Russian state-backed hackers are suspected of conducting a destructive cyber-attack against Jaguar Land Rover, with security experts identifying characteristics typical of Kremlin-linked threat actors including deployment of previously undocumented ransomware and deliberate obfuscation tactics. The breach's strategic timing and technical indicators have led analysts to attribute the incident to Russian state-sponsored operations, though attribution efforts have been complicated by the attackers' counter-forensic measures.
The FBI has issued a warning that Russian intelligence operatives are conducting phishing campaigns specifically aimed at compromising Signal backup keys. By targeting these encryption recovery mechanisms, attackers seek to undermine the security of Signal's encrypted messaging platform and potentially gain access to user communications.
Prompt analysis is reshaping AI security. Learn why prompts are behavioral signals, not just text, and why context is critical to identifying real enterprise risk.
HackTheBox - WingData
IppSec·7.1K views · 1 month ago
00:00 - Introduction
01:00 - Start of nmap
03:20 - Searching for vulnerabilities in Wing FTP Server
06:20 - Testing the RCE and running a command
09:30 - Weaponizing the POC to get a reverse shell
12:10 - Shell returned, grabbing the password hashes, discovering it uses a hard-coded salt and then cracking it
22:40 - Got the wacky password and can run a python script with sudo, searching for CVE's found one in tarfile
31:40 - Got our Elevated File Write working, finding safe files to get a shell, crontab did not work. But overwriting the script or sudoers.d file did work
A China-linked threat group is targeting critical infrastructure in Southeast Asia using a newly discovered custom backdoor named TinyRCT. The campaign highlights ongoing efforts by Chinese-affiliated actors to establish persistent access to strategic assets in the region.
The UK Cyber Monitoring Centre has released analysis and guidance following a Canvas data breach that impacted 160 UK universities, underscoring the significant data theft risks and financial consequences associated with such incidents in the education sector. The breach highlights vulnerabilities within institutional learning management systems and the broader threat landscape facing higher education institutions.
Google has disclosed that a high-severity vulnerability in Cisco Catalyst SD-WAN Manager was actively exploited in the wild approximately three months before Cisco's official patch release in early June. This extended window of undetected exploitation underscores the risks posed by zero-day vulnerabilities and highlights the importance of rapid vulnerability disclosure and patching practices.
A new Cobalt study reveals a significant erosion of confidence in automated AI vulnerability scanning, with trust dropping to just 9% among organizations that rely solely on AI automation for security testing. The research indicates a 20-percentage-point decline in organizations depending entirely on automated AI solutions, suggesting security teams are increasingly skeptical of AI-only approaches to vulnerability detection.
The Cybersecurity and Infrastructure Security Agency has released new guidance enabling federal agencies to transition from legacy TIC 2.0 architectures to zero trust security models through the adoption of Secure Access Service Edge (SASE). This guidance provides a practical pathway for government organizations to modernize their network security posture and align with contemporary security frameworks.
Researchers at Black Kite have identified a surge in ransomware attacks targeting Europe, with incidents rising over 50% in the past year according to their analysis. Supply chain attacks represent a particularly growing concern within this overall increase, indicating attackers are increasingly leveraging third-party dependencies to compromise victims.
ESET Research has identified an evolved Gamaredon toolkit that increasingly leverages legitimate online services to conceal command-and-control infrastructure and exfiltrate stolen data. The analysis reveals the threat actor's adoption of tunneling mechanisms, worker processes, dead drops, and new partnerships to enhance operational security and evasion capabilities in 2025.
Researchers at LayerX demonstrated a vulnerability in AI browsers by successfully tricking ChatGPT Atlas and Comet into bypassing their security guardrails and leaking credentials. The attack exploits weaknesses in how these AI-powered browsers handle sensitive information and access controls. This finding highlights risks in deploying AI agents with access to user data and web browsing capabilities.
Europol-led Operation Endgame has successfully disrupted two major infostealer malware families, StealC and Amadey, by seizing approximately 50 domains and nearly 200 active IP-based servers used in their operations. The coordinated takedown targets the infrastructure supporting these widespread information-stealing threats that have affected numerous organizations and individuals globally.
SentinelLabs discovered a macOS backdoor linked to North Korea that leverages prompt injection attacks to evade AI-based security triage systems. The malware exploits vulnerabilities in how AI tools process and analyze threats, potentially allowing it to bypass automated detection and analysis workflows.