Aggregator
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
Artifacts: versioned storage that speaks Git
Deploy Postgres and MySQL databases with PlanetScale + Workers
AI Search: the search primitive for your agents
Your AI Automation Platform Decision is Missing Someone
The post Your AI Automation Platform Decision is Missing Someone appeared first on AI Security Automation.
The post Your AI Automation Platform Decision is Missing Someone appeared first on Security Boulevard.
Менеджер зависимостей, который слишком много себе позволяет. Как Composer едва не открыл двери хакерам
Microsoft 365 Web Services Hit by Google Chrome 147 Compatibility Issue
Microsoft is actively investigating a widespread authentication issue affecting users attempting to access Microsoft 365 web-based services through Google Chrome version 147. The problem, first reported on April 16, 2026, has left a significant number of users unable to properly load or interact with Microsoft 365 applications in their browser. According to Microsoft’s official service […]
The post Microsoft 365 Web Services Hit by Google Chrome 147 Compatibility Issue appeared first on Cyber Security News.
字节跳动前沿技术领域人才校招,正式启动!
Drupal security advisory (AV26-359)
NIST Drops NVD Enrichment for Pre-March 2026 Vulnerabilities
Browser Guard gets even better with Access Control
Take control of pesky permission pop-ups and decide exactly which websites can access your camera, microphone, location, and send you notifications.
The post Browser Guard gets even better with Access Control appeared first on Security Boulevard.
Is Aquila (Dmitry) from WASM Forum Community the Author of the Carberp Banking Malware?
Dear blog readers,
I recently did something very interesting and I decided to share my results and findings.
What I did was the following. While doing a technical collection round for malicious software I came across to Carberp's source where I decided to take a peek and found out some pretty interesting and relevant personally attributable IoCs (Indicators of Compromise) which led me to further pursue an OSINT enrichment process which led me to believe and conclude that there's a high probability that Aquilla (Dmitry) from the WASM forum community could be one of the main authors of the Carberp banking trojan.
The most interesting part of this technical collection round which then turned into IoCs extraction and then OSINT enrichment based on the successfully found hardcoded IoCs in Carberp's publicly accessible and leaked source code is that I think I have managed to establish a direct connection between the hardcoded C&Cs and Is Aquila (Dmitry) from the WASM forum community.
Here's the interesting part and the actual hardcoded C&C IoCs I found in Carberp's publicly accessible source code:
hxxp://178.63.11.137 (Primary test C2)
hxxp://94.240.148.127 (Alt configuration node parsing `/cfg/passw.plug`)
Payload Drop Zones & Telemetry:
hxxp://apartman-adriana.com (http://.../temp/DrClient.dll) - Email: [email protected]
hxxp://56tgvr.info
We then have an interesting connection for one of the IoCs (hxxp://178.63.11.137) which appears to have been known to be responding to the email server for the WASM forum community which based on additional analysis appear to have been managed and operated and actually owned by Aquila also known as Dmitry (Email: [email protected]; [email protected]; hxxp://dimon.ru).
Related domain registrations for Aquila:
hxxp://symbolographia.com
hxxp://wasm.site
hxxp://posthumanism.info
Related screenshot:
The post Is Aquila (Dmitry) from WASM Forum Community the Author of the Carberp Banking Malware? appeared first on Security Boulevard.
Data Centers Are Feeling the Heat, and That’s OK
DragonForce
You must login to view this content
«Нет» значит «да». Кнопка отказа от Cookie оказалась лишь красивой болванкой
大疆 OSMO Pocket 4 深度体验:三年之后,大疆如何继续定义「手持云台相机」
HSCC Guide Targets Third-Party AI Risk in Healthcare
The Health Sector Coordinating Council released guidance to help the healthcare and public health sector better manage the explosion of third-party AI vendor cyber risk concerns they face, especially as the technology is embedded in all sorts of products.
US FCC Grants Netgear Temporary Exemption From Router Ban
Netgear obtained a temporary waiver from the Federal Communications Commission allowing it to continue importing consumer routers through most of 2027, making the networking hardware giant the first consumer brand to circumvent a ban on foreign-made hardware.
Artemis Gets $70M to Build AI Agents for Detection, Response
Artemis, a New York startup led by former Amazon GuardDuty product leader Shachar Hirshberg, emerged from stealth with $70 million to build an AI-driven SIEM alternative that correlates telemetry across enterprise environments, tailors detections and speeds investigations.