UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

A Highly Sophisticated Server Attack Has Emerged, Leveraging AI and Evasion Techniques to Evade Detection The cybersecurity landscape has been shaken by a new server attack vector known as UAT-10147. This highly advanced threat utilizes artificial intelligence (AI) to scale its attacks, making it particularly challenging for security teams to detect and mitigate. What’s more … Read more

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

A Small Minority of AI Users Pose a Huge Security Risk, New Research Reveals A disturbing trend has emerged in the world of artificial intelligence (AI) security, where only 5% of users are responsible for nearly all cybersecurity breaches. These individuals, often referred to as “superusers,” have inadvertently created backdoors into their organizations’ systems through … Read more

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

A sophisticated cyberattack campaign has been uncovered, targeting the Myanmar government and its IT sector with a particularly nasty backdoor malware. Dubbed Operation QUICSILVER, this espionage effort leverages a custom-built tool called QUICAgent to infiltrate and maintain access to compromised systems. The attackers’ goal is clear: they’re after sensitive information, likely related to national security … Read more

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

A Critical Flaw in Keycloak Exposes Millions of Users to Account Takeover Attacks A severe vulnerability has been discovered in Keycloak, a popular open-source identity and access management platform used by millions of organizations worldwide. The flaw, which allows unauthenticated attackers to reset passwords for any account, poses a significant risk to the security of … Read more

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

Shipping Companies Left Exposed as AI Code and Identity Exposure Create Breach Routes A recent wave of cyber attacks has highlighted a critical vulnerability in the shipping industry, where companies are struggling to keep pace with the rapid deployment of artificial intelligence (AI) code. As these organizations rely increasingly on AI-driven systems to optimize logistics … Read more

Venezuelan Gets Record Federal Prison Term for ATM Jackpotting

A Venezuelan national has been handed a record-breaking 8-year prison sentence for his role in a massive ATM jackpotting scheme that caused over $3.5 million in losses, marking one of the longest federal sentences imposed on an individual involved in this type of cybercrime. Juan Manuel Gouveia-Aguilera, 27, was sentenced to 96 months in prison … Read more

91 Vulnerabilities Patched in Spring Application Framework

A massive patch update has been released by Broadcom to address a staggering 91 vulnerabilities in its Spring application development framework. The update is crucial, as it affects more than 200,000 software components across various projects, including Spring Security and AI tools. This is not just a routine patch release – the surge in vulnerabilities … Read more

Microsoft shares temporary fix for Windows 11 gaming issues

Windows 11 Gaming Issues Spark Temporary Fix from Microsoft A growing number of gamers have been plagued by frustrating and unexplained issues with their favorite titles on Windows 11, causing games to crash or fail to launch. Microsoft has finally stepped in to provide a temporary fix for these problems, which have affected users who … Read more

CISA orders urgent patching of actively exploited Zimbra flaw

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal government agencies, requiring them to patch a critical vulnerability in Zimbra Collaboration Suite (ZCS) within three days. This latest development comes as part of an ongoing effort to combat cyber threats targeting organizations that rely on the popular email and … Read more

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

A highly sophisticated and highly damaging malware campaign has been uncovered, leveraging artificial intelligence (AI) to scale massive server attacks. Dubbed UAT-10147, this threat uses a range of sophisticated tactics to evade detection and wreak havoc on vulnerable systems. The good news is that security experts have already sounded the alarm; the bad news is … Read more