ShinyHunters zegt gegevens van duizenden FBI-medewerkers in handen te hebben post, september 22, 2026september 23, 2026 Hackersgroep ShinyHunters zegt de gegevens van duizenden medewerkers en sollicitanten van de FBI te hebben bemachtigd. Dat melden diverse Amerikaanse media op basis van woordvoerders van de groep. De hackers beweren gisteravond de systemen van de FBI te zijn binnengedrongen. ShinyHunters zei tegen persbureau Reuters dat de hack een reactie… Continue Reading
AI Agents Are Rewriting the Rules of Lateral Movement post, september 22, 2026september 23, 2026 Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows… Continue Reading
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation auto_post, september 22, 2026 Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42. Continue Reading
Meta Sued Over Training Data for Its AI and Face-Recognition Systems auto_post, september 22, 2026 The proposed class action alleges Meta illegally harvested people’s Facebook and Instagram photos to train its AI image-generation models and to build its unreleased “NameTag” face recognition feature. Continue Reading
Gyazo server flaw exploited to steal 23.6 million user records auto_post, september 21, 2026 The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. […] Continue Reading
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia auto_post, september 21, 2026september 23, 2026 Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.” The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing. Continue Reading
Cisco Zero-Day Highlights API Endpoint Authentication Issues auto_post, september 21, 2026september 23, 2026 The authentication bypass flaw CVE-2026-76460 impacts Cisco’s Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score. Continue Reading
Nederlandse energiebedrijven zetten zich schrap post, september 19, 2026september 21, 2026 Bewapende beveiligers en dronenetten om de energie-infrastructuur te beschermen. Vandaag op de voorpagina van Het Financieele Dagblad schrijven Eva Rooijers en ik over hoe Nederlandse energiebedrijven zich schrap zetten voor fysieke aanvallen. Hoogspanningsstations, energiecentrales en andere vitale infrastructuur zijn makkelijke doelwitten; de fysieke beveiliging loopt ver achter. Terwijl de dreiging… Continue Reading
Using Cyber Decoys to Strengthen Detection and Response post, september 16, 2026september 21, 2026 CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move… Continue Reading
Cyberactoren uit Iran zetten malware in tegen dissidenten, activisten en journalisten post, september 15, 2026september 16, 2026 Uit recent onderzoek van de Britse inlichtingen- en veiligheidsdiensten en de AIVD blijkt dat Iraanse cyberactoren specifieke malware inzetten. Het doel hiervan is om gevoelige informatie te verzamelen over critici van het Iraanse regime die in het Westen verblijven, waaronder dissidenten, activisten en journalisten. Daarom waarschuwt de AIVD opnieuw voor… Continue Reading