Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

Iranian hackers have been using a sophisticated tactic to deliver malicious software, exploiting vulnerabilities in coding test platforms to gain unauthorized access to target devices. The group’s modus operandi involves posing as recruiters or HR personnel, luring unsuspecting individuals into participating in online coding tests that promise lucrative job opportunities. These seemingly legitimate coding tests … Read more

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

A sophisticated campaign of malware has been uncovered, targeting unpatched iPhones and exploiting a vulnerability in their package manager, Packagist, to steal sensitive information from cryptocurrency wallet users. The attack, which was discovered on August 25th, affects any iPhone running iOS 14 or earlier that has not been updated to the latest version. The malicious … Read more

Hackers Start Exploiting Critical Langflow Vulnerability

Critical Langflow Vulnerability Exploited in the Wild, Threat Actors Targeting Users Globally A critical remote code execution (RCE) vulnerability in the AI low-code platform Langflow has been exploited by threat actors, with over 360 attempts detected by vulnerability intelligence firm VulnCheck in just a few days. The security defect, tracked as CVE-2026-0768, allows attackers to … Read more

Five Venezuelans plead guilty to ATM jackpotting attacks in US

A group of five Venezuelan nationals has pleaded guilty to attempting to use malware to drain cash from ATMs across the United States. The brazen heists, known as “jackpotting” attacks, have been on the rise in recent years, with criminals using sophisticated malware to take control of ATM internal computers and issue commands to dispense … Read more

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Russian-aligned hackers have unleashed a sophisticated malware strain that not only steals sensitive information but also leaves behind a digital calling card, known as UAC-0099. This unique signature is linked to a specific type of attack that disrupts artificial intelligence (AI) analysis capabilities, allowing malicious actors to evade detection and maintain their grip on compromised … Read more

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

Cybersecurity Breach Exposes Hundreds of Thousands in AI Credits, Highlights Dangers of API Key Mismanagement A sophisticated cyber attack has compromised a high-value API (Application Programming Interface) key, allowing attackers to drain approximately $600,000 worth of AI credits from an unnamed company. The breach is a stark reminder of the importance of secure API management … Read more

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

Cyber Threat Actors Prioritize Repeatable Attacks Over Innovation, Leaving Victims Vulnerable for Months On End In a disturbing trend that’s been unfolding for years, threat actors have shifted their focus from developing sophisticated new attacks to perfecting repeatable and efficient ones. By exploiting vulnerabilities in software applications and leveraging identity exposure, these attackers can gain … Read more

Recently patched PaperCut zero-days used in data theft attacks

A critical vulnerability in PaperCut print management software has been exploited by attackers to steal sensitive information from thousands of organizations worldwide. The two zero-day vulnerabilities, which were patched just last week, have allowed hackers to bypass authentication and gain remote access to vulnerable servers. PaperCut Software’s software is used by a staggering 100 million … Read more

Five Venezuelans plead guilty to ATM jackpotting attacks in US

Five Venezuelans Plead Guilty in High-Profile ATM Jackpotting Case A group of five Venezuelan nationals has pleaded guilty to attempting to drain millions from automated teller machines (ATMs) across the United States. The defendants, who targeted vulnerable ATMs using malware, have been charged with conspiracy to commit bank larceny and are facing significant prison sentences. … Read more

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

A wave of targeted attacks is sweeping through various sectors, exploiting critical vulnerabilities in programming languages and frameworks. The hackers are using these weaknesses to probe for sensitive credentials and establish command-and-control (C2) channels, ultimately leading to devastating breaches. This alarming trend affects organizations worldwide, including those in finance, healthcare, and government. At the heart … Read more