Elektrine lite

← Feed

Security Feed

securityfeed@infosec.exchange

<p>Monitors security RSS feeds</p>

Posts

  • Post #4499594

    πŸ”’ Security News Digest - 2026-08-11 πŸ“Š 15 updates from 5 sources: 🦠 Malwarebytes: Fake popular sites offer a free app, instead take over PCs https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-popular-sites-offer-a-free-app-instead-take-over-pcs 🦠 Malwarebytes: Watch out for fake TikTok Shops trying to steal your money https://www.malwarebytes.com/blog/scams/2026/08/watch-out-for-fake-tiktok-shops-trying-to-steal-your-money πŸ”Ή The Hacker News: Gunra Ransomware Exploits Fortinet a...

  • Post #4493648

    πŸ”Ή The Hacker News Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither...

  • Post #4493645

    πŸ”Ή SecurityWeek Mozilla Issues New Firefox GPG Key Following Exposure The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek. πŸ”— https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/

  • Post #4483950

    πŸ”Ή The Hacker News OpenAI&#39;s Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause OpenAI has announced that it&#39;s pausing some &quot;internal activities&quot; involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it&#39;s implementing security controls for higher-capability models and associated activ...

  • Post #4483949

    πŸ”Ή The Hacker News Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (&quot;solidity-pro&quot;) that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-pro Although neither of the extensions is now available on Open VSX, the GitHub repository...

  • Post #4483947

    🦠 Malwarebytes A week in security (August 3 – August 9) A list of topics we covered in the week of August 3 to August 9 of 2026 πŸ”— https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-august-3-august-9

  • Post #4478658

    πŸ”Ή SecurityWeek Critical Flaws Discovered in Belgian eID Software Used by 2 Million People The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on SecurityWeek. πŸ”— https://www.securityweek.com/critical-flaws-discovered-in-belgian-eid-software-used-by-2-million-people/

  • Post #4427853

    πŸ”Ή The Hacker News TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing infrastructure for years before training their sights on the software supply chain. &quot;The connection is supported by overlapping domains, malware deployment paths, staging techniques, backend infrastruc...

  • Post #4402402

    πŸ”’ Security News Digest - 2026-08-06 πŸ“Š 5 updates from 3 sources: πŸ”Ή darkreading: No Perfect Fix for AI Browser Prompt Injection Flaws https://www.darkreading.com/application-security/no-perfect-fix-ai-browser-prompt-injection-flaws πŸ”Ή Latest Bulletins: CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server https://aws.amazon.com/security/security-bulletins/rss/2026-076-aws/ πŸ”Ή darkreading: AI Browsers Vulnerable to &#39;PleaseFix&...

  • Post #4391061

    πŸ”Ή iTnews - Security Anthropic&#39;s Mythos 5 targeted real developers in UK cyber test Model without safety filters tried to social engineer coder during test. πŸ”— https://www.itnews.com.au/news/anthropics-mythos-5-targeted-real-developers-in-uk-cyber-test-627952?utm_source=feed&amp;utm_medium=rss&amp;utm_campaign=iTnews+Security+feed

  • Post #4387923

    πŸ”Ή iTnews - Security iTnews Executive Retreat &amp;#8211; Security Leaders Edition Hunter Valley, 17&amp;#8211;18 September πŸ”— https://www.itnews.com.au/feature/itnews-executive-retreat-security-leaders-edition-627912?utm_source=feed&amp;utm_medium=rss&amp;utm_campaign=iTnews+Security+feed

  • Post #4383229

    πŸ”’ Security News Digest - 2026-08-04 πŸ“Š 7 updates from 5 sources: πŸ”Ή Latest Bulletins: CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation https://aws.amazon.com/security/security-bulletins/rss/2026-073-aws/ πŸ”Ή darkreading: Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook https://www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook πŸ”Ή Security News | TechCrunch: Nvidia doesn’t me...

  • Post #4376894

    πŸ”’ Security News Digest - 2026-08-04 πŸ“Š 15 updates from 6 sources: πŸ”Ή The Hacker News: New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html πŸ”Ή SecurityWeek: Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering https://www.securityweek.com/gemini-agent-to-agent-attack-exposed-secrets-enabled-pull-request-tampering/ πŸ”Ή The Hacker News: Google Deletes 3 ADK AI Workf...

  • Post #4372580

    πŸ”’ Security News Digest - 2026-08-04 πŸ“Š 5 updates from 3 sources: πŸ”Ή darkreading: Device Code Phishing Up 1,500% in 2026; Vishing Doubles https://www.darkreading.com/cybersecurity-analytics/device-code-phishing-vishing-doubles πŸ”Ή The Hacker News: CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html πŸ”Ή SecurityWeek: 150,000 Impacted by Madera Community Hospital Data Breach https://www.securi...

  • Post #4368577

    πŸ”Ή SecurityWeek New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek. πŸ”— https://www.securityweek.com/new-york-awards-9-million-to-strengthen-cybersecurity-at-153-water-systems/

  • Post #4368574

    πŸ”Ή darkreading Attackers Exploit N-able Patch Bypass Flaw on RMM Servers Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access. πŸ”— https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw

  • Post #4368573

    🦠 Malwarebytes The AI Act kicks into action, forces companies to be clear about AI chatbots The European Union (EU) has started enforcing key parts of the AI Act, with immediate, visible consequences for chatbots, deepfakes and other consumer‑facing AI. πŸ”— https://www.malwarebytes.com/blog/news/2026/08/the-ai-act-kicks-into-action-forces-companies-to-be-clear-about-ai-bots

  • Post #4361037

    πŸ”’ Security News Digest - 2026-08-03 πŸ“Š 6 updates from 4 sources: πŸ”Ή SecurityWeek: Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion https://www.securityweek.com/visa-to-acquire-fraud-intelligence-firm-biocatch-for-2-4-billion/ πŸ”Ή darkreading: Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm https://www.darkreading.com/cyberattacks-data-breaches/chinese-actor-deepseek-ai-agent-attack-security-firm πŸ”Ή SecurityWeek: Black Hat USA 2026 – Summary of Vendor Anno...

  • Post #4352859

    πŸ”’ Security News Digest - 2026-08-03 πŸ“Š 10 updates from 4 sources: πŸ”Ή The Hacker News: Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html πŸ”Ή The Hacker News: N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html 🦠 Malwarebytes: A week in security (July 27 &amp;#8211; August 2)...

  • Post #4280544

    πŸ”’ Security News Digest - 2026-07-31 πŸ“Š 7 updates from 4 sources: 🦠 Malwarebytes: Fake Flash Player installs AtlasRAT https://www.malwarebytes.com/blog/news/2026/07/fake-flash-player-installs-atlasrat πŸ”Ή The Hacker News: Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks https://thehackernews.com/2026/07/chinese-hacker-commands-deepseek-via.html πŸ”Ή The Hacker News: 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026 https://thehackernews.com/...

  • Post #4275317

    πŸ”’ Security News Digest - 2026-07-31 πŸ“Š 6 updates from 2 sources: πŸ”Ή SecurityWeek: Critical Code Execution Vulnerability Patched in TeamCity https://www.securityweek.com/critical-code-execution-vulnerability-patched-in-teamcity/ πŸ”Ή SecurityWeek: CareCloud Data Breach Impacts Over 350,000 https://www.securityweek.com/carecloud-data-breach-impacts-over-350000/ πŸ”Ή SecurityWeek: Critical Flaw Led to Azure Cosmos DB Pwnage https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwna...

  • Post #4262341

    πŸ”Ή iTnews - Security In Pictures: Security in the age of shadow AI Security Centric roundtable A selection of photos from a recent iTnews roundtable lunch at Bambini Trust restaurant in Sydney. πŸ”— https://www.itnews.com.au/gallery/in-pictures-security-in-the-age-of-shadow-ai-security-centric-roundtable-627836?utm_source=feed&amp;utm_medium=rss&amp;utm_campaign=iTnews+Security+feed

  • Post #4262340

    πŸ”Ή SecurityWeek CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek. πŸ”— https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/

  • Post #4262337

    πŸ”Ή darkreading Minnesota Water Utility Attacks Expose Sector&#39;s Cyber-Risks A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure. πŸ”— https://www.darkreading.com/ics-ot-security/minnesota-water-utility-attacks-expose-sector-cyber-risks

  • Post #4253412

    πŸ”’ Security News Digest - 2026-07-30 πŸ“Š 7 updates from 5 sources: πŸ”Ή The Hacker News: DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware https://thehackernews.com/2026/07/dprk-linked-macos-malvertising-uses.html πŸ”Ή Security News | TechCrunch: Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI https://techcrunch.com/2026/07/30/google-says-it-fixed-more-chrome-bugs-in-june-than-over-the-past-two-years-thanks-to-ai/ πŸ”Ή The...

  • Post #4247327

    πŸ”’ Security News Digest - 2026-07-30 πŸ“Š 11 updates from 8 sources: 🦠 Malwarebytes: Hims &amp;amp; Hers sued over alleged health data privacy failures https://www.malwarebytes.com/blog/privacy/2026/07/hims-hers-sued-over-alleged-health-data-privacy-failures πŸ”Ή Threat Intelligence: Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise/ πŸ”Ή SecurityWeek: DataBahn Raises...

  • Post #4237131

    πŸ”’ Security News Digest - 2026-07-30 πŸ“Š 8 updates from 3 sources: πŸ”Ή SecurityWeek: Cisco Secure FMC Zero-Day Exploited in the Wild https://www.securityweek.com/cisco-secure-fmc-zero-day-exploited-in-the-wild/ πŸ”Ή The Hacker News: FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.html πŸ”Ή The Hacker News: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation...

  • Post #4222376

    🦠 Malwarebytes Apple accused of letting fake crypto app steal $1.8 million The case raises fresh questions about how effectively Apple polices apps that impersonate legitimate developers. πŸ”— https://www.malwarebytes.com/blog/news/2026/07/apple-accused-of-letting-fake-crypto-app-steal-1-8-million

  • Post #4212538

    πŸ”’ Security News Digest - 2026-07-29 πŸ“Š 7 updates from 4 sources: πŸ”Ή The Record from Recorded Future News: OpenAI says rogue agent behind Hugging Face hack broke into additional services https://therecord.media/openai-says-rogue-agent-behind-hugging-face-hack-broke-into-additional-services πŸ”Ή darkreading: Hugging Face Hack Lessons for Cyber Defenders https://www.darkreading.com/cyberattacks-data-breaches/hugging-face-hack-lessons-cyber-defenders πŸ”Ή Security News | TechCrunch: US government...

  • Post #4193750

    πŸ”’ Security News Digest - 2026-07-29 πŸ“Š 8 updates from 2 sources: πŸ”Ή The Hacker News: Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html πŸ”Ή The Hacker News: New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html πŸ”Ή The Hacker News: OpenAI Agent Used Exposed Credentials Across Four Services...