ZCyberNews
中文

Articles

460 articles

Trellix Breach: Source Code Repository CompromisedHIGH
Industry News

Trellix Breach: Source Code Repository Compromised

Trellix confirmed attackers accessed a portion of its source code repository. The firm engaged forensic experts and notified law enforcement. No customer data impact disclosed.

2 min read
AI Agents Wreck Production Databases Due to Poor Access ControlsHIGH
Industry News

AI Agents Wreck Production Databases Due to Poor Access Controls

Dark Reading reports AI agents are deleting production databases because organizations deploy agent integrations without proper security testing or access controls.

2 min read
Deep#Door Python Backdoor Targets Windows Systems for EspionageHIGH
Malware

Deep#Door Python Backdoor Targets Windows Systems for Espionage

Deep#Door Python backdoor deploys persistent Windows implant for espionage — uses encrypted C2 channels, file exfiltration, and remote shell. No patch available.

2 min readDeep#Door
Ex-Incident Responders Sentenced to 4 Years for Ransomware AttacksHIGH
Industry News

Ex-Incident Responders Sentenced to 4 Years for Ransomware Attacks

Two cybersecurity incident responders who abused client access to deploy ransomware were sentenced to 4 years in prison — a rare case of responders turning attackers.

2 min read
Ex-Ransomware Negotiators Sentenced to 4 Years for BlackCat AttacksHIGH
Industry News

Ex-Ransomware Negotiators Sentenced to 4 Years for BlackCat Attacks

Two former IR firm employees got 4 years each for laundering $18M+ in BlackCat ransom payments and advising attackers on negotiation tactics.

2 min readBlackCat
Mini Shai-Hulud Attack Hijacks SAP, Lightning, Intercom PackagesCRITICAL
Malware

Mini Shai-Hulud Attack Hijacks SAP, Lightning, Intercom Packages

Attackers compromised SAP, Lightning, and Intercom npm packages in a supply chain attack affecting 1,800 victims; packages had 10M monthly downloads.

2 min readMini Shai-Hulud
UK Cyber Agency Warns AI Will Trigger 'Patch Wave' of Urgent FixesMEDIUM
Industry News

UK Cyber Agency Warns AI Will Trigger 'Patch Wave' of Urgent Fixes

NCSC warns organizations to brace for a surge of urgent patches as AI accelerates vulnerability discovery, raising exploitation risk. No specific CVEs cited.

2 min read
Anthropic Launches Claude Security for AI-Driven Exploit DefenseHIGH
Tools & Techniques

Anthropic Launches Claude Security for AI-Driven Exploit Defense

Anthropic released Claude Security, a defensive AI suite to counter autonomous exploit tools like Mythos that weaponize zero-days in minutes. Targets enterprise SOCs.

2 min read
BHIS Pentest Data: Same Top Flaws Plague Orgs in 2025HIGH
Industry News

BHIS Pentest Data: Same Top Flaws Plague Orgs in 2025

Black Hills InfoSec's 2025 pentest analysis of 15 months of data shows the same top 10 vulnerabilities as 2022 — weak passwords, unpatched RDP, and misconfigured MFA remain…

2 min read
Brazilian DDoS Firm Behind Botnet Attacks on ISPsHIGH
Industry News

Brazilian DDoS Firm Behind Botnet Attacks on ISPs

Brazilian anti-DDoS firm's infrastructure used to launch massive botnet attacks against rival ISPs. CEO claims breach by competitor caused the abuse.

2 min read
CISA Details FCEB Agency Breach Response Lessons LearnedHIGH
Industry News

CISA Details FCEB Agency Breach Response Lessons Learned

CISA's incident response at a U.S. federal agency uncovered gaps in EDR alert triage, credential hygiene, and network segmentation — three lessons for all defenders.

3 min read
CISA, FBI Warn of LummaC2 Infostealer Targeting OrgsHIGH
Malware

CISA, FBI Warn of LummaC2 Infostealer Targeting Orgs

CISA and FBI joint advisory details LummaC2 infostealer TTPs and IOCs: malware steals credentials, crypto wallets, and session data from compromised networks.

2 min readLummaC2
← PrevPage 19 of 39Next →