Hackers are misusing React2Shell flaw in Next.js apps to carry out an automatic scheme to steal credentials. This has already affected at least 766 servers in less than 24 hours. The threat activity is tracked as “UAT‑10608”. It relies on a custom framework dubbed NEXUS Listener to systematically harvest and …
Read More »Qilin and Warlock Ransomware Utilize Vuln Drivers to Disable Over 300 EDR Tools
Threat groups linked to Qilin and Warlock ransomware have been seen using the bring your own vulnerable driver (BYOVD) method to disable security tools on compromised computers, as reported by Cisco Talos and Trend Micro. Qilin attacks analyzed by Cisco Talos have been found to deploy a malicious DLL named …
Read More »FBI Alert AVrecon Malware Affecting Network Devices Globally in 163 Countries
The FBI has observed a type of malware named AVrecon, which was used to target many network devices around the world. The malware has a flexible design, allowing new attack tools to be added when new weaknesses are found. This increases the number of devices it can infect. The FBI …
Read More »Starcloud raises $170 million Series A to develop data centers in space
Starcloud’s newest funding round sets the company’s value at $1.1 billion. This makes it one of the quickest startups to become a unicorn after completing Y Combinator. The company’s Series A finished 17 months after its demo day. Benchmark and EQT Ventures led the round. This shows that there is interest …
Read More »HP and Dell To Plan Quantum-Resistant Device Security and AI Cyber Resilience
HP and Dell Technologies each shared news this week about new security features. These features improve hardware protection and help keep data safe from physical attacks and new threats from quantum computers in the AI age. HP starts TPM Guard and adds strong security to printers. HP made HP TPM …
Read More »NIST Unveils Quick-Start Guide on Cybersecurity, Risk, and Workforce Management
The National Institute of Standards and Technology (NIST) has unveiled NIST SP 1308, the “Quick-Start Guide for Cybersecurity, Enterprise Risk Management, and Workforce Management”. Published in March 2026, this report gives a clear way to include cybersecurity risk management (CSRM) in larger enterprise risk management (ERM) plans. The guide highlights …
Read More »HK police given new powers to obtain phone, computer passwords
Hong Kong police can ask for phone or computer passwords from people they think may have broken the National Security Law (NSL). Those who say no might spend a year in jail and pay a fine of up to HK$100,000 ($12,700; £9,600). People who give “false or misleading information” could go …
Read More »RBI to set facial recognition at ATMs, bank branches to curb fraud
The Reserve Bank of India (RBI) has asked banks for feedback on using facial recognition or other AI systems at ATMs, branch counters, and banking places, especially in areas known for fraud. A new digital shield for banking security If put into use, the system would make banking safer. Facial …
Read More »EU court adviser says banks must refund phishing victims
Athanasios Rantos, Advocate General of the CJEU, said that banks should quickly refund account holders for unauthorized transactions, regardless of the account holders’ fault. The opinion was issued in response to a request for a preliminary ruling submitted by the District Court in Koszalin, Poland, in a dispute between the …
Read More »OpenAI AI Powered Codex autonomously identify, validate, and remediate vulnerabilities
OpenAI launched Codex Security on Friday, an AI security agent that identifies and suggests fixes for vulnerabilities. The feature is in research preview for ChatGPT Pro, Enterprise, Business, and Edu customers through the Codex web, available free for the next month. “It builds deep context about your project to identify complex …
Read More »
InfoSecBulletin Cybersecurity for mankind