loader image
Hackers Hijack AI Tools to Launch Malicious Payloads

Hackers are exploiting misconfigured artificial intelligence tools to launch sophisticated cyberattacks by generating malicious AI-powered payloads, according to researchers at Sysdig. These intrusions leverage exposed APIs, unsecured machine learning environments, and open-source platforms like Jupyter and TensorFlow to gain unauthorized access. Once inside, attackers use the compromised AI infrastructure to create dynamic, context-aware malware, phishing […]

Anthropic MCP Flaws Expose AI to Secret-Leaking Hacks

Researchers have disclosed critical security flaws in Anthropic’s Model Context Protocol (MCP), highlighting the risk of stealthy exploitation in production environments. According to newly published findings, attackers can execute Full-Schema Poisoning attacks, injecting malicious logic into any schema field within MCP. This vulnerability enables adversaries to manipulate model behavior without detection during development or testing […]

Salesforce Fixes 5 Flaws, Blames Users for 16 More

Salesforce has patched five software bugs after a series of issues were reported, the customer relationship management (CRM) provider confirmed. The company said it addressed the vulnerabilities internally and emphasized that the remaining 16 reported concerns were the result of customer-side misconfigurations, not flaws in its platform. The disclosure follows heightened scrutiny of cloud application […]

Microsoft Adds Export Tool to Windows Recall in EU

Microsoft has introduced a new export feature for its Windows Recall tool in Europe, giving users the ability to back up snapshots of their digital activity. The update allows individuals to manage and preserve their Recall data more securely, addressing privacy concerns tied to the tool’s automatic screen capture function. Microsoft Adds Export Tool aims […]

Crypto CEO’s Zoom Slip Costs Him $200,000 in Scam

A cryptocurrency executive inadvertently exposed sensitive information during a Zoom call, leading to a costly breach that unraveled his digital life. The incident occurred when the CEO shared his screen during a virtual meeting, unknowingly revealing private access credentials. The mistake provided cybercriminals with a gateway into his accounts, resulting in the loss of $200,000. […]

Chinese Hackers Forge LAPD Cert in Infrastructure Hit

A cybercrime group resembling a typhoon in reach and disruption has constructed a network of more than 1,000 compromised devices, according to a new report. The attackers, identified as Chinese hackers, forged an apparently legitimate TLS certificate claiming to be signed by the Los Angeles Police Department (LAPD), in an effort to disguise malicious traffic. […]

Cisco Flags 10.0-Rated Flaws in Identity Software

Cisco has issued an urgent warning regarding critical security flaws in its Identity Services Engine (ISE) platform, with vulnerabilities rated at the highest severity level. The company flagged the issues as part of its latest security advisory, stating that the flaws could allow remote attackers to execute arbitrary code on affected systems. Cisco flags 10.0 […]

Estonia Seeks Moroccan in Pharmacy Data Breach

Estonian authorities have issued an arrest warrant for a Moroccan national suspected of breaching a sensitive customer card database belonging to Allium UPI, the parent company of the Apotheka pharmacy chain. The intrusion, which occurred in February 2024, reportedly involved unauthorized access to confidential user data, prompting a criminal investigation into the breach. Details about […]

**Splunk Web Flaw Lets Hackers Run Rogue JavaScript Code**

Splunk Inc. has disclosed a cross-site scripting (XSS) vulnerability in its Enterprise and Cloud Platform products that could allow low-privileged users to execute unauthorized JavaScript code. Tracked as CVE-2025-20297, the flaw resides in the PDF generation feature, specifically the pdfgen/render REST endpoint within the Splunk Web interface. The security issue carries a CVSSv3.1 score of […]

Mirai Botnet Hacks TBK DVRs Using Injection Flaw

A newly discovered strain of the Mirai botnet malware is targeting TBK DVR-4104 and DVR-4216 digital video recorders by exploiting a command injection vulnerability, according to cybersecurity researchers. The flaw allows attackers to remotely execute malicious code on vulnerable devices, effectively hijacking them and adding them to the Mirai botnet network. The malware variant leverages […]

Black Basta Veterans Target Firms via Teams, Python

Former affiliates of the Black Basta ransomware group have resurfaced with renewed cyberattack strategies, leveraging familiar and emerging techniques to breach corporate networks, according to a report by ReliaQuest. The attackers continue to rely on email bombing and phishing lures delivered through Microsoft Teams — methods previously linked to their operations — to gain initial […]

Microsoft Halts Windows 11 Update Over Glitches

Microsoft has delayed the full rollout of its Windows 11 24H2 update, citing unspecified technical issues that surfaced during its latest Patch Tuesday cycle. The company is throttling the distribution of the update to users, signaling potential instability or compatibility concerns that emerged after its initial release. The decision to slow deployment suggests Microsoft is […]