Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on th...
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on th...
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restricti...
Chainguard has surpassed 1 billion container build manifests, doubling production from 500 million in six months as it expands its AI-assisted software suppl...
Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named HOO...
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S.
A threat actor used frontier artificial-intelligence models and attack-specific agentic frameworks to breach an enterprise environment, harvest root credenti...
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
The implant, identified by Rapid7 Labs with medium confidence as originating from North Korean state-sponsored actors, targets entities in South Korea's auto...
The attack occurred between 07:35 UTC and 21:45 UTC on Monday, August 31.
Abliteration.ai aims to enable offensive cyber operations, red-teaming, and agent testing that other models refuse.
The cyberattack, which occurred around June 15, resulted in the theft of patient data including names, dates of birth, medical testing information, laborator...
Invisible Unicode tag characters often used for AI prompt injection have appeared in high-volume phishing attacks.
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153...
The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection. AI data company Micro1 has now offered $12.
Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to exchan...
Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets.
Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security iss...
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and...
Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campai...
A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. T...