OpenSSL Updates Close Heap Corruption and Remote Crash Weaknesses
OpenSSL has released patched builds for a broad set of vulnerabilities affecting CMS, CMP, DTLS, QUIC and cryptographic operations. Several weaknesses are remotely triggerable, making dependency discovery and...
Core Werewolf Deploys Custom CoreRAT Against Russian Defense Targets
The Core Werewolf threat group is using a newly documented Windows remote access trojan in campaigns aimed at Russian public-sector and defense organizations. Telegram lures and forged official...
Actively Exploited SharePoint Flaw Combines With RCE for Server Takeover
Two on-premises SharePoint vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers. With the authentication flaw already listed as exploited, administrators should patch exposed...
ToxNetV2 Botnet Adds AI-Guided Commands to Linux Attack Operations
Researchers have analyzed a peer-to-peer Linux botnet whose controller consults an NVIDIA-hosted AI model to propose operational actions. Human approval still gates the most consequential commands, but the...
Iran-Linked Hackers Knocked a UK Power Plant Offline for Four Days in a First-of-Its-Kind Attack
A small UK energy generator was forced completely offline for four days last month in what officials describe as the first successful cyberattack to shut down a British...
Fake Adobe Reader Site Powers a New Malware-as-a-Service Platform Targeting Windows Users
Researchers have uncovered a live malware-as-a-service operation hiding behind a convincing fake Adobe Acrobat Reader site, using a WebDAV trick and a disguised batch file to install information-stealing...
This Week in Cyber: An AI Coding Assistant Helped Run a Ransomware Attack, and Azure Logins for 9 Major Firms Hit the Dark Web
Two stories from this week show how enterprise security is being reshaped from both ends: a ransomware affiliate reportedly used an AI coding assistant to breach VPNs and...
Microsoft’s New Windows Tool Quietly Resets Chrome, Firefox, and Brave to Bing
A newly spotted Microsoft installer called MicrosoftSettings.exe pushes a browser extension that switches Chrome, Firefox, and Brave over to Bing search and the MSN homepage. Security researchers note...