Consulting News

News und Newsarchiv für unsere NC Consultants
Firefox Add-on

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

Erfasst 18.09.2026 11:34 | The Hackers News
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package...
Quelle ansehen

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

Erfasst 18.09.2026 08:19 | The Hackers News
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (A...
Quelle ansehen

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Erfasst 18.09.2026 05:49 | The Hackers News
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak log...
Quelle ansehen

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Erfasst 18.09.2026 05:49 | The Hackers News
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the net...
Quelle ansehen

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

Erfasst 17.09.2026 15:47 | The Hackers News
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire servic...
Quelle ansehen

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Erfasst 17.09.2026 15:47 | The Hackers News
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-20...
Quelle ansehen

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Erfasst 17.09.2026 15:47 | The Hackers News
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company sa...
Quelle ansehen

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

Erfasst 17.09.2026 15:47 | The Hackers News
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-s...
Quelle ansehen

OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads

Erfasst 17.09.2026 15:47 | The Hackers News
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reportin...
Quelle ansehen

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

Erfasst 17.09.2026 15:47 | The Hackers News
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multip...
Quelle ansehen

CISO's Expert Guide to Agentic Pentesting for Websites

Erfasst 17.09.2026 15:47 | The Hackers News
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new fr...
Quelle ansehen

Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

Erfasst 17.09.2026 15:47 | The Hackers News
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment...
Quelle ansehen

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Erfasst 17.09.2026 15:47 | The Hackers News
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. A...
Quelle ansehen

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

Erfasst 16.09.2026 18:28 | The Hackers News
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products...
Quelle ansehen

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Erfasst 16.09.2026 18:28 | The Hackers News
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspers...
Quelle ansehen

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

Erfasst 16.09.2026 18:28 | The Hackers News
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerabili...
Quelle ansehen

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

Erfasst 16.09.2026 16:13 | The Hackers News
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attac...
Quelle ansehen

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Erfasst 16.09.2026 16:13 | The Hackers News
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 inte...
Quelle ansehen
Hinweis: Dies ist ein News-Aggregator. Das Copyright liegt bei den jeweiligen Webseiten. Die Links wurden zum Zeitpunkt der Abfrage als virenfrei und sicher bewertet. Bitte dennoch mit der nötigen Vorsicht prüfen.