Normal view
-
Information Security Buzz
- Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick
Next-Level Test for Secure Transportation Vehicle
With rockets propelling it down the sled track at Sandia National Laboratories, a semitrailer loaded with mock nuclear weapons slammed into a barrier. It took mere moments to complete the second and final full-scale crash test of the Mobile Guardian Transporter, a next-generation system that will carry nuclear weapons and other sensitive materials for the Department of Energyβs Office of SecureΒ Transportation.
-
Homeland Security Newswire
- When the Dust Settles: Researchers Measure How Everyday Activity Spreads Hazardous Dust
When the Dust Settles: Researchers Measure How Everyday Activity Spreads Hazardous Dust
Argonne researchers study the movement of dust particles from concrete surfaces during a simulated radiological contamination scenario, measuring how pedestrians and moving cars affect the spread of theΒ particles.
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.
The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.
Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars.
The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek.
4 Ways Organisations Create Non-Human Insider Risk
As AI agents become embedded across business operations, they are also creating a new category of insider risk. Unlike traditional insiders, these non-human identities can act at machine speed, operate continuously and access multiple systems without direct human oversight.
The danger rarely stems from one obvious security failure. Instead, it emerges when several weaknesses overlap. Here are four common ways organisations inadvertently create non-human insider risk:
1. Persistent access
Long-lived API keys, OAuth tokens, service accountsΒ and standing privileges give agents constant access long after it is needed.
2. Excessive privilege
Many agents can read, write, modify, approve, deleteΒ or deploy far more than their actual tasks require.
3. Untrusted input
Agents consume information from emails, support tickets, documents, chat conversations, websites and repositories. If attackers can influence those inputs, they may also influence the agentβs decisions.
4. Limited behavioural monitoring
Many organisations can tell that an AI agent performed an action. Far fewer can determine whether that action actually made sense. Logging tells us what happened, understanding whether it should have happened is a different challenge altogether.
You can read the full blog from Erich Kron, CISO Advisor at KnowBe4. Stay tuned for part 2 where Erich will reveal what security teams should do to stay secure.
The post 4 Ways Organisations Create Non-Human Insider Risk appeared first on IT Security Guru.
Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair
UK cybersecurity specialist Core to Cloud has appointed former Currys Group CIO Andy Gamble as Chair of its Advisory Board as the company looks to accelerate the growth of its managed security services.
Gamble brings nearly 30 years of board-level technology leadership and will work with Core to Cloud on its strategic, advisory and commercial direction across the UK enterprise and mid-market sectors.
His appointment adds further experience to the companyβs Advisory Board, which includes senior security leaders from major UK organisations.
From cybersecurity buyer to advisor
Gamble spent six years as Group CIO and Chief Transformation Officer at Currys PLC, where his responsibilities included large-scale technology transformation and cyber risk.
His career has also included senior CIO positions at Dyson, Sony Electronics and Essentra PLC. That experience means Gamble has spent much of his career on the customer side of the cybersecurity market, buying and managing the types of services Core to Cloud now provides.
βI spent the better part of three decades as a buyer of cybersecurity services, and the experience left me with a clear view of where the market falls short,β Gamble said.
βMost organisations understand that cyber risk is real. Far fewer have a security function that can communicate that risk clearly at board level, or a partner that moves fast enough to keep pace with the threat.β
Gamble said Core to Cloud stood out because of its focus on proactive security, adding that he intends to help the business scale its model as a challenger to conventional managed security service providers.
Supporting Core to Cloudβs next stage of growth
Based in Cirencester, Core to Cloud works with more than 150 organisations across sectors including the NHS, retail, financial services and critical national infrastructure.
Its services span Managed Detection and Response, Third-Party Cyber Risk Management, Security Assurance, Dark Web Monitoring and Threat Intelligence, and Cyber Crisis Simulation.
James Cunningham, CEO and Founder of Core to Cloud, said Gambleβs experience at the intersection of technology, risk and commercial strategy would bring a new perspective to the company.
βHe understands what good security looks like from the inside and brings a depth of experience and perspective that will be hugely valuable as we continue to grow,β Cunningham said.
βWe have an ambitious business, a strong customer base and services we genuinely believe in. Having Andy chair our board will help us build on those foundations, challenge our thinking and accelerate the next stage of Core to Cloudβs growth.β
The post Former Currys CIO Andy Gamble Joins Core to Cloud as Advisory Board Chair appeared first on IT Security Guru.
Webinar Today: Keep Pace With AI β A New Operating Model for Endpoint Remediation
Join the webinarΒ for a focused, 20-minute discussion onΒ Frontier Pace Governance,Β an approach to balancing automation, policy, and business risk as IT operations accelerate.
The post Webinar Today: Keep Pace With AI β A New Operating Model for Endpoint Remediation appeared first on SecurityWeek.
New βShieldCrashβ Zero-Day Exploit Targets Microsoft Defender
The exploit provides full System privileges on Windows machines running the September 2026 patches.
The post New βShieldCrashβ Zero-Day Exploit Targets Microsoft Defender appeared first on SecurityWeek.
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a userβs browser traffic.
The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.
Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victimsβ devices.
Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.
Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.
Fake browser makes phishing harder to spot
BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.
In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.
The fake browser page appeared to show Adobeβs legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.
Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.
Second attack follows same playbook
Huntress identified another incident on 31 August involving the same Adobe Reader lure.
This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.
The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.
Legitimate tools remain attractive to attackers
The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.
RMM abuse is a growing problem. Huntressβ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.
Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.
Read the full research here.Β
The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.
Ivanti Patches Critical Flaws Across Enterprise Security Products
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.
The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek.
This Key Will Self-Destruct: An Open Standard for Revocable API Keys
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default.
The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek.
Thrown into the SOC: A Black Hat First-Timerβs Story
MikroTik Patches Critical Flaws Chained to Hack Routers
Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices.
The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek.
Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes
Distributed Latency Monitoring at Black Hat
Black Hat USA 2026: Safeguarding DNS with Secure Access
-
Cisco Security
- Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha)