Nation-StateKaspersky Securelist·1 week ago

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

Project CAV3RN uses Google Apps Script as a command-and-control relay to target Israeli systems, leveraging legitimate Google services as cover for malicious traffic. The campaign employs a modular .NET NativeAOT framework paired with DNS-based C2 channel selection, enabling attackers to route commands while blending communications with benign Google traffic to bypass security detection.

MalwareUnit 42·1 week ago

Kimwolf v7: An Evolution of the Kimwolf Botnet

Kimwolf v7 represents an updated iteration of the Kimwolf botnet with enhanced capabilities targeting Android IoT devices, leveraging HTTP/2 DDoS fingerprinting for attacks. The malware employs Ethereum ENS for command-and-control resolution alongside Tor-based backup routing to maintain resilience against takedown efforts.

VulnerabilityBishop Fox·1 week ago

Critical SQL Injection in Metabase via Password Reset: CVE-2026-72898

A critical unauthenticated SQL injection vulnerability has been discovered in Metabase's password reset functionality, tracked as CVE-2026-72898, with confirmed active exploitation occurring in the wild. Organizations operating self-hosted Metabase instances are urged to take immediate remediation action to protect against this vulnerability, which requires no authentication to exploit.

Supply ChainRecorded Future·1 week ago

Mines, Minds, and Machines: The Journey of AI

Minerals become chips. Chips become data centers. Data centers become models, and models are acquiring arms and legs. From Earth to Embodied AI traces the supply chain of the fourth industrial revolution, and shows how geopolitical rivalry and cyber operations now run along every link, from mine to machine.

OtherElastic Security Labs·1 week ago

13 million tool calls: auditing every AI coding agent action with Elastic Agent

Elastic Security Labs released an analysis of 13 million tool calls from AI coding agents, demonstrating how Cursor hooks and Elastic Agent can capture and log every action including shell commands, file reads, and MCP requests as structured events. This capability enables security teams to hunt through AI agent activities using ES|QL, providing visibility into potentially risky automated actions in development environments. The research highlights the growing need for detailed auditing and threat hunting capabilities as AI coding tools become more prevalent in enterprise workflows.

VulnerabilityCISA KEV·1 week ago

CVE-2026-72898: Metabase SQL Injection Vulnerability

Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. Added to CISA's Known Exploited Vulnerabilities catalog with a CVSS score of 10 (Critical). Affects Metabase Metabase.

MalwareUnit 42·1 week ago

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

Unit 42 has published an analysis of the Aeternum botnet loader, which uses Polygon blockchain smart contracts to establish decentralized command-and-control infrastructure and execute payloads. This approach represents an evolution in botnet evasion tactics, leveraging blockchain technology to distribute and maintain C2 operations outside traditional network chokepoints. The analysis examines how Aeternum's architecture enables resilient malware communications through on-chain smart contracts.

VulnerabilityDark Reading·1 week ago

Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius

A maximum-severity zero-day vulnerability in Metabase allows remote attackers to gain administrator access to the business-analytics platform, potentially exposing both the platform itself and its downstream users to compromise. The flaw remains unpatched and has not yet been assigned a CVE identifier, creating immediate risk for organizations using the affected software.

VulnerabilityDark Reading·1 week ago

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains that were previously restricted to nation-state actors are now proliferating among organized cybercrime groups globally. The Coruna and DarkSword exploits represent a significant shift in the accessibility of advanced iOS attack capabilities, expanding the threat landscape beyond state-sponsored operations to larger criminal ecosystems.

Policy & LegalDark Reading·1 week ago

Outdated Cybercrime Laws Put Security Researchers at Risk

A public policy expert has developed a five-point framework to address gaps in global cybercrime legislation that currently expose ethical hackers and security researchers to legal risk. The analysis maps existing cybercrime laws across jurisdictions to identify how outdated regulations fail to adequately protect good-faith security research activities. This framework aims to guide policymakers in updating laws to better distinguish between malicious hacking and legitimate security work.

OtherMicrosoft Security Blog·1 week ago

Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

Microsoft has been recognized as a Leader in the 2026 IDC MarketScape for managed detection and response services, reflecting competitive positioning in the enterprise MDR/MXDR market. The company's Defender Experts MDR offering integrates artificial intelligence, threat intelligence, and human security expertise to deliver detection and response capabilities.

Load more