Your Controls Block Known Attacks. What About the Behavior?

Cybersecurity controls are not foolproof, even when they’re blocking known attacks. A recent report from Picus Labs highlights a disturbing trend: as attack tools become more sophisticated, traditional security measures are struggling to keep up. The Blue Report 2026, which measured the effectiveness of enterprise prevention and detection in real-world environments, revealed some shocking numbers. … Read more

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

A new wave of attacks is sweeping through corporate networks, exploiting a critical vulnerability in Microsoft’s SharePoint and Teams platforms. Dubbed “TwinLoot,” this sophisticated malware campaign has already compromised hundreds of companies worldwide, leaving sensitive data exposed to unauthorized access. At its core, TwinLoot leverages the vulnerabilities inherent in collaborative tools like SharePoint and Teams … Read more

AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files

A new wave of cyber threats has emerged, leveraging AI-powered “mind viruses” that can spread between agents through a previously unknown vulnerability in persistent prompt files. This exploit has significant implications for organizations and individuals alike, as it allows attackers to create a chain reaction of compromised systems. The concept of mind viruses is not … Read more

Microsoft tests faster Windows File Explorer, new context menu

A Major Overhaul for Windows File Explorer: Microsoft Tests Faster Navigation and Customizable Context Menu In a significant move to improve user experience, Microsoft has begun testing a revamped version of its Windows File Explorer, which boasts faster navigation, a more customizable context menu, and reduced clutter. The updates are part of the ongoing effort … Read more

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybercriminals have been exploiting a vulnerability in RubyGems, a popular package manager for Ruby developers, by creating typosquatted versions of legitimate packages. These malicious packages, which mimic the names of well-known gems, can steal browser credentials and cryptocurrency wallets from unsuspecting users. The affected packages, 16 in total, were discovered on August 18th, with most … Read more

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A stealthy attacker has been exploiting vulnerabilities in both Salesforce and ServiceNow portals, compromising sensitive data and creating backdoors for future attacks. The hacker’s activities have been ongoing since 2025, with a total of eleven identified instances of identity exposure used to unlock active attack paths. The method behind the attacks is based on cross-domain … Read more

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

Cybersecurity Threat TCO Raises Alarm with TwinLoot Attacks on SharePoint and Teams A sophisticated attack campaign, code-named “TwinLoot,” has been spotted targeting organizations that use Microsoft’s collaboration platforms, SharePoint and Teams. The attackers have been leveraging a combination of clever tactics to steal sensitive credentials and move laterally across networks, leaving victims scrambling to contain … Read more

AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files

A New Threat Emerges: “Mind Viruses” Spread Between AI Agents Through Persistent Prompt Files Researchers have discovered a novel attack vector that allows malicious actors to spread between artificial intelligence (AI) agents through persistent prompt files. This vulnerability has significant implications for organizations relying on AI-powered systems, as it enables attackers to create chains of … Read more

CISA: Windows Task Host flaw now exploited by ransomware gangs

A critical Windows vulnerability that was previously patched by Microsoft has been confirmed to be exploited by ransomware gangs, putting millions of devices at risk. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this flaw, tracked as CVE-2025-60710, to its list of actively exploited vulnerabilities after discovering evidence of in-the-wild attacks. Task Host … Read more