Skip to main content

Cybersecurity

General cybersecurity news and analysis

CometJacking: Risky Attack Exposes Data — Must-See Fixes

CometJacking: Risky Attack Exposes Data — Must-See Fixes

One click can turn your helpful AI into a sneak thief — CometJacking hides malicious prompts in links that trick Perplexity’s Comet into leaking email, calendar and connected data. Stay safe by updating clients, reviewing agent permissions, and avoiding unfamiliar links while these agentic AIs get harder to fool.

Analyst 207
Palo Alto portal scans: Stunning 500% Risky Surge

Palo Alto portal scans: Stunning 500% Risky Surge

Is your firewall login page being probed right now? GreyNoise logged a nearly 500% one‑day surge in targeted scans against Palo Alto Networks admin portals — a structured reconnaissance blast that should prompt immediate checks: lock down management interfaces, enable MFA, patch, and review logs.

Analyst 207
Rhadamanthys Stealer: Exclusive Dangerous Threat

Rhadamanthys Stealer: Exclusive Dangerous Threat

Rhadamanthys has evolved from a simple credential stealer into a stealthy, full-stack threat that fingerprints devices and hides stolen data inside ordinary PNG images while pairing with proxy and crypt services for turnkey attacks. Defenders should boost telemetry, enforce phishing‑resistant MFA, and add content‑aware inspection (including steganalysis) to spot these covert exfiltration channels.

Analyst 207
IIS server hijacking: Stunning Risky Threat

IIS server hijacking: Stunning Risky Threat

A Chinese‑speaking cybercrime group has been quietly hijacking Microsoft IIS servers to inject poisoned pages that hijack search results and steer real traffic to scams and affiliate schemes. If you run IIS sites, now’s the time to patch, lock down admin access, and add file‑integrity and content monitoring to stop stealthy SEO fraud before it ruins your reputation.

Analyst 207
consulting GitLab instance: Must-Have Risky Breach Fixes

consulting GitLab instance: Must-Have Risky Breach Fixes

Red Hat confirmed that an unauthorized party accessed a consulting GitLab instance and exfiltrated data, spotlighting how even non-core environments can expose customers to serious risk. Act now: audit access logs, rotate credentials and secrets, isolate consulting projects, and enforce least-privilege and stronger identity controls to stop lateral attacks.

Analyst 207
Drone incursions: Risky, Stunning Threat to Airports

Drone incursions: Risky, Stunning Threat to Airports

Late-night drone sightings over Munich forced authorities to suspend flights during Oktoberfest, leaving thousands stranded. The episode shows how cheap, hard-to-detect drones can paralyze airports and why better detection, rules and coordination are urgently needed.

Analyst 207
digital ID Must-Have or Risky? Exclusive Warning

digital ID Must-Have or Risky? Exclusive Warning

The UK says its new digital ID will be optional — a welcome reassurance after a 2.76 million-signature petition — but critics warn voluntariness won’t mean much without strong legal safeguards, inclusive design and independent oversight. Whether it stays a genuine choice or becomes a de facto requirement will come down to implementation, privacy protections and how businesses adopt the system.

Analyst 207
Oracle E-Business Suite Critical Patch: Must-Have Fix

Oracle E-Business Suite Critical Patch: Must-Have Fix

Oracle’s July patch closes the immediate Clop-linked weakness in E-Business Suite portals — but with thousands of internet-facing, heavily customized EBS installs still at risk, organizations need to patch, isolate access, and harden defenses now to avoid extortion.

Analyst 207
Oracle E-Business Suite: Urgent Must-Have Patch

Oracle E-Business Suite: Urgent Must-Have Patch

Oracle warned and patched critical E-Business Suite flaws in July 2025 — yet attackers are actively scanning and exploiting systems that haven’t applied the fixes, turning patch delays into real-world breaches. If your ERP runs on EBS, now’s the time to prioritize updates, isolate vulnerable modules, and tighten access controls before the next compromise hits payroll, procurement, or customer trust.

Analyst 207
Lone horse stands on cracked asphalt road under distant streetlight, with crumbling cityscape and full moon in background.

Cavalry Werewolf Exclusive: Dangerous State-Grade Threat

BI.ZONE’s new report exposes Cavalry Werewolf, a stealthy campaign that pairs the FoalShell backdoor with StallionRAT to quietly map and then exploit Russian public-sector networks—an urgent reminder that reusable, modular tooling lets attackers scale persistent intrusions. Defenders should prioritize centralized telemetry, network segmentation, MFA and practiced playbooks to spot the subtle reconnaissance before it escalates.

Analyst 207
subpoena management platform Stunning Risky Outage Exposes

subpoena management platform Stunning Risky Outage Exposes

When Kodex — the subpoena-tracking platform trusted by police and big tech — went dark after its domain was frozen over a forged legal order, agencies were left scrambling and the outage revealed how social engineering against registrars and cloud providers can cripple critical legal services without touching any code. It’s a wake-up call to strengthen verification, add redundancy, and treat DNS and registrar governance as core security, not an afterthought.

Analyst 207
Context wins: Must-Have Best AI Defense Tactics

Context wins: Must-Have Best AI Defense Tactics

Context wins — whoever understands systems fastest will shape the outcome of the AI-accelerated attack/defense race. Build inventories, sharpen telemetry, harden processes, and share actionable intelligence to tilt the balance back toward defenders.

Analyst 207
government shutdown: Exclusive Risky Cyber Warning

government shutdown: Exclusive Risky Cyber Warning

When the phones go silent, attackers don’t—so a federal shutdown that furloughs about 65% of CISA staff leaves dangerous blind spots in the nation’s cyber defenses. Now is the time for businesses and local agencies to harden defenses, share intel, and push for smarter funding solutions before a temporary gap becomes long-term damage.

Analyst 207
Python backdoors: Exclusive Risky Threat Warning

Python backdoors: Exclusive Risky Threat Warning

Researchers warn the Confucius espionage group is shifting from weaponized documents to Python backdoors like AnonDoor, widening the attack surface and making detection much harder. Organizations should boost visibility into scripting, enforce least privilege, and monitor package and repository activity before attackers hide in legitimate developer tooling.

Analyst 207
IT Modernization: Must-Have Strategies for Best Missions

IT Modernization: Must-Have Strategies for Best Missions

Federal IT modernization isn’t just about new tech—it’s a pragmatic playbook for delivering faster, more secure services using cloud, AI, automation and zero-trust practices while keeping critical missions running without disruption. Leaders shared phased approaches, shared platforms and workforce-first strategies that balance risk, procurement and policy to turn legacy systems into resilient, mission-ready capabilities.

Analyst 207
free VPN apps: Risky Secrets & Must-Have Warning

free VPN apps: Risky Secrets & Must-Have Warning

Think “free VPN” means safe? A Zimperium study shows many no-cost VPN apps harbor serious flaws that can leak your data or let attackers intercept traffic — so choose reputable, audited services or risk trading privacy for peril.

Analyst 207
commercial spyware firms: Risky EU Ties Exposed

commercial spyware firms: Risky EU Ties Exposed

European MPs are demanding answers after investigations showed EU research grants and procurement money have flowed — sometimes via subcontractors — to companies tied to commercial spyware, raising urgent questions about whether public funds are enabling surveillance of journalists, activists and political rivals. Europe must reconcile its push for tech sovereignty with stronger transparency, vetting and clawback rules to ensure funding defends, not undermines, democracy.

Analyst 207
delivery of pentest results: Must-Have Best Practices

delivery of pentest results: Must-Have Best Practices

Penetration testing uncovers real attack paths, but static PDFs and emails let critical fixes stall — automating delivery into ticketing, CI/CD, and dashboards turns findings into fast, measurable remediation. Adopt continuous workflows to shrink exposure windows, boost collaboration, and make pen-test insights actually stick.

Analyst 207
detection gaps: Exclusive Best Practices to Stop Breaches

detection gaps: Exclusive Best Practices to Stop Breaches

Stop drowning in alert noise—prioritize the right telemetry, map gaps to MITRE ATT&CK, build chained detections and automated enrichment so analysts can find real threats faster. Start small, measure actionable alerts per analyst-hour, and invest in people and integration to close gaps before attackers exploit them.

Analyst 207
Cybersecurity Information Sharing Act: Must-Have Fix Needed

Cybersecurity Information Sharing Act: Must-Have Fix Needed

With key protections of the Cybersecurity Information Sharing Act expired, companies and government teams now face legal uncertainty that could slow the rapid data-sharing defenders rely on — giving attackers a wider window to strike. Unless lawmakers or industry act quickly to restore clear, privacy-conscious rules, our ability to detect, analyze and stop cyberattacks may fragment just as threats grow more sophisticated.

Analyst 207
agentic AI Must-Have Defense: Risky Breach Guide

agentic AI Must-Have Defense: Risky Breach Guide

Forrester warns agentic AI could spark a major breach by 2026, so now’s the time for boards and security teams to treat agentic risk as design — not a checkbox — by locking down privileges, boosting observability, and baking in human-in-the-loop controls before autonomous agents can act maliciously at scale.

Analyst 207
Red Hat repositories Exclusive Critical Leak

Red Hat repositories Exclusive Critical Leak

Red Hat is scrambling after a hacking group called the Crimson Collective claims to have leaked roughly 570 GB from about 28,000 private repositories — including source code, internal notes and customer documents — a breach that could upend supply chains and privacy protections. If confirmed, assume exposure: rotate credentials, audit CI/CD and follow Red Hat’s guidance while investigators work to assess the full scope.

Analyst 207
phishing Warning: Exclusive Risky Threat & Must-Have Fixes

phishing Warning: Exclusive Risky Threat & Must-Have Fixes

ENISA warns that simple phishing emails and unpatched systems were behind most EU cyber intrusions last year, turning tiny mistakes into big national-security headaches. It’s a wake-up call to harden the basics—MFA, patching, email defenses, and smarter user training—before the next click becomes a crisis.

Analyst 207
SharePoint incident: Stunning Air Force Privacy Scare

SharePoint incident: Stunning Air Force Privacy Scare

The Air Force is investigating a privacy-related SharePoint outage that left personnel without access to mission files and collaboration tools while working with Microsoft and cyber partners to restore normal operations. The disruption highlights how reliant modern missions are on commercial cloud services — and why stronger safeguards and clearer communication are essential when those systems fail.

Analyst 207