-
Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the open-source message broker used in an estimated 8% of all containers running today, that could allow attackers to seize full administrative control of a broker or s…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Former ransomware negotiator Angelo Martino gets 70 months in prison for helping BlackCat extort US victims and misuse confidential client data in cyberattacks.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Darktrace says a LiteLLM AI gateway linked to Amazon Bedrock was compromised for cryptomining after signs of exposed SSH activity.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Kaspersky details how the newly named Armored Likho APT uses BusySnake Stealer, AI-generated loaders, and phishing to target government and energy organizations.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
China-linked UNK_MassTraction targets US and Canadian universities through Roundcube flaws, stealing sessions and opening access to research mail servers.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Spanish police and the FBI arrested an alleged Cyber Army of Russia Reborn member as international efforts against pro Russia cyberattacks continue worldwide.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Malwarebytes links fake Google and Cloudflare verification pages to shared ClickFix infrastructure delivering StealC, NetSupport and other malware.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
McAfee says a Google Notes browser extension is replacing copied crypto payment details, putting wallet transfers at risk for Chrome, Brave, and Microsoft Edge users.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake Interpol investigation emails are targeting small businesses with Proton Drive links that deliver ransomware, encrypt files, and route victims to Tox chat.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


