Five Venezuelan nationals pleaded guilty to failed ATM jackpotting attempts in Kansas, with one drawing nine months.
Aesto Health told HHS that 9.5 million people had personal and health data stolen from its AWS infrastructure.
A GitHub repo promising free Claude Opus 5 is quietly installing the RevStealer infostealer, according to Morphisec.
WatchTowr reports attackers are minting admin tokens through the critical JFrog Artifactory auth bypass patched August 28.
A 33-hour BGP hijack diverted Softaculous traffic and pushed a malicious Virtualizor update to a handful of servers.
Researcher Chaotic Eclipse published HardBreacher, a working exploit for a Kaspersky Endpoint Security privilege escalation zero-day.
ESET says Russia-aligned UAC-0099 hides a nuclear weapon request in malware comments to stall AI-powered triage.
AI safety nonprofit METR says attackers stole an API key and burned about $600,000 in model credits across two incidents.
Unit 42 maps a campaign that hit 150 employees and pushed toward domain controllers.
VulnCheck says KindaRails2Shell is under attack roughly a month after patches shipped.
CloudSEK and Gambit find a Russian-speaking crew leaning on AI coding tools to plan intrusions.
The OpenAI-led group says AI attacks will outpace fixes without a coordinated defense surge.
Anthropic locks victims out and refunds charges after infostealers hijack active login sessions.
ShinyHunters says it entered through phone calls, seized Okta sessions, and drained Salesforce and Snowflake data.
Sygnia traces the China-nexus group beyond VMware to routers, TACACS servers, and management hosts.
Kaspersky ties the backdoor's new disguise to Silver Fox, which hid it inside a signed Chinese wallpaper tool.
CRPx0's white-label ransomware service claims 48 victims as ClickFix lures spread to Windows and macOS.
The NovaCookies phishing service uses genuine Docusign notifications to steal Microsoft 365 sessions in real time.
Acronis says a Cambodia-targeting campaign loads a vulnerable OPSWAT driver to kill security tools and drop Spark RAT.
A prompt injection flaw in Amazon's Kiro IDE can push sensitive local data to attackers when a poisoned project is…
GoCaracal, a malware framework tied to Dark Caracal, stores a fallback C2 address on the Ethereum blockchain.
Five critical flaws across WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP open sites to takeover and code execution.
Ubiquiti shipped fixes for 22 UniFi vulnerabilities, three of them perfect-10 access control flaws.
Hasbro is warning current and former employees that personal data may have been exposed in a breach tied to its…