Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

Claude Opus 5 sharpens coding and cybersecurity work on AWS

Claude Opus 5 went live on Amazon Bedrock and Claude Platform on AWS. Anthropic says the model improves on Claude Opus 4.8’s cyber capabilities, coding through cybersecurity. Anyone with an AWS account in a supported region can call it. On higher-risk requests, Opus 5 hands the job back to Opus 4.8, the older model. The user sees a notice when that happens. API customers can configure the fallback. The guardrail that catches the riskiest requests … More → The post Claude Opus 5 sharpens coding and cybersecurity work on AWS appeared first on Help Net Security.

BY Anamarija Pogorelec
MIN READ 1 MIN READ
EXPLORE north_east
Claude Opus 5 sharpens coding and cybersecurity work on AWS
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
CYBERSECURITY

Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: AI agents are still logging in as humans Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mixed stacks as companies keep their options open. PR3TACK preemptive framework maps threats before … More → The post Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached appeared first on Help Net Security.

1 MIN READ arrow_forward
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
CYBERSECURITY

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and

1 MIN READ arrow_forward
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
CYBERSECURITY

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires

1 MIN READ arrow_forward
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
CYBERSECURITY

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused phishing operations reveal a more immediate approach. Instead of harvesting

1 MIN READ arrow_forward
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
CYBERSECURITY

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. “Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling

1 MIN READ arrow_forward
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
CYBERSECURITY

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis. “The portal combined build generation, finance,

1 MIN READ arrow_forward