https://krebsonsecurity.com/2025/07/poor-passwords-tattle-on-ai-hiring-bot-maker-paradox-ai/

Latest CyberSec News by @thecyberpicker
https://www.lastwatchdog.com/news-alert-squarex-and-fortune-500-cisos-to-debut-bowser-security-guide-black-hat-usa-2025/
Citrix Bleed 2 exploited weeks before PoCs as Citrix denied attacks
A critical Citrix NetScaler vulnerability, tracked as CVE-2025-5777 and dubbed "CitrixBleed 2," was actively exploited nearly two weeks before proof-of-concept (PoC) exploits were made public, despite Citrix stating that there was no evidence of attacks.
Microsoft Teams voice calls abused to push Matanbuchus malware
The Matanbuchus malware loader has been seen being distributed through social engineering over聽Microsoft Teams calls impersonating IT helpdesk.
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin
VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025.
United Natural Foods loses up to $400M in sales after cyberattack | CyberScoop
The food distributor and wholesaler completely shut down its systems upon discovering the attack last month, yet core systems were restored and normal operating capacity returned within three weeks.
State Department cyber diplomacy firings and changes threaten U.S. defenses
Departures and restructuring will make it harder for the agency to pursue global policies that strengthen its own critical infrastructure, experts said.
Google sues to disrupt BadBox 2.0 botnet infecting 10 million devices
Google has filed a lawsuit against the anonymous operators of the Android BadBox 2.0 malware botnet, accusing them of running a global ad fraud scheme against the company's advertising platforms.
This is your sign to step away from the keyboard
This week, Martin shows how stepping away from the screen can make you a stronger defender, alongside an inside scoop on emerging malware threats.
LameHug malware uses AI LLM to craft Windows data-theft commands in real-time
A novel malware family named LameHug is using a large language model (LLM) to generate commands to be executed on compromised Windows systems.
Hackers Use GitHub Repositories to Host Amadey Malware and Data Stealers, Bypassing Filters
Malicious GitHub repositories used by threat actors to host Amadey payloads and steal data, impacting targeted entities.
Recession, Risk and Retaliation: Mapping Global Economic Fault Lines - interos.ai
Author: Teddy DeWitt, PhD, Lead Computational Social Scientist聽 Recession Fears Linger Amidst Consumer Pessimism and Tariff Uncertainty聽 The U.S. economy ma
Russian vodka producer reports disruptions after ransomware attack
Novabev Group, the Russian maker of Beluga Vodka and other brands, had to stop shipments and temporarily close stores in its WineLab subsidiary after a ransomware attack.
Hacker steals $27 million in BigONE exchange crypto breach
Cryptocurrency exchange BigONE announced that it suffered a security breach, in which hackers stole various digital assets valued at $27 million.
Thai officials restore Ministry of Labor website after hack, defacement
Officials confirmed the incident on Thursday but claimed the hackers only defaced the website and did not penetrate servers that stored any data.
Transparency on Microsoft Defender for Office 365 email security effectiveness
Read how Microsoft is transparently sharing performance data from Microsoft Defender for Office 365 and other ecosystem providers to help customers evaluate email security solutions.
[tl;dr sec] #288 - Prompt Injection in Malware, Preventative Security, Top Bug Bounty War Stories
Checkpoint finds malware containing prompt injection, why preventative security is hard, @Rhynorater talk sharing 11 of his most impactful and technically challenging vulnerabilities
Armenian, Ukrainian nationals among Ryuk ransomware actors facing US hacking charges
Armenian national Karen Serobovich Vardanyan, 33, was extradited from Ukraine last month and now faces up to five years in prison for his role in Ryuk, prosecutors said on Wednesday.
Chinese hackers breached National Guard to steal network configurations
The Chinese state-sponsored hacking group known as Salt Typhoon breached and remained undetected in a U.S. Army National Guard network for nine months in 2024, stealing network configuration files and administrator credentials that could be used to compromise other government networks.
AI-powered attacks creep upward as CISOs prioritize AI security risks
Security executives are concerned about flaws in AI agents but also eager to see them replace humans in some roles, according to a new report.
Researchers warn of cyberattacks targeting key Fortinet software
Experts urged Fortinet customers to immediately apply patches or disable the affected administrative interface.
Max severity Cisco ISE bug allows pre-auth command execution, patch now
A critical聽vulnerability (CVE-2025-20337) in Cisco's聽Identity Services Engine (ISE) could be exploited to let an unauthenticated attacker聽store malicious files, execute arbitrary code, or gain root privileges on vulnerable devices.
Malware-as-a-Service Campaign Exploits GitHub to Deliver Payloads
A new malware campaign uses GitHub to deliver payloads via Amadey botnet, bypassing email distribution
Airbus pr茅pare l鈥橝400M 脿 devenir le 芦 vaisseau m猫re 禄 des drones de combat
L鈥橝irbus A400M, connu depuis ses d茅buts comme une r茅f茅rence mondiale du transport militaire, s鈥檃ppr锚te 脿 endosser de nouveaux r么les. Parmi eux ? Celui de 芦 vaisseau m猫re 禄 pour les drones de combat. Initialement con莽u pour l鈥檈mport de charges lourdes et le soutien logistique, l鈥橝400M voit ses missions s鈥櫭﹍argir au
Elite Russian university launches degree program on sanctions evasion
The Higher School of Economics (HSE), a leading Russian institution, said the two-year course will focus on international corporate compliance and business ethics, and will be taught in both Russian and English.
UK NCA officer jailed for stealing bitcoin from darknet criminal he previously helped investigate
A former National Crime Agency investigator who worked on the Silk Road case was sentenced to more than five years in prison for stealing 50 bitcoin seized in that operation.
Hackers Exploit Apache HTTP Server Flaw to Deploy Linuxsys Cryptocurrency Miner
A new attack uses CVE-2021-41773 in Apache HTTP Server to install a cryptocurrency miner via compromised websites.
Meta AI chatbot bug could have allowed anyone to see private conversations
A researcher has disclosed how he found a鈥攏ow fixed鈥攙ulnerability in Meta AI that could have allowed others to see private questions and answers.
Adoption agency leaks over a million records
The database contained 1,115,061 records including the names of children, birth parents, adoptive parents, and other potentially sensitive information like case notes.
Compliance is Falling Behind with Non-Human Identities | CSA
Every major compliance framework, including PCI DSS, GDPR, and ISO 27001, requires strong access controls. Yet Non-Human Identities (NHIs) are often overlooked.