RansomwareInfosecurity Magazine·1 month ago

Russian Hackers Accused of Destructive Cyber-Attack on Jaguar Land Rover

Russian state-backed hackers are suspected of conducting a destructive cyber-attack against Jaguar Land Rover, with security experts identifying characteristics typical of Kremlin-linked threat actors including deployment of previously undocumented ransomware and deliberate obfuscation tactics. The breach's strategic timing and technical indicators have led analysts to attribute the incident to Russian state-sponsored operations, though attribution efforts have been complicated by the attackers' counter-forensic measures.

OtherDarktrace·1 month ago

Protecting Stadiums & Events with AI

Discover how Self-Learning AI tackles event security challenges like the 'access paradox' and IT/OT convergence with speed and precision.

PhishingInfosecurity Magazine·1 month ago

FBI Sounds Alarm Over Russian Intelligence Signal Phishing

The FBI has issued a warning that Russian intelligence operatives are conducting phishing campaigns specifically aimed at compromising Signal backup keys. By targeting these encryption recovery mechanisms, attackers seek to undermine the security of Signal's encrypted messaging platform and potentially gain access to user communications.

OtherDarktrace·1 month ago

The Curious Case of Prompt Language Analysis

Prompt analysis is reshaping AI security. Learn why prompts are behavioral signals, not just text, and why context is critical to identifying real enterprise risk.

HackTheBox - WingData

IppSec·7.1K views · 1 month ago

00:00 - Introduction 01:00 - Start of nmap 03:20 - Searching for vulnerabilities in Wing FTP Server 06:20 - Testing the RCE and running a command 09:30 - Weaponizing the POC to get a reverse shell 12:10 - Shell returned, grabbing the password hashes, discovering it uses a hard-coded salt and then cracking it 22:40 - Got the wacky password and can run a python script with sudo, searching for CVE's found one in tarfile 31:40 - Got our Elevated File Write working, finding safe files to get a shell, crontab did not work. But overwriting the script or sudoers.d file did work

Nation-StateInfosecurity Magazine·2 months ago

China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor

A China-linked threat group is targeting critical infrastructure in Southeast Asia using a newly discovered custom backdoor named TinyRCT. The campaign highlights ongoing efforts by Chinese-affiliated actors to establish persistent access to strategic assets in the region.

Data BreachInfosecurity Magazine·2 months ago

CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach

The UK Cyber Monitoring Centre has released analysis and guidance following a Canvas data breach that impacted 160 UK universities, underscoring the significant data theft risks and financial consequences associated with such incidents in the education sector. The breach highlights vulnerabilities within institutional learning management systems and the broader threat landscape facing higher education institutions.

VulnerabilityInfosecurity Magazine·2 months ago

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

Google has disclosed that a high-severity vulnerability in Cisco Catalyst SD-WAN Manager was actively exploited in the wild approximately three months before Cisco's official patch release in early June. This extended window of undetected exploitation underscores the risks posed by zero-day vulnerabilities and highlights the importance of rapid vulnerability disclosure and patching practices.

Policy & LegalInfosecurity Magazine·2 months ago

Trust in Automated AI Vulnerability Scanning Collapses to 9%, New Study Finds

A new Cobalt study reveals a significant erosion of confidence in automated AI vulnerability scanning, with trust dropping to just 9% among organizations that rely solely on AI automation for security testing. The research indicates a 20-percentage-point decline in organizations depending entirely on automated AI solutions, suggesting security teams are increasingly skeptical of AI-only approaches to vulnerability detection.

Policy & LegalInfosecurity Magazine·2 months ago

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

The Cybersecurity and Infrastructure Security Agency has released new guidance enabling federal agencies to transition from legacy TIC 2.0 architectures to zero trust security models through the adoption of Secure Access Service Edge (SASE). This guidance provides a practical pathway for government organizations to modernize their network security posture and align with contemporary security frameworks.

RansomwareInfosecurity Magazine·2 months ago

Major Increase in Ransomware Attacks Targeting Europe, Warns New Report

Researchers at Black Kite have identified a surge in ransomware attacks targeting Europe, with incidents rising over 50% in the past year according to their analysis. Supply chain attacks represent a particularly growing concern within this overall increase, indicating attackers are increasingly leveraging third-party dependencies to compromise victims.

Nation-StateWeLiveSecurity·2 months ago

Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances

ESET Research has identified an evolved Gamaredon toolkit that increasingly leverages legitimate online services to conceal command-and-control infrastructure and exfiltrate stolen data. The analysis reveals the threat actor's adoption of tunneling mechanisms, worker processes, dead drops, and new partnerships to enhance operational security and evasion capabilities in 2025.

OtherInfosecurity Magazine·2 months ago

Researchers Trick AI Browsers Into Leaking Credentials

Researchers at LayerX demonstrated a vulnerability in AI browsers by successfully tricking ChatGPT Atlas and Comet into bypassing their security guardrails and leaking credentials. The attack exploits weaknesses in how these AI-powered browsers handle sensitive information and access controls. This finding highlights risks in deploying AI agents with access to user data and web browsing capabilities.

MalwareInfosecurity Magazine·2 months ago

Europol-Led Operation Endgame Takes Down StealC and Amadey Infostealers

Europol-led Operation Endgame has successfully disrupted two major infostealer malware families, StealC and Amadey, by seizing approximately 50 domains and nearly 200 active IP-based servers used in their operations. The coordinated takedown targets the infrastructure supporting these widespread information-stealing threats that have affected numerous organizations and individuals globally.

MalwareInfosecurity Magazine·2 months ago

macOS Backdoor Uses Prompt Injection to Evade AI Triage

SentinelLabs discovered a macOS backdoor linked to North Korea that leverages prompt injection attacks to evade AI-based security triage systems. The malware exploits vulnerabilities in how AI tools process and analyze threats, potentially allowing it to bypass automated detection and analysis workflows.

Load more