Cyber Security News
Chrome Store Hosts Poper Blocker Spyware Downloaded by Millions
A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google’s stamp of approval despite researcher warnings. Read more
Prompt-Injection Bug Hits $4B Agentic AI App Manus
AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage. Read more
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use. Read more
BragJack Attack Can Turn a Browsers Agentic AI Against It
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate da… Read more
Best Practices
New npm malware finds a way around install script defenses
Blocking suspicious install scripts may no longer be enough to mitigate threats from malicious JavaScript dependencies used in software s… Read more
A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vu… Read more
Oracle’s September patches put Fusion Middleware back in the hot seat
Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, wit… Read more
New Threats and Vulnerabilities
17000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new glo… Read more
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026… Read more
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to… Read more
101 Malicious npm Packages Add Developers WhatsApp Accounts to Groups Without Consent
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed Phanto… Read more
Patch Management
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared … Read more
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere el… Read more
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 100) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability,… Read more
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are u… Read more
AI and Security
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers – Google Gemini, DeepSeek, Qwen, and Mistral – to autonomously select from predefi… Read more
Meta Muse AI app flaw lets local malware redirect dictation traffic
Meta made much of the security of its AI assistant app Muse at launch earlier this month, calling out the app’s reliance on Muse Secure VM. "Each person stays … Read more