Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

A Critical Vulnerability in Switchvox VoIP Systems Allows Attackers to Bypass Security Measures and Deploy Malicious Code Without Credentials A severe security flaw has been discovered in the Switchvox Voice over Internet Protocol (VoIP) system, allowing attackers to deploy reverse shells without needing login credentials. The vulnerability affects Switchvox 7.x versions, which are widely used … Read more

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

A Highly Critical Exploit Spreads Across Industrial Control Systems, Threatening Global Supply Chains Researchers have successfully adapted a pre-authentication remote code execution (RCE) exploit from one Programmable Logic Controller (PLC) model to another, using a sophisticated technique dubbed “Claude.” This development has significant implications for industrial control systems, where compromised devices can lead to catastrophic … Read more

Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars

Cybersecurity Researchers Demonstrate AI-Powered PLC Exploit Porting in Hours and Dollars In a stunning demonstration of the accelerating pace of artificial intelligence (AI) in cybersecurity, researchers at Forescout’s Vedere Labs have successfully ported a working remote code execution exploit from one programmable logic controller (PLC) to another using Anthropic’s Claude AI. The experiment, which was … Read more

Coast Guard Establishes Office of Maritime Cybersecurity Policy

The US Coast Guard has taken a crucial step towards safeguarding the nation’s maritime infrastructure by establishing a dedicated Office of Maritime Cybersecurity Policy. This new office, which will serve as the central authority for developing and implementing policies governing cyber safety and security in the Marine Transportation System (MTS), marks a significant response to … Read more

Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense

Sevii’s AI-Driven Defense Puts an End to AI-Speed Attacks As artificial intelligence (AI) driven attacks continue to rise in both speed and scope, companies are struggling to keep up with the pace of remediation. Traditional security measures often rely on human intervention, which can be slow and ineffective against rapidly unfolding threats. Enter Sevii’s new … Read more

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

A Critical Alert for SonicWall Customers: Zero-Day Vulnerabilities Exploited in the Wild SonicWall is sounding the alarm for its customers, urging them to patch two newly discovered zero-day vulnerabilities that have been exploited by attackers. The flaws affect the SMA1000 series of secure remote access gateways and SSL-VPN appliances, putting sensitive data at risk. The … Read more

SonicWall warns of actively exploited SMA1000 zero-day flaws

Cybersecurity firm SonicWall has issued a dire warning to its customers, revealing that threat actors are actively exploiting two previously unknown vulnerabilities in its Secure Mobile Access (SMA) 1000 appliances. The company’s advisory comes as a stark reminder of the ongoing threat landscape and the importance of timely patching. The two zero-day flaws, identified as … Read more

Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense

Cybersecurity firms are racing to develop defenses against AI-driven attacks, which can move at lightning speed and cause significant damage. Sevii, a cybersecurity company, has taken a bold step in this direction by launching an AI security module that promises instant remediation. The new module, part of Sevii’s Autonomous Defense & Remediation (ADR) platform, is … Read more

Palo Alto Networks Acquires AI Agent Platform Console

Palo Alto Networks Scoops Up Console’s AI-Native Platform to Bolster Cortex Capabilities In a significant move that will undoubtedly reshape the cybersecurity landscape, Palo Alto Networks has announced its acquisition of Console, an innovative AI-native platform designed to automate operational tasks using natural language. This deal is expected to amplify the agentic capabilities of Palo … Read more

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

**Sophisticated Attack Campaign Compromises 31 Organizations Using Abused Polygon Blockchain** A highly sophisticated cyberattack campaign has compromised at least 31 organizations by abusing the Polygon blockchain technology. The ClickFix campaign uses a technique called “EtherHiding” to obscure and automate its malicious activity, making it challenging for security teams to detect and block. The attackers behind … Read more