A newly disclosed flaw in Microsoft’s official Azure DevOps MCP server shows how an invisible comment in a pull request can silently hijack a developer’s AI coding assistant and turn it into a data-exfiltration tool. Security researchers at Manifold Security…
Category: Cyber Security News
Anonymous Researcher Dumps 204 0-Day Exploit Files Before Vendors Can Patch Them
An anonymous GitHub user has quietly assembled one of the most disruptive exploit collections of the year, dropping 204 zero‑day proof‑of‑concept files for dozens of open‑source projects before vendors had a chance to patch them. The archive, hosted under the…
GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions
A new malware campaign is targeting cryptocurrency and Web3 professionals through fake job interviews. The operation delivers GolangGhost, a remote access trojan that can steal browser credentials, collect wallet data, and give attackers control of infected macOS systems. The attackers…
OpenAI’s GPT Agents Exploit Zero-Days and Hacked Hugging Face Servers
Hugging Face has disclosed a security incident that security researchers are calling a watershed moment for AI safety: an autonomous AI agent, built on OpenAI models, independently discovered and chained multiple vulnerabilities, including a zero-day, to breach Hugging Face’s production…
Google Chrome Update Fixes 12 Vulnerabilities That Could Enable Browser Attacks
Google has rolled out a new Stable channel update for Chrome, patching 12 security vulnerabilities, including nine rated “High” severity. The update brings Chrome to version 150.0.7871.181/.182 for Windows and Mac, and 150.0.7871.181 for Linux, with the rollout expected to…
Qilin Ransomware Claims 1,358 Victims as Global Attacks Reach New Record
Qilin ransomware has grown from a fast-moving criminal operation into one of the most visible threats in the global extortion landscape. The group encrypts systems and steals data, then pressures victims with the risk of public leaks. Its campaigns have…
Hackers Turn Fake Games Into Multi-Stage Infostealers That Steal Passwords and Crypto Wallets
Criminals are using fake game downloads to slip a sophisticated information stealer onto Windows computers. The campaign hides behind supposed games, mods, cracks, and other software, exploiting the trust and urgency around free or hard-to-find downloads. A downloaded archive can…
Trump’s AI Safety Chief Quits Just Three Months After Taking Charge
Chris Fall has resigned as the director of the Center for AI Standards and Innovation (CAISI), leaving the Trump administration’s AI safety organization without a permanent leader just three months after his appointment. CNBC confirmed the departure on Monday following…
Hackers Hijack 20+ Government Websites to Deliver Malware Through Trusted Links
An active malware campaign, dubbed PhantomEnigma, that abuses compromised Brazilian government infrastructure to distribute malicious payloads while evading detection. The operation has hijacked at least 20 official “.gov.br” municipal and police portals, using them as trusted delivery points for malware…
This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk
A criminal service called Cruciferra is giving malware operators a way to slip past Windows defenses. Sold as a subscription crypter for as much as $2,000 a month, it wraps malicious programs so security tools struggle to inspect, block, and…
Gemini 3.5 Flash Cyber With Automated Faster Vulnerability Detection and Patch Capabilities
Google has launched Gemini 3.5 Flash Cyber, a specialized cybersecurity model fine-tuned to find, validate, and patch software vulnerabilities faster and more efficiently than mainline Gemini Flash models. The release marks a significant expansion of Google’s automated security research efforts,…
Now You Can teach a Skill to Claude by Just Recording your Screen
Anthropic has rolled out a new capability in Claude Cowork that lets users teach the AI assistant a repeatable skill simply by recording their screen while performing a task. The feature, called “Record a skill,” turns a screen capture into…
Top 10 Malware Used by Hackers Last Week to Launch Cyberattacks
Cybercriminals continued to lean on a familiar arsenal of malware last week, with information stealers and remote access trojans (RATs) dominating the threat landscape as the primary tools for initial access, credential theft, and long-term system control. Topping the list…
Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild
A newly disclosed vulnerability, tracked as CVE-2026-50522, is rattling enterprise IT teams as it allows unauthenticated attackers to remotely execute code on on-premises Microsoft SharePoint servers. The flaw carries a critical CVSS score of 9.8 and stems from deserialization of…
APT42 Uses AI-Assisted Phishing and TAMECAT Malware to Target Government and Defense Officials
APT42, an Iran-linked cyber espionage group, has expanded its phishing operations with AI-assisted research, convincing personas, and a more resilient version of its TAMECAT malware. The campaign has targeted senior government and defense officials, policy experts, and, in some cases,…
Agentic JADEPUFFER Exploits Langflow Flaw to Deploy ENCFORGE AI Ransomware
A ransomware campaign is now targeting the assets behind artificial intelligence systems. The threat actor known as JADEPUFFER has evolved from damaging databases to deploying ENCFORGE, a ransomware strain designed to encrypt AI models, training data, and vector databases. The…
Hackers Hide Malware Commands in Outlook Events Dated 2050 and Use as C2 Channel
A newly identified malware component linked to the Project CAV3RN framework is abusing Microsoft Outlook calendar events scheduled for 2050 to conceal command-and-control (C2) traffic. The tool also uses DNS AAAA responses as a fallback channel to restore Microsoft Graph…
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware
Malware operators are increasingly using tools built to extend artificial intelligence as a delivery route. A newly documented campaign called AgentBaiting uses fraudulent AI Skills and Model Context Protocol, or MCP, servers to distribute SmartLoader malware through trusted-looking GitHub projects…
Craneware Data Breach – Hackers Stole Significant Amount of Data
Healthcare financial software provider Craneware has confirmed a cybersecurity incident involving unauthorized access to a portion of its data environment. The company reported that threat actors viewed and exfiltrated a substantial number of file names, along with some employee data,…
Microsoft to Discontinue Podcasts Option on Copilot and to Delete Contents
Microsoft will retire the Podcasts feature in its consumer Copilot app on August 18, 2026, permanently removing access to both the creation tool and all previously generated podcast content. This change affects both free and paid Copilot users, including those…
