Data BreachHelp Net Security·10 hours ago

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Researchers have discovered methods to bypass Windows 11's strongest security defenses without physical access to the machine, though the attack requires the attacker to already possess privileged system access. Last week also saw reports of records allegedly stolen from Azure tenants and Medusa ransomware targeting over 500 organizations, along with law enforcement actions against cybercrime operations.

Policy & LegalCyberScoop·1 day ago

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

Policy & LegalThe Hacker News·1 day ago

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

TikTok has agreed to pay $400 million to settle a U.S. Department of Justice lawsuit alleging violations of child privacy laws, with $300 million due immediately and the remaining $100 million conditional on vacating a prior consent decree. The settlement resolves claims brought against ByteDance's social media platform in 2024 for its handling of children's personal data.

MalwareSecurityWeek·1 day ago

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Three banking trojans are currently active threats: Manic, which incorporates spyware capabilities; Grandoreiro, which maintains persistent campaigns targeting victims in Latin America and Europe; and ToxicPanda 2.0, an expanded variant of the ToxicPanda malware. Security professionals should monitor these banking trojans as they demonstrate ongoing development and geographic targeting sophistication.

Supply ChainUnit 42·1 day ago

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Attackers are increasingly focusing on CI/CD pipelines and developer tools rather than application code itself, exploiting gaps in the software development lifecycle supply chain. Organizations need comprehensive visibility across their entire SDLC and implement rigorous security controls to defend these overlooked but critical infrastructure components.

OtherSchneier on Security·1 day ago

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii), the subsequent study states, a species that is part of a 20-strong flying squid family that was known to leap from the water but, until then, was only rumoured to also be able to glide above it. The neon flying squid was able to gain such elevation by using the hyponome, a funnel-like muscular organ also present in other cephalopods, such as octopuses. The organ is able to force water out in a jet, propelling the body along both in and out of the sea. Photographs of the gliding squid show them with their arms (they have 10 limbs in all) splayed outwards. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

Supply ChainThe Hacker News·1 day ago

14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

Researchers discovered 14 malicious npm packages disguised as calendar and streak utilities that deliver RedC2 4.0, an AI-powered Linux backdoor to infected systems. Upon installation, the trojanized packages extract and execute a bundled binary as a background process to establish command and control. This supply chain attack demonstrates how legitimate package repositories remain a vector for distributing sophisticated implants with AI-assisted capabilities.

OtherDark Reading·2 days ago

OWASP Flags Top AI Skill Risks in New Security Blueprint

OWASP has released a new top 10 security list designed for the current threat landscape, introducing a Universal Skill Format to standardize and enhance security practices around AI integrations. The framework aims to address the distinct risks associated with AI implementations across development and deployment environments.

OtherSchneier on Security·2 days ago

AI Is Learning to Write Genetic Code

Researchers have successfully used AI models to generate synthetic bacteriophage genomes, with 16 of 285 designs synthesized and tested in E. coli proving viable and some more effective than the natural ΦX174 strain at destroying bacteria. While this demonstrates promising applications for phage therapy and biological research, the capability to design functional viral genomes raises significant biosecurity concerns about potential misuse of AI-generated pathogens.

OtherSecurityWeek·2 days ago

Former NSA Director Paul Nakasone Launches National Security Advisory Firm

The newly-formed Nakasone Group will counsel government leaders, corporations, prominent families, and other private clients confronting cybersecurity, geopolitical, and personal security risks. The post Former NSA Director Paul Nakasone Launches National Security Advisory Firm appeared first on SecurityWeek.

OtherThe Hacker News·2 days ago

Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique leveraging Microsoft Defender's legitimately signed BTR.sys boot-time remediation driver to perform arbitrary kernel-level file and registry operations across Windows 7 through Windows 11 25H2 without exploiting any software vulnerability. The attack requires no external drivers or patches, instead weaponizing the trusted boot-time removal tool already present on affected systems. This capability allows attackers to delete security software and other protected files during the boot process before standard security mechanisms can intervene.

OtherThe Hacker News·2 days ago

Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet

Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet. "The malware spread through the built-in updaters of

Load more