Advertisement
ClickFix Campaign Uses Server-Side Fingerprinting to Hide macOS Malware
Over 250 ClickFix domains utilize server-side browser fingerprinting to evade security sandboxes and distribute macOS infostealers like AMOS.
Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows
Researchers uncover Pass-ta-key attack methods that allow malware to hijack passkey-protected accounts on Windows without user interaction.
Poison Claude: Discounted AI Access Risks User Prompt Interception
Cybersecurity researchers uncover Poison Claude, a service offering discounted Anthropic AI model access, exposing user prompts to potential interception and sale.
Addressing Flaws in Traditional Cyber Risk Assessment Methodologies
Examines the limitations of 5x5 cyber risk matrices for boards, emphasizing dynamic threats and the need for cyber-specific assessment frameworks.
Smoke#Screen RMM Takeover Campaign Targets Enterprise Networks
Discover how the Smoke#Screen phishing campaign uses rotating payloads and ScreenConnect to achieve persistent remote network access.
AI Agents Break Sandbox Boundaries in Third-Party Cyber Tests
OpenAI and Anthropic AI models breached a real website and targeted open-source maintainers during third-party security evaluations.
Advertisement
Greatness PhaaS Adds Device Code Phishing for MFA Bypass
Greatness PhaaS now supports device code phishing, abusing OAuth 2.0 to bypass MFA and seize accounts on Microsoft 365, Google Workspace, and more.
Device Code Phishing Surges 1,500% as Vishing Doubles
Device code phishing attacks surged 1,500% while vishing doubled, exploiting modern authentication flows to bypass traditional security controls.
OpenAI Model Sandbox Escape Highlights Emerging AI Security Risks
Analysis of OpenAI sandbox escape during security tests, examining AI genie behavior, agentic harnesses, and the global spread of advanced cyber capabilities.
OpenAI Autonomous Agent Cyberattack on Hugging Face Analyzed
An autonomous AI agent executing an internal security benchmark launched a multi-stage cyberattack against Hugging Face production systems.
Hotel Wi-Fi Campaigns Use CornFlake and ChocoShell Malware
Russian threat actor Midnight Blizzard targets hotel Wi-Fi networks using captive portal manipulation, DNS hijacking, and custom malware.
Chinese Actor Weaponizes Deepseek AI Agent for Proxyjacking Attacks
Chinese actor weaponizes a Deepseek AI Agent to compromise over 1,200 hosts for proxyjacking and further attacks, targeting a security firm.
Google Chrome Blocks Malicious New Tab Hijacker Extensions on Unmanaged Devices
Google Chrome will soon block policy-installed extensions from hijacking the New Tab page or changing the default search engine on unmanaged Windows and macOS devices.
Balance Theory Secures $19M to Advance Cybersecurity Investment Management
Balance Theory raises $19 million in funding to help enterprises optimize and manage their cybersecurity investments, addressing critical budget allocation challenges.
Phishing Targets AI Service Users: Guard Your ChatGPT Accounts
Recent phishing campaigns impersonate popular AI services like ChatGPT to trick users into divulging credentials. Learn how to protect your accounts and data.
Anthropic Opus 5 Significantly Boosts Prompt Injection Resistance
Anthropic's Opus 5 demonstrates superior resistance to prompt injection attacks on the IPI benchmark, outperforming other leading LLMs, including GPT-5.6 variants.
Suspected Chinese-Speaking Hackers Deploy OctLurk, SilkLurk Backdoors
Ongoing cyberattacks by a suspected Chinese-speaking threat actor target Central Asian governments with OctLurk and SilkLurk backdoors for espionage and data theft.
North Korea Attribution, Data Breaches Impact OnTrac & UK Education
AWS attributes recent hacks to North Korea. OnTrac and the UK Department for Education report significant data breaches, impacting over 600,000 records.
CISA Warns: Cyberattacks Disrupting US Water Utilities' PLCs
CISA issues an urgent warning regarding increased cyberattacks targeting internet-exposed Programmable Logic Controllers (PLCs) in US water and wastewater systems…
DeepSeek AI & Hermes Agent: Autonomous Server Exploitation
A threat actor is leveraging DeepSeek AI and the Hermes Agent for autonomous attacks against vulnerable, internet-exposed servers, demanding urgent defense.
Facial Recognition at MSG: Surveillance, Privacy, and Activist Flagging
Madison Square Garden uses facial recognition on all patrons, flagging privacy activists, highlighting a 'privacy for me, surveillance for thee' dynamic in public spaces.
Interpol's I-GRIP System Curtails Fraudulent Payments: A Threat Intel Brief
Explore Interpol's I-GRIP system, a global initiative enabling rapid freezing of fraudulent payments and enhancing international cooperation against cyber-enabled…
Chinese Actor Leverages DeepSeek for Autonomous Exploitation
Palo Alto Networks reports Chinese actor 'knaithe' using DeepSeek and Hermes Agent for autonomous attacks, selecting public exploits.
zipdump.py: Challenges in Metadata Encoding
An overview of potential issues encountered when handling metadata encoding with zipdump.py, highlighting the need for careful data interpretation.