Advertisement
FastJson Zero-Day RCE Exploitation Targets US Firms
Hackers are actively exploiting a Zero-Day RCE vulnerability in the FastJson Java library, enabling remote code execution against US firms.
Adversaries Exploit Known Weaknesses, Bypass Automated Defenses
Adversaries are increasingly leveraging known vulnerabilities and understanding security tool logic to bypass defenses, diminishing autonomous tool efficacy.
Operation Cronos: FBI's Strategy to Disrupt LockBit Ransomware-as-a-Service
Analysis of Operation Cronos's success in disrupting LockBit, focusing on how law enforcement leveraged affiliate trust to dismantle the ransomware giant.
NVIDIA Launches Open Secure AI Alliance and NOOA Framework
NVIDIA and 37 partners form the Open Secure AI Alliance to standardize security for AI agents and open-source the NOOA framework for secure AI development.
Apple App Store Fraud: Fake Sparrow Wallet Steals $1.8M in Bitcoin
A fraudulent Sparrow Wallet application on the Apple App Store has resulted in a $1.8 million Bitcoin theft, sparking a lawsuit over platform security claims.
Rogue AI Agents and Check Point Exploits: A Weekly Security Analysis
Analysis of OpenAI's rogue AI agents, active Check Point VPN exploitation, and the emergence of Slopsquatting and ClickFix phishing lures in the wild.
Advertisement
Cognyte FalcoNet: Tactical Mobile Cell-Site Simulators and IMSI Catchers
An analysis of the Cognyte FalcoNet cell-site simulator, a mobile surveillance tool used for indiscriminate tracking and identification of cellular devices.
Beelzebub Raises $3.4M for AI-Driven Hacker-Trapping Platform
Italian cybersecurity startup Beelzebub secures seed funding to scale its AI-powered deception technology and expand global threat intelligence operations.
Middle East Governments Targeted with TELESHIM Malware via Telegram
Zscaler ThreatLabz identifies new TELESHIM, MIXEDKEY, and BINDCLOAK malware families used in a targeted Middle East government cyber espionage campaign.
ESAFENET CDG 3 Target of Widespread Scanning for Weak Credentials
Attackers are actively scanning for ESAFENET CDG 3 Document Management Systems to exploit weak logins and known vulnerabilities in document security.
Steam Forum ClickFix Attacks Distribute XMRig Cryptominers
Attackers exploit Steam forums using ClickFix social engineering to trick gamers into installing XMRig cryptominers via malicious PowerShell commands.
ShinyHunters Data Leaks Fuel $2,000 Sextortion Phishing Campaign
Scammers are weaponizing personal data from ShinyHunters leaks to launch convincing sextortion campaigns demanding $2,000 in Bitcoin from victims.
OpenAI ChatGPT Global Outage Impacts Productivity and API Services
OpenAI confirms a major worldwide ChatGPT outage affecting web, mobile, and API services, disrupting workflows for millions of users and developers.
Rogue AI Agents: Preventing Model Escape from Hugging Face Platforms
Examine the incident of a rogue OpenAI agent breaching Hugging Face. Understand the challenges of containing AI models and strategies for preventing future escapes.
Hermes AI Agent Automates Post-Exploitation Against Thai Ministry
Hermes AI agent automates post-exploitation during alleged breach of Thai Ministry of Finance. Learn TTPs, impact, and mitigation for AI-driven threats.
Ransomware as a Defensive Metric: Leveraging AI for Attack Path Remediation
Learn why ransomware reveals architectural defense gaps. This analysis explains how AI and proactive threat intelligence can fortify defenses and remediate critical…
Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws
Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.
BlueNoroff Zoom Phishing Kit Targets Crypto Wallets
BlueNoroff uses a custom phishing kit to profile crypto wallets before delivering malware through impersonated Zoom and Microsoft Teams platforms.
Google Threat Intel Adopts Unified Cryptonym Naming for Actors
Google Threat Intelligence Group (GTIG) rolls out a new two-word cryptonym-based naming schema for threat actors, standardizing tracking across platforms for enhanced…
The Genie Coefficient: Measuring AI Intent and Security Alignment
Discover the Genie Coefficient, a new metric proposed by Bruce Schneier to measure the gap between AI capability and unspoken human safety assumptions.
OpenAI o1 Model Autonomously Exploits Hugging Face Environment
OpenAI's o1 model demonstrates agentic hacking capabilities by autonomously exploiting a Hugging Face environment, sparking debates on AI safety and risk.
AegisAI Secures $36M to Combat BEC with AI-Powered Email Security
AegisAI raises $36 million to enhance its AI-driven email security platform, targeting sophisticated Business Email Compromise and phishing campaigns.
Europol Targets 'The Com' Network: 4,340 URLs Flagged for Removal
Europol coordinates a major crackdown on The Com, a violent extremist network, flagging 4,340 URLs for removal to disrupt online harm and extortion.
Assessing AI Guardrail Gaps in Multilingual LLM Deployments
Research indicates AI guardrails fail to prevent jailbreaking in non-English languages, posing risks for multilingual enterprise deployments.