Search/emerson
Vendor

emerson

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
xweb300d evo firmware
Connections
114 relationships
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
Unit 42’s 2026 Global Incident Response Report offers frontline intelligence drawn directly from global investigations. The report spotlights four defining trends shaping the threat landscape. We’ll take a closer look at Trend 1: AI Has Become a Force Multiplier for Attackers. Drawing on hundreds of incident response engagements, the Unit 42 2026 Global Incident Response (IR) Report provides evidence-backed insights that illustrate how threat actors leverage AI to reduce the friction behind attacks. Specific use cases include shortening development cycles, automating content generation and streamlining reconnaissance techniques. These operational efficiencies have effectively compressed the attack lifecycle, transforming what once took days into a matter of hours. Yet, while the speed of AI has undoubtedly impacted the attack surface, the fundamental threat landscape has remained relatively consistent over the past year. The attacks observed in recent investigations are largely consistent with historical patterns. Threat actors continue to rely on established techniques such as credential theft, phishing, exploitation of known vulnerabilities and ransomware deployment. This points us to the conclusion that AI is acting as a force multiplier to increase the speed and efficiency of attacks, but is not significantly redefining methods of compromise. This also implies that defenders already have the knowledge and capabilities to prevent, detect and respond to AI-enhanced cyberattacks. As an intern at Palo Alto Networks and a full-time college student, I have had the chance to observe perspectives surrounding AI from both academic and industry organizations. AI has transformed cybersecurity, but its presence in academia remains limited. The speed of AI innovation, as well as concerns regarding academic integrity, have restricted the incorporation of AI platforms into curriculum, leading to an almost “anti-AI” mindset. Rapid AI integration within workplace operations poses challenges for students with limited formal education in these tools. This disconnect challenges the traditional assumption that higher educational institutions adequately prepare students for the workforce and reflects a larger problem: technologies are evolving much faster than established systems can adapt to them. While this grants opportunities for the select few familiar with AI tools, it ultimately expands the skills gap between employers and students, leading to increased job uncertainty. For students and emerging cybersecurity professionals, understanding AI is as essential as understanding the security technologies and principles it can support. As AI becomes increasingly embedded within the cybersecurity industry, organizations are prioritizing professionals who can use it effectively — not just to automate basic tasks, but to deepen analysis, enhance decision making and identify missing gaps. Equally important is recognizing AI’s limitations. Practitioners must be able to validate AI-generated responses, think critically, identify hallucinations or inaccuracies and know when human expertise is required. As AI continues to amplify attackers’ operations, the strongest practitioners will be those who combine strong technical foundations with AI proficiency and the judgement to recognize when human intervention is needed. Because AI continues to advance at record speeds, the threat landscape looks different today than it did when we published the IR Report in February 2026. To gain the latest updates on how these tactics have evolved, I interviewed Andy Piazza, senior director of threat intelligence, Unit 42, and Richard Emerson, senior manager of reactive intelligence, Unit 42. According to Andy, AI-assisted cyberattacks have still not yet reached a level that urges organizations to redesign their cyber defense strategy — but the initial signals of AI-adoption are beginning to emerge. Threat actors are leveraging AI to lower the barrier to entry and to streamline certain stages of an attack. Between the market demand for “AI impact” driving a hype cycle, and initial signs that threat actors are exploring AI-enabled attacks, these campaigns appear louder or more visible in media coverage than they really are present in the threat landscape. However, the underlying tradecraft remains largely unchanged — the techniques for compromising systems are based on the underlying technology of the compromised hosts, not the technology that is compromising them. At this stage, Unit 42 has not observed a meaningful shift in capabilities related to AI-enabled attacks. Rather, adversaries are applying AI to the established tactics, techniques and procedures (TTPs) that they already engage in. Still, the operational efficiency gains AI offers adversaries should not be dismissed. We are seeing threat actors test AI in their attacks. From malware written using AI to malware that calls out to a large language model (LLM) or Model Context Protocol (MCP) server for command and control instructions, attackers are exploring many use cases for AI-enabled threats, just like defenders are across most enterprises. To date, these campaigns are nascent and have not had major impacts. Yet, that is a temporal assessment that is likely to change as adoption increases. If AI enables attackers to operate faster or at greater scale, organizations that rely primarily on detect-and-respond models may struggle to keep up. This reinforces the need to emphasize prevention controls, rather than assuming security operations center (SOC) teams can absorb high increases in alert volume. Andy’s advice: AI-driven threats should be treated as a strategic priority, particularly as the technology continues to evolve. However, they do not currently represent a fundamentally new class of risk. Defenders can mitigate these threats using existing processes and controls, but it is critical to continue to adapt and remain informed on emerging technologies. Richard agrees that AI has not introduced fundamentally different attack vectors. He does, however, emphasize more strongly that threat actors are leveraging AI in more sophisticated and scalable ways. In one instance, researchers identified agentic ransomware managing multiple stages of an extortion operation. While the AI agent was not fully autonomous, it operated from end to end across the attack lifecycle, significantly reducing operational complexity and compressing the timeline for the threat actors involved. Richard also points to the rise of token jacking, where threat actors exploit exposed credentials to gain unauthorized access to cloud AI services and LLM API tokens. This can potentially generate millions of dollars in unauthorized compute charges at the victim's expense. Recent trends suggest that adversaries are evolving past simply misusing the stolen tokens to training their own malicious models as well. Looking ahead, Richard expects threat actors to continue using AI to optimize existing stages of the attack lifecycle rather than creating entirely new attack vectors. He anticipates broader adoption of AI for processes such as vulnerability discovery, malware development and decision-making during active intrusions. Although he believes that fully autonomous agentic attacks remain an emerging capability, he warns that these systems will eventually operate at speeds that outpace human defenders alone. As a result, organizations must combat AI with AI to respond to these threats in real time. That being said, defenders must still think critically and understand the logic behind these agents to identify their mistakes and manually redirect defense efforts when they fail. My conversations with Andy and Richard have reinforced one clear idea: AI is changing the speed and scale of cyberattacks more than it is changing the attacks themselves. This distinction is critical. From a defense perspective, this means that foundational security knowledge is still as relevant as ever, with AI being an additional piece of the puzzle. AI is a force multiplier for attackers, but it has the potential to become an equally powerful force multiplier for defenders. As students and emerging professionals entering the dynamic world of cybersecurity, our responsibility is to understand these technologies and guide how they can be used. The future of cybersecurity will be shaped by those who are willing to continuously learn, adapt to new tools, and leverage technology to protect our digital way of life. Global Incident Response Report 2026 – Unit 42 Analyzing the Current State of AI Use in Malware – Unit 42
unit42.paloaltonetworks.comJul 16, 2026extracted
New Relic expands observability into AI-assisted software development
New Relic expands observability into AI-assisted software development New Relic has announced AI Coding Observability, an open-source tool for monitoring AI-assisted software development workflows. As organizations adopt AI coding assistants, these tools often operate outside existing observability systems, limiting visibility into their use. AI Coding Observability extends monitoring into the software development process, enabling organizations to track, analyze, and audit AI-assisted coding activities. “You can’t manage what you can’t see. AI coding assistants are having a measurable impact on businesses, but without real-time oversight into how they’re behaving, organizations are scaling risk as fast as they’re scaling output,” said New Relic Chief Product Officer Brian Emerson. “New Relic AI Coding Observability will close this gap, removing barriers to quality innovation that succeeds in production.” Bringing enterprise-grade rigor to the AI coding phase AI coding tools are now producing more code than ever, as Gartner predicts that 90% of enterprise software engineers will use AI code assistants by 2028. However, engineering organizations rarely standardize on just one AI tool. Instead, developers leverage a highly fragmented mix of coding assistants depending on the task. New Relic AI Coding Observability is being designed to future-proof development strategies and introduce a unified, vendor-neutral pane of glass that normalizes telemetry across the major AI coding assistants and correlates it seamlessly with existing production infrastructure. Key features and benefits of New Relic AI Coding Observability will include: Gain insights into code development actions – Teams will be able to move away from blind trust in their AI coding tools to gaining comprehensive insights into how these tools are actually behaving as applications and services are developed. Exercise cost control – AI coding assistants are a rapidly growing line item, yet most organizations treat them as an unmonitored expense. New Relic AI Observability will allow teams to track AI spend and eliminate black box invoices, and forecast spend against budgets and alert before thresholds are hit. Enhance productivity metrics – To understand productivity gains from coding assistant use, the capability will replace anecdotal success stories with hard data and catch inefficiencies and hidden failure modes. Ensure security and compliance – Local-only / zero-outbound mode will run queries entirely within the user’s private network, guaranteeing data sovereignty, privacy and regulatory compliance. Receive strong code transparency – Will eliminate black-box AI skepticism by providing fully readable, open-source and source-available code, empowering engineering and security teams to independently verify data privacy protocols and AI reasoning with certainty. Avoid vendor lock-in – Backed natively by the OpenTelemetry protocol and Model Context Protocol (MCP), the feature will deliver true vendor-neutrality that allows organizations to seamlessly port their telemetry data and AI workflows across any cloud ecosystem or language model provider. Provides broad coding assistant coverage – Will support Claude Code, Cursor, GitHub Copilot, Windsurf and Amazon Q. New Relic AI Coding Observability will be available as an open-source feature on June 23 at no additional cost.
helpnetsecurity.comJun 8, 2026extracted
New Relic advances AI observability with new intelligence layer
New Relic advances AI observability with new intelligence layer New Relic has announced New Relic Knowledge, a new platform capability that integrates telemetry and knowledge sources to enhance issue detection and resolution. By combining real-time telemetry with historical incident data, system changes, and deep operational context, New Relic Knowledge provides the foundational intelligence required for AI agents and engineering teams to better understand systems, make decisions, and resolve issues faster. As a result, organizations can mitigate the $76 million risk of median annual downtime by accelerating mean time to resolution (MTTR) to machine speed, turning technical reliability into a measurable business edge. As organizations adopt AI-driven and agentic operations, the reliability of autonomous systems depends entirely on accurate, real-time system context. Without it, AI agents lack the institutional knowledge needed to correctly diagnose issues or take trustworthy action. New Relic Knowledge addresses this by delivering a continuous intelligence layer that operates across the entire New Relic Intelligent Observability Platform. “Organizations today must solve technology problems at a pace that far exceeds human scale. While AI agents are addressing this challenge, they are only as effective as the data they can access,” said New Relic Chief Product Officer Brian Emerson. ”New Relic Knowledge provides the connective tissue between telemetry and action, ensuring that every technical decision—whether made by a human or an agent—is grounded in real-world context to drive true business impact.” Moving from signals to answers in real-time In addition to serving AI agents, New Relic Knowledge is purpose-built for SREs, DevOps teams, and platform engineers who are under increasing pressure to maintain uptime in hyper-complex environments. Yet engineers spend up to 40% of their time searching for context across dashboards, logs, docs, and tickets. New Relic Knowledge analyzes telemetry across metrics, logs, traces, and events, and correlates it with prior incidents, system changes, and service relationships. It then surfaces relevant context instantly, enabling both engineers and AI agents to move quickly from detection to explanation and resolution. New Relic Knowledge connects telemetry, documentation, and historical incidents to deliver context aware and trusted insights in real time. Key features and benefits of the capability include: Machine-speed troubleshooting: Correlates anomalies with recent deployments and configuration updates instantly, identifying what changed without manual investigation. Agentic decision support: Empowers AI agents to diagnose issues and recommend next steps with high confidence by referencing similar past incidents and system behavior patterns. Operational toil reduction: Provides context-rich answers embedded directly within existing workflows, such as alert triage and incident response, eliminating the need for engineers to pivot across disparate tools to find answers. Continuous intelligence: Unlike static knowledge bases, New Relic Knowledge continuously assesses the user’s intent and utilizes historical business information to provide responses grounded in proprietary knowledge.
helpnetsecurity.comMay 6, 2026extracted
New Relic Agentic Platform brings governance and scale to AI agents
New Relic Agentic Platform brings governance and scale to AI agents New Relic announced enterprise-grade Agentic Platform capabilities that enable organizations to build, deploy, and manage a full spectrum of AI agents and agentic workflows, from simple single-task automations to complex, multi-agent orchestrations. With an intuitive no-code builder for domain experts, New Relic’s Agentic Platform empowers enterprises to intelligently automate a wide range of processes, leading to a significant reduction in manual toil, faster incident resolution, and improved operational resilience. “As software complexity outpaces human ability to manage it, businesses recognize agentic AI is the solution but run into a talent and trust wall during complex implementations,” said New Relic CPO Brian Emerson. “Our enterprise-grade Agentic Platform caters to the needs of both domain experts and technical operators, democratizing AI for the entire organization. We’re eliminating the barriers that keep true AI-driven automation out of reach and allowing teams to confidently create a custom, autonomous AI workforce to augment their teams.” Agentic platform enables enterprises to automate complex investigations and fixes Application complexity is outpacing automation, and many rule-based systems are falling short, leaving teams trapped in a cycle of manual toil and operational friction. Engineers lose 33% of their time to reactive firefighting, preventing them from focusing on innovation or feature development. Agentic AI is increasingly seen as the solution, as Gartner predicts 40% of enterprise apps will feature AI agents by 2026. However, organizations are facing a lack of expertise to build AI agents and the challenge of scaling from simple tasks to dynamic, multi-step processes without standardized testing and validation. The New Relic Agentic Platform is a game-changer for organizations struggling to reduce manual toil. Designed specifically for enterprise production environments, it allows teams to build, deploy, and manage a full spectrum of agents that move operations from passive observation to active task execution. It acts as a unified operations center that coordinates the automation lifecycle, allowing domain experts like SREs and Ops leads to capture knowledge and data in visual agents. Unlike standalone AI assistants or fixed automation scripts, New Relic’s Agentic Platform delivers the secure foundation and governance necessary to resolve incidents 24/7. “Agentic AI is now a boardroom conversation as executives face relentless pressure to decrease manual toil and accelerate growth. For developers, SREs and DevOps teams, the opportunity for agentic automation is clear: it’s about moving from reactive monitoring to autonomous resolution,” said Stephen Elliot, Group Vice President at IDC. “The real winners will be enterprises that deploy these agents within a robust governance framework. Those who can ensure agents make accurate, compliant decisions at scale will revolutionize their observability strategies and unlock a new level of operational efficiency.” The Agentic Platform delivers: No-code agent builder: A drag-and-drop tool enables SREs and operations leaders to capture institutional knowledge and design workflows visually, creating agents without coding. Pre-built agents: A suite of expert, out-of-the-box agents such as the SRE Nerd provide immediate value and accelerate time to adoption. Dynamic agent runtime: Enables New Relic AI agents to handle multi-step “reasoning” and adapt to novel or complex failure scenarios using dynamic logic and advanced “reasoning.” Unified AI orchestration: Centralized command center to control, manage and coordinate agents at scale. The Agentic Platform supports the model context protocol (MCP) for secure tool access, integrates natively with New Relic Workflow Automation, and provides enterprise-grade governance through fine grained role-based access control (RBAC) and audit logging. To guarantee reliability, a built-in evaluation engine continuously tests agent performance, building the trust necessary for autonomous action.
helpnetsecurity.comFeb 24, 2026extracted
Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems
The cybersecurity challenge for Industrial Control Systems (ICS) is they were designed in conditions of peace but now operate in a continuous war zone. Bryson Bort, CEO and founder at SCYTHE, starts his conversations on ICS security with a joke: ‘How can you tell a computer is an ICS?… It’s at least 20 years old.’ The purpose is not to elicit laughter but to make people think. “Once the humor passes and the reality sets in, the scale of the problem – an entrenched ecosystem with the inertia of security challenges baked in for years – becomes apparent..” The continuing problem for securing ICS This is the biggest problem for ICS security. “Something that was designed and tested to the best practices available when it was released can easily become vulnerable to attacks using more sophisticated attacks later in its lifecycle,” explains Tim Mackey, head of software supply chain risk strategy at Black Duck. “In effect, legacy best practices may not be up to the task of mitigating current threats; or worse – those that might be deployed in the coming years.” ICS are vulnerable. This is exacerbated by the operators’ reluctance, if not inability, to take the systems off-line to patch any vulnerabilities. Dario Perfettibile, VP and GM of European operations at Kiteworks, expands, “ICS security problems will unfortunately persist in 2026 because the core challenge is both economic and operational. Critical infrastructure operators simply cannot accept downtime for comprehensive overhauls, and legacy systems with 20- to 30-year lifespans weren’t designed for today’s cyber threats.” Mackey continues, “Attackers know that critical infrastructure providers are measured in their up-time or service availability; so, once a device is compromised, the attackers have the luxury of mapping out and planning a very targeted attack rather than just being opportunistic.” Industrial Control Systems were built for reliability and safety, not cybersecurity; and their weaknesses are persistent. “Many devices still rely on outdated protocols without authentication, flat network architectures, and long hardware lifecycles that make patching or replacement difficult,” says Jeff Macre, principal OT security solutions architect at Darktrace. “These challenges are compounded by limited visibility into assets and the operational risks of downtime, so the fundamental security problems in ICS environments will persist well into the future.” This is the challenge for both industry and society – the critical industries we depend upon, themselves depend upon some of the most vulnerable computer systems. Cyberattacks against ICS Both nation states and cybercriminals target ICS: the former for political expediency and the latter for financial extortion. “The critical infrastructure (CI) has become a strategic target as nation states and criminal groups both understand its value and vulnerability,” comments Raed Albuliwi, CPO at Xona. The need to keep ICS operational makes it more susceptible to ransomware from criminals, while taking down areas of the critical infrastructure can adversely affect public sentiment and disrupt society for political purposes. Elite nation state actors also breach and quietly occupy critical industries – a process known as pre-positioning – so they can neutralize the CI in rapid order either in response to, or preparation for, kinetic warfare. Michael Freeman, head of threat intelligence at Armis, warns, “By 2026, more than a third of global energy and utilities infrastructure will have experienced cyber pre-positioning activity – quiet access, data collection, and operational mapping by both human and AI-assisted adversaries.” Gary Schwartz, go-to-market lead at NetRise, adds, “State-aligned actors increasingly prioritize pre-positioning during periods of relative calm by infiltrating software supply chains that feed into network infrastructure. These footholds may appear benign today: simple reconnaissance, credential harvesting, mapping. But in a geopolitical crisis, the same access can be rapidly weaponized to disrupt industrial operations.” The fusion of IT, OT and IoT exposes every sector of the CI to new attack vectors. “Attackers could weaponize ‘smart city’ systems or exploit minor IoT devices as entry points, and then laterally move into core operational networks to cause physical damage or service outages,” says Alex Mosher, president and CRO at Armis. “Agriculture, transportation, healthcare, and energy grids will face cyber sabotage designed to disrupt essential services rather than steal information.” Joe Saunders, founder and CEO at RunSafe Security, notes that artificial intelligence (AI) is powered by vast amounts of electricity. “The surge in demand will bring renewed attention to the resilience of ICS and SCADA environments that power energy production, transmission, and data center operations.” He continues, “Greater dependency on the energy grid and data centers gives adversaries more incentive to target industrial systems for both disruption and leverage, as the consequences of an attack will be much higher. Securing these environments will move from a technical challenge to a national security imperative.” The ICS stakes can be very high. Consider, for example, the November 2025 announcement that the UK plans to build Small Modular Reactors (SMRs) in Wales. “The ICS systems in the SMRs will undoubtedly be computer controlled, and internet connected – massively increasing the threat landscape,” suggests Jeremy Epstein, security co-chair of the ACM US technology policy committee, and principal research scientist at Georgia Tech Research Institute. “Nation-state adversaries and terrorists can be expected to be monitoring the progress of SMRs in the UK, US, and everywhere else, developing new types of attacks. And whatever gets installed will probably be there for 30-50 years, the lifecycle of a nuclear power plant.” The current nation state situation will get worse. “Attacks will demonstrably increase as geopolitical tensions worsen. Russia’s Ukrainian power grid attacks and Chinese reconnaissance of U.S. water systems establish ICS as legitimate targets,” comments Perfettibile. “Geopolitical conflicts are fueling a surge in OT/ICS attacks,” adds Vikesh Khanna, CTO and co-founder at Ambient.ai. “State-sponsored actors and hacktivists target critical infrastructure for disruption, as seen in DDoS campaigns, ransomware, and even physical sabotage attempts. This convergence of cyberwarfare and geopolitics heightens risks.” Macre adds, “We’re already seeing more OT‑focused malware and ransomware linked to geopolitical conflict. For example, VoltRuptor is a sophisticated ICS/SCADA malware developed by the Infrastructure Destruction Squad, featuring multi-protocol support, persistence, and anti-forensics capabilities. It has been deployed in attacks against critical infrastructure and is sold on dark web forums. Analysts believe it is aligned with state-sponsored campaigns targeting countries that aren’t either pro-Russia or China, making it a significant geopolitical cyber threat.” Bort believes, “Ransomware will continue to increase. The asymmetric advantages of these kinds of cyberattacks will continue to increase.” It is often difficult to accurately attribute ransomware to criminals, state actors or a mix of the two since disruption could be the result of criminal activity or the purpose of state actors. Cyble reported it observed ‘a staggering 5,967 (ransomware) attacks globally in 2025’, with many of these targeting critical industries. Andrew Lintell, GM for EMEA at Claroty, adds, “With 12% of OT devices expected to carry known exploitable vulnerabilities (KEVs) and 7% linked to ransomware campaigns, industrial cybersecurity will need to be treated as a continuous operational priority.” ICS is a nut caught between cybercriminals and state actors, and between them it will increasingly be targeted and cracked in the coming years. ICS in 2026 and beyond The overriding belief is that ICS will seek and require greater resilience in 2026, although Trevor Dearing, Director of critical infrastructure at Illumio stresses the need to go further into ‘anti-fragility’, “Aiming not just to withstand attacks, but to emerge stronger from them… It’s not just about recovery, it’s about adaptation, learning, and improvement.” Since the primary cause of ICS problems is the longevity of the hardware, the most obvious solution would be to rip them out and replace them with modern, more secure systems. Although replacement may happen gradually over time, this is not considered a short term solution. “Many ICS assets are designed for 10‑ to 20‑year lifecycles, and replacing them outright is rarely cost‑effective. The equipment itself is expensive, and new components often have interoperability challenges with existing systems. Mixing old and new technologies can introduce more risk than it solves,” explains Macre. Khanna comments, “Practical and financial hurdles like downtime, compatibility, and high costs (often millions per site) slow progress, particularly when factoring in physical retrofits.” Saunders adds, “The economic and operational barriers to replacement are simply too high. Gradual modernization will happen over time, but resilience has to start now, with cybersecurity that protects existing assets while the industry transitions.” As a result, improvements to security will need to co-exist with aging hardware. “Industrial systems and critical infrastructure are entering a new era of hybrid automation. Modern controllers, robots, and automation software are making real-time decisions alongside decades-old, legacy equipment,” says Anusha Iyer, Founder and CEO at Corsha. Modern security must be added to ICS hardware without interfering with its operational priorities. This will most likely be achieved by modern security controls assisted by artificial intelligence to achieve a degree of automation – and will focus on introducing zero trust principles. “Automation provides a great opportunity for enterprises to optimize and gain efficiencies but also adds complexity and risk. Taking an identity-centric approach to controlling connections and managing risk creates a shared foundation for visibility, trust, and governance across digital and operational domains,” continues Iyer. Understanding and reducing the identity attack surface should be critical thinking for every organization, says James Maude, field CTO at BeyondTrust. “Organizations need to think about how to securely manage privileged access into their critical environments. Ensuring that employees, vendors, and 3rd parties have just the access and permissions needed to do their job without additional risk exposure. This can be combined with real time monitoring and controls to audit and terminate access in the event of identity compromise.” Brian Reed, CMO at Corsha, says “Automated machine identity with continuous authentication establishes that control layer in a way that is simple to deploy, simple to manage, and easy to scale as systems grow.” Identity management is key to any zero trust approach. “The C-Suite, CISOs, and CSOs need to look beyond siloed views of obviously privileged identities in individual systems and take a holistic view of the combinations of privileges, entitlements and roles that could be exploited by an attacker to elevate privilege, move laterally and inflict damage,” continues Maude. The identity security debt accumulated by many organizations represents a greater risk than any other area since it only takes one attacker to login with the right identity and all is lost because of the available paths to privilege. Schwartz comments on the growing adoption of OT-aware zero trust. “Carnegie Mellon’s Software Engineering Institute, Emerson, and Control Engineering have all published guidance showing how zero trust can be adapted to ICS using authenticated engineering actions, granular segmentation, and tightly governed remote access. This reflects the reality that supply-chain compromise is often inevitable, so access must be constrained even for trusted components.” He adds that SBOMs and vendor transparency are becoming essential. “Supply-chain failures like Log4Shell and XZ Utils demonstrated that operators need visibility into what’s inside their controllers and software stacks. None of these approaches solve everything, but collectively they move ICS toward a more verifiable, trustworthy ecosystem that’s harder to compromise at the source and easier to defend in practice.” Segmentation is an important part of the path to resiliency through zero trust. Agnidipta Sarkar, chief evangelist at ColorTokens, has two recommendations for resilience. The first is microsegmentation. It prevents an attacker using lateral movement to reach the ‘ICS islands of excellence’. The second is to prevent credential misuse “by using cryptographic passwordless authentication. Both approaches are fundamental to adopting zero trust for cyber resilience,” he suggests. Carlos Buenano, CTO for operational technology at Armis, believes that CTEM will become the operational center of gravity. “A few years ago, CTEM (continuous threat exposure management) was just another Gartner acronym. In 2026, it’s the organizing principle for any serious OT security program.” He explains, “CTEM represents a shift from periodic vulnerability management to continuous, risk-based exposure assessment and management across hardware, firmware, network paths, and even supply-chain dependencies. But the key difference this year is context. We’re no longer prioritizing based on CVSS scores alone. Instead, we’re aligning exposures with what actually matters; the physical process, the human safety implications, and the potential operational impact.” AI is increasingly included to add speed and efficiency to security controls. Agentic AI offers enormous potential for autonomous action in the future, but the extent to which it may safely be introduced into the ICS ecosphere is unclear and likely to be very slow. However, it has already arrived within ICS physical security. “A key innovation is agentic physical security for proactive threat prevention,” comments Ambient.ai’s Khanna. Such platforms can leverage AI agents to monitor physical spaces in real-time, detecting anomalies such as unauthorized access attempts or suspicious behavior near ICS assets. AI-driven anomaly detection is another recommended use of AI. “It could detect anomalies like unauthorized access attempts or suspicious behavior near ICS assets,” suggests Khanna. “This integrates seamlessly with ICS for holistic monitoring, combining computer vision with access control systems to verify identities and prevent breaches before they escalate. Adaptive protections using ML for real-time encryption and threat response are game-changers, especially when layered with physical barriers and AI-verified access.” Darktrace’s Macre adds, “Passive anomaly detection is safe for fragile ICS networks, and AI can take it further by learning what ‘normal’ looks like for each unique environment. That means fewer false positives and more actionable insights – which is critical for teams who are drowning in ‘noise’. When paired with autonomous response, organizations can stop threats in real time, while still keeping humans in the loop when needed.” However, NetRise’s Schwartz warns, “Its value is often overstated. It can highlight unusual network traffic, suspicious engineering actions, or deviations in process behavior, providing a spotlight on activity that operators might otherwise miss. But anomaly detection only sees what happens after a compromise manifests on the network. It does little to address the deeper software supply-chain risks that now dominate ICS intrusions.” He continues, “Real resilience comes from combining behavioral monitoring with pre-deployment assurance: examining the code that runs on devices, validating its integrity, and governing how updates are introduced into the environment. In other words, anomaly detection watches the symptoms; supply-chain analysis addresses the cause.” SCYTHE’s Bort also warns, “The inclusion of AI, or any security tooling, increases risk: think about it, how exactly do these tools work? Most of them depend on internet connectivity for execution or the updates needed to be current. That connectivity increases risk because it increases direct surface area.” But before resilience and recovery can be realized, ICS environments will need two things in 2026. The first will be a more complete and detailed ‘inventory’ of components in the CPS area. Christian Terlecki, Director of Federal at Armis says, “In 2026, Agencies will need continuous CPS discovery and purpose-aware risk scoring. That means the ability to identify controllers, medical devices, industrial controllers, and edge appliances and to understand not just that a device exists, but what its operational role is, where its interconnections lead, and what safe remediation looks like.” In many federal contexts, he continues, “safe remediation won’t be an automatic patch; it will be a compensating micro-segmentation rule, compensating control or a virtual patch applied at the network layer, and the CPS program must support those options with clear, actionable steps.” Sam Maesschalck, lead OT cyber security engineer at Immersive, suggests the second new requirement: “In 2026, the industry will also face increasing pressure to grow and upskill the OT security workforce. Organizations will prioritize hands-on training, scenario-based exercises, and cross-discipline capability building between IT and OT teams. Those that mature fastest will be the ones investing in continuous education, realistic OT lab environments, and workforce development programs rather than relying solely on tools and external consultancies.” So, how do we defend today’s systems? “Through a continually evolving set of defenses, monitoring systems, and responses,” suggests Epstein. “What works in 2025 will certainly not be good enough in 2030, as the threats will continue to advance, and the systems will continue to evolve adding new attack surfaces.” Will AI be the silver bullet? “No,” he continues. “But it can be part of a solution, going beyond anomaly detection. The protection for the water system for Springfield Ohio will be different from the one from Springfield Virginia and all of the dozens of other Springfields around the country – not even including The Simpson’s hometown. Upgrades to address security will be different for each Springfield, and AI systems addressing security will need to be customized for each one.” In the end, he adds, “It’s hard to be a serious cybersecurity expert without being a pessimist. In nearly 40 years in the field, I’ve seen some things get better (for example, we’re much better at building software than we were), but the threats have evolved more rapidly. ICS needs more attention in the form of industry, government, and academic R&D to build and adapt technologies to address rapidly evolving threats.” Related: CISA Warns of ScadaBR Vulnerability After Hacktivist ICS Attack Related: Canada Says Hackers Tampered With ICS at Water Facility, Oil and Gas Firm Related: NIST Publishes Guide for Protecting ICS Against USB-Borne Threats Related: Iranian Hackers’ Preferred ICS Targets Left Open Amid Fresh US Attack Warning
securityweek.comFeb 17, 2026extracted
Cybersecurity jobs available right now: December 23, 2025
Cybersecurity jobs available right now: December 23, 2025 Application Security Architect ARRISE | UAE | Hybrid – No longer accepting applications As an Application Security Architect, you will define and mature the application security architecture strategy, standards, and guardrails across products and platforms. You will lead threat modeling and architecture reviews for modern systems, including web, API, microservices, and cloud-native environments. You will oversee secure design and code reviews, vulnerability assessments, and partner with DevOps and engineering teams to embed security tools and controls throughout the SDLC. CISO LyondellBasell | France | Hybrid – No longer accepting applications As a CISO, you will develop and execute the enterprise cybersecurity strategy aligned with business and IT priorities. You will advise the CIO, Board, and executives on cyber risk, threats, and compliance, embed security into major IT and transformation initiatives, and represent security in governance forums. You will lead the GRC function, ensure regulatory compliance, oversee risk assessments and audits, and report cybersecurity posture to executive leadership. Cloud Security Architect AIB | Ireland | Hybrid – No longer accepting applications As a Cloud Security Architect, you will design cloud security processes for risk and posture management, incident response, and operational resilience to ensure timely and effective delivery. You will design and implement security frameworks that support cloud adoption and ensure compliance with ISO 27001, NIST, and CIS Benchmarks. Get weekly updates on new cybersecurity job openings. Subscribe here! Cyber Security Engineer-Pentester Protergo | Indonesia | On-site – No longer accepting applications As a Cyber Security Engineer-Pentester, you will conduct vulnerability assessments, penetration testing, and red team engagements in a consulting environment. You will use tools such as Metasploit, Nmap, and Burp Suite to assess cloud, on-premises, and hybrid environments, including mobile, web, and infrastructure platforms. Cyber Security Lead Joseph Rowntree Foundation | United Kingdom | On-site – No longer accepting applications As a Cyber Security Lead, you will lead the delivery of the organization’s cybersecurity activities, ensuring digital systems and information assets are protected from current and emerging threats. You will maintain the cyber risk register, lead investigations into security breaches, coordinate disaster recovery and incident response, and support business continuity planning, including defining Recovery Point and Recovery Time Objectives. Cyber Security Process Specialist ESB | Ireland | Hybrid – No longer accepting applications As a Cyber Security Process Specialist, you will support the compliance monitoring program to assess adherence to established policies and standards. You will regularly report findings to management and provide recommendations for improvement. You will also collaborate with risk management teams to identify, assess, and prioritize cybersecurity risks, ensuring controls and mitigations are effective and aligned with policy standards. Cyber Security Specialist (ICS/OT) AtkinsRéalis | Canada | Hybrid – No longer accepting applications As a Cyber Security Specialist (ICS/OT), you will plan cybersecurity activities and apply a risk-based approach across all project phases, from feasibility and design to testing, commissioning, and operations. You will conduct risk assessments and evaluate the effectiveness and impact of mitigation strategies. You will also perform gap, threat, and vulnerability assessments in line with industry standards by identifying critical assets and appropriate security controls. Cybersecurity Vulnerability Analyst Marelli | Italy | Hybrid – No longer accepting applications As a Cybersecurity Vulnerability Analyst, you will perform vulnerability assessments and cybersecurity validation on work products. You will define and review test suites, develop and run automated tests, and generate test reports. You will review security-critical software, report vulnerabilities identified during testing, and support and coordinate with penetration testing suppliers. IT Security Specialist Volkswagen Group | Italy | Hybrid – No longer accepting applications As an IT Security Specialist, you will design, implement, and validate security controls across networks, servers, endpoints, cloud services, and applications. You will support infrastructure and development teams in adopting secure configurations and practices, lead technical investigations during security incidents, and perform vulnerability assessments, penetration testing coordination, and security hardening. Lead Application Security Engineer Swift | USA | Hybrid – No longer accepting applications As a Lead Application Security Engineer, you will lead comprehensive security architecture reviews across Swift’s applications in all business domains. You will conduct advanced code security reviews with developers across Java, JavaScript, C++, Python, and other emerging languages. You will also lead security assessments for critical applications, defining required controls based on business needs, and optimize DevSecOps tools within CI/CD pipelines to reduce false positives and improve developer adoption. Manager – Cybersecurity Emerson | India | On-site – No longer accepting applications As a Manager – Cybersecurity, you will drive the timely and effective execution of product security activities, including SDL consultations, penetration testing, cybersecurity training, and IEC 62443–based assessments. You will ensure strong product security involvement in identifying architectural weaknesses through threat modeling and provide guidance on secure coding practices. You will also develop and execute product security project plans aligned with product release timelines, milestones, and deliverables. Manager, Cybersecurity and Cloud Policy Hewlett Packard Enterprise | USA | On-site – No longer accepting applications As a Manager, Cybersecurity and Cloud Policy , you will develop and maintain the cybersecurity and cloud policy framework and strategy. You will analyze global policy developments related to cybersecurity and cyber resilience, product, telecom, network, supply chain, and cloud security, as well as critical infrastructure protection and other regulatory issues shaping the security landscape. NMC Cyber Threat Intelligence Specialist Police Digital Service | United Kingdom | Hybrid – No longer accepting applications As a NMC Cyber Threat Intelligence Specialist, you will tactical and operational analysis using appropriate tools and techniques to identify gaps, patterns, and trends, assess threats, risks, and impacts, and provide recommendations to support decision-making, prioritization, and resource allocation. You will correlate intelligence from multiple sources to develop and lead analysis of contextually relevant threats. You will also lead independent project analysis and develop materials on specific subjects of concern. OT Security Architect dormakaba | Germany | Hybrid – No longer accepting applications As an OT Security Architect, you will design and implement advanced security solutions to protect OT and IoT infrastructures and critical production systems. You will advise leadership on integrating OT and IoT security into business decisions, migrations, and resilience initiatives. You will conduct risk assessments to identify vulnerabilities, define security requirements for new systems and machinery, and monitor and respond to OT and IoT security incidents to maintain operational continuity. Principal, Cyber Security, Risk & Compliance Deakin University | Australia | Hybrid – No longer accepting applications As a Principal, Cyber Security, Risk & Compliance, you will oversee the delivery of security controls aligned with business objectives and industry standards. You will develop and manage cybersecurity, resilience, risk, and compliance frameworks and roadmaps, lead projects to successful delivery, and conduct enterprise-wide risk, resilience, and third-party assessments across complex digital environments. Principal Offensive Security Engineer Autodesk | Canada | Hybrid – No longer accepting applications As a Principal Offensive Security Engineer, you will proactively fuzz, research, and investigate AEC products and processes to identify security issues and improvements. You will support AEC security incident BPM processes and assist engineering teams with secure code development through your expertise. You will also help establish policies, procedures, and standards to strengthen the overall security posture. Senior Analyst, Mandiant Threat Intelligence Services Google | USA | Hybrid – No longer accepting applications As a Senior Analyst, Mandiant Threat Intelligence Services, you will contribute to customers’ global security missions by delivering actionable intelligence and supporting monitored escalations. You will evaluate current and emerging tools and best practices for tracking advanced threat actor tools, techniques, and procedures, along with their motivations and industry trends. You will also conduct operational and tactical research using Mandiant sources, tailored to the client’s industry, geography, and technology stack, to produce timely and relevant intelligence. Senior Cyber Security Engineer Airbus Aircraft | France | Hybrid – View job details As a Senior Cyber Security Engineer, you will investigate cyberattacks and perform digital forensics and incident response activities. You will enhance threat hunting through improved intrusion detection, contribute to the design and development of detection, response, and DFIR tools, and conduct threat intelligence on attacker groups targeting the aerospace and defense sector. You will also contribute to research and publications produced by the Airbus CERT. Senior Mobile Threat Analyst ActiveFence | Israel | Hybrid – No longer accepting applications As a Senior Mobile Threat Analyst, you will investigate and identify threat signals across web and mobile platforms, including social media, forums, apps, and the darknet. You will analyze large datasets to uncover patterns, monitor third-party channels for malicious activity, and produce clear reports with actionable insights and recommendations. Senior SecOps Engineer UVeye | Israel | Hybrid – No longer accepting applications As a Senior SecOps Engineer, you will implement and manage security tools such as static code analysis, cloud posture monitoring, and penetration testing solutions. You will embed security into the DevOps lifecycle across CI/CD pipelines, infrastructure as code, and development workflows. You will design and enforce cloud security policies and lead incident response, vulnerability management, and forensic investigations to mitigate threats. Senior SOC Engineer (AI & Automation) CPX | UAE | On-site – No longer accepting applications As a Senior SOC Engineer (AI & Automation), you will build and maintain AI-driven solutions that improve workflows and user experience. You will develop scalable backend services and APIs for AI/ML workloads and evolve platform components such as vector search, feature stores, and evaluation tooling. You will also implement security, data protection, and responsible AI controls to ensure safe and compliant use of models and data. Software Security Engineer, Experienced or Senior Boeing | USA | Remote – No longer accepting applications As a Software Security Engineer, Experienced or Senior, you will operationalize open-source policy and processes through automation. You will independently investigate, analyze, and resolve licensing issues with a focus on business-driven outcomes. You will automate Software Composition Analysis using a mix of commercial, open-source, and in-house tools, conduct trade studies, and collaborate with Product Owners to meet stakeholder requirements. You will also manage dependency scanner configurations, triage critical open-source vulnerabilities, and work with development teams to ensure timely remediation. Specialist Information Security Risk Management SIXT | Germany | On-site – No longer accepting applications As a Specialist Information Security Risk Management, you will contribute to improving the risk management framework and conduct security risk assessments, supporting asset owners with remediation planning. You will assist control owners in implementing technical measures to achieve remediation objectives, help keep security policies current with emerging trends, and integrate internal controls and KPI/KRI practices into daily operations. Zero Trust ISSM Cedelis | USA | On-site – No longer accepting applications As a Zero Trust ISSM, you will execute Risk Management Framework activities across the system lifecycle, including documentation, assessment support, and authorization maintenance. You will monitor system security posture through continuous monitoring, reviewing configuration data, vulnerability findings, and compliance artifacts. You will also identify, document, and track vulnerabilities and control deficiencies, supporting the development and management of POA&Ms.
helpnetsecurity.comDec 23, 2025extracted
Auto Parts Giant LKQ Confirms Oracle EBS Breach
Automotive parts giant LKQ Corporation has confirmed that it has been impacted by the recent cybercrime campaign targeting customers of the Oracle E-Business Suite (EBS) solution. The Fortune 500 company provides recycled, refurbished, and aftermarket components for cars and other types of vehicles. LKQ was one of the first victims of the Oracle EBS hack named on the Cl0p ransomware website, where the cybercriminals behind the campaign have been listing targeted organizations. SecurityWeek reached out to LKQ for comment multiple times since it was named on the Cl0p website in late October, but the company has not responded. LKQ has now finally confirmed that it was targeted in the EBS campaign. The firm told the Maine Attorney General’s Office that the personal information of more than 9,000 individuals was compromised in the attack. Based on the notification letter example submitted by the company to the Maine AGO, the incident impacts sole proprietor suppliers, including information such as Employer Identification Number and SSN. The automotive parts distributor launched an investigation on October 3 and completed its analysis into personal information compromise on December 1. “There is no evidence of impact to LKQ’s systems beyond the Oracle E-Business Suite environment,” the company is telling impacted individuals in a data breach notice. Several terabytes of files allegedly stolen from LKQ’s EBS instance have been made available for download by the cybercriminals. This is not the first time LKQ has been targeted by hackers. Exactly one year ago, the company revealed that a cyberattack had caused disruptions at a Canadian business unit. Over 100 organizations targeted in Oracle EBS hack The Cl0p ransomware website currently lists more than 100 alleged victims of the Oracle EBS hacking campaign. For a vast majority of these organizations, the cybercriminals have leaked data allegedly stolen from their systems. Many major companies named on the Cl0p leak site have yet to issue a public statement on the matter. The cybercriminals typically do not name victims without cause, but the impact of their attack may be exaggerated. The list of major companies that have confirmed impact includes Logitech, Canon, Cox, Mazda, and several important US colleges. Related: NHS Investigating Oracle EBS Hack Claims as Hackers Name Over 40 Alleged Victims Related: Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack Related: CISA Confirms Exploitation of Latest Oracle EBS Vulnerability
securityweek.comDec 17, 2025extracted
Mazda Says No Data Leakage or Operational Impact From Oracle Hack
Mazda has confirmed being targeted in the recent Oracle E-Business Suite (EBS) hacking campaign. However, the carmaker told SecurityWeek that the incident did not impact system operations or production. In addition, the company said “no data leakage has been confirmed”. A Mazda Motor Europe representative clarified that “traces of an attack” were detected, but its “defensive measures were effective, preventing any system impact or data leakage”. The company said it continues to monitor its systems. The carmaker said it promptly applied the EBS patches provided by Oracle in October. Oracle initially said threat actors exploited a known vulnerability patched in July to hack into customers’ EBS instances. The software giant later patched two other potentially involved flaws tracked as CVE-2025-61884 and CVE-2025-618842, suggesting that zero-days may have been exploited in the attacks. However, nearly two months after the EBS campaign came to light, it’s still unclear exactly which vulnerability or vulnerabilities have been exploited. The Cl0p ransomware group, which has taken credit for the campaign, has named both Mazda and Mazda USA on its leak website, but it has yet to make public any data allegedly stolen from the carmaker. The leak site currently states that the company is being given “some time to respond”. However, given Mazda’s assessment of the impact, it’s unlikely that it will pay a ransom. Although organizations are generally listed on the Cl0p website for a genuine reason, the threat actors may exaggerate the breach’s actual scope to increase pressure for a ransom payment. The Cl0p website currently names more than 100 alleged victims of the Oracle EBS campaign, including dozens of major organizations. For some of the victims, the hackers have made public hundreds of gigabytes and even terabytes of files allegedly stolen from their systems. The latest to confirm being impacted is Cox Enterprises, which said the personal information of nearly 9,500 individuals was compromised in the incident. Logitech, The Washington Post, GlobalLogic, Harvard, and Envoy Air have also confirmed being hit. Other major companies named on the Cl0p site do not appear to have publicly addressed the cybercriminals’ claims, including Schneider Electric, Emerson, Michelin, Broadcom, Bechtel, Canon, and Entrust. Related: Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks Related: CISA Confirms Exploitation of Latest Oracle EBS Vulnerability
securityweek.comNov 24, 2025extracted
Cox Confirms Oracle EBS Hack as Cybercriminals Name 100 Alleged Victims
Cox Enterprises has confirmed that its Oracle E-Business Suite (EBS) instance was impacted in the recent cybercrime campaign that has targeted many organizations. Cox did not respond to SecurityWeek’s request for comment when it was listed as a victim of the Oracle EBS campaign on the Cl0p ransomware leak website in late October. However, it did confirm last week to the Maine Attorney General that it was targeted. The company said the attackers obtained personal information belonging to nearly 9,500 individuals after breaching its Oracle EBS instance between August 9 and August 14. Cox is a conglomerate with divisions focusing on communications, automotive services, and agriculture. It’s unclear which of these units were impacted by the data breach and whether the compromised information belongs to employees, customers, or partners. The cybercriminals have made public 1.6 Tb of archives containing files allegedly stolen from Cox. The number of organizations named on the Cl0p website — apparently as victims of the Oracle EBS hack — has exceeded 100, and nearly half of them are major companies in sectors such as IT, telecommunications, healthcare and pharmaceuticals, heavy industry and manufacturing, automotive and transportation, retail, energy and utilities, and media. Organizations such as Logitech, The Washington Post, Harvard, Mazda, and American Airlines subsidiary Envoy Air have confirmed being targeted. However, other large companies have not responded to SecurityWeek’s requests for comment, including Schneider Electric, Emerson, Broadcom, Michelin, Bechtel, Canon, Entrust, LKQ Corporation, and Pan American Silver. The United Kingdom’s National Health Service (NHS) has confirmed conducting an investigation, but it has yet to confirm a data breach. Cl0p has been the public-facing group to take credit for the Oracle EBS campaign, but the cybersecurity community has linked the attacks to an unknown cluster of a threat actor tracked as FIN11, which was also responsible for similar operations targeting customers of Cleo, MOVEit, and Fortra file transfer products. Based on past incidents, organizations are not listed on the Cl0p website without cause, but the actual scope of the breach may be exaggerated by the threat actors to pressure victims into paying a ransom. Related: CISA Confirms Exploitation of Latest Oracle EBS Vulnerability Related: Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks
securityweek.comNov 24, 2025extracted
Logitech Confirms Data Breach Following Designation as Oracle Hack Victim
Logitech disclosed a data breach shortly after it was named as a victim of the recent hacking and extortion campaign targeting customers of Oracle’s E-Business Suite (EBS) enterprise resource planning solution. In a Friday filing with the SEC, the consumer electronics giant said it recently experienced a cybersecurity incident that involved data exfiltration. “While the investigation is ongoing, at this time, Logitech believes that the unauthorized third party used a zero-day vulnerability in a third-party software platform and copied certain data from the internal IT system,” Logitech said. “The data likely included limited information about employees and consumers and data relating to customers and suppliers. Logitech does not believe any sensitive personal information, such as national ID numbers or credit card information, was housed in the impacted IT system,” it added. The company noted that products, business operations, or manufacturing were not impacted, and it does not believe the incident will have a material impact on its financial condition or results of operations. “Logitech maintains a comprehensive cybersecurity insurance policy, which we expect will, subject to policy limits and deductibles, cover costs associated with incident response and forensic investigations, as well as business interruptions, legal actions and regulatory fines, if any,” the company said. While Logitech has not named the third-party platform targeted in the zero-day attack, the disclosure comes after the company was named on the Cl0p ransomware leak website as a victim of the Oracle EBS campaign. Logitech was listed on the Cl0p site in early November. After repeated requests for comment from SecurityWeek, the company responded on November 10 to say that it’s not commenting on the matter. The cybercriminals have leaked 1.8 TB worth of archive files allegedly storing information stolen from Logitech. Over 50 victims have been named to date on the Cl0p website, including major companies. Some organizations, such as The Washington Post, Hitachi subsidiary GlobalLogic, Harvard University, and American Airlines subsidiary Envoy Air, have confirmed being impacted. It’s still not clear which Oracle EBS zero-days have been exploited in the campaign claimed by Cl0p, but the main candidates are CVE-2025-61884 and CVE-2025-618842. While Cl0p has been the public-facing entity, the cybersecurity community has linked the campaign to an unknown cluster of the threat actor tracked as FIN11, which was also responsible for similar operations targeting customers of Cleo, MOVEit, and Fortra file transfer products. Related: NHS Investigating Oracle EBS Hack Claims as Hackers Name Over 40 Alleged Victims Related: Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack Related: Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks
securityweek.comNov 17, 2025extracted
Washington Post Says Nearly 10,000 Employees Impacted by Oracle Hack
The Washington Post says nearly 10,000 individuals are affected by a data breach stemming from a cyberattack on its Oracle E-Business Suite (EBS) instance. A threat actor associated with the use of the Cl0p ransomware, presumably a cluster of a group tracked as FIN11, targeted the Oracle EBS instances of dozens of organizations through the exploitation of zero-day vulnerabilities. The attacks came to light in early October when the hackers attempted to extort victims. More than 40 organizations that refused to pay a ransom have been listed to date on the Cl0p leak website, including The Washington Post. Roughly 180 GB of archive files allegedly storing data stolen from the newspaper have been made public through the Cl0p leak website. In a filing with the Maine Attorney General’s Office, The Washington Post said the attackers stole the personal information of 9,720 current and former employees and contractors. Compromised data includes names, bank account numbers and routing numbers, Social Security numbers, and tax ID numbers. The media company said it was contacted by the threat actor on September 29. An investigation showed that the hackers accessed data between July 10 and August 22. The disclosure confirms previous reports that exploitation of the Oracle EBS vulnerabilities may have started as early as July, months before the patches were released. The Washington Post is among the few organizations named on the Cl0p website that have confirmed being impacted by the Oracle EBS campaign. Confirmed victims also include Hitachi subsidiary GlobalLogic, Harvard University, and American Airlines subsidiary Envoy Air. Other major companies have yet to confirm impact, either because their investigations are ongoing or because they are trying to maintain a low profile. *total size of files made available by hackers updated from 120 GB to 180 GB Related: NHS Investigating Oracle EBS Hack Claims Related: Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack Related: Akira Ransomware Group Made $244 Million in Ransom Proceeds
securityweek.comNov 14, 2025extracted
NHS Investigating Oracle EBS Hack Claims as Hackers Name Over 40 Alleged Victims
Cybercriminals have named the United Kingdom’s National Health Service (NHS) as one of the victims of the recent data theft and extortion campaign targeting organizations that use Oracle’s E-Business Suite (EBS) enterprise resource planning solutions. “We are aware that the NHS has been listed on a cyber-crime website as being impacted by a cyber-attack, but no data has been published,” a spokesperson for NHS England told SecurityWeek. “Our cyber security team is working closely with the National Cyber Security Centre to investigate.” The Oracle EBS hacking campaign came to light in early October and within two weeks the cybercriminals started naming victims on the Cl0p ransomware group’s leak website. The hackers have since made public data allegedly stolen from organizations such as Harvard University, American Airlines subsidiary Envoy Air, industrial giants Schneider Electric and Emerson, and The Washington Post. The NHS is the latest organization named on the Cl0p ransomware leak website, which now lists more than 40 alleged victims of the Oracle EBS campaign. Data allegedly obtained from 25 targets has been published. One of the victims named in recent days is Hitachi subsidiary GlobalLogic, a provider of digital engineering solutions. GlobalLogic confirmed this week that the cybercriminals gained access to HR information for current and former employees, including names, addresses, contact information, dates of birth, passport information, Social Security numbers, salary information, and bank account details. The company said the incident impacts more than 10,000 individuals. A majority of the organizations named on the Cl0p website have yet to confirm or deny being impacted. The list includes major companies such as Logitech, Cox Enterprises, Pan American Silver, LKQ Corporation, and Copeland. Victims of the Oracle EBS hack are likely conducting investigations and some of them likely do not want to share information until their probes are completed. Others are likely trying to avoid the spotlight by staying silent. While Cl0p’s history suggests that organizations are rarely listed as victims without cause, the actual scope of the breach may be exaggerated by the threat actors to pressure victims into payment. Related: CISA Confirms Exploitation of Latest Oracle EBS Vulnerability Related: Exploitation of Oracle EBS Zero-Day Started 2 Months Before Patching Related: Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks
securityweek.comNov 13, 2025extracted
Cybersecurity jobs available right now: November 11, 2025
Cybersecurity jobs available right now: November 11, 2025 Academy Cyber Threat Intelligence Analyst Bridewell | United Kingdom | Hybrid – No longer accepting applications As an Academy Cyber Threat Intelligence Analyst, you will manage OpenCTI data, triage and escalate attack surface monitoring alerts, and raise internal alerts for critical cases. You will use Feedly to identify relevant threats, produce reports and advisories, and refine AI rules with keyword and entity lists. You will monitor the CTI mailbox, assign and track planner tasks, and support the creation and delivery of CTI products. You will also assist with data analysis, trend reporting, and commentary for MSR and QSR reports. CISO Swyfft | USA | Remote – No longer accepting applications As a CISO, you will lead Swyfft’s cybersecurity program, ensuring NYDFS compliance. You will manage the third-party service provider security governance program, conduct annual risk assessments, and coordinate penetration testing. You will develop and maintain security policies, incident response, and business continuity plans, and prepare board reports and regulatory certifications. Corporate Vice President – Data Protection Engineer New York Life Insurance Company | USA | Hybrid – No longer accepting applications As a Corporate Vice President – Data Protection Engineer, you will you will lead the enterprise data protection strategy and design solutions across DSPM, DLP, DAM, DAG, encryption, and secrets management. You will implement and integrate controls across cloud and on-prem environments, ensuring compliance and business alignment. You will mentor technical teams, resolve complex challenges, and establish standards that balance strong protection with operational efficiency. Get weekly updates on new cybersecurity job openings. Subscribe here! Cybersecurity Expert Deloitte | Israel | Hybrid – No longer accepting applications As a Cybersecurity Expert, you will design and implement network security architectures, including NGFW, SWG, CASB, WAF, IDPS, endpoint protection, and DLP solutions. You will apply SecOps practices with SIEM and SOC methodologies, manage incident response, and coordinate threat mitigation. You will implement zero-trust models such as ZTNA, SASE, and SSE, and architect cloud network security controls across AWS, GCP, Azure, and OCI using native and third-party tools. Cybersecurity Engagement Director (Non-Management) Boeing | Italy | Remote – No longer accepting applications As a Cybersecurity Engagement Director (Non-Management), you will manage daily operations to ensure efficient delivery and client satisfaction. You will identify and mitigate risks, ensure compliance, and implement risk management strategies. You will communicate with leadership, internal teams, and clients to align goals and monitor performance metrics to drive continuous improvement. Cybersecurity Researcher SLING | Israel | On-site – No longer accepting applications As a Cybersecurity Researcher, you will research vulnerabilities, frameworks, and ecosystems to identify and analyze attack vectors and exploitation techniques. You will work with engineering teams to design and implement mitigations, stay current with emerging threats and attack trends, and publish research findings to support knowledge sharing. Cyber Security Engineer Emerson | Germany | On-site – No longer accepting applications As a Cyber Security Engineer, you will analyze security vulnerabilities and assess their impact on products and systems. You will validate security requirements in collaboration with test engineers and maintain cybersecurity infrastructure such as HSM appliances and the vulnerabilities database. You will work with cross-site security teams, including PSIRT, to manage and resolve security incidents. You will provide expert guidance on cybersecurity matters to internal stakeholders and contribute to improving and expanding internal cybersecurity processes. Cyber Security GRC Analyst ReadyTech | Australia | Hybrid – No longer accepting applications As a Cyber Security GRC Analyst, you will manage and improve ReadyTech’s GRC framework aligned with IRAP, SOC 2, and ISO 27001. You will oversee audits, maintain the cyber risk register, and ensure timely remediation. You will also develop and update security policies and procedures to meet compliance standards. Global Security and Compliance Head YAGEO Group | Taiwan | On-site – No longer accepting applications As a Global Security and Compliance Head, you will lead the organization’s global risk management strategy to protect the business while supporting innovation. You will promote a strong security culture across all levels, guide stakeholders with best practices to safeguard intellectual property and ensure compliance, and define and communicate key security metrics aligned with business goals. Head of Information Security Action for Children | United Kingdom | Remote – No longer accepting applications As a Head of Information Security, you will provide strategic leadership to ensure the information security strategy aligns with organisational goals and regulatory requirements. You will lead and manage a team of information security professionals, promoting a culture of security awareness and compliance across the organisation. Your responsibilities include identifying and mitigating threats, managing risks, and applying current technologies to improve departmental effectiveness. You will also oversee penetration testing, vulnerability assessments, incident response, data loss prevention, phishing simulations, and system audits. Information Security Analyst GALLO | USA | Hybrid – No longer accepting applications As an Information Security Analyst, you will investigate incidents, implement corrective actions, and optimize security controls across on-prem and cloud environments. You will lead projects, support operations, and collaborate with stakeholders to ensure resilience and compliance. You will also conduct risk assessments, review test results, and develop security implementation plans. Information Security Officer State Street | Ireland | On-site – No longer accepting applications As an Information Security Officer, you will perform cyber risk assessments at the application, platform, and system levels to identify vulnerabilities and threats. You will design and implement controls to mitigate risks and manage them in line with the organisation’s risk appetite through ongoing engagement with business units. You will collaborate closely with application and platform owners to ensure effective risk management and security alignment. Information Systems Security Officer Docebo | Canada | Hybrid – No longer accepting applications As an Information Systems Security Officer, you will define and maintain the FedRAMP governance model, including roles, responsibilities, and interactions with Sponsors and Authorizing Officials. You will manage and version-control all ATO documentation, including the SSP, SAR, continuous monitoring artifacts, POA&Ms, and related annexes. You will build and operate the continuous monitoring program, defining telemetry, dashboards, vulnerability management, incident reporting, and thresholds. Information Security Specialist Unity Infotech | UAE | On-site – No longer accepting applications As an Information Security Specialist, you will be responsible for overseeing security technologies like Cloud Security, DLP, Kubernetes, API security, SIEM and EDR, and ensuring compliance with standards and policies. Responsibilities include managing incident response, performing risk assessments, and optimizing security tools across cloud and network environments. Information Security Specialist ruya | UAE | On-site – No longer accepting applications As an Information Security Specialist, you will develop, implement, and manage IAM strategies, policies, and solutions such as RBAC, SSO, MFA, and PAM in line with business and regulatory requirements. You will oversee user lifecycle management, including onboarding, access changes, and de-provisioning for employees, contractors, and third parties. You will perform regular access reviews, identity attestations, and segregation of duties analyses to maintain least privilege and compliance. Junior Information Security Analyst Intern SOPHiA GENETICS | France | On-site – No longer accepting applications As a Junior Information Security Analyst Intern, you will esearch and evaluate modern security testing tools and techniques such as Atomic Red Team and AzureHound. You will maintain and integrate SAST and DAST tools into the SDLC. You will review GitLab configurations to strengthen security and code review processes. You will conduct security reviews and analyses of Azure cloud infrastructure and help improve security alerting and monitoring. Manager, Detection Engineering Datadog | France | On-site – No longer accepting applications As a Manager, Detection Engineering, you will lead and develop a team of security practitioners focused on building and improving integrations and detections in Datadog Security products. You will research and test emerging attack and defense techniques in cloud environments and turn those insights into actionable security content. You will guide the design of security integrations across Logs, Cloud SIEM, Cloud Security, and Workflow products. Manager, Issue Remediation Testing BMO | Canada | Hybrid – No longer accepting applications As a Manager, Issue Remediation Testing, you will lead and perform remediation testing to validate the closure of issues across fraud, cybersecurity, and technology domains. You will develop and maintain risk-based test plans aligned with enterprise policies and regulatory standards. You will collect and validate remediation evidence to ensure effective and sustainable issue resolution. Network & Cybersecurity Engineer Oversonic | Italy | Hybrid – No longer accepting applications As a Network & Cybersecurity Engineer, you will manage, configure, and maintain on-premise, edge, and cloud network infrastructure. You will administer and optimize firewalls, load balancers, and VPNs to ensure performance and security. You will monitor network health, troubleshoot connectivity issues, and resolve problems promptly. You will also implement and manage network security policies, procedures, and controls. Security Operations Analyst Monument Re Group | Ireland | On-site – No longer accepting applications As a Security Operations Analyst, you will manage and improve security controls such as SIEM, honeypots, EDR, vulnerability scanners, and email filters. You will monitor, triage, and respond to daily security events and incidents, including phishing attacks. You will work with the external SOC to ensure effective alerting, investigation, and escalation of suspicious activities. Senior Cyber Security Engineer (P3) Raytheon | USA | On-site – No longer accepting applications As a Senior Cyber Security Engineer (P3), you will review and resolve Tenable/Nessus findings, assess system vulnerabilities, and verify hardening and patching compliance with current STIGs, SRGs, and checklists. You will manage POA&M activities, support Assessment and Authorization processes, perform software assurance tasks, and provide cybersecurity engineering support throughout system Senior Cybersecurity Event Triage Analyst Baker Hughes | India | Hybrid – No longer accepting applications As a Senior Cybersecurity Event Triage Analyst, you will monitor and analyze cybersecurity events, identify potential incidents and trends, and support incident response through threat data analysis. You will also use threat intelligence to strengthen the organization’s understanding of emerging threats and improve its security posture. Specialist, Cyber Security Vestas | Germany | On-site – No longer accepting applications As a Specialist, Cyber Security, you will review legal and customer documents to identify and extract technical requirements. You will map cybersecurity requirements to a consistent and trusted architecture and collaborate with value chain representatives to ensure alignment across all lifecycle stages, including production, commissioning, and operations. You will implement security controls to protect OT data and infrastructure, support change management to maintain consistent cybersecurity practices, and assist in managing cybersecurity incidents when required. Third Party Cyber Risk Analyst Protective Life | USA | Remote – No longer accepting applications As a Third Party Cyber Risk Analyst, you will conduct and track third-party risk assessments, collecting and reviewing security documentation from vendors. You will manage vendor onboarding and offboarding, apply a shift-left approach to embed security early in the vendor lifecycle, and monitor third-party security reports, controls, and remediation efforts. You will also prepare and maintain reports on vendor risk and compliance status for management.
helpnetsecurity.comNov 11, 2025extracted
Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site
Cybercriminals have named nearly 30 organizations allegedly impacted by the recent campaign targeting customers of Oracle’s E-Business Suite (EBS) enterprise resource planning solutions. The campaign, which involved extortion emails being sent to executives at dozens of organizations in late September, is believed to have been conducted by a cluster of a profit-driven threat actor tracked as FIN11. The attacks were claimed by the Cl0p (aka Clop) ransomware group. Cl0p was previously linked by the cybersecurity community to FIN11 and the decision to use it as the public-facing entity for the campaign was likely motivated by its prior involvement in similar high-impact campaigns targeting customers of Cleo, MOVEit, and Fortra file transfer products. Twenty-nine alleged victims of the Oracle EBS hack have been listed on the Cl0p leak website to date. The organizations that were the first to be named, such as Harvard University, South Africa’s Wits University, and American Airlines subsidiary Envoy Air, confirmed being impacted shortly after they were named by the attackers in mid-October. Last week, The Washington Post also confirmed it had been successfully targeted in the campaign, but did not share any details, Reuters reported. However, a majority of the other alleged victims have yet to confirm suffering a data breach. SecurityWeek has reached out for comment to several important organizations from the list, but none responded. This includes industrial giants Schneider Electric and Emerson, consumer electronics giant Logitech, communications and automotive giant Cox Enterprises, silver and gold producer Pan American Silver, automotive parts firm LKQ Corporation, and HVAC company Copeland. Other alleged victims include companies in the mining, professional services, wastewater, construction, insurance, financial, manufacturing, transportation, technology, automotive, energy, and HVAC sectors. The organizations impacted by the Oracle EBS hack are likely conducting investigations and some of them likely do not want to share any information until those probes are completed. Others, as past Cl0p attacks have shown, are likely trying to avoid the spotlight by staying silent. The cybercriminals leaked data allegedly stolen from 18 victims, in some cases making public hundreds of gigabytes and even several terabytes of files. SecurityWeek has conducted only a limited structural analysis of some of the leaked files and concluded that they likely originated from an Oracle environment. Given Cl0p’s history, it’s unlikely that organizations have been falsely listed as victims. However, it’s not uncommon for the cybercriminals to deliberately name parent companies as the victim when the actual impact was limited to a smaller subsidiary (as in the case of American Airlines being listed for the Envoy Air hack). It’s also possible that in some cases the hackers have exaggerated the value and sensitivity of the stolen data. It’s still unclear exactly which Oracle EBS vulnerabilities have been exploited in the campaign. The most likely candidates are CVE-2025-61882 and CVE-2025-61884, both of which can be exploited remotely without authentication or user interaction to gain access to sensitive data. In the case of CVE-2025-61882, exploitation as a zero-day appears to have started at least two months prior to patches being released. Related: Sophisticated Malware Deployed in Oracle EBS Zero-Day Attacks Related: State-Sponsored Hackers Stole SonicWall Cloud Backups in Recent Attack
securityweek.comNov 10, 2025extracted
Canada Says Hackers Tampered With ICS at Water Facility, Oil and Gas Firm
The Canadian Centre for Cyber Security has warned CISOs and other decision-makers that hacktivists are increasingly targeting internet-exposed industrial control systems (ICS). The government cybersecurity agency has provided several examples of recent attacks reported to authorities. In one incident, hackers targeted a water facility and tampered with water pressure valves, which resulted in degraded service for the community served by the compromised facility. In another incident, hackers triggered false alarms at a Canadian oil and gas company by tampering with an automated tank gauge (ATG). ATGs are often plagued by severe vulnerabilities and they have been targeted by hackers for at least a decade. The third example shared by the Canadian Centre for Cyber Security describes an attack on a farm, with attackers manipulating temperature and humidity parameters in a grain-drying silo. The agency noted that the hackers’ actions could have resulted in unsafe conditions had they not been caught on time. The cybersecurity agency said hacktivists often target internet-accessible and poorly secured ICS devices in an effort to gain media attention, discredit organizations, and to “undermine Canada’s reputation”. These types of hackers often launch opportunistic attacks rather than targeting specific organizations. There are at least 100,000 internet-exposed ICS devices around the world and they are in many cases easy to hack. While the Canadian Centre for Cyber Security alert describes the threat actors as hacktivists — such hackers have often targeted ICS — it’s worth noting that it’s not uncommon for state-sponsored threat groups to launch attacks under the guise of hacktivism. According to the agency, the types of ICS devices targeted by hackers can include safety systems, building management systems, industrial IoT devices, programmable logic controllers, human-machine interfaces, remote terminal units, and supervisory control and data acquisition systems. The Canadian Centre for Cyber Security’s alert offers some high-level recommendations for securing ICS, and provides links to more detailed resources. The agency has also advised victims of such attacks to report incidents to both the agency and police. Related: Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack Related: Up to 25% of Internet-Exposed ICS Are Honeypots Related: CISA Warns of Exploited DELMIA Factory Software Vulnerabilities
securityweek.comOct 30, 2025extracted
Ad and PR Giant Dentsu Says Hackers Stole Merkle Data
Japan-based Dentsu, one of the world’s largest advertising and PR companies, has disclosed a data breach impacting systems of its subsidiary Merkle. With headquarters in the US and UK, Merkle is a customer experience management company that has more than 16,000 employees and over 80 locations worldwide. According to a statement issued on Tuesday by Dentsu, the breach was discovered after abnormal activity was detected on the Merkle network. Some systems have been shut down in response to the incident. Dentsu has admitted that the hackers have taken certain files from the Merkle network, including ones containing information related to some suppliers, clients, and current and former employees. In a separate statement on its UK website, which is addressed to current and former employees of its UK operations, Dentsu said the compromised files are believed to include sensitive information such as personal contact details, salary, bank and payroll data, and National Insurance number. Impacted individuals are being notified and offered free dark web monitoring services. Dentsu pointed out that its systems in Japan are not affected. Some financial impact is expected, but its full extent will be determined later. It’s unclear whether the company has been targeted in a ransomware attack. No known cybercrime group has taken credit for an attack on Merkle or Dentsu at the time of writing. However, Dentsu noted that it’s not aware of any public disclosure of the stolen files. It also said that it “has taken measures to prevent the public disclosure of the data”, which could be interpreted as the company paying a ransom to prevent data leakage. SecurityWeek has reached out to Dentsu for clarifications and will update this article if the company responds. UPDATE: Dentsu has sent the following statement to SecurityWeek, but it did not provide any clarifications on whether a ransom has been paid. We identified unusual activity on a portion of Merkle’s network. Upon discovery, we immediately took action to respond by initiating our incident response protocols, taking some of our systems offline, out of precaution, and taking other steps to contain the activity. Third-party cyber incident response firms who have helped other companies in similar situations were engaged to assist, and law enforcement has been notified. We have brought systems back online and we are fully operational. The investigation identified that certain files were taken from Merkle’s network. A review of those files determined that they contained information relating to some clients, suppliers, and current and former employees. Although our investigation remains ongoing, we have begun the notification process in accordance with applicable law. Related: Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack Related: Cybercriminals Trade 183 Million Stolen Credentials on Telegram, Dark Forums
securityweek.comOct 29, 2025extracted
Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack
Industrial giants Schneider Electric and Emerson have been named by cybercriminals as victims of the recent campaign targeting Oracle E-Business Suite (EBS) instances. Threat actors, presumably a cluster of the FIN11 profit-driven threat group, have exploited Oracle EBS vulnerabilities to steal data from dozens of organizations, including major companies. The hackers have started naming alleged victims on the leak website set up for the Cl0p ransomware, and in some cases they have started releasing data that allegedly originates from the targeted companies. Two of those alleged victims are Schneider Electric and Emerson, neither of which has responded to SecurityWeek’s repeated requests for comment. The Cl0p leak website contains links to 2.7 TB of archive files storing information allegedly obtained from Emerson and 116 GB of archive files with information allegedly belonging to Schneider Electric. SecurityWeek’s investigation, limited to a structural analysis of the leaked file tree and associated metadata, indicates that in both cases the data likely originates from an Oracle environment. Security researcher Dominic Alvieri has independently confirmed that the leaked data was likely obtained as a result of the recent Oracle EBS hack. SecurityWeek has reached out to several of the companies listed on the Cl0p leak website and none of them has responded, likely due to their ongoing investigations. However, major organizations such as Harvard University, South Africa’s Wits University, and American Airlines subsidiary Envoy Air have publicly confirmed being impacted. The threat group that is behind the recent Oracle EBS hack is also believed to have conducted similar campaigns targeting Cleo, MOVEit, and Fortra file transfer products. Each of those operations targeted many organizations and resulted in massive amounts of data being compromised. While historical evidence suggests the cybercriminals responsible for the Oracle EBS campaign are unlikely to make false claims of compromise, they, and other profit-driven groups, have been observed exaggerating the sensitivity of the exfiltrated data. If confirmed, this would not be the first time Schneider Electric and Emerson have been targeted by cybercriminals. Roughly one year ago, the Medusa ransomware group claimed to have stolen nearly 1 TB of data from Emerson and demanded a $100,000 ransom. Schneider Electric last year confirmed on at least two separate occasions that it had been targeted by cybercriminals. Related: CISA Confirms Exploitation of Latest Oracle EBS Vulnerability Related: Toys ‘R’ Us Canada Customer Information Leaked Online
securityweek.comOct 28, 2025extracted
CISA Confirms Exploitation of Latest Oracle EBS Vulnerability
The cybersecurity agency CISA has confirmed that an Oracle E-Business Suite (EBS) vulnerability patched earlier this month has been exploited in the wild. Dozens of Oracle customers have been targeted in a campaign that involved data theft from their EBS instances. The cybercriminals, presumably a cluster of a threat group named FIN11, stole significant amounts of files and attempted to extort victims. The attackers exploited EBS vulnerabilities to gain access to data, but Oracle and the cybersecurity community have yet to share definitive information on which flaws have been exploited. Oracle initially said known flaws patched in July were involved, and later announced that a zero-day tracked as CVE-2025-61882 was also apparently exploited in the campaign. A few days later, on October 11, the software giant announced fixes for CVE-2025-61884, which can be exploited remotely without authentication and without user interaction to gain access to sensitive data. However, Oracle’s advisory did not and still does not provide any indication that CVE-2025-61884 has been exploited in attacks. Only the timing of the patch suggested that CVE-2025-61884 too has been leveraged by the attackers. However, CISA on Monday added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its exploitation. With the flaw added to CISA’s KEV catalog, federal agencies are required to apply mitigations by November 10. Bleeping Computer reported last week that CVE-2025-61884 corresponds to a PoC exploit leaked by Scattered Lapsus$ Hunter (a partnership between the Scattered Spider and ShinyHunters groups) shortly after the Oracle EBS hacking campaign came to light. It was initially believed that the PoC corresponds to CVE-2025-61882. Regardless of which vulnerabilities have been exploited as n-day or zero-day vulnerabilities, it appears that up-to-date Oracle EBS installations should no longer be susceptible to attacks, based on what Bleeping Computer learned from various security firms. The extortion emails sent to victims have been signed by the Cl0p group, which has gained notoriety over the past years, particularly as a result of similar campaigns targeting Cleo, MOVEit, and Fortra file transfer products through the exploitation of zero-day vulnerabilities. At the time of writing, four alleged victims of the Oracle EBS hack have been listed on the Cl0p ransomware leak website: Harvard University, American Airlines (subsidiary Envoy Air), South Africa’s University of the Witwatersrand, and industrial giant Emerson. Emerson is the only one of them that has yet to confirm being impacted and the company has not responded to SecurityWeek’s request for comment. Related: F5 Hack: Attack Linked to China, BIG-IP Flaws Patched, Governments Issue Alerts Related: Hackers Steal Sensitive Data From Auction House Sotheby’s Related: Organizations Warned of Exploited Adobe AEM Forms Vulnerability
securityweek.comOct 21, 2025extracted
American Airlines Subsidiary Envoy Air Hit by Oracle Hack
American Airlines subsidiary Envoy Air has confirmed being impacted by the recent cybercrime campaign targeting organizations that use Oracle’s E-Business Suite (EBS) enterprise management solution. American Airlines was listed late last week on the Tor-based leak website of the Cl0p ransomware group. The Oracle EBS campaign has been claimed in the name of Cl0p and it has been linked to a cybercrime group known as FIN11. At the time of writing, the cybercriminals have made public the allegedly stolen American Airlines data, which totals more than 26 GB of archive files. While the hackers named American Airlines on their leak website, it appears that in reality they targeted an Oracle EBS instance used by Envoy Air. Texas-based Envoy Air describes itself as the largest regional carrier for American Airlines, with over 800 daily flights to more than 160 destinations under the American Eagle brand. In a statement to the media, Envoy confirmed being impacted by the Oracle EBS campaign, but the company said its investigation has shown that customer or other sensitive data was not compromised. Envoy admitted that “a limited amount of business information and commercial contact details may have been compromised”. Harvard University was the first confirmed victim of the Oracle EBS hack. Other organizations have since been listed on the Cl0p leak website, including South Africa’s University of the Witwatersrand, Johannesburg. The South African university confirmed in a statement posted on its website that it has been targeted, and said it’s working on determining what data was compromised as a result of the attack. The hackers have already made public the files allegedly stolen from the University of the Witwatersrand. The Cl0p site also lists industrial giant Emerson, but no data has been leaked at the time of writing. SecurityWeek has reached out to Emerson for comment. Dozens of victims of the Oracle EBS campaign have received extortion emails from the attackers. The organizations that are now being listed on the Cl0p website are likely those that have refused to pay a ransom. While the Oracle campaign has been linked to Cl0p and FIN11, it’s worth pointing out that Google’s Mandiant tracks several threat clusters under the FIN11 umbrella, and it’s unclear exactly which cluster is behind the attack. It’s also unclear which Oracle EBS vulnerabilities have been exploited in the attack. Oracle initially said known flaws patched in July were involved, and later announced patches for a zero-day (CVE-2025-61882) apparently exploited in the campaign. The software giant has also fixed CVE-2025-61884, another EBS flaw exposing sensitive data, but has not clarified whether it has also been exploited. Related: F5 Hack: Attack Linked to China, BIG-IP Flaws Patched, Governments Issue Alerts Related: Microsoft Revokes Over 200 Certificates to Disrupt Ransomware Campaign Related: Hackers Steal Sensitive Data From Auction House Sotheby’s
securityweek.comOct 20, 2025extracted
VMware Certification: Your Next Career Power Move
By Brad Tompkins, Executive Director, VMUG Every IT pro remembers the first time they built something that just worked. A perfectly tuned lab, clean deployment, the moment everything clicked. VMware certification gives you that feeling again and again. It’s a framework for mastering complex systems, proving your expertise, and building the confidence to design and defend infrastructure that lasts. And, when you combine that power with VMUG Advantage, you get a direct line to hands-on practice, expert mentorship, and real savings on your VMware journey. As VMUG President Brenda Emerson put it, “VMware certifications aren’t about memorizing trivia—they’re about proving capability, clarity, and consistency.” Certified teams don’t guess their way through workloads or network plans; they execute with confidence. Tamecka McKay, a VMUG Board Director, said it even more directly: “When your team is trained and confident in VMware’s platforms, you’re prepared to build secure, trusted infrastructure. Certification creates that confidence and competence.” Across our community, from Brenda to Tamecka, one message keeps coming through: Certification doesn’t just change your skills. It changes your career. The Proof Is in the Progress And survey data backs it up. According to Pearson VUE's 2025 Value of IT Certification Candidate Report, 63% of surveyed professionals received a job promotion or were anticipating one after becoming certified. And 82% reported more confidence in pursuing new job opportunities! Why? Because certified professionals build more secure, scalable, and consistent environments. And when entire teams are certified together, as Brenda shared, “Innovation doesn’t get stalled at the handoff. It builds empowered teams.” That empowerment creates a culture where certified teams move faster, communicate better, and retain talent longer. From Lab to Leadership VMUG Vice President Matt Heldstab described the moment he passed his first certification exam as the moment everything clicked. "[Certification] didn’t just validate what I already knew, it gave me a framework to understand what I didn’t yet know — and the confidence to bridge that gap.” When you feel in the dark in your work, certification is like a mirror to help you peek around the corner. It prepares you to design better, troubleshoot smarter, and lead stronger. As Matt put it, “Certification isn’t just about checking a box. It shapes your mindset. It moves you from short-term fixes to long-term architecture and transforms you from a reactive operator into a proactive strategist.” VMUG Advantage gives you everything you need to earn your VMware certification faster. Join thousands of IT pros who are already learning smarter, building stronger, and saving more with VMUG Advantage. Save 10% with code ADVNOW The Shortcut to “Certified and Confident” So, here’s where I come in. If certification is the key to staying relevant and resilient in this industry, VMUG Advantage is how you get there faster. Think of Advantage as your certification accelerator. It’s a membership built for VMware professionals who want to learn, experiment, and grow without hitting roadblocks and with dedicated certification study tools at your disposal. Here’s what you get: Discounts on official VMware training and exams and VMUG events Personal-use licenses to boost your home lab once you’re certified On-demand labs and learning tools to practice hands-on Access to the global VMUG community for mentorship and collaboration Brenda talked about the importance of “building certification into workforce strategy.” VMUG Advantage gives you the infrastructure to accelerate your career as an individual and the resources to empower your team as a whole. For Individuals: Invest in Yourself If you’re an IT professional looking to build momentum in your career, VMUG Advantage is the easiest way to start. You’ll save on training, practice in real labs, and join a network of peers who’ve been where you are. “VMUG took me from a general attendee to a public speaker traveling around the world.” - Matt Heldstab With VMUG Advantage, as you prepare for a certification exam, you’re also preparing for your next career milestone. For Teams: Build a Culture of Capability For IT leaders, certification isn’t just a personal win; it’s a strategic play. Tamecka McKay reminded us that “security and trust start with capability.” That capability comes from teams that train together, speak the same technical language, and solve problems faster. VMUG Advantage makes that knowledge scalable with group licensing options and volume discounts so you can elevate your whole team without breaking your training budget. Why Now? Our industry is in motion. Hybrid clouds, AI-driven security, and VCF adoption are redefining what “expertise” looks like. VMware certification is your anchor amid change, and VMUG Advantage is the launchpad to get you started. Because at the end of the day, certification gives you credibility, community gives you connection, and VMUG Advantage gives you both. Sponsored and written by VMUG.
bleepingcomputer.comOct 17, 2025extracted
Why Certified VMware Pros Are Driving the Future of IT
By Brenda Emerson, VMUG President IT isn't getting any simpler. For many, the cloud’s gone hybrid, AI’s moved in permanently, and security threats seem to evolve faster than the tech built to stop them. But what’s at the forefront of all of this? People. The IT teams configuring, troubleshooting, deploying, and defending. And the IT staff that take the extra step to get certified are becoming some of the most valuable assets in modern enterprise. The Certification Advantage: It's More Than a LinkedIn Update There was a time when a VMware certification looked nice on a resume. Now? It’s a powerful differentiator for both the individual and the organization that backs them. VMware certifications aren’t about memorizing trivia—they’re about proving capability, clarity, and consistency. Certified professionals don’t guess their way through a workload migration or a network segmentation plan. They execute with purpose. When I’m leading my team through tough calls, I rely on that expertise to help make smart decisions. Hackers and security risks aren’t slowing down, but neither is my team. It’s my job to ensure they have the muscle-memory and expertise to use every part of our VMware ecosystem to solve these threats in real-time. Why Smart Teams Are Getting Certified Together This isn’t just about additional skills for a few team members. More and more tech leaders are going big and certifying entire teams. Why? Because when everyone speaks the same technical language, innovation doesn’t get stalled at the handoff. It builds empowered teams which are critical as you’re navigating complex IT and security issues. Team-wide certification doesn’t just make your environment more resilient; it makes your talent more loyal, more tuned-in and better prepared to handle the threats to their ecosystems. With VMUG Advantage, give your team the tools to get VMware certified and access personal-use licenses to build powerful home labs as they test and expand their expertise in the VMware ecosystem, keeping them engaged and ready for whatever challenges come their way. Certify Your Team Today! Strategic Certification Is the New Standard CIOs and CTOs are increasingly building certification into their workforce strategy as a core component of operational excellence. And that’s where VMUG can come in. VMUG is more than a user group, we’re a global community where folks can learn from one another, connect and go deeper to solve more complex tech problems. Whether you’re upskilling one engineer or elevating an entire ops team, we’re here to help you go further, faster. And the good news? We have a path to getting VMware certified that includes access to home-lab licenses that can be a game-changer for IT professionals and teams. Whether you start your VMUG experience by consuming on-demand security content or you want the best we have to offer out of the gate as a VMUG Advantage member, you’ll find a home with VMUG. Sponsored and written by VMUG.
bleepingcomputer.comAug 21, 2025extracted
Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws
Microsoft on Tuesday rolled out fixes for a massive set of 111 security flaws across its software portfolio, including one flaw that has been disclosed as publicly known at the time of the release. Of the 111 vulnerabilities, 16 are rated Critical, 92 are rated Important, two are rated Moderate, and one is rated Low in severity. Forty-four of the vulnerabilities relate to privilege escalation, followed by remote code execution (35), information disclosure (18), spoofing (8), and denial-of-service (4) defects. This is in addition to 16 vulnerabilities addressed in Microsoft's Chromium-based Edge browser since the release of last month's Patch Tuesday update, including two spoofing bugs affecting Edge for Android. Included among the vulnerabilities is a privilege escalation vulnerability impacting Microsoft Exchange Server hybrid deployments (CVE-2025-53786, CVSS score: 8.0) that Microsoft disclosed last week. The publicly disclosed zero-day is CVE-2025-53779 (CVSS score: 7.2), another privilege escalation flaw in Windows Kerberos that stems from a case of relative path traversal. Akamai researcher Yuval Gordon has been credited with discovering and reporting the bug. It's worth mentioning here that the issue was documented in detail back in May 2025 by the web infrastructure and security company, giving it the codename BadSuccessor. The novel technique essentially allows a threat actor with sufficient privileges to compromise an Active Directory (AD) domain by misusing delegated Managed Service Account (dMSA) objects. "The good news here is that successful exploitation of CVE-2025-53779 requires an attacker to have pre-existing control of two attributes of the hopefully well protected dMSA: msds-groupMSAMembership, which determines which users may use credentials for the managed service account, and msds-ManagedAccountPrecededByLink, which contains a list of users on whose behalf the dMSA can act," Adam Barnett, lead software engineer at Rapid7, told The Hacker News. "However, abuse of CVE-2025-53779 is certainly plausible as the final link of a multi-exploit chain which stretches from no access to total pwnage." Action1's Mike Walters noted that the path traversal flaw can be abused by an attacker to create improper delegation relationships, enabling them to impersonate privileged accounts, escalate to a domain administrator, and potentially gain full control of the Active Directory domain. "An attacker who already has a compromised privileged account can use it to move from limited administrative rights to full domain control," Walters added. "It can also be paired with methods such as Kerberoasting or Silver Ticket attacks to maintain persistence." "With domain administrator privileges, attackers can disable security monitoring, modify Group Policy, and tamper with audit logs to hide their activity. In multi-forest environments or organizations with partner connections, this flaw could even be leveraged to move from one compromised domain to others in a supply chain attack." Satnam Narang, senior staff research engineer at Tenable, said the immediate impact of BadSuccessor is limited, as only 0.7% of Active Directory domains had met the prerequisite at the time of disclosure. "To exploit BadSuccessor, an attacker must have at least one domain controller in a domain running Windows Server 2025 in order to achieve domain compromise," Narang pointed out. Some of the notable Critical-rated vulnerabilities patched by Redmond this month are below - CVE-2025-53767 (CVSS score: 10.0) - Azure OpenAI Elevation of Privilege Vulnerability CVE-2025-53766 (CVSS score: 9.8) - GDI+ Remote Code Execution Vulnerability CVE-2025-50165 (CVSS score: 9.8) - Windows Graphics Component Remote Code Execution Vulnerability CVE-2025-53792 (CVSS score: 9.1) - Azure Portal Elevation of Privilege Vulnerability CVE-2025-53787 (CVSS score: 8.2) - Microsoft 365 Copilot BizChat Information Disclosure Vulnerability CVE-2025-50177 (CVSS score: 8.1) - Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability CVE-2025-50176 (CVSS score: 7.8) - DirectX Graphics Kernel Remote Code Execution Vulnerability Microsoft noted that the three cloud service CVEs impacting Azure OpenAI, Azure Portal, and Microsoft 365 Copilot BizChat have already been remediated, and that they require no customer action. Check Point, which disclosed CVE-2025-53766 alongside CVE-2025-30388, said the vulnerabilities allow attackers to execute arbitrary code on the affected system, leading to a full system compromise. "The attack vector involves interacting with a specially crafted file. When a user opens or processes this file, the vulnerability is triggered, allowing the attacker to take control," the cybersecurity company said. The Israeli firm revealed that it also uncovered a vulnerability in a Rust-based component of the Windows kernel that can result in a system crash that, in turn, triggers a hard reboot. "For organizations with large or remote workforces, the risk is significant: attackers could exploit this flaw to simultaneously crash numerous computers across an enterprise, resulting in widespread disruption and costly downtime," Check Point said. "This discovery highlights that even with advanced security technologies like Rust, continuous vigilance and proactive patching are essential to maintaining system integrity in a complex software environment." Another vulnerability of importance is CVE-2025-50154 (CVSS score: 6.5), an NTLM hash disclosure spoofing vulnerability that's actually a bypass for a similar bug (CVE-2025-24054, CVSS score: 6.5) that was plugged by Microsoft in March 2025. "The original vulnerability demonstrated how specially crafted requests could trigger NTLM authentication and expose sensitive credentials," Cymulate researcher Ruben Enkaoua said. "This new vulnerability [...] allows an attacker to extract NTLM hashes without any user interaction, even on fully patched systems. By exploiting a subtle gap left in the mitigation, an attacker can trigger NTLM authentication requests automatically, enabling offline cracking or relay attacks to gain unauthorized access." Software Patches from Other Vendors In addition to Microsoft, security updates have also been released by other vendors over the past several weeks to rectify several vulnerabilities, including — 7-Zip Adobe Amazon Web Services AMD AMI Apple Arm ASUS Atlassian Autodesk Axis Communications Bosch Broadcom (including VMware) Check Point Cisco CODESYS D-Link Dell Drupal Elastic Emerson F5 Fortinet Fortra Foxit Software FUJIFILM Fujitsu Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Google Wear OS HMS Networks HP HP Enterprise (including Aruba Networking) Huawei IBM Intel Ivanti Juniper Networks Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitel Mitsubishi Electric Moxa Mozilla Firefox, Firefox ESR, and Thunderbird NVIDIA Palo Alto Networks Qualcomm Rockwell Automation Salesforce Samsung SAP Schneider Electric ServiceNow Siemens SolarWinds SonicWall Sophos Splunk Spring Framework Supermicro Synology TP-Link Trend Micro WinRAR Xerox Zimbra Zoom, and Zyxel
thehackernews.comAug 13, 2025extracted
Patchwork Targets Turkish Defense Firms with Spear-Phishing Using Malicious LNK Files
The threat actor known as Patchwork has been attributed to a new spear-phishing campaign targeting Turkish defense contractors with the goal of gathering strategic intelligence. "The campaign employs a five-stage execution chain delivered via malicious LNK files disguised as conference invitations sent to targets interested in learning more about unmanned vehicle systems," Arctic Wolf Labs said in a technical report published this week. The activity, which also singled out an unnamed manufacturer of precision-guided missile systems, appears to be geopolitically motivated as the timing coincides amid deepening defense cooperation between Pakistan and Türkiye, and the recent India-Pakistan military skirmishes. Patchwork, also called APT-C-09, APT-Q-36, Chinastrats, Dropping Elephant, Operation Hangover, Quilted Tiger, and Zinc Emerson, is assessed to be a state-sponsored actor of Indian origin. Known to be active since at least 2009, the hacking group has a track record of striking entities in China, Pakistan, and other countries in South Asia. Exactly a year ago, the Knownsec 404 Team documented Patchwork's targeting entities with ties to Bhutan to deliver the Brute Ratel C4 framework and an updated version of a backdoor called PGoShell. Since the start of 2025, the threat actor has been linked to various campaigns aimed at Chinese universities, with recent attacks using baits related to power grids in the country to deliver a Rust-based loader that, in turn, decrypts and launches a C# trojan called Protego to harvest a wide range of information from compromised Windows systems. Another report published by Chinese cybersecurity firm QiAnXin back in May said it identified infrastructure overlaps between Patchwork and DoNot Team (aka APT-Q-38 or Bellyworm), suggesting potential operational connections between the two threat clusters. The targeting of Türkiye by the hacking group points to an expansion of its targeting footprint, using malicious Windows shortcut (LNK) files distributed via phishing emails as a starting point to kick-off the multi-stage infection process. Specifically, the LNK file is designed to invoke PowerShell commands that are responsible for fetching additional payloads from an external server ("expouav[.]org"), a domain created on June 25, 2025, that hosts a PDF lure mimicking an international conference on unmanned vehicle systems, details of which are hosted on the legitimate waset[.]org website. "The PDF document serves as a visual decoy, designed to distract the user while the rest of the execution chain runs silently in the background," Arctic Wolf said. "This targeting occurs as Türkiye commands 65% of the global UAV export market and develops critical hypersonic missile capabilities, while simultaneously strengthening defense ties with Pakistan during a period of heightened India-Pakistan tensions." Among the downloaded artifacts is a malicious DLL that's launched using DLL side-loading by means of a scheduled task, ultimately leading to the execution of shellcode that carries out extensive reconnaissance of the compromised host, including taking screenshots, and exfiltrating the details back to the server. "This represents a significant evolution of this threat actor's capabilities, transitioning from the x64 DLL variants observed in November 2024, to the current x86 PE executables with enhanced command structures," the company said. "Dropping Elephant demonstrates continued operational investment and development through architectural diversification from x64 DLL to x86 PE formats, and enhanced C2 protocol implementation through impersonation of legitimate websites."
thehackernews.comJul 25, 2025extracted