The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. This article has been indexed from SecurityWeek Read the original article: Google Adopts New Threat Actor Naming System
China Chipmakers See Profits Surge 2,579.5 Percent
AI boom hits mainland China in first half of 2026, fuelling massive surge in profits as companies race to build data centres This article has been indexed from Silicon UK Read the original article: China Chipmakers See Profits Surge 2,579.5…
Five Progress LoadMaster Flaws Let Attackers Execute Commands and Gain Root Access
Progress has addressed five serious vulnerabilities affecting Kemp LoadMaster, ECS Connection Manager, and Connection Manager for ObjectScale appliances. These vulnerabilities, tracked as CVE-2026-59686 through CVE-2026-59690, impact several older product releases and could lead to complete appliance compromise when exploited by…
Drone Follows Police Scotland Helicopter At Close Range
Drone passes within 50 feet of police helicopter, continues to follow it for about a minute in latest unmanned vehicle incident This article has been indexed from Silicon UK Read the original article: Drone Follows Police Scotland Helicopter At Close…
U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited…
PortSwigger Launches Burp AT Agentic AI for Human-Led Web Penetration Testing
PortSwigger has officially launched Burp AT in public beta, bringing agentic AI capabilities directly into Burp Suite Professional for the first time. The new feature allows penetration testers to delegate specific investigative tasks to AI agents while retaining full control…
LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another account. This technique was published by the Nightmare-Eclipse disclosure…
Microsoft Teams Vishing Attack Uses Quick Assist to Deploy GoGRPC Backdoor
A new Microsoft Teams vishing campaign is using fake IT support calls to gain remote access to corporate systems. The attackers then deploy GoGRPC, a Go-based backdoor that can run commands, collect system details, and maintain access to compromised devices.…
Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools. This article has been indexed from Securelist Read the original article: Mirage Kitten targets Middle East and Africa…
Multiple FFmpeg Vulnerabilities Allow Attackers to Corrupt Memory Via Malicious Video File
Multiple high-severity vulnerabilities have been identified in FFmpeg, the widely used open-source multimedia framework. These flaws impact media parsing, decoding, filtering, and encoding components and can be triggered when an application processes malicious files. Several issues can lead to heap…
Apple Delays First Smart Glasses to WWDC 2027 Over Privacy Concerns
Apple has postponed the reveal of its first smart glasses to WWDC in June 2027, with sales anticipated later that year, according to Bloomberg analyst Mark Gurm Thank you for being a Ghacks reader. This article has been indexed from…
Operation STANDOFF Hides Command-and-Control Traffic Behind GitHub Redirects
Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise. Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet components, while operators can later focus on selected victims for direct network intrusion.…
Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks
A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) operations. Dysphoria’s evolution has been unusually aggressive, transitioning from early…
SpaceX Starship Rocket Splashes Down After Successful Test
Forty-storey-tall Starship vessel carries out sub-orbital flight and splashes down in Indian Ocean in latest test This article has been indexed from Silicon UK Read the original article: SpaceX Starship Rocket Splashes Down After Successful Test
Top 10 Best VPN Alternatives For Secure Remote Access in 2026
In the rapidly evolving landscape of 2026, the traditional VPN is increasingly showing its age. While a VPN creates a secure, encrypted tunnel to a private network, it often functions like an “all-access key,” granting users broad, undifferentiated access once…
AutoIT Payload Injector , (Tue, Jul 28th)
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote…
PortSwigger Introduces Burp AT Agentic AI for Automated Penetration Testing
PortSwigger has launched Burp AT, an agentic AI system that allows penetration testers to delegate web security investigation tasks while maintaining direct control over the testing scope, approvals, and final conclusions. The public beta is currently available for Burp Suite…
Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data
Nvidia opens the AI security tent Microsoft puts a cyber sprinter in MDASH Fairlife ransomware spills data Get the show notes here: https://cisoseries.com/cybersecurity-news-nvidia-opens-ai-security-tent-microsoft-adds-cyber-sprinter-to-mdash-fairlife-ransomware-spills-data/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and…
Unpatched Fastjson Vulnerability Exploited in Attacks
The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. This article has been indexed from SecurityWeek Read the original article: Unpatched Fastjson Vulnerability Exploited in Attacks
Command Injection Cheatsheet: OS Payloads And Prevention (2026)
OS Command Injection is a critical vulnerability (CWE-78) where an attacker executes arbitrary operating system commands via a… This article has been indexed from Hackers Online Club Read the original article: Command Injection Cheatsheet: OS Payloads And Prevention (2026)
Shein Sees $99m Loss Ahead Of Hong Kong IPO
China-founded e-commerce company sees US market contract, falls to loss in first quarter as it prepares to list in Hong Kong This article has been indexed from Silicon UK Read the original article: Shein Sees $99m Loss Ahead Of Hong…
Houston City College – 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from the college was later published publicly and included 832k unique email addresses along with names, addresses, phone numbers, academic…
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor
An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an…
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. This article has been indexed from SecurityWeek Read the original article: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day