-
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host env…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A coordinated supply-chain campaign has been weaponizing GitHub proof-of-concept (PoC) repositories to compromise vulnerability researchers and penetration testers, delivering a stealthy Python Remote Access Trojan (RAT) dubbed “ChocoPoC.” The lure is …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An incident that began with innocuous enumeration commands but quickly escalated into a focused, multi-stage effort to impair detection and extract credentials. The intruder uploaded a steganographic webshell to an IIS server, used the process w3wp.exe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale password spray campaign linked to the infrastructure provider LSHIY LLC has targeted Microsoft 365 environments, resulting in over 81 million login attempts. This campaign has led to at least 78 confirmed account compromises across 64 org…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A novel, practical ransomware technique that runs entirely inside the browser by abusing the File System Access API, demonstrating how AI can turn high-level malicious ideas into operational attack chains without any native payload. The proof-of-concep…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Two significant remote code execution (RCE) vulnerabilities in the widely used Cursor ID expose developers to zero-click attacks driven by prompt injection. These vulnerabilities, tracked as CVE-2026-50548 and CVE-2026-50549, collectively known as R…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate crede…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
U.S. authorities have announced federal charges against an alleged member of the notorious cybercriminal group Scattered Spider, following his arrest in Finland and extradition to the United States. The defendant, identified as 19-year-old Peter Stokes…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Technically sophisticated campaign delivering a malicious Chromium extension that silently swaps cryptocurrency wallet addresses during transactions. Delivered via unsigned installers observed in both .NET and Golang variants access, the payload masque…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
MacSync Stealer is a newly discovered macOS infostealer actively distributed through a sophisticated malvertising campaign on Google Ads that impersonates Anthropic’s Claude Code CLI. Security researchers from Beezlebub have uncovered the complete atta…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


