A new frontier artificial intelligence model, Gemini 4 Argon, has been introduced by Google through its Fairwind Program for initial distribution to…
When Productivity Extensions Become Attack Platforms
Our research uncovered a campaign of 32 malicious browser extensions that uses remote configs to spy on 9,800+ users and hijack browsing activity.
The Silent Container Death: A TCP Dial That Never Times Out
A pod goes into CrashLoopBackOff . You pull the logs expecting a stack trace, a panic, an error string – anything that points you somewhere. Instead, you…
FTC Probes OpenAI, Anthropic as AI Agent Safety Risks Draw Scrutiny
The FTC is investigating OpenAI, Anthropic and other AI firms over potential consumer harms, safety claims and risks tied to increasingly autonomous AI…
In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report,…
Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials
Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying…
Pentagon Confirms Breached 3 Million DMDC Personnel Database
HOC Shorts The Pentagon confirmed a major data breach involving the Defense Manpower Data Center (DMDC), exposing sensitive…
Unidentified Flock Cameras in Florida
St. Lucie County in Florida discovered ( alt link ) a dozen Flock cameras whose ownership it can’t identify, and that the county government had not…
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to…
Meta disputes claim that Muse read a user’s private messages without permission
Meta says its Muse AI agent cannot access a user’s Messages without explicit permission, disputing a journalist’s account that the agent read his private…
Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data
Security researchers at Huntress have detailed a multi-stage intrusion in which a threat actor compromised three web servers belonging to a popular…
101 Malicious npm Packages Secretly Enroll Developers into WhatsApp Spam Channels
Researchers at OX Security have flagged 101 npm packages that silently subscribe developers to WhatsApp spam channels the moment they are installed. The…
16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
It’s 2 am. Do you know what your teen is doing?
AI Agents Attempt SQL Injection While Searching Government Data
AI agents probing US and Canadian government sites made SQL injection attempts while seeking data, but investigators found no evidence of compromise.…
iPhone Security Warning: Apple Says iOS 26 Flaw May Have Been Exploited
Apple patched an iPhone flaw that may have been exploited in targeted attacks. Here’s what iOS 26 users need to know and how to update.
Hackers steal protective order and foster care records from Arizona courts
Attackers copied sensitive court records, including more than 150,000 foster care reports, raising privacy and safety concerns for those Arizonans…
Global Group Ransomware Abuses WinMerge to Deploy Encryptor
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large…
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect.…
Mass exploitation of Citrix NetScaler: What we currently know
Suspected state-linked actors targeted critical vulnerabilities in the widely used platform, causing widespread disruption across Europe and North America.
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of…
Ship fast, verify independently: keeping application security in step with AI-written code
AI coding assistants have transformed how quickly software can be built, but they have also intensified a long-running tension between development speed…
84% of Indian SMEs Plan Higher Cybersecurity Spending as Readiness Gaps Remain
A large proportion of Indian small and medium enterprises (SMEs) plan to boost cybersecurity spending in the next 12-24 months yet experience gaps in…
OpenAI’s wandering AI agents earn it a California subpoena
Plus: Attorneys-general say investigators should have direct access to AI companies’ records when things go wrong
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that…
