By Yogesh Ranade from Palo Alto Networks, and Senthil Ramakrishnan from AT&T The digital world is currently navigating a dual-speed revolution. Acceleration of AI and hyperconnectivity is unlocking unprecedented economic value. The … The post Palo Alto Networks and AT&T…
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
FortiGuard Labs analyzes a global phishing campaign using obfuscated JScript, disguised .ttf files, and Lua loaders to deliver RATs and infostealers. This article has been indexed from FortiGuard Labs Threat Research Read the original article: The TTF Trap: A…
Adaptiva simplifies secure patch management for air-gapped networks
Adaptiva has announced AirGap for OneSite Patch, a new capability that extends autonomous patch management to air-gapped environments. Developed in response to growing demand from government agencies, critical infrastructure operators, and large enterprises managing highly secure environments, AirGap for OneSite…
Scattered Spider members jailed over Transport for London hack that cost £29 million
Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters and cost the transport…
Millions of Shark Robot Vacuums Vulnerable to Unpatched Remote Code Execution Flaw
Millions of internet-connected Shark robot vacuums may be vulnerable to a critical remote code execution (RCE) flaw that could allow attackers to control devices remotely, access onboard cameras, retrieve home maps, and potentially steal stored Wi-Fi credentials. An independent researcher…
Two Scattered Spider Hackers Sentenced to Jail in UK
Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL). The post Two Scattered Spider Hackers Sentenced to Jail in UK appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the…
CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance
On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post explaining how…
New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password
ClickLock Stealer, a new macOS infostealer, answers a victim’s refusal by killing their apps on a loop until they hand over the login password. It arrives as a command pasted into Terminal, asks for the password behind a fake system…
New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that’s been spreading via websites infected with ClickFix lures since late April 2026. “The malware is full-featured, lightweight, and modular,” Elastic Security Labs researcher Cyril François said in…
Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers This article has been indexed from www.infosecurity-magazine.com Read the original article: Single Prompt Enables ChatGPT to…
Modular macOS Stealer Uses Kill Loops to Force Password Entry
New ClickLock macOS stealer locked victims out of their own system until they surrendered a password This article has been indexed from www.infosecurity-magazine.com Read the original article: Modular macOS Stealer Uses Kill Loops to Force Password Entry
New Framework Redefines AI Penetration Testing Around Prompt Injection and Behavioral Objective Violations
A newly proposed framework argues that AI penetration testing must move beyond conventional infrastructure compromise and assess whether an adversary can make an AI-enabled system act against its intended operational purpose. Traditional penetration testing typically measures compromise through outcomes such…
Hackers Exploit SonicWall SMA1000 Zero-Days to Execute Commands as Root
Hackers are actively exploiting two zero-day vulnerabilities in the SonicWall SMA 1000 Series remote access appliances. They are chaining a critical server-side request forgery flaw with a local code injection bug to execute commands with root privileges. Rapid7’s Managed Detection…
Specter Turns Your Flipper Zero Into a Pocket Skimmer Detector
A new Flipper Zero app called Specter aims to turn the handheld device into a passive counter-surveillance tool for finding active 13.56 MHz NFC readers, including potentially suspicious readers hidden near payment terminals, access-control panels, desks, or other equipment. Unlike…
JetBrains Patched 6 Vulnerabilities Across TeamCity, YouTrack and IntelliJ IDEA
JetBrains has addressed six security vulnerabilities in its software development and project management products. The affected applications include IntelliJ IDEA, TeamCity, and YouTrack. The most critical vulnerability, tracked as CVE-2026-59792, is an improper path handling (CWE-23) flaw that could allow…
WhatsApp GhostPairing Lets Scammers Hijack Accounts Without Stealing Passwords
WhatsApp users are being targeted by a social-engineering technique called GhostPairing that can give scammers access to an account without requiring a password or one-time verification code. Instead of breaking into the service directly, the scam abuses WhatsApp’s legitimate device-linking…
Hackers Don’t Crack Telegram 2FA—They Copy Your Already Logged-In Session
A macOS information-stealing malware is turning stolen Telegram desktop data into immediate account access. Instead of guessing passwords or breaking two-factor authentication, it copies the local files that prove a user has already logged in. When those files are restored…
Brit Scattered Spider duo handed tickets to prison over Transport for London attack
Sentencing bookends the biggest cybercrime conviction in UK history This article has been indexed from www.theregister.com – Articles Read the original article: Brit Scattered Spider duo handed tickets to prison over Transport for London attack
‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. The post ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read…
AI Data Centers Are Being Built Faster Than They Can Be Secured
AI infrastructure introduces new security risks that traditional data center designs were never built to handle. The post AI Data Centers Are Being Built Faster Than They Can Be Secured appeared first on SecurityWeek. This article has been indexed from…
CISA Orders Feds to Patch Oracle Flaw
The Cybersecurity and Infrastructure Security Agency has issued an emergency directive requiring federal agencies to patch a critical vulnerability in Oracle E-Business Suite financial applications by Saturday. This article has been indexed from CyberMaterial Read the original article: CISA Orders…
AWS CloudFront outage disrupts multiple services
Amazon Web Services suffered a significant CloudFront outage on the morning of the incident, beginning at 0945 UTC and affecting customers using VPC Origins. This article has been indexed from CyberMaterial Read the original article: AWS CloudFront outage disrupts multiple…
CISA urges vendors to formalize vulnerability disclosure
The Cybersecurity and Infrastructure Security Agency (CISA) and four international partners have released guidance calling on software manufacturers and online service providers to formalize coordinated vulnerability disclosure (CVD) programs. This article has been indexed from CyberMaterial Read the original article:…
Telegram t.me links disrupted over sanctioned VPN
Telegram’s widely used t.me shortlinks experienced a complete outage lasting roughly one day after the .ME domain registry suspended the domain in response to US sanctions targeting a VPN service popular with cybercriminals. This article has been indexed from CyberMaterial…