Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
KREMLIN Banking Malware is a new trojan that hijacks Chrome and Edge browsers to steal banking credentials and sensitive financial data from infected users. The malware uses browser hooking techniques to intercept and modify web traffic in real time, capturing login credentials and payment information before encryption is applied.
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company.
You choose a model, ask a question and get an answer. Behind that familiar exchange is a less familiar journey involving prompt logs, shifting model identities and servers whose role is never explained to users.
Iranian state-sponsored hackers are using Telegram-controlled malware to conduct espionage operations against diaspora groups, with the malware receiving commands through Telegram bots and channels for stealthy C2 communication. The campaign leverages Telegram's encrypted infrastructure to evade network-based detection, making it harder for defenders to identify command-and-control traffic.
The principle of least privilege is straightforward to articulate but challenging to maintain at scale, and by operationalizing IAM remediation through CI/CD pipelines, organizations can automate the enforcement of proper permission boundaries.