433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (656) 236-3022

Nobody likes talking about long-term care, but waiting could cost more

“The cost of healthcare services don’t rise like regular inflation. It’s about twice the rate of inflation,” said Thiago Glieger.
http://news.poseidon-us.com/TTghMf

How attackers hosted a fake Claude download page on the claude.ai domain

A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored Bing ad. The ad pointed to the genuine claude.ai domain, but landed on an attacker-published public artifact, which redirected them to a spoofed download site serving SectopRAT. What are Claude Artifacts? Artifacts are a … More → The post How attackers hosted a fake Claude download page on the claude.ai domain appeared first on Help Net Security.
http://news.poseidon-us.com/TTgd4C

Cobalt adds Autonomous Pentest to scale application security testing

Cobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizations to ship software faster than ever, while attackers are using AI to automate reconnaissance and accelerate exploitation. Pentesting performed quarterly or even monthly, can no longer keep pace. As security teams face growing attack surfaces and constrained budgets, organizations need … More → The post Cobalt adds Autonomous Pentest to scale application security testing appeared first on Help Net Security.
http://news.poseidon-us.com/TTgd3b

TAG-195 Upgrades MaaS Ecosystem with Modular Tools

Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
http://news.poseidon-us.com/TTgZGq

Months-long breach exposes South Korean diplomats’ personal data

South Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad. The Korea National Diplomatic Academy launched the online training platform in 2022 to support remote learning during the COVID-19 pandemic. Since then, it has been used to deliver job training and language courses for diplomatic personnel. According to the ministry, the intrusion started in … More → The post Months-long breach exposes South Korean diplomats’ personal data appeared first on Help Net Security.
http://news.poseidon-us.com/TTgV5r

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration,” the company said. The vulnerability is being exploited, they confirmed, and a “handful” … More → The post Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) appeared first on Help Net Security.
http://news.poseidon-us.com/TTgV5l

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or Edge on the victim machine and controls it through Chrome DevTools Protocol, a debugging interface built into both browsers. The browser then carries the command-and-control traffic over a WebRTC channel. Once installed, the RAT process keeps all of … More → The post Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process appeared first on Help Net Security.
http://news.poseidon-us.com/TTgV4y

PyPI hardens package security with new upload restrictions

The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and reduce the amount of “cleanup” work associated with project compromises for PyPI admins. This restriction also means that compromises don’t put releases into an indeterminate and confusing state of both “compromised” and “not compromised”, … More → The post PyPI hardens package security with new upload restrictions appeared first on Help Net Security.
http://news.poseidon-us.com/TTgN2C