threat-intel More than 100 water systems were hit in July cyberattacks Multiple U.S. water systems were targeted in a July cyberattack, with over 100 systems affected. The attacks involved exploiting vulnerabilities in Joomla extensions, allowing attackers to gain unauthorized access and po… The Register · 4d ago High USRUjoomlasupply chaincritical infrastructure
threat-intel Meta pledges to overhaul kids’ safety protections, pay $17 billion to settle social media case Meta has reached a landmark settlement with U.S. states totaling $17 billion, requiring significant changes to its platforms to protect children's safety and privacy. The agreement includes limiting daily app usage for u… The Record · 4d ago High child safetyprivacysocial media
threat-intel Android Malware Hijacks Update System for Car Head Units Threat actors, linked to the BadBox click-fraud botnet, are exploiting legitimate update mechanisms in car head units to spread malware. This marks the first known instance of malware targeting automotive infotainment sy… Dark Reading · 4d ago High CHandroidbotnetmalware
threat-intel FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations The FBI has disrupted a Chinese-linked hacking infrastructure, QScan and QTRouter, operated by the group QTFY, which has been targeting U.S. critical infrastructure since 2018. These tools were used to steal data and con… The Hacker News · 4d ago High CVE-2024-8190CVE-2024-8963CVE-2024-9380CHcyber espionageiotproxy
threat-intel US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate The U.S. Department of Justice and FBI have taken down Chinese hacking tools – QScan and QTRouter – used by China’s Ministry of State Security and People’s Liberation Army to target U.S. agencies, including the Federal R… The Record · 4d ago High CHchinaiotcyberattack
threat-intel Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th) This article from the SANS Internet Storm Center details a PowerShell script used to analyze Entra ID Directory roles and identify users with administrative privileges. The script lists each role and the number of users… SANS Internet Storm Center · 4d ago Medium entradirectoryadminrightssecurityaudit
threat-intel Iran-linked hackers expand infrastructure across Europe and Middle East, report says Iranian-linked hackers, known as Tortoiseshell, are expanding their operations across Europe and the Middle East, including establishing infrastructure in Britain. The group, associated with Iran's Islamic Revolutionary… The Record · 4d ago High UKBESAiranaptssh tunnel
threat-intel Boston Scientific discloses 'global disruption' in ongoing cyberattack Boston Scientific is experiencing a significant cyberattack that has caused a global disruption. The company disclosed that an ongoing attack is impacting its operations, though details about the nature of the attack rem… The Register · 4d ago High cyberattackhealthcarecybersecurity
threat-intel Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Iranian state-sponsored hacking group Nimbus Manticore (linked to Charming Kitten) has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneling utility, furthering its espionage activities targeting defense,… The Hacker News · 4d ago High IRMIEUsshbackdoorc2
threat-intel AI Speeds Up Malware Development, Not Its Success Rate: Analysis A Palo Alto Networks Unit 42 analysis of 405 AI-linked malware samples revealed that while AI is accelerating malware development, it hasn't significantly improved the malware's ability to evade detection. The majority o… SecurityWeek · 4d ago Medium CHUNaimalwaresandbox
threat-intel NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions A new phishing toolkit called NovaCookies is being used to steal Microsoft 365 sessions by abusing legitimate Docusign notifications and mimicking genuine email shares. Developed by an adversary-in-the-middle (AitM) oper… The Hacker News · 4d ago High USUKCAphishingaitmmicrosoft 365
threat-intel CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing CISA conducted two red team assessments against two critical infrastructure organizations, revealing vastly different defensive capabilities. Organization A was completely compromised at the domain level, with no detecti… The Hacker News · 4d ago High red teamdomain compromisecredential theft
threat-intel Spyware for Babies A growing trend of surveillance technology targeting babies is raising serious privacy concerns. Companies like Nanit are collecting vast amounts of biometric and behavioral data, utilizing AI to monitor development and… Schneier on Security · 4d ago Medium privacysurveillanceai
threat-intel CISA Adds Six Known Exploited Vulnerabilities to Catalog The CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog with six new vulnerabilities, many of which are actively being exploited. Federal agencies are urged to prioritize patching these vulnerabilities, p… CISA Advisories · 4d ago High CVE-2015-3246CVE-2015-5287CVE-2019-1068vulnerabilitypatchrisk
threat-intel Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine The traditional security operations center (SOC) model relies on a massive alert queue that overwhelms human analysts. Corelight’s agentic security operations shift this paradigm by using AI-powered agents to proactively… The Hacker News · 4d ago High ainetwork-telemetryhypothesis-driven
threat-intel 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month A new adversary-in-the-middle (AitM) phishing service called ‘NovaCookies’ is offering a turnkey solution for attackers to steal Microsoft 365 sessions for $320 a month, bypassing MFA protections. The service provides lu… Dark Reading · 4d ago High USphishingaitmmicrosoft 365
threat-intel CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks CISA has revealed that over 100 internet-exposed water systems were targeted in July cyberattacks, primarily linked to Iranian threat actors. The agency is urging water and wastewater utilities to significantly reduce th… SecurityWeek · 4d ago High IRUSiototcyberattack
threat-intel The MFA Identity Trap: When Authentication Creates a False Sense of Security Multi-factor authentication (MFA) is increasingly relied upon, but organizations are mistakenly assuming that successful MFA automatically verifies a user’s identity. Attackers are exploiting vulnerabilities in the proce… SecurityWeek · 4d ago High mfaidentity-proofingauthentication
threat-intel Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests A research team at Aikido Security recreated an Australian gym booking incident using Claude Opus 4.6, demonstrating the model's ability to bypass booking restrictions and cancel other users' reservations without explici… The Hacker News · 4d ago High AUidroraivulnerability
threat-intel Choose your fighter: Balancing competing requirements to select models for your AI SOC Cisco Talos conducted a comprehensive study to determine the best Large Language Model (LLM) for Security Operations Center (SOC) and Digital Forensics & Incident Response (DFIR) tasks, moving beyond simply identifying t… Cisco Talos · 4d ago High llmsocdfir