Tag: nation state threats
42 articles

Pentagon Deploys Directed-Energy System to Down Hostile Drones at Border
The Pentagon is fighting back against cartel drones at the southern border, using a powerful military laser system to shoot down three hostile unmanned aircraft that were smuggling humans and spying on US personnel. This high-tech defense move marks a new front in the battle against border threats.

Vulnerability Management Scrambles to Keep Pace with AI-Driven Discovery
The National Vulnerability Database (NVD) is undergoing a major overhaul as it struggles to keep up with a staggering 30,000 reclassified vulnerabilities, now marked as "Not Scheduled" for further analysis, amid a surge in AI-driven discoveries. This change aims to help manage the overwhelming backlog through selective processing and automation.

CISA Warns of Persisting Vulnerabilities
Threat actors are still finding success by exploiting simple, preventable software weaknesses that have been known for years - and it's a problem that CISA says could have been designed out of products from the start. The agency's review reveals that decades-old bugs, like improper input validation, continue to plague the industry.

Tech Giants Warn of AI-Driven Cyber Threats, Push for AI-Powered Defenses
The world's top tech and security companies are sounding the alarm: AI-driven cyber threats are on the rise and we only have a small window of time to boost our defenses before attacks become more widespread and sophisticated. Over 100 industry giants, including OpenAI, Google, and Microsoft, are urging for AI-powered defenses to protect critical infrastructure like hospitals and water treatment plants.

Tech Giants Warn of Looming AI-Enabled Cyber Attack Surge
Over 100 tech giants, including OpenAI, Google, and Microsoft, are sounding the alarm: AI-enabled cyber attacks are about to surge, becoming more widespread and sophisticated, threatening critical public services. The clock is ticking - and collective action is needed now to harness AI for defense.

Tech Giants Urge Global AI-Powered Cyber Defense Surge
The clock is ticking: over 100 tech giants, including OpenAI, Google, and Microsoft, are sounding the alarm that we must urgently boost our AI-powered cyber defenses to avoid a surge in sophisticated attacks. They're calling on us to take action now to reduce risk before it's too late.

ATF Probes Ransomware Gang's Claims of Major Cybersecurity Breach
A ransomware gang has claimed responsibility for a major cybersecurity breach, prompting a swift response from the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). The ATF is investigating the incident, but few details have been released so far.

Federal Agencies Face Shrinking Window to Defend Against Cyber Threats
The threat landscape has drastically changed: cyber attackers can now exploit vulnerabilities in as little as two days, leaving federal agencies with a shrinking window to defend against threats. To stay ahead, they must shift their focus from reacting to attacks to anticipating and preparing for what's next.

Ransomware gangs exploit Microsoft SharePoint flaw
Ransomware gangs are actively exploiting a high-severity Microsoft SharePoint flaw, known as CVE-2026-45659, that allows them to execute arbitrary code on unpatched servers, and it's crucial to patch up ASAP to avoid falling victim. Microsoft has already released security updates for affected SharePoint versions, so make sure to get those installed pronto!

OpenAI Bolsters Security for Advanced AI Model Astra
OpenAI is stepping up security for its advanced AI model Astra, implementing stricter controls such as isolated testing environments and enhanced encryption to prevent potential cyber threats. The company has flagged Astra as a model that may possess critical cyber capabilities, requiring extra precautions to ensure safety.

Interpol Warns AI Fuels 55% of African Cybercrime
Cybercrime is on the rise in Africa, with a whopping 55% of attacks now fueled by AI, which is automating every stage of a cyber-attack, from sneaky phishing emails to cunning evasion tactics. This alarming trend has led to a staggering jump in losses, from $192m in 2024 to $484m last year.

Big Tech Bolsters Open-Source AI as Attackers Target Vulnerabilities
Big tech giants like Nvidia, Amazon, and Google are joining forces to supercharge open-source AI, embracing a new era of transparency and collaboration. By adopting open-weight models, they're acknowledging that the future of AI safety lies in community-driven innovation and collective vigilance.

FBI Warns of AI-Powered Vulnerability Exploits
The FBI is sounding the alarm on a new threat: AI-powered vulnerability exploits that can target the very foundation of our digital infrastructure, including operating systems, security, web infrastructure, and encryption. This emerging threat has the potential to revolutionize the way law enforcement approaches cybersecurity.

Industry Leaders Forge Open Secure AI Alliance to Counter Evolving Threats
In response to rising AI threats, industry leaders are joining forces to launch the Open Secure AI Alliance, aiming to develop and share cutting-edge cybersecurity defenses to safeguard software and AI agents. This move comes on the heels of a recent incident where AI models breached Hugging Face data, highlighting the urgent need for coordinated action.

US Coast Guard Seeks Tech to Counter Unmanned Underwater Vehicles
The US Coast Guard is on the hunt for cutting-edge tech that can not only detect but also defeat and mitigate unmanned underwater vehicles (UUVs) that could be used for malicious activities like smuggling, sabotage, and surveillance. They're seeking systems with a powerful punch that can effectively neutralize these underwater threats.

Anubis Ransomware Targets Coca-Cola's Fairlife, Threatens Data Leak
The Anubis ransomware gang has claimed responsibility for a cyberattack on Fairlife, a subsidiary of The Coca-Cola Company, boasting that they encrypted the company's systems and stole a whopping one terabyte of corporate data. With a deadline looming, the gang is threatening to leak the sensitive information unless Coca-Cola agrees to negotiate by the end of the week.

Ransomware Targets Government Agencies Daily, Study Reveals
Government agencies are under attack, with ransomware hitting a staggering 187 organizations in just six months - that's one body disrupted every single day, on average. This alarming trend is up 13% from the previous half-year, leaving public services vulnerable and citizens at risk.

CISA Exposes Lessons from AWS GovCloud Key Incident Response
When a security researcher uncovered exposed credentials in a public GitHub repository, CISA sprang into action, swiftly mitigating any potential exposure to its cloud resources and code repositories. Thanks to the researcher's sharp eyes and KrebsOnSecurity's reporting, CISA was able to respond quickly and contain the incident.
UK Cyber Monitoring Centre Probes Canvas Breach Impact
The UK's Cyber Monitoring Centre is investigating a massive breach of Canvas, a popular learning management system, that exposed sensitive data at nearly 160 UK universities and colleges, as part of a global incident affecting around 9,000 educational institutions. The breach was caused by a notorious cybercrime group that exploited vulnerabilities on April 29 and again on May 7.

Vulnerability Management Faces AI-Driven Time Crunch
The time it takes for hackers to exploit a newly discovered vulnerability has dramatically shrunk from 53 days to just 8 hours, thanks to AI-driven automation that accelerates the process of finding and weaponizing weaknesses. This alarming trend makes it increasingly challenging for organizations to keep pace with patching and remediation efforts.

Cybercrime Surges Across Asia and South Pacific, Hits 30% of All Crime
Cybercrime is surging across Asia and the South Pacific, now accounting for over 30% of all recorded crime, with organised networks leveraging AI, ransomware, and social engineering on a massive scale. The rapid rise is driven by rapid digital adoption and new technologies.

Microsoft Warns AI Adoption Exposes Organizations to New Malware Threats
Microsoft's senior security researcher warns that the AI tools making our jobs easier can also be exploited by threat actors, highlighting a new and urgent risk for organizations to manage. As AI adoption grows, companies must recognize it as both a valuable asset and a potential attack surface that requires careful protection.

Malicious NuGet Package Exfiltrates Sicoob Banking Credentials
A malicious NuGet package, masquerading as a C# SDK for a major Brazilian financial system, was designed to steal sensitive banking credentials, including client IDs, PFX passwords, and certificate bytes, from unsuspecting developers. This rogue package, downloaded nearly 500 times, put automation and security at risk.

MyPillow Targeted in Play Ransomware Attack
MyPillow has been hit by a ransomware attack, with hackers claiming to have stolen highly sensitive data including private documents, financial information, and employee details. The attackers are demanding a ransom and threatening to publish the stolen data unless paid.