#internationaal
39 artikelen over dit onderwerp
Tools77 Open VSX extensions found harvesting developer info77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were inst...ToolsAI Notetaker Lets Hackers Spy on Government, Corporate Video CallsA Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join calls.DreigingenCISA Adds Exploited N-able N-central Flaw to KEV After Customer CompromisesThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KE...PhishingDevice Code Phishing Up 1,500% in 2026; Vishing DoublesNewer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.NieuwsDOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RATA new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliv...PhishingFake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote AccessCybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business doc...AnalyseGoogle Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged AgentGoogle deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent in...PhishingGreatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal TokensThe commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber th...NieuwsHotel Wi-Fi attacks use custom malware to breach Microsoft 365 accountsMicrosoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. [...]AnalyseKeyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code HooksA credential-stealing npm worm that first appeared in keyv@6.0.0 spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4...NieuwsMassive ChainDrop npm supply-chain attack infects hundreds of packagesSelf-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. [...]DreigingenNew cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database RootcPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the se...PhishingSmoke#Screen RMM Takeover Gambit Exposes Threat Actor PlaybookThe attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.NieuwsVaronis Agent IBAC keeps AI agents within their intended boundariesAI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user's intent. Varonis explains how Agent IBAC detects in...NieuwsWhen Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always WantedThe cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long esti...Tools18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool UsersCybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part...NieuwsAnthropic: Claude Attacks Result of Security Gaps, Not Model IssuesLast month's incidents in which the AI model breached real-world systems derived from over-permissioning, especially with Internet access.DreigingenAttackers Exploit N-able Patch Bypass Flaw on RMM ServersOver the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.AnalyseChinese Actor Weaponizes Deepseek AI Agent to Attack Security FirmResearchers from Jesta intercepted and investigated the model, which was attempting to compromise more than 1,200 hosts for proxyjacking and to launch further attacksToolsChinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOSAn unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surfac...NieuwsExfilSquad hackers leak info of over 100,000 UK police officers, staffA cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. [...]NieuwsFake Roblox Xeno script launcher pushes infostealer, RAT malwareFake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]NieuwsFOMO in the SOC: Where AI Platforms like Claude Actually FitAI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write dete...ToolsGoogle Password Manager Attacks Could Let Malware Hijack Passkey-Protected AccountsMalware running as an ordinary user on a Windows machine can sign into a victim's passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victi...ToolsHugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary CodeThree high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machi...RansomwareINC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 FlawsThe INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN app...AnalyseInside the Underground Business of the Android BTMOB RAT malwareFlare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors,...NieuwsIs There Really a Fix for CISO Fatigue?Accountability without any real authority is driving CISO burnout, and organizations need to take notice.DreigingenN-able Says Attackers Take Over N-central Servers After Initial Fix Proves IncompleteN-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first f...DreigingenN-able warns of N-central auth bypass flaw exploited in attacksN-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]NieuwsNew DOUBLECUP ClickFix service hides malware in browser cache imagesA new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers, ultimately delivering CountLoader to Windo...ToolsNew Pass-ta-key attacks let malware hijack Google-synced passkeysSecurity researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over account...ToolsNew Tool Traces AI Videos Back to Their SourceResearchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.NieuwsPNLD Breach Exposes U.K. Police and Government Contact Details on Dark WebThe Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included na...ToolsThermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly UndetectableThermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them...Tools⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThis week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel network...DreigingenCOLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theftA vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a f...NieuwsGoogle Chrome may soon block New Tab hijacker extensions by defaultGoogle is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]NieuwsOpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problemsOpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theore...