The Muse artificial intelligence assistant from Meta has been found to be vulnerable to an attack which allows malicious software to redirect its…
Category: CySecurity News – Latest Information Security and Hacking Incidents
Chinese Hackers Exploit ZyXEL Switch Flaw to Steal Data From Nearly 1,000 Devices
A Chinese threat actor has been using the recently discovered vulnerability in ZyXEL GS1900 switches to steal crucial information from the devices around…
Cyberattack Hits University of Munich, Exposing Student Data
Germany’s Ludwig Maximilian University of Munich (LMU) is investigating a significant cyberattack that potentially exposed sensitive student information,…
Foreign Hackers Got Into Two Colorado Water Systems, Messed With Pump Controls and Killed the Alarms
Foreign actors broke into the industrial control systems of two small private water utilities in Colorado last month, altered pumping cycles, changed…
STOMP Backdoor Uses PowerShell for Sensitive Data Theft
An advanced malware campaign known as TASK#STOMP has recently been discovered, which utilizes a PowerShell-based backdoor to collect business documents,…
TraderTraitor Mac Malware Targets IT Firm Through Weaponized Terraform Projects
A North Korean-linked cybercrime group known as TraderTraitor has tied another macOS infection in an IT services company with no cryptocurrency ties to…
Claude Code Glitch Erases Years of Bengaluru Heritage Data
A critical AI mishap has put years of digital heritage preservation at risk in Bengaluru, after an automated coding assistant inadvertently wiped out…
Hacker vs. Hacker: ShinyHunters Outsmarts Clop Ransomware Gang
The extortion group ShinyHunters hacked the dark web leak site run by Clop, one of the most active ransomware operations in the world, defaced it with…
Researchers Escape OpenAI Codex Sandbox to Run Commands on Host
In OpenAI Codex, security researchers have identified two sandbox escape vulnerabilities, one of which allows developers to execute commands on their…
Four Linux Kernel Flaws Expose Systems to Local Root Exploits
A security researcher has publicly released working exploit code for four Linux kernel vulnerabilities that can allow local users to escalate their…
Critical Orkes Conductor Flaw Exploited for Unauthenticated Remote Code Execution
A critical vulnerability in Orkes Conductor is being actively exploited by attackers, potentially allowing them to execute arbitrary commands on…
An AI Helped Researchers Break Into OpenAI
A three-person security research team quietly walked into OpenAI’s internal infrastructure last July, submitted a pull request inside the company’s…
Unauthenticated RCE Bug Fixed in SolarWinds Access Rights Manager
SolarWinds has issued an urgent security advisory for a high-severity vulnerability in its Access Rights Manager (ARM) product, tracked as CVE-2026-28326.…
Gyazo Server Vulnerability Targeted to Steal Millions of User Records
Gyazo, an image-sharing platform, has confirmed a breach after attackers exploited a vulnerability in its upload server, gaining unauthorized access to…
Plugin4Shell: The Zero-Click Flaw That Broke Every Prominent AI Coding Agent at Once
The security promise was simple. A plugin marketplace reviews a piece of code, locks it to a specific, verified version, and every AI coding agent that…
Microsoft Fixes Critical Azure AI Flaw Rated CVSS 10.0
Microsoft has patched a maximum-severity vulnerability in Azure AI Foundry that could allow unauthorized attackers to escalate their privileges over a…
WeaselBiscuit Stealer Found in 13 Malicious npm Packages
Researchers have discovered 13 npm packages carrying a previously undocumented JavaScript information stealer called WeaselBiscuit, introducing yet…
RatHat Android Malware Uses AI to Control Infected Devices
A new Android backdoor called RatHat utilizes an AI-powered system to remotely navigate compromised devices, while also stealing sensitive information and…
Docker Fixes Critical Sandboxes Flaw That Could Expose Host Files
Docker has patched two vulnerabilities in Docker Sandboxes that could allow malicious code running inside an isolated sandbox to cross its intended…
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Global Crackdown
The U.S. Department of Justice has announced the court-authorized seizure of internet domains linked to “NightmareStresser,” one of the world’s…
