Search/veritas
Vendor

veritas

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
aptare
Connections
35 relationships
Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released
Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access into a security incident. To reduce the risk, Luke Hinds and Stephen Parkinson co-founded nolabs and released Nono, an open-source runtime that sandboxes AI agents at the operating system kernel, limiting what they can access and do. Marathon Petroleum’s CISO on OT security automation, supply chain risk In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model helps her team apply controls without stopping production, and where supply chain risk sits when vendors and their vendors hold the keys. Shadow AI incident response begins with logs that may already be gone In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound traffic to AI platforms are often gone before responders arrive, and what regulators look for when they assess whether a company did enough. Your AI agents can reach data no one approved A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the failure back to a non-human account no one had been logging. The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the losses travel down the supply chain in both directions. Refineries, chemical plants and pipeline operators carry this exposure across control systems that run 20 to 40 years. An AI agent can pass every safety check and still leak secrets A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning. Elad Meged, a founding engineer at Novee Security, ran that sequence against three vendors’ own repositories, in the configurations those vendors ship by default. Top companies to visit at Black Hat USA 2026 Black Hat USA 2026 returns to Mandalay Bay with a re-engineered six-day program designed to spark innovation, challenge assumptions, and unite the global security community. From cutting-edge innovators to industry veterans launching new offerings to rising stars shaking up the status quo, these exhibitors are bringing something special to the floor this year. Make time in your schedule to stop by, because your next big opportunity might be waiting. 200 new CVEs a day and no realistic way to patch them all Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. Data breach cost 2026 averaged $4.99 million, AI attacks ran higher More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran without AI. Aviation cyber risk sits on the ground, the blindness sits in the air In this interview with Help Net Security, Eliran Almog, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in a SIEM, and a PX4 Autopilot flaw his team disclosed where drone command channels accept unsigned messages. PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. Hugging Face breach reignites open-weights debate, raises liability questions The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of Cloud Security Alliance’s CISO community, the nonprofit organization laid out the most salient points for security leaders and advised on what they should do next. Cisco FMC static credentials exploited by attackers (CVE-2026-20316) A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The warning comes from Proofpoint, who detected emails carrying the concealed exploit hitting inboxes. What the identity attack surface looks like when trust becomes the target In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022 Uber breach as an example. Impersonation protection: How to protect your executives when the truth isn’t clear How do you protect your executives when truth doesn’t seem to be truth anymore? It’s a question BlackCloak Founder and CEO Dr. Chris Pierson recently discussed with SVP of Product Matt Covington. GitHub delays version updates so malware gets caught first Automated dependency update tools normally open pull requests as soon as a new package version is released, but that speed can backfire. In September 2025, attackers published malicious versions of popular npm packages such as chalk and debug, and although they were removed within about two hours, that was enough time for update bots to propose them to downstream projects. To reduce this risk, GitHub introduced Dependabot cooldown, which delays non-security update pull requests for at least three days by default. Google changes how it names cyber threat actors Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes built up over years. Tech giants form alliance to put open AI in cyber defenders’ hands NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during an internal security evaluation. The new group, called the Open Secure AI Alliance, builds on work already underway at the Linux Foundation’s Akrites initiative and the Open Source Security Foundation (OpenSSF). Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency, before being redirected to a second page requesting their 2FA code. AI took more than junior developer jobs and the bill comes later A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it to Claude and the patch merges before lunch. Coca-Cola confirms hackers stole data in Fairlife ransomware attack Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities. VERITAS project could change the way scientists secure AI The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by establishing AI Assurance as a core function of scientific research infrastructure. Exposed BMCs hand out password hashes before login An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced in 2004. WhatsApp brings end-to-end encrypted voice and video calls to the web WhatsApp has launched support for voice and video calls on the web, allowing users to make and receive calls directly from their browser without installing the desktop app. Stolen Meta and Google ad accounts are worth more than the money they hold Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy complete with tiered pricing, escrow services, and money-back warranties for stolen accounts. Public reporting on this topic tends to focus on drained ad budgets, but according to Mimecast, that’s often a short-lived gain for attackers. Cloudflare reveals what’s behind major internet outages Storms, earthquakes, and infrastructure failures disrupted internet access throughout the second quarter, while governments deliberately shut networks down, according to Cloudflare’s latest Internet Disruption Summary. Tengu botnet reboots Linux devices to survive removal A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. Coordinated cyberattack hits more than 30 Minnesota water utilities A coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat. Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the warning signs employees are trained to spot, according to Check Point. AI takes on a bigger role in finding Chrome vulnerabilities Google has expanded the use of AI in Chrome’s security workflow, using it to find vulnerabilities, triage bug reports, generate patches, and review code to shorten the time between discovering software flaws and delivering security updates. Anthropic’s Claude breached three companies during security tests Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environment by exploiting a previously unknown vulnerability and reached the systems of Hugging Face, the open-source machine learning platform. Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device identity spoofing, AI-generated websites, and residential proxy services to generate advertising revenue without device owners’ knowledge. Claude Opus 5 sharpens coding and cybersecurity work on AWS Claude Opus 5 went live on Amazon Bedrock and Claude Platform on AWS. Anthropic says the model improves on Claude Opus 4.8’s cyber capabilities, coding through cybersecurity. Anyone with an AWS account in a supported region can call it. On higher-risk requests, Opus 5 hands the job back to Opus 4.8, the older model. The user sees a notice when that happens. API customers can configure the fallback. Product showcase: LastPass Authenticator brings Face ID, Apple Watch, and cloud backup to 2FA LastPass Authenticator is a free app that provides two-factor authentication (2FA) for accounts and any service that supports time-based one-time passwords (TOTP). It supports push notifications for one-tap approvals and generates six-digit verification codes for online accounts. The app is available for iPhone, iPad, Apple Watch, and Android devices. AWS gives DevOps teams an AI investigator for firewall incidents AWS DevOps Agent helps administrators inspect logs, review firewall rules and network paths, identify configuration changes that caused AWS Network Firewall to block traffic, and restore connectivity. The service is an AI-powered operations assistant for DevOps and SRE teams that investigates and troubleshoots application and infrastructure issues. ChatGPT joins the most impersonated brands in phishing attacks Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, according to Check Point’s Q2 2026 Brand Phishing Report. AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027 AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode. Android malware detection collapses when the context stage comes out A phone backup app requests storage, contacts, SMS, and call logs. A device management app requests even more. Run either through an Android malware detector, and it may be flagged as malicious. Researchers at Singapore Management University and Nankai University found that six widely used Android malware detectors. Specter: Open-source NFC reader bug sweep for Flipper Zero Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The onboard ST25R3916 carries a hardware external-field detector, the same circuit that lets the device emulate a card and register when a reader starts talking to it. Specter reads that one bit, hundreds of times a second, with its own transmitter dark. Exposed credentials are giving attackers a head start many organizations don’t see Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response capabilities continue to lag. Product showcase: Dashlane Password Manager is more security toolkit than password vault Dashlane is a password manager for individuals and families that stores passwords, passkeys, payment cards, personal information and secure notes in an encrypted vault. It also includes a password generator, password health reports, an authenticator, credential sharing, dark web monitoring and phishing protection. CISA sets a new SBOM baseline The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), replacing the 2021 guidance published by the National Telecommunications and Information Administration (NTIA). AI agents are changing where cybersecurity seed funding lands Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed deal volume in cyber ticked down. Those figures come from the Q2 2026 Insights report published by DataTribe, an early-stage cybersecurity investor. Companies push AI, sysadmins keep it on a short leash In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimistic. Cybercrime goes subscription: AI, malware and infrastructure on demand Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report. Download: The High-Performance Team Playbook Get practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level. ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. Cybersecurity jobs available right now: July 28, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: July 31, 2026 Here’s a look at the most interesting products from the past week, featuring releases from BlackCloak, Contrast Security, Dropzone AI, PortSwigger, Realm Security, Reco, Root Evidence, and ZeroFox.
helpnetsecurity.comAug 2, 2026extracted
VERITAS project could change the way scientists secure AI
VERITAS project could change the way scientists secure AI The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by establishing AI Assurance as a core function of scientific research infrastructure. Led by Anita Nikolich, research scientist and director of research and technology innovation at the University of Illinois School of Information Sciences, the initiative has received a three-year, $896,000 grant from the US National Science Foundation’s Cybersecurity Innovation for Cyberinfrastructure program. The project brings together experts in adversarial AI, research cyberinfrastructure, data science and workforce development to address security risks unique to AI-powered science. “We cannot simply bolt traditional cybersecurity onto AI-driven science,” said Nikolich. “When a poisoned dataset or backdoored model produces an answer that looks plausible but is subtly wrong, no firewall or virus scanner is likely to catch it. The researchers doing our most important scientific work deserve assurance that the AI systems they rely on are documented, tested, and behaving as intended.” Nikolich said VERITAS is built to fold AI Assurance into the research infrastructure scientists already use, so scientists don’t need to become cybersecurity experts and cybersecurity teams don’t need to become machine-learning specialists. Three pieces of the plan VERITAS is structured around three connected efforts. The first is documentation. The project will pilot standardized model cards and dataset datasheets for large scientific computing allocations. These are records that lay out where a model or dataset came from, how it was built or altered, what it’s meant for, and what its limits are, making it possible to trace problems back through a workflow. The second is a new operational role, an AI Assurance Engineer, piloted at the National Center for Supercomputing Applications. That person would review technically novel AI projects before they go live, scan model files for unsafe or malicious behavior, check software for vulnerabilities, and look at how much autonomy agents are given. The third is education. Through the National Data Platform Education Hub, VERITAS will build hands-on challenges that teach students to spot poisoned data, inspect suspect models, evaluate agent permissions, and find weak points in scientific AI pipelines. Bringing red-teaming into the lab AI red-teaming, deliberately probing a system to expose its weaknesses, is common in the tech industry. However, it has rarely been applied to scientific research infrastructure, where compromised AI models or datasets can influence research without obvious warning signs. VERITAS is among the first projects to bring red-teaming into research computing. “AI systems can fail in ways that are difficult to distinguish from legitimate scientific results,” noted Nikolich. “Proactive red teaming allows us to identify those weaknesses before a vulnerable model or agent becomes embedded in a research pipeline. The objective is to help research teams make their systems more trustworthy and resilient.” Beyond the technical work, the project has a workforce component. Students taking part in the challenges will work with scientific models, datasets, and infrastructure through the National Data Platform, and get exposure to responsible disclosure practices along the way. “AI is now part of the scientific workflow. We need to protect its integrity just as seriously as we protect the networks and computing systems around it,” Nikolich concluded. If successful, VERITAS could help establish AI assurance as a standard component of research cyberinfrastructure, providing universities and research institutions with a framework for evaluating the security and trustworthiness of AI systems before they become embedded in critical scientific workflows.
helpnetsecurity.comJul 28, 2026extracted
La rivoluzione OT: la sfida dei sistemi legacy tra sanità, navi e industria
La digitalizzazione accelerata delle infrastrutture fisiche ha trasformato radicalmente il perimetro della sicurezza informatica, spostando l’attenzione verso il mondo della tecnologia operativa, comunemente noto come OT. Durante il recente Security Summit Milano 2026, nel corso della sessione promossa dalla community Women For Security, esperti e dirigenti di settori strategici hanno analizzato come la convergenza tra sistemi informativi e operativi stia ridefinendo i paradigmi della protezione dei dati e della continuità operativa. Il passaggio da reti isolate a ecosistemi iper-connessi ha reso evidente la vulnerabilità dei cosiddetti sistemi legacy, apparecchiature nate decenni fa senza alcuna predisposizione nativa alla sicurezza, che oggi devono essere integrate in framework normativi moderni. Indice degli argomenti La metamorfosi digitale della sanità e l’ingegneria clinica Il settore sanitario rappresenta uno degli ambiti più complessi per l’implementazione della sicurezza OT, a causa della coesistenza di dispositivi medicali avanzati e infrastrutture datate. Rosaria Di Fiore, di ASST Ovest Milanese, evidenzia come la realtà ospedaliera di Legnano, che gestisce 1.350 posti letto distribuiti su quattro presidi , abbia vissuto un’evoluzione digitale importantissima stimolata dal PNRR e dalle lezioni apprese durante l’emergenza COVID. In questo scenario, la sicurezza non riguarda più soltanto i server dell’ufficio IT, ma si estende a tutto il comparto dell’ingegneria clinica. La sfida principale è rappresentata dall’integrazione di oggetti che un tempo erano considerati isolati. Rosaria Di Fiore spiega: «Un tempo la TAC era isolata; oggi il sistema è integrato dall’identificazione del cittadino fino al referto nel Fascicolo Sanitario Elettronico nazionale». Questo significa che ogni dispositivo, dal semplice misuratore di glicemia fino ai grandi macchinari diagnostici e ai dispositivi indossabili come le CPAP, fa ora parte di un sistema applicativo che gestisce dati estremamente sensibili. Per garantire la continuità operativa e la protezione dei pazienti, le strutture sanitarie devono oggi governare questi asset attraverso un’attenta analisi dei rischi e un monitoraggio costante, cercando di sanare il “debito tecnico” accumulato negli anni. Sicurezza in mare: dai radar alla sovranità digitale di Starlink Spostando lo sguardo verso il settore marittimo, le problematiche dell’OT assumono una dimensione mobile e geograficamente distribuita. Bruno Ceradelli, rappresentante di GNV (Grandi Navi Veloci), descrive la nave come un ecosistema complesso che funge simultaneamente da hotel, ristorante e mezzo di trasporto. Sebbene le navi non rientrino strettamente nel perimetro della NIS2, esse sono soggette a una stratificazione normativa che include l’IMO e le raccomandazioni di enti come Rina o Bureau Veritas, creando spesso “attrito interpretativo”. La priorità assoluta a bordo è la safety, ovvero la protezione delle 2.000 persone che possono essere trasportate su una singola unità. Tuttavia, l’interazione tra IT e OT è diventata critica poiché sistemi concepiti 30 o 40 anni fa, originariamente “air-gapped” o isolati, necessitano ora di connessione costante per estrarre dati sui consumi e sulle emissioni di CO2. L’introduzione di tecnologie come Starlink ha abbattuto le latenze delle comunicazioni satellitari, ma ha aperto interrogativi profondi sulla sovranità digitale. Ceradelli sottolinea che, mentre la parte IT è ormai una commodity, la vera criticità risiede nei sistemi radar, nell’ECDIS (cartografia digitale) e negli strumenti basati su PLC che possono essere attaccati accidentalmente da terze parti. La strategia adottata prevede la segregazione rigorosa delle reti e l’attivazione di accessi remoti per la manutenzione solo “on-demand”. L’industria energetica e il fattore tempo: il valore della microsegmentazione Nel comparto industriale ed energetico, il termine OT è sinonimo di protezione delle fabbriche e degli impianti di produzione. Ivan Monti, di Ansaldo Energia, pone l’accento sulla differenza fondamentale tra il mondo IT e quello delle infrastrutture critiche: il tempo di fermo. Se nell’informatica d’ufficio un riavvio di sistema è spesso accettabile, spegnere una turbina o una centrale elettrica può richiedere giorni e avere impatti devastanti sulla rete di distribuzione nazionale. Moltissimi impianti industriali attualmente in funzione sono stati progettati 20 anni fa, in un’epoca in cui la cyber security OT non era una priorità per i board aziendali, focalizzati esclusivamente sul funzionamento costante delle macchine. Per colmare questo divario, Ansaldo Energia ha puntato sulla collaborazione tra esperti di automazione e specialisti cyber certificati secondo lo standard IEC 62443. Una delle soluzioni più efficaci implementate è stata la microsegmentazione fisica della fabbrica. Nonostante i costi elevati e i disservizi iniziali, questa misura garantisce che un errore o un attacco in una sezione del sistema non si propaghi ad altre, impedendo ad esempio che «un carroponte si muova per errore perché un manutentore si è collegato al sistema sbagliato». Grazie anche alla spinta normativa della NIS 2, il budget destinato alla sicurezza operativa in Ansaldo è cresciuto di 20 volte nell’ultimo quinquennio. L’importanza cruciale dell’Asset Inventory e il ruolo dei fornitori Un punto di convergenza tra tutti i settori analizzati è la difficoltà nel censire correttamente i propri asset. Ivan Monti afferma con chiarezza: «La prima cosa da fare è l’asset inventory: non si mette in sicurezza ciò che non si conosce». Si tratta di un’operazione apparentemente banale ma estremamente complessa sul campo, dove spesso le utility non sono a conoscenza dell’esatta natura dei sistemi installati. Anche Bruno Ceradelli conferma che il primo asset inventory OT per GNV risale solo al 2020, evidenziando la necessità di forzare i grandi produttori di componenti industriali ad accettare clausole di sicurezza più stringenti. La gestione della supply chain diventa quindi un pilastro della difesa informatica. Rosaria Di Fiore spiega che in sanità è necessario definire processi rigorosi fin dalla fase di approvvigionamento, analizzando il rischio residuo dei dispositivi medicali che non possono essere scelti direttamente dai dipartimenti IT. Secondo Milena Antonella Rizzi, Capo Servizio Regolazione dell’ACN, questo cambio di mentalità è obbligatorio: «Serve Security by Design fin dalla progettazione». L’Agenzia per la Cybersicurezza Nazionale sta promuovendo un approccio di supporto per aiutare il mondo OT a recuperare un gap tecnologico ventennale rispetto all’IT. Intelligenza Artificiale e monitoraggio: il futuro della difesa fisica L’evoluzione della sicurezza OT guarda con crescente interesse all’Intelligenza Artificiale, pur mantenendo una cautela necessaria quando si tratta di sistemi fisici. Ivan Monti riporta che l’IA è oggi fondamentale per ridurre i falsi positivi nel monitoraggio, evitando allarmi impropri che porterebbero a fermi impianto non necessari e costosi. Un’altra applicazione strategica è l’uso dei Digital Twin, che permettono di testare gli impatti delle misure di sicurezza in un ambiente virtuale prima di implementarle su macchinari reali. Tuttavia, l’automazione totale della risposta agli incidenti (remediation) rimane un tema delicato. Ivan Monti cita l’esempio di importanti vendor internazionali che rifiutano di dare “carta bianca” all’IA senza una supervisione umana, specialmente in contesti dove è in gioco la sicurezza nazionale. In ambito sanitario, il segreto risiede nel monitoraggio continuo, manuale o automatico, per mitigare i rischi derivanti dai sistemi legacy che non possono essere sostituiti nell’immediato. Come evidenziato dai vari interventi, la protezione delle infrastrutture OT non è solo una questione di software, ma di consapevolezza culturale che deve partire dai vertici aziendali. Solo attraverso una collaborazione stretta tra specialisti cyber, ingegneri clinici e tecnici dell’automazione sarà possibile garantire la resilienza dei servizi essenziali per il cittadino.
cybersecurity360.itMay 28, 2026extracted
Electric Motorcycles and Scooters Face Hacking Risks to Security and Rider Safety
Electric motorcycles from Zero Motorcycles and electric scooters from Yadea are affected by vulnerabilities that, if exploited, could have a physical security and safety impact. CISA recently published separate advisories for these vulnerabilities, and SecurityWeek has reached out to the researchers who reported the flaws to find out more about their potential real-world impact. Zero Motorcycles vulnerability Researchers at Bureau Veritas Cybersecurity discovered that electric motorcycles from US-based Zero Motorcycles are affected by a vulnerability that could allow an attacker to connect to a vehicle over Bluetooth. The security hole, tracked as CVE-2026-1354, affects firmware version 44 and earlier. According to CISA, which classified the vulnerability as ‘medium severity’ due to the attack’s high complexity, an attacker could gain unauthorized access to all Bluetooth functions and even upload malicious firmware to the bike. Dinesh Shetty, director of security engineering at Bureau Veritas, told SecurityWeek that while conducting an attack may not be easy, a motivated and well-resourced attacker could pull it off. The expert pointed out that the attacker needs to be physically close to the targeted motorcycle, understand the pairing flow, and remain in proximity until the malicious firmware upload is completed. Shetty explained, “Zero motorcycles have a Bluetooth pairing mode that activates when you hold the Mode button for about five seconds, or if the bike has simply never been paired before. During that window, the key exchange doesn’t actually verify who is connecting. An attacker standing within Bluetooth range could jump in and pair their own device to the bike, and the motorcycle would accept it as a legitimate connection. Once you’re paired, you look like a trusted device, and you can use the firmware update channel to push a modified firmware image to the motorcycle.” Once the attacker uploads malicious firmware, they can perform actions that could pose a serious safety risk. “The motorcycle’s main microcontroller controls safety-critical features which includes the torque output, regenerative braking, the contactors that deliver power to the motor, and battery management. If you can get your own firmware on there, you can mess with any of that. For a real world impact, you can think about what that means on a vehicle doing highway speeds. You could alter how the throttle responds, interfere with braking behavior, or even manipulate battery thermal safeguards. The board also has access to a cellular modem for GPS and telemetry, which in theory could be repurposed for remote command-and-control. We’re not talking about someone changing the color of your dashboard; this is firmware that governs the physical behavior of the vehicle.” The researchers who discovered the Zero motorcycle vulnerabilities, Persephone Karnstein and Mitchell Marasch, recently presented technical details of their findings at Bsides Seattle. CISA said the vendor plans on releasing a firmware patch in May and in the meantime it has advised users to pair their motorcycle to their phone in a safe location where no one else can attempt pairing at the same time. Bureau Veritas Cybersecurity says it regularly conducts in-depth research of various types of products, including open source frameworks, healthcare and financial protocols, password managers, and even proprietary systems like scoreboards. Zero Motorcycles has not responded to SecurityWeek’s request for comment. Yadea T5 scooter vulnerability CISA recently published a separate advisory for another potentially serious vulnerability affecting a powered two-wheeler, the T5 scooter made by Chinese company Yadea. The security hole, tracked as CVE-2025-70994 and rated ‘high severity’, is a weak authentication issue that can allow an attacker to intercept legitimate key fob transmissions. According to an advisory from Ashen Chathuranga, the researcher who found the vulnerability, an attacker in proximity of the targeted scooter can intercept a non-sensitive command — for instance, a lock command — issued by the owner. Using data from the victim’s command, the attacker can “mathematically synthesize” a different command, including unlock and start commands, which enables the attacker to steal the electric scooter. Conducting an attack does not take long. Chathuranga told SecurityWeek that an attacker can instantly issue a new command and conduct a replay attack after capturing a command from the victim. CISA and the researcher say Yadea has yet to release a patch. The vendor has not responded to SecurityWeek’s request for comment. *updated to add that the Zero motorcycle vulnerabilities were discovered by Mitchell Marasch and Persephone Karnstein. Added video of their Bsides Seattle presentation. Related: Free Wi-Fi Leaves Buses Vulnerable to Remote Hacking Related: Researchers Uncover Method to Track Cars via Tire Sensors Related: Serial-to-IP Converter Flaws Expose OT and Healthcare Systems to Hacking
securityweek.comApr 28, 2026extracted
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems
Threat actors are suspected to be exploiting a maximum-severity security flaw impacting Quest KACE Systems Management Appliance (SMA), according to Arctic Wolf. The cybersecurity company said it observed malicious activity starting the week of March 9, 2026, in customer environments that's consistent with the exploitation of CVE-2025-32975 on unpatched SMA systems exposed to the internet. It's currently not known what the end goals of the attack are. CVE-2025-32975 (CVSS score: 10.0) refers to an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. Successful exploitation of the flaw could facilitate the complete takeover of administrative accounts. The issue was patched by Quest in May 2025. In the malicious activity detected by Arctic Wolf, threat actors are believed to have weaponized the vulnerability to seize control of administrative accounts and execute remote commands to drop Base64-encoded payloads from an external server (216.126.225[.]156) via the curl command. The unknown attackers then proceeded to create additional administrative accounts via "runkbot.exe," a background process associated with the SMA Agent that's used to run scripts and manage installations. Also detected were Windows Registry modifications via a PowerShell script for possible persistence or system configuration changes. Other actions undertaken by the threat actors are listed below - Conducting credential harvesting using Mimikatz. Performing discovery and reconnaissance by enumerating logged-in users and administrator accounts, and running "net time" and "net group" commands. Obtaining remote desktop protocol (RDP) access to backup infrastructure (Veeam, Veritas) and domain controllers. To counter the threat, administrators are advised to apply the latest updates and avoid exposing SMA instances to the internet. The issue has been addressed in versions 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), and 14.1.101 (Patch 4).
thehackernews.comMar 23, 2026extracted
Cybersecurity jobs available right now: February 10, 2026
Cybersecurity jobs available right now: February 10, 2026 Cloud Security Engineer KPMG | Israel | On-site – No longer accepting applications As a Cloud Security Engineer, you will establish, secure, and support critical Azure cloud infrastructure, with a strong focus on sensitive and regulated environments. You will design and implement secure cloud architectures using infrastructure-as-code practices, maintain and operate cloud systems and servers, and use tools such as Terraform, Bicep, and ARM templates for automation and standardization. Cloud Security Researcher Pentera | Israel | Hybrid – No longer accepting applications As a Cloud Security Researcher, you will research and develop novel attack techniques targeting cloud infrastructure and analyze vulnerabilities across multi-cloud platforms such as AWS, Azure, and GCP. You will identify and document security flaws in cloud configurations, networking, identity, and Kubernetes environments, perform hands-on testing, and develop proofs of concept, tools, and automation. Cyber Defence Senior Analyst Google | United Kingdom | Remote – No longer accepting applications As a Cyber Defence Senior Analyst, you will conduct real-time security analysis using SIEM, endpoint, and network technologies to identify true security events and reduce false positives. You will advise on Cyber Defence Centre (CDC), CSIRT, and SOC management activities, and leverage threat intelligence, attacker techniques, and remediation strategies to improve SOC detection and response capabilities. Get weekly updates on new cybersecurity job openings. Subscribe here! Cyber Investigation Specialist Group-IB | UAE | On-site – No longer accepting applications As a Cyber Investigation Specialist, you will perform initial incident assessments by analyzing access vectors and defining investigation scope. You will examine network infrastructure, digital assets, and threat indicators, and identify and track threat actors across the clear, deep, and dark web using passive and active intelligence techniques. Cyber Security Operations Analyst UNSW | Australia | Hybrid – No longer accepting applications As a Cyber Security Operations Analyst, you will monitor and analyze security events across controls such as firewalls, EDR, WAF, applications, and systems to identify threats, trends, and risks. You will triage and respond to security incidents and requests, support forensic investigations to understand attack methods and impact, and perform threat hunting to uncover targeted threats and suspicious activity. ICT Security & Networking Specialist MENARINI Group | Italy | On-site – No longer accepting applications As an ICT Security & Networking Specialist, you will configure and upgrade switches, define VLANs and port channels, and apply security controls to protect LAN connectivity while monitoring traffic and performance. You will manage the Wi-Fi environment and PBX infrastructure, and monitor internet data links and SD-WAN connectivity, including coordination with corporate service providers. Information Security Analyst AD Ports Group | UAE | On-site – No longer accepting applications As an Information Security Analyst, you will conduct penetration testing and red-teaming exercises across systems, networks, applications, mobile platforms, and AI/ML environments to identify vulnerabilities and attack paths. You will perform AI model and system testing focused on adversarial attacks, prompt injection, data poisoning, and model inversion, and assess AI pipelines, APIs, and LLM integrations for misuse, data leakage, and unauthorized access risks. Information Security Specialist 1 Commonwealth of Pennsylvania | USA | Hybrid – No longer accepting applications As an Information Security Specialist 1, you will monitor IT security applications and tools to detect anomalies, assess alerts, and differentiate false positives from actual threats. You will investigate alerts to identify root causes, resolve or escalate incidents to the CISO, and ensure compliance with established policy and procedures. Intern, Cyber Security Otis Elevator | India | On-site – No longer accepting applications As an Intern, Cyber Security, you will assist in monitoring security alerts, logs, and incidents, and support vulnerability assessments, patch verification, and basic threat analysis. You will help document security policies, procedures, and incident reports, participate in security tool evaluations such as SIEM, endpoint, and network scanners, and contribute to security awareness and compliance initiatives. Network Security Architect Sonepar | France | Hybrid – No longer accepting applications As Network Security Architect, you will lead secure network architecture and design across datacenter, cloud, and hybrid environments. You will define and enforce foundational security controls, drive Zero Trust and software-defined segmentation, and oversee secure design reviews to ensure networks are consistently implemented, documented, and protected against security threats. OT and IT Manager Egis | Ireland | On-site – No longer accepting applications As an OT and IT Manager, you will lead the convergence of operational and enterprise technologies by defining technology strategy, integration, and digital transformation roadmaps. You will oversee system architecture to ensure interoperability between IT systems and industrial control environments, implement and enforce cybersecurity and risk management practices, and manage IT and OT infrastructure to ensure availability, reliability, and rapid incident response across both domains. Penetration Tester PFH Technology Group | Ireland | Hybrid – No longer accepting applications As a Penetration Tester, you will perform penetration testing of web applications before deployment and during updates to identify vulnerabilities and potential attack paths. You will identify applications at risk of exploitation, including issues that could enable malware infection or data exfiltration, and assess code and system weaknesses to support stronger code reviews, threat analysis, forensic investigations, and incident response. Penetration Tester MSC Mediterranean Shipping Company | Italy | Hybrid – No longer accepting applications As a Penetration Tester, you will plan, execute, and document penetration tests and vulnerability assessments across web applications, network infrastructure, and mobile devices to identify weaknesses and assess impact. You will analyze and classify vulnerabilities by severity, provide clear mitigation recommendations, and produce detailed technical reports outlining methodologies, findings, and remediation guidance. Platform Engineer – Cloud & Security Automation KUBRA | Canada | Hybrid – No longer accepting applications As a Platform Engineer – Cloud & Security Automation, you will build and support Terraform modules, Kubernetes manifests, and GitOps pipelines for the platform and developer portal. You will implement security guardrails and automated controls across cloud environments, contribute to CI/CD workflows, and help strengthen Kubernetes security. Project Cybersecurity Manager 1 Alstom | Canada | On-site – No longer accepting applications As a Project Cybersecurity Manager 1, you will define program security objectives and risk strategies, ensuring compliance with applicable laws and regulations. You will plan and oversee cybersecurity activities across the development lifecycle, managing cost, quality, and delivery, while driving risk analysis, architecture and requirements definition, third-party risk management, assurance levels, and evaluation of overall cybersecurity maturity. Product Security Engineer Databricks | USA | Remote – No longer accepting applications As a Product Security Engineer, you will provide end-to-end SDLC security support, including threat modeling, design and code reviews, and exploit development. You will collaborate on incident and vulnerability response, evaluate SAST and DAST results, and maintain security automation to support compliance requirements such as FedRAMP, PCI, and HIPAA. Security Operations Lead Hume City Council | Australia | Hybrid – No longer accepting applications As a Security Operations Lead, you will ensure continuous monitoring of vulnerabilities and security alerts while managing tools and technologies to detect and respond to threats promptly. You will lead effective incident response and recovery in line with policies and best practices, and oversee independent assessments of security controls to ensure ongoing compliance and identify improvement opportunities. Security Engineer II Subsplash | USA | Remote – No longer accepting applications As a Security Engineer II, you will identify, analyze, and remediate security vulnerabilities across software codebases and cloud infrastructure. You will manage penetration testing and bug bounty programs, and focus on selecting, integrating, and operating tools that automate preventative security measures and reduce manual, reactive work. Senior Cybersecurity Manager Spacelabs Healthcare | United Kingdom | Hybrid – No longer accepting applications As a Senior Cybersecurity Manager, you will lead cross-functional product teams as the cybersecurity product owner, driving all technical cybersecurity initiatives for cloud products. You will ensure the confidentiality, integrity, and availability of Spacelabs cloud solutions, lead cybersecurity and privacy by design and by default, and represent cybersecurity and privacy within product development teams to ensure they are embedded throughout the product lifecycle. Senior Offensive Cybersecurity Specialist Bureau Veritas Cybersecurity | Germany | Remote – No longer accepting applications As a Senior Offensive Cybersecurity Specialist, you will lead and perform technical security assessments in line with agreed methodologies. You will act as the technical lead for assessments, engage with external customers at both technical and management levels to support assessment and certification activities, and report findings while guiding customers on results and next steps. Senior Platform Security Engineer Aignostics | Germany | Hybrid – No longer accepting applications As a Senior Platform Security Engineer, you will secure the cloud foundation across GCP and AWS by designing and implementing security controls for Kubernetes, storage services, VPCs, Cloud Run, and cloud-native workloads, protecting sensitive healthcare data and AI models in alignment with ISO 27001 controls. Senior Security Engineer – Data & Identity Shift Technology | France | Hybrid – No longer accepting applications As a Senior Security Engineer – Data & Identity, you will design and automate identity and access workflows, including JML processes, IAM integrations, RBAC, DLP, and just-in-time access. You will also support security operations through incident response, vulnerability management, cloud security monitoring, security tooling maintenance, and acting as a technical escalation point for complex identity and access issues. Senior Vulnerability Management Engineer Cisco | USA | On-site – No longer accepting applications As a Senior Vulnerability Management Engineer, you will build and enhance vulnerability management capabilities through automation, data analysis, and process improvements. You will analyze vulnerability data to identify trends and root causes, and help develop security standards and baselines. You will perform vulnerability assessments, respond to emerging threats, and triage vulnerabilities to provide company-specific severity guidance. Threat Intelligence Analyst Alignerr | USA | Remote – No longer accepting applications As a Threat Intelligence Analyst, you will analyze and classify threat reports, campaigns, and adversary behavior. You will evaluate indicators, TTPs, and end-to-end attack narratives. You will help generate, structure, and validate threat-intelligence data used to train and assess AI systems, and review AI-generated outputs for accuracy and consistency. Vulnerability Management Manager Changi Airport Group | Singapore | On-site – View job details As a Vulnerability Management Manager, you will lead and scale the enterprise vulnerability management program across multiple technology domains. You will implement CISO-defined strategies to improve visibility, prioritization, and remediation efficiency, establish centralized SecOps oversight for consistent governance and data-driven decisions, and drive automation and intelligent workflows to sustainably scale vulnerability management operations. Vulnerability Management Specialist Droisys | India | Remote – No longer accepting applications As a Vulnerability Management Specialist, you will manage vulnerability detection, tracking, and remediation using tools such as Qualys, CriticalStart, ServiceNow, MDE, and Azure. You will prioritize risks based on severity, exploitability, and business impact, automate remediation, validation, reporting, and SLA tracking, and collaborate with infrastructure, application, and security teams.
helpnetsecurity.comFeb 10, 2026extracted