A Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts, execute shell…
Category: EN
Somewhere in your traffic logs, a bot is doing more than looking
Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of…
Rogue AI agents put trusted access under scrutiny
Two newly disclosed incidents involving rogue AI agents are raising questions about what happens when autonomous software operates through apparently…
WordPress Patches ‘Click2Shell’ Vulnerability
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
Researchers used Claude to hack OpenAI
Claude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and…
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something…
Top 10 Best Passwordless Authentication Solutions in 2026 [Ranked & Scored]
The password’s obituary has been written for a decade, but 2026 is the year the funeral actually gets scheduled: platform passkeys are mainstream,…
North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
North Korean hackers are using fake Terraform job tests to deploy macOS backdoors and target developer access to cloud infrastructure.
Texas utility CenterPoint confirms breach after attacker leaks customer data
Texas utility CenterPoint Energy has confirmed a data breach after a threat actor published customer information online and claimed to have stolen around…
CISA Warns of Zyxel GS1900 Switches Flaw Actively Exploited in Attacks
CISA added CVE-2026-7273, a critical stack-based buffer overflow in the CGI program of Zyxel GS1900 Series Switches, to its KEV catalog after confirming…
Orkes Conductor RCE Draws Nearly 7,000 Exploit Attempts
A critical Orkes Conductor flaw is under active attack, with 6,696 exploit attempts blocked in a week. Defenders should upgrade to version 3.30.2 or later.
Top 10 Best Customer Identity & Access Management (CIAM) Solutions in 2026 [Ranked & Scored]
Customer identity is where security meets revenue: every point of login friction costs conversions, while every authentication gap invites account…
Gemini crosses the line in cybersecurity test
Google has confirmed that its Gemini AI accessed systems belonging to three companies during a cybersecurity evaluation after mistaking them for targets…
ZTE SmartLife Flaws Let Attackers Hijack Accounts by Resetting Passwords Without Verification
ZTE has addressed four vulnerabilities in its SmartLife mobile application following the discovery of critical weaknesses that allowed attackers to…
Vidar Malware Rewrites Its Obfuscation With Every Build to Make Detection Harder
Vidar has spent years stealing the data people keep closest: saved passwords, browser cookies, wallet files and system details. Now its operators have…
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to…
Hackers Steal NTDS.dit to Dump Active Directory Password Hashes and Forge Golden Tickets
Threat actors that gain a foothold in a Windows network are increasingly aiming for the domain controller, the server that manages identities and…
The Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in…
Top 10 Best Identity Threat Detection & Response (ITDR) Tools in 2026 [Ranked & Scored]
The modern breach doesn’t kick the door in it signs in. Stolen sessions, abused service accounts, and helpdesk-reset social engineering made identity the…
