Tata Electronics Hit by World Leaks — 630GB Allegedly Stolen from Apple and Tesla Supplier
Summary Indian electronics and semiconductor manufacturer Tata Electronics has confirmed a cyberattack and data breach, with the “World Leaks” threat group claiming to have exfiltrated 630GB of sensitive data. Tata…
SimpleHelp Auth Bypass Weaponized to Deploy Djinn Stealer — A Cross-Platform Infostealer Targeting Cloud and AI Credentials
Summary A critical authentication bypass vulnerability in SimpleHelp (CVE-2026-48558), a popular remote monitoring and management (RMM) platform, is being actively exploited to deploy “Djinn Stealer” — a previously undocumented cross-platform…
Critical Oracle E-Business Suite Flaw Exploited in the Wild — Unauthenticated Instance Takeover via Payments Component
Summary Attackers are actively exploiting CVE-2026-46817, a critical improper privilege management and authentication flaw in Oracle E-Business Suite’s Oracle Payments component. The vulnerability allows unauthenticated attackers with HTTP network access…
Agentjacking — New Attack Class Hijacks AI Coding Agents Through Sentry Error Injection with 85% Success Rate
Summary Security firm Tenet Security has disclosed “agentjacking,” a novel attack class that enables threat actors to hijack AI coding agents — including Anthropic’s Claude Code and Cursor — by…
CISA Confirms Ransomware Gangs Exploiting BlueHammer Microsoft Defender Privilege Escalation Flaw
Summary CISA has confirmed that ransomware gangs are actively exploiting CVE-2026-33825, a high-severity privilege escalation vulnerability in Microsoft Defender dubbed “BlueHammer.” The flaw, which was initially leaked by a security…
OpenAI Previews GPT-5.6 Sol — Its Most Capable Model for Vulnerability Research Yet
Summary OpenAI has launched a limited preview of GPT-5.6 Sol, the flagship model in its new GPT-5.6 family alongside Terra and Luna variants. Currently restricted to trusted partners and the…
SANS 2026 Detection Engineering Survey: 83% Use AI Tools, but Only 42% Trust Them for Core Detection Work
The SANS 2026 Detection Engineering Survey, conducted in partnership with Anvilogic, paints a sobering picture of the state of defensive security operations. Surveying 307 practitioners across more than 10 industries,…
Polymarket Hit by Frontend Supply Chain Attack — $3.1 Million Drained from User Wallets
Prediction market platform Polymarket has confirmed a frontend supply chain attack that resulted in approximately $3.1 million being stolen from eleven user wallets. The attack, which began around June 25,…
Anthropic Accuses Alibaba of Using 25,000 Fake Accounts to Distill Claude AI — 28.8 Million Exchanges Harvested
Anthropic has accused Chinese tech giant Alibaba of orchestrating the largest known model distillation attack against its Claude AI platform. In a letter sent to the U.S. Senate Banking Committee…
Microsoft Disrupts StegoAd Campaign — Removes 119 Malicious Edge Extensions That Hid Malware in Images
Microsoft has removed 119 malicious Edge browser extensions and suspended over 90 associated developer accounts in a takedown of “StegoAd,” a long-running malware operation active since at least 2021. The…
