Uncategorized

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions 2026-08-26 at 16:44 By Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead […]

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions Read More »

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine 2026-08-26 at 16:07 By The SOC we’ve always known was built around a model that guarantees most of the alert queue will never receive analyst review. There’s never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Read More »

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code 2026-08-26 at 14:55 By The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura’s HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code Read More »

INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown

INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown 2026-08-26 at 14:32 By An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. “The operation, which brought together 22 countries from six continents, is a response to the

INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown Read More »

Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode 2026-08-26 at 14:32 By An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its

Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode Read More »

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests 2026-08-26 at 13:27 By Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests Read More »

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation 2026-08-26 at 12:38 By OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation Read More »

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload 2026-08-26 at 09:27 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Read More »

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes 2026-08-26 at 08:47 By Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple’s Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode.

Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes Read More »

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches 2026-08-26 at 04:02 By The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an “unprecedented, whole-of-government, economic campaign” against the nation and its enablers. “We are launching an economic onslaught against Iran’s financial connections around the

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches Read More »

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode 2026-08-25 at 22:03 By Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck’s CVE Numbering Authority (CNA) record. The

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode Read More »

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android 2026-08-25 at 22:03 By Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant

WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android Read More »

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape 2026-08-25 at 18:00 By Organizations need more than perimeter defenses — they need a comprehensive data resilience strategy that combines access controls with immutable backups and recovery capabilities. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source

When Cyber Meets Physical: Rethinking Data Management for a New Threat Landscape Read More »

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw 2026-08-25 at 17:07 By Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Read More »

Over a third of webpages created after ChatGPT’s debut show signs of AI writing, study finds

Over a third of webpages created after ChatGPT’s debut show signs of AI writing, study finds 2026-08-25 at 15:00 By Zoe Hussain More than one-third — 35% — of webpages created after the launch of ChatGPT in 2022 show signs of AI authorship, a Pew Research Center anaylsis found. This article is an excerpt from

Over a third of webpages created after ChatGPT’s debut show signs of AI writing, study finds Read More »

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows 2026-08-25 at 14:56 By Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Read More »

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages 2026-08-25 at 14:52 By Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Read More »

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands 2026-08-25 at 14:33 By Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands Read More »

Scroll to Top