Furtex Toolkit Enhances Linux Post-Exploitation and Evasion Research
A new open-source toolkit named Furtex offers security researchers and red teamers advanced capabilities for testing Linux endpoint defenses through novel evasion techniques.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,662 stories synthesized.
A new open-source toolkit named Furtex offers security researchers and red teamers advanced capabilities for testing Linux endpoint defenses through novel evasion techniques.
A Pennsylvania bank's SEC filing over an employee's unauthorized AI use for customer data processing marks a new frontier in cyber disclosure, underscoring the risks of 'shadow AI'.
Cosmetics giant Estée Lauder has disclosed a data breach impacting customer personal information, stemming from the exploitation of a vulnerability in Oracle E-Business Suite.
Cloudflare announced the general availability of its Internal DNS service, a unified platform for managing both private and public DNS resolution, aiming to simplify split-horizon DNS and extend Zero Trust policies.
Ivanti is piloting the use of large language models to automate the identification and remediation of software vulnerabilities, aiming to accelerate patching and improve security.
Fraudsters are using fake social media profiles and AI-generated videos to impersonate the FBI and its Internet Crime Complaint Center (IC3) to deceive and re-victimize individuals, the FBI warns.
A theoretical attack, dubbed Bit2Watt, could allow malicious cloud tenants to destabilize power grids by manipulating GPU workloads, potentially causing blackouts.
A sophisticated phishing campaign dubbed 'The TFF Trap' is employing fileless techniques and disguised loaders to deliver multiple remote access Trojans and stealers, aiming to facilitate Business Email Compromise (BEC) attacks.
The FakeGit campaign has compromised nearly 7,600 GitHub repositories, using them to distribute the SmartLoader malware, with a concerning AI-driven evolution dubbed AgentBaiting.
Scammers are rapidly capitalizing on the release of Christopher Nolan's 'The Odyssey' by deploying fake piracy websites that lure users with malicious browser warnings or disguise malware as movie downloads.
Hackers accessed South Korea's Ministry of Foreign Affairs' online education system for nine months, exfiltrating personal data of current and former employees.
The Cruciferra crypter service, marketed on underground forums, employs sophisticated techniques like process ghosting and kernel-driver abuse to obfuscate malware and evade security software.
Gig economy platform Paidwork has suffered a massive data breach, exposing the sensitive personal and banking information of over 23 million users, leaked publicly on dark web forums.
Attempts to block AI models for cyber defense are futile; experts urge a strategic shift towards robust defensive measures and shared responsibility between industry and government.
The threat actor known as JadePuffer has resurfaced with a new ransomware variant, ENCFORGE, specifically engineered to destroy trained AI model artifacts, marking a significant escalation in ransomware tactics.
Microsoft will cease OneDrive sync app updates for Windows 10 versions 21H2 and earlier on August 15, 2026, potentially exposing users to security risks.
This week's security landscape is dominated by critical vulnerabilities in widely used software, including WordPress, SonicWall, Microsoft SharePoint, and OpenSSL, with many already being actively exploited in the wild.
Italy's data protection authority has fined WINDTRE €1.7 million for significant security lapses that enabled two data breaches, compromising over 365,000 customers.
SentinelOne Labs proposes an 'agentic SOC' model, leveraging AI-driven data pipelines to normalize disparate telemetry, thereby enhancing defensive velocity and addressing the administrative burden on security analysts.
Researchers uncover an exposed WebDAV server meticulously engineered as a malware delivery lab, complete with AI-generated lures and automated testing, signaling an accelerated attacker development cycle.
A critical vulnerability in the official Kimai Docker image allows unauthenticated attackers to forge authentication cookies and take over user accounts, including administrators.
A new malware strain, HollowGraph, has been discovered weaponizing Microsoft 365 calendars and Graph APIs to establish covert command and control channels, evading traditional detection methods.
Check Point Research's latest bulletin covers a wide array of threats including a Jscrambler supply chain attack, Fairlife ransomware incident, and AI-powered exploits targeting government and financial sectors.
A writer was mistakenly arrested due to Flock's AI license plate recognition system misinterpreting partial plate data, highlighting concerns about the technology's accuracy and broader surveillance capabilities.