Hackers run khunt post-exploitation toolkit from Oracle database

Cyberattackers have been caught exploiting a vulnerability in an Oracle database to install a post-exploitation toolkit, giving them unfettered access to a corporate network. The attack was discovered by security firm Huntress on July 27, after its platform detected suspicious activity involving credential theft on a server hosting the Oracle database. The attackers exploited a … Read more

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

A recently discovered vulnerability in Paperclip AI, a popular artificial intelligence development platform, has left thousands of users exposed to potentially catastrophic attacks. The flaw, which allows malicious agents to run host commands via malicious agent imports, has significant implications for anyone who’s ever used the platform. Paperclip AI is designed to simplify AI model … Read more

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

A Shadowy Market Emerges, Selling Sensitive Customer Data and Opening Up Entire Networks to Attack In a disturbing revelation, it’s been discovered that sensitive customer data from a popular online platform called Claude is being sold on dark web marketplaces at discounted prices. What’s even more alarming is that the operator behind this illicit trade … Read more

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

A Major Cyber Heist Brought Down by AI: OpenAI’s ChatGPT Foils Poipet Scam Network In a stunning display of cybersecurity innovation, OpenAI’s chatbot technology has disrupted a sophisticated network of scammers using multiple fraud schemes to exploit victims worldwide. The Poipet scam network, named after the Cambodian border town where it originated, had been evading … Read more

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Malicious macOS Malware Hidden in Plain Sight on ClickFix Domains Over 250 websites hosted by ClickFix, a popular domain registrar and hosting provider, have been found to be using browser fingerprinting techniques to conceal malware-laden landing pages. This clever tactic allows hackers to evade detection by security software and deceive unsuspecting users into installing malicious … Read more

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that hackers are exploiting critical vulnerabilities in three widely used software products, including IBM’s Langflow visual framework for building AI agents. The agency is urging federal agencies to take immediate action to mitigate these flaws, which have already been actively exploited by attackers. … Read more

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

A Sneaky New Threat Has Emerged in the npm Ecosystem, Putting Thousands of Developers at Risk A sophisticated new tactic has been spotted in the wild, leveraging a trusted package repository to spread malware. The attack involves compromising popular npm packages with a type of Trojan, designed to decode and retrieve a Command-and-Control (C2) server … Read more

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Cybersecurity researchers have uncovered a series of vulnerabilities in Paperclip AI, a popular software platform used for automating various business processes. The flaws, which allow attackers to run arbitrary host commands, can be exploited via malicious agent imports. This means that hackers can gain unfettered access to sensitive systems and data, putting thousands of users … Read more

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

A Chilling Revelation: Poisson Claude Exploits Customer Data for Malicious Gain A disturbing discovery has shed light on a widespread practice where identity exposure is being leveraged by attackers to gain unauthorized access to sensitive systems. Dubbed “Poisson Claude” after its alleged developer, this technique involves exploiting customer data to unlock active attack paths and … Read more