Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Security researchers created a fake cryptocurrency startup and hired three individuals believed to be North Korean operatives. The operation revealed common red flags such as AI-generated driver's licenses and mismatched identity details, highlighting the need for thorough vetting to prevent infiltration by North Korean IT workers.
Cisco disclosed two high-severity vulnerabilities in the Secure Endpoint Connector affecting ClamAV. These flaws enable denial-of-service attacks that crash the scanning process, and public exploits are already available, urging immediate patching.
Researchers demonstrated a technique that abuses Windows Plug and Play auto-install to escalate from an unprivileged user to SYSTEM access on fully updated Windows 11. By emulating USB devices, they trigger installation of signed vendor software that contains exploitable components.
Researchers developed GhostSplice, an attack that splits a malicious instruction into fragments placed across different MCP tool fields, causing AI coding assistants to exfiltrate secrets without any single fragment appearing harmful. Compliance rates rose dramatically when instructions were split, with some models reaching 100% exfiltration.
Kaspersky reports new components in the CAV3RN espionage framework targeting Israel, including a multi-transport C2 module that uses DNS responses to select between direct HTTPS and a Google Apps Script relay for each transaction. The framework also features a local broker that discovers and loads DLL components, routes messages, and supports runtime upgrades.
Kimwolf v7 is an evolution of the Kimwolf botnet that targets Android IoT devices. It uses HTTP/2 DDoS fingerprinting, Ethereum ENS for C2 resolution, and Tor backup routing.