15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

As it turns out, a world-leading device manufacturer has inadvertently highlighted the risks inherent in automated network device provisioning. Researchers at Forescout’s Vedere Labs have disclosed 15 vulnerabilities in TP-Link networking technologies, specifically targeting its zero-touch provisioning (ZTP) process. The impacted products are part of TP-Link’s Omada ecosystem, used by over 1.7 billion people across … Read more

CSS: The Hidden Threat Lurking in Your Inbox

A Hidden Threat Lurking in Your Inbox: Researchers Warn CSS Can Exfiltrate Data from Webmail Cybersecurity researchers have discovered a previously unknown threat lurking in plain sight: Cascading Style Sheets (CSS), used for web page design, can be exploited to exfiltrate sensitive user information from email platforms. This alarming finding has left many vendors scrambling … Read more

No Perfect Fix for AI Browser Prompt Injection Flaws

A Persistent Threat Lurks in AI-Powered Browsers: Experts Warn of Prompt Injection Flaws A growing number of web browsers are incorporating artificial intelligence (AI) assistants to navigate and interact with online applications on behalf of users. However, as researchers have discovered, these AI-powered browsers remain vulnerable to a type of attack known as prompt injection, … Read more

AI Browsers Vulnerable to ‘PleaseFix’ Zero-Click Agent Hijacking

A New Era of Cyber Threats: AI Browsers Vulnerable to Sneaky Attacks A major cybersecurity threat has emerged in the world of artificial intelligence (AI) browsers. Researchers from Zenity Labs have discovered a vulnerability class they call “PleaseFix,” which allows attackers to hijack the agents within popular agentic browsers like Claude, Gemini, Perplexity Comet, and … Read more

AI Sends Global Crime Syndicates Into Fraud Nirvana

Global crime syndicates have hit the jackpot with AI-powered scams, generating billions in illicit funds by exploiting weaknesses in identity verification systems. Major financial institutions, online retailers, cryptocurrency exchanges, and unsuspecting individuals are among those being targeted by sophisticated scammers who have industrialized their operations using cutting-edge artificial intelligence (AI) tools. According to Eric Huber, … Read more

AI Browsers Vulnerable to ‘PleaseFix’ Zero-Click Agent Hijacking

**AI Browsers Left Vulnerable to Sneaky Zero-Click Attacks** A new class of zero-click exploits has been discovered in artificial intelligence (AI) browsers, allowing attackers to hijack these agents and turn them against their users. This vulnerability, dubbed “PleaseFix” by the researchers who uncovered it, can be exploited through malicious instructions hidden in content supplied to … Read more

AI Sends Global Crime Syndicates Into Fraud Nirvana

Global crime syndicates have found a lucrative way to bypass identity-verification methods and scam at scale using advanced AI tools. Organized crime groups are leveraging AI-powered voice cloning, deepfake real-time video overlays, large language model-driven persona management, and automated translation to convincingly create synthetic identities that can fool even the most sophisticated defenses. This has … Read more

How AI-powered phishing killed blocklists for good

Phishing Attacks Just Got a Whole Lot Harder to Stop The cat-and-mouse game between cybersecurity professionals and attackers has just taken a significant turn in favor of the latter. Artificial intelligence (AI) has revolutionized the way phishing campaigns are designed, executed, and dismantled, making it increasingly difficult for blocklists and indicator-based detection methods to keep … Read more

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian Man Pleads Guilty to Extortion Scheme Involving Stealing Data from 165 Organizations on Snowflake Cloud Storage Connor Riley Moucka, a 26-year-old Canadian man also known as Alexander Moucka and Waifu, has pleaded guilty to his role in a brazen extortion scheme that targeted over 165 organizations using Snowflake’s cloud storage service. The scheme, … Read more

Ransom Cartel ransomware creator sentenced to 16 years in prison

A notorious cybercrime mastermind has been brought to justice. Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison for his role in orchestrating a series of devastating attacks against at least 18 companies worldwide. Silnikau, a 40-year-old Belarusian national, was active on Russian-speaking cybercrime … Read more