Elektrine lite

← Feed

CyberWorldOps

cyberworldops@infosec.exchange

<p>Cybersecurity news, vulnerabilities and CVE tracking — IT · EN · ES · FR · DE. Articles are AI-drafted under human editorial responsibility, and every article says so. Free CVE database and CISA KEV tracker. Posts here are automated.</p>

Posts

  • Post #4498817

    Genians has documented Kimsuky, a North Korean unit under the Reconnaissance General Bureau, building an offline AI stack on its own infrastructure. The group is not training custom models but assembling and testing existing AI tools to automate phishing, malware creation, and data exfiltration. #Kimsuky #ThreatIntelligence #StateSponsored #AIsecurity https://cyberworldops.eu/en/kimsuky-prepares-an-offline-ai-stack-to-enhance-phishing-malware-and

  • Post #4492937

    BdThemes, a WordPress premium tool developer, was compromised in a supply-chain attack. Attackers injected malicious JavaScript into a remote JSON feed rendered in WordPress admin panels, enabling automatic creation of rogue administrator accounts on victim sites. #SupplyChainAttack #WordPress #BdThemes #Cybersecurity https://cyberworldops.eu/en/bdthemes-compromised-wordpress-supply-chain-attack-creates-rogue

  • Post #4485489

    Levi Strauss disclosed to the SEC that its corporate computers were compromised through a social engineering attack targeting three employees. Preliminary findings indicate the attackers likely accessed and exfiltrated corporate information. No customer data has been confirmed stolen so far. #SocialEngineering #CorporateSecurity #DataExfiltration #ThreatLandscape https://cyberworldops.eu/en/social-engineering-attack-against-levi-strauss-computers-of-three

  • Post #4479684

    Critical vulnerabilities found in Connective, Belgium&#39;s eID digital identity extension used by over 2 million citizens. The browser plugin, developed by Nitro Software Belgium, exposes PINs, electronic signatures, and devices to compromise. #DigitalIdentity #BelgianEID #CriticalInfrastructure #ZeroTrust https://cyberworldops.eu/en/critical-vulnerabilities-in-belgium-s-connective-digital-identity

  • Post #4477233

    NatJack is a class of NAT table manipulation attacks presented at Black Hat 2026. By tampering with connection state, an attacker can hijack live TCP sessions, spoof DNS responses, saturate NAT tables, and expose internal ports to the internet. #NatJack #NATSecurity #BlackHat2026 #TCPHijacking https://cyberworldops.eu/en/natjack-targets-nat-tables-hijacked-sessions-and-exposed-ports

  • Post #4473104

    Stade Français Paris, the French rugby club, has confirmed a ransomware attack that disrupted part of its IT infrastructure. Systems were restored using clean backups and core operations have resumed. However, a sample of allegedly stolen data has appeared online, raising concerns about a potential breach involving personal information. #Ransomware #DataBreach #IncidentResponse #StadeFrançais https://cyberworldops.eu/en/stade-francais-paris-restores-systems-after-ransomware-attack