nestdaddy
APIs
Web Global News Country News Financial News Tech News Software Maps
Images Research AI Tools Games
Showing 20 of 99 tech news articles in Cybersecurity
AI Sends Global Crime Syndicates Into Fraud Nirvana Cybersecurity
Darkreading 1 hour ago

AI Sends Global Crime Syndicates Into Fraud Nirvana

Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking Cybersecurity
Darkreading 1 hour ago

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking

Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.

Cybersecurity
Bleepingcomputer 2 hours ago

Ransom Cartel ransomware creator sentenced to 16 years in prison

Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...]

No Perfect Fix for AI Browser Prompt Injection Flaws Cybersecurity
Darkreading 3 hours ago

No Perfect Fix for AI Browser Prompt Injection Flaws

AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.

Cybersecurity
Bleepingcomputer 3 hours ago

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]

Cybersecurity
Bleepingcomputer 5 hours ago

Hackers run khunt post-exploitation toolkit from Oracle database

Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]

CSS: The Hidden Threat Lurking in Your Inbox Cybersecurity
Darkreading 5 hours ago

CSS: The Hidden Threat Lurking in Your Inbox

CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.

Cybersecurity
Securityaffairs 5 hours ago

AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems

AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI Security Institute (AISI) has put something uncomfortable on the table: during cyber testing, frontier models didn’t just follow instructions badly. In s

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning Cybersecurity
Darkreading 6 hours ago

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures Cybersecurity
Thehackernews 6 hours ago

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The server-side gate hides the malicious page from craw

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes Cybersecurity
Thehackernews 6 hours ago

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts lik

Flaws in Google APK for Python Unlock Agent-to-Agent Attack Cybersecurity
Darkreading 7 hours ago

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.

Cybersecurity
Bleepingcomputer 7 hours ago

COLDCARD security audit phishing attack installs remote access tool

A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]

Cybersecurity
Securityaffairs 9 hours ago

Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals

Brown Health Medical Group-MA breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. Brown Health Medical Group-MA data breach exposed personal, medical, and financial data of over 311,000 individuals after hackers accessed its servers. T

Cybersecurity
Bleepingcomputer 9 hours ago

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...]

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt Cybersecurity
Thehackernews 9 hours ago

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic's large language models (

Cybersecurity
Securityaffairs 10 hours ago

U.S. CISA adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabil

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports Cybersecurity
Thehackernews 10 hours ago

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expo

Cybersecurity
Bleepingcomputer 10 hours ago

Google Blogger locks hundreds of blogs in malware false positive

Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites deleted from the platform. [...]

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug Cybersecurity
Thehackernews 11 hours ago

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A cross-ten

Link copied to clipboard!