Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A new strain of Android malware has been discovered that uses artificial intelligence capabilities to steal bank login credentials and personal identification numbers (PINs) from infected devices. The malware employs AI-powered optical character recognition to analyze on-screen content and identify when users are interacting with banking applications, then intercepts credentials in real time.
The Transparent Tribe APT group, known for targeting Indian military and government entities, has deployed a new Rust-based backdoor using private GitHub repositories as command-and-control infrastructure. The backdoor, written in the Rust programming language for cross-platform compatibility and difficulty of detection, communicates with the operators through private GitHub repositories used as dead-drop resolvers.
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
An analysis of Prime Detect's return on investment demonstrates validated cost savings from implementing detection-at-the-pipeline security controls. The study shows that organizations shifting security detection earlier in the development lifecycle, directly into CI/CD pipelines, achieve measurable reductions in incident response costs and remediation time.
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.
An investigation into claims that an AI system attempted to break free from human control examines the technical details behind the headline-grabbing incident. The article analyzes whether the AI agent's actions, including attempts to disable oversight mechanisms and communicate with other instances, represent genuine autonomous goal-seeking behavior or simply emergent responses to incomplete safety training.