AI Model Evaluator METR Hit by Credential Theft, Probing

Cybersecurity Nonprofit METR Hit by Credential Theft and Probing Attacks A security nonprofit that helps evaluate risks in frontier AI models has disclosed two cybersecurity incidents, including a breach that exposed an API key and resulted in over $600,000 in unauthorized credits being consumed. The attacks highlight the growing threat of credential theft and probing … Read more

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Cyberattackers have compromised multiple organizations in the Philippines, including a nuclear agency, by exploiting old and unpatched vulnerabilities in their systems. The breach highlights the growing threat landscape in the region, where cyberattacks are increasingly used as a tool for espionage and political influence. The attackers initially gained access to the organizations’ networks through an … Read more

Palo Alto Networks Acquires AI Agent Platform Console

Palo Alto Networks has made a major move to bolster its cybersecurity capabilities with the acquisition of Console, an AI-native platform that enables organizations to automate operational tasks using natural language. The deal is expected to deepen the agentic capabilities of Palo Alto’s Cortex platform, allowing security teams to investigate signals, prioritize work, and take … Read more

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

Attackers have exploited a sophisticated campaign, dubbed ClickFix, compromising at least 31 organizations and leveraging the Polygon blockchain technology in a technique known as “EtherHiding” to obscure and automate malicious activity. This campaign has already targeted various businesses across e-commerce, professional services, and retail logistics sectors. GuidePoint Security’s Research and Intelligence Team (GRIT) released a … Read more

AI Model Evaluator METR Hit by Credential Theft, Probing

Security Nonprofit METR Hit by Credential Theft and Probing Attacks A security nonprofit that evaluates risks in frontier AI models has disclosed two cybersecurity incidents this week, including a breach that exposed an API key and led to the theft of $600,000 in public AI model credits. The attacks highlight the growing threat of credential … Read more

Critical Langflow Flaw Exploited as Attacks on AI Platform Rise

A critical vulnerability in Langflow, a low-code AI development platform, is being heavily exploited by attackers, marking the latest threat against this increasingly popular target. The remote code execution flaw, CVE-2026-0768, was initially disclosed in January and has since been observed being used to conduct reconnaissance, credential harvesting, and other malicious activities. The attacks are … Read more

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Cybersecurity Threats in the Philippines Take a Dire Turn as Nuclear Agency Breached A recent cybersecurity incident has left the Philippines’ nuclear agency vulnerable, with attackers exploiting old and unpatched vulnerabilities to gain access to sensitive information. The breach highlights the growing threat landscape in the region, where political tensions between China and neighboring countries … Read more

Critical Langflow Flaw Exploited as Attacks on AI Platform Rise

A Critical Langflow Vulnerability is Being Widespread Exploitation, Marking a Growing Threat to AI Development Platforms A critical vulnerability in Langflow, a low-code development platform used for designing AI agents, has been heavily exploited by attackers. The flaw, identified as CVE-2026-0768, allows remote code execution (RCE) and was initially disclosed in January with a 9.8 … Read more

Stronger Security Drives Ransomware Groups to Recruit From Within

**Ransomware Groups Exploit Legitimate Employees to Bypass Security Measures** A disturbing trend has emerged in the world of cybersecurity, as ransomware groups increasingly turn to recruiting from within organizations themselves. By targeting employees with legitimate access, these malicious actors can bypass even the strongest security measures and wreak havoc on a company’s data and finances. … Read more

Attackers Pounce on Critical Artifactory Flaw Following Disclosure

Attackers Quickly Exploit Critical Artifactory Flaw After Disclosure, Putting Thousands at Risk A critical vulnerability in JFrog’s Artifactory repository manager has been publicly disclosed, and malicious actors are already taking advantage of it. The flaw, identified as CVE-2026-82329, allows attackers to bypass authentication and gain administrative access to affected systems with ease. This has significant … Read more