Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.

The operation has been attributed to a cyber espion… Continue reading Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection→

Posted in Uncategorized

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report.

Wiz saw the atta… Continue reading Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors→

Posted in Uncategorized

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims’ computers, security company Gen Digital said in research published T… Continue reading China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor→

Posted in Uncategorized

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.

The software development company said Pa… Continue reading PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws→

Posted in Uncategorized

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”

An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An expo… Continue reading ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories→

Posted in Uncategorized

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.

Early Access apps are apps that haven’t been released on the official Android app marketplace. … Continue reading Google Play Early Access Abused to Push Thousands of Deceptive Android Apps→

Posted in Uncategorized

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only “under specific conditions” that it… Continue reading Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE→

Posted in Uncategorized