SecurityTicks

AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours

AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours 2026-04-30 at 22:46 By Kevin Townsend Industrialized cybercrime delivers attacks with greater scale, speed and success. Defenders must match this with use of AI and automation. The post AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours appeared first on SecurityWeek. This article is an excerpt […]

AI Fuels ‘Industrial’ Cybercrime as Time-to-Exploit Shrinks to Hours Read More »

PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials

PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials 2026-04-30 at 22:46 By In yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious versions to conduct credential theft. According to Aikido Security, OX Security, Socket, and StepSecurity, the two malicious […]

PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials Read More »

Judge in OpenAI trial has had it with Musk’s ‘steal from a charity’ quip: ‘You’re not a lawyer’

Judge in OpenAI trial has had it with Musk’s ‘steal from a charity’ quip: ‘You’re not a lawyer’ 2026-04-30 at 22:32 By Marc Vartabedian The judge presiding over the bombshell trial over the future of artificial intelligence titan OpenAI has apparently had it with Elon Musk’s favorite line over the last three days – “You […]

Judge in OpenAI trial has had it with Musk’s ‘steal from a charity’ quip: ‘You’re not a lawyer’ Read More »

FBI cyber boss: China’s hacker-for-hire ecosystem ‘out of control’

FBI cyber boss: China’s hacker-for-hire ecosystem ‘out of control’ 2026-04-30 at 22:30 By Jessica Lyons One alleged cyber contractor was extradited to the US over the weekend China’s “hacker-for-hire ecosystem has gotten out of control,” according to Brett Leatherman, assistant director of the FBI’s cyber division.… This article is an excerpt from The Register View […]

FBI cyber boss: China’s hacker-for-hire ecosystem ‘out of control’ Read More »

AWS says acute server memory shortage is driving customers to the cloud

AWS says acute server memory shortage is driving customers to the cloud 2026-04-30 at 18:18 By Dan Robinson When you can’t get ’em with a ‘transformation plan,’ supply chain pain will do the job The great memory shortage is having yet another effect, pushing enterprises into the waiting arms of the cloud operators as they […]

AWS says acute server memory shortage is driving customers to the cloud Read More »

Inside Vect Ransomware-as-a-Service

Inside Vect Ransomware-as-a-Service 2026-04-30 at 18:18 By Nathaniel Morales Vect ransomware, a new group that emerged in January 2026, has recently begun attracting attention in the cybersecurity space for its strategic partnerships, which are helping it expand. One notable collaboration is with TeamPCP, with evidence already surfacing as the latest victims on Vect’s leak site […]

Inside Vect Ransomware-as-a-Service Read More »

SonicWall Urges Immediate Patching of Firewall Vulnerabilities

SonicWall Urges Immediate Patching of Firewall Vulnerabilities 2026-04-30 at 18:18 By Ionut Arghire The bugs could be exploited to bypass security controls, access restricted services, and crash firewalls. The post SonicWall Urges Immediate Patching of Firewall Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SonicWall Urges Immediate Patching of Firewall Vulnerabilities Read More »

Survey says no, American workers are not keen on Microsoft’s AI

Survey says no, American workers are not keen on Microsoft’s AI 2026-04-30 at 17:35 By Richard Speed Lock-in worries threaten to dampen the E7 launch party The Coalition for Fair Software Licensing has published research showing that US workers reckon Microsoft is using its productivity tools to lock their employers into the company’s AI services.… […]

Survey says no, American workers are not keen on Microsoft’s AI Read More »

Incident Response Retainers Are Now Foundational to Cyber Resilience

Incident Response Retainers Are Now Foundational to Cyber Resilience 2026-04-30 at 17:35 By LevelBlue has been named a Representative Service Provider in the Gartner® Market Guide for Cybersecurity Incident Response Retainer Services (CIRR), marking the fifth consecutive time the company has been included in the report. We believe this continued recognition reflects LevelBlue’s ongoing focus […]

Incident Response Retainers Are Now Foundational to Cyber Resilience Read More »

SAP NPM Packages Targeted in Supply Chain Attack

SAP NPM Packages Targeted in Supply Chain Attack 2026-04-30 at 17:35 By Ionut Arghire The Mini Shai-Hulud attack introduced a preinstall hook to fetch and execute a Bun binary and bypass security monitoring. The post SAP NPM Packages Targeted in Supply Chain Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

SAP NPM Packages Targeted in Supply Chain Attack Read More »

ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories

ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories 2026-04-30 at 17:35 By The internet is noisy this week. We are seeing some wild new tactics, like people using fake cell towers to send scam texts, while some developers are accidentally downloading tools that peek into their private files during […]

ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories Read More »

SAP user group slams ‘uncertainty’ in ERP giant’s API policy

SAP user group slams ‘uncertainty’ in ERP giant’s API policy 2026-04-30 at 16:46 By Lindsay Clark Concerns over new rules might stop customers from adopting innovations – including AI – that connect to SAP systems An influential SAP user group has criticized the vendor’s API policy update, saying it lacks clarity and potentially prevents users from […]

SAP user group slams ‘uncertainty’ in ERP giant’s API policy Read More »

The Week in Vulnerabilities: GitHub Enterprise, Argo CD, Oracle Identity Manager, and Mozilla Security Flaws

The Week in Vulnerabilities: GitHub Enterprise, Argo CD, Oracle Identity Manager, and Mozilla Security Flaws 2026-04-30 at 16:45 By Ashish Khaitan The latest weekly vulnerability Insights report to clients by Cyble provides a detailed view of vulnerabilities tracked between April 15, 2026, and April 21, 2026. The findings highlight a slight dip in overall disclosures compared to the previous week, but the persistence […]

The Week in Vulnerabilities: GitHub Enterprise, Argo CD, Oracle Identity Manager, and Mozilla Security Flaws Read More »

cPanel zero-day exploited for months before patch release (CVE-2026-41940)

cPanel zero-day exploited for months before patch release (CVE-2026-41940) 2026-04-30 at 16:45 By Zeljka Zorz A critical authentication bypass vulnerability (CVE-2026-41940) in cPanel, a popular web-based control panel for managing web hosting accounts, is being exploited by attackers in the wild. What’s more, attackers didn’t have to wait for watchTowr security researchers to release technical […]

cPanel zero-day exploited for months before patch release (CVE-2026-41940) Read More »

Microsoft boss tells investors the company is working to ‘win back fans’

Microsoft boss tells investors the company is working to ‘win back fans’ 2026-04-30 at 16:17 By Richard Speed But why did those fans go away in the first place, Satya? Microsoft boss Satya Nadella told investors during an earnings call last night that the company needs to “win back” its fans.… This article is an […]

Microsoft boss tells investors the company is working to ‘win back fans’ Read More »

Cisco releases open-source toolkit for verifying AI model lineage

Cisco releases open-source toolkit for verifying AI model lineage 2026-04-30 at 16:02 By Mirko Zorz Enterprises pulling models from Hugging Face and other open repositories rarely keep records of how those models are altered after download, leaving organizations with little ability to confirm what they are running in production. The State of AI Security 2026 […]

Cisco releases open-source toolkit for verifying AI model lineage Read More »

Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks

Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks 2026-04-30 at 16:02 By Eduard Kovacs An attacker could have planted a malicious configuration to execute commands outside the sandbox. The post Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Critical Gemini CLI Flaw Enabled Host Code Execution, Supply Chain Attacks Read More »

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades 2026-04-30 at 16:02 By Intro A sophisticated, high-resilience malicious campaign was identified by Atos Threat Research Center (TRC) in March 2026. This operation specifically targets the high-privilege professional accounts of enterprise administrators, DevOps engineers, and security analysts by impersonating administrative utilities they rely on for daily operations. […]

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades Read More »

New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials 2026-04-30 at 16:02 By Cybersecurity researchers have disclosed details of a stealthy Python-based backdoor framework called DEEP#DOOR that comes with capabilities to establish persistent access and harvest a wide range of sensitive information from compromised hosts. “The intrusion chain begins with execution of […]

New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials Read More »

Scroll to Top