Tag: security

‘A new frontier model trained by Anthropic that we believe could reshape cybersecurity’: Project Glasswing wants to use AI to prevent AI cyberattacks — but will ‘overeager’ Claude Mythos do more damage than help?

Project Glasswing and Anthropic’s Claude Mythos Preview are designed to tackle AI security threats Mythos is so powerful that it’s not being released to the public – only select companies Work has already found decades-old bugs and critical flaws in major OSs and browsers Anthropic has lifted the wraps off…

Read More

Microsoft flags China-based hackers using vicious new ‘rapid attack’ zero-days to launch ransomware at targets across the world

Storm-1175 rapidly moves from access to ransomware deployment Exploits zero-days and n-days across multiple products Targets healthcare, finance, education, and professional services Chinese-speaking hacking collective Storm-1175 is moving fast, going from initial access to full system compromise and data exfiltration in weeks, and sometimes in less than 24 hours, experts…

Read More

‘Stolen session cookies render MFA irrelevant’: How $900-per-month turnkey malware is putting enterprise-grade account hijacking in the hands of rookie hackers

Storm enables session hijacking that bypasses passwords and multi-factor authentication Attackers can restore stolen sessions remotely without triggering standard security alerts Malware operates server-side to process encrypted browser credentials for stealthy exploitation A new strain of infostealer malware dubbed Storm is changing how account compromise works, experts have warned. New…

Read More

‘Your login credentials may already be slipping into the hands of a cybercriminal’: Hackers target LinkedIn accounts with devious new phishing attacks — here’s how to stay safe

Hackers exploit LinkedIn notifications to trick users into giving login credentials Phishing emails often pose as urgent job opportunities to manipulate recipients Fraudulent domains like “inedin[.]digital” mimic LinkedIn to gain trust Experts have warned hackers are increasingly exploiting LinkedIn notifications to trick users into providing sensitive login information, using highly…

Read More

SparkCat malware returns to target Android and iOS users, hiding in innocent apps to try and steal your details

SparkCat infostealer hidden in iOS App Store and Play Store apps Targets cryptocurrency seed phrases via OCR and keywords New obfuscation techniques make detection more difficult SparkCat, a mobile-first infostealer that targets people’s cryptocurrencies, is back with new upgrades that make it more difficult to spot. Cybersecurity researchers Kaspersky claim…

Read More

One of the largest corporate espionage and data breach scandals in digital history’: New “BrowserGate” report claims LinkedIn secretly scans user browsers for installed extensions and collects device data

Report alleges LinkedIn scans browsers for extensions Claims data used against competitors in “BrowserGate” LinkedIn denies misuse, calls accusations a smear campaign A new report is alleging LinkedIn uses hidden JavaScript to scan its visitors’ browsers for installed extensions, looks for those that compete with its own sales tools, and…

Read More