Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire

A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device identity spoofing, AI-generated websites, and residential proxy services to generate advertising revenue without device owners’ knowledge. “Fuyao’s business model operates under its ability to always identify where an ad lives on a website, spoof the device … More → The post Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire appeared first on Help Net Security.

BY Sinisa Markovic
MIN READ 1 MIN READ
EXPLORE north_east
Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
CYBERSECURITY

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

An academic study has disclosed a “widespread class” of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user’s network session. The findings have been released by a group of researchers from Singapore’s Nanyang Technological University

1 MIN READ arrow_forward
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
CYBERSECURITY

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn’t originally

1 MIN READ arrow_forward
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
CYBERSECURITY

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks’ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,

1 MIN READ arrow_forward
Facial Recognition at Madison Square Garden
CYBERSECURITY

Facial Recognition at Madison Square Garden

Last month, the story broke (alternate link) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among other groups—flags activists that oppose using facial recognition. Turns out that the system was shut off for Taylor Swift’s wedding. Evan Greer—one of the people that MSG alerts on—comments: Ironically, Swift herself has reportedly used facial recognition at her own concerts to identify stalkers. This “privacy for me, surveillance for thee” attitude feels like a perfect encapsulation of the future we’re already living in: one where wealthy elites can afford privacy, while the rest of us are forced to live in a corporate surveillance panopticon…

1 MIN READ arrow_forward
Anthropic’s Claude breached three companies during security tests
CYBERSECURITY

Anthropic’s Claude breached three companies during security tests

Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environment by exploiting a previously unknown vulnerability and reached the systems of Hugging Face, the open-source machine learning platform. “After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which … More → The post Anthropic’s Claude breached three companies during security tests appeared first on Help Net Security.

1 MIN READ arrow_forward
Critical Flaw Led to Azure Cosmos DB Pwnage
CYBERSECURITY

Critical Flaw Led to Azure Cosmos DB Pwnage

Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Led to Azure Cosmos DB Pwnage appeared first on SecurityWeek.

1 MIN READ arrow_forward
Traefik Labs introduces Distro Zero secure runtime for API and AI gateways
CYBERSECURITY

Traefik Labs introduces Distro Zero secure runtime for API and AI gateways

Traefik Labs has introduced the Distro Zero image, a hardened, vendor-supported secure runtime delivered as Traefik Hub in proxy mode. It gives platform and security teams a container whose entire executable content is a single memory-safe binary, with validated cryptography built inside it and every advanced capability, from API gateway to AI and MCP gateway to full API management, unlocked by license on that same binary. No binary swap, no migration, no re-validation as needs … More → The post Traefik Labs introduces Distro Zero secure runtime for API and AI gateways appeared first on Help Net Security.

1 MIN READ arrow_forward