Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on…
Tag: EN
N-able N-central Vulnerability Under Active Exploitation
Threat actors are actively exploiting an N-able N-central vulnerability that can grant unauthenticated administrative access.
AI slop pollutes the CVE pipeline with fake vulns
With NIST still buried under its backlog, expect AI-generated bogus reports to continue
DNA Test Software Vulnerability Allows Attackers to Alter Analysis Data
Thermo Fisher Scientific has disclosed a high-severity security flaw affecting several of its Applied Biosystems Human Identification (HID) software…
More on the OpenAI Agent’s Attack on Hugging Face
Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based…
Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
Amazon linked four npm supply-chain attacks to North Korea’s Sapphire Sleet, exposing the security risks posed by compromised maintainer accounts.
Public PoC Released for Critical Rails Active Storage RCE Vulnerability
A critical vulnerability in Ruby on Rails has raised new concerns about cloud data breaches, particularly for companies that host customer platforms in…
Hugging Face Breach Raises Concerns Over AI-Driven Attacks
Hugging Face is investigating a security incident after its production infrastructure was compromised in an intrusion the company says involved an…
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at…
AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek
Unit 42 uncovered an AI-driven Chinese hacking campaign where DeepSeek autonomously scanned targets, selected exploits, and launched attacks. Researchers…
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access…
OT security coalition urges Congress, CISA to enact reforms amid water sector hacks
Iran-nexus hackers are suspected in a broad campaign targeting drinking and wastewater sites in at least seven U.S. states.
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Register for an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents Talos IR faced in Q2.
AI Adoption Shifts Focus Toward Data Governance and Enterprise Trust
The rise of artificial intelligence (AI) is uncovering vulnerabilities in enterprise data governance, as organizations grapple with managing information…
TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as…
Russian spies turn public Wi-Fi into malware delivery systems
Keyloggers, audio-visual surveillance, and token theft on CaptivePortal’s agenda as hospitality sector put on alert
Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)
Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas.
Hugging Face Diffusers Vulnerabilities Enable Remote Code Execution Through Malicious AI Models
A set of high-severity vulnerabilities in Hugging Face’s diffusers library that allow a malicious model repository to silently execute arbitrary code on…
China-based hacker employs DeepSeek in autonomous threat campaign
Researchers said the hacker also attempted to test Western AI tools, but ultimately was forced to revert to manual operations to succeed.
Android RAT Survives Reboots Using Watchdog Services and Boot Receivers
Android users are facing a new remote-access threat that hides behind a fake emergency alert application. The malware, called Octagon, poses as Bahrain’s…