generalnews.media
All World Business Technology Science Health Sports Entertainment Security
311 stories
Exclusive

Three OpenClaw Flaws Enable WhatsApp-to-Host Attack Chain

A security researcher has detailed a chain of three vulnerabilities in the OpenClaw library that can be exploited to attack a host system via WhatsApp messages. The flaws, when combined, allow remote code execution, posing a significant threat to users of the messaging platform. This disclosure highlights the need for prompt patching to prevent potential widespread exploitation.

Exclusive

MODBEACON RAT Leverages gRPC Streaming for Encrypted C2 Communications

A new remote access trojan named MODBEACON uses gRPC streaming technology to encrypt its command-and-control (C2) traffic, making detection more challenging. This approach allows attackers to maintain covert communication with infected systems, highlighting an evolving tactic in cybercrime. Security researchers warn that this technique could be adopted by other malware strains.

Exclusive

Lumen Technologies Scales Exposure Management from 17,000 to 1.1 Million Assets

Lumen Technologies overhauled its exposure management platform to handle a massive increase from 17,000 to 1.1 million tracked assets. The company implemented automation and a unified risk view to maintain security at scale. This case highlights how large organizations can effectively manage growing attack surfaces.

Exclusive

Exposed Hacker Server Reveals WP-SHELLSTORM Backdoor in Thousands of WordPress Sites

A hacker server was uncovered, revealing the WP-SHELLSTORM backdoor that has compromised thousands of WordPress sites. The campaign uses malicious plugins to gain unauthorized access, posing a significant security risk to website owners. This discovery highlights the ongoing vulnerability of widely-used content management systems.

Exclusive

Balancing AI Surveillance and Social Progress

An analysis from Schneier on Security examines the dual role of AI surveillance in advancing and hindering social progress. It highlights the tension between security benefits and threats to privacy and civil liberties. This matters as AI monitoring becomes more pervasive in public and private sectors.

Exclusive

Hackers Use Fake Microsoft Entra Passkey Enrollment to Breach M365

Cybercriminals are deploying fake Microsoft Entra passkey enrollment prompts to trick users into granting unauthorized access to Microsoft 365 accounts. This phishing technique bypasses traditional security measures by mimicking legitimate authentication flows. Organizations should educate users about verifying enrollment requests and enable additional safeguards.

Exclusive

Dormant GitHub Accounts Help Attackers Blend In While Mapping Companies

Cyber attackers are exploiting dormant GitHub accounts to evade detection as they map corporate organizational structures. By using inactive accounts, they blend in with legitimate users, making it harder for security teams to spot reconnaissance activities. This tactic highlights the need for monitoring old or unused accounts in software repositories.

security technology

How AI Language Models May Alter Human Communication

The article explores the potential for AI language models to influence and change human speech patterns and writing styles. As these models become more integrated into daily communication tools, they may subtly shift how people express ideas, raising questions about originality and linguistic evolution.

Exclusive

Microsoft Patches Flaw in RoguePlanet Defender That Could Grant SYSTEM Privileges

Microsoft released a security update for its RoguePlanet Defender application, fixing a vulnerability that attackers could exploit to gain SYSTEM-level privileges. This flaw could allow an attacker to escalate privileges and take full control of an affected system. The patch is critical for users of the product to prevent potential exploitation.