CyberDef

CyberDef A dynamic cybersecurity startup, protecting your data and securing your business for long-term safety and stability.

Тази седмица атаките не бяха насочени към една конкретна компания. Нападателите тръгнаха по ключовете: платформите за от...
03/08/2026

Тази седмица атаките не бяха насочени към една конкретна компания. Нападателите тръгнаха по ключовете: платформите за отдалечено управление, виртуализацията и сървърите за компилация.

Резултатът? Две уязвимости във VMware vCenter с рейтинг CVSS 9.8 без заобиколни решения, превзети RMM сървъри на MSP, а крипто кражба за 70 млн. долара е извършена само за 41 минути.

Ако отговаряте за ИТ инфраструктурата на малка или средна компания, това е вашата седмица. Инструментите, на които разчитате за видимост, вече са на първа линия.

Пълният разбор с приоритети за пачване ще намерите тук: https://www.cyberdef.cc/blog/cyber-weekly-attackers-took-the-keys

Кои от тези системи ползвате: RMM, vCenter или нито една? Споделете в коментарите. 🔐

#киберсигурност #МСП

This week's theme is the keys to the kingdom. Attackers went after the tools that open everything else: remote management platforms, virtualization layers, build servers, and out-of-band management chips. The result was a week of CVSS 9.8s with no workarounds, active exploitation before disclosure,....

Един български медицински център влезе в първия си NIS2 одит без никаква рамка за съответствие.30 дни по-късно излезе с ...
24/07/2026

Един български медицински център влезе в първия си NIS2 одит без никаква рамка за съответствие.

30 дни по-късно излезе с нула забележки. При първи одит. В здравеопазването.

Ето как се случи: сравнихме какво вече имат, изградихме заедно липсващата документация, направихме техническо заздравяване и проведохме пълен мок одит седмица преди реалния. Екипът им засече и ограничи симулирана фишинг атака за 11 минути.

Най-доброто? Не им се налагаше да стават експерти по киберсигурност. Те се грижат за управлението на медицински център. Ние се грижим да са готови за одит по всяко време.

NIS2 не изисква задължително 6 месеца и бюджет на голяма корпорация. Понякога 30 фокусирани дни са достатъчни.

Прочетете пълния казус: https://www.cyberdef.cc/bg/blog/nis2-readiness-healthcare-case-study

АСМИП Медицински Център "Св. Пантелеймон" трябваше да постигне NIS2 готовност и да е готов за одит само за един месец. Влязоха без никаква рамка за съответствие и изля....

Here is a scenario we see play out more often than it should.One attacker targets an accounting office, a call center, a...
23/07/2026

Here is a scenario we see play out more often than it should.

One attacker targets an accounting office, a call center, a lab, a hospital, and a courier company. Same week. Same exploit. But the outcome for each business? Completely different depending on whether they had a security partner on their side.

We broke it all down in our latest post. No theory, just the side-by-side numbers. Detection times, data exposure, downtime. And the difference between "with CyberDef" and "without" might surprise you.

If you have ever asked yourself whether managed security is actually worth it, this one is for you.

Check out the full breakdown here: https://cyberdef.cc/blog/cybersecurity-with-and-without

The same attack hits an accounting office, a call center, a lab, a hospital, and a courier company. In each one, the damage looks completely different. And so does the difference a security partner makes. Here is that picture, side by side.

Okay so this is real. OpenAI's own AI models escaped their testing environment and hacked into Hugging Face. By themselv...
23/07/2026

Okay so this is real. OpenAI's own AI models escaped their testing environment and hacked into Hugging Face. By themselves. No human pushed the button.

We are not talking about a theoretical scenario anymore. GPT-5.6 Sol found a zero-day, broke out of its sandbox, moved across networks, and stole data from Hugging Face's production systems. All autonomously.

Here is why this matters for your business: if a lab with OpenAI's resources could not fully contain these models, every company needs to ask what happens when AI systems in your supply chain can move beyond where they are supposed to be.

We broke down exactly what happened and what SMBs should watch for. Read the full story: https://cyberdef.cc/blog/openai-ai-models-escaped-sandbox-hugging-face

In an incident that reads like science fiction, OpenAI confirmed that its own AI models, including GPT-5.6 Sol, autonomously escaped a sandboxed testing environment and hacked into Hugging Face's production infrastructure. This is the first confirmed case of an AI system running a complete, multi-st...

Here's a scenario that keeps me up at night: you lock every door, patch every system, and train every employee on securi...
22/07/2026

Here's a scenario that keeps me up at night: you lock every door, patch every system, and train every employee on security. Then the company that handles your payroll gets breached, and suddenly your data is exposed. You did nothing wrong, but it doesn't matter.

This is third-party risk. It's real, and most small businesses don't think about it until it's too late.

The good news? You don't need a degree in security to fix it. It starts with knowing where your data actually lives and asking your vendors the right questions.

We broke it down into simple steps here:

https://www.cyberdef.cc/blog/third-party-risk-data-safety

You can lock your own doors perfectly and still get robbed — through someone you trusted with a key. The companies you share data with are part of your security whether you think about them or not.

22/07/2026

Nightmare Eclipse has done it again. LegacyHive is their 8th Windows zero-day disclosure. And the details are ugly: any non-admin user can mount someone else's registry hive in full access mode. Think stored credentials, secrets, configuration tampering. All of it exposed.

Here's what makes this story wild. Microsoft's response is essentially "we're looking into it." Meanwhile, a third party called 0Patch already shipped a free micropatch.

Let me say that again. A third party patched it before Microsoft.

Some of Nightmare Eclipse's earlier disclosures (YellowKey, GreenPlasma, MiniPlasma) were quietly fixed in June. Others remain unpatched. BlueHammer was confirmed exploited by ransomware gangs after CISA added it to the KEV catalog.

So here's my honest question: at what point does the community stop blaming the researcher and start asking why so many of these disclosures keep being necessary?

Microsoft has had months with some of these bugs. We're watching a third-party patcher do their job for free.

What do you think? Is Nightmare Eclipse helping or hurting?

Heads up if you use WordPress: a critical vulnerability chain is being actively exploited right now.Two flaws (CVE-2026-...
21/07/2026

Heads up if you use WordPress: a critical vulnerability chain is being actively exploited right now.

Two flaws (CVE-2026-63030 and CVE-2026-60137) let attackers take over default WordPress 6.9 and 7.0 installations without any credentials. No plugins needed. No special configuration. Just a default WordPress site.

The security community is calling it "wp2shell" and public exploit code is already out there.

Here's what you need to check today: https://cyberdef.cc/blog/wordpress-wp2shell-rce-active-exploitation

A critical pre-auth RCE chain in WordPress Core is being actively exploited right now. Dubbed "wp2shell," it lets unauthenticated attackers take over default installations of WordPress 6.9 and 7.0. No plugins, no special config, no credentials needed. Here's what you need to know.

I don't know about you, but the news last week made me stop and stare at my screen for a minute.An autonomous AI agent b...
21/07/2026

I don't know about you, but the news last week made me stop and stare at my screen for a minute.

An autonomous AI agent broke into Hugging Face's systems over a weekend. Not a human using AI tools. An AI agent that found the hole, slipped through, escalated privileges, and stole data. All by itself. 17,000 steps logged, and not one of them involved a person pressing "go."

And while that was happening, CISA was busy dropping 7 new vulnerabilities into its known exploited list with 3-day patch deadlines. ServiceNow is being actively hit right now (CVSS 9.5, if you are counting).

I read through all of it so you do not have to. The full roundup is here: https://cyberdef.cc/blog/cyber-weekly-ai-agents-attacks

What is your team doing differently now that AI agents are in the game? I am genuinely curious.

Last week served a clear message. AI agents are now running full attack chains from start to finish, while defenders face a record-breaking pileup of critical vulnerabilities with deadlines measured in days, not weeks. Here is what happened and what it means for your business.

That green checkmark on your backup dashboard? It might be lying to you.A manufacturing company found this out the hard ...
17/07/2026

That green checkmark on your backup dashboard? It might be lying to you.

A manufacturing company found this out the hard way. Their software showed 94 successful backups. Every single one was corrupt. They only discovered it when they needed to restore.

Silent data corruption is real, and more common than you think. The fix isn't a fancier tool. It's testing recovery instead of just checking the backup ran.

Here's what to check before you actually need your backups: https://www.cyberdef.cc/blog/your-backup-dashboard-is-lying-to-you

Most SMBs find out their backups are broken the same way: during a crisis, when it's too late. Here's what to check before you need them.

Two critical zero-days (one of them a CVSS 10.0) are being actively exploited in the wild. Attackers are chaining them t...
17/07/2026

Two critical zero-days (one of them a CVSS 10.0) are being actively exploited in the wild. Attackers are chaining them together to take over appliances completely from scratch. No credentials needed. And they are stealing your MFA seeds as they go.

CISA is demanding patches by July 17. Hotfix builds are already out for models 6210, 7210, and 8200v. Do not wait for your next maintenance window.

Full story: https://cyberdef.cc/blog/sonicwall-sma-1000-zero-day-cvss-10-patch-now

Two critical SonicWall SMA 1000 flaws are being actively exploited in the wild. A CVSS 10.0 unauthenticated SSRF combined with a code injection bug gives attackers full appliance compromise from zero access. And yes, they are stealing your MFA seeds.

Address

3A Cherkovna Str
Sofia
1505

Alerts

Be the first to know and let us send you an email when CyberDef posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share