Unit 42 maps a campaign that hit 150 employees and pushed toward domain controllers.
VulnCheck says KindaRails2Shell is under attack roughly a month after patches shipped.
CloudSEK and Gambit find a Russian-speaking crew leaning on AI coding tools to plan intrusions.
The OpenAI-led group says AI attacks will outpace fixes without a coordinated defense surge.
Anthropic locks victims out and refunds charges after infostealers hijack active login sessions.
ShinyHunters says it entered through phone calls, seized Okta sessions, and drained Salesforce and Snowflake data.
Sygnia traces the China-nexus group beyond VMware to routers, TACACS servers, and management hosts.
Kaspersky ties the backdoor's new disguise to Silver Fox, which hid it inside a signed Chinese wallpaper tool.
CRPx0's white-label ransomware service claims 48 victims as ClickFix lures spread to Windows and macOS.
The NovaCookies phishing service uses genuine Docusign notifications to steal Microsoft 365 sessions in real time.
Acronis says a Cambodia-targeting campaign loads a vulnerable OPSWAT driver to kill security tools and drop Spark RAT.
A prompt injection flaw in Amazon's Kiro IDE can push sensitive local data to attackers when a poisoned project is…
GoCaracal, a malware framework tied to Dark Caracal, stores a fallback C2 address on the Ethereum blockchain.
Five critical flaws across WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP open sites to takeover and code execution.
Ubiquiti shipped fixes for 22 UniFi vulnerabilities, three of them perfect-10 access control flaws.
Hasbro is warning current and former employees that personal data may have been exposed in a breach tied to its March cyberattack.
Executive Order 14420 targets foreign bulk-power equipment over cyber, sabotage and supply-chain risks.
Microsoft tracks a ClickFix variant that drops a Python reverse tunnel through fake CAPTCHA overlays.
VulnCheck found two factory implants in ZBT router firmware that give unauthenticated attackers root access.
Socket found 19 Chrome and Edge extensions quietly stealing crypto wallet secrets in the Superior campaign.
OS-wide Encrypted Client Hello in Android 17 hides visited domains from carriers and Wi-Fi snoops.
Hunt.io found an exposed server packed with evidence of ownCloud and WordPress intrusions against Philippine targets.
A critical Cosmos EVM balance flaw let attackers drain six blockchains before the patch shipped.
Berlin refuses to pay after Rhysida-linked attackers exfiltrate data from the city's state network.