A malicious HEIF upload exploited Discourse, crossed OpenAI’s identity layer, and reached an internal GitHub repo through a connected Codex account.
Category: EN
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive…
CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast
Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be.
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people…
Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal
The transaction is part of the $4.1 billion deal in which Accenture acquired a majority stake in Dragos in an OT cybersecurity push.
Researchers Escape OpenAI Codex Sandbox to Run Commands on Host
In OpenAI Codex, security researchers have identified two sandbox escape vulnerabilities, one of which allows developers to execute commands on their…
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and…
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
This post has no text preview — click the link below to read the original article. This article has been indexed from Blog Read the original article: September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972…
Burger King Russia – 3,155,792 breached accounts
In October 2024, news of a data breach exposing Burger King Russia customers broke following an August attack on the Mindbox marketing automation…
Four Linux Kernel Flaws Expose Systems to Local Root Exploits
A security researcher has publicly released working exploit code for four Linux kernel vulnerabilities that can allow local users to escalate their…
Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
CloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenance
Microsoft Confirms September 2026 Windows Updates Break File History Backups
Microsoft has confirmed that its September 2026 Windows security updates can prevent File History from creating or updating backups on some systems. The…
No Attacker Required: What a Two-Day Hackathon Taught Us About Agent Security
In this article Nineteen Check Point AI Security R&D teams spent two days on one prompt: build the demo customers would ask to see twice. Three of the…
North Korean TraderTraitor Hackers Use Fake Terraform Job Tests to Deploy macOS Backdoors
North Korean threat actors are using fake Terraform job tests to compromise macOS developers and reach cloud systems. The campaign shows how a routine…
ChainScript: the RAT that hides its command server inside a blockchain contract
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit…
ChatGPT Ad Tracking Cookie Follows Users Across Third-Party Advertiser Websites
OpenAI’s advertising measurement system appears to use a cross-site cookie that can link activity on advertiser websites to a person’s ChatGPT account.…
TerminalFix Campaign Uses PNG Steganography
A sophisticated malware campaign identified by Microsoft Security Research employs PNG image files with steganography to deliver malicious payloads…
Leaky TLS Certificate Exposes North Korea’s Hangro VPN Infrastructure Across Two Countries
North Korea’s Hangro platform has exposed an unusually detailed view of infrastructure used to connect officials and trade representatives abroad with…
FBI warns of police impersonation extortion scams
The FBI has issued an updated warning about a persistent extortion scam in which criminals impersonate law enforcement officers and federal agents to…
CrowdSec Source Code Stolen in Supply Chain Attack
Cybersecurity firm CrowdSec has confirmed that threat actors successfully stole its source code following a supply chain attack that compromised TanStack,…
