Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking

Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking

1+ hour, 1+ min ago   (625+ words) A Russian state-sponsored APT is behind a recent credential theft campaign mounted via hacked public Wi-Fi gateway appliances at organizations running captive portal networks, Microsoft reports. The campaign was flagged roughly a week ago by ReliaQuest, which noticed that hackers…...

SecurityWeek
securityweek.com > danglegeddon-ai-could-weaponize-forgotten-dns-records-at-global-scale

‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale

3+ day, 22+ hour ago   (864+ words) Researchers warn that AI could turn dangling DNS takeovers into a nation-state weapon capable of disrupting governments, banks and global supply chains. A ‘dangling DNS takeover’ is a known attack method that allows a bad actor to take over a…...

SecurityWeek
securityweek.com > 1-in-5-data-center-assets-are-within-easy-reach-of-attackers

1 in 5 Data Center Assets Are Within Easy Reach of Attackers

4+ day, 37+ min ago   (507+ words) Claroty has analyzed 750,000 cyber-physical systems across some of the world’s largest data center facilities. Nearly one in five of the cyber-physical systems (CPS) that keep the world’s largest data centers running sits just a single network connection away from pathways…...

SecurityWeek
securityweek.com > google-adopts-new-threat-actor-naming-system

Google Adopts New Threat Actor Naming System

6+ day, 1+ hour ago   (618+ words) The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. Google has announced that Google Threat Intelligence Group (GTIG) is adopting a new cryptonym-based naming convention for tracking threat actors. According to the…...

SecurityWeek
securityweek.com > hacked-public-wi-fi-gateways-used-to-harvest-corporate-credentials

Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

6+ day, 23+ hour ago   (493+ words) A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees. A threat actor has been hacking public Wi-Fi gateway appliances at organizations running captive portal networks to compromise the Microsoft 365 accounts of…...

SecurityWeek
securityweek.com > when-identity-verification-fails-lessons-from-a-real-world-sim-swap-and-near-account-takeover > amp

When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover

1+ week, 4+ day ago   (724+ words) Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. The attack began with an unsolicited call from someone claiming to represent my wireless carrier. The phone number was not flagged as suspicious, and…...

SecurityWeek
securityweek.com > new-hollowgraph-malware-abuses-microsoft-365-calendar-for-cc-communication

New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication

1+ week, 5+ day ago   (681+ words) Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop. A recently discovered piece of malware abuses the Microsoft 365 calendar for command-and-control (C&C) communication, Group-IB reports. Dubbed HollowGraph, the malware is believed to be part…...

SecurityWeek
securityweek.com > ai-data-centers-are-being-built-faster-than-they-can-be-secured

AI Data Centers Are Being Built Faster Than They Can Be Secured

2+ week, 3+ day ago   (712+ words) AI infrastructure introduces new security risks that traditional data center designs were never built to handle. The use and reliance on AI is the biggest single growth area in technology. But AI is enormously energy-intensive and requires a new quality…...

SecurityWeek
securityweek.com > unpatched-claude-for-chrome-flaw-lets-extensions-read-gmail-calendar

Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar

2+ week, 5+ day ago   (619+ words) AI security firm Manifold says two vulnerabilities it reported to Anthropic in May remain exploitable in the latest version of Claude for Chrome, the company’s agentic browser extension. According to Manifold, the flaws let a malicious browser extension trigger Claude…...

SecurityWeek
securityweek.com > 12-million-impacted-by-data-breach-at-japanese-telco-kddi

12 Million Impacted by Data Breach at Japanese Telco KDDI

3+ week, 3+ day ago   (559+ words) Hackers exploited a zero-day vulnerability in a third-party system to access a KDDI email system for ISPs. Japanese telecommunications giant KDDI this week confirmed that over 12 million people were affected by a June data breach. The incident occurred on June…...