Cybersecurity News
Filters
AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration | Huntress
Threat actors are using AI tools to generate custom PowerShell malware for Active Directory attacks. Huntress researchers analyzed real "vibe-coded" samples, finding that AI-assisted scripts can enumerate AD environments effectively even without deep attacker expertise. The shift lowers the barrier for creating functional malware, complicating detection since AI-generated code may lack the patterns defenders typically recognize.
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup offering millions for zero-day software vulnerabilities is led by two convicted felons with far-right, conspiracy theorist backgrounds. Their previous ventures included fraudulent intelligence firms and a defunct AI lobbying platform run under false identities, raising serious concerns about the legitimacy of their latest operation.
LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress
Attackers increasingly use "Living off the Land" techniques, abusing legitimate tools like PowerShell, WMI, and RMM software to blend in with normal IT activity. Key red flags include scripts running outside business hours, encoded commands, unusual parent-child process relationships, and tools accessing systems they don't normally touch. Context and behavioral baselines are critical for distinguishing malicious use from routine administrator work.
Telstra mobile outage disrupts services across Australia
Matched: Australia
Telstra's mobile network suffered a major outage across Australia, disrupting voice and data services for millions of customers, as well as businesses, transport operators and other organisations. The company acknowledged the issue and said it was working to restore services. It is one of the most significant disruptions to hit Australia's largest telco in recent years.
FBI Seizes NetNut Proxy Platform, Popa Botnet
The FBI seized hundreds of domains tied to NetNut, a residential proxy service run by Israeli company Alarum Technologies. The action followed a KrebsOnSecurity report linking NetNut to the Popa botnet, a network of at least two million devices infected without owner consent. The seizure involved industry partners and came roughly two weeks after the security findings were published.
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two members of the Scattered Spider cybercrime group pleaded guilty on the first day of their trial in the UK, avoiding what was expected to be a six-week proceeding. The pair were charged in connection with an August 2024 cyberattack on Transport for London, which severely disrupted the city's public transport network.
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
A years-long Android botnet called Popa has hijacked millions of consumer TV boxes to relay traffic tied to ad fraud, account takeovers, and data scraping. Security researchers have linked the operation to NetNut, a residential proxy service run by Alarum Technologies, a publicly traded Israeli company listed on NASDAQ.
Who Runs the Ransomware Group ‘The Gentlemen?’
A ransomware group called The Gentlemen has quickly become the second most active such gang, luring hackers with a 90% affiliate payout. An investigation into the group's administrator reveals clues pointing to a real-world identity behind the operation, though the group's rapid rise and recruitment success make it a significant emerging cybercrime threat.
A Record-Breaking Patch Tuesday for June 2026
Microsoft's June 2026 Patch Tuesday addressed nearly 200 security vulnerabilities across Windows and related software, the largest monthly update in the company's history. Around 30 of the flaws were rated critical, and exploit code for at least three vulnerabilities is already publicly available, raising the urgency for users and administrators to apply the patches promptly.
