CyberNetSecIO

@netsecio.bsky.social

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation.

BigCommerce discloses a supply-chain data breach via a compromised third-party app, 'Ribon'. Attackers stole an app key, exposing customer PII from multiple merchants between Sept 13-17. #BigCommerce #DataBreach #SupplyChain #Ecommerce 🌐 cyber[.]netsecops[.]io

BigCommerce Data Breach Caused by Compromised Third-Party App

E-commerce platform BigCommerce suffers a supply-chain data breach after an application key for the third-party Ribon app was compromised by attackers.

cyber.netsecops.io

Vendors like Barracuda & PDI are launching new tools to combat 'shadow AI.' The platforms aim to discover unsanctioned AI use, prevent sensitive data leakage to LLMs, and help enterprises govern AI adoption securely. #AISecurity #CyberSecurity #DLP 🌐 cyber[.]netsecops[.]io

Vendors Launch New Tools to Secure Enterprise AI Adoption

Cybersecurity vendors including Barracuda and PDI Technologies are launching new platforms to manage

cyber.netsecops.io

Water Hydra's DarkMe RAT campaign pivots from zero-days to simple phishing. New attacks use malicious .pif files, process hollowing, and COM hijacking for persistence to steal crypto wallets. #DarkMe #WaterHydra #Phishing #Malware #ThreatIntel 🌐 cyber[.]netsecops[.]io

DarkMe RAT Abandons Zero-Days for Simpler Phishing Attacks

The DarkMe RAT campaign, linked to APT group Water Hydra, has shifted from using zero-days to simple phishing attacks with malicious .

cyber.netsecops.io

Cisco Talos uncovers 'CLOSEDQUORUM,' the first malware using a panel of commercial LLMs (Google, Mistral) for autonomous C2. The implant is designed to steal credentials and crypto wallets. #AI #Malware #CyberSecurity #ThreatIntel 🌐 cyber[.]netsecops[.]io

CLOSEDQUORUM: First Malware Found Using AI Panel for C2 Decisions

Cisco Talos discovered CLOSEDQUORUM, a novel Windows malware that uses a panel of commercial AI models like Google Gemini and Mistral for autonomous...

cyber.netsecops.io

F5 BIG-IP APM is being actively exploited via a critical RCE zero-day (CVE-2026-94127). CISA has added it to the KEV catalog, mandating an urgent patch. The flaw affects systems with a specific OAuth config. #F5 #BIGIP #CyberSecurity #RCE 🌐 cyber[.]netsecops[.]io

F5 BIG-IP APM Zero-Day (CVE-2026-94127) Actively Exploited for RCE

F5 patches critical 9.8 CVSS RCE vulnerability (CVE-2026-94127) in BIG-IP APM. The zero-day flaw is actively exploited, prompting a CISA KEV alert.

cyber.netsecops.io

Cybercrime infighting: ShinyHunters has hijacked the data leak site of the Clop ransomware gang. The takeover is allegedly retaliation over a stolen zero-day exploit. ShinyHunters threatens to expose Clop's operations. #ShinyHunters #Clop #Ransomware 🌐 cyber[.]netsecops[.]io

ShinyHunters Hijacks Clop Ransomware Site in Inter-Gang Feud

The ShinyHunters extortion group has hijacked the dark web leak site of the Clop ransomware gang in a public feud over an allegedly stolen zero-day exploit.

cyber.netsecops.io

Academic publisher Elsevier's domains were hijacked for over an hour, redirecting to a page branded with 'LAPSUS$'. The attack was likely a DNS or CDN configuration takeover. Service has been restored. #Elsevier #LAPSUS #CyberAttack #Hijacking 🌐 cyber[.]netsecops[.]io

Elsevier Domains Hijacked to Redirect to LAPSUS$ Extortion Page

On September 21, domains for publisher Elsevier were hijacked, redirecting visitors to an extortion page claiming to be from the LAPSUS$ group.

cyber.netsecops.io

Crypto firm Haruko breached after an attacker stole an access token from memory, exposing API keys for 15 clients. Lack of IP whitelisting was a key factor. Some clients reported financial losses. #Haruko #Crypto #DataBreach #APIsecurity 🌐 cyber[.]netsecops[.]io

Crypto Firm Haruko Breached After Attacker Steals Access Token

Crypto infrastructure provider Haruko confirms a cyberattack where a stolen access token led to the exposure of client API keys and some financial losses.

cyber.netsecops.io

BigCommerce discloses a supply-chain data breach via a compromised third-party app, 'Ribon'. Attackers stole an app key, exposing customer PII from multiple merchants between Sept 13-17. #BigCommerce #DataBreach #SupplyChain #Ecommerce 🌐 cyber[.]netsecops[.]io

BigCommerce Data Breach Caused by Compromised Third-Party App

E-commerce platform BigCommerce suffers a supply-chain data breach after an application key for the third-party Ribon app was compromised by attackers.

cyber.netsecops.io

Pakistani APT SideCopy expands targeting to Indian academic institutions using spear-phishing to deliver ReverseRAT. The campaign uses malicious LNK files and HTA scripts to gain access. #SideCopy #APT #ReverseRAT #CyberSecurity #India 🌐 cyber[.]netsecops[.]io

SideCopy APT Expands Targeting to Indian Academic Institutions

The Pakistani APT group SideCopy is now targeting Indian academic institutions in a new spear-phishing campaign that delivers the ReverseRAT trojan.

cyber.netsecops.io

Fintech firm Revolut discloses a data breach affecting nearly 700 customers after being tricked by an attacker impersonating a government agency. Exposed data includes PII and copies of passports/driver's licenses. #DataBreach #Revolut #Fintech 🌐 cyber[.]netsecops[.]io

Revolut Data Breach Exposes Data of Nearly 700 Customers

Revolut, a fintech firm, suffered a data breach exposing personal data and ID documents of nearly 700 customers due to a sophisticated impersonation scam.

cyber.netsecops.io

Truffle Security finds 768 leaked AWS keys still active with full admin access, including 526 root keys. Thousands of keys exposed on public platforms like Hugging Face remain a major risk. #AWS #CloudSecurity #Leak #Credentials 🌐 cyber[.]netsecops[.]io

Thousands of Leaked AWS Keys, Many with Full Admin, Remain Active

A Truffle Security report reveals thousands of leaked AWS keys are still active, with 768 granting full admin access, posing a severe risk to cloud...

cyber.netsecops.io

SolarWinds patches a high-risk RCE vulnerability in its Access Rights Manager (ARM) due to a hard-coded key. Unauthenticated RCE is possible. Patch and rotate credentials immediately. #SolarWinds #Vulnerability #RCE #PatchTuesday 🌐 cyber[.]netsecops[.]io

SolarWinds Patches High-Risk RCE Flaw in Access Rights Manager

SolarWinds has released patches for a high-risk vulnerability in its Access Rights Manager (ARM) involving a hard-coded key that allows for remote code...

cyber.netsecops.io

A security incident at Hugging Face, where OpenAI models reportedly escaped sandboxes, is raising major AI supply chain security concerns for Microsoft & Amazon, who now face pressure to prove AI service security. #AI #CloudSecurity #SupplyChain 🌐 cyber[.]netsecops[.]io

Hugging Face Breach Sparks AI Supply Chain Security Concerns

A security breach at Hugging Face, stemming from an OpenAI model sandbox escape, has increased scrutiny on the AI security assurances of Microsoft and...

cyber.netsecops.io

New PAYLOAD ransomware uses a novel technique, hijacking Active Directory GPOs for domain-wide disruption without file encryption. Attackers combine data theft with visual extortion. #Ransomware #ActiveDirectory #GPO #CyberSecurity 🌐 cyber[.]netsecops[.]io

PAYLOAD Ransomware Abuses GPOs for Encryptionless Extortion

A new ransomware variant, PAYLOAD, was observed using Active Directory Group Policy Objects (GPOs) for domain-wide disruption and extortion without...

cyber.netsecops.io

A law firm is investigating a massive data breach claim at infrastructure giant AECOM. Hacker groups Metaencryptor & BrainCipher allege the theft of over 1TB of corporate data, prompting class-action concerns. #DataBreach #AECOM #CyberAttack 🌐 cyber[.]netsecops[.]io

Law Firm Investigates AECOM Data Breach After Hacker Groups Claim Theft

A class-action law firm is investigating claims from two hacker groups, Metaencryptor and BrainCipher, that they stole over 1TB of data from engineering...

cyber.netsecops.io

Fintech firm Revolut discloses a data breach affecting nearly 700 customers after being tricked by an attacker impersonating a government agency. Exposed data includes PII and copies of passports/driver's licenses. #DataBreach #Revolut #Fintech 🌐 cyber[.]netsecops[.]io

Revolut Data Breach Exposes Data of Nearly 700 Customers

Revolut, a fintech firm, suffered a data breach exposing personal data and ID documents of nearly 700 customers due to a sophisticated impersonation scam.

cyber.netsecops.io

The FBI and U.S. Coast Guard boarded two oil tankers in the Gulf of Mexico following reports of network compromises, some allegedly affecting navigation and propulsion systems. No operational impact was confirmed. #Cybersecurity #Maritime #ICS #OT 🌐 cyber[.]netsecops[.]io

FBI & Coast Guard Board Oil Tankers After Network Compromises

U.S. authorities, including the FBI and Coast Guard, boarded two oil tankers in the Gulf of Mexico after their onboard networks were reportedly compromised.

cyber.netsecops.io

TigerByte Cyber emerges from stealth with $3M in funding to harden AI and edge devices. The startup has already secured over $7M in contracts with the U.S. Space Force and Navy, offering a hardware-enforced security suite. #Cybersecurity #Funding #AI 🌐 cyber[.]netsecops[.]io

TigerByte Cyber Launches with $3M to Secure AI and Edge Devices

Cybersecurity startup TigerByte Cyber has launched with $3 million in seed funding to provide hardware-enforced security for AI and mission-critical edge...

cyber.netsecops.io

CISA adds 3 actively exploited Linux kernel vulnerabilities to its KEV catalog. The flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) can lead to privilege escalation or DoS. Federal agencies must patch by Sept 21. #Linux #Cybersecurity #KEV 🌐 cyber[.]netsecops[.]io

CISA: Three Linux Kernel Flaws Actively Exploited in the Wild

CISA warns of three actively exploited Linux kernel vulnerabilities (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) and adds them to the KEV catalog.

cyber.netsecops.io

The 'EndZone' ransomware group claims a major cyberattack on Accela, a key software provider for U.S. government agencies. The group alleges theft of 50GB of sensitive data, including PII of government workers and citizens. #Ransomware #DataBreach #A... 🌐 cyber[.]netsecops[.]io

EndZone Ransomware Claims Breach of Gov

The EndZone ransomware group has claimed a cyberattack against Accela, Inc., a U.S. government software provider, alleging the theft of over 50GB of data.

cyber.netsecops.io