100+ Internet-Exposed Water Systems Faced Cyberattacks Last Month
More than 100 water systems were targeted with cyberattacks. Security leaders weigh in.
More than 100 water systems were targeted with cyberattacks. Security leaders weigh in.
Research examined artifacts from the campaign and discovered hundreds of organizations targeted.
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed byRead More »FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. NimbusRead More »Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler
Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints. The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek.
Red team tests were conducted at the behest of two critical infrastructure organizations.
Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-basedRead More »NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. Both organizations were fully compromised at the domain level, and in both,Read More »CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products. The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recentlyRead More »Spyware for Babies