Huntress found attackers using a fake Custom GPT to funnel victims into a ClickFix malware chain.
Microsoft traced phishing emails that drop one remote tool, then install a second, redundant one.
MI5 has publicly tied a Beijing research funder to China's civilian spy agency.
A 16-year-old used a homemade AI bot to find an auth flaw that opened Microsoft's analytics backend.
MetaMask is exiting affected Ethereum validators while it investigates an intrusion inside its infrastructure.
Two of the bugs earn a perfect 10.0 score, and Dell says there is no workaround short of upgrading.
A signed-in Duo user could break out of a prompt template sandbox and run commands on self-hosted AI Gateway hosts,…
The company's 13-million-follower account was hijacked and used to boost a token tied to an old Office mascot.
Researchers say CloudSyncD has moved from the lab to live deployment, riding in on a fake Zoom installer.
Autonomous agents hunting for public data drifted into SQL injection attempts against US and Canadian government sites.
A China-tied crew skips the dedicated command server, turning a Microsoft mailbox into its control channel instead.
Microsoft's 2026 report says attackers are reaping AI's speed gains faster than defenders can respond.
Sucuri's SC backdoor hides in eight places and rebuilds itself from any one that survives cleanup.
Longlegs and Storm-2603 keep breaching unpatched SharePoint servers to plant Warlock ransomware.
A China-aligned crew posed as a White House adviser and an economist to phish US AI policy experts.
Police seized KillSec's leak site and froze 110 terabytes of stolen data, detaining a 16-year-old they call its leader.
A 9.8-rated FortiMail flaw lets unauthenticated attackers write files, and the fix is still pending.
Truffle Security found more than half a million still-valid credentials exposed in public GitHub repositories.
The US Treasury has sanctioned the alleged developer of Tren de Aragua's ATM jackpotting malware and seven of his associates.
Google is handing a guardrail-free build of its newest frontier model, Gemini 4 Argon, to a small circle of vetted…
An AI-driven intruder chained two Zammad zero-days to climb from a helpdesk account to root in seconds.
Kevin Mandia's offensive security startup has raised $255.5 million in Series B funding, pushing its valuation past $2.5 billion.
CISA has ordered federal agencies to patch a critical Cisco SD-WAN Manager flaw that attackers are already exploiting.
With one AI firm disclosing agent risk to investors and another facing a hacking suit, liability for runaway models is…