CrashStealer, a new macOS malware, uses a notarized dropper to evade Apple's Gatekeeper security checks. The malware targets macOS users by exploiting the trust granted to notarized applications. This discovery underscores a critical vulnerability in Apple's verification process, potentially allowing malicious software to run undetected.
CISA inadvertently exposed sensitive information on a public GitHub repository, highlighting risks in code management. The leak included system details and credentials, prompting a review of security protocols. This incident underscores the need for rigorous oversight to prevent data breaches in government agencies.
Researchers have identified the MemGhost attack, which can implant persistent false memories into AI agents through a single malicious email. This manipulation allows attackers to control an agent's future behavior without detection, posing serious risks for trust and security in AI-assisted systems.
A new phishing-as-a-service platform called Forg365 is targeting Microsoft 365 users by abusing the device code authentication flow and performing adversary-in-the-middle session theft. This technique bypasses multi-factor authentication and steals session tokens, enabling persistent access to accounts. The emergence of such a tool heightens risks for organizations reliant on Microsoft 365, requiring enhanced monitoring and user training.
Meta has filed a patent for an AI system that can continuously listen to audio and monitor a user's emotional state throughout the day. The technology aims to detect sentiment through voice analysis, potentially for targeted advertising or personalized recommendations. This raises significant privacy concerns about constant surveillance and data collection.
This article discusses applying the "thinking fast and slow" concept to security operations, advocating for combining autonomous AI for rapid threat detection with analyst copilots for deeper investigation. It argues this hybrid approach improves SOC efficiency and decision-making by balancing speed with human oversight.
Researchers discovered a misconfigured server that revealed three separate phishing operations using the Evilginx framework, targeting Microsoft 365 credentials. The attackers employed reverse proxy techniques to bypass multi-factor authentication. The exposure highlights the persistent threat of advanced phishing campaigns against enterprise cloud services.
Security researchers report that two Joomla extensions, iCagenda and Balbooa Forms, contain critical flaws that are being actively exploited as zero-days. The vulnerabilities allow attackers to compromise websites running these components before patches are available. Joomla site administrators should urgently review their installed extensions and apply any available fixes.
Security researchers have identified a new vulnerability in the Squid web proxy cache, dubbed "Squidbleed". This flaw could potentially allow attackers to leak sensitive data or disrupt proxy services. The finding highlights ongoing security challenges in widely used network infrastructure software.