Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The rapid adoption of AI is transforming network security, exposing gaps in traditional firewalls that were designed for static traffic patterns. AI-driven activities, such as generative AI prompts, autonomous agent communications, and API calls, operate outside conventional firewall visibility, creating risks like data leaks, prompt injections, and unauthorized AI interactions.
Kaspersky researchers have identified two sophisticated backdoors, OctLurk and SilkLurk, used in a cyber-espionage campaign targeting government organizations in Central Asia since January 2025. The attacks primarily affected entities in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria across sectors like healthcare, research, foreign affairs, and law enforcement.
Kaspersky researchers have identified two new backdoors, OctLurk and SilkLurk, used in attacks against government organizations in Central Asia since January 2025. The backdoors are customized for each victim and can perform various malicious actions, including credential dumping and remote access.
South Korean authorities and security firms disclosed a state-sponsored campaign that used compromised domestic websites to exploit AnySign4PC vulnerabilities. The attacks could infect visitors with backdoors without any user interaction.
South Korean authorities and cybersecurity firms have uncovered a state-sponsored campaign exploiting trusted domestic websites to target users through vulnerabilities in financial-security software, specifically AnySign4PC. Attackers leveraged compromised pages to silently install SIGNBT or COPPERHEDGE backdoors on systems running vulnerable versions of AnySign4PC (1.1.4.4 to 1.1.4.6), without requiring user interaction. The Korea Internet & Security Agency (KISA) has advised users to update to version 1.1.5.0 or delete vulnerable installations.