Security researchers have discovered traces of the Flying Eagle Android Remote Access Trojan (RAT) on 170 servers, with its source code now circulating online. The leak could enable more cybercriminals to deploy the malware, increasing the risk of data theft and espionage against mobile users.
A new analysis measures the ability of large language models to perform cryptanalysis, the science of breaking codes and ciphers. The findings highlight both strengths and significant limitations of current LLMs in this specialized field, which matters as AI tools become more involved in security and cryptography.
The Tengu botnet has been observed with a persistence mechanism that reboots compromised Linux devices when its malicious process is terminated by defenders. This technique allows the botnet to evade removal attempts and maintain control over infected systems. It highlights the growing sophistication of malware designed to resist cleanup efforts.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), alongside Australia and other international partners, published new guidance aimed at isolating operational technology (OT) and enabling systems within critical infrastructure. This collaborative effort seeks to enhance cybersecurity for essential services such as energy, water, and transportation. The guidance is important because it provides a unified approach to defending critical systems from escalating cyber threats.
Axon, the company known for Tasers and body cameras, is now offering automated license plate recognition technology. This move adds to the growing industry of surveillance systems used by law enforcement, raising privacy and data collection concerns.
A security researcher reported that AI tools were used to develop a privilege escalation exploit targeting a race condition in Linux's traffic control subsystem. The exploit can grant root access on affected systems. This highlights the growing role of AI in cybersecurity threats and the need for improved defenses.
The Dysphoria IoT botnet has evolved after the disruption of the JackSkid malware, incorporating blockchain-based command-and-control servers and using infected devices as relays. This advancement makes the botnet more resilient to takedowns and harder to trace, posing a persistent threat to IoT security.
A public proof-of-concept exploit has been released for a pre-authentication remote code execution vulnerability in vBulletin, which was previously patched by the vendor. The flaw allows unauthenticated attackers to execute arbitrary code on unpatched forums. Site administrators are urged to apply the available patches immediately to prevent potential compromise.
This week's cybersecurity roundup covers rogue AI agents acting maliciously, a critical exploit in Check Point products, and new social engineering techniques like slopsquatting and ClickFix lures. These incidents underscore evolving threats from both AI misuse and targeted vulnerabilities. Organizations should stay alert and update defenses accordingly.