OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became a route for code that could run on documentation systems, collect online material, and seek …

Google Chrome 153 Update Fixes 42 Security Flaws, Including Two Critical Bugs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the browser, including three bugs rated Critical. The Stable channel is moving to 153.0.8010.47/.48 for Windows …

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have released final technical guidance to stop attackers from forging, stealing, replaying, or misusing …

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers use to compromise Microsoft Active Directory environments. The technical guide explains how attackers exploit identity …

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities across iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode. The patches …

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

You can’t detect today’s attacks with yesterday’s threat intelligence; that’s how you could briefly formulate the challenge many modern SOCs face.  Indicators lose relevance quickly. New infrastructure appears daily. SOCs …

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house MAI models from launching cyberattacks, supplying operational attack capabilities, or increasing their own privileges. The …

Hackers Advertise Uncensored Luciferus AI Service on Underground Forums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are advertising a new “uncensored” artificial intelligence service called Luciferus, positioning it as a subscription assistant willing to process malware-development requests that mainstream AI systems would reject. Sophos Counter …

CISA Warns of Cisco Secure Email Gateway 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has added a critical Cisco Secure Email Gateway vulnerability to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw in real-world attacks. The issue, tracked …