Topic: attack mitigation

  • Storm-1175 Uses Medusa Attack Flaws

    Storm-1175 Uses Medusa Attack Flaws

    A financially motivated group, Storm-1175, has conducted relentless Medusa ransomware attacks for three years by exploiting newly disclosed and previously unknown vulnerabilities, heavily impacting healthcare, education, and finance sectors across multiple countries. The group's consistent tactic...

    Read More »
  • Check Point Flaw Allows Root Code Execution

    Check Point Flaw Allows Root Code Execution

    Check Point has released urgent patches for CVE-2026-91843, a critical stack-based buffer overflow in the Security Management Server and Log Server that allows unprivileged attackers to gain root code execution without user interaction. Immediate mitigation strategies include restricting access v...

    Read More »
  • Aisuru Botnet Unleashes Record 31.4 Tbps DDoS Attack

    Aisuru Botnet Unleashes Record 31.4 Tbps DDoS Attack

    The Aisuru botnet set a new DDoS record with a 31.4 Tbps attack, primarily using compromised Android TV devices to target telecom and IT firms. Cloudflare's 2025 threat report shows a 121% annual increase in DDoS attacks, with telecoms being the most frequent target and Bangladesh the top source ...

    Read More »
  • Defenders adopt prompt injection as a new tactic

    Defenders adopt prompt injection as a new tactic

    Researchers have developed "context bombing," a defensive tactic that uses prompt injections placed alongside sensitive data to trick AI hacking agents into triggering their own refusal mechanisms, halting attacks. In tests across five leading AI models, context bombing reduced the rate of full a...

    Read More »
  • Your Digital Footprint: How Geolocation Puts Your Privacy at Risk

    Your Digital Footprint: How Geolocation Puts Your Privacy at Risk

    Geolocation data from smartphones and apps creates a significant privacy risk, enabling cybercriminals to exploit traceable information for targeted attacks. These geofenced threats, like the Stuxnet worm, can remain dormant until reaching specific locations, making early detection difficult and ...

    Read More »
  • HashJack Attack Hijacks AI Browsers and Assistants

    HashJack Attack Hijacks AI Browsers and Assistants

    Security researchers have discovered a method called HashJack that embeds malicious commands in URL fragments to manipulate AI browsing tools into executing harmful actions like inserting dangerous links or sharing user data. The attack's success varies by platform, affecting Perplexity Comet, Mi...

    Read More »
  • Windows MiniPlasma zero-day exploit grants full SYSTEM access, PoC out

    Windows MiniPlasma zero-day exploit grants full SYSTEM access, PoC out

    A security researcher released a working "MiniPlasma" exploit for a Windows zero-day in the Cloud Filter driver (cldflt.sys), granting SYSTEM-level access on fully patched Windows 11 systems. The exploit abuses an unpatched flaw originally reported in 2020 (CVE-2020-17103), allowing arbitrary reg...

    Read More »