OpenAI has released a detailed plan for cybersecurity called “Cybersecurity in the Intelligence Age: An Action Plan for Democratizing AI-Powered Cyber Defense.” It describes a five-part strategy to give trusted defenders better AI tools and stop bad use. Artificial intelligence is changing the way we protect against cyber threats. It’s …
Read More »TP-Link Routers Affected by CVE-2023-33538 Mirai
Hackers are looking for weak TP-Link home routers to spread Mirai-like malware, taking advantage of CVE-2023-33538 in a new round of automated attacks. Current exploit attempts have some technical problems, but researchers say the bug is real and can be dangerous when used with default passwords and outdated firmware. Network …
Read More »Recently leaked Windows 0-Day flaw exploited in attacks
Threat actors are exploiting 3 new Windows security flaws in their attacks to get SYSTEM or higher administrator access. Since the beginning of the month, a security expert called “Chaotic Eclipse” or “Nightmare-Eclipse” has shared proof-of-concept exploit code for all three security problems. Two of the flaws, called BlueHammer and RedSun, …
Read More »US alerts banks on cyber risks from Anthropic’s new AI model
Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell called for an important meeting with bank CEOs this week to talk about the cyber dangers from Anthropic’s new AI model. Bessent and Powell met with the group on Tuesday to talk about the risks linked to Anthropic’s Mythos and …
Read More »Hackers breach 766 hosts in 24 hours via Next.js React2Shell vuln
Hackers are misusing React2Shell flaw in Next.js apps to carry out an automatic scheme to steal credentials. This has already affected at least 766 servers in less than 24 hours. The threat activity is tracked as “UAT‑10608”. It relies on a custom framework dubbed NEXUS Listener to systematically harvest and …
Read More »Qilin and Warlock Ransomware Utilize Vuln Drivers to Disable Over 300 EDR Tools
Threat groups linked to Qilin and Warlock ransomware have been seen using the bring your own vulnerable driver (BYOVD) method to disable security tools on compromised computers, as reported by Cisco Talos and Trend Micro. Qilin attacks analyzed by Cisco Talos have been found to deploy a malicious DLL named …
Read More »FBI Alert AVrecon Malware Affecting Network Devices Globally in 163 Countries
The FBI has observed a type of malware named AVrecon, which was used to target many network devices around the world. The malware has a flexible design, allowing new attack tools to be added when new weaknesses are found. This increases the number of devices it can infect. The FBI …
Read More »Starcloud raises $170 million Series A to develop data centers in space
Starcloud’s newest funding round sets the company’s value at $1.1 billion. This makes it one of the quickest startups to become a unicorn after completing Y Combinator. The company’s Series A finished 17 months after its demo day. Benchmark and EQT Ventures led the round. This shows that there is interest …
Read More »HP and Dell To Plan Quantum-Resistant Device Security and AI Cyber Resilience
HP and Dell Technologies each shared news this week about new security features. These features improve hardware protection and help keep data safe from physical attacks and new threats from quantum computers in the AI age. HP starts TPM Guard and adds strong security to printers. HP made HP TPM …
Read More »NIST Unveils Quick-Start Guide on Cybersecurity, Risk, and Workforce Management
The National Institute of Standards and Technology (NIST) has unveiled NIST SP 1308, the “Quick-Start Guide for Cybersecurity, Enterprise Risk Management, and Workforce Management”. Published in March 2026, this report gives a clear way to include cybersecurity risk management (CSRM) in larger enterprise risk management (ERM) plans. The guide highlights …
Read More »
InfoSecBulletin Cybersecurity for mankind