SparkKitty is a cross‑platform mobile stealer that weaponizes users’ photo galleries, using OCR to extract sensitive text from images and silently exfiltrating it to attacker‑controlled C2 servers on both Android and iOS. Built as an apparent successor to SparkCat, the…
Category: EN
Nono: Open-source sandbox for AI agents
An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads.…
PyPI Blocks New File Uploads to Old Releases to Prevent Package Poisoning Attacks
PyPI has introduced a new supply-chain security control that prevents publishers from uploading additional files to package releases older than 14 days, reducing the risk of attackers poisoning previously trusted versions after compromising project credentials, automation workflows, or publishing tokens.…
What the identity attack surface looks like when trust becomes the target
In this Help Net Security video, Joel Moses, VP, Strategic Engineering at F5, explains how attackers use identity instead of breaking through it. He walks through MFA fatigue, session token theft, and consent given to malicious applications, using the 2022…
BlueNoroff Fake Meeting Kit Captures Webcams, Disables Defender and Steals Cryptocurrency Credentials
BlueNoroff, a financially motivated threat cluster linked to the Lazarus Group, has been observed deploying a highly sophisticated “fake meeting” phishing kit. That goes far beyond traditional lures, enabling webcam capture, Microsoft Defender evasion, and targeted cryptocurrency credential theft. New…
Eight NodeBB Vulnerabilities Let Hackers Read Your Private Chats and Take Over the Forum
Eight high-severity vulnerabilities have been discovered in NodeBB, a popular Node.js-based forum platform, exposing millions of users to risks including private message leaks, stored cross-site scripting (XSS), and full forum compromise. The issues affect all NodeBB versions prior to 4.14.0…
Google Indexed Claude AI Shared Chats Exposing Sensitive User Conversations
Anthropic’s Claude includes a share feature that creates a publicly accessible URL for conversations, allowing users to share AI chats with colleagues, clients, or friends. However, this convenience also brings exposure risks when shared URLs are posted in public forums,…
Product showcase: LastPass Authenticator brings Face ID, Apple Watch, and cloud backup to 2FA
LastPass Authenticator is a free app that provides two-factor authentication (2FA) for accounts and any service that supports time-based one-time passwords (TOTP). It supports push notifications for one-tap approvals and generates six-digit verification codes for online accounts. The app is…
MCBS Data Breach Affects 1.2 Million Individuals
The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company. The post MCBS Data Breach Affects 1.2 Million Individuals appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the…
GitLab RCE Flaws Allow Attackers to Execute Commands via Malicious Jupyter Notebooks
A critical remote code execution (RCE) vulnerability chain in GitLab’s Jupyter Notebook diff renderer. This issue is rooted in two long-standing memory safety vulnerabilities within the Oj Ruby JSON parser. The vulnerabilities impact both GitLab Community Edition and Enterprise Edition…
GitHub delays version updates so malware gets caught first
An automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job it was built to do. In September 2025, that speed cut the…
ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024, (Mon, Jul 27th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Monday, July 27th, 2026 https://isc.sans.edu/podcastdetail/10024,…
Hotel Wi-Fi Hijack, Six Years For A Snapchat Predator, Chicken on the hacking menu globally
Hotel Wi‑Fi steals Microsoft 365 logins, ShinyHunters sextortion spam, and Chick‑fil‑A stuffed again Hotel and conference Wi‑Fi networks are being hijacked to harvest Microsoft 365 credentials by compromising captive portals and DNS, redirecting travelers to convincing lookalike logins and even…
Claude Opus 5 sharpens coding and cybersecurity work on AWS
Claude Opus 5 went live on Amazon Bedrock and Claude Platform on AWS. Anthropic says the model improves on Claude Opus 4.8’s cyber capabilities, coding through cybersecurity. Anyone with an AWS account in a supported region can call it. On…
How the Bing Images RCE Flaws Actually Worked, and How to Check Your Own Pipeline
A three-line SVG gave XBOW SYSTEM access on Bing's servers through a default ImageMagick setting. Here's the exploit chain and a checklist for anyone running a similar image pipeline. How the Bing Images RCE Flaws Actually Worked, and How to…
ENCFORGE Ransomware Targets AI Models After Langflow RCE Exploit
An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known Langflow RCE and pivoting via an exposed Docker socket. ENCFORGE Ransomware Targets AI Models After Langflow RCE Exploit on Latest Hacking News…
Azure DevOps MCP Flaw: How to Lock Down Your AI Review Agent Before Microsoft Patches It
A practical checklist for the Azure DevOps MCP flaw that lets hidden PR comments hijack AI coding agents, plus the configuration changes to make right now. Azure DevOps MCP Flaw: How to Lock Down Your AI Review Agent Before Microsoft…
Chaos Ransomware’s msaRAT Hides Its C2 Inside Your Own Browser
Cisco Talos has detailed msaRAT, a Rust-based RAT used by the Chaos ransomware crew that drives a headless Chrome or Edge session over CDP to smuggle C2 traffic through Cloudflare and Twilio infrastructure. Chaos Ransomware’s msaRAT Hides Its C2 Inside…
How the Fastjson RCE Vulnerability Actually Works, and How to Check You’re Exposed
A practical checklist for the Fastjson RCE vulnerability (CVE-2026-16723): how the exploit chain works, four questions to answer this week, and how to mitigate it before a patch exists. How the Fastjson RCE Vulnerability Actually Works, and How to Check…
Shark Vacuum Vulnerability Lets Attackers Hijack Cameras Across an Entire AWS Region
A researcher found that anyone with physical access to one Shark robot vacuum can extract its AWS IoT certificate and use it to take over other Shark vacuums region-wide, with no patch yet available. Shark Vacuum Vulnerability Lets Attackers Hijack…
