Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

A Critical Ruby on Rails Vulnerability is Now Being Exploited by Attackers A severe vulnerability in Ruby on Rails, a popular web application framework, has been exploited by attackers. The flaw, known as KindaRails2Shell, allows an unauthenticated attacker to execute arbitrary code remotely, potentially leading to data breaches and lateral movement within a network. This … Read more

PaperCut Exploitation Escalates to Active Intrusions

PaperCut Attacks Escalate to Active Intrusions, Threatening Thousands of Systems A disturbing trend is unfolding in the cybersecurity world as attacks exploiting vulnerabilities in PaperCut’s print management solutions escalate from reconnaissance to active intrusions. The threat actors, who were initially using two recently discovered zero-day vulnerabilities to gain access to affected systems, have now moved … Read more

Anthropic Warns Claude Users of Infostealer Malware Infections

A sophisticated malware campaign targeting users of Anthropic’s Claude AI platform has compromised thousands of accounts, allowing attackers to hijack login sessions and run up unauthorized charges. In an email notification sent to affected customers, Anthropic revealed that infostealer malware had infiltrated computers running Windows and macOS, stealing sensitive information such as saved passwords, browser … Read more

What the Hugging Face Incident Teaches Security Leaders About AI Agent Access

A High-Profile Breach Exposes AI Agent Security Gaps: What It Means for Your Organization In a stark reminder of the evolving threat landscape, AI agents have been used to breach a high-profile organization’s production environment, highlighting critical security gaps that even the most prepared teams may struggle to address. The recent Hugging Face incident has … Read more

McKesson Confirms Data Breach as Attacker Deadline Looms

McKesson Faces Data Breach Nightmare as Hackers Threaten to Release Stolen Info Healthcare giant McKesson Corporation has confirmed a data breach that has left many worrying about the security of their sensitive medical information. The company, which supplies one-third of prescription medicines to North American hospitals and pharmacies, revealed on August 25 that hackers had … Read more

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

ServiceNow Patches Critical Code Injection Vulnerabilities in AI Platform In a major security patch release, ServiceNow has addressed four vulnerabilities, including three critical code injection flaws in its AI platform. The company’s emergency updates are aimed at preventing attackers from exploiting these weaknesses and gaining unauthorized access to sensitive data. The three critical bugs, tracked … Read more

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

A Zero-Day Exploit Targets Kaspersky Endpoint Security, Leaving Users Vulnerable to Privilege Escalation Attacks In a disturbing revelation, a security researcher known as Nightmare Eclipse has released a zero-day exploit targeting Kaspersky’s endpoint security product. The exploit, dubbed HardBreacher, takes advantage of a privilege escalation vulnerability in the software, allowing attackers to gain elevated access … Read more

Anthropic Warns Claude Users of Infostealer Malware Infections

Claude Users Hit by Infostealer Malware, Risking Account Takeovers and Unauthorized Charges Anthropic, the AI giant behind the popular Claude AI platform, has issued a warning to some of its users that their accounts have been compromised due to infostealer malware infections on their computers. The company detected the malicious activity, took steps to protect … Read more

What the Hugging Face Incident Teaches Security Leaders About AI Agent Access

Cybersecurity Teams Struggle to Keep Pace with AI Agent Attacks A recent high-profile breach at Hugging Face, a leading provider of natural language processing tools, highlights the growing threat of AI agent attacks. In just four days, an unauthorized AI agent infiltrated the company’s production environment and took 17,600 actions, demonstrating the speed and sophistication … Read more

McKesson Confirms Data Breach as Attacker Deadline Looms

McKesson Confirms Data Breach as Hackers Demand Ransom Payment Healthcare giant McKesson Corporation has confirmed that hackers have stolen customer data from its systems, leaving millions of people’s sensitive information in the hands of extortionists. The ShinyHunters group, notorious for demanding ransom payments in exchange for deleting stolen data, is threatening to release the compromised … Read more