Microsoft Threat Intelligence has uncovered NeedyMantis, a modular post-compromise malware framework designed to preserve covert access inside…
Category: Cyber Security News
Florida AG Seeks Emergency Injunction to Restrict OpenAI and ChatGPT Over AI Safety Risks
Florida Attorney General James Uthmeier has asked a Highlands County judge to impose sweeping temporary restrictions on OpenAI, CEO Sam Altman, and…
New File Notification Attack Lets Hackers Track User Activity Across Linux, Windows and macOS
A cross-platform side-channel attack that abuses file-notification services to monitor user activity on Linux, Windows and macOS. The technique turns…
Hackers Built an AI-Powered Attack Machine and Accidentally Left the Control Panel Open
A criminal crew linked to Blackhatsect0r and DXQRTXX built an automated system designed to find weaknesses across the internet. Its exposed server…
OpenCode AI Coding Agent Flaw Lets Malicious Websites Execute Code on Developer Machines
A critical attack path in OpenCode, an open-source AI coding agent, could let a malicious website execute commands on a developer’s computer. Tracked as…
NCSC Urges UK organizations to Patch for Citrix NetScaler ADC and Gateway 0-Day Vulnerabilities
The UK National Cyber Security Center (NCSC) has urged organizations to take immediate action against eight vulnerabilities affecting customer-managed…
TrustSink Attack Uses Rogue MFA Provider to Steal Microsoft Entra Passwords During Legitimate Logins
TrustSink is a newly disclosed identity attack that turns a trusted MFA step into a password-stealing trap. Rather than sending victims to a clearly fake…
NVIDIA Launches Open Agent Safety Platform With 100 Industry Partners to Secure Autonomous AI Agents
NVIDIA has launched the Open Agent Safety Platform, an open framework designed to secure autonomous AI agents as they gain access to models, tools, code…
ShinyHunters Bypasses WAF Protections to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
ShinyHunters has renewed attacks against Oracle PeopleSoft systems by slipping past web application firewall protections and planting web shells. The…
Attackers Create Fake Jev AI Stores to Intercept Prompts Through Third-Party Servers
Fake storefronts appeared days after the launch of Jev, an artificial intelligence model that returns decisions rather than written answers. The sites…
Bitget Backend Breach Drains $387.5 Million as DPRK-Linked Launderers Expose Themselves
Cryptocurrency exchange Bitget has begun restoring withdrawals after attackers exploited its backend wallet infrastructure on September 24, stealing…
CISA Warns of Microsoft SharePoint Code Injection Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Microsoft SharePoint code injection vulnerability, tracked as CVE-2026-65660,…
OpenAI Agent Swarm Bypassed Sandbox Limits and Left 80,000 Attack Payloads Behind
About 700 OpenAI agents allegedly escaped evaluation sandboxes, compromised parts of Hugging Face infrastructure, and generated over 80,000 attack…
Top 10 Best Authentication-as-a-Service (AaaS) Providers in 2026 [Ranked & Scored]
Nobody gets promoted for building login, but plenty get breached maintaining it. Authentication-as-a-Service moved from convenience to best practice:…
Python MaaS Infostealer Builder Steals Passwords, Credit Cards and Cookies From 17 Browsers
A Python-based malware builder can turn a single stealer into Windows programs for different operators. The tool packages a payload designed to take saved…
Hackers Exploit GlobalProtect Flaw and Turn Stolen Data Into 2.4 Million Fraud Messages
Hackers broke into business networks, stole customer records and used those details to send convincing fake bills. The campaign, called Operation Master,…
Top 10 Best Adaptive / Risk-Based Authentication Tools in 2026 [Ranked & Scored]
Prompting every user for MFA on every login trains people to approve anything, leaving enterprises open to push-bombing and MFA fatigue attacks;…
Top 10 Best Biometric Authentication Solutions in 2026 [Ranked & Scored]
Matching a face got easy; proving the face is a live human at a real camera while generative AI mass-produces convincing deepfake threats is where the…
Hackers Don’t Need to Break Into the Cloud When They Can Steal the Keys
Infostealer malware is giving criminals a quieter route into corporate cloud environments. Instead of forcing their way through a hardened cloud…
Kiteworks Warned Customers to Shut Down Servers Over Potential Zero-Day Attack
Kiteworks warned customers to temporarily shut down their servers after receiving credible threat intelligence that a threat actor could target some…
