The commercial phishing-as-a-service (PhaaS) toolkit called Greatness, distributed via Telegram that uses token theft with device code and…
Mac Malware Found Draining Crypto Wallets After Fake CAPTCHA Trick
Researchers at Huntress have uncovered a strain of macOS malware that can gradually siphon funds out of victims’ cryptocurrency wallets, after tracing an…
Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera…
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
One of Meta’s AI models exploited a third-party security flaw during an evaluation, the latest in a series of similar incidents involving advanced AI…
Shared C2 Kit Links State & Criminal Operators
Security researchers analyzing state-sponsored intrusion campaigns have documented a fundamental shift in how nation-state actors build their operational…
Photos: Black Hat USA 2026
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors:…
Apple bug bounty flooded with AI-generated reports
Apple has introduced new submission restrictions on its bug bounty portal following a surge of AI-generated vulnerability reports that threatened to…
Critical Paperclip AI Agent Flaws Allow Unauthenticated Remote Code Execution
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed…
Coldcard hackers launder $4.5M in BTC/ETH
Threat actors responsible for exploiting Coldcard hardware wallets have moved $4.5 million in stolen cryptocurrency through mixing protocols in an attempt…
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities.…
Windows 10 LTSC 2021 ESU pricing announced
Microsoft has announced pricing for Extended Security Updates (ESU) for Windows 10 Enterprise LTSC 2021, which reaches end of support on January 12, 2027.
Fake Xeno Roblox Executor Delivers Powercat Java Stealer Through Discord
The fake “undetected” Xeno Roblox executor currently circulating on gaming forums and Discord is a weaponized loader for the Powercat Java stealer, a…
75% of European businesses fear US tech kill switch
Three-quarters of European businesses fear losing access to US-based technology services through what researchers call a kill switch scenario, according…
Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway
(Video) In this podcast, we share insights from Edna Conway, a recognized leader in cybersecurity and supply chain resilience with over 40 years of…
Apple iCloud Private Relay Leaks Users Real IP Addresses via WebKit Flaws
Security researchers have uncovered three critical WebKit vulnerabilities that expose users’ real IP addresses and DNS information—even when…
Scammers target OnlyFans users with deepfakes
Criminals are impersonating OnlyFans creators using AI tools in order to scam followers.
Cloudflare Launches Open-Source OS to Secure AI Agents’ Access to Internal Data
Cloudflare has open-sourced Cloudflare OS, a platform designed to provide enterprise AI agents with controlled access to internal systems, company…
Canadian Man Pleads Guilty for Hacking U.S. Cloud Storage Provider
Connor Riley Moucka, a 26-year-old resident of Kitchener, Ontario, has pleaded guilty in the United States for his role in a major computer hacking and…
Violent Physical Crypto Thefts Surge to $30m in Losses
So-called “wrench attacks” have resulted in $30m in losses so far in 2026, says Chainalysis
AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses…
Snowflake hacker pleads guilty, faces up to 32 years in prison
A Canadian man is facing decades in prison for hacking customer accounts at cloud storage provider Snowflake and stealing data from more than 165…
Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched.
Vanta Stealer Uses PyArmor to Steal Browser Passwords, Crypto Wallets and Discord Tokens
Vanta Stealer is a Python‑based, cross‑platform information stealer that uses layered PyArmor obfuscation on top of a PyInstaller‑packed executable to…
Critical Jenkins Vulnerability Allows Attackers to Execute Malicious Code on Controller
Jenkins has disclosed a critical security vulnerability that could allow attackers to execute malicious code on a Jenkins controller by bypassing a…