Anthropic revealed Thursday that three of its Claude AI models escaped test environments and successfully breached real-world companies during security…
Category: EN
Cybercrime goes subscription: AI, malware and infrastructure on demand
Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These…
Attackers abuse Microsoft auth for phishing
Cybercriminals have shifted tactics in phishing campaigns by exploiting Microsoft’s legitimate authentication infrastructure rather than deploying fake…
What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery
An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature…
CVE-2026-63077 TeamCity RCE Vulnerability
JetBrains has disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that enables remote attackers to execute arbitrary…
Keycloak Flaw Exposes Users’ Personal Data to Restricted Admins
A broken access control vulnerability in Keycloak could allow unauthorized administrator accounts to access users’ personal information. This issue,…
IBM: Average Data Breach Cost Hits $5M
The global average cost of a data breach has climbed to $4.99 million, marking a 12% increase over the previous year and setting a new record, according…
Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire
A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao…
120 fake Walmart stores stealing credit cards
A network of more than 120 fraudulent websites impersonating Walmart is actively stealing credit card information from online shoppers.
XRP Volatility Surges as Cybersecurity Threats and Market Changes Raise New Concerns
XRP volatility drives faster crypto trading as AI tools gain traction, while phishing, exchange attacks and automation risks test digital asset safeguards.
CISA adds Arista and Fortinet flaws to KEV catalog
The U.S.
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Palo Alto Networks’ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks…
Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations
Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and…
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing – the abuse of the OAuth 2.0 device authorization grant to steal access tokens – has evolved from a niche red-team technique to an…
Mythos Asks the Right Question. It Doesn’t Answer It.
AI is compressing exploit timelines. The real question isn’t whether your vulnerability management playbook needs to change, it’s which part of it you’ve…
Facial Recognition at Madison Square Garden
Last month, the story broke (alternate link ) that Madison Square Garden uses facial recognition software on everyone entering the facility, and—among…
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.…
Ransomware Killers Overwrite Security Process Memory Without Terminating Applications
Ransomware operators are increasingly deploying “ransomware killers” that surgically overwrite the memory of security processes instead of simply…
Fake Flash Player installs AtlasRAT
Researchers have uncovered a new campaign that spreads the AtlasRAT remote access Trojan by disguising it as a Flash Player installer.
Managing cyber-physical risk in smart buildings
Smart buildings promise greater efficiency, improved sustainability and enhanced operational oversight. However, as building management systems, security…
