Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google has taken swift action to delete three AI workflows from its cloud platform after a malicious issue was discovered on GitHub that could have potentially triggered privileged access. The incident highlights the risks of identity exposure and the importance of securing sensitive workflows in cloud environments. The affected workflows were using Google’s Cloud Development … Read more

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

As we’ve seen time and time again, cyber threats are constantly evolving. The latest twist on this theme is a new tactic that combines social engineering with artificial intelligence (AI) to compromise even the most secure systems. Dubbed “vibe hacking,” this emerging threat leverages AI-driven reconnaissance to pinpoint vulnerabilities in an organization’s defenses, effectively turning … Read more

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

A new wave of malicious updates has been circulating, posing as legitimate software from Adobe and Zoom. These fake updates are not only installing unwanted software but also granting hackers persistent remote access to compromised computers. The affected parties are widespread, with reports indicating that individuals in various industries have fallen victim to this scheme. … Read more

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

**A Sneaky npm Worm Spreads Malware, Threatening Thousands of Packages** In a worrying trend, hundreds of software packages on the popular npm (Node Package Manager) repository have been compromised by a malicious worm, dubbed “Keyv-Linked”. This insidious attack injects malware into innocent codebases, exploiting vulnerabilities in widely-used development tools like Claude Code and Visual Studio … Read more

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

A Critical Flaw in TP-Link’s Omada Ecosystem Puts Networks at Risk of Complete Takeover Security researchers have uncovered a chain of vulnerabilities in the zero-touch provisioning (ZTP) systems used by TP-Link’s Omada networking ecosystem, which can be exploited to compromise entire fleets of managed devices. The affected ZTP protocols allow routers, switches, and access points … Read more

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A New Wave of Cyber Threats Exploits Web Browser Vulnerabilities, Leaving Millions Exposed The past few weeks have seen a surge in reports of a sophisticated cyber threat campaign, dubbed DoubleCup, which leverages two clever tactics to deliver highly advanced malware. The attackers are exploiting vulnerabilities in popular web browsers to gain unauthorized access to … Read more

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

A critical vulnerability in cPanel, a widely-used web hosting platform, has been discovered, potentially allowing customers to run arbitrary SQL commands as the database root user. This flaw, identified as CVE-2023-1234, affects cPanel versions 11 and 12, and if exploited, could grant attackers full control over a website’s databases. The vulnerability is related to how … Read more

Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent

Google’s AI Infrastructure Left Vulnerable After Malicious GitHub Issue Exposes Privileged Agent Flaw A critical security flaw in Google’s cloud-based Artificial Intelligence (AI) infrastructure has been discovered, allowing attackers to potentially gain privileged access to sensitive data and systems. The issue arose from a malicious GitHub repository that exploited a vulnerability in the way AI … Read more

When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted

As hackers continue to exploit new vulnerabilities, a disturbing trend has emerged: Vibe Hacking, where AI-powered tools are being used to uncover and leverage sensitive identity information, effectively turning artificial intelligence into a junior hacker’s dream come true. This insidious tactic has been quietly making headlines in recent months, with 11 real-life cases highlighting the … Read more

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Thousands of Data Centers Exposed to Attacks Due to Decades-Old BMC Vulnerability A 22-year-old security flaw in Baseboard Management Controller (BMC) management processors has put thousands of data centers at risk of compromise. The vulnerability, which affects nearly 37,000 internet-exposed server-management interfaces, allows attackers to obtain password hashes and crack them offline. The issue stems … Read more