EC-Council News, Trends & Updates
Ir al canal en Telegram
Mostrar más
8 372
Suscriptores
Sin datos24 horas
-197 días
-8930 días
Archivo de publicaciones
💡Critical Avada WordPress theme flaw enables zero-click RCE
A critical vulnerability chain has been discovered in the popular Avada theme for WordPress. This flaw enables an unauthenticated attacker to achieve zero-click Remote Code Execution (RCE). Attackers can exploit it to execute arbitrary PHP code on the server without any user interaction, posing a severe risk.
Source: [ bleepingcomputer.com ]
https://www.bleepingcomputer.com/news/security/critical-avada-wordpress-theme-flaw-enables-zero-click-rce/
AI risk has outgrown the security team. It now belongs in the boardroom, and September 11 is where that conversation happens.
Artificial intelligence has rapidly moved from an emerging capability to a core enterprise dependency, and the risks it introduces, including model integrity, data exposure, third-party dependencies, and regulatory uncertainty, can no longer be managed within technical domains alone. CISOs are being asked to elevate AI risk to board-level oversight, and most are still building the framework to do it.
Dewayne Hart, cybersecurity strategist, author, and founder of SEMAIS, closes a three3-part CCISO webinar series with a strategic session on governing enterprise AI risk at the board level.
This is the final session of the series, so don’t miss it.
Register now: https://shorturl.at/edBzS
#CCISO #ECCouncil #AIGovernance #CISOLeadership #BoardroomSecurity #AIRisk #CyberResilience #SecurityLeadership #Webinar #TechWebinar #AIWebinar
Upcoming Webinar Alert!
Attackers are adapting to bypass SIEM, EDR, and XDR defenses. Join Milton Araújo on September 7, 2026, for Breaking the Blue Team: Techniques to Bypass Modern Detection Systems.
Register now: https://shorturl.at/JuHGK
#ECCU #Webinar #CyberSecurity #BlueTeam #ThreatDetection #SIEM #EDR #XDR #ThreatHunting #CyberDefense #SOC
Jay Bavisi on How AI Is Transforming Penetration Testing
“If you're not using AI to attack your own systems, your adversaries will.”
EC-Council Founder & Group President Jay Bavisi shares his perspective with The Register on how AI-enabled attackers are changing penetration testing.
Key takeaways:
• AI-enabled attackers operate continuously, making annual or quarterly testing increasingly inadequate.
• Pentesters must go beyond finding vulnerabilities to assessing business impact and making informed engineering decisions.
• LLMs, agentic behavior, guardrails, and containment mechanisms are becoming part of the attack surface.
• AI won’t replace pentesters but will raise the level of expertise and judgment expected from them.
The article also features insights from Kevin Mandia, Matt Hartman, and Rob Joyce.
Read the full conversation on AI and offensive security →
💡WhatsApp adds stronger two-step verification, multiple passkeys
WhatsApp is significantly enhancing account security by rolling out new features. Users can now benefit from stronger two-step verification and support for multiple passkeys. These updates aim to provide better protection, making your messaging experience even more secure. Get ready for improved safeguards as WhatsApp introduces these latest measures to keep your personal communications safe and your account well-protected.
Source: [ bleepingcomputer.com ]
https://www.bleepingcomputer.com/news/security/whatsapp-adds-stronger-two-step-verification-multiple-passkeys/
LIVE NOW – Join Us!
The webinar AI's Impact on SOC: Scaling and Automating Security Operations with AI is happening now, featuring cybersecurity expert Shervin Evans.
Time: 9:30 AM EDT | 8:30 AM CDT | 7:00 PM IST
Join live now: https://shorturl.at/6c4J4
Learn how AI is transforming threat detection, incident response, analyst workflows, and modern security operations. Gain actionable insights into building scalable, intelligence-driven, and adaptive SOC environments.
#ECCU #Webinar #CyberSecurity #AISecurity #SOC #ThreatIntelligence #CyberDefense
💡Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
Urgent warning for users of Calix GS7 XGS routers! An unpatched vulnerability allows remote, unauthenticated attackers to bypass NAT. They can create port-forwarding rules, exposing your internal network devices to the public internet. This affects residential customers using these routers via multiple U.S. broadband providers. Your home network could be silently exposed.
Source: [ bleepingcomputer.com ]
https://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/
What does it take to make AI security work for the business?
Register now: https://shorturl.at/nOqhy
Preity Gupta, TEDx speaker, bestselling author, and Global Security Board Advisor at EC-Council, returns for the series finale of the Certified AI Program Manager (CAIPM) webinar series on September 21.
About the Speaker:
• Chief Enterprise AI Cybersecurity Advisor (GRC) and Global Security Board Advisor, EC-Council
• Enterprise AI Security Architect at Wipro
• Delivered 35% reduction in compliance costs and 25% improvement in project success
• Founder, Preity Gupta SecureBiz
• 20+ years across Azure, AWS, Oracle, and GCP
• Formerly with Accenture and HCL
• CISM, AZ-500, SC-100, AWS SAA-C02
• Author of Cost Savvy Secure Cloud
#CAIPM #ECCouncil #AIROI #AISecurity #AIGovernance #CyberSecurity #EnterpriseAI #Webinar
💡ToxicPanda Android malware uses VPN permissions to block Google Play
ToxicPanda Android malware has significantly evolved, now targeting 349 applications and supporting 167 remote commands. This sophisticated threat leverages VPN permissions to specifically block Google Play access, preventing users from downloading legitimate apps or updates. Stay vigilant against this advanced mobile security risk, as it impacts app availability and user security.
Source: [ bleepingcomputer.com ]
https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/
A TEDx speaker, bestselling author, EC-Council board advisor, and security leader behind programs that reduced compliance costs by 35%. Learn from Preity Gupta’s expertise in AI governance, multi-cloud security, and risk optimization.
Register now to catch Preity Gupta live on August 26: <LINK>
About the Speaker:
• Chief Enterprise AI Cybersecurity Advisor (GRC) and Global Security Board Advisor, EC-Council
• Enterprise AI Security Architect and Advisor, Wipro
• Executive Board Member, Bharatiya Vitta Salahkar Samiti
• 20+ years across Azure, AWS, Oracle, and GCP
• Formerly with Accenture and HCL
• Founder, Preity Gupta SecureBiz
• Expertise in ISO 27001, GDPR, NIST, DORA, AI Governance, and Zero Trust
• CISM, AZ-500, SC-100, AWS SAA-C02
• Author of Cost Savvy Secure Cloud
#COASP #ECCouncil #AISecurity #AIGovernance #CyberSecurity #Webinar
Upcoming Webinar Alert
AI adoption is accelerating. Strong data governance is essential to keeping enterprise data secure, reliable, and ready for AI.
Join Dr. Jonathan Reichental on September 15 for Creating an Enterprise Data Governance Strategy for the AI Era.
Register now: https://shorturl.at/T0fAa
#ECCU #Webinar #CyberSecurity #DataGovernance #AI #AIGovernance
💡Hackers infect Android car head units with proxy botnet malware
Beware! Hackers are targeting Android car head units with malware spread via a legitimate device-update app. This supply-chain attack enlists compromised vehicles into a proxy botnet or uses them for ad fraud. Ensure your car's software is updated only through trusted sources to protect against this evolving threat targeting in-car systems.
Source: [ bleepingcomputer.com ]
https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/
💡TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
TikTok will pay $400 million to settle a U.S. child privacy lawsuit, the Department of Justice announced. The ByteDance-owned platform faced accusations of violating child privacy laws. This significant settlement includes an immediate $300 million payment, with an additional $100 million due upon a prior consent decree being vacated. It resolves the 2024 legal action against the social media giant.
Source: [ thehackernews.com ]
https://thehackernews.com/2026/08/tiktok-agrees-to-400-million-settlement.html
Forty years of information security experience. Clients spanning Microsoft, AT&T, the U.S. Marine Corps, DISA, and some of the world's largest healthcare and financial organizations. That is the depth Jayson Ferron brings to August 27.
Catch Jayson Ferron live on August 27.
About the Speaker:
CEO of Interactive Security Training, LLC and multi-certified Information Security Subject Matter Expert
More than 40 years of professional experience spanning security and compliance, integration and transformation, information security management, and operational metrics
Clients include the Community Health Network of Connecticut, Cigna Insurance, Microsoft, Rogers Communications, GM, AT&T, the U.S. Marine Corps, the U.S. Air Force, the U.S. Army, and DISA
Also works with banks, government agencies, and healthcare organizations globally
Register now: https://shorturl.at/nxood
#CEH #ECCouncil #EthicalHacking #PenTesting #RedTeaming #AISecurity #CyberSecurity #ThreatLandscape #OffensiveSecurity #Webinar #TechWebinar
💡Named Pipes Under Attack: Securing Windows Interprocess Communication
Windows named pipes, vital for fast interprocess communication, are under attack due to weak access controls exposing privileged services to untrusted processes. ThreatLocker details how to secure them. Implement endpoint verification, command authorization, strict input validation, and narrowly scoped privileges to protect Windows interprocess communication effectively against potential threats.
Source: [ bleepingcomputer.com ]
https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/
Upcoming Webinar Alert
AI adoption is accelerating. Strong data governance is essential to keeping enterprise data secure, reliable, and ready for AI.
Join Dr. Jonathan Reichental on September 15 for Creating an Enterprise Data Governance Strategy for the AI Era.
Register now: https://shorturl.at/T0fAa
#ECCU #Webinar #CyberSecurity #DataGovernance #AI #AIGovernance
💡14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers uncovered 14 trojanized npm packages disguised as calendar/streak utilities. These packages stealthily deliver RedC2 4.0 - an AI-powered Linux backdoor. Upon loading, the malicious module launches a bundled binary as a detached background process, posing a significant, advanced threat to Linux systems via its AI-assisted command and control. Users should exercise caution with npm packages.
Source: [ thehackernews.com ]
https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.html
