APT28's attacks rely on specially crafted Microsoft Rich Text Format (RTF) documents to kick off a multistage infection chain to deliver malicious payloads.
0
Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days
Thứ Ba, 3 tháng 2, 2026
Việt Nam Hacker
0
GlassWorm Malware Returns to Shatter Developer Ecosystems
Việt Nam Hacker
The self-replicating malware has poisoned a fresh set of Open VSX software components, leaving potential downstream victims with infostealer infections.
0
8-Minute Access: AI Accelerates Breach of AWS Environment
Việt Nam Hacker
The AI-assisted attack, which started with exposed credentials from public S3 buckets, rapidly achieved administrative privilges.
0
Dark Patterns Undermine Security One Click at a Time
Việt Nam Hacker
People trust organizations to do the right thing, but websites’ and apps’ dark patterns pose a hidden threat that can lead to inadequate security behaviors.
0
County Pays $600K to Wrongfully Jailed Pen Testers
Thứ Hai, 2 tháng 2, 2026
Việt Nam Hacker
Iowa police arrested two penetration testers in 2019 for doing their jobs, highlighting the risk to security professionals in red teaming exercises.
0
Chinese Hackers Hijack Notepad++ Updates for 6 Months
Việt Nam Hacker
State-sponsored threat actors compromised the popular code editor's hosting provider to redirect targeted users to malicious downloads.
0
ShinyHunters Expands Scope of SaaS Extortion Attacks
Việt Nam Hacker
Following its attacks on Salesforce instances last year, members of the cybercrime group have broadened their targeting and gotten more aggressive with extortion tactics.
0
Torq Moves SOCs Beyond SOAR With AI-Powered Hyper Automation
Thứ Bảy, 31 tháng 1, 2026
Việt Nam Hacker
Investors poured $140 million into Torq's Series D Round, bringing the startup's valuation to $1.2 billion, to bring AI-based "hyper automation" to SOCs.
0
Out-of-the-Box Expectations for 2026 Reveal a Grab-Bag of Risk
Thứ Sáu, 30 tháng 1, 2026
Việt Nam Hacker
Security teams need to be thinking about this list of emerging cybersecurity realities, to avoid rolling the dice on enterprise security risks (and opportunities).
0
Tenable Tackles AI Governance, Shadow AI Risks, Data Exposure
Việt Nam Hacker
The Tenable One AI Exposure add-on discovers unsanctioned AI use in the organization and enforces policy compliance with approved tools.
0
OpenClaw AI Runs Wild in Business Environments
Việt Nam Hacker
The popular open source AI assistant (aka ClawdBot, MoltBot) has taken off, raising security concerns over its privileged, autonomous control within users' computers.
0
From Quantum to AI Risks: Preparing for Cybersecurity's Future
Thứ Năm, 29 tháng 1, 2026
Việt Nam Hacker
As 2026 begins, these journalists urge the cybersecurity industry to prioritize patching vulnerabilities, preparing for quantum threats, and refining AI applications, in the latest edition of Reporters' Notebook.
0
More Critical Flaws on n8n Could Compromise Customer Security
Việt Nam Hacker
A new around of vulnerabilities in the popular AI automation platform could let attackers hijack servers and steal credentials.
0
'Semantic Chaining' Jailbreak Dupes Gemini Nano Banana, Grok 4
Việt Nam Hacker
If an attacker splits a malicious prompt into discrete chunks, some large language models (LLMs) will get lost in the details and miss the true intent.
0
Months After Patch, WinRAR Bug Poised to Hit SMBs Hardest
Thứ Tư, 28 tháng 1, 2026
Việt Nam Hacker
Russian and Chinese nation-state attackers are exploiting a months-old WinRAR vulnerability, despite a patch that came out last July.
0
Consumers Reluctant to Shop at Stores That Don't Take Security Seriously
Việt Nam Hacker
The retail sector must adapt as consumers become more cybersecurity-conscious. Increased attack transparency is a good place to start.
0
Fortinet Confirms New Zero-Day Behind Malicious SSO Logins
Việt Nam Hacker
To stop the ongoing attacks, the cybersecurity vendor took the drastic step of temporarily disabling FortiCloud single sign-on (SSO) authentication for all devices.
0
China-Backed 'PeckBirdy' Takes Flight for Cross-Platform Attacks
Việt Nam Hacker
In two separate campaigns, attackers used the JScript C2 framework to target Chinese gambling websites and Asian government entities with new backdoors.
0
Critical Telnet Server Flaw Exposes Forgotten Attack Surface
Thứ Ba, 27 tháng 1, 2026
Việt Nam Hacker
While telnet is considered obsolete, the network protocol is still used by hundreds of thousands of legacy systems and IoT devices for remote access.
0
'Stanley' Toolkit Turns Chrome Into Undetectable Phishing Vector
Việt Nam Hacker
The malware-as-a-service kit enables malicious extensions to overlay pages on real websites without changing the visible URL, signaling a fresh challenge for enterprise security.
0
Hand CVE Over to the Private Sector
Việt Nam Hacker
How MITRE has mismanaged the world's vulnerability database for decades and wasted millions along the way.
0
Sandworm Blamed for Wiper Attack on Poland Power Grid
Thứ Hai, 26 tháng 1, 2026
Việt Nam Hacker
Researchers attributed the failed attempt to the infamous Russian APT Sandworm, which is notorious for wiper attacks on critical infrastructure organizations.
0
Dark Reading Confidential: Reviving the Hacker Ethos That Built Cybersecurity
Việt Nam Hacker
Dark Reading Confidential Episode 14: How curious, ethical problem-solving can continue to serve as a guiding principle for an evolving cybersecurity sector.
0
DPRK's Konni Targets Blockchain Developers With AI-Generated Backdoor
Việt Nam Hacker
The North Korean threat group is using a new PowerShell backdoor to compromise development environments and target cryptocurrency holdings, according to researchers.
0
2025 Was a Wake-Up Call to Protect Human Decisions, Not Just Systems
Thứ Bảy, 24 tháng 1, 2026
Việt Nam Hacker
Cybersecurity must shift from solely protecting systems to safeguarding human decision-making under uncertainty and system failures.
0
Europe's GCVE Raises Concerns Over Fragmentation in Vulnerability Databases
Việt Nam Hacker
GCVE would enhance global collaboration, flexibility, and efficiency in tracking security flaws. Duplicate entries and a decentralization policy may create more chaos for defenders.
0
Exploited Zero-Day Flaw in Cisco UC Could Affect Millions
Thứ Sáu, 23 tháng 1, 2026
Việt Nam Hacker
Mass scanning is underway for CVE-2026-20045, which Cisco tagged as critical because successful exploitation could lead to a complete system takeover.
0
Dark Reading Confidential: Reviving the Hacker Ethos That Built Cybersecurity
Việt Nam Hacker
Dark Reading Confidential Episode 14: How curious, ethical problem solving can continue to serve as a guiding principle for an evolving cybersecurity sector.
0
Healthy Security Cultures Thrive on Risk Reporting
Việt Nam Hacker
The signs of an effective security culture are shifting as companies call on CISOs and security teams to raise their hands unabashedly.
0
Risky Chinese Electric Buses Spark Aussie Gov't Review
Thứ Năm, 22 tháng 1, 2026
Việt Nam Hacker
Deployed across Australia and Europe, China's electric buses are vulnerable to cybercriminals and sport a virtual kill switch the Chinese state could activate.
0
Fortinet Firewalls Hit With Malicious Configuration Changes
Việt Nam Hacker
Automated infections of potentially fully patched FortiGate devices are allowing threat actors to steal firewall configuration files.
0
From a Whisper to a Scream: Europe Frets About Overreliance on US Tech
Việt Nam Hacker
Concern is growing across Europe about relying on US cybersecurity companies, and Greenland takeover talk is eroding trust across the EU even further.
0
DPRK Actors Deploy VS Code Tunnels for Remote Hacking
Việt Nam Hacker
A spear-phishing campaign tied to the Democratic People's Republic of Korea (DPRK) uses trusted Microsoft infrastructure to avoid detection.
0
AI Agents Undermine Progress in Browser Security
Việt Nam Hacker
Web browser companies have put in substantial effort over the last three decades to strengthen the browser security stack to withstand abuses. Agentic browsers are undoing all that work.
0
'Contagious Interview' Attack Now Delivers Backdoor Via VS Code
Thứ Tư, 21 tháng 1, 2026
Việt Nam Hacker
Once trust is granted to the repository's author, a malicious app executes arbitrary commands on the victim's system with no other user interaction.
0
Phishing Campaign Zeroes in on LastPass Customers
Việt Nam Hacker
The bait incudes plausible subject lines and credible messages, most likely thanks to attackers' use of large language models to craft them.
0
'Damn Vulnerable' Training Apps Leave Vendors' Clouds Exposed
Việt Nam Hacker
Hackers are already leveraging these over-permissioned programs to access the IT systems of major security vendors.
0
'CrashFix' Scam Crashes Browsers, Delivers Malware
Thứ Ba, 20 tháng 1, 2026
Việt Nam Hacker
The attack consists of a NexShield malicious browser extension, a social engineering technique to crash the browser, and a Python-based RAT.
0
Mass Spam Attacks Leverage Zendesk Instances
Việt Nam Hacker
The CRM vendor advised ignoring or deleting suspicious emails and said the attacks were not tied to any breach or software vulnerability.
0
Vulnerabilities Threaten to Break Chainlit AI Framework
Việt Nam Hacker
Familiar bugs in a popular open source framework for AI chatbots could give attackers dangerous powers in the cloud.
0
Microsoft & Anthropic MCP Servers At Risk of RCE, Cloud Takeovers
Việt Nam Hacker
Researchers found the popular model context protocol (MCP) servers, which are integral components of AI services, carry serious vulnerabilities.
0
ChatGPT Health Raises Big Security, Safety Concerns
Thứ Hai, 19 tháng 1, 2026
Việt Nam Hacker
ChatGPT Health promises robust data protection, but elements of the rollout raise big questions regarding user security and safety.
0
More Problems for Fortinet: Critical FortiSIEM Flaw Exploited
Thứ Sáu, 16 tháng 1, 2026
Việt Nam Hacker
CVE-2025-64155, a command injection vulnerability, was disclosed earlier this week and quickly came under attack from a variety of IP addresses.
0
CISOs Rise to Prominence: Security Leaders Join the Executive Suite
Việt Nam Hacker
Security professionals are moving on up the executive ranks as enterprises face rising regulatory and compliance standards.
0
AI System Reduces Attack Reconstruction Time From Weeks to Hours
Việt Nam Hacker
Pacific Northwest National Labs' expert cybersecurity system, ALOHA, can recreate attacks and test them against organizations' infrastructure to bolster defense.
0
Winter Olympics Could Share Podium With Cyberattackers
Thứ Năm, 15 tháng 1, 2026
Việt Nam Hacker
The upcoming Winter Games in the Italian Alps are attracting both hacktivists looking to reach billions of people and state-sponsored cyber-spies targeting the attending glitterati.
0
Microsoft Disrupts Cybercrime Service RedVDS
Thứ Tư, 14 tháng 1, 2026
Việt Nam Hacker
RedVDS, a cybercrime-as-a-service operation that has stolen millions from victims, lost two domains to a law enforcement operation supported by Microsoft.
0
Retail, Services Industries Under Fire in Oceania
Việt Nam Hacker
Last year in Australia, New Zealand, and the South Pacific, Main Street businesses like retail and construction suffered more cyberattacks than their critical sector counterparts.
0
Secure Your Spot at RSAC 2026 Conference
Việt Nam Hacker
0
'VoidLink' Malware Poses Advanced Threat to Linux Systems
Việt Nam Hacker
Researchers discovered a modular, "cloud-first" framework that is feature-rich and designed to maintain stealthy, long-term access to Linux environments.
0
CISO Succession Crisis Highlights How Turnover Amplifies Security Risks
Thứ Ba, 13 tháng 1, 2026
Việt Nam Hacker
0
'Most Severe AI Vulnerability to Date' Hits ServiceNow
Việt Nam Hacker
ServiceNow tacked agentic AI onto a largely unguarded legacy chatbot, exposing customers' data and connected systems.
0
Microsoft Starts 2026 With a Bang: A Freshly Exploited Zero-Day
Việt Nam Hacker
The vendor's first Patch Tuesday of the year also contains fixes for 112 CVEs, nearly double the amount from last month.
0
Shadow#Reactor Uses Text Files to Deliver Remcos RAT
Việt Nam Hacker
Attackers use a sophisticated delivery mechanism of text-only files for RAT deployment, showcasing a clever way to bypass defensive tools and rely on the target's own utilities.
0
GoBruteforcer Botnet Targets 50K-plus Linux Servers
Thứ Hai, 12 tháng 1, 2026
Việt Nam Hacker
Researchers detailed a souped-up version of the GoBruteforcer botnet that preys on servers with weak credentials and AI-generated configurations.
0
FBI Flags Quishing Attacks From North Korean APT
Việt Nam Hacker
A state-sponsored threat group tracked as "Kimsuky" sent QR-code-filled phishing emails to US and foreign government agencies, NGOs, and academic institutions.
0
Hexnode Moves into Endpoint Security With Hexnode XDR
Việt Nam Hacker
0
Two Separate Campaigns Target Exposed LLM Services
Việt Nam Hacker
A total of 91,403 sessions targeted public LLM endpoints to find leaks in organizations' use of AI and map an expanding attack surface.
0
Deepfake Fraud Tools Are Lagging Behind Expectations
Thứ Sáu, 9 tháng 1, 2026
Việt Nam Hacker
Deepfakes are becoming more realistic and more popular. Luckily, defenders are still ahead in the arms race.
0
Illicit Crypto Economy Surges as Nation-States Join in the Fray
Việt Nam Hacker
Cybercriminal cryptocurrency transactions totaled billions in 2025, with activity from sanctioned countries like Russia and Iran causing the largest jump.
0
Maximum Severity HPE OneView Flaw Exploited in the Wild
Thứ Năm, 8 tháng 1, 2026
Việt Nam Hacker
Exploitation of CVE-2025-37164 can enable remote code execution on HPE's IT infrastructure management platform, leading to devastating consequences.
0
Fake AI Chrome Extensions Steal 900K Users' Data
Việt Nam Hacker
Threat actors ripped off a legitimate AI-powered Chrome extension in order to harvest ChatGPT and DeepSeek data before sending it to a C2 server.
0
ChatGPT's Memory Feature Supercharges Prompt Injection
Việt Nam Hacker
0
Here's What Cloud Security's Future Holds for the Year Ahead
Việt Nam Hacker
Here are the top cloud security trends I'm seeing in my crystal ball for the New Year — particularly arming us for AI adoption.
0
Phishers Exploit Office 365 Users Who Let Their Guard Down
Thứ Tư, 7 tháng 1, 2026
Việt Nam Hacker
Microsoft said that Office 365 tenants with weak configurations and who don't have strict anti-spoofing protection enabled are especially vulnerable.
0
Lack of MFA is Common Thread in Vast Cloud Credential Heist
Việt Nam Hacker
An emerging threat actor that goes by "Zestix" used an assortment of infostealers to obtain credentials and breach file-sharing instances of approximately 50 enterprises.
0
Cyberattacks Likely Part of Military Operation in Venezuela
Việt Nam Hacker
Cyber's role in the US raid on Venezuela remains a question, though President Trump alluded to "certain expertise" in shutting down the power grid in Caracas.
0
Scattered Lapsus$ Hunters Snared in Cyber Researcher Honeypot
Thứ Ba, 6 tháng 1, 2026
Việt Nam Hacker
Scattered Lapsus$ Hunters, also known as ShinyHunters, were drawn in using a realistic, yet mostly fake, dataset.
0
Startup Trends Shaking Up Browsers, SOC Automation, AppSec
Việt Nam Hacker
In 2025, these startups have reimagined browser security, pioneered application security for AI-generated code, and are building consensus on agentic vs. human costs.
0
Critical 'MongoBleed' Bug Under Active Attack, Patch Now
Thứ Hai, 5 tháng 1, 2026
Việt Nam Hacker
A memory leak security vulnerability allows unauthenticated attackers to extract passwords and tokens from MongoDB servers.
0
US Cyber Pros Plead Guilty Over BlackCat Ransomware Activity
Việt Nam Hacker
Two US citizens pleaded guilty to working as ALPHV/BlackCat ransomware affiliates in 2023, and both were previously employed by prominent security firms.
0
When the Cloud Rains on Everyone's IoT Parade
Việt Nam Hacker
What happens to all of those always-connected devices when the cloud goes down? Disruptions to sleep, school, and smart homes, just to name a few issues.
0
RondoDox Botnet Expands Scope With React2Shell Exploitation
Việt Nam Hacker
Recent attacks are targeting Next.js servers and pose a significant threat of cryptomining, botnet payloads, and other malicious activity to IoT networks and enterprises.
0
CTO New Year Resolutions for a More Secure 2026
Thứ Sáu, 2 tháng 1, 2026
Việt Nam Hacker
From securing MCPs and supply chain defenses to formal AI and quantum governance, experts share their wish lists for cyber safety in 2026.
Đăng ký:
Nhận xét (Atom)
