Posts

Showing posts from July, 2025

KnowBe4 - Is your Human Risk Management Program Creating Measurable Change? Find Out with Our Free Program Maturity Assessment

Image
In today's threat landscape, your employees represent both your greatest vulnerability and your strongest defense. from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/is-your-human-risk-management-program-creating-measurable-change-find-out-with-our-free-program-maturity-assessment

The Hacker News - Critical Vulnerability in Anthropic's MCP Exposes Developer Machines to Remote Exploits

Cybersecurity researchers have discovered a critical security vulnerability in artificial intelligence (AI) company Anthropic's Model Context Protocol (MCP) Inspector project that could result in remote code execution (RCE) and allow an attacker to gain complete access to the hosts. The vulnerability, tracked as CVE-2025-49596, carries a CVSS score of 9.4 out of a maximum of 10.0. "This is one from The Hacker News https://thehackernews.com/2025/07/critical-vulnerability-in-anthropics.html

The Hacker News - TA829 and UNK_GreenSec Share Tactics and Infrastructure in Ongoing Malware Campaigns

Cybersecurity researchers have flagged the tactical similarities between the threat actors behind the RomCom RAT and a cluster that has been observed delivering a loader dubbed TransferLoader. Enterprise security firm Proofpoint is tracking the activity associated with TransferLoader to a group dubbed UNK_GreenSec and the RomCom RAT actors under the moniker TA829. The latter is also known by the from The Hacker News https://thehackernews.com/2025/07/ta829-and-unkgreensec-share-tactics-and.html

The Hacker News - New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status

A new study of integrated development environments (IDEs) like Microsoft Visual Studio Code, Visual Studio, IntelliJ IDEA, and Cursor has revealed weaknesses in how they handle the extension verification process, ultimately enabling attackers to execute malicious code on developer machines. "We discovered that flawed verification checks in Visual Studio Code allow publishers to add functionality from The Hacker News https://thehackernews.com/2025/07/new-flaw-in-ides-like-visual-studio.html

KnowBe4 - CyberheistNews Vol 15 #26 [My Clicking Time Bomb] What Do I Do About the Repeat Clickers?

Image
from KnowBe4 Security Awareness Training Blog https://blog.knowbe4.com/cyberheistnews-vol-15-26-my-clicking-time-bomb-what-do-i-do-about-the-repeat-clickers

The Hacker News - A New Maturity Model for Browser Security: Closing the Last-Mile Risk

Despite years of investment in Zero Trust, SSE, and endpoint protection, many enterprises are still leaving one critical layer exposed: the browser. It’s where 85% of modern work now happens. It’s also where copy/paste actions, unsanctioned GenAI usage, rogue extensions, and personal devices create a risk surface that most security stacks weren’t designed to handle. For security leaders who know from The Hacker News https://thehackernews.com/2025/07/a-new-maturity-model-for-browser.html

Schneier - Iranian Blackout Affected Misinformation Campaigns

Dozens of accounts on X that promoted Scottish independence went dark during an internet blackout in Iran. Well, that’s one way to identify fake accounts and misinformation campaigns. from Schneier on Security https://www.schneier.com/blog/archives/2025/07/iranian-blackout-affected-misinformation-campaigns.html