Topic: cybersecurity research
-
Security Pro Hacks North Korean Hackers, Finds Hundreds of Networks Breached
A security researcher, Vangelis Stykas, infiltrated North Korean hacking infrastructure over 22 months, finding evidence that 1,640 companies across 57 countries were targeted, with 700-800 suffering "really damaging" intrusions involving root server and AWS access. Stykas gained visibility into ...
Read More » -
AI-Powered Malware Targets Iranian Protesters
A sophisticated cyber campaign named **RedKitten** is targeting individuals and organizations in Iran, particularly human rights and political dissent groups, using AI-generated content and emotionally manipulative lures to deploy spyware. The operation employs a malicious implant called **Sloppy...
Read More » -
FortiSIEM PoC Released, Rakuten Viber CISO on Messaging Risks
A critical FortiSIEM vulnerability (CVE-2025-64155) now has a public exploit, heightening the urgency for immediate patching, while other vendors like Cisco also addressed actively exploited flaws. Security teams are exploring unconventional intelligence sources, such as torrent metadata, and fac...
Read More » -
Unveiling the Forces Behind Influential Cybersecurity Research
The study analyzed two decades of research from the SOUPS and FC cybersecurity conferences, revealing that smaller, diverse, and focused teams often produce higher-impact work than larger consortia, challenging common institutional assumptions. A stark contrast in gender representation was found,...
Read More » -
Adobe Acrobat Reader Zero-Day Exploited Since Last Year
A critical, actively exploited zero-day vulnerability in Adobe Acrobat Reader uses malicious PDFs to execute code, gather sensitive system information, and fetch additional payloads for potential remote code execution. The attack, discovered in late 2025, uses Russian-language document decoys, st...
Read More » -
OpenAI's 'Aardvark' AI Agent Automates Cybersecurity Research
OpenAI has launched Aardvark, an AI-powered cybersecurity researcher that uses GPT-5 to automate the discovery and remediation of software vulnerabilities, currently available in a private beta. The tool analyzes code repositories to identify and annotate vulnerabilities, tests them in a sandboxe...
Read More » -
ChatGPT’s Single Prompt Now Executes Full Cyber-Attack Chain
A single high-level prompt can turn OpenAI's ChatGPT-5.5 into an autonomous cyber-attack tool, completing the full attack lifecycle from reconnaissance to domain-level network access in under 40 minutes, according to tests by Cato Networks. The agentic AI demonstrated remarkable adaptability, dev...
Read More » -
Cybercriminals Pose as Interpol in Ransomware Phishing Attacks
Cybercriminals are impersonating Interpol in a global ransomware campaign, sending phishing emails with official-looking logos and language that trick victims into opening malicious attachments. Once opened, the attachments deploy ransomware that rapidly encrypts files and spreads across networks...
Read More » -
Amazon security research led to White House Anthropic ban
A White House export control directive restricted Anthropic's Fable 5 and Mythos 5 models after Amazon research showed the AI could be prompted to generate information useful for cyberattacks, blocking access for foreign nationals including many of Anthropic's own researchers. Anthropic pushed ba...
Read More » -
$3.2M Awarded for 11 Zero-Day Cloud Vulnerabilities
The inaugural Zeroday Cloud cybersecurity competition awarded over $300,000 for the discovery of 11 zero-day vulnerabilities in major cloud platforms, highlighting persistent security challenges in complex cloud environments. A critical container escape flaw in the Linux kernel was uncovered, pos...
Read More » -
PaperCut Issues 2nd Emergency Patch for Exploited Flaws
PaperCut has issued a second emergency patch for its NG and MF software to address two critical vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which allow unauthenticated remote code execution. This update is necessary because attackers have successfully bypassed the initial security fixes r...
Read More » -
Anthropic exposed unreleased AI model in unsecured database
A misconfigured content management system at Anthropic led to the public exposure of nearly 3,000 unpublished assets, including details on an unreleased advanced AI model and a private CEO event, due to human error. The leaked data included specifics about a next-generation AI model with major im...
Read More » -
Russians Use iPhone Hacking Tools to Steal Ukrainian Data
A new hacking toolkit called Darksword is targeting iPhone users in Ukraine, attributed to a Russian-linked group and designed to steal personal data and cryptocurrency. The malware operates with a fast "smash-and-grab" approach, quickly extracting passwords, messages, and photos before remov...
Read More » -
Millions at Risk as Social Security Numbers Exposed
Cybersecurity researchers discovered an unsecured database containing billions of sensitive records, including email addresses, passwords, and Social Security numbers, highlighting a massive ongoing risk of identity theft. The database was an aggregated compilation from multiple historic breaches...
Read More » -
Notepad++ Supply Chain Attack: Details, Targets, and IoCs Revealed
A Chinese state-sponsored group exploited the Notepad++ update mechanism to deliver malware in a targeted supply chain attack, focusing on high-value victims in Southeast Asia and beyond. The attack used malicious installers to deploy sophisticated backdoors like "Chrysalis" and Cobalt Strike, em...
Read More » -
Critical Flaws Found in Fluent Bit Logging Agent
Severe security vulnerabilities have been discovered in Fluent Bit, a widely used telemetry logging tool installed over 15 billion times, impacting core functions in banking, cloud, and SaaS environments. The flaws include input validation issues, tag manipulation, path traversal, buffer overflow...
Read More » -
UNC2891: Inside the ATM Fraud Money Mule Network
Cybersecurity group UNC2891 executed sophisticated ATM fraud attacks in Indonesia, using a money mule recruitment network and custom malware like STEELCORGI to target banks over multiple years. The criminals employed advanced tools including the CAKETAP rootkit to bypass security checks and multi...
Read More » -
Pro-Russia Hackers Target Water Utility in Honeypot Sting
A Russia-aligned hacktivist group called TwoNet was tricked into attacking a decoy water treatment facility, revealing their shift from website disruptions to targeting industrial infrastructure. The group used default credentials to access the system, performed disruptive actions like deleting c...
Read More » -
Researcher buys noreply.net, receives company secrets
A security researcher who owns the domains noreply.us and noreply.net has inadvertently created a "honeypot," receiving over 400,000 emails since December 2024,roughly 700 per day,containing sensitive data like injury reports, service orders, and corporate credentials. The flood occurs because co...
Read More » -
AI Hacking Still Needs Humans: Top Dangerous Tactics
Agentic AI excels at accelerating vulnerability discovery and generating research leads, but it remains severely limited in fully autonomous innovation and cannot reliably create novel attack methodologies without human intervention. The most effective use of AI in offensive security is human-AI ...
Read More »