Navike oblikuju naš svakodnevni život. Svakoga dana izvodimo stotine radnji gotovo automatski, često bez aktivnog razmišljanja. Pojavi se obavijest o novoj poruci i otvaramo aplikaciju. Zvoni telefon, javljamo se. Vežemo pojas kada uđemo u automobil, peremo zube prije spavanja ili pijemo kavu nakon ručka. Na isti način navike utječu i na naše ponašanje u području informacijske sigurnosti. Provjeravamo li uvijek poveznicu u e-poruci prije nego što kliknemo na nju? Zaključavamo li zaslon svaki…
“Free” movies and TV could cost you your privacy, bandwidth, and control of your home network. We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past. Now, researchers have found that certain SuperBox devices and apps could quietly enroll a household connection into a proxy network, allowing third parties to route traffic through it. An earlier report identified CyberFlix TV, available through SuperBox’s custom app store, as containing Popanet proxy functionality that…
Fusion is a capability you mature into, not a team you hire. Here is the honest maturity path, the metrics that fund it, and the on-ramp that costs no headcount, startable this quarter.
If you already ship Kubernetes (K8s) audit logs and Defend for Containers (D4C) into Elastic, you still have to join them by hand, and neither source is complete on its own. In our lab, a compromised workload service account ran discovery, read secrets, minted a token, created a privileged pod, and execed into it to attempt a container escape. The escape wrappers, nsenter and chroot, never appeared in the runtime process events. Kubernetes audit logs recorded them in the decoded requestURI.Real…
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats. The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC: Raising awareness of quantum…
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program] Honeypot-Omaha is a DShied Sensor located at the Internet Storm Center (ISC) that is set up as a decoy for the original target and deployed over the internet. It is a flawed and very vulnerable system that was intentionally designed to attract threat actors with malicious intents. I view it as a massive log aggregator that collects data that an analyst like myself can then analyse, hypothesize,…
CMMC Phase 2 is paused, but the FAR CUI proposed rule pushes NIST 800-171 obligations past the defense industrial base. Here's what changed, what didn't, and the 32 requirements you can't defer.
In a tech support scam, criminals pretend to work for a trusted technology or security company. They claim there is a problem with your device, software, subscription, or account, then try to persuade you to pay them, share personal information, or give them remote access to your computer. These scams used to rely mainly on browser locks and fake virus warnings. Now, scammers use many more ways to reach people, including websites and platforms they trust. How tech support scams reach you As…
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]
Scammers are becoming more strategic about where they target people. Nine in ten toll scams—the fake unpaid-toll messages that threaten fines or license suspension—arrive by email or text, while roughly six in ten romance scams show up first on social media. That’s no coincidence. Rather than blasting the same message everywhere, criminals are tailoring different scams to the platforms where they’re most likely to succeed. This finding comes from Malwarebytes’ own threat research systems and…
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one…
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.
You might tell an AI chatbot secrets that you wouldn’t divulge to your closest friends. If you do, though, beware: They could end up as evidence in court. An article in the Washington Post this week highlighted several cases in which people had discussed sensitive information with AI systems like Claude and ChatGPT, only to have their conversations obtained by prosecutors or opposing lawyers. Lawyers can get access to your chatbot conversations from AI services like ChatGPT because they aren’t…
Koliko god se pridržavali svih sigurnosnih preporuka, ponekad se dogodi da nešto ipak pođe po krivu, bilo da je riječ o sumnjivoj poruci na koju smo kliknuli, kompromitiranom računu ili neugodnom iskustvu s nekim na internetu. Uz sve savjete o prevenciji, jednako je važno znati i kako reagirati ako se dogodi problem. U nastavku donosimo pregled nekoliko čestih situacija i osnovne korake koje možete poduzeti sami, bez obzira radi li se o vašem uređaju, računu ili neugodnom iskustvu na mreži. Ako…
In this article What is the Cybersecurity Incident Response Readiness Workshop?Our approach: How we assess your maturityLearn more Cybersecurity incidents can unfold in hours, but response plans often fail at the point of execution: ownership is unclear, investigation findings is difficult to access, and critical decisions are delayed. That is why incident response cannot be something your organization figures out in real time. The Detection and Response Team (DART) – the Microsoft team that…
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. [...]
Four years after the Kaseya supply chain attack, a recent incident shows how threat actors still successfully target MSPs’ downstream customers through RMM software.
Healthcare and pharmaceutical-distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data. McKesson Corporation is an American healthcare company that distributes pharmaceuticals and provides medical supplies, health information technology, and care management tools. McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation is still in early stages. “Based on our…
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. [...]
Svaki put kada pristupimo internetu (pretražujemo, komuniciramo, plaćamo online, objavljujemo fotografije ili se prijavljujemo u neku aplikaciju) ostavljamo za sobom trag podataka. Taj trag naziva se digitalni trag i on nas prati mnogo dulje nego što bismo možda željeli. Povratak u školske klupe dobar je trenutak da se podsjetimo kako svjesno upravljati onim što o nama govori internet. Što je digitalni trag i zašto je važan Digitalni trag čini skup svih podataka koje ostavljamo svojim…
Most of a container's vulnerabilities come from the base image. How to harden Docker images, why hardening is ongoing, and how to patch the base you already run. Category: Guides & Best Practices
When quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest now, decrypt later" tactic. Discover why building a comprehensive cryptographic inventory and executing a phased operational strategy are critical for protecting your data against quantum computing attacks.Key takeawaysQuantum computing risks are an operational…
Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.
WhatsApp announced on August 25 that more than one billion people now use passkeys to log back into the app. The announcement included two other security upgrades: a stronger two-step verification method and more context for incoming calls from unknown numbers. It marks one of the largest passwordless authentication rollouts to date. Passkeys are now firmly mainstream, with the FIDO Alliance estimating that 5 billion are in use worldwide and 75% of consumers have enabled one on at least one…
Uživatelé iPhonů se stávají terčem nového podvodu vydávajícího se za technickou podporu, který se je snaží oklamat pomocí falešného upozornění na platbu přes Apple Pay. Na podvodné webové stránce se zobrazí upozornění, které věrohodně napodobuje systémovou notifikaci telefonu a průběh platby přes Apple Pay, včetně údajného ověřování pomocí Face ID a dalších běžných bezpečnostních prvků. Následuje varování o zablokování Apple ID a výzva ke kontaktování falešné podpory Apple. Stránka navíc dokáže…
I veckans brev kan du ta del av ett axplock av händelser inom cybersäkerhetsområdet. Dessutom hittar du en utvärdering av organisationers cyberförsvar som CISA gjort, som innehåller rekommendationer för att stärka sin motståndskraft.
Welcome to this week’s edition of the Threat Source newsletter. Hello, everyone. Long time reader, first time writer here at the Threat Source newsletter! I wanted to start out by introducing myself. My colleague and friend Mick Baccio set the bar pretty high last week, so I was planning to tell you all about myself, including: How I did my first real IR under the influence of The Cuckoo’s Egg while an undergraduate (and failed) My pre-bug bounty flirtation with vulnerability research,…
Recently, we found a listing on BuzzFeed from someone pretending to be Malwarebytes Support. It reminded us why we need to be cautious about content on platforms where anyone can create an entry. Based on the phone number, we suspect the people behind this listing are trying to draw callers into a tech support scam. The scammer may use social engineering to persuade victims to grant remote access to their devices. This is not Malwarebytes’ phone number At first glance, this kind of lure can…
Protect your Australia- and New Zealand-based retail business from cyber threats. Learn five key decisions to secure identities, manage dependencies and ensure trading continuity against ransomware
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. SOC tasks rely on a combination of model efficacy, analysis time, cost, and consistency of results. Cisco Talos tested 66 model and reasoning combinations across offerings from both Anthropic and OpenAI on a log analysis task to see if we could identify a clear winner. Instead, we found a repeatable…
Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.” Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging automation. Together, those functions can help operators turn a compromised phone into a platform for account…
Your Mac comes with a built-in firewall, but it’s probably not something you’ve given much thought to. A firewall helps control incoming connections—requests from apps and other devices that want to connect to your Mac—giving you an extra layer of protection whenever you’re online. For most people, the default settings work just fine. But if you ever want more control over how your firewall works, whether you’re on public Wi-Fi or want to adjust which apps can connect, those settings aren’t…
Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing the patch alone does not complete remediation, as the fix replaces a kernel driver and requires…
Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we’ve achieved a leap in efficacy.…
Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.
Hidden API Estate And AI-speed Recon Are Reshaping Modern Application Risk Key Takeaways Unknown APIs create unattributed exposure, and such exposure rarely gets tested. Attackers build their own inventory through live reconnaissance; they do not wait for your spreadsheet. API discovery must pull from gateways, cloud, specs, traffic paths, scanners, and external exposure signals. OWASP API Top 10 includes improper inventory management because endpoint sprawl is now a core API risk. Qualys…
We gave hundreds of developers an AI agent that can run shell commands, edit files, and call Model Context Protocol (MCP) servers on their laptops, then realized we had no record of what it actually did. So we built one. One 280-line dependency-free bash script, fired by Cursor's hooks, records every tool call as JSONL, and the Elastic Agent already on each endpoint ships it to Elasticsearch. Since the May rollout we have logged over 13 million tool-call events from more than 1,100 machines. A…
We gave hundreds of developers an AI agent that can run shell commands, edit files, and call Model Context Protocol (MCP) servers on their laptops, then realized we had no record of what it actually did. So we built one. One 280-line dependency-free bash script, fired by Cursor's hooks, records every tool call as JSONL, and the Elastic Agent already on each endpoint ships it to Elasticsearch. Since the May rollout we have logged over 13 million tool-call events from more than 1,100 machines. A…
npm's min-release-age setting tells npm to ignore any package version published less than a set number of days ago, keeping freshly compromised releases out of npm install during the window when they do the most damage. Getting the setting onto developer workstations is straightforward. Knowing when someone quietly deletes it is a different problem entirely, and log-tailing inputs are no help because they only fire when lines are appended to a file. We built a ~40-line Common Expression…
npm's min-release-age setting tells npm to ignore any package version published less than a set number of days ago, keeping freshly compromised releases out of npm install during the window when they do the most damage. Getting the setting onto developer workstations is straightforward. Knowing when someone quietly deletes it is a different problem entirely, and log-tailing inputs are no help because they only fire when lines are appended to a file. We built a ~40-line Common Expression…
The calculus of cybersecurity has changed. AI is reshaping how organizations build, deploy, operate, and defend digital systems. AI-powered development tools, agents, and autonomous workflows are accelerating innovation but they are also introducing new attack surfaces, new trust boundaries, and new security challenges. Microsoft has long helped organizations secure their digital estates using Zero Trust principles. That leadership was recently recognized by KuppingerCole analysts, which named…
Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active…
This is Part 3 of the Inside Elastic InfoSec's Agentic SOC series. Part 1: How we triage every alert before an analyst opens it · Part 2: Choosing the right agent architecture for a 5× cost reduction We run 14 AI agents in the Elastic InfoSec security operations pipeline. They were producing correct verdicts and taking up to 19 large language model (LLM) calls to do work that needed 8, at thousands of input tokens per call. At hundreds of runs per day, that compounds fast. We built a five-step…
This is Part 3 of the Inside Elastic InfoSec's Agentic SOC series. Part 1: How we triage every alert before an analyst opens it · Part 2: Choosing the right agent architecture for a 5× cost reduction We run 14 AI agents in the Elastic InfoSec security operations pipeline. They were producing correct verdicts and taking up to 19 large language model (LLM) calls to do work that needed 8, at thousands of input tokens per call. At hundreds of runs per day, that compounds fast. We built a five-step…
This is Part 2 of the Inside Elastic InfoSec's Agentic SOC series. Part 1: How we triage every alert before an analyst opens it. Part 3: how we cut AI agent LLM calls by 60%. Investigating a Windows endpoint alert in Elastic InfoSec's production agentic security operations center (SOC) costs $0.69. That's what we pay running an orchestration workflow of specialized Elastic AI agents on the Elastic Inference Service (EIS). Route the same alert to a single agent working through 14 skills, and the…
This is Part 2 of the Inside Elastic InfoSec's Agentic SOC series. Part 1: How we triage every alert before an analyst opens it. Part 3: how we cut AI agent LLM calls by 60%. Investigating a Windows endpoint alert in Elastic InfoSec's production agentic security operations center (SOC) costs $0.69. That's what we pay running an orchestration workflow of specialized Elastic AI agents on the Elastic Inference Service (EIS). Route the same alert to a single agent working through 14 skills, and the…
We ran a noisy wget detection rule on Elastic's own cloud fleet for seven days. Three destinations survived deterministic filtering, Elasticsearch Query Language (ES|QL) COMPLETION triaged all three, and none of them created an alert that an analyst had to open. Each rule parses the destination from curl and wget executions, filters known-good hosts, redacts secrets, and then hands whatever’s left to a large language model (LLM) for a triage verdict. File transfer detections stay on in cloud…
We ran a noisy wget detection rule on Elastic's own cloud fleet for seven days. Three destinations survived deterministic filtering, Elasticsearch Query Language (ES|QL) COMPLETION triaged all three, and none of them created an alert that an analyst had to open. Each rule parses the destination from curl and wget executions, filters known-good hosts, redacts secrets, and then hands whatever’s left to a large language model (LLM) for a triage verdict. File transfer detections stay on in cloud…
Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation.…
Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can…
A dependency firewall blocks malicious open-source packages before they install. Learn how they work and how Aikido Safe Chain stops supply chain attacks. Category: Guides & Best Practices