Similar Posts
Weekly Cyber Security Newsletter Bulletin – Certighost Exploit, Checkpoint 0-day, HTTP/2 Flaw, Notepad++ Plugin Abuse +20 Stories
Threat actors continued to combine classic exploitation techniques with AI-accelerated tooling this week, from a 15-year-old NGINX bug and an actively exploited Check Point authentication flaw to autonomous AI agents chaining zero-days against Hugging Face. Below is a roundup of 18 major stories covering ransomware, AI security, kernel vulnerabilities, cloud/SaaS abuse, and critical infrastructure flaws….
AI is killing low cost smartphones
Except for the second user/refurbished smartphone markets, AI means the days of cheap phones are over, with huge price pressures putting low-end vendors out of business. Omdia data confirms that Apple and Samsung are undisputed kings of the hill, combining for 42% of the market even as smartphone sales overall have seen a 4% average decline. The…
Program to rotate cyber personnel through federal agencies saw little use
A total of eight cyber personnel have served in a program that began in 2022 to rotate workers between federal agencies to bolster the workforce, a watchdog report said Thursday. Over the life of the Federal Rotational Cyber Workforce program that effectively went away last year, 13 agencies offered 106 positions and received 634 applications,…
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thailand’s Ministry of Finance. The activity was uncovered by threat intelligence company Hunt.io and security researcher Bob Diachenko after they discovered several exposed web directories containing hundreds of files associated with the operation….
Why Modern SOCs Need Multi-Layered Detections
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on credential theft and…
How to Protect Yourself After the Canvas Education Data Breach + Fake Amazon Recall Texts
If you have ever checked your child’s grades online, submitted a college paper through a school portal, downloaded homework assignments, or received messages from a teacher through a classroom app, there is a good chance you have used Canvas, a nationwide learning management system that was just in a massive data breach. This is exactly the moment McAfee+ Advanced was built for….