Cyber Security News
Anthropic Users Hit by Infostealer Attacks Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users. Read more
Hundreds of OpenAI Agents Invaded Hugging Face Servers
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack. Read more
Android Malware Hijacks Update System for Car Head Units
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread inf… Read more
Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI and thousands more
More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm – two men now face charges over TeamPCP’s g… Read more
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access. Read more
Best Practices
FBI investigates breach of 153 million driving license records at IDscannet
Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were f… Read more
Zero trust has a big AI agent problem ahead
Despite singing the praises of zero trust for many years, many CISOs have struggled to implement the framework in full. And now comes wha… Read more
Microsoft warns patch window is collapsing urges shift to network-level containment
Microsoft is warning that the window for patching vulnerabilities is rapidly shrinking, as attackers move from disclosure to exploitation… Read more
Trusted Chrome Edge extensions weaponized in supply chain campaign
Attackers have turned previously legitimate browser extensions into malware after acquiring them from legitimate publishers, potentially … Read more
Cisco bundles fixes for multiple vulnerabilities some critical into one patch
Cisco is looking to get ahead of attackers with a new set of more than a half-dozen fixes, some of them critical, for its IOS XR Linux-ba… Read more
New Threats and Vulnerabilities
Claude Opus 46 Bypasses Gym Booking Limit Cancels Other Users Reservations in Tests
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on t… Read more
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX’s artificial intelligence (AI)-powered coding assistant Cursor to b… Read more
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, tha… Read more
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow c… Read more
APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late Se… Read more
Patch Management
Three CVSS 100 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitabl… Read more
Spark RAT Targets Cambodia Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT…. Read more
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative… Read more
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary… Read more
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe?Commerce and?Magento Open Source that has come under active exploit… Read more
AI and Security
Google research shows when AI agents communicate some cheat while others tattle
When AI agents communicate with one another, they may decide to cheat when they have difficulty achieving their goals. The solution could involve teaching them… Read more
US law firm accuses UK AI software firm of unwanted contract renewal when it tried to leave
A US law firm is alleging that UK-based telecoms and software company ConnexAI sold it software and AI systems that failed to perform as the vendor claimed, an… Read more