< ciso
brief />
Tag Banner

All news with #endpoint security tag

84 articles

ToxicPanda 2.0 Expands Targeting of Financial Apps

🔒 Security researchers at zLabs discovered ToxicPanda 2.0, an Android banking Trojan that now targets 140 banking and cryptocurrency apps and uses overlay-based credential theft against 349 financial institutions. The variant abuses the Android Accessibility Service to enable wireless debugging and attempts to obtain shell access via ADB, bypassing runtime prompts and enforcing persistence. New capabilities include stealing device lock credentials through screen overlays. Recommended defenses include blocking sideloading, treating accessibility grants as privileged events, and alerting on developer options or wireless debugging via MDM.
read more →

Five rules to reduce IP camera surveillance risks

🔒 This article explains where the threat to IP cameras comes from and outlines five practical rules to reduce the risk of becoming a target. It describes real-world incidents — mass hacks, livestreamed footage sales, and stalker cases — and highlights common failures such as unchanged factory passwords, insecure cloud implementations, and lack of firmware updates. The guidance covers device selection, local storage, network segmentation, and good security hygiene to lower exposure.
read more →

Microsoft removes WMIC from Windows 11 beta builds

🛡️ Microsoft has removed the legacy Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2, 25H2 and recent beta builds as part of its planned deprecation. The company previously converted WMIC to a Feature on Demand and announced its eventual removal; WMI itself remains available. IT administrators are advised to migrate scripts to PowerShell, WMI COM APIs, .NET libraries or other modern tools. The change aims to reduce abuse of WMIC as a LOLBIN used by attackers for ransomware, evasion, and other malicious activities.
read more →

Airlock Digital unveils agentic AI control

🔒 Airlock Digital announced Agentic AI Control & Governance at Black Hat USA 2026, extending its preventative endpoint security to provide command- and session-level visibility into trusted AI agent behavior. The offering adds centralized policy management for trusted applications and AI agents, real-time evaluation of agent commands against policy, and dashboard-based monitoring of sessions, files, tokens, and risk. Customer general availability is expected in Q3 2026.
read more →

Ensure security during platform migrations with XDR

🔒 Modern platform migrations must involve security teams from the start. A contemporary XDR/EDR deployment is a multi-component ecosystem—storage, detection, investigation, and response—that places distinct demands on hardware and software. Vendors should specify supported components, versions, and licensing caveats rather than offer a single “yes.” Kaspersky NEXT XDR/EDR Expert now lists support for Nutanix 7.3, enabling integrated security during migration.
read more →

NCSC urges manufacturers to enable forensic observability

🔒 The UK’s National Cyber Security Centre (NCSC) has urged device manufacturers to make forensic evidence collection easier after compromises. Chris A, NCSC technical director, warned that firewalls, VPN gateways and other network devices are increasingly targeted, and stressed that built-in telemetry, logging, memory and data-at-rest collection, and software transparency are crucial. He dispelled myths that observability aids attackers or is too difficult, and called on vendors and buyers to prioritize these capabilities.
read more →

Ransomware Q2 2026: EDR-Kill Becomes Standard

🔍 Halcyon’s Q2 2026 Ransomware Evolution Report warns that shutting down endpoint detection and response (EDR) tools—known as EDR-kill—has become routine among leading ransomware groups, reducing defenders’ time to react. The Gentlemen, a prolific emerging group, incorporates reversed techniques from other gangs and explicitly includes EDR/antivirus shutdowns in attack chains. The report also notes a decline in claimed attacks but a marked rise in sophistication, faster operations, AI-assisted tactics, and the use of ransomware for state-aligned objectives.
read more →

CrashStealer macOS info stealer uses signed dropper

🛡️ Jamf Threat Labs discovered a new native C++ macOS information stealer named CrashStealer that harvests credentials, browser data, cryptocurrency wallet extensions, password manager entries, and keychain material. The campaign uses a signed and Apple-notarized disk image dropper served from a gated site and persists via LaunchAgent after re-signing itself. Collected files are AES-GCM encrypted before exfiltration to an attacker-controlled server, and the malware employs multiple analysis-resistance techniques.
read more →

AI coding agents trigger endpoint behavioral detections

🛡️ Sophos analyzed a week of June 2026 telemetry and found AI coding agents like Claude Code, Cursor, and OpenAI Codex frequently trigger behavioral detection rules designed to catch human attackers. The agents perform actions—decrypting browser credentials, enumerating Windows Credential Manager, downloading files via LOLBins, and writing startup scripts—that look like malicious behavior to endpoint engines. While often benign developer automation, these behaviors overlap precisely with attacker techniques and can generate false positives. Sophos recommends scoping rules to agent parents, workspaces, and download reputations while keeping credential access tightly controlled.
read more →

Turner Industries’ secure cloud-first infrastructure

🔒 Turner Industries migrated to ChromeOS, Google Workspace, Chrome Enterprise Premium, and Cameyo to reduce costs and improve security. The shift extended device lifecycles, cut per-device costs by 40–50%, and saved an estimated $700,000 on new hardware plus $600,000 by converting existing devices with ChromeOS Flex. Faster deployments and simplified management freed IT to focus on strategic work while maintaining strong endpoint protection and legacy app access.
read more →

Microsoft named Leader in Forrester Wave 2026

🔒 Microsoft is recognized as a Leader in The Forrester Wave™: Endpoint Management Platforms, Q2 2026, reflecting Intune’s role in connecting identity, security, compliance, and AI governance across endpoints. The report highlights Intune’s cross-platform management, AI-powered Endpoint Privilege Management, and integrated Security Copilot features that enable faster remediation and device onboarding. Forrester also cited Microsoft’s partner strategy and licensing value as factors supporting enterprise adoption.
read more →

macOS XPC Flaw Lets Non‑Root Users Disable EDR/MDM

🔒 A disclosed macOS privilege escalation allows a non-root user to abuse XPC trusted caller caching to invoke privileged helper functions without authentication, impacting multiple EDR and MDM products. XM Cyber found attackers can tamper with a legitimate app to inherit its cached trust and call sensitive methods to unload or disable security agents with minimal forensic traces. Vendors including CrowdStrike and Kandji have issued fixes and mitigations, while XM Cyber released a scanner and will present findings at Black Hat.
read more →

New macOS Biome App.MenuItem Artifact Discovered

🔎 This report details the discovery of a new macOS Tahoe 26 Biome stream, App.MenuItem, which records specific menu selections made by users across the OS. It explains the artifact's location at ~/Library/Biome/streams/restricted/App.MenuItem/local, the SEGB-encapsulated protobuf format, and recommended processing steps using ccl-segb. The article highlights how the stream reconstructs user intent and workflow, and notes limitations when menu text is non-descriptive.
read more →

How to disable AI features across major platforms

🛡️ This article provides practical, step-by-step tactics for detecting and disabling built-in AI features in popular enterprise platforms including Microsoft Copilot, Google Gemini, Chrome, and Apple Intelligence. It covers detection via logs and admin consoles, recommended policy settings in Microsoft 365, Group Policy, Chrome Enterprise, Google Workspace, and MDM profiles for Apple, plus network-level blocks and caveats about potential feature breakage. The guidance emphasizes granular controls, SKU management, and layered protections such as NGFW/web-filter rules and application control.
read more →

Microsoft named Leader in 2026 Endpoint Protection

🛡️ For the seventh consecutive time, Microsoft has been named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection, reflecting customer trust in Microsoft Defender. Defender provides industry-leading EDR backed by global threat intelligence and connects endpoints, identities, email, apps, cloud, and data to enable earlier detection and stronger prevention. Recent advancements include proactive attack disruption, custom telemetry, simplified onboarding, sovereign-ready protection, and agentic endpoint security for local AI agents.
read more →

CypherLoc scareware locks browsers, targets users globally

🔒 Security researchers warn of a new scareware strain, CypherLoc, used in around 2.8 million attacks since early 2026. The campaign starts with phishing that directs victims to a malicious page which only activates when specific URL fragments and cryptographic checks pass. Once triggered, the code forces full-screen browser lockdowns, disables controls, displays fake security warnings and a fraudulent support number, with operators posing as Microsoft support. Barracuda urges anti-phishing, browser and endpoint protections and user education to mitigate the threat.
read more →

25M Alert Analysis: Low-Severity Leads to Missed Breaches

🔍 In a sweeping analysis of 25 million enterprise security alerts, researchers found that nearly 1% of confirmed incidents began as low‑severity or informational alerts, rising to about 2% on endpoints. The dataset included 10 million monitored endpoints, 82,000 forensic endpoint investigations with live memory scans, and 180 million files analyzed. The report shows EDR remediation frequently reports systems as 'mitigated' even when memory forensics reveal active malware, and it documents evolving phishing and cloud persistence tactics that evade legacy triage models.
read more →

Microsoft Agent 365 Now GA: Expanded Agent Controls

🔒 Microsoft announces Agent 365 is generally available, offering a unified control plane to observe, govern, and secure AI agents across endpoints, cloud, and SaaS. The release adds discovery of local and cloud agents (including OpenClaw, GitHub Copilot CLI, and Claude Code) and integrates with Intune and Defender for inventory, policy controls, runtime blocking, and alerting. Agent 365 also introduces Windows 365 for Agents, partner integrations, and licensing via Microsoft 365 E7 or standalone at USD 15 per user per month.
read more →

Microsoft lets admins pick preinstalled Store apps to remove

🛠️ Microsoft expanded its in-box app removal policy for Windows 11 to add a dynamic list that allows IT admins to specify which preinstalled Microsoft Store apps to uninstall by Package Family Name (PFN). The RemoveDefaultMicrosoftStorePackages policy can be applied via Group Policy or a custom OMA-URI for MDM and requires the April 2026 non-security update (Insiders can get it with the March 13, 2026 Dev/Beta builds). Intune support for the dynamic list will arrive in the coming months.
read more →

One in Four Healthcare Organizations Hit by Device Attacks

🏥 A new RunSafe Security index found that 24% of healthcare organizations experienced cyber-attacks affecting medical devices in the past year, with 80% of those incidents causing moderate or significant patient impact, from delayed imaging to interruptions in critical care. The survey of 551 professionals across the US, UK and Germany shows growing integration of security into procurement—82% deploying runtime exploit protection and 84% including cyber requirements in vendor RFPs—yet legacy devices remain a major exposure.
read more →