsible for inserting malicious code into widely used open-source software in a campaign that compromised more than 1,000 organizations worldwide. Australian authorities did not formally name the men, but Australian media identified them as Ruben
- [[tl;dr sec] #343 - Hugging Face Technical Report, AWSHound, OWASP Agentic Skills Top 10](https://cybernoz.com/tldr-sec-343-hugging-face-technical-report-awshound-owasp-agentic-skills-top-10/) - Full 38 page report from OpenAI on the incident, map your AWS environment, top 10 agent skill no no's I hope you’ve been doing well! Staying Afloat Hope you’ve been doing well amidst the busy-ness these days. Alas, a personal life anecdote shall have to wait for next week, tonight a meme and bedtime for
- [AI can be made to read an email much differently than you do](https://cybernoz.com/ai-can-be-made-to-read-an-email-much-differently-than-you-do/) - During each pass through the injected email, the summary output reported an invoice deadline of September 3, 2026, instead of the actual August 21, 2026, and omitted the name “Diego Siciliani” mentioned in the original email. This was exactly what the injected instructions had asked the summarizer to do. The model used to drive the
- [Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others](https://cybernoz.com/australian-police-arrest-two-over-teampcp-hacks-targeting-mercor-openai-and-others/) - Australian police have arrested two people in Perth accused of being members of TeamPCP, a prolific hacking group blamed for high-profile hacks against big tech giants in recent months. The two have been charged with more than a dozen hacking, money laundering, and other cybercrime offenses and are expected in court later on Thursday. According
- [Claude, Codex, and Hermes installed unowned code inside corporate networks](https://cybernoz.com/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/) - Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware. The potentially
- [LevelBlue opens Sydney SOC to provide local cybersecurity support, 24/7 monitoring for Australian critical infrastructure](https://cybernoz.com/levelblue-opens-sydney-soc-to-provide-local-cybersecurity-support-24-7-monitoring-for-australian-critical-infrastructure/) - LevelBlue is making a multi-million-dollar investment in a new local Security Operations Center (SOC) in Sydney, going live August 25, 2026. The Sydney SOC gives Australian organizations, with a particular focus on critical infrastructure owners and operators, access to onshore analysts and local escalation pathways, backed by the scale, threat intelligence, and 24/7 coverage of
- [CISA issues Internet Exposure Reduction guidance to reduce risks from IT, OT, ICS and industrial systems](https://cybernoz.com/cisa-issues-internet-exposure-reduction-guidance-to-reduce-risks-from-it-ot-ics-and-industrial-systems/) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released guidance to help organizations identify systems accessible from the internet, remove unnecessary remote access and secure internet-facing assets. The guidance focuses on reducing an organization’s exposure to potential cyber threats by identifying externally accessible systems and addressing access that is not required. It also concentrates on
- [Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps](https://cybernoz.com/version-control-dfir-a-cheatsheet-to-github-gitlab-bitbucket-and-azure-devops/) - As threat actors increasingly target Version Control Systems (VCS) to execute both targeted attacks and broad supply chain compromises (such as the campaigns attributed to TeamPCP), it is essential to understand available telemetry, recommended configurations, and available audit events. Preventing an initial compromise is challenging, making post-compromise visibility and rapid response capabilities critical.To assist security
- [Google Threat Intelligence in Elastic Security](https://cybernoz.com/google-threat-intelligence-in-elastic-security/) - Elastic Security natively ingests Google Threat Intelligence: known-malicious IPs, domains, URLs, and file hashes matched against your telemetry the moment they appear, each carrying a verdict and a 0–100 threat score. The setup consists of an API key and two data streams, with no extra infrastructure. When an indicator is ambiguous, workflows built on Agent
- [How Threat Research and MDR Help SMBs Build a Defensive Edge](https://cybernoz.com/how-threat-research-and-mdr-help-smbs-build-a-defensive-edge/) - Corporate IT and security teams have the unenviable task of keeping relentless and increasingly sophisticated adversaries at bay. They’re often faced with limited resources and expanding attack surfaces, but recruiting and retaining top-tier security professionals to run an in-house Security Operations Centre (SOC) is out of reach for many organizations. At the same time, threats
- [Two Australians Charged Over TeamPCP Supply-Chain Attacks That Hit 1,000+ Organizations](https://cybernoz.com/two-australians-charged-over-teampcp-supply-chain-attacks-that-hit-1000-organizations/) - Two Western Australian men have been charged over alleged TeamPCP supply-chain attacks that police say planted malicious open-source code and reached more than 1,000 organizations worldwide. The Australian Federal Police charged the pair on 26 August 2026 with a combined 14 offenses after search warrants in Perth, working with the Western Australia Police Force and
- [AI Agents Used by 68% of Top-Performing Cybersecurity Teams](https://cybernoz.com/ai-agents-used-by-68-of-top-performing-cybersecurity-teams/) - AI agents are already finding their way into the working methods of some of the highest-performing cybersecurity teams, according to new three-year benchmark data from Hack The Box (HTB). The 2026 Global Cyber Skills Benchmark found that 68% of the top 25 teams included an AI agent, despite AI agents accounting for just 2.7% of
- [AWS Security Teams Can Correlate CloudTrail, VPC and Route 53 Logs to Detect Attacks](https://cybernoz.com/aws-security-teams-can-correlate-cloudtrail-vpc-and-route-53-logs-to-detect-attacks/) - AWS security teams can improve detection of multi-stage intrusions by correlating API activity in CloudTrail with network metadata in VPC Flow Logs and DNS activity in Route 53 Resolver query logs. The approach turns isolated alerts into an attack narrative spanning credential abuse, reconnaissance, privilege escalation, lateral movement and data exfiltration. A suspicious GetCallerIdentity request
- [Women In Cybersecurity Report, Summer 2026: Black Hat(HER) Special Edition](https://cybernoz.com/women-in-cybersecurity-report-summer-2026-black-hather-special-edition/) - The Women in Cybersecurity Report, hosted by Cybercrime Magazine Deputy Editor Amanda Glassner, highlights the latest breakthroughs, voices, and stories from women leading the charge in cybersecurity. In this special episode, we cover Black Hat(HER), a new platform created to address the persistent underrepresentation of women in cybersecurity. Built around the global reach and community of Black
- [Cyberattack causes network outage at Boston Scientific, disrupts global operations](https://cybernoz.com/cyberattack-causes-network-outage-at-boston-scientific-disrupts-global-operations/) - Medical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations. Boston Scientific makes devices for minimally invasive procedures, including stents, catheters, pacemakers and defibrillators. According to its website, the company employs 59,000 people across 127 countries, treats an estimated 48 million patients a year,
- [Fake Apple Pay charge brings the classic tech support scam to your phone](https://cybernoz.com/fake-apple-pay-charge-brings-the-classic-tech-support-scam-to-your-phone/) - iPhone users are being targeted in a new tech support scam, using a fake Apple Pay notification to trick users. Tech support scams that use fake warnings to push victims into calling a phone number have been around for years, but this page has been designed specifically for phones. Instead of a desktop warning claiming
- [Learn How to Build Security Operations Ready for AI-Powered Attacks](https://cybernoz.com/learn-how-to-build-security-operations-ready-for-ai-powered-attacks/) - The Hacker NewsAug 27, 2026Artificial Intelligence / Webinar Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built
- [Public wary of UK government ‘backdoor’ surveillance following Apple row, poll reveals](https://cybernoz.com/public-wary-of-uk-government-backdoor-surveillance-following-apple-row-poll-reveals/) - The public is wary of UK government surveillance powers that require technology companies to build “backdoors’ to access encrypted communications, according to a poll of 2,000 people in the UK by a Washington-based advocacy group. Only 12% of those surveyed believe the government should be able to issue secret orders to tech companies to allow
- [Can We Trust AI Agents? Adarsh Sinha On AI Security Risks](https://cybernoz.com/can-we-trust-ai-agents-adarsh-sinha-on-ai-security-risks/) - As organizations race to move from AI chatbots and copilots toward autonomous AI agents, security leaders are being forced to answer a harder question than “should we adopt AI?” — it’s “can we trust AI to make security decisions?” To unpack this, The Cyber Express sat down with Adarsh Kant Sinha, Founder and CEO of
- [Two Aussies alleged to be "principal participants" of TeamPCP hacking group](https://cybernoz.com/two-aussies-alleged-to-be-principal-participants-of-teampcp-hacking-group/) - Key points Two Western Australian men, aged 21 and 23, have been charged as alleged principal participants of hacking group TeamPCP following raids in Cottesloe, Hamilton Hill and Mandurah. The joint AFP, WA Police and FBI operation alleges TeamPCP inserted malicious code into open-source software, potentially compromising more than 1000 organisations worldwide. Police estimate the
- [Australia Arrests 2 Alleged TeamPCP Hackers](https://cybernoz.com/australia-arrests-2-alleged-teampcp-hackers/) - Two men suspected of being members of the notorious cybercrime group TeamPCP have been arrested and charged by Australian authorities. The suspects, Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, have been arrested in Perth. They face several charges related to their alleged role in a cybercrime syndicate that is believed to have caused
- [Meta to Pay Up to $18B Over Teen Social Media Use](https://cybernoz.com/meta-to-pay-up-to-18b-over-teen-social-media-use/) - Meta to Pay Up to $18B Over Teen Social Media Use Pierluigi Paganini August 27, 2026 Meta will pay up to $18B and cap teen Facebook and Instagram use at two hours daily after nearly all US states sued over child safety. Meta will pay up to $18 billion over the next decade and impose
- [Three 10.0 security flaws fixed across Ubiquiti’s UniFi line](https://cybernoz.com/three-10-0-security-flaws-fixed-across-ubiquitis-unifi-line/) - Ubiquiti has patched 21 critical vulnerabilities, three of which were rated the highest severity possible, the communications product company said Wednesday in a security bulletin. In all, the company patched 22 vulnerabilities, with the last one rated “high,” it said in the bulletin. Three of the vulnerabilities had a Common Vulnerability Scoring System rating of
- [Industrial threat report for Q2 2026](https://cybernoz.com/industrial-threat-report-for-q2-2026/) - All threats In Q2 2026, the percentage of ICS computers on which malicious objects were blocked continued to decrease, falling to 19.15%, its lowest level since 2022. Percentage of ICS computers on which malicious objects were blocked, Q3 2023–Q2 2026 Regionally, the percentages ranged from 8.1% in Northern Europe to 27.9% in Africa. Regions ranked
- [Critical infrastructure’s long, undefended tail exposed by UK energy attack](https://cybernoz.com/critical-infrastructures-long-undefended-tail-exposed-by-uk-energy-attack/) - The same connection can expose equipment designed decades ago, when its manufacturers never contemplated that it would face internet-based attackers. “The thing that brought the efficiency has made those assets exposed,” Tonkin says. “In smaller organizations, there is no governance to stop an engineer from doing it. Thousands and thousands of very vulnerable devices are
- [Trump issues EO 14420 to secure US bulk-power systems from foreign equipment, cybersecurity risks](https://cybernoz.com/trump-issues-eo-14420-to-secure-us-bulk-power-systems-from-foreign-equipment-cybersecurity-risks/) - U.S. President Donald Trump declared a national emergency over foreign supply of bulk-power system electric equipment, citing risks that foreign actors could create or exploit vulnerabilities in equipment supporting U.S. national defense, emergency services, critical infrastructure and the economy. In a Wednesday order, the administration said the growing dependence on reliable electricity driven by advanced
- [CISA Vulnerability Review flags CVE data gaps, common weaknesses; urges Secure by Design to address vulnerability root causes](https://cybernoz.com/cisa-vulnerability-review-flags-cve-data-gaps-common-weaknesses-urges-secure-by-design-to-address-vulnerability-root-causes/) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday published its CISA Vulnerability Review, which examines the root causes of insecure software and basic security failures. Drawing on CISA and open-source data from fiscal years 2024 and 2025, the review provides vulnerability insights and tools to help software producers and organizations reduce cyber risk.
- [3 Critical CVEs in Palo Alto Networks Expedition](https://cybernoz.com/3-critical-cves-in-palo-alto-networks-expedition/) - Palo Alto Networks’ Expedition tool contains multiple critical vulnerabilities (CVE-2024-9463, CVE-2024-9464, CVE-2024-9465, CVE-2024-9466, CVE-2024-9467), including OS command injection, SQL injection, cleartext storage of sensitive information, and cross-site scripting (XSS). These issues, with CVSS scores reaching 9.9, expose systems running Expedition to unauthorized access, credential theft, and administrative takeover. Exploitation requires minimal complexity and no user
- [Recorded Future Launches AI Alert Filtering](https://cybernoz.com/recorded-future-launches-ai-alert-filtering/) - AI Alert Filtering is now available. Powered by Recorded Future AI, it automates the first pass of filtering Alerts by relevance so analysts prioritize faster while keeping control. Starting today, Recorded Future is launching AI Alert Filtering, an AI agent that automatically filters every Alert by relevance before an analyst opens it. At scale, Alerts
- [Microsoft Sentinel detection rules: automatic migration to Elastic](https://cybernoz.com/microsoft-sentinel-detection-rules-automatic-migration-to-elastic/) - Elastic automatically translates your Microsoft Sentinel detection rules into Elastic Security. Export your Scheduled and Near Real Time (NRT) analytics rules from Sentinel, upload them, and Elastic picks up the mapping and translation from there using an LLM you choose. Watchlists and severity mappings carry over. This is the first automatic migration path off a
- [CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday](https://cybernoz.com/cisa-orders-feds-to-patch-citrix-netscaler-rce-flaw-by-saturday/) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered government agencies to patch their Citrix NetScaler appliances against an actively exploited vulnerability by Saturday. Tracked as CVE-2026-8452, this high-severity security flaw stems from a memory overflow weakness affecting NetScaler ADC and NetScaler Gateway appliances configured with Gateway VPN or AAA (Authentication, Authorization, and Auditing)
- [Veeam Backup & Replication Flaw Exposes Guest OS Credentials in Cleartext Logs](https://cybernoz.com/veeam-backup-replication-flaw-exposes-guest-os-credentials-in-cleartext-logs/) - Veeam has disclosed a critical security vulnerability in Veeam ONE 13 that could allow an unauthenticated remote attacker to coerce SMB authentication from the product’s service account. Tracked as CVE-2026-65641, the issue carries a CVSS v4.0 score of 9.3 and was reported through the HackerOne vulnerability disclosure program. It affects Veeam ONE 13.1.0.7034 and all
- [CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability](https://cybernoz.com/cisa-warns-of-actively-exploited-microsoft-sql-server-rce-vulnerability/) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution vulnerability affecting Microsoft SQL Server, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. This vulnerability allows an attacker to execute code in the security context of the SQL Server Database Engine service account. Microsoft SQL Server
- [FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate](https://cybernoz.com/fbi-takes-down-china-linked-hacking-network-behind-attacks-on-nasa-doj-and-u-s-senate/) - The Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used against U.S. government agencies for years. The tools, known as QScan and QTRouter, were developed by a group called QTFY, which court documents tie to
- [New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access](https://cybernoz.com/new-gputhor-rowhammer-defeats-ecc-on-nvidia-rtx-a6000-to-gain-host-root-access/) - Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM
- [Deutsche Bank selects Thought Machine to support core system reduction](https://cybernoz.com/deutsche-bank-selects-thought-machine-to-support-core-system-reduction/) - Deutsche Bank’s private bank will use Thought Machine’s cloud-based banking platform as it reduces core systems from 15 to two cloud-based platforms, after agreeing a 10-year deal. As part of its plan to simplify its private banking landscape, the German banking giant is adopting Thought Machine’s Vault Core cloud-based banking software. The software from the
- [Boston Scientific Cyberattack Disrupts Order Processing, Shipping Worldwide](https://cybernoz.com/boston-scientific-cyberattack-disrupts-order-processing-shipping-worldwide/) - Boston Scientific said a cyberattack detected this Tuesday, caused a network outage and cut off its ability to process and ship customer orders globally, and the medical device maker has not been able to say when full service will return. The company disclosed the incident in an 8-K filed with the Securities and Exchange Commission
- [Moving from threat intelligence to understanding business risk](https://cybernoz.com/moving-from-threat-intelligence-to-understanding-business-risk/) - The dam wall has burst. The volume of threats and vulnerabilities today’s organisations face exceeds their ability to react in a timely way by orders of magnitude. AI agents, that are either maliciously or accidentally executed, can compromise defences and cause damage to corporate data and applications. “With the new frontier AI models, we’re seeing
- [Recent Citrix NetScaler Vulnerability Exploited in the Wild](https://cybernoz.com/recent-citrix-netscaler-vulnerability-exploited-in-the-wild/) - The Cybersecurity and Infrastructure Security Agency (CISA) is urging government organizations to immediately address a recently patched Citrix NetScaler vulnerability that is being exploited in the wild. The vulnerability is tracked as CVE-2026-8452 and it was one of the several flaws for which Citrix announced patches on June 30. The vendor said the vulnerability can
- [CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do](https://cybernoz.com/cisa-warns-water-utilities-find-your-exposed-plcs-before-attackers-do/) - CISA Warns Water Utilities: Find Your Exposed PLCs Before Attackers Do Pierluigi Paganini August 27, 2026 CISA urges water utilities to find and secure internet-exposed PLCs after July attacks showed how easily exposed industrial systems can be compromised. Over 100 internet-exposed systems in the US water and wastewater sector got hit by cyberattacks in July
- [OpenAI: Agent behavior that led to Hugging Face intrusion formed in May](https://cybernoz.com/openai-agent-behavior-that-led-to-hugging-face-intrusion-formed-in-may/) - OpenAI says the behavior that led its agents to breach Hugging Face emerged in its research environment more than two months before the incident, and concluded that it was a failure of alignment as much as it was a failure of security. The details come from a technical report the frontier AI company released Wednesday,
- [Two WA men charged after AFP-FBI-WAPF probe into alleged open-source supply-chain attack](https://cybernoz.com/two-wa-men-charged-after-afp-fbi-wapf-probe-into-alleged-open-source-supply-chain-attack/) - Two Western Australian men have been charged with a combined 14 offences following an international cybercrime investigation into an alleged syndicate accused of compromising open-source software to infiltrate more than 1,000 organisations worldwide. The Australian Federal Police (AFP) charged the men on 26 August following a joint investigation with the Western Australia Police Force (WAPF),
- [Wiz Adds Runtime Sensor to its Wiz for Gov Platform ](https://cybernoz.com/wiz-adds-runtime-sensor-to-its-wiz-for-gov-platform/) - We are excited to announce the addition of the Wiz Runtime Sensor to Wiz for Gov, expanding our full-featured Cloud Native Application Protection Platform (CNAPP) for government customers. Our commitment to the FedRAMP authorization process allows us to offer the same product experience across both commercial and FedRAMP environments. Wiz was born in the cloud and
- [Elastic Defend: 800+ vulnerable driver YARA rules](https://cybernoz.com/elastic-defend-800-vulnerable-driver-yara-rules/) - We know you’re tired of hearing how every vendor is going to finally help you solve alert fatigue. Well, one way we’re improving alert fatigue is from a slightly different angle, better prevention at the endpoint. Because stopping more at the endpoint means fewer alerts ever raised. We have three endpoint enhancements, all contributing to
- [Meta agrees to $18 billion settlement over teen social media harms](https://cybernoz.com/meta-agrees-to-18-billion-settlement-over-teen-social-media-harms/) - Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. The settlement, which is awaiting court approval, resolves a lawsuit filed in 2023 by California Attorney General Rob Bonta
- [WatchGuard Agent for Windows Vulnerability Allows Code Execution with Elevated Privileges](https://cybernoz.com/watchguard-agent-for-windows-vulnerability-allows-code-execution-with-elevated-privileges/) - WatchGuard has disclosed two critical vulnerabilities in its Windows-based WatchGuard Agent that could allow unauthenticated attackers to execute arbitrary code with elevated privileges. The flaws, tracked as CVE-2026-57910 and CVE-2026-57909, affect WatchGuard Agent versions earlier than 1.25.13.0000. The security issues were published on August 25, 2026. WatchGuard said it is not aware of either vulnerability
- [Ubiquiti Fixes 22 UniFi Flaws Enabling Command Injection, Authentication Bypass and Privilege Escalation](https://cybernoz.com/ubiquiti-fixes-22-unifi-flaws-enabling-command-injection-authentication-bypass-and-privilege-escalation/) - Ubiquiti has released security updates to address 22 vulnerabilities across its UniFi ecosystem. These updates include multiple critical flaws that could allow unauthenticated command injection, authentication bypass, and privilege escalation on exposed devices. Documented in Security Advisory Bulletin 067 and published on August 26, 2026, these vulnerabilities affect several components, including UniFi OS, UniFi Protect,
- [Production data in testing is still common, and Tricentis' CISO wants it gone](https://cybernoz.com/production-data-in-testing-is-still-common-and-tricentis-ciso-wants-it-gone/) - In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for a week until it was fixed. Dean describes
- [NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions](https://cybernoz.com/novacookies-campaigns-abuse-genuine-docusign-notifications-to-steal-microsoft-365-sessions/) - Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that facilitates real-time
- [Ransomware attack volumes hit ‘high-water-mark’ in July](https://cybernoz.com/ransomware-attack-volumes-hit-high-water-mark-in-july/) - July saw ransomware attacks reach a peak of 894 recorded attacks, hitting the highest level seen so far this year, up almost a quarter on June, according to NCC Group’s latest monthly Threat Intelligence Report. Though much attention remains on the impact of artificial intelligence (AI) on the cyber security world, NCC said the number
- [Internet Architecture Board says service-level age checks 'will fail'](https://cybernoz.com/internet-architecture-board-says-service-level-age-checks-will-fail/) - The Internet Architecture Board (IAB) says it is concerned that age assurance approaches that rely on service provider checks will not only fail, but also leave youth less safe on the internet. IAB, which provides long-range technical direction for the internet's development since 1979, said age checks are better done on users' own devices than
- [The MFA Identity Trap: When Authentication Creates a False Sense of Security](https://cybernoz.com/the-mfa-identity-trap-when-authentication-creates-a-false-sense-of-security/) - Multi-factor authentication (MFA) has become one of cybersecurity’s most important controls. Roughly 70% of enterprise workforce users are now protected by it. But its success has created an unintended problem. Organizations increasingly treat successful authentication as proof of identity. They assume that because someone passed MFA, they have verified who that person is. They may
- [CISA Red Team Fully Compromised Two Critical Infrastructure Orgs](https://cybernoz.com/cisa-red-team-fully-compromised-two-critical-infrastructure-orgs/) - CISA Red Team Fully Compromised Two Critical Infrastructure Orgs Pierluigi Paganini August 26, 2026 CISA red teams fully compromised two critical infrastructure orgs. One SOC isolated hosts in minutes; the other never detected the breach. CISA published an advisory (AA26-237A) documenting two simultaneous red team assessments at critical infrastructure organizations. Both organizations lost full domain
- [Officials disrupt Chinese espionage operation that hit multiple federal agencies](https://cybernoz.com/officials-disrupt-chinese-espionage-operation-that-hit-multiple-federal-agencies/) - Federal authorities Wednesday revealed a multi-layered Chinese state-sponsored espionage operation that’s targeted and compromised U.S. critical infrastructure, including multiple federal agencies, since 2018. Officials seized domains and unsealed an affidavit detailing how a Chinese government-funded front company assembled a botnet and complementary systems that allowed attackers to intrude highly sensitive networks. The FBI and Justice
- [US seizes Chinese hacking platforms targeting Nasa, Fed and Senate](https://cybernoz.com/us-seizes-chinese-hacking-platforms-targeting-nasa-fed-and-senate/) - The Justice Department and the FBI said on Wednesday that they seized two Chinese state-sponsored online platforms that targeted US critical infrastructure and other critical networks, including Nasa, the Federal Reserve and the US Senate.According to court documents, the seizures involved a group known as “QTFY”, operated by China-based Nanjing Xinjiuwei Network Technology Co, which
- [Protect your Okta identities with Wiz](https://cybernoz.com/protect-your-okta-identities-with-wiz/) - Protecting identities in the cloud is paramount to ensuring the security and integrity of your data and resources. Misconfigured identities or identity-related risks can create an entry point into your cloud environment and even lead to lateral paths, and eventually your crown jewels. Such identity risks can put an environment at critical risk such as
- [Elastic Security at Black Hat 2026: Alert Zero and agentic SOC](https://cybernoz.com/elastic-security-at-black-hat-2026-alert-zero-and-agentic-soc/) - At Elastic, we know that the best way to build security tools is to bring them to the community, have security pros use them, and let them tell us what features and functionality matter and why. This year, we’re excited to do this at Black Hat and DEFCON, the weeklong security marathon affectionately known as
- [Critical Avada WordPress theme flaw enables zero-click RCE](https://cybernoz.com/critical-avada-wordpress-theme-flaw-enables-zero-click-rce/) - A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. The exploit chains six security issues into a zero-click attack. The flaws are collectively tracked as CVE-2026-18431 and received a 9.8 critical severity score. The attack comprises exploits for
- [Critical Next.js Vulnerabilities Enables Remote Code Execution Attacks](https://cybernoz.com/critical-next-js-vulnerabilities-enables-remote-code-execution-attacks/) - Two critical Next.js flaws allow unauthenticated remote code execution on Windows-hosted applications using the Image Optimization API to process AVIF images. The first flaw, tracked as CVE-2026-75604, affects Next.js applications that use either the Pages Router or the App Router without Cache Components. An attacker may exploit the issue when the affected application runs on
- [WhatsApp Introduces Multi-Passkey and Complex 2FA Upgrades ](https://cybernoz.com/whatsapp-introduces-multi-passkey-and-complex-2fa-upgrades/) - Cross-Platform Passkey Integration Meta revealed a major security upgrade for WhatsApp on August 25, 2026, which increases passkey support and enables users to create numerous passkeys for a single account. Previously, WhatsApp supported a single passkey per account. People who use both iOS and Android devices may now generate and save unique, biometric-backed passkeys for
- [FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure](https://cybernoz.com/fbi-disrupts-chinese-proxy-tools-used-in-mass-hacking-of-us-agencies-and-infrastructure/) - For years, China's military and intelligence agencies, which carry out hacking campaigns against targets around the globe, have grown increasingly reliant on a vast web of proxy devices that enable and obfuscate their targeting. Now the FBI has named and disrupted one key network of those proxies—and in doing so, revealed just how extensively the
- [Critical WatchGuard Agent Flaws Let Unauthenticated Attackers Execute Remote Code](https://cybernoz.com/critical-watchguard-agent-flaws-let-unauthenticated-attackers-execute-remote-code/) - WatchGuard has revealed two critical vulnerabilities in its Windows WatchGuard Agent, which could allow unauthenticated attackers to execute arbitrary code on affected endpoints. These vulnerabilities, tracked as CVE-2026-57910 and CVE-2026-57909, have CVSS v4.0 scores of 9.3 and 9.4, respectively. Both issues impact WatchGuard Agent versions earlier than 1.25.13.0000. If exploited, these vulnerabilities could give an
- [Bogus recruiters go after high-value corporate credentials on mobile](https://cybernoz.com/bogus-recruiters-go-after-high-value-corporate-credentials-on-mobile/) - Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on recruitment phishing. They scrape public profile data and use it to craft convincing scheduling flows designed
- [Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler](https://cybernoz.com/nimbus-manticore-expands-toolset-with-twostroke-like-backdoor-and-ssh-tunneler/) - Ravie LakshmananAug 26, 2026Malware / Cyber Espionage Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in
- [UK government set to adjudicate on ‘risky’ tech purchases](https://cybernoz.com/uk-government-set-to-adjudicate-on-risky-tech-purchases/) - The UK government intends to give itself new powers to step in if essential service providers, such as electricity and water suppliers or NHS bodies, propose to buy technology from suppliers with ties to hostile states that the authorities believe could seek to use them for cyber espionage or other forms of malicious activity, including
- [US says Chinese hackers broke into Justice Department, NASA, Federal Reserve, Senate](https://cybernoz.com/us-says-chinese-hackers-broke-into-justice-department-nasa-federal-reserve-senate/) - The United States said it ⁠had disrupted a Chinese hacking operation responsible for break-ins and attempts on the US Justice Department, NASA, the Federal Reserve, the Senate, and other sensitive government agencies. In a statement, the Justice Department said it had seized domains used by ‌two hacking platforms, dubbed QScan and QTRouter, which it said
- [CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks](https://cybernoz.com/cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks/) - The Cybersecurity and Infrastructure Security Agency (CISA) says it’s aware of 100 internet-exposed water systems targeted in cyberattacks in July. The information was shared as part of guidance released by CISA to help organizations reduce the internet exposure of systems that could be targeted by threat actors. “In July 2026, CISA observed malicious cyber activity
- [88 ID Verification Breaches Show the Cost of Collecting Identity Data](https://cybernoz.com/88-id-verification-breaches-show-the-cost-of-collecting-identity-data/) - 88 ID Verification Breaches Show the Cost of Collecting Identity Data Pierluigi Paganini August 26, 2026 88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or
- [Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure](https://cybernoz.com/cyber-threats-nudge-trump-to-sign-executive-order-on-foreign-equipment-in-u-s-energy-infrastructure/) - Citing cyber and other security threats, President Donald Trump signed an executive order Wednesday that declares a national emergency to secure the U.S. bulk-power system and aims to prohibit certain foreign-produced equipment, software and systems from being used in the country. The order says it forbids “any acquisition, importation, transfer, or installation” of such foreign-produced
- [Who is accountable when your AI agent goes rogue?](https://cybernoz.com/who-is-accountable-when-your-ai-agent-goes-rogue/) - Security teams must extend the same controls to the agent’s interactions with internal systems and agents. Restricting what it can access on the internet, or disabling internet access entirely, does not ensure an agent will not attack third-party systems. In OpenAI’s and Anthropic’s tests, AI agents attempted to exploit other internal systems to overcome access
- [US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate](https://cybernoz.com/us-seizes-domains-of-chinese-botnet-used-to-hack-nasa-justice-department-and-the-senate/) - The FBI has seized a series of domains that were used by a large-scale botnet to coordinate and launch China-backed cyberattacks against American targets. According to the Justice Department’s statement on Wednesday, the seizures of the botnet’s domains deny the operators access to the platforms. The botnet was allegedly used by the Chinese government to
- [DOJ, FBI seize China-linked QScan and QTRouter platforms used to target US critical infrastructure](https://cybernoz.com/doj-fbi-seize-china-linked-qscan-and-qtrouter-platforms-used-to-target-us-critical-infrastructure/) - The U.S. Department of Justice (DOJ) and Federal Bureau of Investigation (FBI) seized two hacking platforms used by a China state-sponsored group to target U.S. critical infrastructure and other sensitive networks. The court-authorized seizures targeted QScan and QTRouter, platforms operated by QTFY, a China-based group employed by Nanjing Xinjiuwei Network Technology Company. Victims of QTFY
- [Cloud and AI Cost Attribution with the Wiz Service Catalog](https://cybernoz.com/cloud-and-ai-cost-attribution-with-the-wiz-service-catalog/) - When you look at a cloud bill, you are looking at the combined output of decisions made by developers, platform engineers, and SREs across your organization. With the rapid adoption of generative AI workloads, developers also directly drive model inference, token usage, and dynamic resource consumption. Because engineering choices directly dictate cloud and AI spend,
- [SOC case management and detection rule history](https://cybernoz.com/soc-case-management-and-detection-rule-history/) - Elastic Security now tracks every change to a detection rule and lets you roll back to any previous version with one click. The same history log gives compliance teams a timestamped audit trail that's immutable and append-only. Case data is queryable across 3 global indices (down from 12 per space), so SOC managers can build
- [New GPUThor attack defeats NVIDIA ECC protection for root access](https://cybernoz.com/new-gputhor-attack-defeats-nvidia-ecc-protection-for-root-access/) - A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. In a paper published by the University of Toronto, researchers say that GPUThor achieves far more practical bit-flip rates than past concepts like their own GPUHammer or GPUBreach, which became irrelevant after
- [21 Critical Ubiquiti UniFi Flaws Enable Authentication Bypass, Command Injection and Privilege Escalation](https://cybernoz.com/21-critical-ubiquiti-unifi-flaws-enable-authentication-bypass-command-injection-and-privilege-escalation/) - Ubiquiti has patched 21 critical-severity vulnerabilities spanning nearly its entire UniFi product line, warning that attackers with only network access could chain the flaws to bypass authentication, inject commands, and seize full control of routers, cameras, access-control systems, and cloud gateways. The disclosures, tracked under a fresh batch, arrive months after Ubiquiti’s earlier Security Advisory
- [Shrinking Patch Windows, Quantum Risk And Rogue AI Agents: The Three Threats Collapsing Modern Security Assumptions](https://cybernoz.com/shrinking-patch-windows-quantum-risk-and-rogue-ai-agents-the-three-threats-collapsing-modern-security-assumptions/) - Security teams are entering a period where many of the assumptions that shaped modern cybersecurity programs no longer hold the way they once did. Until recently, the security industry has largely abided by the same MO: vulnerabilities would gradually emerge, defenders would have some time to respond, encryption standards could be trusted to remain effective
- [Why Provision 29 is raising the bar for board accountability](https://cybernoz.com/why-provision-29-is-raising-the-bar-for-board-accountability/) - By Tim Williams, CEO at Quod Orbis Under the 2024 UK Corporate Governance Code, the revised Provision 29 requires boards to demonstrate that their material internal controls are working effectively. Every business has hundreds of controls, however material controls have the potential to create an immense operational, security or regulatory impact. The message behind this
- [OpenAI’s Hugging Face Hack Debrief Raises More Questions Than It Answers](https://cybernoz.com/openais-hugging-face-hack-debrief-raises-more-questions-than-it-answers/) - OpenAI published the most complete report to date on Wednesday about what happened when its AI agents hacked into Hugging Face last month. For the most part, though, the 37-page document raises more questions than it answers, including about what preceded the incident and how OpenAI can stop another one like it from happening again.What
- [Iran-Linked Hackers Use Reverse SSH Tunnels to Reach Deep Inside Compromised Networks](https://cybernoz.com/iran-linked-hackers-use-reverse-ssh-tunnels-to-reach-deep-inside-compromised-networks/) - Iran-linked threat actor Tortoiseshell is expanding its espionage toolkit with reverse SSH tunneling utilities and a TWOSTROKE-like backdoor designed to give operators covert, durable access to compromised internal networks. The research began with public reporting from Kaspersky on Mirage Kitten’s newer malware ecosystem, which included the NightLedger backdoor and WebSocket tunneling tools ArcBridge and BridgeHead.
- [Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)](https://cybernoz.com/critical-gitea-vulnerability-now-exploited-in-the-wild-cve-2026-60004/) - Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details about the attacks, but according to an incident report published by a professed full-stack developer
- [Popular school apps may be sharing student data with advertisers](https://cybernoz.com/popular-school-apps-may-be-sharing-student-data-with-advertisers/) - A two-year investigation into educational technology (EdTech) apps used by Utah schools found that many were collecting and sharing student data in ways that appeared inconsistent with their privacy commitments. EdTech is a massive commercial industry and some argue that it functions much like traditional big tech by prioritizing profits, scalable software, and user data
- [FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations](https://cybernoz.com/fbi-disrupts-china-linked-qtfy-infrastructure-used-to-steal-data-from-u-s-organizations/) - The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company
- [AI Speeds Up Malware Development, Not Its Success Rate: Analysis](https://cybernoz.com/ai-speeds-up-malware-development-not-its-success-rate-analysis/) - Palo Alto Networks’ Unit 42 team analyzed 405 malware samples tied to AI in some way, from ransomware partly written with the help of LLMs to installers that simply borrowed the name of a popular AI app. The researchers found that roughly 97% of the samples in the dataset never left a sandbox, research repository,
- [FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure](https://cybernoz.com/fbi-seizes-china-linked-hacking-platforms-qscan-and-qtrouter-used-against-critical-infrastructure/) - FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure Pierluigi Paganini August 26, 2026 FBI seizes QScan and QTRouter, China-linked platforms used to hide intrusions and target U.S. critical infrastructure. The U.S. Department of Justice and the FBI have seized two platforms, QScan and QTRouter, used by a China-linked group to hide
- [Boston Scientific says cyberattack disrupted order processing, shipping](https://cybernoz.com/boston-scientific-says-cyberattack-disrupted-order-processing-shipping/) - The medical device-maker says it cannot yet determine any financial impact from the attack it suffered this week. Source link
- [Election official says Tina Peters would be consultant, won’t have access to election systems](https://cybernoz.com/election-official-says-tina-peters-would-be-consultant-wont-have-access-to-election-systems/) - The top election official for Shasta County, Calif. said he has offered convicted felon and former Mesa County, Colo. clerk Tina Peters a position as a consultant to help with the 2026 elections, but that she hasn’t accepted the position yet. Earlier this month, Shasta County registrar Clint Curtis told local news outlets that he
- [Microsoft warns patch window is collapsing, urges shift to network-level containment](https://cybernoz.com/microsoft-warns-patch-window-is-collapsing-urges-shift-to-network-level-containment/) - Microsoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation faster than enterprises can safely deploy fixes, and is urging organizations to adopt network-level controls to limit exposure during that gap. In a blog post, Igor Sakhnov, corporate vice president and general manager for Azure Networking
- [Report Recap: State of Cloud Risk 2026](https://cybernoz.com/report-recap-state-of-cloud-risk-2026/) - Today, Wiz Research is releasing The State of Cloud Security Risk 2026. In it, we explore how cloud risk is being heavily influenced by two converging trends: expanding attack surfaces and shrinking response windows.To keep pace, defenders must shift from chasing raw alert volume to prioritizing deep environmental context, unlocking the precise insights needed to
- [The Evolution of Hacktivism in Hybrid Warfare: Modern Tactics and Real-World Impact](https://cybernoz.com/the-evolution-of-hacktivism-in-hybrid-warfare-modern-tactics-and-real-world-impact/) - Hacktivism used to be perceived as digital graffiti, with lone-wolf threat actors defacing government websites or temporarily crashing banking portals to make a political point. However, Flashpoint is tracking a fundamental shift in how these groups operate. Modern hacktivism is evolving into a disciplined component of global hybrid warfare, capable of bridging digital disruptions with
- [Beyond Patching: What IT Teams Need to Know About Unpatchable Exposures](https://cybernoz.com/beyond-patching-what-it-teams-need-to-know-about-unpatchable-exposures/) - Executive Summary Most IT teams still operate under a false binary: patch or accept risk. That assumption creates unnecessary operational pressure. Patchless remediation is real and production-proven. Mitigate, Uninstall, Run Custom Scripts, Isolate; close exposure when no reliable patch exists. Same-day exposure neutralization becomes possible for CISA KEV items without emergency change control or restart
- [Boston Scientific says cyberattack disrupted operations globally](https://cybernoz.com/boston-scientific-says-cyberattack-disrupted-operations-globally/) - Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. The company detected the incident on August 25 and says in an announcement today that it caused a network outage and "impacted access to certain operating systems and business applications, including the ability to process
- [OpenAI Bans Russia-Linked ChatGPT Accounts Used in Covert Influence Campaign](https://cybernoz.com/openai-bans-russia-linked-chatgpt-accounts-used-in-covert-influence-campaign/) - OpenAI has removed a cluster of ChatGPT accounts linked to a covert influence operation from Russia. The accounts produced social-media posts and replies designed to steer people toward the International Burke Institute, or IBI, a purported Israeli expert community. The campaign did not depend on malicious software or an exploit. It used generative AI to
- [Huntress Uncovers Five Cases of North Korean Operatives Posing as Remote IT, Sales and Healthcare Workers](https://cybernoz.com/huntress-uncovers-five-cases-of-north-korean-operatives-posing-as-remote-it-sales-and-healthcare-workers/) - Cybersecurity firm Huntress has confirmed five separate incidents this year in which suspected North Korean operatives were successfully hired into legitimate organisations under false identities, in a wave of activity researchers say shows how the country’s so-called “remote IT worker” scheme has expanded well beyond IT roles. The cases, disclosed in a new advisory, involved
- [Russia-Linked Operators Used ChatGPT to Run a Secretive Online Influence Campaign](https://cybernoz.com/russia-linked-operators-used-chatgpt-to-run-a-secretive-online-influence-campaign/) - OpenAI has disrupted a covert influence operation that used ChatGPT to promote a purported Israeli think tank, spread Russia-favorable narratives, and manufacture the appearance of academic legitimacy across major social platforms. The company banned a cluster of accounts it assessed as very likely originating in Russia after tracing AI-generated posts to a broader network built
- [Clover: Building the Future of Product Security](https://cybernoz.com/clover-building-the-future-of-product-security/) - Clover Security is on a mission to enable both humans and AI to build secure-by-design software, at scale, without slowing down innovation. The startup, founded in 2023, with offices in Tel Aviv and New York City, empowers product security teams with design-led AI agents that plug into the tools they already use, enabling secure design, secure
- [AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes](https://cybernoz.com/anonymouskit-phishing-as-a-service-uses-ai-voice-calls-to-steal-iphone-passcodes/) - A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation unraveled a reseller supply chain of 506 domains and 168 storefront brands active since early 2024.
- [Update Chrome before you browse again](https://cybernoz.com/update-chrome-before-you-browse-again/) - Chrome is rolling out an update for its desktop browser. The update includes 327 security fixes, ten of which address critical vulnerabilities. The stable channel has been updated to 152.0.7977.64/.65 for Windows and Mac, and 152.0.7977.64 for Linux. How to update Chrome If you don’t want to wait for the rollout to reach you, manually updating is easy.
- [Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code](https://cybernoz.com/unpatched-kaltura-mwembed-flaws-could-let-remote-attackers-read-files-and-run-code/) - The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed
- [AI-Powered Cyber Defense: Cyble, DRONA Join Forces](https://cybernoz.com/ai-powered-cyber-defense-cyble-drona-join-forces/) - AHMEDABAD (INDIA) — Cyble, the global AI-native cybersecurity company, and DRONA Cyber Solutions, the Ahmedabad-headquartered security operations firm, have launched an AI-powered cyber defense initiative in Ahmedabad, combining threat intelligence, investigation and endpoint enforcement through a joint managed security model. The AI-Powered Intelligence for Cyber Defense initiative was formally launched Tuesday at DRONA Cyber Solutions’
- [New NASA telescope to probe dark energy, dark matter and exoplanets](https://cybernoz.com/new-nasa-telescope-to-probe-dark-energy-dark-matter-and-exoplanets/) - Key points NASA plans to launch the roughly US$4 billion Nancy Grace Roman Space Telescope on Sunday from Kennedy Space Center aboard a SpaceX Falcon Heavy rocket, nine months ahead of schedule. The telescope's main survey will take more than a year and aims to unlock the fundamental nature of dark matter and dark energy
- [Adobe and Nvidia Patch Dozens of Vulnerabilities](https://cybernoz.com/adobe-and-nvidia-patch-dozens-of-vulnerabilities/) - Adobe and Nvidia on Tuesday announced patches for dozens of vulnerabilities affecting their products, including flaws rated critical severity. Nvidia Nvidia published four new advisories on Tuesday. One advisory alerts customers to 18 security vulnerabilities in NemoClaw and OpenShell, enterprise AI security and runtime infrastructure products designed to wrap around autonomous AI agents. Two of
- [U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog](https://cybernoz.com/u-s-cisa-adds-gitea-flaw-to-its-known-exploited-vulnerabilities-catalog/) - U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog Pierluigi Paganini August 26, 2026 U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS
- [Treasury to help financial firms transition to quantum-resistant encryption](https://cybernoz.com/treasury-to-help-financial-firms-transition-to-quantum-resistant-encryption/) - The government is concerned that hackers someday will be able to decrypt financial information and other secrets using code-breaking quantum computers. Source link
- [NemoClaw’s AI can be poisoned through a browser tab](https://cybernoz.com/nemoclaws-ai-can-be-poisoned-through-a-browser-tab/) - The problem starts with networking. Because the OpenShell sandbox runs inside a Docker container, it cannot reach an Ollama service listening only on the loopback address, 127.0.0.1. NemoClaw therefore starts Ollama with “OLLAMA_HOST=0.0.0.0:11434,” making it listen on all network interfaces. That solves the container connectivity problem but also disables an important Ollama protection. Ollama’s API
- [Gurobi, Carahsoft partner to expand decision intelligence technology access across US public sector](https://cybernoz.com/gurobi-carahsoft-partner-to-expand-decision-intelligence-technology-access-across-us-public-sector/) - Gurobi Optimization, vendor of decision intelligence technology, and Carahsoft Technology Corp. announced a partnership on Tuesday. Under the agreement, Carahsoft will serve as Gurobi’s Master Government Aggregator, making the company’s optimization solutions available to the public sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, Information Technology Enterprise Solutions – Software
- [Building a Text-to-Query Engine for Wiz's Security Graph](https://cybernoz.com/building-a-text-to-query-engine-for-wizs-security-graph/) - In this blog post, we take you through our journey of developing a user-friendly text-to-query search engine for Wiz's Security Graph. We’ll discuss the challenges we faced and the innovative solutions we implemented to make complex cybersecurity data accessible to everyone. Whether you're a tech enthusiast or new to the field, we break it down
- [Massive DDoS attack disrupts Norway’s government digital services](https://cybernoz.com/massive-ddos-attack-disrupts-norways-government-digital-services/) - A large distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, affecting services used by the public sector. The attack started at 03.38 CEST on Monday and has targeted the infrastructure supporting services operated by the Norwegian Digitalization Agency, Digitaliseringsdirektoratet (Digdir), and its operations provider, Vivicta. Digdir operates Norway’s shared digital
- [Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access](https://cybernoz.com/hackers-abuse-legitimate-rmm-tools-in-46-country-phishing-campaign-to-gain-remote-access/) - A phishing operation is abusing legitimate remote monitoring and management tools to give attackers direct control over victim systems. The campaign uses convincing document lures, rapidly changing hosting infrastructure, and signed software that can blend into normal IT activity. A phishing campaign is turning familiar support software into a direct route into corporate systems. Rather
- [NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding](https://cybernoz.com/nvidia-nemoclaw-vulnerability-lets-attackers-hijack-ai-agents-via-dns-rebinding/) - The 0.0.0.0 binding also introduces a separate LAN exposure risk: other devices on the same network segment could directly access Ollama without needing DNS rebinding. The researchers reported this issue to NVIDIA’s Product Security Incident Response Team before publication. Organizations using NemoClaw with local Ollama inference should review exposed interfaces, restrict access to port 11434,
- [Meta adds three new features to keep WhatsApp accounts secure](https://cybernoz.com/meta-adds-three-new-features-to-keep-whatsapp-accounts-secure/) - Meta has added new security enhancements to WhatsApp, this time in the form of stronger two-step verification, additional information about calls from unknown numbers, and the ability to add multiple passkeys to the same account. New account security features (Source: Meta) “On WhatsApp, your conversations belong only to you and the people you’re talking to.
- [Beware of fake Indeed interview apps used to install spyware](https://cybernoz.com/beware-of-fake-indeed-interview-apps-used-to-install-spyware/) - From several independent reports, we’ve seen evidence of scammers using fake Android “interview” apps to target job seekers on the Indeed platform.Indeed is one of the world’s largest employment websites, giving scammers access to a huge pool of potential victims, especially in a competitive job market.What we foundA user in the UK posted on our
- [INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown](https://cybernoz.com/interpol-operation-jackal-iv-arrests-58-identifies-263-in-global-cyber-fraud-crackdown/) - Ravie LakshmananAug 26, 2026Cybercrime / Online Scams An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks –
- [AI datacentres must provide proof, not promises](https://cybernoz.com/ai-datacentres-must-provide-proof-not-promises/) - Datacentres are now designated as critical infrastructure in the United States, the UK, the EU, China, and other countries. National AI training and inference capacity is viewed as vital to competitiveness and security, and has prompted governments to encourage AI infrastructure development. The industry has responded with a surge of project announcements that is straining
- [UK Ukraine AI Partnership Opens Avengers AI Labs Access](https://cybernoz.com/uk-ukraine-ai-partnership-opens-avengers-ai-labs-access/) - The UK Ukraine AI partnership will give Britain access to Ukraine’s Avengers AI Labs, bringing together Ukrainian battlefield experience, operational data and engineering expertise with the UK’s AI ecosystem. The agreement, signed by President Volodymyr Zelenskyy and Prime Minister Andy Burnham in Ukraine, will focus initially on defence and national security. Under the partnership, British
- [West African Organized Crime Groups Face Global Crackdown](https://cybernoz.com/west-african-organized-crime-groups-face-global-crackdown/) - An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions. The operation
- [NAB's CSO to move to ANZ Banking Group](https://cybernoz.com/nabs-cso-to-move-to-anz-banking-group/) - Key points Sandro Bucchianeri will leave NAB, where he has been group chief security officer for over five years, to join ANZ. He starts as ANZ's chief information security officer on November 11, reporting to Group CIO Donald Patra. Shane Ripley remains acting CISO at ANZ until Bucchianeri arrives, following Dr Maria Milosavljevic's retirement earlier
- [Sensitive Information Exposed in Nutex Health Data Breach](https://cybernoz.com/sensitive-information-exposed-in-nutex-health-data-breach/) - Houston-based healthcare management and operations company Nutex Health Inc. (NASDAQ: NUTX) has suffered a data breach that could involve sensitive information. Nutex Health is a healthcare services and operations company that operates micro-hospitals, specialty hospitals, and outpatient departments. The company revealed in an SEC filing this week that it recently detected unauthorized access to its
- [Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams](https://cybernoz.com/operation-jackal-58-arrests-expose-the-money-laundering-machine-behind-global-scams/) - Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams Pierluigi Paganini August 26, 2026 INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263
- [Interpol targets Black Axe’s illicit financial web in latest international sting](https://cybernoz.com/interpol-targets-black-axes-illicit-financial-web-in-latest-international-sting/) - An international law enforcement operation carried out against organized crime groups in West Africa resulted in 58 arrests and identified 263 suspects, Interpol announced Tuesday. The operation, known as Operation Jackal IV, aimed to disrupt money laundering, locate high-value targets, seize assets and support prosecutions tied to various Africa-based criminal groups, including Black Axe. Black
- [Fragmented cybersecurity defenses struggle to keep pace as AI boosts cyberattacks, cuts attacker breakout times](https://cybernoz.com/fragmented-cybersecurity-defenses-struggle-to-keep-pace-as-ai-boosts-cyberattacks-cuts-attacker-breakout-times/) - Cybersecurity defenses that operate as isolated functions can leave organizations with costly blind spots even as spending on security tools, personnel and monitoring increases, according to Tariq Alharbi, vice president of cybersecurity managed services at Saudi Information Technology Company (SITE). He observed that organizations often have security operations centers, incident response teams and threat intelligence
- [ARI urges Trump to designate AI as 'critical infrastructure' amid growing cyber risks across critical sectors](https://cybernoz.com/ari-urges-trump-to-designate-ai-as-critical-infrastructure-amid-growing-cyber-risks-across-critical-sectors/) - Americans for Responsible Innovation (ARI) released a report warning that the growing integration of artificial intelligence across health care, finance and manufacturing creates infrastructure vulnerabilities that could have sector-wide consequences if attacked. It identifies that voluntary corporate security measures are insufficient as reliance on AI expands across private and public sectors. Furthermore, the report recommends
- [Wiz Expands Runtime Protection to Serverless Containers](https://cybernoz.com/wiz-expands-runtime-protection-to-serverless-containers/) - Serverless containers are reshaping how developers build and deploy applications. By removing the need to manage the underlying infrastructure, serverless containers like AWS Fargate and Azure Container Apps (ACA) allow developers to focus on what they do best—writing code—while the cloud service provider takes care of the servers, scaling, and maintenance. This approach accelerates development
- [A Detection Engineer's Guide for Delegating Work to AI](https://cybernoz.com/a-detection-engineers-guide-for-delegating-work-to-ai/) - Detection rules fail in two directions: they can be too broad and create false positive alerts for the Security Operations Center (SOC) to triage, or they can be too precise and miss malicious activity. Either way, the fix starts by comparing what the rule matched against what actually happened.If an attacker uses a stolen Microsoft
- [Hackers abuse npm mirrors to host phishing redirect pages](https://cybernoz.com/hackers-abuse-npm-mirrors-to-host-phishing-redirect-pages/) - Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. The technique was previously spotted in July by security researcher inf0stache, who found a 'china_airlines' npm package that used a fake Cloudflare verification page to redirect visitors to a malicious domain, and was
- [Linux Turns 35 - Hobby Kernel Now Powers Cloud, Android, and Global Cyber Defense](https://cybernoz.com/linux-turns-35-hobby-kernel-now-powers-cloud-android-and-global-cyber-defense/) - On August 25, 1991, a 21-year-old University of Helsinki student posted a modest note to the Usenet group comp.os.minix. “I’m doing a (free) operating system (just a hobby, won’t be big and professional like gnu) for 386(486) AT clones,” Linus Torvalds wrote, adding that the project had been brewing since April and was starting to
- [Microsoft Teams Outage Disrupts Meetings and Screen Sharing for Users](https://cybernoz.com/microsoft-teams-outage-disrupts-meetings-and-screen-sharing-for-users/) - Organizations that depend on Teams as their default communication tool in emergencies should treat such incidents as continuity events. During a live service disruption, switching between desktop, web, and mobile clients, using an alternative conference bridge, or moving to a secondary messaging channel is usually more effective than implementing local policy changes. Microsoft 365 Status
- [Hottest cybersecurity open-source tools of the month: August 2026](https://cybernoz.com/hottest-cybersecurity-open-source-tools-of-the-month-august-2026/) - Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. SkillSpector: NVIDIA’s open-source security scanner for AI agent skills SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it
- [Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode](https://cybernoz.com/marimo-notebook-flaw-could-run-mcp-commands-before-cells-execute-in-edit-mode/) - Swati KhandelwalAug 25, 2026Vulnerability / AI Security Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local
- [Predictable costs, provable control drives data repatriation](https://cybernoz.com/predictable-costs-provable-control-drives-data-repatriation/) - As AI becomes the latest impost to drive up the cost of doing business, prudent Australian organisations reconsider what stays in public cloud and what returns home. Although hyperscalers can hike subscription prices at a whim, on-premises hardware is a single, upfront investment against which a business can budget for years, Neil Shan, managing director
- [WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update](https://cybernoz.com/whatsapp-adds-multiple-passkeys-and-stronger-2sv-in-account-security-update/) - WhatsApp on Tuesday announced several new features designed to enhance account security, including related to passkeys, two-step verification (2SV), and caller context. The Meta-owned messaging app says more than 1 billion individuals now rely on a passkey to log in to their WhatsApp accounts. Users can now add more than one passkey, which can be
- [Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable](https://cybernoz.com/two-cvss-9-8-auth-bypasses-in-miniorange-saml-wordpress-plugin-were-exploited-before-any-database-even-listed-the-paid-editions-as-vulnerable/) - Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable Pierluigi Paganini August 25, 2026 Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities
- [Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice](https://cybernoz.com/arrested-man-allegedly-impersonated-nsa-elite-hacking-unit-supreme-court-chief-justice/) - Colorado police arrested a man last week over charges that he impersonated both Supreme Court Chief Justice John Roberts and head of the National Security Agency’s famed Tailored Access Operations hacking unit. Joshua Culver, also known as “Maverick Young,” appeared in a Colorado court Tuesday after his arrest stemming from an indictment in Indiana in
- [How Equifax is using AI to elevate its cybersecurity](https://cybernoz.com/how-equifax-is-using-ai-to-elevate-its-cybersecurity/) - “We can use AI in that process as well,” Koppen says, noting how AI has helped Equifax perform code review earlier in the design process, ensuring adequate guardrails are built in and reducing the time that process takes. “It used to be 46 days and now we’re down to 18,” Koppen says. “It’s great to
- [Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS](https://cybernoz.com/fast-track-ism-ready-cloud-environments-and-irap-assessments-with-landing-zone-accelerator-on-aws/) - This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with Australian Government Information Security Manual (ISM) security controls coverage at scale. The report includes findings from an independent third-party analysis conducted
- [The patch window is collapsing: Why security needs a new control plane](https://cybernoz.com/the-patch-window-is-collapsing-why-security-needs-a-new-control-plane/) - For decades, cybersecurity defenders have relied on a relatively straightforward model: a vulnerability is disclosed, security teams assess exposure, test available fixes, deploy patches into production, and ultimately close the risk before attackers can exploit it at scale. That model increasingly reflects a world that no longer exists. Today’s enterprises operate thousands of interconnected workloads
- [New Partner View for Security Incident Investigations](https://cybernoz.com/new-partner-view-for-security-incident-investigations/) - For a long time, partners have told us the same thing: when an investigation was closed as benign, it was hard to know what actually happened behind the scenes. You might see that our Security Operations Center (SOC) looked at something and decided it was not a threat, but not much about why.That lack of
- [LACMA data breach last year exposed social security and medical data](https://cybernoz.com/lacma-data-breach-last-year-exposed-social-security-and-medical-data/) - The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. The museum says that on July 11, 2025, it detected suspicious activity on its systems that had started four days earlier. A month later, the investigation confirmed that the network was compromised. At the time,
- [SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams](https://cybernoz.com/synkloader-mimic-as-it-support-personnel-attacking-users-via-microsoft-teams/) - Once launched, the fake installer starts the loader and begins the next stage without relying on an email attachment. The delivery path can begin with either vishing or Teams messages, but both routes lead to the same deceptive installer. That pattern matters because staff may be trained to question email links yet treat Teams as
- [Shadow AI Is the New Shadow IT — And Policy Is Just the Starting Line](https://cybernoz.com/shadow-ai-is-the-new-shadow-it-and-policy-is-just-the-starting-line/) - Every few weeks I talk to a security leader who tells me they have shadow AI in progress. They wrote an acceptable use policy. They published a list of approved tools. They blocked the rest at the proxy and ran a training session on not pasting sensitive data into chatbots. And they will tell you,
- [Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud](https://cybernoz.com/scammers-impersonate-microsoft-to-push-fake-security-scans-and-refund-fraud/) - A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products, disclosing personal and banking information, and granting remote access to their computers. The sites, branded as SysScan, claim to assess whether an antivirus product is functioning properly. Their conclusion is predetermined: the victim’s computer is allegedly
- [Unpatched Zimbra servers are falling to CVE-2026-73570 attacks](https://cybernoz.com/unpatched-zimbra-servers-are-falling-to-cve-2026-73570-attacks/) - At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over their data or can’t afford a pricy alternative service like Microsoft 365 or Google
- [ToxicPanda 2.0 can take over your Android phone and banking apps](https://cybernoz.com/toxicpanda-2-0-can-take-over-your-android-phone-and-banking-apps/) - Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.” Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging
- [U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches](https://cybernoz.com/u-s-sanctions-iran-linked-hackers-behind-critical-infrastructure-breaches/) - The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this
- [FlyBuys reveals analysts' virtual assistant "Nex"](https://cybernoz.com/flybuys-reveals-analysts-virtual-assistant-nex/) - Key points Flybuys has launched Nex, a virtual assistant built on Snowflake's CoWork, to help marketing analysts make commercial recommendations. The data "pantry" built on Snowflake in AWS Sydney initially eased access to millions of daily transactions and signals, but this shifted the bottleneck to investigation, prompting the need for AI analytics. Linking Nex to
- [Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails](https://cybernoz.com/alice-raises-140m-to-expand-ai-model-defenses-and-enterprise-guardrails/) - AI trust, safety, and security company Alice announced on Tuesday that it raised $140 million in a funding round to secure AI systems against emerging vulnerabilities and adversarial attacks. The latest capital injection brings the firm’s total funding to $280 million, which will be used to further advance its AI platform, expand the team behind
- [Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack](https://cybernoz.com/norway-s-digital-government-infrastructure-hit-by-a-new-ddos-attack/) - Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack Pierluigi Paganini August 25, 2026 Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used
- [CISA orders agencies to fix exploited Zimbra vulnerability](https://cybernoz.com/cisa-orders-agencies-to-fix-exploited-zimbra-vulnerability/) - The collaboration software’s developer took almost a full month to patch the flaw after disclosing it. Source link
- [The GTA VI leaks are breaking the internet. Security researchers have seen this before.](https://cybernoz.com/the-gta-vi-leaks-are-breaking-the-internet-security-researchers-have-seen-this-before/) - Grand Theft Auto VI, widely heralded as the game event of the decade, took a significant hit last week after a cybercriminal sent much of the internet into pandemonium after publishing gameplay footage a week before the game’s publisher planned to reveal core portions of the game to the public. The files posted by the
- [Trump says China is driving anger at US data centres. These residents disagree](https://cybernoz.com/trump-says-china-is-driving-anger-at-us-data-centres-these-residents-disagree/) - On the tree-lined streets of Sterling, northern Virginia, Lindsay Shaw’s home sits across from an industrial neighbour that has consumed the past several years of her life: a data centre.When Shaw sits outside, she can hear its constant hum. At night, the security lights blaze through her window, making it harder to sleep. Gas turbines,
- [New attack lets hackers plant hidden instructions in AI memory with a single prompt](https://cybernoz.com/new-attack-lets-hackers-plant-hidden-instructions-in-ai-memory-with-a-single-prompt/) - The researchers said the method targets AI agents that store past interactions and reuse them during future tasks, enabling malicious content introduced during an initial exchange to persist and affect later outputs. The study evaluated the technique on a memory system called MemoryOS along with an agent framework, MemGPT, and tested it across several domains,
- [WhatsApp tightens account security with stronger two-step verification and more](https://cybernoz.com/whatsapp-tightens-account-security-with-stronger-two-step-verification-and-more/) - WhatsApp announced Tuesday that it’s launching new security features and updates to help users keep their accounts secure, including stronger two-step verification and the ability to add more than one passkey to your account. The Meta-owned app is also adding context to calls from unknown numbers. The updates come as WhatsApp and other messaging apps,
- [The essential steps for cloud vulnerability management](https://cybernoz.com/the-essential-steps-for-cloud-vulnerability-management/) - Vulnerability management in the cloud presents new challenges due to the dynamic and complex nature of cloud environments that require new tools and workflows. Without an integrated cloud-first approach to vulnerability management, most security practitioners find themselves under a constant barrage of vulnerability alerts that lack risk context and are challenging to triage. With the
- [AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes](https://cybernoz.com/anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-passcodes/) - A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. The illegal service has been active since early 2024 and is powering a structured ecosystem that sells stolen iPhones, harvests Apple IDs, accesses iCloud backups, and Keychain credentials. Researchers at
- [CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps](https://cybernoz.com/cisa-red-team-breaches-critical-infrastructure-to-reveal-soc-and-cloud-security-gaps/) - CISA’s latest advisory for red teams warns critical infrastructure operators that security systems can fail even if they have a lot of funding. This is because trained analysts are needed to respond to alerts effectively. The agency’s “A Tale of Two SOCs” report compares two parallel red team engagements: one against a Government Services and
- [HKCERT Issues High-Risk Advisory for Zimbra Collaboration Suite Flaws](https://cybernoz.com/hkcert-issues-high-risk-advisory-for-zimbra-collaboration-suite-flaws/) - Carmen EstelaCyber Defense MagazineAugust 24, 2026 HKCERT Bulletin Overview On August 24, 2026, the Hong Kong Computer Emergency Response Team Coordination Center (HKCERT) published security notice S26-0824-01, warning businesses of a number of Zimbra Collaboration Suite vulnerabilities. CVE-2026-10631, CVE-2026-50054, CVE-2026-50055, and CVE-2026-73570 were the four different tracking IDs that were addressed in the alert. Because
- [Iran-Linked Hackers Blamed for UK Energy Cyberattack](https://cybernoz.com/iran-linked-hackers-blamed-for-uk-energy-cyberattack/) - A cyberattack reportedly linked to Iran forced a small UK energy generator offline for four days, raising fresh concerns about the security of the country’s critical infrastructure and smaller operators that may sit outside existing regulatory thresholds. The UK government has confirmed that a small-scale generator was affected by a cyber incident in July. It
- [Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records](https://cybernoz.com/multi-agent-ai-framework-compromises-government-systems-and-steals-thousands-of-records/) - A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities in Asia, stealing thousands of personnel records, cracking employee credentials, and establishing persistent access to state infrastructure, according to Dream Research Labs. Researchers discovered a 160 MB operational archive containing 1,395 files generated over about 4 days of activity, from
- [Fake OpenAI Codex download tricks macOS users into installing malware](https://cybernoz.com/fake-openai-codex-download-tricks-macos-users-into-installing-malware/) - A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. It’s a variation of ClickFix, a popular social engineering technique that persuades victims to execute the infection step themselves rather than opening a
- [GTA 6 leak hunt could expose data belonging to thousands of Discord users](https://cybernoz.com/gta-6-leak-hunt-could-expose-data-belonging-to-thousands-of-discord-users/) - Someone leaked footage of the upcoming game Grand Theft Auto (GTA) 6 this month, and the game’s publisher badly wants to know who. It’s after a range of data about members of three Discord servers going back to June 1 this year in a bid to nail the perpetrator. Take-Two Interactive, the publisher behind the
- [A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw](https://cybernoz.com/a-malicious-webpage-could-poison-your-local-ai-model-behind-nvidia-nemoclaw/) - Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to
- [US Treasury sets up quantum readiness unit](https://cybernoz.com/us-treasury-sets-up-quantum-readiness-unit/) - The United States Department of the Treasury has officially launched a Quantum Readiness Task Force, supporting wider efforts to secure innovation, strengthen supply chains, and ensure the US remains a leading voice at the post-quantum table. The new unit fulfils a key obligation imposed by president Trump in an Executive Order (EO), Securing The Nation
- [Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation](https://cybernoz.com/linux-foundation-to-govern-trace-an-open-standard-for-ai-runtime-attestation/) - The Linux Foundation said Tuesday it will take on governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), a new open specification for producing verifiable evidence of how AI agents and other confidential workloads run. Contributed by confidential computing vendor OPAQUE, the specification was developed jointly with AMD, Intel, Microsoft, and the Technology Innovation Institute
- [When the Algorithm Fires You: Uber Faces €825M Fine](https://cybernoz.com/when-the-algorithm-fires-you-uber-faces-e825m-fine/) - When the Algorithm Fires You: Uber Faces €825M Fine Pierluigi Paganini August 25, 2026 Uber faces an €825M GDPR fine for automatically suspending drivers without human review, highlighting the risks of AI decisions affecting workers. The Dutch Data Protection Authority handed Uber its largest privacy fine yet, and this one isn’t about data transfers or
- [Researchers warn about chained SharePoint sequence](https://cybernoz.com/researchers-warn-about-chained-sharepoint-sequence/) - An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks. Source link
- [Water sector passes, government sector fails attempts to spot and halt simulated CISA attack](https://cybernoz.com/water-sector-passes-government-sector-fails-attempts-to-spot-and-halt-simulated-cisa-attack/) - When the Cybersecurity and Infrastructure Security Agency tested defenses for two targets — one in the government sector and the other in the water sector — red teamers were able to get into both of their systems, but the water organization discovered the simulated attack and acted to defend itself, whereas the government organization did
- [Nucleus wants to get ahead of scanners on new vulnerabilities](https://cybernoz.com/nucleus-wants-to-get-ahead-of-scanners-on-new-vulnerabilities/) - Today, Kuffer said, the agent’s role is primarily research and reasoning. It can search and investigate exposure data, explain vulnerabilities, surface remediation guidance, create queries, and help build dashboards and automations, he added. For production processes, the Helix agent can effectively “write the code” of the Nucleus platform through its interface, letting the Automation engine
- [That fake Grand Theft Auto VI demo is actually just malware](https://cybernoz.com/that-fake-grand-theft-auto-vi-demo-is-actually-just-malware/) - In the long wait for the highly anticipated Grand Theft Auto VI, an open-world game about crime, some in the gaming community are being targeted by cybercriminals in the real world. Fans are still waiting for the game more than a decade after the release of GTA 5, which sold more copies than any game
- [NTT DATA, Palo Alto Networks sign global strategic alliance to boost secure AI transformation](https://cybernoz.com/ntt-data-palo-alto-networks-sign-global-strategic-alliance-to-boost-secure-ai-transformation/) - NTT DATA, vendor of AI, digital business and technology services, and Palo Alto Networks announced a multi-year strategic alliance designed to help organizations securely adopt AI, modernize cybersecurity, simplify complex technology environments and build cyber resilience for the AI era. As Palo Alto Networks initial strategic alliance of this kind with a global systems integrator,
- [CYFIRMA reports telecom sector faces high cyber risk as China, Russia-linked APT campaigns intensify](https://cybernoz.com/cyfirma-reports-telecom-sector-faces-high-cyber-risk-as-china-russia-linked-apt-campaigns-intensify/) - New data from CYFIRMA rated telecommunications and media sector’s external cyber threat landscape as high, citing sustained activity from advanced persistent threat actors, cyber incidents, dark web activity and vulnerabilities. In a report published Aug. 23, the cybersecurity firm said telecommunications and media organizations appeared in 25 of 70 observed APT campaigns, or 36%, up
- [Supply Chain Attack Targets JavaScript’s Lottie-Player](https://cybernoz.com/supply-chain-attack-targets-javascripts-lottie-player/) - On October 30, 2024, a supply chain attack was initiated against the popular JavaScript library lottie-player, injecting malicious code that populates a Web3 wallet connection prompt on legitimate websites using the library, potentially targeting prominent cryptocurrency platforms and other high-traffic websites. The compromised versions of lottie-player were later removed from major CDNs and npm, but
- [Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense](https://cybernoz.com/mexicos-cybersecurity-plan-2025-2030-turning-ambition-into-defense/) - Mexico faces an increasingly complex cyber threat landscape, including ransomware, state-sponsored espionage, financial malware, data breaches, hacktivism, and cyber-enabled organized crime. Its 2025–2030 National Cybersecurity Plan seeks to address these challenges through stronger governance, new legislation, a national operations center, integrated incident-response teams, cyber exercises, AI-enabled defenses, and expanded regional cooperation. Insikt Group assesses ransomware
- [5 Modern Threats You Need to Watch](https://cybernoz.com/5-modern-threats-you-need-to-watch/) - More tools. More alerts. More late nights.And yet, the incidents that keep blowing up your week rarely start with some flashy, sophisticated exploit. They start with a login that "looks fine," a remote tool your team already trusts, or a user who thinks they're just pasting a command to "fix" their browser.This post walks through
- [Hospital operator Nutex Health says data stolen in cyberattack](https://cybernoz.com/hospital-operator-nutex-health-says-data-stolen-in-cyberattack/) - Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. The organization has disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission (SEC), noting that the stolen data includes details that may be private or confidential. “Based on preliminary findings from
- [AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge](https://cybernoz.com/ai-security-startup-alice-raises-140-million-as-enterprise-ai-threats-surge/) - Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a $140 million funding round led by Apax Digital Funds, with new backing from SentinelOne, Samsung Electronics, Maj Invest, MoreTech, and Phoenix Insurance, alongside existing investors Resolute Ventures, Grove Ventures, CRV, Highland Europe, Vintage Investment Partners, Norwest, NFX, and Claltech. The
- [What's in a tag name? JavaScript, apparently](https://cybernoz.com/whats-in-a-tag-name-javascript-apparently/) - I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with "a-zA-Z", but what about after that? I t Source link
- [Check Point Threat Brief: Critical Infrastructure Breaches and Emerging AI Attack Surfaces](https://cybernoz.com/check-point-threat-brief-critical-infrastructure-breaches-and-emerging-ai-attack-surfaces/) - Widespread Infrastructure Breaches and Novel AI Threats Several significant security breaches and new exploitation patterns are highlighted in the Check Point Research threat bulletin, which was released on August 24, 2026. The Road Traffic Safety Directorate (CSDD) in Latvia, which reported a significant data breach impacting payment details for more than 1.2 million people and
- [The County Prosecutors Who Became ICE Informants](https://cybernoz.com/the-county-prosecutors-who-became-ice-informants/) - This story was produced in partnership with Injustice Watch, a nonprofit newsroom in Chicago focused on the court system.Rolando Perez Samayoa had come to the US in 2023 seeking safety. Fleeing violence in Mexico, he’d first planned to make a life in Alabama but had been told that Illinois would protect immigrants like him. “There’s
- [AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands](https://cybernoz.com/ai-assisted-toxnetv2-linux-botnet-uses-llm-to-generate-shell-and-ssh-commands/) - ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into proposed operational actions. The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 model output to controller-side functions including local shell execution, file writes, remote SSH commands, persistent state changes, and cross-compilation. Analysis published by Joe Reverser
- [The Security Poverty Line: Fireside Chat At Black Hat USA 2026](https://cybernoz.com/the-security-poverty-line-fireside-chat-at-black-hat-usa-2026/) - In 2011, when Wendy Nather was at 451 Research, she coined the term Security Poverty Line, the line below which an organization cannot be effectively secured. The arrival of agentic AI is the most consequential shift in cybersecurity since the cloud, and it has put the poverty line under more pressure than at any point in history. At Black Hat
- [INTERPOL crackdown on West African crime rings uncovers troubling new trend](https://cybernoz.com/interpol-crackdown-on-west-african-crime-rings-uncovers-troubling-new-trend/) - Police across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups. Suspects detained in an operation targeting West African crime groups (Source: INTERPOL) Operation Jackal IV ran from November 2025 to June 2026. The goal was to disrupt money laundering, flag high-value targets, seize
- [Grok fooled into stealing user chat, location data, and more](https://cybernoz.com/grok-fooled-into-stealing-user-chat-location-data-and-more/) - A new type of prompt injection attack shows why giving AI assistants access to browsers, code tools, and private data deserves extra caution. AI researchers describe “Cryptographic Context Injection”—an attack that hides malicious instructions inside encrypted data. The AI is then persuaded to decrypt that data using its own code-execution tool. As a result, the
- [WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android](https://cybernoz.com/whatsapp-adds-multiple-passkeys-for-phishing-resistant-sign-ins-across-ios-and-android/) - Ravie LakshmananAug 25, 2026Authentication / Password Security Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a
- [UK fintech investment plummets over past six months](https://cybernoz.com/uk-fintech-investment-plummets-over-past-six-months/) - Investment in UK financial technology (fintech) firms dropped by two-thirds in the first six months of this year, hitting its lowest level for 10 years. According to KPMG’s latest Pulse of Fintech report, investment was £1.8bn in the period compared to £5bn during the same half year in 2025. There were 205 deals in the
- [Operation Economic Outcast Targets Iran With New Sanctions](https://cybernoz.com/operation-economic-outcast-targets-iran-with-new-sanctions/) - The U.S. Department of the Treasury has launched Operation Economic Outcast, a whole-of-government campaign aimed at disrupting the economic networks and revenue channels supporting the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC). The initiative expands Iran sanctions across digital assets, technology, gold, aviation and shipping, while targeting nearly 60 entities, individuals and vessels
- [Feds and telcos tell customers 000 camp-on delays can last up to a minute](https://cybernoz.com/feds-and-telcos-tell-customers-000-camp-on-delays-can-last-up-to-a-minute/) - Key points Optus, Telstra and TPG Telecom will launch a public campaign this week telling Australians to stay on the line for up to 60 seconds if a triple zero call doesn't instantly connect via another network. The campaign responds to a key finding of Dr Kerry Schott's review into Optus' September 2025 triple zero
- [WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities](https://cybernoz.com/wordpress-websites-targeted-via-miniorange-plugin-vulnerabilities/) - Threat actors have been attempting to hack WordPress websites by exploiting two recently patched vulnerabilities affecting a MiniOrange plugin. The two vulnerabilities are CVE-2026-61979 and CVE-2026-15981, and they affect the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin, which enables SSO for WordPress websites. The free edition of the plugin is installed on more than 10,000
- [U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog](https://cybernoz.com/u-s-cisa-adds-maximum-severity-oracle-flaw-to-its-known-exploited-vulnerabilities-catalog/) - U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog Pierluigi Paganini August 25, 2026 U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962
- [AI helps Chinese-speaking hackers speed up attacks on exposed servers](https://cybernoz.com/ai-helps-chinese-speaking-hackers-speed-up-attacks-on-exposed-servers/) - A Chinese-speaking cybercrime group is using AI-driven tools to help compromise internet-facing Windows and Linux web servers, according to Cisco Talos, Cisco’s threat intelligence research unit. Talos said the activity points to increasingly automated offensive operations. Talos, which tracks the group as UAT-10147, found evidence that AI-generated operational guidance had been used during an intrusion.
- [Top GenAI Security Risks and Best Practices](https://cybernoz.com/top-genai-security-risks-and-best-practices/) - As we approach the spookiest season of the year, it’s essential to ensure that your organization's embrace of Generative AI (GenAI) doesn’t open the door to cyber threats that lurk in the shadows. The rise of AI technologies has brought exciting advancements, but with these innovations come unique security risks that need to be managed
- [Every Ransomware Attack Has a Backstory](https://cybernoz.com/every-ransomware-attack-has-a-backstory/) - Ransomware is the part of the attack that gets the most attention.It's the locked screens, the ransom note, the disrupted workflows, the scramble to figure out what happened, and the public headlines that follow.But by the time attackers make their big move, the real story usually started much earlier.When we only focus on the ending,
- [Police arrests dozens of suspects in global cybercrime crackdown](https://cybernoz.com/police-arrests-dozens-of-suspects-in-global-cybercrime-crackdown/) - Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. The "Operation Jackal IV" international joint action targeted West African criminal networks between November 2025 and June 2026. The operation also focused on disrupting the Black Axe cybercrime syndicate, known for its
- [EvilTokens Doesn’t Just Steal Microsoft Sessions—Its AI Tells Attackers Who to Scam Next](https://cybernoz.com/eviltokens-doesnt-just-steal-microsoft-sessions-its-ai-tells-attackers-who-to-scam-next/) - EvilTokens is pushing phishing beyond the moment a victim clicks a link. The service steals Microsoft 365 session access, then examines the compromised mailbox to help criminals choose the contacts, payments, and conversations most likely to produce fraud. Unlike a conventional credential-stealing kit, the operation uses a real Microsoft sign-in process. A lure sends the
- [91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain](https://cybernoz.com/91-spring-cves-impact-over-209000-software-components-across-the-supply-chain/) - Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply chain remediation event that Sonatype estimates impacts 209,569 software components. The advisory issued on August 20 highlights the widening gap between AI-accelerated vulnerability discovery and organizations’ ability to identify, fix, rebuild, and deploy affected software.
- [ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack](https://cybernoz.com/shinyhunters-taunts-reliaquest-after-its-own-employee-falls-for-social-engineering-attack/) - Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group ShinyHunters posted screenshots on its leak site, claiming a bigger win. The incident was preceded by an unusual
- [TikTok phishing: How to spot fake login and verification pages](https://cybernoz.com/tiktok-phishing-how-to-spot-fake-login-and-verification-pages/) - Phishing pages don’t need to be sophisticated. They just need to look convincing enough to make you trust them.TikTok phishing often starts with an email or message designed to make you think you need to act on your account. It might claim your account has been suspended, reported, or hit with a copyright violation, or
- [Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data](https://cybernoz.com/actively-exploited-oracle-weblogic-flaw-lets-unauthenticated-attackers-access-critical-data/) - Ravie LakshmananAug 25, 2026Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with
- [Argentina’s ‘techno-authoritarian’ turn expands state spying](https://cybernoz.com/argentinas-techno-authoritarian-turn-expands-state-spying/) - The unchecked deployment of artificial intelligence (AI) surveillance tools by the Argentinian government is reinforcing a “techno-authoritarian infrastructure of social control”, according to Amnesty International. In a report published 19 August, titled Sensing the surveillance state, Amnesty documents how, in the first two years of Javier Milei’s administration, the Argentinian government has sought to significantly
- [Ledger Ethereum App Flaw: TestMachine Disclosure Dispute](https://cybernoz.com/ledger-ethereum-app-flaw-testmachine-disclosure-dispute/) - Ledger CTO Charles Guillemet said on Aug. 23, 2026, that the company had fixed a clear-signing flaw in its Ethereum app two weeks before security firm TestMachine publicly disclosed the issue. As of Aug. 24, there were no independently verified reports of funds stolen through the specific vulnerability. The issue involved clear signing, a security
- [Social Media Ban: New Zealand Moves To Restrict Under-16s](https://cybernoz.com/social-media-ban-new-zealand-moves-to-restrict-under-16s/) - New Zealand is moving ahead with a social media ban for under-16s, with the Government introducing the Online Safety (Minimum Age and Child Safety Risk Assessment) Bill to Parliament. The proposed law would require high-risk social media platforms to take reasonable steps to prevent children under 16 from accessing their services and would place greater
- [ASD warns Australian TeamCity servers under attack](https://cybernoz.com/asd-warns-australian-teamcity-servers-under-attack/) - Key points The ACSC is warning that CVE-2026-63077, a critical authentication bypass in JetBrains' TeamCity On-Premises server, is under active local attack. Rated 9.8 out of 10 in severity, the flaw lets unauthenticated attackers with HTTP/HTTPS access run arbitrary OS commands and compromise CI/CD pipelines. CISA has added the TeamCity flaw to its Known Exploited
- [CISA Warns of Exploited Oracle WebLogic Vulnerability](https://cybernoz.com/cisa-warns-of-exploited-oracle-weblogic-vulnerability/) - The cybersecurity agency CISA has instructed government organizations to immediately patch a critical vulnerability that has been widely exploited in attacks against Oracle WebLogic servers. The remote code execution flaw, identified as CVE-2026-21962 with a CVSS score of 10, affects Oracle HTTP Server and the WebLogic Server Proxy plugin, which bridges HTTP Server to WebLogic.
- [Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown](https://cybernoz.com/fake-minecraft-sites-are-still-spreading-weedhack-after-c2-takedown/) - Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown Pierluigi Paganini August 25, 2026 WeedHack Minecraft Malware Survives C2 Takedown: Fake Client Sites Still Active, SEO Poisoning Puts Malicious Downloads at the Top of Google McAfee Labs published a follow-up report on the WeedHack Malware-as-a-Service campaign this week, documenting ten active malicious sites and
- [Bipartisan Senate bill aims to prepare energy sector for Q-Day](https://cybernoz.com/bipartisan-senate-bill-aims-to-prepare-energy-sector-for-q-day/) - A new bipartisan Senate bill would require federal regulators to prepare the U.S. electric grid for cybersecurity threats from quantum computers and create a technical sandbox to study how the technology could impact both information and operational technology systems. The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Sens. Mike Rounds, R-S.D.,
- [ACSC warns of active exploitation of TeamCity servers in Australia](https://cybernoz.com/acsc-warns-of-active-exploitation-of-teamcity-servers-in-australia/) - The Australian Cyber Security Centre (ACSC) has issued a high-severity alert warning that it has observed active exploitation of a vulnerability affecting TeamCity On-Premises servers within Australia. The ACSC said the alert is relevant to all Australian organisations using TeamCity On-Premises, a continuous integration and continuous deployment (CI/CD) platform used to automate building, testing and
- [AI-Powered Remediation 2.0: Choose Your Own Remediation Path](https://cybernoz.com/ai-powered-remediation-2-0-choose-your-own-remediation-path/) - Responding fast to risks in your cloud environment is critical to ensure you can proactively remove issues before attackers discover them and they become active threats. That is why reducing the mean-time-to-remediate (MTTR) is a priority for security and cloud teams. Our goal is to provide customers with easy and efficient ways to remediate risks
- [TikTok reaches $400M settlement with US over COPPA violations](https://cybernoz.com/tiktok-reaches-400m-settlement-with-us-over-coppa-violations/) - The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA). The TikTok social media platform, owned by the Chinese technology company ByteDance, allows users to create, watch, and share short-form videos. In 2024, the U.S. Department of
- [Researcher Discloses Five High-Risk Vulnerabilities in Palo Alto GlobalProtect PAN](https://cybernoz.com/researcher-discloses-five-high-risk-vulnerabilities-in-palo-alto-globalprotect-pan/) - A security researcher has disclosed five vulnerabilities that he responsibly reported to Palo Alto Networks, affecting GlobalProtect, the VPN and endpoint agent used across thousands of enterprise networks worldwide. The disclosure, published through a dedicated research site, has reignited debate over how vendors handle vulnerability reports even when researchers follow coordinated disclosure norms. According to
- [Hackers Exploit Critical Oracle HTTP Server Flaw to Access and Modify Sensitive Data](https://cybernoz.com/hackers-exploit-critical-oracle-http-server-flaw-to-access-and-modify-sensitive-data/) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-21962, affects both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. CISA classified this issue as
- [New TCG guidance gives buyers a way to test PQC-ready TPM claims](https://cybernoz.com/new-tcg-guidance-gives-buyers-a-way-to-test-pqc-ready-tpm-claims/) - The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the platform can later prove it has not been altered. Buyers can now ask a
- [AliExpress caught using silent audio to fingerprint visitors’ browsers](https://cybernoz.com/aliexpress-caught-using-silent-audio-to-fingerprint-visitors-browsers/) - AliExpress, the online marketplace owned by Alibaba Group, has come under scrutiny after researchers and browser maker Brave reported finding silent Web Audio processing on the site that could help fingerprint visitors’ devices. The audio processing did not record people through their microphones. Instead, it generated and processed an inaudible signal, then measured small, repeatable
- [Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account](https://cybernoz.com/critical-keycloak-password-reset-flaw-could-let-unauthenticated-attackers-take-over-any-account/) - Swati KhandelwalAug 24, 2026Vulnerability / Identity Security Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE identifier CVE-2026-18963,
- [NSW mandates facial recognition in gaming reform package](https://cybernoz.com/nsw-mandates-facial-recognition-in-gaming-reform-package/) - NSW will bring in mandatory facial recognition technology (FRT) for hotels and clubs with gaming machines, tied to an exclusion register and expected to be ready by 2028, the state government announced. NSW' statewide register is meant to replace the current patchwork of venue self-exclusion agreements for problem gamblers. Over the next couple of years,
- [91 Vulnerabilities Patched in Spring Application Framework](https://cybernoz.com/91-vulnerabilities-patched-in-spring-application-framework/) - The developers of Broadcom’s Spring application development framework last week announced the release of updates that patch 91 vulnerabilities. Spring is an open source application framework for the Java platform that simplifies the creation of enterprise applications through features such as dependency injection, aspect-oriented programming, and modular support for web, data, and messaging architectures. After
- [SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules](https://cybernoz.com/scotus-tosses-one-of-two-injunctions-against-trump-usps-mail-in-ballot-rules/) - The Supreme Court dismissed one of two lawsuits blocking the Trump administration from implementing changes to U.S. Postal Service regulations regarding mail-in ballots, saying that states lacked standing because they could not prove that the regulations would cause “concrete harm.” California and 23 other states sued the federal government after a White House executive order
- [SCX.ai partners with DDN after ASX debut](https://cybernoz.com/scx-ai-partners-with-ddn-after-asx-debut/) - SCX.ai has announced a strategic partnership with AI data intelligence company DDN, days after the company listed on the Australian Securities Exchange on 21 August following a fully underwritten $40 million initial public offering. SCX.ai said the deal will combine its ASIC-accelerated infrastructure with DDN’s Infinia data intelligence platform to expand what it describes as
- [Effective Data Access Governance in the Cloud w/DSPM & CIEM](https://cybernoz.com/effective-data-access-governance-in-the-cloud-w-dspm-ciem/) - The dynamic and decentralized nature of the cloud makes managing data governance a challenging task, with most organizations running across cloud providers and regions, leading to data sprawl. This fragmentation makes it difficult to maintain consistent data policies, track data lineage, and ensure compliance with various regulatory standards like GDPR or HIPAA. Furthermore, as environments
- [Wishin’ for Switchin’? The Huntress Buyout Program Has You Covered](https://cybernoz.com/wishin-for-switchin-the-huntress-buyout-program-has-you-covered/) - Picture this scene: I'm at the Huntress booth at a trade show. Partner walks up, "I love Huntress. I wish we were using you guys, but ______"Take your pick:We signed a long-term contract with another vendor before I got hereWe bought based on a demo and the reality is way differentTheir tool cost was cheaper,
- [Unpatched Calix flaw lets hackers bypass NAT to expose internal devices](https://cybernoz.com/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/) - An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. The flaw is tracked as CVE-2026-75501 and is described as a missing authentication issue that affects devices running EXOS/6.6.47 firmware. Security
- [Microsoft Teams' New Policy Lets Admins Automatically Block Meeting Bots](https://cybernoz.com/microsoft-teams-new-policy-lets-admins-automatically-block-meeting-bots/) - Microsoft is rolling out a fresh line of defense against unwanted digital eavesdroppers in virtual meetings. The tech giant confirmed that Microsoft Teams will soon let administrators automatically block identified external meeting bots from entering meetings, closing a gap that automated notetakers, transcription tools, and AI assistants have exploited for months. The change, detailed in
- [Hackers Impersonate Security Staff to Steal Credentials in ReliaQuest Social Engineering Attack](https://cybernoz.com/hackers-impersonate-security-staff-to-steal-credentials-in-reliaquest-social-engineering-attack/) - ReliaQuest has reported a targeted social engineering attack in which threat actors impersonated company security personnel, used a spoofed domain, and successfully persuaded one employee to approve a malicious multi-factor authentication (MFA) request. The incident, detected on August 22, 2026, resulted in the temporary exposure of a single identity session with view-only access to ReliaQuest’s
- [CISA's logging guidance works beyond government](https://cybernoz.com/cisas-logging-guidance-works-beyond-government/) - The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Logging Reference Architecture (LRA), released in August 2026, is meant to help US federal civilian
- [Fake Microsoft security scans trick victims into uninstalling their antivirus](https://cybernoz.com/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus/) - A wave of websites is offering to check whether your antivirus is working. They call themselves SysScan, carry Microsoft branding, and all reach the same conclusion: Your computer has serious problems, and the cause is the antivirus software you installed. Windows, they claim, no longer supports third-party antivirus. Uninstall it immediately. That is false, and
- [Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning](https://cybernoz.com/weedhack-malware-spreads-via-fake-minecraft-clients-and-seo-poisoning/) - Ravie LakshmananAug 24, 2026Malware / SEO Poisoning Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to
- [UK power plant shutdown highlights CNI cyber challenges](https://cybernoz.com/uk-power-plant-shutdown-highlights-cni-cyber-challenges/) - The emergency closure of an unidentified UK power generation facility following a cyber attack linked to the Iranian regime has highlighted some of the resilience challenges facing operators of critical national infrastructure (CNI) – particularly those that fall below regulatory incident reporting thresholds. First reported by the Telegraph on Saturday 22 August, the shutdown is
- [AEMO predicts seven-fold rise in data centre power use over next decade](https://cybernoz.com/aemo-predicts-seven-fold-rise-in-data-centre-power-use-over-next-decade/) - Key points AEMO forecasts data centre electricity consumption will grow seven-fold over the next decade, from 5 TWh currently to around 34 TWh. The 2026 forecast is based on 225 known data centre projects, though more than 40 percent since 2025 have dropped out or regressed in connection status. New standards for energy and water
- [Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts](https://cybernoz.com/uber-fined-nearly-1-billion-by-dutch-regulators-over-automated-suspensions-of-driver-accounts/) - Dutch data protection authorities have fined Uber nearly $1 billion, saying the ride-hailing company used automated software to suspend driver accounts, sometimes permanently, with no human review to check for mistakes. The Dutch Data Protection Authority said Friday it is imposing a fine of 825 million euros ($964 million) because Uber violated the EU’s General
- [iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset](https://cybernoz.com/iauthflow-v2-the-10000-phishing-toolkit-that-survives-your-password-reset/) - iAuthFlow v2: The $10,000 Phishing Toolkit That Survives Your Password Reset Pierluigi Paganini August 24, 2026 iAuthFlow v2 phishing toolkit uses a phished Google session to enroll an attacker-controlled passkey that survives password resets. Abnormal Security researchers have published an analysis of iAuthFlow v2, a phishing toolkit sold on a Russian-language cybercrime forum for $10,000
- [House Democrats ask GAO to study CISA workforce cuts](https://cybernoz.com/house-democrats-ask-gao-to-study-cisa-workforce-cuts/) - The five lawmakers, who serve on the Homeland Security Committee, said Congress didn’t know enough about the Trump administration’s changes to the cybersecurity agency. Source link
- [Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’](https://cybernoz.com/treasury-sanctions-alleged-iranian-hackers-as-part-of-economic-d-day/) - As part of its “economic D-Day” against Iran, the Treasury Department designated four Iranians for sanctions Monday stemming from their alleged role in hacking critical infrastructure targets and waging cybertheft against the United States. It’s the second time in as many weeks that the Trump administration has taken aim at the same group of alleged
- [Inaudible sounds used to fingerprint browsers catch AliExpress red-handed](https://cybernoz.com/inaudible-sounds-used-to-fingerprint-browsers-catch-aliexpress-red-handed/) - Variability in different math libraries, which are used when audio is produced through browsers, were once high enough to provide a massively large number of uniquely different signatures when combined with different CPUs and other system differences. After the audio soundprinting technique became well known, Firefox implemented a fix, starting in version 118 released in
- [The Cloudflare Blog – Brought to you by EmDash](https://cybernoz.com/the-cloudflare-blog-brought-to-you-by-emdash/) - You likely noticed the recent redesign of the Cloudflare Blog. We added dark mode, modernized the look and feel, and made a lot of other small improvements along the way.What you might not have noticed – well, except for those who are more terminally online – is that the redesign was part of a much
- [Custom HTML for Custom Phishing: Make the Fake Feel Real](https://cybernoz.com/custom-html-for-custom-phishing-make-the-fake-feel-real/) - It happens all the time in Business Email Compromise (BEC) attacks: someone in the finance department gets an invoice email from what looks like a vendor they work with every day. The logo's right, the tone matches, and the amount is close enough to what they'd expect to pay. It looks like such a routine
- [Hackers target WordPress sites in miniOrange auth bypass attacks](https://cybernoz.com/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/) - Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. The miniOrange SAML SSO plugin turns a WordPress site into a SAML service provider, letting users log in through corporate identity
- [Zimbra Collaboration Suite Vulnerability Actively Exploited in the Wild](https://cybernoz.com/zimbra-collaboration-suite-vulnerability-actively-exploited-in-the-wild/) - CERT Polska has warned that threat actors are actively exploiting CVE-2026-73570, a critical OS command-injection vulnerability in Zimbra Collaboration Suite that allows remote, unauthenticated attackers to execute arbitrary shell commands as the zimbra user. The vulnerability affects Zimbra installations in which the SNMP trap service is enabled via the snmp_notify parameter and the swatchdog service
- [North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access](https://cybernoz.com/north-korean-hackers-hide-anydesk-on-victim-pcs-to-maintain-secret-remote-access/) - North Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk, giving attackers persistent, interactive remote access while blending into legitimate software activity. The operation combines OneDrive-hosted lures, malicious Windows shortcut files, scheduled-task persistence, PowerShell payloads, and email theft across Thunderbird, Outlook, and Gmail. The archives
- [Cybersecurity job ads demanding AI skills double in a year](https://cybernoz.com/cybersecurity-job-ads-demanding-ai-skills-double-in-a-year/) - Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. Analysis from recruitment firms Cornerstone and Indeed covering 24 months, from April 2024 to March 2026, spans G7 markets. It found that 28.5% of cybersecurity job postings between
- [Fake GTA 6 Extended Look and demo sites deliver an infostealer](https://cybernoz.com/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer/) - GTA 6 footage really has leaked online, and Rockstar has an official Extended Look coming to Netflix on August 27. But cybercriminals are exploiting the hype with fake Rockstar sites that lead visitors to password-stealing malware. We identified a network of sites appearing in searches for a GTA 6 demo and impersonating Rockstar Games. One
- [Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt](https://cybernoz.com/shipping-more-ai-code-than-you-can-secure-watch-how-to-control-remediation-debt/) - The Hacker NewsAug 24, 2026AI Security / Webinar If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never
- [Beyond detection: the challenge of infrastructure AI](https://cybernoz.com/beyond-detection-the-challenge-of-infrastructure-ai/) - Ask a developer to build AI for bridge inspection and most will reach for object detection: train a model, draw a boundary box around the rust, ship it. That work has been done. Off-the-shelf models can now reliably flag surface defects in a single image, and the capability is becoming a commodity. The problem is
- [Nvidia customers notified about AI-related price hikes](https://cybernoz.com/nvidia-customers-notified-about-ai-related-price-hikes/) - Some of Nvidia's largest ⁠customers ⁠have been told prices of servers containing its AI chips will rise by more than 15 percent ‌in many cases with memory ‌chip ‌costs soaring, Bloomberg ‌News reported. The ⁠price hikes will go into effect on systems shipped early next year and will impact systems including ​those with the flagship
- [ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited](https://cybernoz.com/reliaquest-confirms-shinyhunters-hack-but-says-impact-was-limited/) - Cybersecurity firm ReliaQuest has confirmed being targeted by hackers affiliated with the notorious ShinyHunters group, but claims the impact of the attack was limited. ReliaQuest revealed on August 17 in a post on X that it had been tracking a widespread ShinyHunters phishing campaign involving domains with the ‘company.claims’ URL pattern. The company also warned
- [Cybercriminals Turn GTA VI Leaks Into Malware Bait](https://cybernoz.com/cybercriminals-turn-gta-vi-leaks-into-malware-bait/) - The malware became obvious when researchers examined its code. It included commands to exclude the entire C: drive from Windows Defender and shut down other security software. Anyone who ran it could effectively disable their antivirus before the malware launched its next stage. This was not an accidental side effect, it was a deliberate step
- [UK power facility disabled for days after suspected state-linked cyberattack](https://cybernoz.com/uk-power-facility-disabled-for-days-after-suspected-state-linked-cyberattack/) - The disruption took place amid a wave of attacks targeting vulnerable industrial devices in the water and energy sectors. Source link
- [7 ways AI can be used to enhance security operations](https://cybernoz.com/7-ways-ai-can-be-used-to-enhance-security-operations/) - 1. Enhancing network and user monitoring AI can continuously monitor network and user activity while automating routine security tasks, says Leslie Daigle, CTO at the Global Cyber Alliance, a nonprofit organization of cybersecurity professionals. “Whether through behavioral analytics, machine learning models, or newer generative AI capabilities, AI can identify suspicious patterns and flag the most
- [UK power generator reportedly taken offline in Iran-linked cyberattack, raising energy security concerns](https://cybernoz.com/uk-power-generator-reportedly-taken-offline-in-iran-linked-cyberattack-raising-energy-security-concerns/) - Hackers linked to Iran reportedly forced a small British power generator offline for four days in July, marking an apparent escalation in cyber threats against the U.K. energy sector, according to reports by the BBC and The Telegraph. The affected facility was not identified, but the U.K. government said it was a small-scale generator and
- [Making Sense of Kubernetes Initial Access Vectors Part 1 – Control Plane](https://cybernoz.com/making-sense-of-kubernetes-initial-access-vectors-part-1-control-plane/) - Kubernetes (K8s) is a complex distributed system designed to run containerized workloads in a scalable and manageable way. It’s now the default method for deploying workloads in cloud-native environments. Thanks to its flexibility and extensibility, Kubernetes has proven effective in handling a variety of workloads (e.g., Batch, HPC, GPU-based), which has contributed to its widespread
- [Meet Athena: Huntress' Agentic SOC Analyst](https://cybernoz.com/meet-athena-huntress-agentic-soc-analyst/) - The emergence of AI has been a major boon for cyberattackers. They're using it to chain together tools, automate credential theft and session hijacking, generate new malware, and write convincing phishing lures. The result is more campaigns, launched faster, against organizations that were already stretched thin.Defenders still have to investigate every signal and act without
- [ReliaQuest confirms failed data-theft attack after ShinyHunters breach](https://cybernoz.com/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/) - Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. In a statement over the weekend, ReliaQuest said that an attacker called multiple employees and tried to trick them into accessing "a fake ReliaQuest single sign-on (SSO) page behind
- [Hackers Poison Google and Bing Results to Deliver Cloaked Banking Phishing Pages](https://cybernoz.com/hackers-poison-google-and-bing-results-to-deliver-cloaked-banking-phishing-pages/) - Bank customers searching for a login page can now be led into a trap before they receive a suspicious email or text message. Criminals are manipulating Google and Bing results so that fraudulent banking pages appear where people expect to find legitimate services. The campaign, called Chameleon SEO Poisoning, turns ordinary searches for terms such
- [Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages](https://cybernoz.com/google-and-bing-search-results-used-to-deliver-hidden-banking-phishing-pages/) - Threat actors are increasingly using Google and Bing as phishing delivery channels, employing a cloaking technique that presents harmless pages to security scanners while serving credential-harvesting banking portals to genuine search users. The campaigns target users of major financial institutions and combine search-engine optimization abuse, recently registered lookalike domains, and referral-aware payload delivery to extend
- [Who's Who In Cyberinsurance For Small Businesses](https://cybernoz.com/whos-who-in-cyberinsurance-for-small-businesses/) - Many small business owners operate under the dangerous misconception that they’re too small to be a target. The reality? Cybercriminals often view small businesses as easier prey, lacking the robust security infrastructure of larger enterprises. A single data breach can be catastrophic. Without adequate cyberinsurance, a small business could be left footing an astronomical bill
- [Suspected Iran-linked attack knocked UK power plant offline for days](https://cybernoz.com/suspected-iran-linked-attack-knocked-uk-power-plant-offline-for-days/) - News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks. According to sources of UK news outlet The Telegraph, the power plant was offline for four days in
- [Your data doesn't die when you do (Lock and Code S07E17)](https://cybernoz.com/your-data-doesnt-die-when-you-do-lock-and-code-s07e17/) - This week on the Lock and Code podcast… You will die. Your data will not. The afterlife of our information is a recent phenomenon, and some of the companies with the most to sort through are still just figuring it out. As far back as 2007, Facebook was forced to reckon with mass grief when
- [WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords](https://cybernoz.com/wordlistloader-delivers-amatera-via-clickfix-synkloader-phishes-windows-passwords/) - Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) technique
- [Post Office finally signs off Horizon replacement deal after three-month delay](https://cybernoz.com/post-office-finally-signs-off-horizon-replacement-deal-after-three-month-delay/) - The Post Office has formally signed a contract with the supplier set to replace the controversial Horizon system, following a three-month delay induced by a challenge from the losing bidder. The £169.2m deal for an electronic point of sale system (EPOS) is Lot 2 of the plan to remove Fujitsu and its system, which is at
- [Services Australia's CIDO heads to RBA](https://cybernoz.com/services-australias-cido-heads-to-rba/) - Key points Charles McHardie is leaving Services Australia to become the Reserve Bank of Australia's chief information officer from October 19. His last day at Services Australia will be September 19, with Claire Roennfeldt taking on interim CIDO responsibilities. McHardie joined Services Australia in early 2020 and led the welfare payments infrastructure transformation, a major
- [Hired for One Job, Judged on Another: The CISO’s Real Problem](https://cybernoz.com/hired-for-one-job-judged-on-another-the-cisos-real-problem/) - Industry surveys have long put CISO tenure below that of other C-suite roles, and part of the reason is a double standard. During recruitment, the focus is technical depth, security experience, and leadership. But when budget season arrives and the board weighs a leader’s performance, the lens is cost, growth, customer trust, and brand protection.
- [Slovakia Warns of Cyber Risks in Road Speed Cameras](https://cybernoz.com/slovakia-warns-of-cyber-risks-in-road-speed-cameras/) - Slovakia Warns of Cyber Risks in Road Speed Cameras Pierluigi Paganini August 24, 2026 Slovakia warns that vulnerable speed cameras could expose vehicle data, enable remote access and provide attackers with a foothold into public networks. Slovakia’s National Security Authority, NBÚ, recently issued a warning about several road speed cameras, calling them a significant cyber
- [Windows Defender’s own driver can leave systems defenseless](https://cybernoz.com/windows-defenders-own-driver-can-leave-systems-defenseless/) - Once decrypted, the configuration contains a sequence of actions like file deletion, directory deletion, file moves, and registry operations. Registry operations found possible included deleting registry keys and values, setting registry values, arbitrary registry modification, and, potentially, persistence or security control tampering. When the destination is set to System32, the file-move primitive can become an
- [GAO urges NASA to strengthen cybersecurity risk management as spacecraft, space systems face growing cyber threats](https://cybernoz.com/gao-urges-nasa-to-strengthen-cybersecurity-risk-management-as-spacecraft-space-systems-face-growing-cyber-threats/) - A new report from the U.S. Government Accountability Office (GAO) has urged the National Aeronautics and Space Administration (NASA) to strengthen its cybersecurity risk management after finding that the agency has yet to implement a priority recommendation to conduct an organization-wide cybersecurity risk assessment. GAO said spacecraft and space systems face increased risks of cyberattacks
- [Accelerating our commitment to Europe](https://cybernoz.com/accelerating-our-commitment-to-europe/) - A few weeks ago, we underscored our commitment to Europe by opening the Wiz EMEA Headquarters in London. This expansion brings our engineering and research teams closer to major organizations in the region, such as Asos, Revolut, Shell, BMW, and LVMH. Today, we are expanding our commitment by enabling Wiz support for AWS European Sovereign
- [How We Cut Noise Before It Hits the Analyst](https://cybernoz.com/how-we-cut-noise-before-it-hits-the-analyst/) - The average security operation center (SOC) today is drowning, not because analysts aren't skilled, but because the signal-to-insight ratio has become brutal. More endpoints, more identities, more telemetry, more alerts. If every signal had to be manually triaged by a human analyst, no SOC would keep pace.Huntress has always been known for low noise. We
- [CISA orders urgent patching of actively exploited Zimbra flaw](https://cybernoz.com/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw/) - The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The Zimbra security team patched the security flaw (tracked as CVE-2026-73570) in version 10.1.20, released on July 20. Successful exploitation allows unauthenticated attackers to gain remote code execution by
- [Fake CAPTCHA Tricks Mac Users Into Installing a Backdoor That Steals Passwords and Mines Crypto](https://cybernoz.com/fake-captcha-tricks-mac-users-into-installing-a-backdoor-that-steals-passwords-and-mines-crypto/) - Mac users are being lured into a ClickFix campaign that turns a routine CAPTCHA check into a path for password theft, remote control, and cryptocurrency mining. It persuades a visitor to run an attackers’ command in Terminal rather than download an application. The fake verification page is styled as a TrustKey human check and displays
- [Open VSX Unblocks 3 IDs Used in 77-Extension Evil-Twin Malware Campaign](https://cybernoz.com/open-vsx-unblocks-3-ids-used-in-77-extension-evil-twin-malware-campaign/) - Open VSX has removed three extension identifiers from its malicious-extension list after the legitimate projects they impersonated began reclaiming their names. The move restores publishing access for the affected maintainers but highlights a supply-chain tracking gap: a single extension ID can represent both a removed malicious artifact and a later legitimate release. Between August 16
- [Android car head units infected with proxy botnet malware through built-in software updaters](https://cybernoz.com/android-car-head-units-infected-with-proxy-botnet-malware-through-built-in-software-updaters/) - A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found. According to the researchers, it’s the first documented case of malware found on a car head unit with an infection chain specific to that
- [A week in security (August 17 – August 23)](https://cybernoz.com/a-week-in-security-august-17-august-23/) - Last week on Malwarebytes Labs: Zombie Card: An expired Visa credit card can be used for purchases Medical records, SSNs, and bank details exposed in CareCloud data breach ChatGPT for Teens tackles risky chats and homework shortcuts Twitch wants your content for Amazon AI training. Here’s how to opt out Your Mac already has a
- [UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit](https://cybernoz.com/uat-10147-uses-ai-to-scale-server-attacks-deploys-spectre-with-edr-bypass-and-linux-rootkit/) - Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of
- [How can the UK plan rationally for the datacentre future it needs?](https://cybernoz.com/how-can-the-uk-plan-rationally-for-the-datacentre-future-it-needs/) - Rising demand for datacentres is fuelled by rapid technological development and increased reliance on digital and AI innovations in personal and professional life. The government’s research briefing, Datacentres: planning policy, sustainability, and resilience, estimated datacentre capacity could rise between 3.3GW and 6.3 GW by 2030. Additionally, the International Data Center Authority’s Global Data Centre Report
- [Encrypted Prompts Defeat Grok and Gemini Guardrails; Chat Histories Stolen](https://cybernoz.com/encrypted-prompts-defeat-grok-and-gemini-guardrails-chat-histories-stolen/) - Researchers at Adversa AI disclosed an attack technique that smuggles malicious instructions past AI safety filters by encrypting them. They then demonstrated it against production deployments of xAI's Grok and Google's Gemini - including a zero-click chain that could exfiltrate a Grok user's entire chat history. The technique, which the researchers call Cryptographic Context Injection,
- [Microsoft Reverses Exploitation Warning On Entra ID CVE-2026-69836 Bug](https://cybernoz.com/microsoft-reverses-exploitation-warning-on-entra-id-cve-2026-69836-bug/) - Microsoft disclosed and fixed a maximum-severity remote code execution vulnerability in Entra ID, its cloud identity platform, on August 20, then quietly reversed the advisory’s exploitation status a day later – leaving enterprise defenders without a clear account of whether the flaw was ever used in attacks. The vulnerability, tracked as CVE-2026-69836, carries a CVSS
- [Vocus gets to work on route for Sydney-Melbourne fibre](https://cybernoz.com/vocus-gets-to-work-on-route-for-sydney-melbourne-fibre/) - Key points Vocus has appointed UGL as development partner to begin detailed route planning for its $500 million Sydney-Melbourne ducted fibre link. The project, marketed as the Australian Digital Infrastructure Platform, is scheduled to be operational by 2029 and can accommodate up to 3456 fibre pairs. Its ducted design will let Vocus add capacity without
- [TikTok Reaches $400 Million Settlement With US Justice Department Over Children's Privacy](https://cybernoz.com/tiktok-reaches-400-million-settlement-with-us-justice-department-over-childrens-privacy/) - TikTok has reached a $400 million settlement with the U.S. Department of Justice, ending a 2024 lawsuit alleging the company violated federal children’s privacy laws. The DOJ said Friday that TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, Musical.ly. “This settlement
- [TikTok Settles U.S. Child Privacy Case for $400 Million](https://cybernoz.com/tiktok-settles-u-s-child-privacy-case-for-400-million/) - TikTok Settles U.S. Child Privacy Case for $400 Million Pierluigi Paganini August 24, 2026 TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s
- [When fear no longer holds you back. Interview with Ryan Bonner (Roll4CombatUS)](https://cybernoz.com/when-fear-no-longer-holds-you-back-interview-with-ryan-bonner-roll4combatus/) - Ryan Bonner, also known as Roll4CombatUS, is a respected Bug Bounty hunter, consultant, speaker, and Intigriti Hacker Ambassador based in the United States. In today’s interview, we discuss his journey into bug hunting, his recommended tools and techniques, and share advice for hunters just getting started. To put it frankly, I got fired from my first
- [Kubernetes Initial Access Vectors Part 2: Data Plane](https://cybernoz.com/kubernetes-initial-access-vectors-part-2-data-plane/) - This is the second part of our two-blog series, where we explore various initial access vectors into Kubernetes environments, analyze the associated attack angles, and clarify the relevant risks. In the first blog, we presented the taxonomy of initial access vectors and discussed control plane access. In this part, we focus on data plane access. We
- [What Are Initial Access Brokers?](https://cybernoz.com/what-are-initial-access-brokers/) - Cybercriminals don't need to do the whole job alone anymore.Today’s threat landscape operates as a highly commoditized ecosystem built on a sophisticated supply chain of handoffs. That’s exactly where initial access brokers (IABs) come into play.IABs are specialized cybercriminals who break into organizations and sell that foothold to other attackers. Instead of carrying out every
- [AWS Network Firewall Now Shows Which Security Rules Are Actually Being Triggered](https://cybernoz.com/aws-network-firewall-now-shows-which-security-rules-are-actually-being-triggered/) - AWS has introduced rule hit count support for AWS Network Firewall, giving security teams direct visibility into which stateful firewall rules are matching live network traffic. The new capability is enabled by default and helps organizations identify active, inactive, and potentially misconfigured rules without manually reviewing large volumes of firewall logs. As firewall policies grow,
- [Sysdig: Industry Highlights from Black Hat 2026](https://cybernoz.com/sysdig-industry-highlights-from-black-hat-2026/) - Sysdig is acknowledging the fact that CISOs don’t have time to click through a dashboard anymore. Conor Sherman, the company’s Global CISO, argues the next era of cloud security has to run at machine speed, headless, and outcome-first. “I don’t care how the meal is made,” Sherman said. “I just need to make sure it’s
- [Iran-Linked Hackers Shut Down UK Power Plant for Four Days in Cyberattack](https://cybernoz.com/iran-linked-hackers-shut-down-uk-power-plant-for-four-days-in-cyberattack/) - A cyberattack linked to Iranian threat actors forced a British power plant offline for four consecutive days in July, reportedly marking the first successful cyber incident to disrupt a UK energy-generation facility completely. This incident, first reported by The Telegraph, affected a small-scale electricity generator rather than a major power station. The UK government emphasized
- [Fake bank websites play dead to evade security scanners](https://cybernoz.com/fake-bank-websites-play-dead-to-evade-security-scanners/) - A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra. The company’s threat intelligence unit, Fortra Intelligence and Research Experts (FIRE), spent three months tracking the technique and reports a 40% jump in cases during the
- [CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification](https://cybernoz.com/cdn-tsunami-attack-abuses-http-3-translation-for-up-to-350x-dos-amplification/) - Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server. The attacks, collectively named "CDN Tsunami," were evaluated against Alibaba, Baidu, Cloudflare, Amazon CloudFront,
- [AI Without Governance Is Just Expensive Risk](https://cybernoz.com/ai-without-governance-is-just-expensive-risk/) - As businesses race to deploy AI in pursuit of productivity, efficiency and competitive advantage, they are often overlooking the single most important factor that will determine whether their AI investments succeed or fail. Cyber governance, risk and compliance planning will be the ultimate decider on how successful widespread AI adoption can in effect be. We
- [Introducing New Amazon Q Developer Plugin for Wiz](https://cybernoz.com/introducing-new-amazon-q-developer-plugin-for-wiz/) - Traditional cloud security tools are typically catered to security teams, making it challenging to scale and democratize security to other teams in organizations. At Wiz, our goal is to help organizations democratize security so they can innovate faster in the cloud. The Wiz Security Graph already simplifies cloud security and makes it more accessible to
- [How the LSHIY Password-Spraying Attack Abuses OAuth’s ROPC Grant](https://cybernoz.com/how-the-lshiy-password-spraying-attack-abuses-oauths-ropc-grant/) - Spray bottles are famously finicky. How many times have you bought a cleaning product only to find that after just a few uses, the nozzle is stuck in place and therefore inoperable? In the event of a password spraying attack, our job as defenders requires a similar level of precision: to block the entry point so
- [AvePoint: Industry Highlights from Black Hat 2026](https://cybernoz.com/avepoint-industry-highlights-from-black-hat-2026/) - Most organizations think they’ve solved the data sensitivity problem. AvePoint’s research says otherwise. In the company’s third annual State of AI Report, 82.7% of organizations said they were “very” or “extremely” confident in their ability to prevent unauthorized AI data access. Yet 72% of that same confident group had already experienced an AI-related unauthorized access
- [Why "Shady AI" is Security's Next Big Governance Problem](https://cybernoz.com/why-shady-ai-is-securitys-next-big-governance-problem/) - In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it. The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI agent to analyze it,
- [Allianz tech 'transformation' exposed as offshoring drive](https://cybernoz.com/allianz-tech-transformation-exposed-as-offshoring-drive/) - Key points Allianz Technology's Speed2Value initiative, publicly framed as a transformation for innovation and operational excellence, is actually an offshoring and cost-out drive, an unfair dismissal decision reveals. AzTech's direct employee headcount in Australia fell from 515 in March 2023 to 329 in March 2026 since the initiative began. An analyst programmer's unsuccessful challenge to
- [Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection](https://cybernoz.com/zero-click-grok-chat-history-theft-adversa-ai-demonstrates-cryptographic-context-injection/) - Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection Pierluigi Paganini August 23, 2026 New Cryptographic Context Injection technique bypasses AI guardrails via AES-encrypted payloads, leaking full Grok chat histories zero-click Adversa AI researcher Rony Utevsky devised a new attack technique, called Cryptographic Context Injection, that bypasses AI safety filters by sending instructions
- [Overcoming Kubernetes Log Challenges in Detection](https://cybernoz.com/overcoming-kubernetes-log-challenges-in-detection/) - In writing the Wiz 2023 State of Kubernetes Report, we found that overall container security maturity remains low, yet these environments are appealing targets for attackers and attempts to breach them are on the rise. Moreover, once an attacker gains access, the opportunities for lateral movement and privilege escalation within a cluster are numerous. In this
- [Employee Spotlight: Andrew Schlemmer | Huntress](https://cybernoz.com/employee-spotlight-andrew-schlemmer-huntress/) - In this edition of our "Employee Spotlight" series, I sat down with Andrew Schlemmer, a Channel Account Manager who came to Huntress with a personal score to settle with cybercriminals. For Andrew, this work hits close to home in the most literal sense.Here's what he had to say.What's your role here at Huntress?Andrew: I'm a
- [Iran-Linked Hackers Force UK Power Plant Offline in Unprecedented Four-Day Cyberattack](https://cybernoz.com/iran-linked-hackers-force-uk-power-plant-offline-in-unprecedented-four-day-cyberattack/) - A cyberattack attributed to hackers linked to Iran forced a British power plant offline for four consecutive days last month, marking what officials describe as the first successful attack of its kind against UK energy infrastructure. The incident, first reported by The Telegraph, has raised fresh alarm over the vulnerability of critical infrastructure amid heightened
- [Rethinking Cyber Readiness In Our Current Threat Landscape](https://cybernoz.com/rethinking-cyber-readiness-in-our-current-threat-landscape/) - Cybersecurity leaders are dealing with a threat landscape where disruption spreads quickly across systems, vendors, and business operations. AI is accelerating how quickly attackers identify and exploit weaknesses, while identity-based attacks and growing third-party dependencies are making incidents harder to contain. At the same time, operating across cloud environments means it is increasingly difficult to
- [Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments](https://cybernoz.com/zombie-card-attack-can-revive-expired-visa-cards-for-contactless-payments/) - Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the card's cryptography. The attack, which the researchers named "Zombie Card," requires physical possession of
- [SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111](https://cybernoz.com/security-affairs-malware-newsletter-round-111/) - Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between Banking Malware & Spyware Clop
- [Introducing Wiz Champion Center: Become a CloudSec Leader](https://cybernoz.com/introducing-wiz-champion-center-become-a-cloudsec-leader/) - Operationalizing cloud security requires leaders to build successful programs by fostering structure, visibility, and accountability across their teams. These leaders need tools to scale their efforts in identifying, correlating, and addressing risks—across all security pillars ( identity, vulnerabilities, data security, and more). The Wiz Champion Center empowers these leaders—Wiz Champions—to operationalize their cloud security programs
- [What Our AI SOC Analyst Can Do (and What We Won’t Let It Do)](https://cybernoz.com/what-our-ai-soc-analyst-can-do-and-what-we-wont-let-it-do/) - When security buyers hear "AI-centric SOC," half view it as expected, and the other half get nervous. The nervous half has reasonable questions, like: Who's actually in control? What happens when AI gets it wrong? Is my security really being handled by a machine that makes its own decisions?What role do human SOC analysts still play?These are the
- [What Our AI SOC Analyst Can Do (and What We Won’t Let It Do)](https://cybernoz.com/what-our-ai-soc-analyst-can-do-and-what-we-wont-let-it-do/) - When security buyers hear "AI-centric SOC," half view it as expected, and the other half get nervous. The nervous half has reasonable questions, like: Who's actually in control? What happens when AI gets it wrong? Is my security really being handled by a machine that makes its own decisions?What role do human SOC analysts still play?These are the
- [ToxicPanda Android malware uses VPN permissions to block Google Play](https://cybernoz.com/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/) - The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google
- [Microsoft Windows 11 App Pushes Bing as Default Search in Chrome, Firefox and Brave](https://cybernoz.com/microsoft-windows-11-app-pushes-bing-as-default-search-in-chrome-firefox-and-brave/) - Microsoft has built a dedicated Windows 11 app that exists to put Bing in front of users who already chose another search engine. The utility, Microsoft Recommended Search Settings, arrives as a standalone 22.2 MB installer named MicrosoftSettings.exe. It is hosted on Microsoft’s official download servers rather than Windows Update or the Microsoft Store, and
- [The Cyber Resilience Imperative: Why CISOs Must Shift from Prevention to Business Survival](https://cybernoz.com/the-cyber-resilience-imperative-why-cisos-must-shift-from-prevention-to-business-survival/) - For decades, cybersecurity strategies have been built around a single objective: preventing attacks. Organizations invested heavily in perimeter defenses, endpoint security, identity controls, and threat detection technologies with the expectation that stronger defenses would keep adversaries out. Yet today’s threat landscape tells a different story. Ransomware groups operate like multinational businesses. Nation-state actors possess sophisticated
- [Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution](https://cybernoz.com/attackers-exploit-zimbra-snmp-flaw-for-unauthenticated-remote-code-execution/) - Ravie LakshmananAug 20, 2026Vulnerability / Email Security A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote
- [UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks](https://cybernoz.com/uk-power-plant-disabled-for-four-days-by-iran-linked-hackers-concurrent-with-us-water-attacks/) - UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks Pierluigi Paganini August 23, 2026 Iran-linked hackers shut down a UK power plant for four days in the first confirmed attack of its kind, concurrent with water infrastructure attacks across 12 US states. Iran-linked hackers shut down a British power
- [Keeping OT Going When IT Goes Dark](https://cybernoz.com/keeping-ot-going-when-it-goes-dark/) - OT Insights CenterKeeping OT Going When IT Goes Dark Keeping OT Going When IT Goes Dark Register Now Join us on Wed. September 16th10am (NYC) / 3pm (London) / 6pm (Dubai) A consortium of governments behind the CI-Fortify initiative are advising critical infrastructures to isolate / island in cyber emergencies – separate IT entirely from
- [Wiz Remediation and Response Available for Azure and GCP](https://cybernoz.com/wiz-remediation-and-response-available-for-azure-and-gcp/) - A few months ago, we announced Wiz Remediation and Response. Today, we are thrilled to extend enhanced remediation and response capability to support Azure and GCP cloud environments. As a result, Cloud security teams on all major public cloud environments can enforce security best practices in real-time and empower incident responders to quickly contain and
- [Credential Stuffing Campaign Hits SonicWall](https://cybernoz.com/credential-stuffing-campaign-hits-sonicwall/) - Acknowledgments: Special thanks to Andrea Ochoa, Cristian Poenaru, Harry Godridge, Rob Stynes, Joshua Kiriakoff, Jordan Sexton, Anthony Gibbs, Austin Worline, Michael Tigges, Tyler Bohlmann, and Nick Roddy for their contributions to this investigation and response.BackgroundStarting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and
- [Citrix urges admins to patch new NetScaler flaws as soon as possible](https://cybernoz.com/citrix-urges-admins-to-patch-new-netscaler-flaws-as-soon-as-possible/) - Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The most severe of the two, tracked as CVE-2026-19490, can allow remote attackers without privileges to bypass authentication when the appliance is configured as an AAA virtual server or as a
- [Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs](https://cybernoz.com/week-in-review-records-allegedly-stolen-from-azure-tenants-medusa-ransomware-hits-500-orgs/) - Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriverResearchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the
- [Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers](https://cybernoz.com/critical-netscaler-flaw-can-bypass-authentication-on-certain-gateway-and-aaa-servers/) - Ravie LakshmananAug 20, 2026Network Security / Enterprise Security Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScaler ADC and NetScaler Gateway, including certain FIPS and NDcPP builds, as
- [Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION](https://cybernoz.com/security-affairs-newsletter-round-591-by-pierluigi-paganini-international-edition/) - Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION Pierluigi Paganini August 23, 2026 A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. International
- [Wiz to acquire Dazz, transforming risk remediation from cloud to code](https://cybernoz.com/wiz-to-acquire-dazz-transforming-risk-remediation-from-cloud-to-code/) - Today’s announcement is a big moment for us at Wiz. It’s another milestone on our never-ending journey to build an even stronger Cloud Native Application Protection Platform (CNAPP) by bringing on incredible companies that will make a real difference for our customers. Everything we do is rooted in customer need. Wiz has always been driven by
- [Introducing Huntress Webhooks. Get Real-Time Security Alerts.](https://cybernoz.com/introducing-huntress-webhooks-get-real-time-security-alerts/) - In security, every minute counts. When an incident report or escalation comes in, a quick response can mean the difference between being the hero and having a very bad day. But here's the reality: you and your team aren't always staring at the Huntress portal. You're in your PSA triaging tickets, glancing at Slack, or
- [SickKids data breach exposes employee and job applicant info](https://cybernoz.com/sickkids-data-breach-exposes-employee-and-job-applicant-info/) - The Hospital for Sick Children (SickKids) has disclosed that the personal information of some current and former employees, as well as job applicants, was exposed in a "cybersecurity incident." The hospital says the breach stemmed from a flaw in third-party software. Clinical systems and patient records were untouched, according to the Toronto pediatric hospital, but
- [Claude Opus 5 Routes Around Obfuscated Binaries Instead of Defeating the Protection](https://cybernoz.com/claude-opus-5-routes-around-obfuscated-binaries-instead-of-defeating-the-protection/) - Claude Opus 5 did not crack hardened binaries in a reverse-engineering experiment. Instead, it sought easier ways to recover hidden information, showing AI-assisted analysis can be capable yet unreliable. The test was not a malware outbreak. It used stripped AArch64 binaries containing hidden strings, then placed an autonomous coding agent in a sandbox with disassembly,
- [OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing](https://cybernoz.com/openai-frontier-models-get-zero-data-retention-with-private-safety-processing/) - OpenAI has reaffirmed its commitment to Zero Data Retention (ZDR) for eligible API customers using frontier models while introducing the new Private Safety Processing. This safety architecture is designed to detect multi-session misuse without exposing the underlying prompts or responses to OpenAI personnel. Announced on August 19, 2026, this initiative addresses a critical challenge in
- [Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE](https://cybernoz.com/isolated-vm-flaw-lets-sandboxed-javascript-escape-to-host-for-potential-rce/) - Ravie LakshmananAug 20, 2026Vulnerability / Application Security Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet to be assigned a CVE identifier,
- [CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities](https://cybernoz.com/cisa-urges-immediate-patching-of-exploited-trueconf-vulnerabilities/) - The US cybersecurity agency CISA on Thursday warned federal agencies that threat actors have been exploiting two vulnerabilities in TrueConf. A secure on-premises video conferencing platform, TrueConf relies on Scalable Video Coding (SVC) to connect client applications through a dedicated corporate server. All TrueConf Server versions since 2022 contain two critical-severity bugs tracked as CVE-2026-72529
- [Wiz observes CVE-2024-0012 and CVE-2024-9474 exploitation](https://cybernoz.com/wiz-observes-cve-2024-0012-and-cve-2024-9474-exploitation/) - Palo Alto Networks recently disclosed two critical vulnerabilities affecting PAN-OS that were suspected of being exploited in the wild as 0days, and they later confirmed their active exploitation: the first vulnerability is an authentication bypass (CVE-2024-0012) and the second is a privilege escalation vulnerability (CVE-2024-9474). When chained together, these two vulnerabilities allow unauthenticated remote code execution
- [Huntress hits an inflection point](https://cybernoz.com/huntress-hits-an-inflection-point/) - In my last blog, I wrote about Huntress crossing $250M ARR. That post was about the people who got us here: the teammates, partners, customers, investors, and families who carried this thing long before it looked obvious from the outside.This one's about where our mission must go next, and the threats we'll face if we
- [Hackers abuse FTP server banners to deliver new Windows malware](https://cybernoz.com/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/) - Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. MalwareHunterTeam observed this unusual technique in July in an attack that used shortcut files (.LNK) and FTP server banners as dead-drop resolvers (DDR) to retrieve commands. FTP banners are text strings the server uses
- [Hackers Hide Agent Tesla JScript Behind Unicode Emojis to Evade Detection](https://cybernoz.com/hackers-hide-agent-tesla-jscript-behind-unicode-emojis-to-evade-detection/) - Hackers are using Unicode emoji characters to hide an Agent Tesla JScript dropper in a business email compromise campaign aimed at finance teams. The tactic turns a payment-related attachment into a difficult-to-read script while leaving malicious instructions ready for Windows to execute. A forwarded wire-transfer email impersonates Metropolitan Bank and Trust Company. It urges recipients
- [768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts](https://cybernoz.com/768-leaked-aws-keys-still-active-with-full-admin-access-to-corporate-accounts/) - A large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a serious risk of account takeover, data theft, infrastructure abuse, and cloud billing fraud. The credentials include 526 root access keys and 242 IAM user keys attached to AWS’s AdministratorAccess managed
- [New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data](https://cybernoz.com/new-cryptographic-context-injection-attack-could-let-web-pages-steal-grok-chat-data/) - Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI security company, which has codenamed the technique
- [Microsoft Patches Exploited Entra ID Vulnerability](https://cybernoz.com/microsoft-patches-exploited-entra-id-vulnerability/) - Microsoft on Thursday announced the rollout of 22 new security updates that resolve severe vulnerabilities across multiple products, including a critical Entra ID zero-day exploited in attacks. The exploited Entra ID flaw is tracked as CVE-2026-69836, and it could have been exploited for remote code execution (RCE). Microsoft discovered the issue internally and patched it
- [U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog](https://cybernoz.com/u-s-cisa-adds-zimbra-collaboration-suite-zcs-flaw-to-its-known-exploited-vulnerabilities-catalog/) - U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog Pierluigi Paganini August 22, 2026 U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Zimbra Collaboration Suite (ZCS) flaw CVE-2026-73570 to its
- [Say it once: introducing Bot Preference Sync](https://cybernoz.com/say-it-once-introducing-bot-preference-sync/) - We’re constantly building for the different goals of our customers. Some customers want to optimize for discovery, while others want to protect their content with the strictest security policy. Among these differing policies, there are multiple ways to mitigate bot traffic. Some mechanisms simply state your preference, assuming best intent from crawlers, and other approaches
- [Device Code Phishing Keeps Evolving. Here’s What to Watch For](https://cybernoz.com/device-code-phishing-keeps-evolving-heres-what-to-watch-for/) - Acknowledgments: Special thanks to Rich Mozeleski for his contributions to this investigation and writeup.Huntress has seen a notable influx in device code phishing attacks in 2026. Earlier this year, we reported a massive wave of device code phishing attacks that stemmed from Railway, a platform-as-a-service built for vibe coding. Starting in April, we also saw
- [CISA orders feds to patch actively exploited TrueConf Server flaws](https://cybernoz.com/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/) - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. TrueConf Server is designed for secure corporate messaging and video conferencing and, unlike cloud-based software like Zoom or Microsoft Teams, it operates inside an organization's local network (LAN). The
- [Chinese Hackers Use AI Agents to Exploit Web Servers and Automate Attacks](https://cybernoz.com/chinese-hackers-use-ai-agents-to-exploit-web-servers-and-automate-attacks/) - A Chinese-speaking cybercrime group is using AI-assisted tools to turn vulnerable web servers into entry points. It shows how familiar flaws become more dangerous when attackers automate the work around them. The group, tracked as UAT-10147, targeted internet-facing Windows and Linux systems in government, education, media, technology, and gaming. Victims were identified across several countries,
- [Zero-Click Grok Attack Lets Hackers Steal Chat History Using Encrypted Prompt Injection](https://cybernoz.com/zero-click-grok-attack-lets-hackers-steal-chat-history-using-encrypted-prompt-injection/) - A newly disclosed prompt-injection technique could turn a routine request to summarize a webpage in xAI’s Grok web chat into a silent data-exfiltration attack, potentially exposing a user’s name, approximate location, subscription tier, and active conversation history. Security researchers at Adversa AI have dubbed the technique “Cryptographic Context Injection.” The attack targets Grok’s ability to
- [TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit](https://cybernoz.com/tiktok-agrees-to-400-million-settlement-in-u-s-child-privacy-lawsuit/) - Ravie LakshmananAug 22, 2026Privacy / Regulation The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an additional
- [Turn datacentre impact uncertainty into datacentre clarity](https://cybernoz.com/turn-datacentre-impact-uncertainty-into-datacentre-clarity/) - Datacentres, once a quiet backbone of the digital economy, are now one of the most visible infrastructure points of contention of the AI era. Globally, their growth increases pressure on electricity, water, land use, emissions pathways, and local communities. The IEA reports that electricity demand from datacentres rose 17% in 2025, with AI-focused facilities growing
- [Contractors' CMMC Confidence Rises as Ability to Prove It Falls Behind](https://cybernoz.com/contractors-cmmc-confidence-rises-as-ability-to-prove-it-falls-behind/) - Two industry surveys released this week paint a consistent picture of the defense industrial base: contractors say they’re more confident in their cybersecurity compliance than ever, even as their ability to prove that compliance lags behind. Kiteworks surveyed 273 defense contractors in the days following the Pentagon’s July suspension of CMMC 2.0 Phase 2 third-party

## Pages

- [CyberSecurity News](https://cybernoz.com/home/)
- [Contact](https://cybernoz.com/contact/)

## Categories

- [Genel](https://cybernoz.com/category/genel/) - Browse the latest Genel cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Bleeping Computer](https://cybernoz.com/category/bleeping-computer/) - Browse the latest Bleeping Computer cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [TheHackerNews](https://cybernoz.com/category/thehackernews/) - Browse the latest TheHackerNews cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [CyberSecurityNews](https://cybernoz.com/category/cybersecuritynews/) - Browse the latest CyberSecurityNews cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [PortSwigger](https://cybernoz.com/category/portswigger/) - Browse the latest PortSwigger cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [CyberDefenseMagazine](https://cybernoz.com/category/cyberdefensemagazine/) - Browse the latest CyberDefenseMagazine cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [ITSecurityGuru](https://cybernoz.com/category/itsecurityguru/) - Browse the latest ITSecurityGuru cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Krebson](https://cybernoz.com/category/krebson/) - Browse the latest Krebson cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Wired](https://cybernoz.com/category/wired/) - Browse the latest Wired cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [CyberNews](https://cybernoz.com/category/cybernews/) - Browse the latest CyberNews cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [ExploitOne](https://cybernoz.com/category/exploitone/) - Browse the latest ExploitOne cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [GBHackers](https://cybernoz.com/category/gbhackers/) - Browse the latest GBHackers cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [HackRead](https://cybernoz.com/category/hackread/) - Browse the latest HackRead cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [HackerCombat](https://cybernoz.com/category/hackercombat/) - Browse the latest HackerCombat cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [CyberSecurity-Insiders](https://cybernoz.com/category/cybersecurity-insiders/) - Browse the latest CyberSecurity-Insiders cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Cyber Security Ventures](https://cybernoz.com/category/cybersecurityventures/) - Browse the latest Cyber Security Ventures cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [HelpnetSecurity](https://cybernoz.com/category/helpnetsecurity/) - Browse the latest HelpnetSecurity cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [MalwareBytes](https://cybernoz.com/category/malwarebytes/) - Browse the latest MalwareBytes cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [ITnews](https://cybernoz.com/category/itnews/) - Browse the latest ITnews cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [TheCyberExpress](https://cybernoz.com/category/thecyberexpress/) - Browse the latest TheCyberExpress cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [DarkReading](https://cybernoz.com/category/darkreading/) - Browse the latest DarkReading cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [ComputerWeekly](https://cybernoz.com/category/computerweekly/) - Browse the latest ComputerWeekly cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Bankinfosecurity](https://cybernoz.com/category/bankinfosecurity/) - Browse the latest Bankinfosecurity cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Mix](https://cybernoz.com/category/mix/) - Browse the latest Mix cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [SecurityWeek](https://cybernoz.com/category/securityweek/) - Browse the latest SecurityWeek cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Securityaffairs](https://cybernoz.com/category/securityaffairs/) - Browse the latest Securityaffairs cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [CyberSecurityDive](https://cybernoz.com/category/cybersecuritydive/) - Browse the latest CyberSecurityDive cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Cyberscoop](https://cybernoz.com/category/cyberscoop/) - Browse the latest Cyberscoop cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [welivesecurity](https://cybernoz.com/category/welivesecurity/) - Browse the latest welivesecurity cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Agbi](https://cybernoz.com/category/agbi/) - Browse the latest Agbi cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [SCMP](https://cybernoz.com/category/scmp/) - Browse the latest SCMP cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Australiancybersecuritymagazine](https://cybernoz.com/category/australiancybersecuritymagazine/) - Browse the latest Australiancybersecuritymagazine cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [CyberWire](https://cybernoz.com/category/cyberwire/) - Browse the latest CyberWire cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Zerosalarium](https://cybernoz.com/category/zerosalarium/) - Browse the latest Zerosalarium cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Tldrsec](https://cybernoz.com/category/tldrsec/) - Browse the latest Tldrsec cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Unit42](https://cybernoz.com/category/unit42/) - Browse the latest Unit42 cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [securelist](https://cybernoz.com/category/securelirt/) - Browse the latest securelist cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [AttackDefense](https://cybernoz.com/category/attackdefense/) - Browse the latest AttackDefense cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Rapid7](https://cybernoz.com/category/rapid7/) - Browse the latest Rapid7 cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [Crowdstrike](https://cybernoz.com/category/crowdstrike/) - Browse the latest Crowdstrike cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [CISOOnline](https://cybernoz.com/category/cisoonline/) - Browse the latest CISOOnline cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [techcrunch](https://cybernoz.com/category/techcrunch/) - Browse the latest techcrunch cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [ArsTechnica](https://cybernoz.com/category/arstechnica/) - Browse the latest ArsTechnica cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [InfoSecurity](https://cybernoz.com/category/infosecurity/) - Browse the latest InfoSecurity cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [IndustrialCyber](https://cybernoz.com/category/industrialcyber/) - Browse the latest IndustrialCyber cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [OTSecurity](https://cybernoz.com/category/otsecurity/) - Browse the latest OTSecurity cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [CloudSecurity](https://cybernoz.com/category/cloudsecurity/) - Browse the latest CloudSecurity cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [VendorResearch](https://cybernoz.com/category/vendorresearch/) - Browse the latest VendorResearch cybersecurity news, expert analysis and breaking updates on CyberNoz.
- [ThreatIntelligence-IncidentResponse](https://cybernoz.com/category/threatintelligence-incidentresponse/) - Browse the latest ThreatIntelligence-IncidentResponse cybersecurity news, expert analysis and breaking updates on CyberNoz.

Поделиться или продолжить анализ
Поделиться результатами
Обсудить с ИИ
Добавлен 06.09.2026
cybernoz.com - проверка ИИ-оптимизации | llmsmap.ru