cybersecurity news

A newly disclosed class of vulnerabilities, dubbed GitSpawn, allows a booby-trapped repository to silently execute code on a developer’s machine the moment it is… A newly disclosed WhatsApp flaw on Android is https://rogerdmoore.ca/ai-main/ai-for-cybersecurity raising fresh privacy alarms, allowing anyone holding a locked phone to browse through its entire photo…

Get the latest news, expert insights, exclusive resources, and strategies from industry leaders, all for free. 11 years of practitioner data on what it takes to keep pace with a field that keeps shifting. According to CrowdStrike, the e-crime group is operating out of Brazil and has been active since September 2023, monetizing their intrusions by gaining unauthorized access to internal payment systems and carrying out fraudulent transactions. Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. „Cybercriminals, botnets, and malware are a clear and present danger to our nation’s security and economy,” said First Assistant United States Attorney Bill Essayli. Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.

cybersecurity news

„JFrog Artifactory https://travelusanews.com/how-artificial-intelligence-will-make-travel-platforms-better-in-2024.html contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges,” according to a description of the flaw on CVE.org. The unauthenticated file upload flaw allows an anonymous user to write arbitrary .xsl or .zip formatter files to the GeoNetwork f… Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. SonicWall said it has „investigated a case indicating the active exploitation of the vulnerabilities,” suggesting th… Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the agent runs on the developer’s machine, four of them still unpatched at publication.

WhatsApp Video Call Flaw Lets Anyone Bypass Your Android Lock Screen and View Your Photos

  • Dropbox has disclosed that approximately 5,000 user accounts were compromised in August after attackers exploited a weakness involving its Lenovo ID sign-in integration.
  • The Windows maker has assessed with moderate confidence that the campaign is consistent with a Chinese threat cluster dubbed Silver Fox (aka Yinhu), which has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT (a…
  • Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.
  • The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR.
  • „There is little doubt that StreamRat is a new and technically sophisticated threat, developed by individuals with prior experience in the Android malware ecosystem,” ThreatFabric said in its StreamRat analysis .

Virtualizor released Patch 9 with a Security Analyzer on September 1, but the vendor said cryptographic package signing remained future work. Fixes have shipped for goose, Claude Code, and Cursor, while Hermes Agent, Qwen Code, Grok Build, and a second path in Claude Code were still executing repository-supplied commands when Manifold retested them on September 1. The Windows maker has assessed with moderate confidence that the campaign is consistent with a Chinese threat cluster dubbed Silver Fox (aka Yinhu), which has a track record of using spoofed vendor download pages to distribute Gh0st RAT and ValleyRAT (a… The program is available to a group of Google Cloud customers, government agencies, and cybersecurity partners. Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has https://iwantmyopenid.org/2022/11 made it available to a set of trusted defenders via a new initiative called the Fairwind Program .

cybersecurity news

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

  • Ransomware operators are using a previously undocumented remote-control framework called TukTuk to steal credentials, watch compromised machines, and weaken protections.
  • „JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges,” according to a description of the flaw on CVE.org.
  • A Russian national has been indicted in the United States over an alleged malware operation that targeted roughly 80,000 freelance workers worldwide.
  • 11 years of practitioner data on what it takes to keep pace with a field that keeps shifting.
  • SonicWall said it has „investigated a case indicating the active exploitation of the vulnerabilities,” suggesting th…

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. „So defenders have an early advantage, to help them protect vital infrastructure – which in turn protects people who rely on those systems.” The tech giant said it’s currently working with over 650 partners globally, including CrowdStrike, Datadog, Menlo Security, Palo Alto Networks, and Snowflake. A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities. The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information. The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash.