Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Unit 42 analyzed the Aeternum botnet loader, which leverages Polygon blockchain smart contracts to run decentralized command-and-control operations and execute payloads. This approach gives threat actors resilient infrastructure that is difficult to disrupt using traditional takedown methods.
New research reveals a technique called GhostJacking, where attackers manipulate AI agents by feeding them security alerts and blocked events. This approach exposes identity governance gaps, allowing malicious actors to hijack autonomous decision-making processes.
Attacks on water systems continue to expand across more than a dozen states, with Iran suspected as the likely actor. The campaigns target poorly secured, Internet-exposed programmable logic controllers, underscoring urgent risks to critical infrastructure.
A threat actor compromised the upstream infrastructure of BdThemes, a WordPress plugin developer, to modify a remote JSON feed. This modification created rogue admin accounts in administrators' browsers, enabling unauthorized access.
A maximum-severity SQL zero-day vulnerability in Metabase allows remote administrator access to the business-analytics platform. The flaw, which still lacks a CVE, could have a wide blast radius affecting downstream users.
AWS announced the renewal of its Police-Assured Secure Facilities (PASF) accreditation for the Europe (London) Region, allowing UK law enforcement to run applications securely. The accreditation involves a control set of security requirements, on-site inspections, and audit interviews.