Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada.
TeamPCP Traced Back to 2020 Cryptojacking Operation
Oligo Security has linked TeamPCP to ShadowRay 2.0 and to cryptojacking infrastructure dating back to 2020
One Fake Movie Download Can Expose Passwords, Payments and Crypto Assets
Cybercriminals are weaponizing pirated downloads of the blockbuster theatrical release “The Odyssey (2026)” to deliver Lumma Stealer. This prolific…
CISA Warns of Exploited Langflow, N-central, Tomcat Flaws
The Cybersecurity and Infrastructure Security Agency has issued warnings about three vulnerabilities now under active exploitation in the wild.
OpenAI and Anthropic AI Agents Crossed Testing Boundaries During Cybersecurity Evaluations
A separate cybersecurity evaluation conducted by OpenAI and Anthropic revealed that artificial intelligence models were behaving in unexpected ways…
Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents
Researchers disclosed critical flaws in AI coding agents from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain…
Greatness PhaaS Uses Phishing Code to Escape 2FA and Attacks Microsoft 365 Users
The commercial phishing-as-a-service (PhaaS) toolkit called Greatness, distributed via Telegram that uses token theft with device code and…
Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick
Researchers at Huntress have uncovered a strain of macOS malware that can gradually siphon funds out of victims’ cryptocurrency wallets, after tracing an…
Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera…
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI…
Shared C2 Kit Links State & Criminal Operators
Security researchers analyzing state-sponsored intrusion campaigns have documented a fundamental shift in how nation-state actors build their operational…
Photos: Black Hat USA 2026
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors:…
Apple bug bounty flooded with AI-generated reports
Apple has introduced new submission restrictions on its bug bounty portal following a surge of AI-generated vulnerability reports that threatened to…
Critical Paperclip AI Agent Flaws Allow Unauthenticated Remote Code Execution
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed…
Coldcard hackers launder $4.5M in BTC/ETH
Threat actors responsible for exploiting Coldcard hardware wallets have moved $4.5 million in stolen cryptocurrency through mixing protocols in an attempt…
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities.…
Windows 10 LTSC 2021 ESU pricing announced
Microsoft has announced pricing for Extended Security Updates (ESU) for Windows 10 Enterprise LTSC 2021, which reaches end of support on January 12, 2027.
Fake Xeno Roblox Executor Delivers Powercat Java Stealer Through Discord
The fake “undetected” Xeno Roblox executor currently circulating on gaming forums and Discord is a weaponized loader for the Powercat Java stealer, a…
75% of European businesses fear US tech kill switch
Three-quarters of European businesses fear losing access to US-based technology services through what researchers call a kill switch scenario, according…
Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway
(Video) In this podcast, we share insights from Edna Conway, a recognized leader in cybersecurity and supply chain resilience with over 40 years of…
Apple iCloud Private Relay Leaks Users Real IP Addresses via WebKit Flaws
Security researchers have uncovered three critical WebKit vulnerabilities that expose users’ real IP addresses and DNS information—even when…
Scammers target OnlyFans users with deepfakes
Criminals are impersonating OnlyFans creators using AI tools in order to scam followers.
Cloudflare Launches Open-Source OS to Secure AI Agents’ Access to Internal Data
Cloudflare has open-sourced Cloudflare OS, a platform designed to provide enterprise AI agents with controlled access to internal systems, company…
Canadian Man Pleads Guilty for Hacking U.S. Cloud Storage Provider
Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has pleaded guilty in the United States for his role in a major computer hacking and…