MalwareInfosecurity Magazine·1 month ago

New Dolphin X Stealer Employs AI Profiling to Prioritize Targets

Dolphin X, a newly identified infostealer, leverages artificial intelligence to profile and prioritize victims based on their potential value to attackers. This AI-driven targeting capability enables cybercriminals to more efficiently identify high-value targets, streamlining their victim selection process beyond traditional infostealer operations.

RansomwareInfosecurity Magazine·1 month ago

Two-Thirds of Ransomware Victims Say AI Boosted Attack Effectiveness

A recent study of ransomware victims indicates that approximately two-thirds attribute increased attack effectiveness to the use of AI tools by threat actors. The findings underscore growing concerns among security professionals that artificial intelligence is amplifying the sophistication and impact of ransomware campaigns against defended organizations.

Nation-StateGraham Cluley·1 month ago

Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

A Russian intelligence-linked hacker was arrested in Thailand, with investigators using unusual forensic details including multiple McDonald's orders to connect him to the Russian government. AI music generator Suno fell victim to a hack that exposed internal data regarding their use of copyrighted material for model training. The episode covers these incidents and additional cybersecurity developments.

MalwareInfosecurity Magazine·1 month ago

TrickBot Ditches HTTP for DNS Tunneling in Latest Variant

A newly observed TrickBot variant has shifted its command-and-control communication from traditional HTTP connections to DNS tunneling, embedding C2 traffic within DNS queries to evade detection. This represents a significant operational change from the malware's long-established HTTP-based communication pattern that had remained largely consistent for over a decade.

VulnerabilityInfosecurity Magazine·1 month ago

Ubuntu snap-confine Vulnerability Enables Local Root Access

A race condition in Ubuntu's snap-confine component allows local users to escalate privileges to root on systems with default configurations. This vulnerability poses a significant risk to Ubuntu deployments where untrusted local users have access to the system.

OtherInfosecurity Magazine·1 month ago

Google Makes CodeMender Available as Managed AI Security Agent

Google has launched CodeMender as a managed AI security agent that actively constructs and executes exploits within customer-controlled sandbox environments. The tool aims to validate whether identified vulnerabilities pose genuine exploitation risks, moving beyond theoretical vulnerability detection to practical exploitability assessment.

Policy & LegalKrebs on Security·1 month ago

LG to Ban Residential Proxies from Smart TV Apps

LG Electronics USA plans to ban residential proxy apps from its smart TV platform following researcher findings that over 42 percent of apps in its webOS store permit unknown third parties to route internet traffic through users' televisions. The suspension addresses security and privacy concerns around devices being weaponized as always-on proxy nodes without explicit user awareness. This action represents a significant step in addressing how consumer IoT devices can be exploited in proxy networks.

OtherZero Day Initiative·1 month ago

Pwn2Own Ireland 2026 – New Targets and Categories

Pwn2Own Ireland 2026 will take place October 6-9 in Cork, featuring seven target categories including mobile phones, smart home devices, wellness/healthcare devices, printers, messaging apps like WhatsApp, AI infrastructure, and AI coding agents. Registration closes October 1st, 2026, with a $15,000 lifetime ZDI bounty requirement for most entrants, though up to 10 new researchers may be accepted at organizer discretion, with a cap of 80 total entries.

VulnerabilityBishop Fox·1 month ago

A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit

ManageEngine's SSO implementation used only millisecond-precision wall-clock time for ticket generation, theoretically enabling unauthenticated account takeover due to the predictability of this value. While Bishop Fox confirmed end-to-end exploitation is feasible, blind exploitation remains impractical in real-world conditions, and the analysis includes actionable guidance for defenders to mitigate the risk.

PhishingInfosecurity Magazine·1 month ago

FBI Warns of Deepfake Videos Impersonating IC3 Leadership

The FBI has alerted the public to deepfake videos impersonating IC3 leadership being used to redirect victims to fraudulent complaint submission sites. This social engineering tactic leverages synthetic media to establish false credibility and deceive users into interacting with spoofed platforms, representing an evolving threat vector that combines deepfake technology with phishing infrastructure.

Nation-StateGraham Cluley·1 month ago

Ukraine warns fake CAPTCHAs are being used to make you hack yourself

Ukraine's CERT-UA has alerted security professionals to a social engineering campaign by the Kremlin-backed Sandworm group that exploits fake CAPTCHA prompts on compromised websites to trick users into executing malicious code. The technique represents a shift toward leveraging user trust in common security mechanisms as an attack vector rather than targeting technical vulnerabilities directly.

Data BreachInfosecurity Magazine·1 month ago

US Hospital Finance Software Provider Craneware Reports Data Theft

Craneware, a financial software provider serving US healthcare organizations, has disclosed a cyber incident resulting in unauthorized access and theft of data. The incident affects healthcare providers that rely on Craneware's systems for financial operations, though specific details regarding the scope of compromised data and the attack vector remain limited.

Nation-StateInfosecurity Magazine·1 month ago

Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros

Researchers have identified a North Korean hacking group called Famous Chollima conducting a targeted campaign against cryptocurrency professionals using ClickFix social engineering lures. The attack delivers trojans designed to compromise both Windows and macOS systems, expanding the threat landscape for Web3 professionals beyond traditional single-platform attacks.

Load more