HTTP/1.1 Must Die: What This Means for AppSec Leadership
07
Aug
2025

HTTP/1.1 Must Die: What This Means for AppSec Leadership

Andrzej Matykiewicz | 06 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research,…

Researchers Uncover ECScape Flaw in Amazon ECS Enabling Cross-Task Credential Theft
07
Aug
2025

Researchers Uncover ECScape Flaw in Amazon ECS Enabling Cross-Task Credential Theft

Aug 06, 2025Ravie LakshmananDevOps / Container Security Cybersecurity researchers have demonstrated an “end-to-end privilege escalation chain” in Amazon Elastic Container…

Black Hat USA: Startup breaks secrets management tools
07
Aug
2025

Black Hat USA: Startup breaks secrets management tools

A total of 14 common vulnerabilities and exposures (CVEs) spanning CyberArk’s Conjur and HashiCorp’s Vault enterprise secrets management platforms have…

Mustang Panda Targets Windows Users with ToneShell Malware Disguised as Google Chrome
07
Aug
2025

Mustang Panda Targets Windows Users with ToneShell Malware Disguised as Google Chrome

The China-aligned threat actor Mustang Panda, also known as Earth Preta, HIVE0154, RedDelta, and Bronze President, has been deploying the…

Chinese Group Stole 115 Million US Cards in 16-Month Smishing Campaign
07
Aug
2025

Chinese Groups Stole 115 Million US Cards in 16-Month Smishing Campaign

A new report from cybersecurity firm SecAlliance has revealed a highly organized criminal operation run by Chinese syndicates that may…

Breaking Down Data Silos in the Age of AI: How Hitachi Vantara Sees The A/NZ Opportunity Evolving
07
Aug
2025

Breaking Down Data Silos in the Age of AI: How Hitachi Vantara Sees The A/NZ Opportunity Evolving

Data volumes are exploding and while this provides an unprecedented opportunity for organisations to leverage and benefit from AI, it’s…

Lazarus Hackers Use Fake Camera/Microphone Alerts to Deploy PyLangGhost RAT
07
Aug
2025

Lazarus Hackers Use Fake Camera/Microphone Alerts to Deploy PyLangGhost RAT

North Korean state-sponsored threat actors associated with the Lazarus Group, specifically the subgroup known as Famous Chollima, have evolved their…

Health expands cloud footprint with $32m Azure deal
07
Aug
2025

Health expands cloud footprint with $32m Azure deal

The Department of Health, Disability and Ageing is scaling up its cloud capabilities with a $32 million contract for Microsoft…

Box
06
Aug
2025

Akira ransomware abuses CPU tuning tool to disable Microsoft Defender

Akira ransomware is abusing a legitimate Intel CPU tuning driver to turn off Microsoft Defender in attacks from security tools…

Akira and Lynx Ransomware Target MSPs Using Stolen Credentials and Exploited Vulnerabilities
06
Aug
2025

Akira and Lynx Ransomware Target MSPs Using Stolen Credentials and Exploited Vulnerabilities

The Acronis Threat Research Unit (TRU) dissected recent samples from the Akira and Lynx ransomware families, revealing incremental enhancements in…

Fake VPN and Spam Blocker Apps Tied to VexTrio Used in Ad Fraud, Subscription Scams
06
Aug
2025

Fake VPN and Spam Blocker Apps Tied to VexTrio Used in Ad Fraud, Subscription Scams

The malicious ad tech purveyor known as VexTrio Viper has been observed developing several malicious apps that have been published…

Sophisticated DevilsTongue Windows Spyware Tracking Users Globally
06
Aug
2025

Sophisticated DevilsTongue Windows Spyware Tracking Users Globally

The emergence of DevilsTongue marks a significant escalation in mercenary spyware capabilities, leveraging advanced Windows-based techniques to infiltrate high-value targets…