Aggregator
Cofense adds AI-powered campaign detection to stop phishing attacks
Cofense has announced new advancements to its Phishing Defense Platform aimed at improving detection and response to AI-powered phishing attacks. The updates include AI-driven phishing detection, enhanced triage automation, and AI-assisted training campaign creation designed to strengthen protection across the phishing lifecycle. Phishing threats are no longer one-off emails. Attackers launch coordinated, polymorphic campaigns that deliberately vary content, senders, and delivery patterns to evade both traditional and AI-only detection approaches. The Cofense platform combines AI … More →
The post Cofense adds AI-powered campaign detection to stop phishing attacks appeared first on Help Net Security.
KongTuke hackers now use Microsoft Teams for corporate breaches
Qilin
You must login to view this content
Мошенники тратят $1,22 и зарабатывают тысячи. Кража крипты стала выгоднее большинства легальных профессий
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Note: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in Emergency Directive 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems and Supplemental Direction ED 26-03: Hunt and Hardening Guidance for Cisco SD-WAN Systems. Adhere to the applicable Binding Operational Directive (BOD) 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Foxconn Attack Highlights Manufacturing's Cyber Crisis
CVE-2016-4055 | moment Package up to 2.11.1 on Node.js Regex duration resource management (Nessus ID 111213 / BID-95849)
CVE-2016-4056 | TYPO3 up to 6.2.18 Backend module cross site scripting (ID 850026)
CVE-2016-4338 | Zabbix up to 2.0.17/2.2.12/3.0.2 Configuration Script userparameter_mysql.conf mysql.size sql injection (EDB-39769 / Nessus ID 95816)
CVE-2016-4340 | GitLab up to 8.7.0 Impersonation access control (EDB-40236 / Nessus ID 90877)
CVE-2016-4484 | cryptsetup Package up to 2:1.7.3-2 on Debian improper authentication (Nessus ID 219567 / BID-94315)
CVE-2016-4793 | CakePHP up to 3.2.4 HTTP Header clientIp CLIENT-IP input validation (EDB-39813 / Nessus ID 97393)
CVE-2016-5091 | TYPO3 up to 8.1.1 ExtbasE 7pk security (Nessus ID 92448 / ID 100641)
CVE-2016-5119 | KeePass up to 2.33 Automatic Update input validation (FEDORA-2016-125ea34ff9 / Nessus ID 94778)
CVE-2016-4055 | Oracle Primavera Unifier 16.x/17.x/18.x Moment resource management (Nessus ID 111213 / BID-95849)
LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises
Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher & threat hunter. You can find Moises on LinkedIn and X. Credential theft malware rarely announces itself with ransomware-level noise. Instead, it operates like a silent siphon hidden inside everyday business workflows: invoices, payroll files, purchase orders, procurement requests. Agent Tesla campaigns are especially dangerous because they target the operational […]
The post LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises appeared first on ANY.RUN's Cybersecurity Blog.