-
Recon-only activity on SSH is not harmless background noise. A recent honeypot session shows an automated Go-based bot logging in as root, exhaustively grading host hardware for cryptomining suitability, then exiting without dropping a single binary. C…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
PHP maintainers have released security updates to address three vulnerabilities affecting the PostgreSQL, BCMath, and Phar extensions. These vulnerabilities could potentially lead to SQL injection attacks, out-of-bounds memory writes, and denial-of-ser…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Chinese-speaking threat actor “knaithe” (aka KnYuan) has been caught running an AI-enabled autonomous attack stack built around DeepSeek and the Hermes Agent framework, proving that large language models can now drive end‑to‑end offensive operations wi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A cloud-security blind spot known as Cloud ShutterGap, which involves millions of AWS resources being briefly exposed to the public before being removed, often within minutes. These short-lived misconfigurations can include Amazon RDS and DocumentDB sn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Astaroth operators have expanded their Brazilian banking malware operations by weaponizing a new WhatsApp Web spambot module that turns infected hosts into automated malware relays, marking a significant evolution of the LATAM e-crime ecosystem. Tradit…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert to the Water and Wastewater Systems (WWS) Sector due to a significant rise in cyber threat activity targeting internet-exposed programmable logic controllers (P…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability chain in Azure Cosmos DB, named CosmosEscape, allowed attackers to gain full read and write access to every Cosmos DB database, including potentially those managed internally by Microsoft. The issue specifically affected the se…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OctLurk and SilkLurk are highly customized, memory‑resident backdoors used in an ongoing cyberespionage campaign against government and critical‑sector networks across Central Asia and Syria, operated by a Chinese‑speaking threat actor but not yet link…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Analog Devices, Inc. has confirmed that unauthorized actors gained access to certain company systems and exfiltrated files. The semiconductor manufacturer detected the cyber incident on June 23, 2023, and immediately activated its incident response pro…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic has disclosed that three Claude AI models gained unauthorized access to the production systems of three real-world organizations during cybersecurity capability evaluations. These incidents resulted from a misconfiguration in a third-party te…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


