ZeroHour

Search: “telemetry”

34 stories in the last 3d

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

Editorial scorecard ranks ten 2026 cloud detection and response platforms; Sysdig, Wiz, and CrowdStrike lead, with Wiz's Gem Security acquisition highlighted.

The editorial scorecard rates ten CDR platforms on real-time detection (30%), cloud telemetry depth, response automation, correlation, and value. Sysdig earns the best real-time detection score for its Falco- and eBPF-powered runtime telemetry, Wiz (8.7) folds acquired Gem Security's real-time CDR into its security graph, and CrowdStrike (8.7) leads response automation. Specialists Stream.Security, Skyhawk Security, Sweet Security, and the open-source Falco project are also assessed.

Cyber Security News · 2d agoIndustry1

VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

CERT/CC details CVE-2026-90999: attacker-controlled Sentry telemetry can steer the Seer coding agent into executing attacker code with repository access.

CERT/CC published VU#212479 for CVE-2026-90999 in Sentry Seer: attacker-submitted events through public DSN endpoints flow into Seer's root-cause analysis, which is embedded directly into the coding agent's initial prompt. In the documented chain, the privileged coding agent downloads and executes an attacker-controlled package before any human review, yielding arbitrary code execution with access to connected source repositories. No vendor patch is available yet; mitigations include disabling automated remediation, restricting coding-agent package installation, and filtering telemetry before Seer analysis.

When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

Cloudflare's Page Shield ML uncovered four malicious JavaScript campaigns on storefronts, including affiliate fraud and a remote-backdoor script, that VirusTotal and URLScan missed.

Cloudflare's Page Shield ML detected four client-side JavaScript operations (eight payloads) in live traffic on online storefronts, enabling affiliate commission hijacking, clickless affiliate theft via hidden iframes, user tracking with a remote-code backdoor, and cloaking of paid mobile visitors. Seven of the eight payloads were absent from VirusTotal and URLScan returned no malicious verdict for any, including a Lnkr-family payload indexed unclassified for roughly 2.5 years. Detection relies on a graph neural network over JavaScript syntax trees, an LLM second opinion on Workers AI, and a frontier-model ensemble voting across benign, magecart, other malware, and cryptomining labels.

Cloudflare Blog · 1d agoMalware in the wild

Bransys ELD

CISA reports Bransys ELD apps ship hardcoded MQTT and FTP credentials plus cleartext transport, exposing real-time telemetry for connected fleet devices.

CISA's advisory covers three Bransys ELD mobile app flaws: CVE-2026-86520 hardcoded MQTT credentials (CVSS 7.5), CVE-2026-86689 cleartext transmission of sensitive information, and CVE-2026-77960 hardcoded FTP credentials. Exploitation could allow unauthorized reading of real-time telemetry data from every active device connected to affected brokers across a subset of carriers. Android versions below 11.00.00 and iOS versions below 1.1.54 are affected; no public exploitation has been reported to CISA.

MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2

Kaspersky reports MovieReaper malware distributed via compromised torrent repository itorrents.org, using Solana blockchain for resilient C2 across four continents.

Kaspersky identified a multi-stage Windows malware framework, detected as HEUR:Trojan.Win64.Agent.gen, delivered through pirated movie torrents after operators compromised the shared repository itorrents[.]org, poisoning magnet-link downloads across multiple dependent tracker sites. The loader evades analysis via PEB walking, custom stream-cipher string encryption, and shellcode from deadhub[.]org, while a second-stage implant resolves C2 addresses through Solana getAccountInfo queries to a hardcoded on-chain account. A later module bypasses UAC and masquerades as msedge.exe in the Windows Telemetry path, ultimately deploying a 21-command remote file manager. Victims were detected in enterprise, government, IT, retail, transportation, and agriculture sectors across Europe, Asia, Africa, and Latin America.

GBHackersupdated · 6h agofirst · 9h agoMalware in the wild 3 sources

Hackers Exploit Critical Cisco ISE Flaw to Bypass Authentication and Gain Root Access

Cisco patched CVE-2026-76460, a CVSS 10.0 authentication bypass in ISE and ISE-PIC that can grant unauthenticated attackers root access.

Cisco's advisory cisco-sa-ISE-ABP-VNSW7Tn5 (September 16, 2026) describes CVE-2026-76460, insufficient authentication controls (CWE-648) on an exposed API endpoint in Cisco ISE and ISE-PIC, rated CVSS 10.0. Successful exploitation lets an unauthenticated remote attacker bypass management interface authentication and potentially obtain command-and-control with root privileges, enabling log tampering and persistence. Software updates are available with no workarounds; Cisco urges prioritized patching, log review for suspicious usernames, and reimaging of suspect nodes.

GBHackersupdated · 17h agofirst · 1d agoVulnerability in the wild 26 sourcesCVE-2026-76460

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

A 2026 scorecard ranks DSPM tools with Wiz and Cyera tied first, documenting consolidation via Palo Alto, Rubrik, Proofpoint, and CrowdStrike acquisitions.

The article ranks ten DSPM platforms: Wiz and Cyera tie at 8.7/10, followed by BigID at 8.5 and Securiti at 8.4, scored on discovery breadth, classification accuracy, access context, remediation, and value. It highlights heavy market consolidation, noting Dig Security was acquired by Palo Alto Networks, Laminar by Rubrik, Normalyze by Proofpoint, and Flow Security by CrowdStrike. Buyers are advised to purchase from current owners and confirm post-acquisition integration state.

Cyber Security News · 2d agoIndustry2· 1 read

BambooToken malware controls Windows and Linux systems via MQTT

Lumen Black Lotus Labs exposes BambooToken, a China-aligned malware framework using MQTT C2 to backdoor Windows and Linux systems at roughly a dozen enterprises.

Lumen's Black Lotus Labs documented BambooToken, a previously unknown malware framework active since at least 2023 that adopted MQTT for command-and-control in 2024-2025 variants targeting Windows and Linux. Infection occurs via DLL side-loading through digitally signed Tendyron OnKey USB-token software or an impersonated Kingsoft Office installer; dead code suggests keylogging, clipboard theft, audio/webcam capture, and screenshot modules. Telemetry identified roughly a dozen compromised entities, mostly in Asia and South America, including a Hong Kong GitLab server and possibly users of the SpeedCN VPN service. Targeting patterns are consistent with China-aligned operations, though no attribution to a known cluster was made.

BleepingComputerupdated · 2d agofirst · 2d agoMalware in the wild 2 sources1

New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturingnew

Huntress details a new Settra ransomware variant deployed against retail and manufacturing victims since June, using MeshAgent RMM, recovery sabotage, and BYOVD techniques.

Huntress reported a new Settra ransomware variant, first observed in June, used in a July attack on a consumer services and retail organization and a September attack on a manufacturing firm. In the retail attack, MeshAgent RMM connected to attacker C2, the ransomware ran from C:\Perflogs, encrypted files with the .locked extension, and created a ransom note; the executable was named after the victim's domain in both incidents. Attackers cleared Windows Event Logs, disabled the Windows Recovery Environment, flushed DNS cache, used DiskPart to remove the recovery partition, and ran Cipher to overwrite free space. The September attack added BYOVD; prior research links Settra to double extortion, and initial access remains unconfirmed.

Infosecurity Magazineupdated · 24m agofirst · 38m agoRansomware in the wild 3 sources

12 Best Multi-Cloud Security Platforms Compared (2026): Features & Pricing

A buyer's guide compares pricing and features of 12 multi-cloud security platforms including Wiz, Prisma Cloud, FortiCNAPP, and Defender for Cloud.

The GBHackers roundup profiles 12 multi-cloud security platforms, including Wiz, Fortinet FortiCNAPP, Palo Alto Prisma Cloud, Sysdig, Microsoft Defender for Cloud, Uptycs, and Check Point CloudGuard. It focuses on cross-cloud billing parity, connector fees, ELA absorption, and negotiation tactics for procurement teams. The article notes Ermetic has consolidated into Tenable Cloud Security and that Google's acquisition of Wiz is finalized.

GBHackers · 5h agoTools 10 sources

Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links

Malwarebytes tracked a large T-Mobile smishing campaign using 81+ rotating .top domains and 1,000+ template variants to harvest credentials via fake rewards-expiry lures.

Malwarebytes has tracked an SMS phishing campaign impersonating T-Mobile since early May 2026, using lures about expiring rewards points (e.g., a claimed 18,400-point balance) to push victims to lookalike domains such as t-mobile.biktpw[.]top. Researchers identified at least 81 short-lived .top domains and more than 1,000 semantically similar message templates, with the 199 closest variants scoring 0.95+ similarity. Links lead to fake login, personal-data, or payment pages aimed at credential harvesting, and attackers may also request one-time verification codes to enable account takeover despite MFA. Users are advised to verify notifications inside the official app and report suspicious texts to 7726.

GBHackersupdated · 4h agofirst · 7h agoPhishing & fraud in the wild 5 sources

Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites

Attackers compromised Brevo-hosted JavaScript to deliver a WordPress backdoor and ClickFix payloads across 100,000+ websites, exposing visitors and admins.

Sansec found injected script tags loading f.js from attacker-controlled subdomains of sendibt1.com appended to legitimate Brevo resources, with PublicWWW listing 114,371 pages referencing Brevo assets. During a September 14 window (16:05:18–20:12:53 UTC), the conditional payload installed a plugin from cdn10.sendibt1.com/p/wm.zip into WordPress admin sessions and showed other visitors a fake human-verification ClickFix overlay instructing them to run pasted commands. Evidence, including an August 25 SSL certificate for cdn.sendibt1.com and Cloudflare DNS usage, suggests a possible compromise of Brevo's Cloudflare environment, unconfirmed by Brevo. Brevo separately disclosed a September 10 SAML SSO incident in which an attacker accessed 138 accounts, sent phishing from six, and exported contacts from 43.

GBHackersupdated · 4h agofirst · 8h agoMalware in the wild 5 sources

AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection

Google's GTIG documents AI-enabled malware PROMPTFLUX and PROMPTSTEAL that query LLMs at runtime to rewrite code and evade signature-based detection.

Google Threat Intelligence Group documented 'just-in-time' AI-enabled malware that queries language models during execution. PROMPTFLUX, an experimental VBScript dropper, calls the Gemini API to regenerate and obfuscate its own source code and writes variants to the Windows Startup folder for persistence. PROMPTSTEAL fetches one-line Windows commands via the Hugging Face API from Qwen2.5-Coder-32B-Instruct to collect files and system information, which Google linked to APT28 activity targeting Ukraine. The article argues signature-based defenses retain value but defenders should prioritize behavioral detection and deterministic prevention controls.

GBHackersupdated · 5h agofirst · 8h agoMalware in the wild 2 sources

Should you care about an “AI slowdown?”

Cisco Talos argues an AI slowdown would barely affect cybersecurity, urging focus on fundamentals and Qilin ransomware trends in Japan.

Cisco Talos' newsletter opines that an AI development slowdown would have limited security impact since current models already uncover substantial vulnerabilities. It highlights Talos findings that Japan's ransomware incidents rose nearly 5 percent in H1 2026, driven by The Gentlemen RaaS group and Qilin, which uses LLMs to generate destructive scripts and targets SMBs with double extortion. The newsletter also recaps headlines including an Android app-cloning campaign, Apple's 200-patch release, ClickFix lures, and VectraRAT.

Cisco Talosupdated · 6h agofirst · 20h agoIndustry 4 sources

Improving email security outcomes with real-world Microsoft Defender insights

Microsoft's quarterly benchmark claims Defender missed 55.4% fewer high-severity email threats than the next-closest secure email gateway.

Microsoft published its fifth consecutive quarterly email security benchmark covering May through July 2026, reporting Defender missed 221 high-severity threats per 1,000 protected users, 55.4% fewer than the next-closest SEG vendor, and caught 92% of post-delivery malicious messages. Microsoft notes missed threats are rising across vendors as AI helps attackers craft more convincing impersonation attempts. The report also highlights product updates, including a redesigned AI model stack that reduced false negatives by roughly two-thirds and new prompt injection protection for Copilot and other AI systems that process email.

Microsoft Security Blog · 22h agoIndustry

FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor

China-aligned FamousSparrow deployed its new SparroWocky backdoor against Latin American governments since August 2025, initially accessing networks via exploited Exchange servers.

ESET attributes the SparroWocky campaign to FamousSparrow with high confidence, partly because early infections were delivered via the group's exclusive SparrowDoor implant. Since at least August 2025, the modular C++ backdoor was found at government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, with 90% of the group's mid-2025 telemetry targets in the region. SparroWocky supports command execution, file execution, TCP proxying, host reconnaissance, screenshot capture, RC4-encrypted TLS exfiltration, and Cobalt Strike BOF loading, using runtime patching and call-stack forging for evasion. ESET links the regional focus to China's response to renewed US interest in Latin America and notes a possible, unclear link to Trend Micro's Earth Estries.

Infosecurity Magazineupdated · 18h agofirst · 23h agoThreat actor in the wild 9 sourcesCVE-2021-26855

SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

Hunt.io linked SpiceRAT, NodeEdgeRAT, and NomadRAT C2 servers to the SilkParasite campaign targeting Central Asian governments since mid-2022.

Hunt.io and researcher Guy Yasur mapped C2 infrastructure tying three of seven RAT families from Bitdefender's SilkParasite report through shared TLS certificates, parent domains, and a cloned RTX Corporation homepage. One certificate spoofing Uzbekistan's state railway was issued by TLC, a CA funded by China's CAICT, and domains impersonate state entities in Turkmenistan, Uzbekistan, Tajikistan, and Kyrgyzstan. Passive DNS pushes the campaign back to mid-2022, and the infrastructure overlaps China-nexus activity including FamousSparrow and IndigoZebra.

Security Affairs · 23h agoThreat actor in the wild 3 sources

Handala Hack Uses CRUDEEXCLUDE to Disable Defender Protections and Deploy HEAVYGRAM

Group-IB links new HEAVYGRAM and CRUDEEXCLUDE malware to Iran-aligned Handala Hack (MOIS/Void Manticore), which spies on Iranian dissidents using Defender exclusions and Telegram C2.

Group-IB documented previously unreported HEAVYGRAM and CRUDEEXCLUDE malware linked with moderate confidence to the Iran-aligned Handala Hack, assessed as a MOIS-linked persona tied to Void Manticore (Storm-0842, Banished Kitten, Red Sandstorm). CRUDEEXCLUDE uses PowerShell to add attacker-controlled Microsoft Defender exclusions, then a Delphi-based loader deploys a PyInstaller-packaged HEAVYGRAM implant that abuses Telegram bot APIs for command-and-control, shell execution, screenshots, audio recording, and Telegram Desktop data theft. The campaign targets Iranian dissidents, journalists, and academics with fake KeePass, Telegram, WhatsApp, and Pictory installers. The DOJ seized four related domains in March 2026 and the FBI published a HEAVYGRAM FLASH report on September 15.

GBHackersupdated · 1d agofirst · 1d agoThreat actor in the wild 10 sources

Druva expands identity resilience with ransomware detection

Druva launched Ransomware Detection and expanded Identity Resilience, using AI analysis of backup data to confirm ransomware impact and guide recovery.

Druva announced new Identity Resilience capabilities and launched Ransomware Detection, powered by a proprietary AI threat pipeline and Dru MetaGraph. The ransomware feature analyzes backup snapshots for patterns like ransom notes and mass file renaming, then validates findings with entropy, MIME type, and file integrity forensics. Dru MetaGraph maps identity activity across Microsoft Entra ID, Active Directory, and Okta, reconstructs attack paths with MITRE ATT&CK mapping, and generates pre-validated recovery plans tied to clean snapshots.

Help Net Security · 1d agoTools1

CISA Urges Organizations to Deploy Cyber Decoys to Detect Hackers Inside Networks

CISA's new guidance urges organizations to deploy cyber decoys like honeytokens and tripwires to detect attackers using valid credentials and living-off-the-land techniques.

CISA published 'Using Cyber Decoys to Strengthen Detection and Response' on September 16, 2026, advising decoy assets that appear legitimate but generate high-confidence alerts when accessed. It describes tripwires, breadcrumbs, and honeytokens such as fake usernames, passwords, API keys, and cloud access tokens, and recommends starting with low-complexity deployments like nonfunctional Active Directory accounts, decoy file shares, and isolated mimic hosts. The agency warns decoys must be segmented and nonfunctional to prevent attackers pivoting to real systems, and aligns decoy planning with MITRE Engage and ATT&CK.

GBHackers · 1d agoAdvisory

CISO's Expert Guide to Agentic Pentesting for Websites

A new free guide urges CISOs to adopt autonomous AI agents for continuous website pentesting as attackers weaponize vulnerabilities in about five days.

A free guide argues annual pentesting is obsolete, citing Verizon's 2026 DBIR finding that vulnerability exploitation starts 31% of breaches and Mandiant telemetry showing a roughly five-day average time-to-exploit versus a 43-day median patch time. It highlights agentic capabilities such as XBOW topping HackerOne's US leaderboard in 2025 and peer-reviewed agents exploiting 87% of one-day flaws unaided. The guide outlines vendor evaluation criteria, including provable work-item coverage, an independent validator agent, and browser-native operation, plus governance guardrails before production use.

The Hacker News · 1d agoIndustry

Top 10 Best Google Cloud (GCP) Security Tools in 2026

An editorial scorecard ranks the top ten Google Cloud security tools for 2026, with Wiz, Sysdig, and Security Command Center leading on correlation, GKE runtime, and native depth.

The roundup evaluates ten GCP security tools across five weighted criteria including GCP-native depth, correlation, runtime protection, multicloud parity, and value. Google Security Command Center is positioned as the included native floor, while Wiz and Sysdig top the weighted scores at 4.50, followed by Prisma Cloud at 4.40. The piece notes Forseti is deprecated and that Lacework is now Fortinet's FortiCNAPP, and flags diligence around Google's acquisition of Wiz. It is an editorial assessment, not a lab test, with pricing compared by model only.

Cyber Security News · 1d agoIndustry1

RatHat Abuses Android Wireless Debugging to Gain Shell Access and Steal Banking PINs

New Android banking trojan RatHat abuses Wireless Debugging to gain shell access and steals banking PINs and OTPs via raw touch capture.

Zimperium and zLabs analyzed RatHat, an Android banking malware linked to China-based actors that chains Accessibility abuse and Wireless Debugging to obtain a local ADB shell without a host computer. Masqueraded Go binaries in /data/local/tmp provide persistence and an FRP reverse tunnel, while a getevent-based collector maps touch coordinates to PIN pads and pattern locks using locateValues.json layouts. It targets banking, crypto, WeChat and Alipay apps through smishing, malicious ads, and HTML overlays, and serializes the accessibility tree for a generative AI assistant to automate on-screen actions. Layered anti-analysis includes malformed DEX, a padded manifest, and debugger, Frida, and emulator checks.

GBHackersupdated · 4h agofirst · 1d agoMalware in the wild 6 sources

BambooToken: The Malware That Speaks MQTT to Stay Under the Radar

Lumen's Black Lotus Labs uncovered BambooToken, a Windows and Linux malware family using MQTT broker-based C2 and DLL sideloading across Asia since February 2023.

Lumen Black Lotus Labs identified BambooToken, a multiplatform malware family that exchanges commands through MQTT brokers so infected hosts never contact the C2 server directly, active from at least February 2023 through July 2026. The Windows variant sideloads via Tendyron's OnKey hardware-token software used in Chinese banking and government, or impersonates Kingsoft Office, without either vendor's signing certificate being compromised; a Linux build appeared by December 2025 with shell, file transfer, and system information commands. Victims include MikroTik and DrayTek routers in Singapore, Cambodia, and Vietnam reached after internet-wide SNMP scanning, and Lumen cannot attribute the family to any known actor.

Security Affairs · 1d agoMalware in the wild1

German Manufacturer Shrinks Security Alert Response While Protecting 10,000 Endpoints

Vendor case study: a German manufacturer's five-person SOC cut alert triage time using ANY.RUN's cloud sandbox across 10,000 endpoints.

ANY.RUN published a case study in which a five-person security team at an unnamed German manufacturer replaced an air-gapped forensic laptop with its cloud-managed interactive sandbox, protecting roughly 10,000 endpoints and 10,000 users. The vendor claims a median 15 minutes saved per alert, 20-40 daily tasks processed, a 2.5-minute alert-to-isolation target, and a 95% agreement rate between analyst and sandbox verdicts; all figures are vendor-supplied with the customer identity withheld. The writeup also describes detonating a multi-stage phishing chain from a PDF link to a password-protected ZIP to malware execution.

Cyber Security Newsupdated · 1d agofirst · 1d agoIndustry 3 sources

Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems

Check Point identifies Noodle RAT as a distinct cross-platform Windows/Linux backdoor used by Chinese-speaking actors against Asia-Pacific organizations since 2016.

Check Point assesses Noodle RAT, also known as ANGRYREBEL, as a distinct backdoor family rather than a variant of Gh0st RAT or Rekoobe, with separate Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) variants sharing a common command-and-control design. The Windows implant runs filelessly via shellcode with loaders like MULTIDROP and MICROLOAD, while the Linux variant provides reverse shells, file management, and SOCKS tunneling after exploitation or web-shell placement on exposed servers. Groups including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper have deployed it against organizations in Thailand, India, Japan, Malaysia, and Taiwan. Check Point released sample hashes and C2 IP indicators alongside the analysis.

Cyber Security News · 2d agoMalware in the wild 2 sources

Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites

Infoblox links China-aligned APT PeckBirdy C2 infrastructure hidden in casino and adult websites targeting Asian government, finance, IT, and education sectors.

Infoblox researchers report that China-aligned APT groups have used casino and adult websites as cover for PeckBirdy, a JavaScript command-and-control framework active since 2023. The sites embed C2 servers, register service workers for persistence, and serve fake browser-update prompts delivering backdoors capable of running commands, stealing credentials, and providing remote access. Targeted sectors across Asia include education, IT, banking, financial services, and government. Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, with detection coverage on VirusTotal ranging from 13 detections to none.

Cyber Security Newsupdated · 24m agofirst · 2d agoThreat actor 3 sources

Rubrik MCP gives AI agents controlled access to security intelligence

Rubrik launched MCP support exposing Rubrik Security Cloud APIs to enterprise AI agents with RBAC, configurable permissions, and OWASP MCP Top 10 guardrails.

Rubrik announced Rubrik MCP (Model Context Protocol), giving organizations' AI agents a secure, programmable path to Rubrik's data, identity, and application intelligence via the Rubrik Security Cloud API schema. Teams can save multi-step recovery or compliance workflows as reusable, deterministic tools, with role-based access control parity and OWASP MCP Top 10 aligned guardrails. Rubrik engineered its agent architecture with Anthropic's teams for multi-step reasoning in incident response, and says Rubrik AI is now trusted by one-third of its global customers.

Help Net Security · 2d agoTools1

Top 10 Best AWS Security Tools in 2026

Editorial roundup ranking the ten best AWS security tools of 2026, from native GuardDuty and Security Hub to CNAPPs like Wiz and Prisma Cloud.

The article recommends enabling AWS-native services first: GuardDuty for threat detection, Security Hub for posture aggregation, the free IAM Access Analyzer, plus CloudTrail logging and Config rules. It then reviews third-party platforms including Wiz, Palo Alto Prisma Cloud, CrowdStrike Falcon Cloud Security, Trend Micro Cloud One, and Orca Security. It is an editorial vendor assessment with pricing described by model only, highlighting cross-account correlation and attack-path prioritization as third-party differentiators.

Cyber Security News · 2d agoTools

You don’t have to join the hack-back program to inherit its risk

A new US presidential memorandum creates a vetted private hack-back program, leaving participating vendors and their customers with untested legal liability and collateral risks.

The August 12 National Security Presidential Memorandum directs the National Coordination Center, run jointly by DOJ and DHS, to approve covert surveillance and disruptive Cyber Effects Operations by vetted private companies, with a forfeitable bond of at least $1 million required as a contract condition. The analysis argues the criminal shield rests on an untested reading of the CFAA exemption at 18 U.S.C. 1030(f), with no civil safe harbor, no state-law preemption and no foreign-law protection. Non-participating organizations can still inherit risk through shared infrastructure collateral damage, lack of customer disclosure, Lloyd's bulletin Y5381 state-backed attack exclusions, and threat-intelligence pipelines feeding offensive proposals.

CSO Online · 2d agoPolicy & legal

NIST Issues New Guidance to Protect SSO and API Tokens From Theft and Forgery

NIST released IR 8587 giving agencies and cloud providers recommendations to prevent identity token forgery, theft, and misuse in SSO and API environments.

NIST Internal Report 8587, released September 15, 2026, provides implementation recommendations covering token creation, signing, validation, storage, revocation, and lifecycle management for SAML, OpenID Connect, and OAuth 2.0 environments. It builds on SP 800-53 Rev. 5.1.1 and incorporates lessons from breaches involving stolen signing keys, abused OAuth applications, and replayed federated assertions. Recommendations include strong signing algorithms, strict claim validation, short token lifetimes, token binding, leakage prevention, and monitoring for abnormal token use.

GBHackers · 2d agoAdvisory 2 sources

12 Best CASB Solutions Compared (2026): Features & Pricing

GBHackers' 2026 buyer's guide compares 12 CASB-capable vendors, arguing standalone CASB pricing has dissolved into per-user SSE subscriptions.

The article evaluates twelve CASB-capable platforms including Microsoft Defender for Cloud Apps, Palo Alto Networks' Prisma Access CASB, Netskope, iboss, Forcepoint ONE (Bitglass), Trend Micro Cloud App Security, and Skyhigh Security. It frames purchasing around SSE bundle economics, noting Defender for Cloud Apps ships inside Microsoft 365 E5 while Netskope, Zscaler, and Skyhigh price CASB into per-user SSE tiers. It also flags Saviynt, common on legacy roundups, as an IGA vendor rather than a true CASB.

GBHackers · 2d agoIndustry 3 sources

ANY.RUN & SentinelOne: One Workspace, Instant Context for Rapid Response

ANY.RUN integrates its interactive sandbox, IOC lookups, and STIX/TAXII threat feeds natively into SentinelOne for faster automated malware triage.

ANY.RUN and SentinelOne launched connectors that embed interactive sandbox analysis and threat intelligence into the SentinelOne console via Singularity Hyperautomation. Suspicious files and URLs from alerts are automatically submitted to the ANY.RUN sandbox, with behavioral verdicts and risk scores returned into alert notes. On-demand IOC lookups draw on sandbox history from 16,000 organizations and 700,000 analysts. A separate STIX/TAXII feed streams verified malicious IPs, domains, and URLs through the SentinelOne Marketplace TAXII Connect app.

ANY.RUN · 2d agoTools

Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities

Apple released iOS 27 and iPadOS 27 patching roughly 126 vulnerabilities across kernel, WebKit, sandboxing, and authentication components; no active exploitation reported.

Apple released iOS 27 and iPadOS 27 on September 14, 2026, fixing approximately 126 vulnerabilities across more than 90 components, including the kernel, WebKit, AppleKeyStore, Sandbox, and TCC. Flaws include memory corruption, information disclosure, denial-of-service, logic errors, sandbox escapes enabling root privileges, and a Bluetooth issue permitting remote code execution in specific circumstances. Apple also shipped iOS 26.7 and iPadOS 26.7 with over 80 fixes for users delaying the major upgrade, including 75 vulnerabilities shared with iOS 27. No vulnerabilities were reported as actively exploited at release time.

GBHackers · 2d agoAdvisory