MalwareKaspersky Securelist·2 weeks ago

IT threat evolution in Q2 2026. Mobile statistics

Kaspersky's Q2 2026 mobile threat report highlights a notable shift toward dropper-based attack mechanisms alongside persistent threats from the Anatsa banking malware. The analysis tracks quarterly trends in mobile threats and documents key discoveries from the period, providing threat actors' tactical evolution on the mobile landscape.

OtherWeLiveSecurity·2 weeks ago

Are AI tutors safe for your kids?

AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child.

Data BreachRecorded Future·2 weeks ago

The Hugging Face Hack Was Cheap Persistence at Work

The Hugging Face and OpenAI security incident showed AI doesn't make attackers smarter. It makes persistence cheap, and defenses built for alerts can't keep up.

VulnerabilitySnyk·2 weeks ago

Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS

A real-world Evo Continuous Offensive Security assessment identified 33 confirmed vulnerabilities within a multi-tenant enterprise SaaS environment, encompassing critical authorization flaws and issues that could enable tenant-wide compromise. The findings demonstrate the practical value of continuous offensive security testing in uncovering systemic weaknesses that traditional assessments might miss in complex SaaS architectures.

DEF CON 34 - Video Team - Voting Machine Hacking Village

DEFCONConference·10K views · 2 weeks ago

Voting Village returns to DEF CON 34 to consider the state of election security.

DEF CON 34 - VideoTeam - Cliff Stoll AfterHours

DEFCONConference·8.6K views · 2 weeks ago

An interview with the delightful Cliff Stolll. So very worth your time

DEF CON 34 - Video Team - Car Hacking Village - Charger Hacking

DEFCONConference·5.5K views · 2 weeks ago

We get an EV charger hacking breakdown from the legend MajorMalfunction.

DEF CON 34 - Video Team - AI Hacking Village - Pokemon

DEFCONConference·5.1K views · 2 weeks ago

From the AI Hacking Village - an AI that plays Pokemon for you, without costing you 20 grand in tokens.

HackTheBox - Helix

IppSec·7.3K views · 2 weeks ago

00:00 - Introduction 00:45 - Start of nmap 03:20 - Using FFUF to VHOST Bruteforce and finding flow.helix.htb 05:30 - Looking into H2 Database RCE's, finding the Alias Command allows us the ability to run Java 07:10 - RCE #1: Using H2 Syntax to create an alias to run a shell command 15:10 - RCE #2: Adding a Processor to run Groovy 18:00 - RCE #3: Adding a Command Processor to run a bash command 19:40 - RCE #4: Is it easier to just use Metasploit? 26:00 - Shell on the box, using Find to show the types of all the files in our CWD and finding an SSH Key 30:15 - Shell as Operator, cracking a PDF 38:00 - Running OPCUA-Client-GUI and editing the registers to put the device in maintenance mode

Data BreachWired Security·2 weeks ago

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Two security researchers purchased commonly-used no-reply email domains and configured them to receive messages, discovering that hundreds of organizations inadvertently send sensitive corporate data to these addresses. The findings highlight a widespread operational security failure where companies fail to properly validate email configurations before deploying automated systems. This research exposes how trivial domain acquisition combined with poor email hygiene practices can expose confidential information at scale.

MalwareElastic Security Labs·2 weeks ago

Living off the coding agent: Two tales of tunnels and LaunchAgents

Elastic Security Labs documents a technique where coding agents create reverse tunnels and LaunchAgents to expose local admin applications to the internet, potentially providing remote access despite benign appearances. Security teams should treat this activity as high severity even when it resembles legitimate development operations rather than confirmed malware, as the outcome—exposing privileged services—represents significant risk regardless of intent.

OtherUnit 42·2 weeks ago

Inside the Modern SOC: The Identity Front Door

Identity-based attacks account for 90% of incidents, making identity management a critical security concern for SOC teams. Unit 42 explores how modern attackers exploit identity vulnerabilities and provides guidance for SOC leaders on developing effective response strategies to counter these threats.

Augmented Cloud Hacking with AI Workflows | BHIS Webcast

Black Hills Information Security·0 views · 2 weeks ago

🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits –

OtherDark Reading·2 weeks ago

AI-Generated Patches Fail Half the Time

A study analyzing over 6,000 patches reveals that AI-generated fixes succeed only about half the time, with even functional patches frequently introducing new bugs, breaking existing functionality, or leaving systems vulnerable to bypass attacks. The findings highlight a critical gap between patch generation and patch quality that security teams must account for when deploying AI-assisted remediation tools.

MalwareGraham Cluley·2 weeks ago

Beware cut-price AI services that read your every word

f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.

Load more