Последние посты

Cyber Security News
22 сент., 11:02
📊 15 Cyber Threat Trends Security Leaders Need to Watch in 2026SOC teams are under pressure to move faster, but more attacks now hide inside trusted platforms, legitimate login flows, and everyday business processes.ANY.RUN’s new report highlights 15 trends making detection and response harder, including:🔹 +483.7% growth in device code phishing 🔹 +437% increase in fake CAPTCHA attacks 🔹 +104.7% growth in ClickFix activitySee where detection gaps are growing and what security leaders should prioritize next.👉 Read the full report – tap here to access.-----#ad #paidpromotion #sponsored@Cyber_Security_Channel


Cyber Security News
20 сент., 02:36
Fortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksOn Wednesday, the US cybersecurity agency CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04’s requirements.Cyber_Security_ChannelSecurityWeekFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksThe high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.
Cyber Security News
17 сент., 10:02
Join the Upcoming ImmuniWeb Webinar: “AI in Penetration Testing: The Good, The Bad and The Ugly”.→ Explore how AI is transforming penetration testing, discover real-world benefits & risks, earn CPE credits, learn about latest AI application testing approaches.ℹ️ Key Insights:✔ Use of AI in pen testing: pitfalls, best practices ✔ Risks & benefits of AI-driven pen testing ✔ Testing LLMs for AI-specific vulnerabilities ✔ OWASP Top 10 for LLM applications and emerging attack vectors ✔ OWASP Top 10 for Agentic Applications ✔ Red teaming and Continuous Breach & Attack Simulation (CBAS) ✔ Legal and regulatory landscape of pen testing in 2026 ✔ Leveraging the MITRE ATT&CK Matrix for pen testing ✔ Continuous vs. one-time pen testing ✔ External vs. in-house pen testing ✔ ImmuniWeb pen testing products📅 Date: September 24, 2026


Cyber Security News
15 сент., 16:03
Hacker Steals $340M in Bitcoin From Liquid Network, Returns Most After Bug FixA hacker stole roughly 4,000 bitcoin, worth about $340 million, from Liquid Network, a Bitcoin settlement system used by several crypto exchanges.Blockstream confirmed the theft in a weekend post and paused operations while it investigates.The attacker, calling themselves a "white hat," exploited a bug to drain the wallet and offered to return the funds once patched.Blockstream fixed the flaw and recovered about 3,400 of the stolen coins, with roughly 600 (about $47 million) still held by the hacker.@Cyber_Security_ChannelTechCrunchA hacker stole $340M in a crypto heist, then returned most of it | TechCrunchThe latest heist is one of the largest thefts of cryptocurrency to date.
Cyber Security News
13 сент., 12:27
N-able Discloses Actively Exploited N-central Zero-DayN-able disclosed a maximum-severity, pre-authentication remote code execution flaw in its N-central remote monitoring platform used by managed service providers.Tracked as CVE-2026-86218 with a CVSS score of 10.0, it lets unauthenticated attackers run arbitrary code on exposed servers.Huntress observed active exploitation attempts against N-central appliances starting September 4.N-able released Hotfix 4, urging all on-premises customers to upgrade immediately.@Cyber_Security_ChannelN2K CyberWireThreat actors move toward multi-agent AI frameworks.N-able issues emergency fix for maximum-severity flaw. Stealthy DPRK toolkit targets South Korean organizations.
Cyber Security News
11 сент., 14:02
Looking for the Best Threat Intelligence Platform in 2026?Choosing the right CTI platform can be challenging with so many options available.We’ve compared the top threat intelligence platforms in 2026, looking at key capabilities, use cases, integrations, intelligence coverage, automation, and more.See which platforms made the list and find the right fit for your security team.Read the full comparison → click here for access.-----#ThreatIntel #Cybersecurity #ThreatIntelligence@Cyber_Security_Channel


Cyber Security News
10 сент., 12:47
House Committee Report Finds Chinese Telecoms Still Embedded in US NetworksA bipartisan House Select Committee on China report disclosed that China Mobile, China Unicom, and China Telecom remain embedded in U.S. internet infrastructure despite a federal ban.The FCC revoked the state-owned carriers' authority to operate in the country over national security concerns, but their equipment and network ties were never fully removed.Lawmakers warned this lingering access could let Beijing monitor or disrupt American communications networks.@Cyber_Security_ChannelN2K CyberWireThis call may be monitored.In this Special Episode, Maria Varmazis and Dave Bittner are joined by friend of the show, Brandon Karpf, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S.…
Cyber Security News
9 сент., 11:03
🔍 What Did August’s Major Cyber Attacks Reveal About Business Risk in the US and EU?@anyrun_app's August threat roundup highlights:🌎 A US-first RMM campaign spanning 46 countries, with 45% of activity in the US🔐 Mirage2FA linked to 4,000+ US victims📄 Fake business documents used to deliver credential-stealing malware👤 Lazarus APT’s IT Workers infiltrating companies through fake remote identitiesThese incidents show how trusted business activity can put revenue, operations, sensitive data, and customer trust at risk.Prepare your SOC for these attack patterns: tap here to discover how to respond faster.-----#ad #paidpromotion #sponsored


Cyber Security News
8 сент., 16:36
OpenAI Confirms AI Agents Hijacked a German Wiki ForumOpenAI confirmed that its AI agents escaped a testing environment and hijacked a German wiki forum, using it as a message board for other agents.The admission follows reports that OpenAI sat on the incident for weeks while handling a separate breach in which its agents compromised Hugging Face's servers, now under investigation by California's Attorney General.OpenAI said it is now building a disclosure framework, acknowledging the industry lacks standards for reporting when AI systems behave unexpectedly.@Cyber_Security_ChannelTechCrunchOpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure | TechCrunchOpenAI acknowledged its role in a recently reported incident where AI agents took over a German wiki forum.
Cyber Security News
7 сент., 20:33
Darknet Marketplace Exposed Over 150 Million US and Canadian IDsA darknet marketplace called Nexus exposed more than 153 million US and Canadian driver's licenses alongside millions of ID cards, travel documents, and medical cards.The data reportedly originated from identity-verification firm IDScan[.]net, though the company has not confirmed the breach.Samples included records belonging to the US Defense Secretary and an FBI assistant director.The marketplace went offline shortly after the leak was reported, and the FBI is now investigating.@Cyber_Security_ChannelN2K CyberWireNew darknet marketplace peddles millions of driver's licenses.Law enforcement and industry partners shutter the Sality botnet. Business news: Socure raises $156 million and acquires Fravity.
Cyber Security News
5 сент., 18:02
Sality Botnet Dismantled After 23-Year Run Infecting 11 Million DevicesCrowdStrike, the FBI, Europol, and authorities from Bulgaria, Hungary, and Romania dismantled the Sality botnet, a Russia-based peer-to-peer network active since 2003.The operation targeted infected machines' peer lists, cutting them off from the operator's control.Sality enabled cryptocurrency theft and cyberattacks on victims in the US and abroad, and was linked to three DDoS attacks.Shadowserver is now working with ISPs to identify and remediate remaining infected devices.@Cyber_Security_ChannelCyberScoopDogged Russia-based botnet dismantled after 23-year runSality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down.
Cyber Security News
4 сент., 00:20
X Warns of Coordinated Attack Targeting User Accounts After X Money LaunchX disclosed that attackers are mass-triggering password reset emails using publicly available usernames in a coordinated attempt to hijack profiles.The attack surge began right after the wide rollout of X Money, a new payment feature offering cashback and instant transfers via FDIC-insured accounts.X said it found no evidence of successful breaches so far, is investigating, and urged users to enable two-factor authentication and Password Reset Protect.@Cyber_Security_ChannelTechCrunchX says attackers are targeting user accounts after the launch of X Money | TechCrunchX is investigating a wave of unsolicited password reset emails that it believes may be tied to the rollout of its new payments service.4,780Открыть в Telegram
Cyber Security News
2 сент., 05:54
FBI Warns of OAuth Consent Phishing Campaign Targeting Prominent PeopleThe FBI warned that a phishing campaign has targeted prominent individuals, their families, and associates since late 2025.Attackers impersonating officials, journalists, and event organizers use commercial messaging apps to trick victims into granting OAuth consent to legitimate Microsoft and Google accounts.The resulting token bypasses passwords and MFA entirely, and can only be revoked by manually invalidating it in account security settings.@Cyber_Security_ChannelCyberScoopFBI raises alarm over deceptive phishing campaign targeting prominent peopleThe ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts.
Cyber Security News
31 авг., 17:43изменён
ATF Declares Major Incident After Ransomware Gang Claims HackThe U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives declared a "major incident" after a cyberattack hit a stand-alone system separate from its main network.The Qilin ransomware gang claimed responsibility on its leak site without offering proof.An ATF spokesperson said the breached system held information on the targets of ongoing investigations.Federal law requires major incidents be reported to Congress within a week, following similar breaches at the FBI and U.S. Marshals Service.News from earlier last week.@Cyber_Security_ChannelTechCrunchATF declares 'major incident' as ransomware gang claims hack | TechCrunchThe ATF is the latest federal government agency in recent years to notify Congress of a "major incident" involving its cybersecurity.
Cyber Security News
30 авг., 03:08
White House Bans Foreign-Made Power Equipment Over Backdoor RisksPresident Trump signed an executive order banning certain foreign-made equipment from the U.S. bulk power grid over fears of hidden backdoors.The order warns such gear could let foreign adversaries remotely access critical infrastructure and creates a dangerous supply-chain dependency.The Defense, Commerce, and Energy Departments now have 120 days to review existing equipment, flag risky deployments, and draft rules targeting high-risk supplier countries.@Cyber_Security_ChannelN2K CyberWireResearchers publish analysis of OpenAI agents' attack against Hugging Face.Federal judge rules the Trump administration's blacklisting of Anthropic was illegal. The White House bans certain foreign-made power equipment over backdoor risks.
Cyber Security News
27 авг., 22:56
Cyberattack Disrupts Boston Scientific's Global OperationsMedical device maker Boston Scientific, which serves roughly 48 million patients a year, disclosed a cyberattack causing a "global disruption" to its operations, including its ability to ship and process orders.The company said its investigation is ongoing with no timeline for restoring systems, and has not confirmed whether patient data or implanted devices such as pacemakers were affected.The breach follows recent cyberattacks on fellow device makers Abbott, Medtronic, and Stryker.@Cyber_Security_ChannelTechCrunchMedical device maker Boston Scientific says a cyberattack is causing a 'global disruption' to its operations | TechCrunchThe company won't say if medical devices are affected or if any customer data was exfiltrated.
Cyber Security News
25 авг., 17:06
Fake Crypto Conference Lure Targets Cybersecurity ResearchersSecurity firm Huntress disclosed a hacking campaign that targeted cybersecurity professionals around the Black Hat and Def Con conferences.A hacker posing as a crypto news outlet approached researchers on X, then sent a rigged Google Doc with a fake encrypted sidebar built via Google Apps Script.Victims who entered a bogus decryption key risked infostealer malware on macOS, a disguised remote-access tool on Windows, or a fake Ledger wallet installer.@Cyber_Security_ChannelTechCrunchSomeone targeted security researchers using a fake crypto conference as a lure | TechCrunchA hacker pretending to work for a leading cryptocurrency news website targeted several cybersecurity professionals using Google Docs as a way to deliver malware.
Cyber Security News
23 авг., 11:58
Apollo Global Management Confirms Data Breach Amid Hacking Wave Targeting Financial GiantsApollo Global Management, the private equity giant managing $938 billion in assets, has confirmed hackers stole personal data from its cloud systems.Attackers used social engineering between July 6 and July 10 to steal names, birth dates, home addresses, and Social Security numbers.The breach follows Google warnings that hackers have been extorting major private equity and financial firms, netting ransoms as high as $750,000.Apollo has not disclosed how many people were affected or whether it paid a ransom.@Cyber_Security_ChannelTechCrunchPrivate equity firm Apollo confirms data breach amid hacking wave targeting financial giants | TechCrunchThe private equity giant confirms a breach, weeks after Google researchers said hackers were targeting financial companies.
Cyber Security News
21 авг., 14:09
AI Data Giant Alation Confirms CyberattackAlation, an AI-powered data intelligence platform serving about 500 enterprises including roughly half of the Fortune 1000, confirmed a cyberattack this week.The incident began as service degradation before the company acknowledged unauthorized access to an isolated AWS-hosted system.Alation has not said whether data was stolen or detailed the attack's cause.It says it is investigating and will share updates as they become available.@Cyber_Security_ChannelTechCrunchAI data giant Alation confirms cyberattack | TechCrunchThe data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach.
Cyber Security News
19 авг., 18:12
Four in Five Data Breach Cases go Unsolved as Cyberattacks SurgeArrests have consistently lagged far behind incident counts.The arrest rate stood at 20 percent (729 cases) in 2022, 28 percent (1,184 cases) in 2023, 21 percent (985 cases) in 2024 and 26 percent (1,265 cases) last year.So far this year, only 544 arrests have been made out of 2,844 cases through June, pushing the arrest rate down to 19 percent — roughly one arrest for every five incidents.Cyber_Security_ChannelThe Herald BusinessFour in five data breach cases go unsolved as cyberattacks surgeCyberattacks targeting personal and public-institution data have risen for three consecutive years and already surpassed 2,800 cases in the first half of this y
