Google Launches Sec-Gemini v1 AI Model for Real Time Cyber Defense
#Cybersecurity #CybersecurityAI #Google #GoogleAI #SecGemini #ThreatIntelligence #AIinSecurity #CyberDefense #Mandiant
Google Launches Sec-Gemini v1 AI Model for Real Time Cyber Defense
#Cybersecurity #CybersecurityAI #Google #GoogleAI #SecGemini #ThreatIntelligence #AIinSecurity #CyberDefense #Mandiant
Meet the Keynote Speakers for OWASP Global AppSec EU 2025 in Barcelona!
Join us May 26-30, 2025, for an incredible lineup of speakers, including two industry leaders shaping the future of cybersecurity.
Dr. Kate Labunets – Assistant Professor, Utrecht University
Sarah-Jane Madden – Director of Cyber Defense, Fortive
Grab your beverage of choice , because there's a LOT to recap from the last 24 hours. Check it out here
https://opalsec.io/daily-news-update-friday-april-4-2025-australia-melbourne/
There's a lot to digest, so if you're running between meetings or scoffing down a quick lunch before the next - here's the TL;DR on the key points:
Urgent Ivanti Patch Alert: A critical RCE zero-day is being actively exploited by suspected China-nexus group UNC5221, who are deploying new malware (TRAILBLAZE, BRUSHFIRE).
Fast Flux is Back in the Spotlight: Five Eyes agencies dropped a joint advisory on the increased use of this evasion technique by sophisticated actors (ransomware gangs, state-sponsored groups). It makes tracking C2s & phishing sites a real headache by rapidly changing IPs/nameservers.
GitHub Supply Chain Attack Deep Dive: Remember that complex attack targeting Coinbase via GitHub Actions? Unit 42 traced its origin back to a single leaked SpotBugs Personal Access Token from late 2024! A huge reminder about token hygiene, the risks of mutable tags, and those cascading dependency threats. Rotate secrets if you use SpotBugs, Reviewdog, or tj-actions!
Oracle's Cloud Breach Saga Continues...: Oracle reportedly admitted a breach to customers, framing it as a "legacy" (pre-2017) environment issue, yet, the actor leaked data allegedly from late 2024/2025. The focus on "Oracle Cloud Classic" vs. OCI feels like damage control over transparency. As I put it in the blog, their handling doesn't exactly inspire confidence – trust is earned, folks.
Rethinking Disaster Recovery in the Ransomware Era: DR is way more than just backups now. With hybrid environments sprawling and ransomware the top threat, recovery is Incident Response (detect, isolate, wipe, reinstall, restore). Homogeneity might simplify recovery, but beware of single points of failure (hello, CrowdStrike outage!).
Mass Scanning Alert: Seeing increased probes against Juniper devices (looking for default 't128' creds - change 'em!) and Palo Alto GlobalProtect portals. Motives are unclear – could be recon, botnet building, or sniffing for vulnerabilities. Keep those edge devices patched and hardened!
New Malware 'Wrecksteel' Hits Ukraine: CERT-UA warns of a new espionage malware targeting state agencies and critical infrastructure via phishing. Deployed by UAC-0219, Wrecksteel exfiltrates documents and takes screenshots.
INC Ransomware Claims State Bar of Texas: The second-largest US bar association confirmed a data breach after INC ransomware listed them on their leak site.
Stay informed, stay vigilant, and let me know your thoughts in the comments! What's catching your eye this week?
OpenAI Backs AI Cybersec-Specialist Adaptive Security to Address AI-Powered Cyber Threats
#AI #AIsecurity #Deepfakes #Cybersecurity #AIcybercrime #AIfraud #CyberDefenses #OpenAI #AdaptiveSecurity #AIthreats #TechFunding #CyberDefense #DeepfakeDetection
#SB Technology (hereinafter referred to as "the Company") announces that #NobuhiroTsuji, a security researcher at the Company, will participate as an expert in the Japan Cybersecurity Initiative by Google Cybersecurity Research Center (hereinafter referred to as "the Initiative"), an effort to raise cybersecurity awareness in Japanese society, which is led by the Google Cybersecurity Research Center.
#CyberDefense #Japan #SoftBank #CyberSecurity
https://www.softbanktech.co.jp/en/news/topics/info/2025/003/
https://www.hhs.gov/sites/default/files/vidar-malware-analyst-note-tlpclear.pdf
#CyberSecurity #MalwareAlert
#VidarStealer #DataProtection #OnlineSafety #CyberThreats #DigitalSecurity #InfoStealer #CyberAwareness #MalwareAnalysis #CyberDefense #HackingTools #CyberCrime #DataBreach #CyberResilience #ThreatIntelligence #CyberProtection #OnlinePrivacy #MalwareDetection #CyberForensics #CyberSec
New VanHelsing Ransomware Expands Across Platforms, Targeting Enterprises with Lucrative Payouts
#Cybersecurity #VanHelsingRansomware #Ransomware #ThreatIntel #CyberThreats #Malware #EnterpriseSecurity #Cybercrime #CyberDefense #Infosec
#Cloudflare announced that it closed all HTTP connections and it is now accepting only secure, HTTPS connections for api.cloudflare.com.
#CyberSecurity
#CyberDefense
#InfoSec https://www.bleepingcomputer.com/news/security/cloudflare-now-blocks-all-unencrypted-traffic-to-its-api-endpoints/
Think Like a Black Hat, Act Like a White Hat!
Let's Face-It ! ->
To Outsmart cybercriminals, you must think like one—but use your skills for defense, not destruction. Learn the mindset of hackers and the strategies ethical hackers use to strengthen cybersecurity.
Read more: https://wardenshield.com/think-like-a-black-hat-and-act-like-a-white-hat
Insomni'hack 2025
We are happy to announce Cymulate as our Silver Sponsor.
Special thanks to the local team: Elizabeth Jeffreys, Martin Tran & Alex Kreutz!
Register here: https://insomnihack.ch/register/?utm_source=Mastodon&utm_medium=Social+Media&utm_campaign=Insomnihack+2025_Sponsor_Cymulate
We got a great question last week from someone on social media:
"How can organizations foster a culture of vigilance in securing their digital assets?
Here's our answer: https://blueridgenetworks.com/the-top-5-actions-organizations-should-take-to-foster-a-culture-of-vigilance-in-securing-their-digital-assets/
Poland Launches Artificial Intelligence Center to Boost Military Power
Poland Launches Artificial Intelligence Center to Boost Military Power
Poland Launches Artificial Intelligence Center to Boost Military Power
Insomni'hack 2025
We are happy to welcome Swiss Expert Group SA to our Service Providers Village.
Big thanks to: Anees Qureshi, Cédric Enzler, Frédérique Hofmann & Caroline Reverchon!
Register here: https://insomnihack.ch/register/?utm_source=Mastodon&utm_medium=Social+Media&utm_campaign=Insomnihack+2025_Sponsor_Swiss+Expert+Group
DeepSeekAI bans are increasing: https://tinyurl.com/DeepSeekBanPA
Regardless of the origin (#AI, #Quantum, etc...), external cyber attacks can and SHOULD be twarted. We can show you how. https://blueridgenetworks.com/cyber-cloak-chronicles/
#CyberCloak #Cybersecurity #CyberDefense #SecureRemoteAccess #NetworkSegmentation
DeepSeekAI bans are increasing: https://tinyurl.com/DeepSeekBanPA
Regardless of the origin (#AI, #Quantum, etc...), external cyber attacks can and SHOULD be twarted. We can show you how. https://blueridgenetworks.com/cyber-cloak-chronicles/
#CyberCloak #Cybersecurity #CyberDefense #SecureRemoteAccess #NetworkSegmentation
Insomni'hack 2025
We are happy to welcome F5 as a Bronze sponsor.
Special thanks to the local team: Valentino Wälter, Roger Gerhard, Guillaume Soubielle, Carine Polaillon, Richard Javet & Patrick Hulliger!
Register here: https://insomnihack.ch/register/?utm_source=Mastodon&utm_medium=Social+Media&utm_campaign=Insomnihack+2025_Sponsor_F5
Enhance Your Data Security with USP!
Seeking a flexible encryption platform that adapts to your specific needs? The Ubiquitous Security Platform offers a solution that evolves with your requirements, ensuring maximum protection for sensitive data. Don’t wait—get started today!
Click to learn more: https://zurl.co/ifB8 #DataProtection #EncryptionServices #CyberDefense