“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels [email protected] (The Hacker News)
Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, HexagonalRodent, and Void Dokkaebi). According to a report published by Proofpoint, the threat actor has been found orchestrating phishing campaigns using developer role recruitment or code review themesRead More
-
Florida public sector training on SimSpace cyber range: Case study
Cyber ranges, once the domain of national defense agencies, are becoming more widely accessible. In the public sector, the state of Florida is leading the charge.Read More
-

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers [email protected] (The Hacker News)
A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one OpenAI-compatible interface. A server takeover exposes every provider…
-
Cyber insurance forces companies to rethink risk management
In this edition of the Reporters’ Notebook video series, our cybersecurity reporters explore why cyber insurance is forcing organizations to quantify risk.Read More
-

One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes [email protected] (The Hacker News)
A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and…
-

⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More [email protected] (The Hacker News)
Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten…
-

The Onboarding Password Mistake That Creates Unnecessary Risk [email protected] (The Hacker News)
Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within a tight timeframe. That usually means sharing a temporary “first-day” password so employees can access systems for the first time. The issue is that these passwords don’t always stay temporary. They may be sent…
-

152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic [email protected] (The Hacker News)
Cybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper add-ons to distribute a potentially unwanted program (PUP) family. The cluster spans 38 separate Chrome Web Store publisher accounts and three brand backends: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com. They have been collectively installed 105,000 times. TheRead More
-

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites [email protected] (The Hacker News)
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker’s control and installed a hidden plugin that opened…
-

Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent Facebook accounts impersonating politicians, public figures, and trusted organizations. “These accounts promoted fake offers, including free mobile internet packages, financial compensation, and government subsidy programs,” Group-IBRead More
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
