Flux RSS

— Sources secondaires
68articles RSS
Reinitialiser
How AI Assistants are Moving the Security Goalposts
Outils & RechercheKrebs on Securityil y a 20 jours

AI-based assistants or "agents" -- autonomous programs that have access to the user's computer, files, online services and can automate virtually any task -- are growing in popularity with developers and IT workers. But as so many eyebrow-raising headlines over the past few weeks have shown, these powerful and assertive new tools are rapidly shifting the security priorities for organizations, while blurring the lines between data and code, trusted co-worker and insider threat, ninja hacker and novice code jockey.

Who is the Kimwolf Botmaster “Dort”?
Vulnérabilités & PatchesKrebs on Securityil y a 28 jours

In early January 2026, KrebsOnSecurity revealed how a security researcher disclosed a vulnerability that was used to assemble Kimwolf, the world's largest and most disruptive botnet. Since then, the person in control of Kimwolf -- who goes by the handle "Dort" -- has coordinated a barrage of distributed denial-of-service (DDoS), doxing and email flooding attacks against the researcher and this author, and more recently caused a SWAT team to be sent to the researcher's home. This post examines what is knowable about Dort based on public information.

‘Starkiller’ Phishing Service Proxies Real Login Pages, MFA
Gouvernance & RégulationKrebs on Securityil y a 36 jours

Most phishing websites are little more than static copies of login pages for popular online destinations, and they are often quickly taken down by anti-abuse activists and security firms. But a stealthy new phishing-as-a-service offering lets customers sidestep both of these pitfalls: It uses cleverly disguised links to load the target brand's real website, and then acts as a relay between the target and the legitimate site -- forwarding the victim's username, password and multi-factor authentication (MFA) code to the legitimate site and returning its responses.

Kimwolf Botnet Swamps Anonymity Network I2P
Malware & RansomwareKrebs on Securityil y a 45 jours

For the past week, the massive "Internet of Things" (IoT) botnet known as Kimwolf has been disrupting the The Invisible Internet Project (I2P), a decentralized, encrypted communications network designed to anonymize and secure online communications. I2P users started reporting disruptions in the network around the same time the Kimwolf botmasters began relying on it to evade takedown attempts against the botnet's control servers.

Patch Tuesday, February 2026 Edition
Gouvernance & RégulationKrebs on Securityil y a 46 jours

Microsoft today released updates to fix more than 50 security holes in its Windows operating systems and other software, including patches for a whopping six "zero-day" vulnerabilities that attackers are already exploiting in the wild.

Please Don’t Feed the Scattered Lapsus ShinyHunters
Gouvernance & RégulationKrebs on Securityil y a 54 jours

A prolific data ransom gang that calls itself Scattered Lapsus ShinyHunters (SLSH) has a distinctive playbook when it seeks to extort payment from victim firms: Harassing, threatening and even swatting executives and their families, all while notifying journalists and regulators… Read More »

The near-term impact of AI on the cyber threat
Gouvernance & RégulationNCSC UKil y a 794 jours

An NCSC assessment focusing on how AI will impact the efficacy of cyber operations and the implications for the cyber threat over the next two years.

ACD - The Sixth Year
Outils & RechercheNCSC UKil y a 996 jours

Key findings and full report from the 6th year of the Active Cyber Defence (ACD) programme.

Cyber Threat Report: UK Legal Sector
Gouvernance & RégulationNCSC UKil y a 1 010 jours

An updated report from the NCSC explaining how UK law firms - of all sizes - can protect themselves from common cyber threats.

ACD - The Fifth Year
GénéralNCSC UKil y a 1 418 jours

Key findings from the 5th year of the Active Cyber Defence (ACD) programme.

Active Cyber Defence (ACD) - the fourth year
Gouvernance & RégulationNCSC UKil y a 1 783 jours

The year four report covers 2020 and aims to highlight the achievements and efforts made by the Active Cyber Defence programme.