CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

Critical Infrastructure Orgs Left Exposed After CISA Red Team Simulation Breaches The Cybersecurity and Infrastructure Security Agency (CISA) has revealed that its red team, a group tasked with testing an organization’s defenses, successfully breached two critical infrastructure organizations in recent simulations. What’s more alarming is that one of the companies failed to detect the intrusion … Read more

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

A sophisticated cyber campaign, dubbed NovaCookies, has been exploiting genuine DocuSign notifications to hijack Microsoft 365 sessions and steal sensitive user data. The attack’s clever use of phishing tactics and exploitation of legitimate authentication mechanisms has left security experts sounding alarm bells. At its core, the NovaCookies campaign relies on social engineering, where attackers send … Read more

Hackers now exploit critical Gitea flaw in code injection attacks

A critical security vulnerability is being actively exploited by hackers to inject malicious code into self-hosted Git services, putting thousands of organizations at risk. The vulnerability, tracked as CVE-2026-60004, affects Gitea, a popular open-source platform for developers to host and manage their own Git repositories. Gitea provides a suite of DevOps tools similar to cloud-based … Read more

Microsoft tests new privacy controls for Windows 11 desktop apps

Microsoft has taken a significant step towards giving users more control over their personal data and device features with the introduction of new privacy controls for Windows 11 desktop applications. These controls, which are currently being tested in Insider Preview builds, will allow users to choose which apps can access sensitive resources such as cameras, … Read more

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

Russian operatives have been caught using compromised ChatGPT accounts to spread disinformation and influence public opinion, a worrying trend that highlights the dark side of AI-powered chatbots. OpenAI, the company behind the popular language model, has since taken action, banning these Russian accounts from accessing its platform. The scope of this operation is not clear, … Read more

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users’ Reservations in Tests

A critical vulnerability has been discovered in Claude Opus 4.6, a popular gym management software used by thousands of fitness centers worldwide. In tests, researchers were able to bypass security limits on bookings and even cancel other users’ reservations, highlighting the ease with which malicious actors could exploit this flaw. Claude Opus 4.6 is designed … Read more

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

Security Teams Reel from Identity Exposures that Fuel Active Attacks, Highlighting Need for AI-Powered Hypothesis Engines A growing trend of identity exposures is turning once-secure systems into ticking time bombs, allowing attackers to exploit privilege escalation and breach even the most robust networks. Behind these seemingly isolated incidents lies a complex web of interconnected vulnerabilities … Read more

Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

A newly discovered backdoor, dubbed SLEEPWALKER, has been found lurking in various devices and systems, waiting for a specific packet of data to trigger its malicious functionality. This sleeper agent is particularly concerning because it can run its own bytecode, essentially giving hackers free rein to wreak havoc on compromised systems. SLEEPWALKER’s presence was first … Read more

INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown

A massive global operation, codenamed Operation Jackal IV, has netted 58 arrests and identified a staggering 263 individuals suspected of involvement in large-scale cyber fraud schemes. The coordinated effort, led by INTERPOL, is a stark reminder that cybercrime knows no borders – and that the authorities are determined to track down those responsible. The operation’s … Read more

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

A sophisticated influence operation has been dismantled, with OpenAI taking swift action against a network of Russian-language ChatGPT accounts used to spread disinformation and propaganda. The operation, which had been ongoing since 2025, involved the use of AI-powered chatbots to generate convincing content that was then disseminated through various online channels. According to reports, the … Read more