SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. « All of the malicious RubyGems packages appear to be typosquats of popular Ruby dependencies, but rather than the clever SEO-fueled typosquats we’ve seen from other threat actors (e.g., events-channel imitating the popular Node.js events module), they’re all clumsy typos. » The 16 gems have been published… OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker . The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and establish persistence on the host. There is no evidence that the technique has spread successfully in the wild, and the same paper reports that a review of archived posts from Moltbook, the social network for AI agents, found no successful agent-to-agent propagation despite several attempts.
Adform is telling people to clear their browser cache because the altered file may remain cached after the fix, and to check any wallet address before sending funds. Attackers modified a JavaScript file served by advertising technology company Adform , turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. « We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques, » the company said. N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. A configuration that allowed arbitrary devices on that APN to communicate with one another let the attacker pivot from a compromised wind-farm network to a controller at the CHP plant. While the intruders were still active inside the network, and customers lost neither heat nor electricity.
More alerts are making your team slower, and an outcome-based SOC fixes that July 20, 2026 Google’s $10,000 refund test shows why AI agents need zero trust August 18, 2026 Microsoft’s August 2026 Patch Tuesday fixes roughly 400 flaws, including three Zero-days, with one actively exploited and two publicly disclosed. NIST seeks input on modernizing the National Vulnerability Database as AI reshapes vulnerability management, risk assessment and remediation. As enterprises race to bolt AI onto every business process, security leaders are being forced to answer a harder question… The program could allow vetted private US companies to access targeted systems without the owner’s authorization and, in more disruptive operations, damage or destroy systems or infrastructure.
Feb Today’s Top Cybersecurity News Stories
- « Specifically, on job search websites, after reviewing a candidate’s resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group), » CERT-UA said .
- Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads.
- GCU’s Dana Gonderzik provides insights on leading a people-first security strategy and staying ahead of AI-driven threats in a rapidly evolving sector…
- MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running.
- The implant is equipped to harvest Windows credentials using pixel-perfect fake lock screens, offer a reverse SOCKS5 pivot into victim networks, execute arbitrary commands, and establish persistence on the host.
- A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure.
« Specifically, on job search websites, after reviewing a candidate’s resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group), » CERT-UA said . The campaign is assessed to be ongoing since May 2026. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145 , which is a subgroup within Sandworm (aka APT44, Seashell Blizzard, and UAC-0002), a sophisticated hacking group affiliated with the GRU. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods.
- The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation.
- The charge was Section 3ZA of the Computer Misuse Act 1990, the Act’s most serious, and they admitted it on the basis that they were reckless as to whether they caused or created a significant risk of serious damage to human welfare.
- The technique requires code execution in the victim’s signed-in session.
- Targets of the campaign include manufacturing, automotive, aerospace, and retail sectors.
- Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined.
Anthropic AI used fake profiles to target people in hack then hid the evidence
President Trump’s bold vision to secure and accelerate American artificial intelligence (AI) innovation is being actioned through the creation of “GOLD EAGLE,” a clearinghouse that enables unprecedented cybersecurity vulnerability coordination. The report also found that cyberattacks are already a recurring business risk. Both versions were released last month. Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Windows ticketing keeps private-key operations available while the user is interactively signed in, allowing code running as the user to ask Windows to sign authentication data.
Targets of the campaign include manufacturing, automotive, aerospace, and retail sectors. Several Artifactory CVE records were published on July 27 with affected-version ranges and fixed-version thresholds, but neither JFrog nor OpenAI has said whether any of those records correspond to the vulnerabilities used during the evaluati… https://sportsbookpayperhead.com/2024/12/27/cybersecurity-best-practices-protecting-your-sportsbook-from-online-threats/ OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face’s production environment also hacked multiple third-party accounts and services as part of the attack. Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge.
AI can find zero-days but still can’t reliably write secure code
The research highlights how compromised routers and IoT devices can be turned into distributed reconnaissance infrastructure that evades traditional IP-based defenses and supports follow-on exploitation. The botnet uses these devices to conduct targeted scanning and fingerprinting, helping threat actors rapidly identify vulnerable infrastructure—sometimes within hours of a new vulnerability disclosure—and appears to have a particular focus on U.S. military-related networks. This abuse has caused people to believe that fake images and videos are genuine and dismiss real content as misinformation.
- Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel.
- The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people.
- But ASSET Research Group’s tests show agents can still combine instructions across them in the same working context, so no single fragment has to contain the whole mal…
- Carlos Morales, SVP & General Manager of Arbor Cloud, NETSCOUT says how proactive defences for uninterrupted availability is now a business risk imperative…
The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The Justice Department has never named the company, in Wednesday’s announcement or in the October 2024 indictment, identifying the victim only as a U.S. software-as-a-service (SaaS) pr… The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people.
Fact Sheet: President Donald J. Trump Promotes Advanced Artificial Intelligence Innovation and Security
The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding collaboration and in a chain https://www.internetling.com/computer-security-tips-that-work.html of paired agents modeled on OpenClaw , the open-source autonomous assistant formerly known as Clawdbot and Moltbot . Security researchers at Anthropic and Switzerland’s EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. Global malware activity climbed sharply over the past week,… A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Shadow hVNC is a remote access tool built to operate where victims cannot see it. C2Looper is a newly identified backdoor that gives attackers a quiet way to control a compromised Windows computer.
Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating Malware
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number of users targeted in 110 countries and that it has notified customers in over 150 countries to date. Apple on Thursday sent a fresh batch of notifications to customers whom http://articlesss.com/cisco-data-center-security-measures-taking-the-next-step-in-data-specific-safety/ it suspects may have been targeted by mercenary spyware attacks. The ransomware payload ultimately failed to deploy due to insufficient virtual memory. Trump expands private-sector role in U.S. offensive cyber operations, raising governance concerns.
