❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security

Next-Level Test for Secure Transportation Vehicle

By: Staff
11 September 2026 at 07:40
9/11/26
SECURE TRANSPORTATION
Enable IntenseDebate Comments:Β 
Enable IntenseDebate Comments

With rockets propelling it down the sled track at Sandia National Laboratories, a semitrailer loaded with mock nuclear weapons slammed into a barrier. It took mere moments to complete the second and final full-scale crash test of the Mobile Guardian Transporter, a next-generation system that will carry nuclear weapons and other sensitive materials for the Department of Energy’s Office of SecureΒ Transportation.

read more

When the Dust Settles: Researchers Measure How Everyday Activity Spreads Hazardous Dust

11 September 2026 at 07:38
9/11/26
HAZARDOUS DUST
Enable IntenseDebate Comments:Β 
Enable IntenseDebate Comments

Argonne researchers study the movement of dust particles from concrete surfaces during a simulated radiological contamination scenario, measuring how pedestrians and moving cars affect the spread of theΒ particles.

read more

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

11 September 2026 at 08:48

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.

4 Ways Organisations Create Non-Human Insider Risk

By: The Gurus
10 September 2026 at 11:55

As AI agents become embedded across business operations, they are also creating a new category of insider risk. Unlike traditional insiders, these non-human identities can act at machine speed, operate continuously and access multiple systems without direct human oversight.

The danger rarely stems from one obvious security failure. Instead, it emerges when several weaknesses overlap. Here are four common ways organisations inadvertently create non-human insider risk:

1. Persistent access

Long-lived API keys, OAuth tokens, service accountsΒ and standing privileges give agents constant access long after it is needed.

2. Excessive privilege

Many agents can read, write, modify, approve, deleteΒ or deploy far more than their actual tasks require.

3. Untrusted input

Agents consume information from emails, support tickets, documents, chat conversations, websites and repositories. If attackers can influence those inputs, they may also influence the agent’s decisions.

4. Limited behavioural monitoring

Many organisations can tell that an AI agent performed an action. Far fewer can determine whether that action actually made sense. Logging tells us what happened, understanding whether it should have happened is a different challenge altogether.

You can read the full blog from Erich Kron, CISO Advisor at KnowBe4. Stay tuned for part 2 where Erich will reveal what security teams should do to stay secure.

The post 4 Ways Organisations Create Non-Human Insider Risk appeared first on IT Security Guru.

Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair

10 September 2026 at 08:34

UK cybersecurity specialist Core to Cloud has appointed former Currys Group CIO Andy Gamble as Chair of its Advisory Board as the company looks to accelerate the growth of its managed security services.

Gamble brings nearly 30 years of board-level technology leadership and will work with Core to Cloud on its strategic, advisory and commercial direction across the UK enterprise and mid-market sectors.

His appointment adds further experience to the company’s Advisory Board, which includes senior security leaders from major UK organisations.

From cybersecurity buyer to advisor

Gamble spent six years as Group CIO and Chief Transformation Officer at Currys PLC, where his responsibilities included large-scale technology transformation and cyber risk.

His career has also included senior CIO positions at Dyson, Sony Electronics and Essentra PLC. That experience means Gamble has spent much of his career on the customer side of the cybersecurity market, buying and managing the types of services Core to Cloud now provides.

β€œI spent the better part of three decades as a buyer of cybersecurity services, and the experience left me with a clear view of where the market falls short,” Gamble said.

β€œMost organisations understand that cyber risk is real. Far fewer have a security function that can communicate that risk clearly at board level, or a partner that moves fast enough to keep pace with the threat.”

Gamble said Core to Cloud stood out because of its focus on proactive security, adding that he intends to help the business scale its model as a challenger to conventional managed security service providers.

Supporting Core to Cloud’s next stage of growth

Based in Cirencester, Core to Cloud works with more than 150 organisations across sectors including the NHS, retail, financial services and critical national infrastructure.

Its services span Managed Detection and Response, Third-Party Cyber Risk Management, Security Assurance, Dark Web Monitoring and Threat Intelligence, and Cyber Crisis Simulation.

James Cunningham, CEO and Founder of Core to Cloud, said Gamble’s experience at the intersection of technology, risk and commercial strategy would bring a new perspective to the company.

β€œHe understands what good security looks like from the inside and brings a depth of experience and perspective that will be hugely valuable as we continue to grow,” Cunningham said.

β€œWe have an ambitious business, a strong customer base and services we genuinely believe in. Having Andy chair our board will help us build on those foundations, challenge our thinking and accelerate the next stage of Core to Cloud’s growth.”

The post Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair appeared first on IT Security Guru.

Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation

10 September 2026 at 09:30

Join the webinarΒ for a focused, 20-minute discussion onΒ Frontier Pace Governance,Β an approach to balancing automation, policy, and business risk as IT operations accelerate.

The post Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation appeared first on SecurityWeek.

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

9 September 2026 at 10:20

Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.

Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.

Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.

Fake browser makes phishing harder to spot

BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.

In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.

The fake browser page appeared to show Adobe’s legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.

Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.

Second attack follows same playbook

Huntress identified another incident on 31 August involving the same Adobe Reader lure.

This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.

The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.

Legitimate tools remain attractive to attackers

The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.

RMM abuse is a growing problem. Huntress’ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.

Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.

Read the full research here.Β 

The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.

Ivanti Patches Critical Flaws Across Enterprise Security Products

9 September 2026 at 06:28

Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.

The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek.

Thrown into the SOC: A Black Hat First-Timer’s Story

7 September 2026 at 11:00
A Black Hat SOC analyst shares how agentic workflows, Splunk ES, packet evidence, and human mentorship accelerated triage & investigation in the NOC/SOC.

Black Hat USA 2026: Safeguarding DNS with Secure Access

7 September 2026 at 11:00
Cisco is the Security Cloud Provider for the Black Hat conferences, over a decade providing DNS Security. Learn about protecting DNS with Secure Access.

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

5 September 2026 at 09:00

Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.

The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek.

❌
❌