Aggregator
Банки остановили мошенников на 1,9 трлн рублей — но 7,35 млрд всё равно украдено: цифры ЦБ за квартал
沙特牵头的财团完成对 EA 的私有化
Практический онлайн-интенсив: «UserGate на практике: от нуля до защиты периметра»
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment
Microsoft Defender’s new automatic device isolation capability has emerged as a decisive control against modern ransomware intrusions that abuse legitimate Windows binaries, as demonstrated in a recent incident at QNET where a multi-stage attack was stopped in just 128 seconds. The mshta.exe process reached out to attacker-controlled infrastructure, retrieved a remote second-stage payload, and began […]
The post Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Три метода, одна цель — выдать себя за пользователя. Palo Alto Networks взломала защиту менеджера паролей Chrome
Future AGI: Open-source platform for shipping self-improving AI agents
Future AGI is an open-source platform for tracing, evaluating, simulating, and guardrailing LLM agents, licensed Apache 2.0 and self-hostable. Self-hosted instances register with Future AGI on first boot and send an instance ID, a version string, a deployment type, and the email addresses and domains of active admin users. That registration fires once, before anyone signs in to the dashboard. The opt-out is one environment variable, FUTURE_AGI_TELEMETRY_DISABLED=1, placed in .env ahead of the first start. … More →
The post Future AGI: Open-source platform for shipping self-improving AI agents appeared first on Help Net Security.
Botnet Scans Router Diagnostic Tools for OS Command Injection Vulnerabilities
Botnet operators are systematically probing router diagnostic interfaces for OS command injection flaws, chaining default credentials, legacy CGI endpoints, and weak command execution patterns to gain full remote control and deploy Mirai‑like payloads. Recent scan telemetry shows concentrated HTTP requests targeting a tight set of “diagnostic” URLs on internet‑exposed routers, including /apply.cgi, /cgi-bin/diagnostic.cgi, /cgi-bin/adv_ping.cgi, /DiagnosticsMsg.cgi, […]
The post Botnet Scans Router Diagnostic Tools for OS Command Injection Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code
A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted coding environment. This flaw could enable attackers to hide malicious commands within links embedded in commit messages, turning a routine developer action into a complete compromise of their endpoint. A victim simply needs to click […]
The post 1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Lets Attackers Execute Arbitrary Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Compromised Microsoft Copilot Accounts Let Hackers Impersonate CEOs and Steal $247,500
A controlled proof-of-concept by Barracuda’s Red Team has demonstrated how a compromised Microsoft 365 account with Copilot access can serve as a powerful launchpad for business email compromise (BEC). This scenario ultimately enables attackers to impersonate a CEO and redirect a $247,500 wire transfer. Research published on August 4, 2026, warns that AI-enabled email accounts […]
The post Compromised Microsoft Copilot Accounts Let Hackers Impersonate CEOs and Steal $247,500 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
1 шутка в Snapchat, 1 ночь в тюрьме: личка мессенджера отправила учительницу под арест
Product showcase: Material unifies Google Workspace email, file & OAuth defense
Here’s an uncomfortable truth: the attack that gets you won’t look like an attack. It’ll look like a normal login, a normal file share, a normal permission request you clicked past without reading. You don’t have a phishing problem, a DLP problem, or an OAuth problem. You have one problem wearing three masks, and most security stacks aren’t built to address this. Material Security designed its platform from a fresh point of view: stop defending … More →
The post Product showcase: Material unifies Google Workspace email, file & OAuth defense appeared first on Help Net Security.
巴基斯坦通过旅行社与网络针对印度教与锡克教徒招募间谍网络曝光,南亚情报渗透与中巴合作风险
藏在日防卫白皮书里的算法战争,日本军用AI转型全调查
Иностранные специалисты увозят из Китая невидимый вирус. Разбор атак группы OVERCAST PANDA
What stops attackers wrecking industrial plants is knowing how
Engineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 flooded the compressors and destroyed them. The replacement units did not match the originals, so the whole system had to be reworked and recharged with gas. That incident is one of roughly forty in Kaspersky ICS CERT’s quarterly roundup of attacks on … More →
The post What stops attackers wrecking industrial plants is knowing how appeared first on Help Net Security.