• Cybersecurity researchers have disclosed details of a now-patched security flaw impacting Ask Gordon, an artificial intelligence (AI) assistant built into Docker Desktop and the Docker Command-Line Interface (CLI), that could be exploited to execute code and exfiltrate sensitive data. The critical vulnerability has been codenamed DockerDash by cybersecurity company Noma Labs. It was addressed by

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Most security teams today are buried under tools. Too many dashboards. Too much noise. Not enough real progress. Every vendor promises “complete coverage” or “AI-powered automation,” but inside most SOCs, teams are still overwhelmed, stretched thin, and unsure which tools are truly pulling their weight. The result? Bloated stacks, missed signals, and mounting pressure to do more with less. This

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Moltbook is a new social platform where AI agents post and interact while humans observe, raising questions about autonomy, security, and agent behavior.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors have been observed exploiting a critical security flaw impacting the Metro Development Server in the popular “@react-native-community/cli” npm package. Cybersecurity company VulnCheck said it first observed exploitation of CVE-2025-11953 (aka Metro4Shell) on December 21, 2025. With a CVSS score of 9.8, the vulnerability allows remote unauthenticated attackers to execute arbitrary

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A new GlassWorm-linked supply chain attack abusing the Open VSX Registry, this time via a suspected compromise of a legitimate publisher’s credentials rather than typosquatted packages. The Open VSX security team assessed the activity as consistent with leaked tokens or other unauthorized access to the publishing pipeline, underscoring how stolen developer credentials can be weaponized […]

    The post GlassWorm Infiltrates VSX Extensions With 22,000+ Downloads to Target Developers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – Feb. 3, 2026

    Read the full story from BreachLock

    Everything you always wanted to know about penetration testing but were afraid to ask can be found in a widely popular blog post from BreachLock, a leading vendor in the Penetration Testing-as-a-Service (PTaaS) market over the past five years, according to Gartner.

    The experts at BreachLock provided Cybercrime Magazine readers with a new blog post that answers a frequently asked question: What is autonomous pentesting, and how does it work?

    Autonomous Penetration Testing is a modern pentesting approach that uses Artificial Intelligence (AI) technologies such as machine learning and natural language processing to autonomously and continuously simulate cyberattacks on enterprise systems with minimal or no human involvement.

    These AI-enabled tools test environments like real attackers would, dynamically planning, executing, pivoting, and moving laterally to uncover weaknesses before a threat actor can exploit them.

    Generative AI-powered autonomous penetration testing systems continuously adapt to changes in enterprise infrastructure and the evolving threat landscape. This enables simulation of complex attack paths aligned with modern attacker tactics, techniques, and procedures (TTPs).

    Read the Full Story



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post What is Autonomous Penetration Testing and How Does it Work? appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sharp rise in campaigns targeting macOS users, while attackers also ramp up Python‑based stealers and abuse trusted platforms like WhatsApp and popular PDF utilities. These attacks focus on harvesting credentials, browser data, cloud keys, and cryptocurrency wallets, then quietly exfiltrating them to attacker‑controlled infrastructure. On macOS, threat actors increasingly rely on social engineering and […]

    The post Infostealer Attacks Hit macOS, Abusing Python and Trusted Platforms appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • French authorities raided the Paris headquarters of Elon Musk’s social media platform X today, escalating a year-old cybercrime probe into alleged algorithmic manipulation and illicit content distribution.

    The operation, led by the Paris prosecutor’s cybercrime unit alongside France’s national cybercrime police and Europol, marks a significant intensification of scrutiny on X’s data practices and moderation failures.

    The search commenced early Tuesday at X’s French offices, focusing on evidence related to suspected abuses. Prosecutors have summoned Musk, X’s chairman, and former CEO Linda Yaccarino, who resigned in July 2025, for voluntary questioning on April 20 in Paris, alongside other employees as witnesses. No arrests were reported, and the probe remains preliminary, with authorities emphasizing compliance with French digital laws.

    Opened on January 5, 2025, following a lawmaker’s complaint, the inquiry initially focused on claims that biased algorithms were distorting automated data processing systems on X.

    It expanded in July 2025 amid reports of X’s AI chatbot Grok disseminating Holocaust denial content and sexually explicit deepfakes infringing image rights. Further allegations include complicity in retaining and distributing child exploitation imagery, potentially punishable by up to 10 years in prison under French law.

    Specific Cybercrime Allegations

    Investigators are probing “fraudulent data extraction” and organized manipulation of X’s recommendation algorithms, which allegedly amplified harmful content.

    The case also examines Grok’s role in generating or promoting illegal materials, highlighting vulnerabilities in AI moderation on social platforms. Europol’s involvement underscores cross-border concerns over platform accountability in cyber-enabled crimes like deepfake proliferation and non-consensual imagery.

    X has not yet commented on the raid but previously dismissed the probe as “politically motivated,” denying algorithm tampering or data breaches.

    In a notable backlash, the Paris prosecutor’s office announced it would cease using X for official communications, pivoting to LinkedIn and Instagram. This move amplifies tensions between regulators and tech giants amid Europe’s push for stricter digital services enforcement.

    The raid signals heightened French enforcement against Big Tech’s cyber risks, from AI-driven misinformation to content moderation lapses.

    Experts warn it could set precedents for international probes into algorithmic bias and deepfake threats, urging platforms to bolster AI safeguards. As hearings loom, X faces potential fines or operational curbs in the EU, underscoring the collision of free speech and cybercrime prevention.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post French Authorities Raid X Office Following Cybercrime Allegations appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The transition away from NTLM (New Technology LAN Manager), a legacy authentication protocol that has existed in Windows for over three decades, is being accelerated.

    The company has announced a phased roadmap to reduce, restrict, and ultimately disable NTLM by default in upcoming Windows releases, marking a significant evolution in Windows authentication security.

    NTLM has long served as a fallback authentication mechanism when Kerberos is unavailable.

    However, the protocol’s age and inherent cryptographic weaknesses make it vulnerable to replay, relay, and pass-the-hash attacks.

    Microsoft’s Three-Phase Transition Plan(source: Microsoft)
    Microsoft’s Three-Phase Transition Plan(source: Microsoft)

    Three-Phase Roadmap for Smooth Transition

    As modern security threats continue to evolve, NTLM’s susceptibility to these attack vectors poses significant risks to enterprise environments.

    Microsoft’s decision to disable NTLM by default reflects the need to adopt stronger, Kerberos-based authentication mechanisms that align with contemporary security standards.

    The transition follows a three-phase approach designed to minimize organizational disruption.

    PhaseTimelineKey FocusDetails
    Phase 1Available nowVisibility & AuditingShows where NTLM is used across systems.
    Phase 2Second half of 2026Reduce NTLM UsageEnables Kerberos in NTLM fallback cases.
    Phase 3Future Windows releaseDisable by DefaultNTLM off by default with legacy support.

    Importantly, Microsoft will provide built-in support for handling legacy NTLM-only scenarios. Minimizing application breakage for organizations with older systems or custom applications.

    Backward Compatibility Maintained During Migration

    The company emphasizes that disabling NTLM by default does not mean complete removal.

    NTLM will remain present in the operating system and can be re-enabled via policy if necessary, ensuring backward compatibility during the transition period.

    This approach balances meaningful security improvements with practical organizational needs.

    Organizations should begin preparing now by deploying enhanced NTLM auditing, mapping application dependencies, and migrating workloads to Kerberos.

    Testing NTLM-disabled configurations in non-production environments. Microsoft encourages enterprises to engage identity, security, and application owners to ensure smooth transitions.

    For organizations facing unique NTLM-dependent scenarios, Microsoft has established ntlm@microsoft[.]com as a point of contact.

    This phased, collaborative approach positions Windows for a more secure, passwordless future while maintaining supported migration pathways for enterprise environments.

    Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

    The post Microsoft to Disable NTLM by Default as a Step Towards More Secure Authentication appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated phishing campaign that uses a multi-stage approach to bypass email filtering and content-scanning systems. The attack exploits trusted platforms, benign file formats, and layered redirection techniques to harvest user credentials from unsuspecting victims successfully. The attack chain begins with a professionally crafted phishing email containing a PDF attachment. The malicious payload leverages legitimate […]

    The post Fake Dropbox Phishing Campaign Targets Users, Steals Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶