NEW#1250
Huntressabout 3 hours ago6 min▣LLM reportmedium Attackers are shifting from network perimeter breaches to identity compromise, leveraging stolen credentials and session tokens to access consolidated SSO environments. MFA alone is insufficient; gaps like overprivileged accounts, unmonitored session tokens, and MFA exceptions create exploitable paths. The article describes ClickFix social engineering and a real-world BEC case to illustrate the impact of identity security gaps.
NEW#1249
Canadian Centre for Cyber Securityabout 11 hours ago3 min▣LLM reporthigh The Canadian Centre for Cyber Security published three security advisories on August 25, 2026. The advisories cover a Remote Code Execution vulnerability in Gitea (CVE-2026-60004) added to the CISA KEV database, multiple vulnerabilities in OpenSSL across various branches, and vulnerabilities in WatchGuard Agent. Users and administrators are encouraged to apply available updates.
NEW#1248
CISAabout 11 hours ago4 min▣LLM reporthigh Rently Smart Home versions 20.1.0 and prior contain an insufficiently protected credentials vulnerability (CVE-2026-75960). Exploitation allows an attacker to retrieve sensitive pins, including the Master Pin, and override standard user permissions. The vendor has patched the vulnerability in late June.
NEW#1247
CISAabout 11 hours ago9 min▣LLM reportcritical CISA published an ICS advisory disclosing eleven vulnerabilities in the Ebyte NE2-D11 industrial gateway device running firmware FW-9167-0-11. Three CVEs are rated CVSS 9.8 Critical, covering missing authentication, client-side authentication bypass, and cleartext MQTT credential transmission. No patch is available; the vendor acknowledged the reports but has not provided remediation. Attackers can exploit these flaws remotely without authentication to gain administrative control, intercept credentials, hijack sessions, and disrupt device operation.
NEW#1246SSpiderlabsabout 15 hours ago6 min▣LLM reporthigh A July 2026 cyber incident disrupted operations at a small UK electricity generator for several days, with media reports attributing the activity to Iran-linked actors. However, public technical evidence detailing the intrusion vector, malware, or specific threat actor remains unavailable. The incident highlights a broader trend of state and state-linked actors targeting exposed operational technology (OT) and industrial control systems (ICS), particularly internet-facing PLCs, to achieve physical operational disruption.
NEW#1245
Recorded Futureabout 15 hours ago5 min▣LLM reporthigh Mexico's 2025-2030 National Cybersecurity Plan addresses a complex threat landscape dominated by ransomware, state-sponsored espionage, and financial malware. The plan outlines a six-phase roadmap to build governance, establish a National Cybersecurity Operations Center, and pass new legislation. Insikt Group assesses that while the plan is ambitious, Mexico's progress depends on institutional capacity-building and sustained international cooperation.
NEW#1244
CISAabout 15 hours ago11 min▣LLM reporthigh CISA conducted simultaneous red team assessments at two critical infrastructure organizations using similar tradecraft. The red team achieved full domain compromise at both organizations by exploiting ADCS misconfigurations, excessive Machine Account Quota settings, cleartext credentials, and overly permissive Entra ID application permissions. Organization A failed to detect the activity due to untuned EDR alerts and organizational silos, while Organization B rapidly triaged and isolated compromised systems. Both organizations lacked Conditional Access policies for workload identities and mature processes for revoking compromised cloud tokens.
NEW#1243
Trail of Bitsabout 18 hours ago7 min▣LLM reporthigh A state divergence bug in Provenance Blockchain's marker module allowed any user to bypass access control checks on non-fixed supply markers. The authorization function accountControlsAllSupply compared a stale stored supply field (always zero for non-fixed markers) against the caller's balance, producing an unconditionally true result when both were zero. This let an attacker grant themselves admin, mint, and withdraw permissions in a single transaction, then mint arbitrary tokens or drain escrowed assets in a second transaction. 82 markers on mainnet were affected, with approximately $500,000 in escrowed nhash at direct risk.
NEW#1242
Palo Alto Networksabout 18 hours ago11 min▣LLM reportmedium Unit 42 analyzed 405 AI-enabled malware samples and found that only 12 (3%) appeared on production endpoints, while 97% existed solely in research repositories and sandboxes. The 12 production samples span five families: FunkSec ransomware, a trojanized AI application (Recipe Lister), Oyster backdoor, Rhadamanthys stealer, and a COM hijacking DLL. Existing behavioral detection, sandbox detonation, code-signing anomaly detection, and entropy analysis caught all production samples without requiring novel detection approaches. AI influences malware authoring velocity but does not alter runtime behavior or evade current defensive frameworks.
NEW#1241
ANY.RUNabout 18 hours ago13 min▣LLM reporthigh A phishing campaign active since January 2026 uses disposable Vercel-hosted lure pages to deliver password-protected ZIP archives containing VBS scripts. The scripts launch PowerShell to download and install legitimate, signed RMM software that provides hands-on-keyboard remote access. The campaign spans 46 countries with 45% of activity in the United States and uses interchangeable RMM products, making product-specific detection ineffective. Durable detection pivots include a shared web font (font1.woff2), a mislabeled Word icon asset, and a consistent secure.html to project/*.zip download chain.
NEW#1240
Akamaiabout 19 hours ago5 min▣LLM reporthigh The article describes the shift toward AI-orchestrated web attacks where LLMs act as orchestrators and secondary tools execute web requests. This decoupled architecture creates a 'speed gap' where functional exploits are generated in under 10 minutes, outpacing human remediation. Attackers leverage protocols like Model Context Protocol (MCP) and spoof User-Agent headers to bypass legacy WAFs, necessitating real-time behavioral analytics and edge-based defenses.
NEW#1239
CISA1 day ago5 min▣LLM reporthigh CISA has added CVE-2026-21962, an improper access control vulnerability in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. Federal agencies are mandated to remediate this under BOD 26-04, while CISA advises all organizations to prioritize patching. The vulnerability poses significant risks to exposed assets.
NEW#1238AAsec1 day ago5 min▣LLM reporthigh The July 2026 Threat Trend Report on Ransomware highlights a complex threat landscape driven by established ransomware groups and the emergence of new data extortion actors. The Gentlemen group led with 159 claimed incidents, while manufacturing and the United States remained the most targeted industry and country, respectively. The report also identifies a SOCKS5 proxy disguised as Nezha RMM and vmtools.Exe, indicating ongoing evasion tactics using legitimate tooling.
NEW#1237
Canadian Centre for Cyber Security1 day ago3 min▣LLM reportmedium The Canadian Centre for Cyber Security published advisory AV26-843 regarding vulnerabilities affecting multiple Dell product lines. Dell released updates on August 17, 2026. Administrators are encouraged to review the advisory and apply necessary updates.
NEW#1236
Check Point1 day ago9 min▣LLM reportcritical This weekly threat intelligence bulletin covers multiple critical vulnerabilities with active exploitation, including CVE-2026-19478 in GitLab (CVSS 9.4) and CVE-2026-12569 in PTC Windchill/FlexPLM targeted by Cl0p with a custom implant for credential decryption and data theft. Check Point Research details the StopAndProtect campaign abusing WordPress sites for malware distribution via ClickFix technique, the repurposing of the Microsoft-signed BTR.sys driver for privileged operations using a hard-coded RC4 key, and emerging AI-assisted threats including autonomous exploitation of CI/CD pipelines and attacks on Siemens S7 industrial controllers.
NEW#1235MMalpedia2 days ago6 min▣LLM reporthigh CNCMachineRMS is a remote access trojan using a custom binary C2 protocol over TCP port 443 without TLS. It leverages DNS over HTTPS (DoH) to resolve C2 domains, bypassing local DNS logging. The protocol is identifiable by statistical analysis due to distinctive byte patterns at fixed offsets. Delivery has been observed via ClickFix attacks delivering the BabaDeda chain.
NEW#12342 days ago13 min▤RecapAug 17 – Aug 24
Trust Becomes the Target: AI Corruption and Identity Abuse Reshape Defense
This week, the tools organizations trust most became the weapons used against them. A Chinese-speaking criminal group called UAT-10147 used AI agents to semi-autonomously exploit web servers, generate attack code, and validate exploits before deploying a cross-platform backdoor called SPECTRE. Meanwhile, a critical flaw in Microsoft Copilot allowed attackers to silently steal data from connected email and calendar accounts and permanently poison the AI's memory through a single malicious link, proving that AI assistants are now both attack tools and attack surfaces.
At the same time, attackers systematically dismantled the assumption that an authenticated session guarantees a legitimate user. Three suspected Russian espionage clusters abused built-in authentication features like OAuth consent flows and WhatsApp device linking to compromise personal accounts without stealing passwords, while the Mirage2FA toolkit bypassed multi-factor authentication for over 4,000 victims. Separately, North Korean IT workers using AI-generated identities applied to over 1,100 companies to gain trusted insider access, and attackers increasingly used collaboration platforms like Teams and Slack as phishing channels because employees let their guard down on internal tools.
Defenders should treat every AI tool interaction with untrusted content as a potential compromise, move beyond password-plus-code authentication toward passkeys and hardware-backed verification, and urgently patch the nine vulnerabilities CISA added to its exploited-vulnerability catalog this week across Zimbra, TrueConf, MLflow, and Microsoft and VMware products.
NEW#1233
Canadian Centre for Cyber Security4 days ago7 min▣LLM reporthigh The Canadian Centre for Cyber Security published five security advisories on 2026-08-21 covering vulnerabilities in Splunk, Apple, Mozilla, Zimbra, and Malcolm products. CVE-2026-73570 affecting Zimbra Collaboration was added to CISA's Known Exploited Vulnerabilities (KEV) Database, indicating active exploitation. The Malcolm network analysis platform used in control system environments is affected by six CVEs across multiple versions.
NEW#1232
CISA4 days ago6 min▣LLM reportcritical CISA added CVE-2026-73570, an OS Command Injection vulnerability in Zimbra Collaboration Suite (ZCS), to its Known Exploited Vulnerabilities (KEV) Catalog based on confirmed active exploitation. The vulnerability allows attackers to execute arbitrary OS commands on affected hosts. BOD 26-04 requires FCEB agencies to remediate KEV-listed vulnerabilities on exposed assets and to investigate whether systems were compromised prior to patching.
NEW#1231KKaspersky5 days ago14 min▣LLM reporthigh Kaspersky identified a multi-stage Android downloader distributed through the built-in update functionality of DoFun-based automotive head unit firmware. The legitimate TWCore system app receives MQTT-based instructions that allow installation of apps not already present on the device, which attackers abused to deliver a JarService dropper that chains through a loader, a clicker/loader, and finally a reverse proxy module (zhima) that recruits the device into a proxy botnet. The activity is attributed with high confidence to MoYu Group based on code artifact naming, thread names, and infrastructure overlap with a related implant found on TV set-top boxes.