CyberNews

Cybersecurity News Dashboard

Showing 51–60 of 277 articles
NEWS The Hacker News

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 - The Hacker News

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that redirection is not allowed by default. Security researchers Alejandro Hernando and Borja Martinez described the technique in "Plug And Pwn: Weaponizing Windows PnP Auto-Install," research prepared for DEF CON 34. They built tooling to emulate arbitrary USB devices and said that, under the required conditions, an unprivileged user can turn the PnP installation path into SYSTEM code execution. Microsoft's own driver documentation describes the underlying selection step: Windows receives hardware and compatible IDs for a device and uses them to find a matching driver package.

Aug 11, 2026, 10:48 AM Read more →
NEWS The Hacker News

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets - The Hacker News

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let the agent stitch them together and send the data back. The attack targets coding tools that connect to outside servers over the Model Context Protocol (MCP), the open standard that lets AI assistants call external tools. A malicious MCP server can put one fragment in a tool description and another in a tool result; some setups also support server-initiated sampling. MCP does preserve structured tool and result boundaries. But ASSET Research Group's tests show agents can still combine instructions across them in the same working context, so no single fragment has to contain the whole malicious request.

Aug 11, 2026, 10:24 AM Read more →
NEWS The Hacker News

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets

A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let

Aug 11, 2026, 10:24 AM Read more →
RESEARCH Kaspersky Securelist

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

Project CAV3RN continues to target Israel with an evolving command-and-control (C2) architecture that leans heavily on legitimate cloud services. In this latest iteration, operators use Google Apps Script as a relay for C2 communications and rely on DNS-based channel selection to steer traffic between C2 routes, making the campaign significantly harder to sinkhole or block at the network edge. The framework is a modular .NET NativeAOT implementation, compiled ahead of time so the payloads are smaller, faster to load, and far more difficult to analyze statically. Each module is delivered independently, letting the operators swap or extend components without redeploying the entire toolset. By blending C2 traffic with genuine Google services and using DNS records to recover configuration and select active channels, the malware avoids dedicated infrastructure and evades many network-level detections. Defenders are advised to monitor for anomalous DNS queries and outbound traffic toward Google Apps Script endpoints in environments with exposure to Israel-based assets.

Aug 11, 2026, 10:00 AM Read more →
RESEARCH Palo Alto Unit 42

Kimwolf v7: An Evolution of the Kimwolf Botnet

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet (https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/) appeared first on Unit 42 (https://unit42.paloaltonetworks.com). Security research like this is a reminder that visibility into endpoints, identity, and network traffic remains the foundation of any effective defense program. Finally, maintain offline, tested backups and a clear communication plan so that business continuity decisions are made ahead of time rather than under pressure.

Aug 11, 2026, 10:00 AM Read more →
NEWS BleepingComputer Ransomware

US and South Korea warn of Gunra ransomware targeting govt agencies

U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. Ransomware operators in this campaign appear to follow the double-extortion playbook, threatening to publish stolen data if the ransom demand is not met. Finally, maintain offline, tested backups and a clear communication plan so that business continuity decisions are made ahead of time rather than under pressure.

Aug 11, 2026, 09:47 AM Read more →
NEWS The Hacker News Ransomware

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of

Aug 11, 2026, 09:16 AM Read more →
NEWS The Hacker News Ransomware

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks - The Hacker News

Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations," CISA Acting Executive Assistant Director for Cybersecurity, Chris Butera, said. Attacks deploying the ransomware have leveraged security flaws in internet-facing Schneider Electric PowerLogic P5 (CVE-2024-5559) and Fortinet FortiOS and FortiProxy (CVE-2025-24472) appliances to obtain initial access, and then deploy the Gunra ransomware as part of a double extortion model that combines data exfiltration and data encryption for maximum impact.

Aug 11, 2026, 09:16 AM Read more →
NEWS The Hacker News

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat The incident highlights how adversaries continue to evolve their tradecraft, combining increasingly accessible tooling with targeted social engineering to slip past traditional perimeter defenses. Security teams should review their detection rules, keep threat-intelligence feeds current, and validate that incident-response runbooks are tested before an incident occurs.

Aug 11, 2026, 06:55 AM Read more →
NEWS The Hacker News

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine - The Hacker News

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat nor electricity. CERT Polska disclosed the December 2025 incident on August 8 after an investigation lasting more than three months. Poland's prime minister had said in January that two CHP plants were hit. This is the second. The route ran through a private APN, or access point name: a dedicated cellular data network managed by the distribution system operator. A configuration that allowed arbitrary devices on that APN to communicate with one another let the attacker pivot from a compromised wind-farm network to a controller at the CHP plant.

Aug 11, 2026, 06:55 AM Read more →