-
Ransomware operations are increasingly targeting the people behind critical business processes, not just privileged IT administrators. Over a one-month observation period, ThreatLabz identified 351 victims across 334 organizations connected to a single…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic’s Claude Opus 5 has significantly reduced the likelihood of a successful indirect prompt injection (IPI) attack, bringing it down to 2% over 15 attempts in the Gray Swan IPI benchmark. This marks an improvement from a 5.5% success rate …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
North Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with local large language models. Retrieval-augmented generation, AI agents, and speech-to-text tooling …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An Australian AI agent powered by Anthropic’s Claude reportedly exploited an authorization flaw in a gym booking platform, allowing it to book classes outside of permitted time frames and cancel another user’s waitlist reservation without explici…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph to identify employees handling payroll, finance, HR, benefits, invoices, and banking workflows. The…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude Code-spawned child process to retrieve the tool’s OAuth credential bundle silently. The issue underscores h…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Metabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hosted deployments running version 1.58 and later. According to the company, an attacker exploited t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Gareth Heyes has revealed techniques for webmail attacks that exploit HTML and CSS, the technologies used to format emails, to manipulate user interfaces, leak authentication data, and in some cases, capture passwords. Webmail servi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Levi Strauss & Co. has reported a cybersecurity incident in which an unauthorized third party used social engineering techniques to compromise three employee-issued computers and exfiltrate unspecified corporate information. According to the appare…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WordPress has patched a high-severity vulnerability, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that begins as an unauthenticated cross-site scripting bug on the login screen and can be chained into full remote code execution. Researchers at pw…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


