OtherKaspersky Securelist·3 weeks ago

An analysis of incidents at Brazilian educational institutions

Kaspersky has analyzed multiple security incidents affecting Brazilian educational institutions and compiled statistics from their incident response cases. The research includes practical security recommendations designed to help schools and universities strengthen their defenses against similar threats.

MalwareBitdefender Labs·3 weeks ago

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums

A malware campaign is distributing a Java stealer malware by posing as an undetected version of the Xeno Roblox script executor, targeting players seeking the legitimate tool. The fake cheats are being promoted through Discord and forum platforms to maximize reach among the gaming community. This attack demonstrates how threat actors continue to exploit gaming tool downloads as a vector for stealing malware delivery.

VulnerabilityQualys·3 weeks ago

Say Hello to Agent Insta: Closing the Detection Gap in Exposure Management at Machine Speed

Executive Summary Frontier AI has turned CVE weaponization timelines to hours, making scan-bound detection a growing compliance and breach-risk challenge. Agent Insta powers InstaScan to deliver scanless detection by transforming existing inventory, telemetry, and threat intelligence into validated exposure findings within minutes of disclosure. Operating 24/7, InstaScan enables AI-speed detection with 90%+ coverage across technologies […]

MalwareInfosecurity Magazine·3 weeks ago

HollowFrame Loader Uses Fake Python DLL to Evade Defender

A newly discovered HollowFrame loader employs a fake Python DLL to conceal Go-based malicious code while evading Windows Defender detection. The threat actor pre-stages Defender exclusions before deploying the loader, enabling it to operate undetected on compromised systems.

VulnerabilityUnit 42·3 weeks ago

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

Passkey implementations can suffer from critical security gaps when relying parties neglect to validate the User Verified flag, effectively degrading multi-factor authentication to single-factor security. This validation failure creates a novel attack surface in passwordless authentication systems that organizations adopting passkeys should understand and address in their deployments.

VulnerabilityTenable·3 weeks ago

30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next

Tenable spent 30 days testing Anthropic's Claude Mythos Preview frontier AI model against its own code repositories and found that it fundamentally shifts code security from ranking suspected defects to proving exploitability through reproducible proof-of-concept exploits. The real value lies not in the AI model itself, but in the orchestration harness around it—the system that transforms suspected flaws into proven, actionable findings—along with a senior security researcher who defines threat models and validates findings. Success requires budgeting both for substantial compute costs (Tenable spent roughly $41,718 in one month) and for expert engineering time, as frontier AI makes one senior researcher as productive as five rather than replacing human expertise entirely.

Data BreachInfosecurity Magazine·3 weeks ago

Korea’s Largest Telco KT Fined $38m After Femtocell Campaign

South Korea's largest telecommunications company KT has received a substantial fine following a year-long security breach involving compromised femtocells. The incident resulted in regulatory penalties totaling approximately $38-39 million, highlighting the critical security risks associated with customer-premises equipment in telecom infrastructure.

Data BreachInfosecurity Magazine·3 weeks ago

Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked

A hacker exploited a legacy vulnerability in Coldcard Bitcoin wallets to drain approximately $89 million from affected users. The attack highlights ongoing security risks in hardware wallet implementations despite their reputation for robust protection of cryptocurrency assets.

OtherElastic Security Labs·3 weeks ago

SOC case management and detection rule history in Elastic Security

Elastic Security has enhanced its platform with detection rule change tracking that enables one-click rollbacks, providing SOC teams with complete audit trails of rule modifications. The update also makes case data immediately queryable without additional configuration, streamlining reporting and compliance documentation for security operations centers.

OtherRecorded Future·3 weeks ago

8 Ways AI is Changing Threat Intelligence

Explore eight key ways that AI is reshaping the threat intelligence landscape, from creating speed and stealth advantages for adversaries to helping defenders better prioritize threats and allocate resources.

HackTheBox - Kobold

IppSec·8.8K views · 3 weeks ago

00:00 - Introduciton 01:00 - Start of nmap 02:30 - Finding the bin and mcp subdomain with ffuf 06:00 - Searching for PrivateBin exploits within version 2.0.2, finding an LFI but having trouble getting Code Execution from it 10:28 - Looking at the MCP Subdomain, finding MCPJam 1.4.2, which has an easy RCE Exploit 16:00 - SSH into the box as ben after dropping ssh key. Looking at processes and ports 18:37 - Looking at Arcane, another website discovering the default user of "arcane" still exists based upon timing on login 21:20 - Using find to see what files we have access to because we are in operator, discovering we can edit privateBin which allows us to weaponize the LFI to switch to its user (www-data) 26:30 - Inside of the PrivateBin Docker, looking for sensitive files, getting a password this lets us into Arcane. 30:03 - Logged into Arcane, a docker management website. Starting a container mounting / of the host to /mnt of the container, then accessing the host disk for privesc 33:30 - Showing a really cool unintended vector, which is the gshadow file. Using newgrp to add ourself to the docker group

JHT Course Launch! Home Labs with Proxmox

John Hammond·4.9K views · 3 weeks ago

Just Hacking Training livestream for Joram Stith's new course launch: Home Labs with Proxmox! Friday, July 31 at 1pm ET

OtherElastic Security Labs·3 weeks ago

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Elastic is showcasing its security tools at Black Hat and DEF CON, demonstrating how Attack Discovery converts raw security alerts into confirmed threats while Elastic Defend addresses vulnerable driver vulnerabilities in real time. The company will run live demonstrations against actual attacks at its conference booth.

Nation-StateMicrosoft Security Blog·3 weeks ago

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been targeting hospitality sign-in portals since May 2026 to deliver malware to travelers and harvest credentials in an operation dubbed CaptiveCrunch. By compromising hotel authentication systems, the threat actor gains access to a high-volume channel for distributing malware and stealing login credentials from a geographically diverse victim pool.

RansomwareWeLiveSecurity·3 weeks ago

This month in security with Tony Anscombe – July 2026 edition

July 2026 saw significant AI-related security developments, including instances of OpenAI models behaving unexpectedly and the emergence of the first documented agentic ransomware operation. A newly identified AI-driven supply chain threat also garnered attention during the month, indicating evolving attack vectors leveraging artificial intelligence capabilities.

OtherBishop Fox·3 weeks ago

What Security Leaders Think About Frontier AI Models: Firsthand of Mythos

Frontier AI models are democratizing attack capabilities while amplifying the effectiveness of sophisticated threat actors, creating a widening security gap. Security leaders from Vista Equity, Cisco, and Bishop Fox discuss the practical implications of this shift, the necessary evolution of defensive technologies, and the timeline for defenders to regain parity against AI-enabled threats.

PhishingGraham Cluley·3 weeks ago

The $5 million threat: AI Is supercharging phishing attacks

According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

Load more