A newly analyzed DarkCrystal RAT (DCRat) campaign shows how threat actors are turning an apparently harmless SVG attachment into a full malware-delivery…
Tag: EN
1.6 Million Likely Impacted by RingCentral Data Breach
The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.
Crypto wallet maker Trezor confirms 13,000 customers’ details exposed in logistics breach
Even if your hardware is secure, quantum-ready, encrypted, and future-proof, no one is immune to a supplier letting the side down
Dysphoria Hijacks Routers, Gateways and IP Cameras to Build Massive IoT Botnet
The Dysphoria botnet has expanded into a major Internet of Things threat, with a new Shadowserver Special Report identifying approximately 296,000…
Brit rail cops bring live facial recognition to the London Underground
Victoria is the first stop as privacy campaigners warn the technology is becoming routine
‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware
Experts allege that two recent incidents in California show the extreme lengths that criminal organizations are willing to go to to steal servers and…
Over 1,000 Charities Hit by Beacon CRM Data Breach
The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.
Nvidia Releases Open, Lightweight Nemotron AI Model
AI chip giant releases Nemotron 3.5 Lightning under open-weight licence, as it reportedly works on large-scale challenger with 1 trillion parameters
Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping
7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange…
Hackers Using New BlackHat AI Tool MessiahGPT to Generate Ransomware and Phishing Kits
A newly surfaced criminal AI service called MessiahGPT is being openly marketed on BreachForums as a purpose-built offensive model that writes ransomware,…
Russian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PL
The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country
OpenAI Unveils Ultrafast Mode in GPT‑5.6 Sol That Works 14× Faster Than Standard Mode
OpenAI has introduced Ultrafast, a new service tier for GPT-5.6 Sol that it says can run up to 14× faster than Standard processing. The feature launches…
Trump Signs Memorandum Allowing Private Firms to Launch Offensive Cyber Operations Against Foreign Threat Actors
President Trump has signed a national security presidential memorandum allowing federal law enforcement agencies to partner with private technology…
AI Token Jacking Lets Hackers Steal API Keys and Rack Up Nearly $1 Million in Charges
AI credentials are drawing criminal attention. A growing form of abuse, called AI token jacking, lets intruders take API keys and consume expensive model…
AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers
AmnesiaStealer targets macOS users through fake GitHub pages, stealing passwords, cookies and data while giving attackers live control of the browser.…
GeoServer 0-Day Vulnerability Enables Remote Code Execution Attacks
A newly disclosed zero-day vulnerability in GeoServer is being targeted by attackers, raising concern for organizations that publish or manage geospatial…
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.…
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections…
Prompt Injections for Defense
This seems to work : Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other…
Scottish prosecutors cast eye over leaky supplier after staff data exposed
Unnamed third party spotted suspicious activity, with names, roles, and email addresses potentially affected
