Learn How to Build Security Operations Ready for AI-Powered Attacks

As threat actors increasingly turn to artificial intelligence (AI) and machine learning (ML) to launch sophisticated attacks, cybersecurity teams are scrambling to stay ahead of the curve. A recent spate of high-profile breaches has highlighted a critical vulnerability that’s being exploited by AI-powered attackers: identity exposure. In this article, we’ll delve into 11 real-world examples … Read more

Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers

Amazon’s Kiro Prompt Injection Vulnerability Exposes Sensitive Data Across Accounts A critical vulnerability has been discovered in Amazon’s Kiro, a cloud-based platform that enables businesses to build and manage large language models. The flaw, dubbed “Kiro Prompt Injection,” allows attackers to exfiltrate sensitive data from one account to another by exploiting the way Kiro handles … Read more

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Cybersecurity Threats in Cambodia Escalate as Spark RAT Exploits Vulnerable Software A highly sophisticated cyber threat has been unfolding in Cambodia, targeting government agencies and financial institutions with a potent malware called Spark RAT. What makes this attack particularly concerning is its ability to disable security tools, rendering affected organizations powerless against further exploitation. At … Read more

What the Data Says About AI in Security Operations in 2026

As we continue to navigate the complexities of modern cybersecurity, a disturbing trend has emerged in the world of AI-powered security operations. A recent analysis of real-world attacks has revealed that identity exposure is being used as a key vector for unlocking active attack paths, allowing threat actors to seamlessly escalate privileges and breach even … Read more

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

A major supply chain cyberattack has come under scrutiny in Australia, with authorities charging a group of hackers allegedly linked to TeamPCP. The operation, which targeted various organizations across the country, highlights the ease with which identity exposure can be exploited by attackers to gain unfettered access to sensitive systems. The alleged TeamPCP hackers are … Read more

Learn How to Build Security Operations Ready for AI-Powered Attacks

As we continue to navigate the complex landscape of modern cybersecurity, a disturbing trend has emerged: identity exposure is becoming an increasingly popular tactic for attackers. In fact, researchers have identified 11 real-world examples where compromised identities were used as a stepping stone to launch devastating attacks on unsuspecting organizations. These cases highlight a critical … Read more

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Australian authorities have made significant progress in dismantling the notorious cybercrime group TeamPCP, arresting two men allegedly involved in its operations. The arrests mark a major blow to the group’s ability to launch sophisticated attacks on software supply chains, but it also raises questions about the nature of this particular threat. The Australian Federal Police … Read more

Carhartt data breach exposes information of 12.9 million accounts

Carhartt Data Breach Exposes Sensitive Info of 12.9 Million Accounts A massive data breach has struck clothing retailer Carhartt, exposing sensitive information from nearly 13 million accounts. The ShinyHunters extortion group claimed responsibility for the attack earlier this month and published the stolen data on its dark web site after failing to pressure Carhartt into … Read more

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

A New Rowhammer Vulnerability Exploits NVIDIA’s RTX A6000, Putting Sensitive Data at Risk Researchers have discovered a fresh Rowhammer vulnerability affecting NVIDIA’s high-end graphics processing unit (GPU), the RTX A6000. Dubbed “GPUThor,” this flaw allows attackers to bypass Error-Correcting Code (ECC) memory protection, gaining host root access and compromising sensitive data. The GPUThor exploit leverages … Read more

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

A sophisticated malware campaign, known as GoCaracal, has been discovered using a unique tactic to evade detection and maintain persistence on compromised systems. The malware exploits an Ethereum smart contract to fetch replacement command and control (C2) addresses, allowing it to stay one step ahead of security researchers and defenders. The GoCaracal malware is designed … Read more