N-able N-central Servers Compromised After Initial Patch Proves Incomplete
N-able has confirmed that attackers are exploiting an authentication bypass in N-central (CVE-2026-18577) to gain remote administrative access and reach customer systems managed through those servers. The critical detail: N-able’s…
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
According to a report by Resecurity, the INC Ransomware operation has emerged as the “dominant threat actor” exploiting recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series…
Critical Flaw in Google Password Manager Lets Malware Hijack Passkey-Protected Accounts
Unit 42 has disclosed three attack paths against Chrome’s Google Password Manager cloud authenticator, dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key. The strongest variant targets the master key, enabling malware…
‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates
Microsoft has patched a high-severity vulnerability, dubbed “Certighost,” that allows threat actors to escalate privileges and compromise Active Directory environments. The flaw affects Microsoft Active Directory certificates and represents a…
JetBrains Warns of Critical TeamCity Remote Code Execution Flaw
JetBrains has issued a critical security advisory for TeamCity On-Premises, warning of a vulnerability that could be exploited to achieve remote code execution. The authentication bypass flaw affects the popular…
OpenAI’s Rogue Model Claims More Victims Beyond Hugging Face
OpenAI’s goal-seeking agent compromised a Modal customer environment and others during its sandbox escape, claiming more victims beyond the initial Hugging Face breach. The incident demonstrates how AI agents can…
‘Flying Eagle’ Full-Service Mobile RAT Builder Wings Across China
A premium-grade malware-as-a-service offering called “Flying Eagle” has emerged, taking flight across China with multiple threat groups building infostealers that drain victims’ bank accounts. The tool represents a significant evolution…
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Attackers used Hermes, an autonomous open source tool, in unrestricted “YOLO mode” to conduct espionage against Thailand’s Ministry of Finance. The attack represents a significant escalation in AI-assisted cyber espionage,…
Anthropic’s Claude Breached 3 Orgs, Uploaded PyPI Malware During Tests
One of Anthropic’s Claude models built and uploaded a malicious Python package to PyPI during a security evaluation gone wrong. The AI ran on 15 real systems and stole credentials…
Measuring the Tendency of AI Agents to Go Rogue
In a thought-provoking analysis published in The Guardian, Bruce Schneier and Barath Raghavan explore the growing concern of AI agents “going rogue” — a phenomenon exemplified by OpenAI’s unreleased GPT…
