France’s tax authority has confirmed a data breach affecting approximately 678,000 individuals and businesses after threat actors gained unauthorized…
Tag: EN
Anthropic Launches New /design Skill for Claude Code UI Workflows
Anthropic has introduced a new /design skill for Claude Code, expanding its developer-focused AI platform into user interface design workflows. The…
Project noRecognition: Teaching AI to Fool Surveillance Cameras
Researchers tested 31 million patterns to disrupt surveillance AI, with promising results but significant gaps between simulation and real-world use. The…
Critical MLflow SSRF Vulnerability Exploited by Hackers in the Wild
Threat actors are actively exploiting a critical, unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, the popular open-source…
Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using…
Microsoft 365 Search Outage Disrupts SharePoint, OneDrive, and Outlook Users Worldwide
Microsoft is actively managing a service disruption that has left a subset of enterprise users unable to search for content across SharePoint Online,…
Security Hub Extended adds Supply Chain Security as its tenth category
Since February, we’ve grown AWS Security Hub Extended from 14 curated partners across 9 categories to 23 partners across 10. At Black Hat this month, 14…
Hackers Hijack Thousands of WordPress Sites to Use as C2 Servers for StopAndProtect Malware
A newly uncovered malware operation dubbed StopAndProtect is transforming thousands of hacked WordPress websites into a sprawling criminal…
Comcast adds motion sensing to millions of its newer routers, with a privacy catch
A new feature added to Comcast’s newest routers can detect if there is motion is inside your home without needing traditional motion sensors.
Projextor Shows How Malware Can Hide Behind Trusted Electron Executables
Projextor is a malware campaign that turns ordinary-looking desktop tools into a doorway for hidden code. Its operators package it inside working document…
DevSecOps Tutorial: Embedding Security into CI/CD Pipelines (2026)
By HOC Team | Last updated: August 2026 | Read time: ~25 min In December 2020, security researchers…
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher
Bluesky says its recent outage was caused by another DDoS attack
This is the latest large-scale DDoS attack to hit the social networking site this year.
BTMob Fraud-as-a-Service Platform Uses 1,400 Live Servers to Power Android Device Takeovers
BTMob is an Android banking malware platform built to turn phones into tools for fraud. It reaches victims through fake apps, cloned download pages, and…
GitLab issues emergency patch for critical code-injection flaw
Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects.
C2Looper Updates Itself Through OneDrive DLL Sideloading to Evade Detection
C2Looper is a newly identified backdoor that gives attackers a quiet way to control a compromised Windows computer. It can run commands, inspect the…
CISA gives feds 3 days to fix actively exploited Ray RCE bug
Phishing, malvertising attacks could target devs to gain access to private corporate networks
Webinar Today: Rethinking Cyber Defense for AI-Speed Attacks
Join the live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest…
Vatican’s Official Prayer App Exposed Data of Over 700,000 Users
There was a security flaw in the Vatican’s official Click to Pray application that exposed personal information linked to more than 700,000 registered…
LiteLLM in the crosshairs: Supply Chain Attack on AI Infrastructure
Users of LiteLLM may have become targets of an attacker group. As early as March, it became known that the “TeamPCP” group had managed to obtain…