From The Hacker News · 34 stories
Russia Used Cellebrite Tools on Activist's iPhone Post-Sales Cutoff
Russian authorities accessed the iPhone of detained activist Andrey Pivovarov using Cellebrite's forensic tools in June 2021, despite the company's pledge to cease sales to Russia. This incident raises serious ethical concerns regarding the use of forensic technology in political prosecutions and reflects ongoing state repression efforts against opposition figures.
Google Reveals Details on Turla's STOCKSTAY Backdoor Targeting Ukraine
Google's Threat Intelligence Group announced the discovery of the STOCKSTAY backdoor, attributed to the Russian cyber espionage group Turla. This malware has been used to target Ukrainian government and military organizations, showcasing an evolution in Turla's cyber capabilities and tactics since its development traceable to late 2022.
Cloudflare Develops Privacy Protocol, curl Bug Discovered, Critical Hoppscotch Vulnerability
Cloudflare, alongside major web browsers, introduced a protocol using Private Access Control Tokens to enhance web privacy. AISLE reported six vulnerabilities in curl, the oldest dating back to 2001, while a critical security flaw in Hoppscotch allows unauthenticated attackers to compromise API instances.
New Rust-based Gaslight Malware Targets macOS with AI Disruption Techniques
A new macOS malware, codenamed Gaslight, uses prompt injection techniques to evade AI analysis. Linked to North Korean threat actors, the malware embeds fabricated system-failure messages to disrupt AI-assisted triage efforts.
DoJ Seizes Huione Cloud Account Linked to Cryptocurrency Fraud
The U.S. Department of Justice has seized a Huione Group cloud account used for money laundering linked to various cyber scams. This action, which follows new sanctions against related entities, aimed to disrupt significant financial networks facilitating fraudulent activities connected to cryptocurrency.
Browser-Based Attack Techniques Evolve with Phishing and Malicious Copy-Paste
Browser-based attacks are increasing, with phishing and malicious copy-paste (ClickFix) identified as leading threats. These techniques bypass traditional security measures by intercepting live sessions, using diverse delivery methods, and exploiting user actions to install malware.
CISOs struggle to answer board questions on security posture and financial exposure
Many CISOs cannot confidently answer board questions regarding overall organizational security, financial exposure, and security posture improvement due to fragmented data across multiple security tools. Boards require reporting focused on exposure, trend, and financial impact rather than activity metrics to assess risk effectively.
CrowdSec Reports Source Code Leak from May 2026, Attributes to Tanstack Compromise
CrowdSec confirmed a source code leak from May 2026 involving its private GitHub repositories, which contained code for its SaaS console, AWS routines, connectors, and automations. The company states no client data or sensitive credentials were leaked, and the incident's impact is limited to CrowdSec, with the Tanstack compromise identified as the likely vector.
DORA's Second Year Focuses on Practical ICT Incident Response and Risk Supervision
The Digital Operational Resilience Act (DORA) is now in its second year of enforcement within the EU, shifting regulatory focus from initial setup to demonstrating effective implementation of ICT incident analysis and risk supervision. Financial entities must ensure their Security Operations Centers (SOCs) have sufficient visibility to detect and investigate intrusions across critical systems, particularly in areas like legacy infrastructure and unmanaged devices. This matters because DORA mandates continuous monitoring beyond basic asset inventories to recognize deviations from normal operational patterns and minimize ICT risk.
Abandoned CDN Domain Re-registered, Posing Supply Chain Risk to Thousands of Sites
An expired CDN domain was re-registered in July 2025, and thousands of websites still hard-code references to its hostnames, allowing the new owner to control content delivered to those sites. This highlights a supply chain vulnerability where third-party scripts can be compromised without a server breach, as seen with the polyfill.io domain in June 2024.
Security Testing Needs to Shift from Individual Techniques to Attack Chains
Current security testing methods, which focus on individual techniques, fail to address how real attackers chain multiple steps together to breach systems. This gap between testing techniques and testing full attack chains leaves organizations vulnerable, despite validated individual controls. The industry needs to adapt its testing strategies to simulate multi-stage attacks to effectively counter modern threats.
F5 BIG-IP APM Malware Hides PHP Web Shell in Memory, Evading Disk Scans
Sophos reported that malware targeting F5 BIG-IP Access Policy Manager appliances injects a PHP web shell directly into memory, bypassing traditional disk-based file scans. This technique allows attackers to maintain persistence and execute commands without leaving traces on the file system, making detection more challenging for organizations using these F5 products.
Cloud Security Index 2026 Reveals Divergent Misconfiguration Risks Across AWS, Azure, GCP
Intruder's 2026 Cloud Security Index analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud, finding that risk profiles vary significantly between providers. This matters because security checklists need to be tailored to specific cloud platforms rather than using a one-size-fits-all approach.
AI-powered agents are transforming phishing attacks, increasing sophistication and scale
Phishing attacks are evolving into "Phishing 3.0," where AI agents automate reconnaissance, lure generation, and multi-channel delivery, making attacks more sophisticated and scalable. This shift means traditional email defenses are becoming obsolete as the threat moves beyond simple malicious content to AI-driven social engineering across various communication platforms.
Picus Labs Report: Enterprise Perimeter Defenses Improve, Internal Security Weak Against Covert Attacks
Picus Labs' Blue Report 2026 indicates that enterprise perimeter defenses have improved, with prevention effectiveness reaching 69% in the first half of 2026. However, internal network security remains weak, particularly against quiet attack techniques like reconnaissance and credential theft, which are stopped less than 22% of the time. This disparity means that while external threats are better mitigated, attackers who bypass the perimeter face little resistance once inside the network.
TeamPCP Linked to Redis Attacks Since 2020 and Supply Chain Campaigns
New analysis by Oligo Security researchers links the threat actor TeamPCP to Redis server compromises dating back to 2020, predating their known supply chain attacks. This connection is based on overlapping infrastructure, malware deployment, and operational techniques, indicating a long-standing presence in cybercrime before targeting software supply chains.
CTM360 Research Details Real-Time Account Hijacking in Insurance Phishing Campaigns
CTM360 research indicates a shift in insurance phishing tactics from credential harvesting to real-time account hijacking, where attackers authenticate immediately as victims log in. This evolution allows attackers to gain immediate access to sensitive personal and financial data, posing a greater risk than traditional phishing methods.
Synthetic Identity Fraud Emerges as Threat to Machine Identities
Synthetic identity fraud, traditionally understood as creating fake human identities, is now identified as a significant, under-discussed threat to Non-Human Identities (NHIs). Attackers can fabricate new machine identities by blending real and fake attributes, making them difficult to distinguish from legitimate ones. This method bypasses traditional security measures focused on detecting hijacked accounts, posing a challenge for organizations managing a growing number of NHIs.
Recent Clearinghouse Announcements Lack Significance, Says Industry Expert
Numerous tech companies have launched clearinghouses for vulnerability data, including Athena. The article argues that while the influx of clearinghouses may seem significant, most won't provide actionable solutions to security issues in the software supply chain.
AI Integration Changes Software Supply Chain Security Approaches
The integration of AI in the software supply chain is altering security paradigms by shifting risk away from solely code to involve AI-generated dependencies and tools. This necessitates enhanced governance and validation processes to manage the evolving threat landscape associated with AI components.
Challenges of Identity Lifecycle Management for AI Agents
Identity lifecycle management systems, designed for human employees, struggle to accommodate AI agents. This gap presents governance issues as enterprises increasingly integrate autonomous agents, necessitating updates to existing frameworks.
Richard Bejtlich Advocates for NDR in Modern Security Operations
Richard Bejtlich highlights the growing need for Network Detection and Response (NDR) in cybersecurity. His guide emphasizes moving beyond traditional alerts to prioritize actionable evidence in detecting and mitigating threats.
Meta Patents AI to Monitor Emotions and Fitness via Voice Recordings
Meta has patented a system that uses AI to monitor users' emotions by analyzing their voice and contextual data. The technology tracks emotional states and links them to physical location and activity for potential use in personalized fitness coaching. This patent showcases Meta's continued interest in integrating user data with AI for customized experiences.
Chainguard Reaches 1 Billion Container Build Manifests, Doubles Output in Six Months
Chainguard announced it has doubled its container build manifest output to over 1 billion in the last six months, now supporting more than 3,000 unique container images and 675,000 image versions. This milestone reflects the company's continuous rebuilding process for maintaining up-to-date and secure container images through its Chainguard OS and Factory infrastructure.
Integrating Autonomous AI and Analyst Copilots in Security Operations Centers
A Fortune 50 CISO discussed AI agents in security operations centers (SOC), revealing limitations in current designs that may overlook many alerts requiring human judgment. The insights of psychologist Daniel Kahneman emphasize the need for a balanced approach between automatic and deliberate human cognition in AI architecture for effective security.
Identity Visibility is Critical for Modern Identity Security
Identity visibility, which involves seeing every identity, its access, and how that access is used, is foundational for modern identity security. This is crucial because stolen credentials are a frequent initial access vector in data breaches, and cloud environments complicate identity management by creating "identity dark matter."
Autonomous Penetration Testing Prioritizes Vulnerabilities Based on Attack Paths
Security teams are shifting focus from isolated vulnerability severity to understanding actual attack paths to compromise. Autonomous penetration testing provides continuous validation by simulating attacker actions to reveal exploitable weaknesses in complex environments. This approach helps prioritize remediation based on real-world risk rather than theoretical severity scores.
Identity Fabric Architecture Addresses Fragmented Identity Systems in Hybrid Cloud Environments
An Identity Fabric is an architectural approach that unifies fragmented identity systems across applications, APIs, and infrastructure, providing runtime visibility into identity behavior. This approach addresses the increasing complexity of identity management in hybrid and multi-cloud environments, where traditional IAM tools struggle to verify access implementation. It matters because it closes the gap between intended access policies and actual access execution, reducing risks associated with unobserved identity activity.
Frontier AI Models Transform Vulnerability Management Landscape
Frontier AI models, such as Anthropic's Mythos, are changing vulnerability management by identifying zero-day flaws and chaining complex exploits. This development necessitates a systemic revolution in how organizations approach vulnerability and patch management. The traditional methods of prioritizing vulnerabilities using CVSS, EPSS, and CISA's KEV list are becoming insufficient as AI rapidly creates new exploits.
Check Point Introduces AI Network Firewall for AI Security
Check Point has launched the AI Network Firewall, integrating it into its AI Defense Plane to secure AI activity across enterprise networks. This new firewall aims to address the visibility gap created by AI's impact on network dynamics, which traditional firewalls were not designed to handle.
Webinar on Defending Against Rapid AI-Powered Attacks Announced
A free webinar hosted by Zscaler will focus on defending against AI-driven attacks, which have become significantly faster. The session will provide strategies to adapt security measures in response to these advanced threats, emphasizing Zero Trust principles.
Open Source Faces New Challenges from AI and Industrialized Malware
Open source software is transitioning from an unregulated, community-driven model to one facing significant external pressures. This shift is driven by increased security threats from AI-generated zero-days and widespread malware, alongside new regulations and executive orders. The change will impact how enterprises consume open source, though the core definition of Open Source (OSI-stewarded) will remain unchanged.
Guide to IAM Compliance Requirements and Best Practices
This guide explains Identity and Access Management (IAM) compliance, focusing on the distinction between policy intent and actual enforcement of access controls. It details why organizations need to move beyond periodic access reviews to continuous, evidence-backed verification for auditors. The guide highlights common evidence gaps and the importance of verifying implementation over just design.
Wazuh Integrates AI for Enhanced Security Operations Center Workflows
Wazuh has integrated AI capabilities, including the Wazuh AI Analyst, into its security platform to assist Security Operations Centers (SOCs) in managing high alert volumes and complex investigations. This integration aims to augment human analysts by providing contextual explanations, summarizing findings, and recommending remediation actions, thereby improving threat detection and incident response.