Irregular has detailed an investigation into an AI cyber-evaluation incident in which internet access unintentionally allowed models to interact with…
Category: Cyber Security News
French Tax Authority Data Breach Exposes 600,000+ Users’ Personal Tax-Related Data
France’s tax authority has confirmed a data breach affecting approximately 678,000 individuals and businesses after threat actors gained unauthorized…
CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human…
French Tax Authority Data Breach Exposes 600,000+ Users Personal Tax-Related Data
France’s tax authority has confirmed a data breach affecting approximately 678,000 individuals and businesses after threat actors gained unauthorized…
Anthropic Launches New /design Skill for Claude Code UI Workflows
Anthropic has introduced a new /design skill for Claude Code, expanding its developer-focused AI platform into user interface design workflows. The…
Critical MLflow SSRF Vulnerability Exploited by Hackers in the Wild
Threat actors are actively exploiting a critical, unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, the popular open-source…
Microsoft 365 Search Outage Disrupts SharePoint, OneDrive, and Outlook Users Worldwide
Microsoft is actively managing a service disruption that has left a subset of enterprise users unable to search for content across SharePoint Online,…
Hackers Hijack Thousands of WordPress Sites to Use as C2 Servers for StopAndProtect Malware
A newly uncovered malware operation dubbed StopAndProtect is transforming thousands of hacked WordPress websites into a sprawling criminal…
Projextor Shows How Malware Can Hide Behind Trusted Electron Executables
Projextor is a malware campaign that turns ordinary-looking desktop tools into a doorway for hidden code. Its operators package it inside working document…
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers
BTMob is an Android banking malware platform built to turn phones into tools for fraud. It reaches victims through fake apps, cloned download pages, and…
C2Looper Updates Itself Through OneDrive DLL Sideloading to Evade Detection
C2Looper is a newly identified backdoor that gives attackers a quiet way to control a compromised Windows computer. It can run commands, inspect the…
OpenAI Warns AI Models Can Automate Cyberattacks and Exploit Security Vulnerabilities
OpenAI has warned that advancing artificial intelligence models are increasingly capable of automating critical phases of real-world cyberattacks. This…
Why Threat Intelligence Feeds Often Fail to Meet SOC Expectations
Threat intelligence (TI) feeds are expected to close visibility gaps that inevitably emerge in enterprise SOCs and make investigations faster and more…
Octagon Can Steal SMS One-Time Codes During Banking and Crypto Account Takeovers
Octagon is an Android theft tool that turns an infected phone into a platform for account takeover. It can steal login details, watch the screen, and…
JWR Phishing Framework Uses Real-Time WebSocket Control and AES Encryption to Steal Banking Credentials
JWR is a phishing framework built for live fraud. It turns a fake payment or bank page into a live channel that lets criminals watch details arrive as…
Kimsuky Expands Its Cyber Espionage Arsenal With Local AI Development Environment
Kimsuky, the North Korean espionage group, has expanded a campaign known as Operation GitPower with a local artificial intelligence development setup. It…
Apple Fixes 28 Security Vulnerabilities Across macOS, iOS, and iPadOS
Apple has released security updates for macOS, iOS, and iPadOS, addressing 28 vulnerabilities that could expose users to data leakage, application…
GEEKOM Mini PC Realtek LAN Driver Package Found Infected With Asruex Trojan
A network driver download is meant to get a computer online. In this case, it became a potential malware route after a Realtek LAN driver package on a…
Crypto Scammer Uses Claude Code to Process 100,000+ Phone Numbers for Victim Targeting
A cryptocurrency fraud operation has been found using AI coding tools to turn huge phone lists into a sharper victim-targeting system. The campaign…
CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks
CISA has added a critical Ray-Project Ray vulnerability, tracked as CVE-2025-62593, to its Known Exploited Vulnerabilities catalog after confirming…