Dutch authorities have dismantled a botnet comprising at least 17 million infected devices, including computers, smartphones, tablets, and IoT devices.
More than 200 servers in the Netherlands supported the operation. Police seized a subset of the infrastructure, and the hosting provider subsequently took the network offline.
Read: https://t.co/76YwhychdN
🚨 Anthropic’s Claude Mythos Preview found 10,000+ severe software flaws in one month.
https://t.co/m9J8tzvbo7
The AI uncovered high- or critical-severity vulnerabilities across widely used software, including 1,726 confirmed flaws and 1,094 rated high or critical severity.
The findings have already led to 97 patches and 88 advisories.
One flaw, CVE-2026-5194 in WolfSSL, could allow certificate forgery.
Happy #WorldQuantumDay! Q-Day is closer than you think, and the window to act is now.
Here's what device OEMs and security leaders need to know: https://t.co/fZRRM1N7mB
Signed firmware on these Android devices would have prevented this.
OEMs of connected devices: you can sign and verify firmware within your CI/CD pipeline in seconds for any chipset with secure boot - no infrastructure required.
14-day free trial: https://t.co/V3c4FucYp1
Krebs (@briankrebs) on Security used OSINT Industries to help track down operators of the Badbox 2.0 botnet: 10 million compromised Android devices.
Phone numbers, emails, corporate entities connected across China.
This is what proper OSINT looks like 💪🏼
Full investigation ⬇️🎯
https://t.co/mZzSk9ruvU
If you are just starting to realize using AI in cybersecurity and offensive security is going to be a pervasive mandatory requirement… it’s ok.
You’re not too behind. You can still master the tool before the tool masters you.
I’ve been teaching these topics for 2 years now as part of “Red Blue Purple AI” and “Attacking AI”
I’ve been through capability changes, all of frameworks, hype, doomers, all of it. I’ve consulted with fortune 100 companies on breaking their AI systems as well as scaling their security teams with AI.
The capabilities that everyone is amazed by has come really only in the last 6 months for most people. No-code agent skills in Claude, cron, program of thought, better models, auto run, research loops, etc.
You have time… but be early. Don’t wait too much longer to change your attitude.
The administration is enlisting private cybersecurity firms for offensive cyber operations as smart devices continue to serve as vulnerable entry points into critical infrastructure.
https://t.co/7MYpvkP0W8
We believe this is the first documented case of a large-scale AI cyberattack executed without substantial human intervention. It has significant implications for cybersecurity in the age of AI agents.
Read more: https://t.co/VxqERnPQRJ
IoT devices are beginning to outnumber IT devices, with organizations using devices from 1629 IoT OEMs on avg, rendering traditional IT security tools obsolete.
OEMs following secure-by-design principles prevent much of this downstream security pain. https://t.co/aSsX20HdoQ
.@PaloAltoNtwks' @Unit42_Intel revealed a new risk: Agent2Agent prompt injection. Malicious #AI agents can now manipulate others into leaking data or taking unauthorized actions through multi-turn A2A sessions. #cybersecurity#CISO#infosec#ITsecurity https://t.co/nlnJjAU9mY
Cybernews: a private encryption key was found in plain text in one of the printer's firmware files, increasing the risk of @Lifeprintphoto's devices being hijacked for use as part of a botnet https://t.co/sfETAcdOuR #iotsecurity
Sometimes the most dangerous breaches are the quiet ones. BRICKSTORM was undetected in appliances for 393 days.
When OEMs skip firmware signing, attackers can live in devices for months or years.
We are releasing details on BRICKSTORM malware activity, a China-based threat hitting US tech to potentially target downstream customers and hunt for data on vulnerabilities in products. This actor is stealthy, and we've provided a tool to hunt for them. https://t.co/kuZ1UUUz6H
The Secret Service dismantled a network of more than 300 SIM servers and 100,000 SIM cards in the New York-area that were capable of crippling telecom systems and carrying out anonymous telephonic attacks, disrupting the threat before world leaders arrived for the UN General Assembly.
📰 Read more about this at https://t.co/m5Q1xQPXqa
A CT town is securing its water treatment plant from cyberattacks. https://t.co/BH0AaWVtIq
Critical infrastructure wasn’t built for today’s threats, but protecting it is essential for public safety.
#CybersecurityNews#otsecurity#PublicSafety#iotsecurity
Honeywell’s 2025 Cyber Threat Report shows a 46% spike in ransomware extortion attacks on OT systems, highlighting the growing cyber risk to critical infrastructure.
@honeywell#OTSecurity#IoTSecurity#IIoTSecurity#CyberSecurity
🔗 https://t.co/Tld4WSOQy5
New and amended cybersecurity exec orders:
By Jan 4, 2027, federal agencies will require vendors to the Federal Government of consumer IoT products, as defined by 47 CFR 8.203(b), to carry US Cyber Trust Mark labeling for those products.
https://t.co/zd1GG78Y62