AI-Generated Patches Fail Half the Time

As AI models increasingly take on tasks traditionally handled by humans, including writing code and identifying vulnerabilities, a disturbing trend is emerging: even when these systems are able to generate patches for security flaws, they often fail to effectively fix the problem. In fact, research suggests that only about half of all AI-generated patches successfully … Read more

Metabase SQLi zero-day exploited in customer data-theft attacks

Critical Metabase SQL Injection Vulnerability Exposed in Customer Data-Theft Attacks A devastating zero-day attack on Metabase, a popular business intelligence and analytics platform, has compromised customer instances across multiple high-profile companies. The unauthenticated SQL injection vulnerability, affecting versions 1.58 and above, allowed attackers to inject arbitrary code into the application database, granting them administrator access … Read more

Unlimited Technology Systems breach impacts 3.8 million people

A massive data breach has left nearly four million people vulnerable to identity theft and other malicious activities. Unlimited Technology Systems, a software company that provides financial and revenue cycle technology for healthcare providers, reported that hackers accessed its server in October 2025, exposing sensitive information on patients. The incident occurred when an unauthorized party … Read more

Metabase SQLi zero-day exploited in customer data-theft attacks

Critical Metabase Vulnerability Exposes Customer Data in Widespread Attacks A devastating zero-day vulnerability in Metabase, a popular business intelligence and data analytics platform, has been exploited by attackers to steal sensitive customer information from multiple companies. The attacks, which have been confirmed to impact Framework and Tally, demonstrate the severity of the vulnerability and highlight … Read more

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

**Vishing Attacks on Personal Phones Expose SaaS Data** A wave of sophisticated phishing attacks, dubbed UNC6671, is targeting personal phones to gain unauthorized access to Software as a Service (SaaS) data. These vishing attacks use social engineering tactics to trick victims into divulging sensitive information, which attackers then leverage to compromise entire organizations. The alarming … Read more

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

A new breed of macOS malware, known as ClickFix, has emerged, targeting cryptocurrency wallets and draining funds from unsuspecting users. The attacks are noteworthy for their sophistication, leveraging a combination of social engineering and clever coding to evade detection. ClickFix operates by masquerading as a legitimate software update, tricking victims into installing the malicious payload. … Read more

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A massive wave of malicious packages has hit the popular npm package repository, with nearly 800 compromised modules delivering a potent combination of a cross-platform Remote Access Trojan (RAT) and an infostealer. This alarming incident underscores the importance of security in software development and highlights the need for developers to remain vigilant against supply chain … Read more

North Carolina Ports confirms cyberattack disrupting operations

A devastating cyberattack has crippled operations at three key North Carolina ports, leaving shippers and truckers scrambling to adjust to the disruption. The North Carolina Ports Authority confirmed that a cyberattack on August 4th targeted IT systems at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port, causing a widespread … Read more

Unlimited Technology Systems breach impacts 3.8 million people

A massive healthcare software company has revealed a data breach that compromised the sensitive information of nearly 4 million people. Unlimited Technology Systems, which provides financial and revenue cycle technology for specialty healthcare providers, reported that hackers gained access to its server in October 2025 and stole personal details, including social security numbers, medical records, … Read more

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A New Wave of Vishing Attacks Exploits Personal Phones to Steal SaaS Data, Leaving Millions Exposed A sophisticated wave of vishing (voice phishing) attacks has been targeting individuals’ personal phones, aiming to steal sensitive data from Software as a Service (SaaS) applications. According to reports, the UNC6671 threat actor group is behind these campaigns, which … Read more