• The National Institute of Standards and Technology (NIST) has officially released NIST Special Publication 800-232, establishing the Ascon family of algorithms as the new standard for lightweight cryptography designed specifically for resource-constrained devices. 

    Published in August 2025, this groundbreaking standard addresses critical security gaps in Internet of Things (IoT) devices, embedded systems, and low-power sensors where traditional cryptographic solutions like AES-GCM may prove too resource-intensive.

    Key Takeaways
    1. NIST SP 800-232 standardizes the Ascon family—using 320-bit states and Ascon-p/p permutations.
    2. Ascon-AEAD128 delivers 128-bit security.
    3. Ascon-Hash256, XOF128, and CXOF128 use a 64-bit sponge (Ascon-p) to produce 256-bit or variable-length outputs.

    Ascon Algorithm Family Multi-Layered Protection

    The newly standardized Ascon family comprises four distinct cryptographic primitives, each serving specific security functions. 

    Ascon-AEAD128 serves as the primary authenticated encryption scheme, offering 128-bit security strength in single-key environments with nonce-based operation. 

    The standard also includes Ascon-Hash256, a cryptographic hash function producing 256-bit digests with 128-bit security strength.

    Two eXtendable Output Functions (XOFs) complete the suite: Ascon-XOF128 and Ascon-CXOF128. 

    The latter introduces customization string capabilities, enabling domain separation for applications requiring distinct outputs from identical inputs. 

    All algorithms utilize the same underlying Ascon-p permutations with varying round counts, specifically Ascon-p for initialization/finalization and Ascon-p for data processing phases.

    The Ascon standard implements a Substitution-Permutation Network (SPN) structure operating on a 320-bit internal state divided into five 64-bit words. 

    The permutation function consists of three layers: constant-addition, substitution, and linear diffusion, providing robust cryptographic security while maintaining computational efficiency.

    Key technical specifications include a 128-bit rate and 192-bit capacity for Ascon-AEAD128, while hash functions operate with a 64-bit rate and 256-bit capacity. 

    The standard mandates specific initial values: 0x00001000808c0001 for Ascon-AEAD128, 0x0000080100cc0002 for Ascon-Hash256, and distinct IVs for XOF variants to ensure algorithm separation.

    Enhanced Security Features 

    NIST’s standard incorporates advanced security measures, including nonce-masking implementation options and truncation capabilities for authentication tags. 

    The specification requires a minimum of 32-bit truncated tags, with careful risk analysis mandated for tags shorter than 64 bits. 

    Data processing limits are established at 2⁵⁴ bytes per key to maintain security margins. For enhanced protection, the nonce-masking option maintains full 128-bit security regardless of key count. 

    This comprehensive approach ensures robust protection against forgery attempts while supporting practical deployment constraints in resource-limited environments.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post NIST Publish ‘Lightweight Cryptography’ Standard To Protect IoT Devices appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A novel macOS infostealer malware, designated as Mac.c, has emerged as a formidable contender in the underground malware-as-a-service (MaaS) ecosystem. Developed openly by a threat actor operating under the pseudonym “mentalpositive,” Mac.c represents a streamlined derivative of the notorious Atomic MacOS Stealer (AMOS), optimized for rapid data exfiltration with minimal footprint. This malware leverages native […]

    The post New macOS Installer Boasts Lightning-Fast Data Theft, Marketed on Dark Web appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Shortly after the May 2025 rollout of 107 Copilot Agents in Microsoft 365 tenants, security specialists discovered that the “Data Access” restriction meant to block agent availability is being ignored. 

    Key Takeaways
    1. The “NoUsersCanAccessAgent” policy is bypassed, leaving some Copilot Agents installable.
    2. Manual per-agent PowerShell revocations add overhead and risk.
    3. Mitigate by auditing inventories, enforcing Conditional Access, and monitoring.

    Despite administrators configuring the Copilot Agent Access Policy to disable user access, certain Microsoft-published and third-party agents remain readily installable, potentially exposing sensitive corporate data and workflows to unauthorized use.

    When administrators set:

    Microsoft Copilot Agent Policy Flaw

    The expectation is that all Copilot Agents are hidden from end-user installation across Teams, Outlook, and other Microsoft 365 services. 

    However, testing by cybersecurity researcher Steven Lim shows that agents such as “ExpenseTrackerBot” and “HRQueryAgent” continue to appear in the Copilot panel despite the global policy restriction.

    In many organizations, manual intervention is now required:

    Microsoft Copilot Agent Policy Flaw

    This workaround must be run per-agent and per-tenant, introducing operational overhead and risk of oversight in large deployments. For external publisher agents, similar manual revocation is necessary, further complicating lifecycle management.

    Copilot Policy Flaw

    Copilot Policy Flaw

    Unauthorized access to AI-driven agents can lead to:

    • Data exfiltration via “ExportDataAgent” or “SearchFileAgent” that query SharePoint or OneDrive content beyond intended scope.
    • Execution of custom RPA workflows through agents like “AutoInvoiceProcessor” without formal change control or audit logging.
    • Compliance violations if unapproved AI models process sensitive PII or regulated data.

    Mitigations

    To mitigate these risks, M365 administrators should:

    Run a weekly discovery script to detect any agents bypassing the global policy:

    Microsoft Copilot Agent Policy Flaw

    Integrate Azure AD Conditional Access to require MFA or device compliance for installing any Copilot Agent and feed agent invocation logs.

    Further, report policy enforcement failures via the Service Health Dashboard and track the resolution of identified bugs.

    As AI agents become integral to productivity, it is critical that access policies designed to govern them actually function as intended.

    Administrators must proactively audit, monitor, and enforce controls to prevent inadvertent exposure of enterprise data and preserve compliance.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post Microsoft Copilot Agent Policy Let Any Users Access AI Agents appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The advanced persistent threat (APT) actor known as Transparent Tribe has been observed targeting both Windows and BOSS (Bharat Operating System Solutions) Linux systems with malicious Desktop shortcut files in attacks targeting Indian Government entities. “Initial access is achieved through spear-phishing emails,” CYFIRMA said. “Linux BOSS environments are targeted via weaponized .desktop

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers at the Cofense Phishing Defense Center (PDC) have uncovered a fresh surge in credential harvesting attacks that leverage the reputable cloud-based email service SendGrid to distribute phishing emails. Attackers are exploiting SendGrid’s trusted status, commonly used for transactional and marketing communications, to craft messages that evade standard email security gateways. By spoofing sender […]

    The post Hackers Exploit SendGrid to Steal User Login Credentials in Latest Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • August 25, 2025, marks the 34th anniversary of Linux, a project that began as a modest hobby and has grown into the bedrock of modern digital infrastructure. On this day in 1991, 21-year-old Finnish student Linus Torvalds posted to the comp.os.minix newsgroup: “I’m doing a (free) operating system (just a hobby, won’t be big and […]

    The post Happy Birthday Linux! 34 Years of Open-Source Power appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A cybersecurity researcher has unveiled a sophisticated new method for extracting Windows credentials and secrets that successfully evades detection by most Endpoint Detection and Response (EDR) solutions currently deployed in enterprise environments. The technique, dubbed “Silent Harvest,” leverages obscure Windows APIs to access sensitive registry data without triggering common security alerts. The breakthrough represents a […]

    The post Hackers Steal Windows Secrets and Credentials Undetected by EDR Detection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The National Institute of Standards and Technology (NIST) has formally published Special Publication 800-232, “Ascon-Based Lightweight Cryptography Standards for Constrained Devices,” establishing the first U.S. government benchmark for efficient cryptographic algorithms tailored to resource-constrained environments such as the Internet of Things (IoT), embedded systems, and low-power sensors. In February 2023, NIST selected the Ascon family […]

    The post NIST Releases Lightweight Cryptography Standard for IoT Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • On August 25, 2025, the world celebrates the 34th anniversary of Linux, marking one of the most significant milestones in computing history.

    What began as a humble hobby project by a 21-year-old Finnish student has evolved into the backbone of modern digital infrastructure, powering everything from smartphones and supercomputers to embedded systems and cloud platforms across the globe.

    The journey started on August 25, 1991, when Linux Torvalds posted a simple message to the comp.os.minix newsgroup: “I’m doing a (free) operating system (just a hobby, won’t be big and professional like gnu) for 386(486) AT clones”.

    Little did Torvalds know that his “little project” would become one of the most successful innovations in tech history, fundamentally changing how we think about software development and collaboration.

    Linux’s Remarkable Journey Through the Decades

    From its initial release of version 0.01 with just 10,239 lines of code in September 1991, Linux has grown exponentially. The Linux kernel now contains over 34 million lines of code, with contributions from more than 25,000 developers worldwide.

    This collaborative development model has produced 10,000 lines of new code being added daily, making Linux one of the most actively developed operating systems in existence.

    The early milestones were impressive: by February 1992, the first installable Linux distribution (MCC Interim Linux) was launched, followed by the first commercial distribution in November 1992. By 1994, familiar distributions like Slackware, Debian, S.u.S.E, and Red Hat Linux had emerged, laying the foundation for today’s multi-billion dollar industry.

    Linux has achieved complete dominance in high-performance computing, powering 100% of the world’s top 500 fastest supercomputers as of 2025. This streak began in 2017 and continues to demonstrate Linux’s scalability and performance capabilities in the most demanding computational environments.

    Linux’s impact on cloud infrastructure is staggering, with the operating system powering over 90% of public cloud workloads globally. Major cloud platforms from Amazon, Google, and Microsoft rely heavily on Linux-based systems, making it the invisible force behind the modern internet economy.

    Through Android, Linux has captured approximately 72% of the global smartphone market. With over 1.5 billion Android devices shipped annually, Linux-based systems reach billions of users worldwide, making it arguably the most widely used operating system kernel on the planet.

    Linux commands a significant market share in server environments, with statistics showing it powers 96.3% of the top one million web servers and holds substantial enterprise adoption rates. The enterprise Linux market alone is projected to generate $14.4 billion in revenue by 2025.

    IoT and Embedded Systems

    Linux has found new relevance in the Internet of Things (IoT) era, powering over 68% of connected devices. Its modular design and customizability make it ideal for embedded systems ranging from smart home devices to industrial automation equipment. The embedded Linux market has reached $5.3 billion, reflecting its critical role in modern device development.

    From smartphones that can be repurposed as Linux servers to sophisticated industrial control systems, Linux’s versatility continues to drive innovation across diverse applications.

    While Linux has historically struggled on desktop computers, recent statistics show encouraging growth. Desktop Linux market share has climbed from 2.76% in 2022 to 4.1% globally as of mid-2025, with the United States seeing even stronger adoption at 5.03%.

    Among developers, Linux enjoys much higher adoption rates, with 78.5% of developers worldwide using Linux as either their primary or secondary operating system.

    The Linux operating system market, valued at approximately $10.94 billion in 2024, is projected to reach $41.27 billion by 2034, representing a compound annual growth rate of 14.2%. This growth is driven by increasing cloud adoption, containerization technologies, and the digital transformation initiatives across industries worldwide.

    Linux job postings have increased by 31% over the past year, indicating strong demand for Linux professionals across the technology sector. The system’s reputation for security, with Linux being considered ten times safer than other operating systems, continues to attract enterprises prioritizing data protection.

    Linux’s 34-year journey represents more than technological achievement it embodies the power of collaborative development and open-source innovation. What started as Torvald’s personal project has become a global phenomenon supported by thousands of contributors, hundreds of distributions, and billions of users worldwide.

    As Linux enters its 35th year, its influence continues expanding into emerging technologies, including artificial intelligence, edge computing, and quantum systems.

    The operating system that Torvalds modestly described as “just a hobby” has become the foundation upon which much of our digital world operates, proving that open collaboration and shared innovation can create technologies that benefit humanity on a global scale.

    The celebration of Linux’s 34th birthday is not just about honoring the past it’s about recognizing the continuing evolution of a technology that powers our connected world and shapes our digital future.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post Happy Birthday Linux! Powering Numerous Devices Across the Globe for 34 Years appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Microsoft has disclosed a critical flaw in its Copilot agents’ governance framework that allows any authenticated user to access and interact with AI agents within an organization—bypassing intended policy controls and exposing sensitive operations to unauthorized actors. At the core of the issue is the way Copilot Agent Policies are enforced—or, more accurately, not enforced—when […]

    The post Microsoft Copilot Agent Policy Flaw Lets Any User Access AI Agents appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶