Výsledky hledání

téma: identita× v celém archivu zrušit filtry

34 karet z 34 položek CZ · EN/orig

13

The story behind the intelligence

Welcome to this week’s edition of the Threat Source newsletter. Our goal is to get accurate threat intelligence to our audience as quickly as possible, with all the context you need to ask the right questions of your own environment: How at risk are we from this threat? Are we prepared for it? And what can we do about it? What you don’t often see is all the... well, frankly, “mess” involved in producing it. All the dead ends we followed until we could confirm those ends were as dead as a…

Cisco McKesson PaperCut Anthropic zdravotnictví US

tg: rozbor tg: návod tg: názor tp: malware tp: únik dat tp: AI tp: identita

Cisco Talos ·

StreamRat Android malware spreads through Meta and TikTok ads

A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking users, with most observed victims located in Spain. One Meta campaign ran from June 11 through July 3, 2026, and the same banners were also used to distribute the malware through TikTok. The available data shows the ads’ reach, not the number of downloads or infections, but…

Meta TikTok finance US

tg: varování tg: zneužíváno tp: malware tp: phishing tp: podvod tp: identita

Malwarebytes Labs ·

ASCII smuggling crosses over from AI prompt injection to phishing evasion

In this article What is ASCII smuggling?Writing a practical ASCII-smuggling signatureWhat we observed: ASCII smuggling repurposed for phishingWhat is known and what is newIs there a detection gap?Mitigation and protection guidanceReferencesLearn More Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people…

Microsoft finance US

tg: varování tg: zneužíváno tp: phishing tp: identita

Microsoft Security Blog ·

Your phone or computer may soon ask how old you are

First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be. California has passed a law that requires a range of operating systems to start collecting your age when you first set them up. Under the state’s Digital Age Assurance Act (DAAA), signed into law in October 2025, Windows, macOS, iOS, and Android will all have to do this from January 1, 2027. Operating…

US

tg: regulace tg: návod tp: identita tp: soukromí

Malwarebytes Labs ·

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 5.9, CVEs: CVE-2026-20354, CVE-2026-20355, Summary: Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these…

CVSS 5.9 CVE-2026-20354 CVE-2026-20355 Cisco FI US 2 zdrojů

tg: zranitelnost tp: identita

NCSC-FI · Cisco PSIRT

6

Tech support scams look different now. Here’s what to watch for

In a tech support scam, criminals pretend to work for a trusted technology or security company. They claim there is a problem with your device, software, subscription, or account, then try to persuade you to pay them, share personal information, or give them remote access to your computer. These scams used to rely mainly on browser locks and fake virus warnings. Now, scammers use many more ways to reach people, including websites and platforms they trust. How tech support scams reach you As…

Malwarebytes US

tg: varování tg: návod tp: phishing tp: podvod tp: identita

Malwarebytes Labs ·

Anatomy of a Silent Domain Takeover

Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking Windows events into a single attack. A full domain takeover can be completed in 54 minutes, from the first password spray to the forged Golden Ticket, with each individual event appearing normal. Detection catches the move; posture management explains why it was…

Qualys Microsoft US

tg: rozbor tp: identita tp: špionáž

Qualys ·

Dark web site puts 153 million driver’s licenses and millions more IDs up for sale

A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards. According to reports, the collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards. The trove of driver’s license scans reported by KrebsOnSecurity is a sharp reminder that identity verification is not a harmless box-ticking exercise. The…

IDScan.net US

tg: incident tg: rozbor tp: podvod tp: únik dat tp: identita

Malwarebytes Labs ·

Savjeti Nacionalnog CERT-a za siguran početak školske godine – što učiniti ako nešto pođe po krivu?

Koliko god se pridržavali svih sigurnosnih preporuka, ponekad se dogodi da nešto ipak pođe po krivu, bilo da je riječ o sumnjivoj poruci na koju smo kliknuli, kompromitiranom računu ili neugodnom iskustvu s nekim na internetu. Uz sve savjete o prevenciji, jednako je važno znati i kako reagirati ako se dogodi problem. U nastavku donosimo pregled nekoliko čestih situacija i osnovne korake koje možete poduzeti sami, bez obzira radi li se o vašem uređaju, računu ili neugodnom iskustvu na mreži. Ako…

školství HR

tg: návod tp: phishing tp: identita tp: soukromí

CERT.hr ·

5

Fake GTA 6 leaked copy drains your crypto wallet

We’ve seen scam sites built around Grand Theft Auto VI (GTA 6) targeting visitors in three different ways this year. In June, we looked at sites selling GTA 6 “early access” for hundreds of dollars in cryptocurrency. You paid, got nothing, and could not reverse the payment. In August, we found fake Extended Look and demo sites delivering an infostealer instead of a game. The site we examined this week looks like a GTA 6 fan countdown site but offers to sell a leaked copy of the game. It loads a…

US

tg: incident tg: rozbor tp: podvod tp: identita

Malwarebytes Labs ·

Infostealers are hijacking Claude accounts at users’ expense

Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the…

Anthropic US

tg: incident tg: varování tp: malware tp: identita

Malwarebytes Labs ·

3

The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)

One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do. Chasing the "free API key" is not new. What…

US

tg: varování tg: rozbor tp: AI tp: identita

SANS Internet Storm Ctr. ·

McKesson confirms cyber incident after ShinyHunters claims patient-data theft

Healthcare and pharmaceutical-distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data. McKesson Corporation is an American healthcare company that distributes pharmaceuticals and provides medical supplies, health information technology, and care management tools. McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation is still in early stages. “Based on our…

McKesson Okta Salesforce Snowflake zdravotnictví US

tg: incident tg: zneužíváno tp: phishing tp: únik dat tp: identita

Malwarebytes Labs ·

3

Protect your WhatsApp account with new passkey and 2FA upgrades

WhatsApp announced on August 25 that more than one billion people now use passkeys to log back into the app. The announcement included two other security upgrades: a stronger two-step verification method and more context for incoming calls from unknown numbers. It marks one of the largest passwordless authentication rollouts to date. Passkeys are now firmly mainstream, with the FIDO Alliance estimating that 5 billion are in use worldwide and 75% of consumers have enabled one on at least one…

WhatsApp US

tg: novinka v produktu tg: návod tp: phishing tp: identita

Malwarebytes Labs ·

2

1

1

Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting

Key Takeaways We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and OpenClaw were embedded in the operator’s day-to-day workflow, supporting troubleshooting, orchestration, and refinement of the collection pipeline. This AI-assisted workflow resulted in the modular platform Bissa scanner […] The post Bissa Scanner Exposed: AI-Assisted Mass Exploitation and…

US

tg: rozbor tp: malware tp: AI tp: identita

The DFIR Report ·