U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

A massive online scam has been disrupted, with US authorities freezing over $52.8 million in cryptocurrency linked to Xinbi Guarantee, a notorious marketplace for fake financial guarantees and stolen identities. The operation, which allowed scammers to sell fake identities and exploit vulnerable individuals, has been brought to its knees by a coordinated effort between law … Read more

Over 36,000 exposed Plex servers vulnerable to recent flaws

Over 36,000 Exposed Plex Servers Remain Unpatched Against Security Vulnerabilities A staggering 36,000+ Plex Media servers exposed online remain vulnerable to attacks due to unpatched security vulnerabilities. The affected servers are running on outdated versions of Plex Media Server v1.43.2 and earlier, leaving their users open to potential cyber threats. Plex issued a warning last … Read more

MFA’s Weakest Link: Account Recovery Is the New Attack Path

Account Recovery Processes Exposed as Vulnerable Weak Link in Multi-Factor Authentication In a disturbing trend, hackers are increasingly targeting account recovery processes to gain unauthorized access to sensitive systems. This tactic exploits a weakness in multi-factor authentication (MFA) mechanisms, which have become the norm in modern cybersecurity. By focusing on the process of resetting or … Read more

Veradigm warns of patient data breach after ransomware gang claims attack

Veradigm has disclosed a patient data breach after a cybersecurity incident at one of its third-party vendors exposed sensitive information for thousands of individuals. The company, which supplies electronic health records and other software to medical practices across the United States, says the breach did not disrupt operations but affected a small number of customers. … Read more

US says Chinese firms extracted billions of tokens from frontier AI models

US Intelligence Agencies Expose Chinese Firms’ Industrial-Scale Theft of AI Models A shocking joint advisory from top US cybersecurity and intelligence agencies reveals that six Chinese AI companies have been conducting industrial-scale distillation attacks on American frontier AI models, extracting billions of tokens since at least late 2024. The affected firms include DeepSeek, Moonshot AI, … Read more

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

A newly uncovered vulnerability in identity exposure management systems has exposed replayable AI tokens that can bypass even the most robust multi-factor authentication (MFA) protocols. This critical flaw, discovered through a series of real-world attacks, allows malicious actors to exploit AI-powered login tokens and gain unauthorized access to sensitive networks. The issue lies in the … Read more

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

A Critical SAP Kernel Flaw Exposes Millions to Remote Code Execution SAP, a leading provider of enterprise software solutions, has issued patches for a devastating kernel flaw that allows unauthenticated attackers to execute code remotely on affected systems. This vulnerability, rated CVSS 10.0 – the highest severity rating possible – puts millions of organizations at … Read more

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

Microsoft’s flagship security software, Defender, has been left vulnerable once again after a researcher revealed a proof-of-concept (PoC) exploit that can bypass the patch designed to protect against ShieldBreak attacks. This development highlights the cat-and-mouse game between cybersecurity vendors and attackers, with each side continually pushing the boundaries of what is possible. The PoC, released … Read more

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

A sophisticated malware campaign has been discovered targeting F5 BIG-IP Application Delivery Controllers (ADCs), leaving organizations vulnerable to web shell injections and potentially catastrophic data breaches. The malicious code, dubbed a “PHP web shell,” injects itself into system memory, evading detection by conventional disk-based scanning methods. The attack vector leverages the vulnerabilities in BIG-IP APM … Read more