CyberSecure Specialist

The devil is still in the email – but wearing a new mask

Business Security When phishing can increasingly pass familiar checks, avoiding or limiting the damage depends on how quickly your company can detect and contain the attack Tomáš Foltýn 28 Sep 2026  •  , 6 min. read Many of today’s phishing attempts are no longer betrayed by poor grammar, a sketchy URL or a crude login page. To be sure, it does still pay to look out for these red flags, but their absence doesn’t make…

Read More

DARPA Selects Xint to Use AI in Securing Military Messaging Apps

The Defense Advanced Research Projects Agency (DARPA) selected Xint to research the use of autonomous AI application security for deep analyses of internally and externally developed messaging applications that are used throughout the Department of War. DARPA was established in 1958 following the USSR’s launch of Sputnik in 1957. The purpose was to ensure the US would never again be surprised by the technological achievements of foreign countries. DARPA consequently partners with and supports private…

Read More

Modulate Raises $25 Million to Advance Deepfake Detection

Frontier AI firm Modulate has raised an additional $25 million funding from Future Ventures, with participation from Hyperplane and Lakestar, bringing its total funding to $60 million. Modulate builds audio-native AI models that enable machines to understand the nuances in human conversation, whether natural or fake.  It uses a proprietary Ensemble Listening Model (ELM) architecture to generate the individual AI models that power its Velma platform. Velma brings together more than 100 of these specialized…

Read More

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p. According to three sources familiar with the matter, the Dutch man arrested by authorities this month is Pepijn van der Stap,…

Read More

Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway

CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026-88776, CVE-2026-88777, and CVE-2026-88778.  CISA has added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities (KEV) Catalog. Both are critical, zero-day vulnerabilities that can independently enable remote code execution. CISA has received reports and partner threat intelligence confirming that threat actors are actively exploiting these vulnerabilities globally. Because updating Citrix NetScaler appliances…

Read More

Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

A Microsoft SharePoint vulnerability tracked as CVE-2026-65660 is now being exploited in attacks, roughly six weeks after Microsoft announced patches and a couple of days after researchers disclosed technical details. CVE-2026-65660 is a remote code execution vulnerability fixed by Microsoft with its August 2026 Patch Tuesday updates. The company’s advisory describes it as a code injection issue that lets an authenticated attacker with low-level access to an affected server execute arbitrary code without user interaction. …

Read More

Is that vibe coded app safe? 5 checks before you download

Mobile Security As AI lets anyone build software, here’s how to vet that shiny new app before it exposes your data Phil Muncaster 25 Sep 2026  •  , 6 min. read AI platforms are transforming many industries. But perhaps none more so than software development. “Vibe coding” was only coined as a term in February 2025. Yet just a few months later, one report suggested 84% of developers were using or planning to use AI…

Read More

New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

A threat actor has been selling access to a new Windows botnet that relies on AI to maintain persistence on infected hosts, Qrator reports. Dubbed x47.c, it is advertised by a threat actor named WraithTools as providing distributed denial-of-service (DDoS) and credential theft capabilities, SOCKS5 proxies, and an AI API drain method. In early August, the threat actor offered the botnet’s base package for $200 and asked $150 for the DDoS add-on. The entire x47.c…

Read More

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims. One of several selfies from the Facebook page of Cameron Wagenius. Cameron John Wagenius, 22, was stationed at a U.S. Army base in South Korea when he…

Read More

Been told to pay at a Bitcoin ATM? Read this first

Crypto ATM scams often follow a predictable script – here’s how to recognize it and what to do if you’ve already been caught out Phil Muncaster 24 Sep 2026  •  , 5 min. read Many of us still view cryptocurrency as a niche asset. Yet some estimates claim that nearly one in 10 people globally own some. That’s why you may have noticed Bitcoin or crypto ATMs springing up in retail stores, transport hubs, and…

Read More