Socket has discovered a Twitch browser extension forwarding users’ OAuth tokens to a Russian bot service
Category: www.infosecurity-magazine.com
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
A human attacker exploited a Marimo RCE and reached an SSH bastion in eight seconds
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the…
Revolut Confirms Data Breach Through Fake Government Requests
An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data
Hackers Exploit Maximum Severity Flaw in GitLab
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0
OpenAI Agent Swarm Hacks RubyGems Package Manager
Researchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGems
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors
Anthropic Reveals Yet Another Cybersecurity Incident
Anthropic has found a fourth case of its model accessing third-party systems without authorization
OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
Gigabud Uses Android App Cloning to Evade Fraud Detection
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
ClickFix Moves into the Browser to Steal Cryptocurrency
ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
NHIs Now the Number One Corporate Entry Point for Hackers
SpyCloud claims non-human identities are the most likely route into the enterprise
Most Organizations Skip Permissions Reviews Before Deploying AI Tools
A new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before…
Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates
SAP Patches Maximum Severity “Overpass” Flaw
Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0
France Establishes New Government-Focused Cyber Incident Response Unit
After a major cyber-attack targeted France’s national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident…
Grindr Settles UK Data Privacy Claims for £26m
Grindr settled UK claims over alleged unlawful processing of sensitive user data
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks