Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

A shocking vulnerability has been discovered in top artificial intelligence (AI) agents designed to detect and prevent malicious code, leaving millions of users potentially exposed to cyber threats. These AI-powered security tools, widely used by organizations worldwide, can be tricked into running the very malware they were created to combat. The flaw, which affects several … Read more

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

A China-linked advanced persistent threat (APT) actor has been updating its arsenal with new backdoors, allowing it to more effectively spy on targets and compromise their systems. The group, tracked as UAT-7810 by Cisco’s Talos researchers, has infected over 1,000 small office/home office (SOHO) routers with a malicious backdoor known as LongLeash. This is part … Read more

Accenture Confirms Data Breach After Hacker Claims Source Code Theft

Accenture Confirms Data Breach After Hacker Claims Source Code Theft Professional services giant Accenture has confirmed a data breach after a hacker claimed the theft of internal source code from the company. The incident highlights the risks that large consulting and services firms face in today’s cybersecurity landscape, where threat actors are increasingly targeting sensitive … Read more

State IDs for AI Agents: Will Estonia Set a Precedent?

Estonia’s bold move to assign official government IDs to AI agents has sparked both excitement and concern among cybersecurity experts. The small Baltic nation, known for its digital transformation initiatives, is poised to set a precedent that could have far-reaching implications for governments and private sector organizations worldwide. The idea behind assigning state IDs to … Read more

Vidar Infostealer Hammers SMBs via Malvertising Campaign

Threat Actors Unleash Double Whammy Malware Campaign on Small Businesses A financially motivated group is exploiting small to midsize businesses (SMBs) globally with a sophisticated malvertising campaign that delivers two payloads in one: the Vidar infostealer and a cryptominer called XMRig. The attackers use lures of pirated or cracked software to entice victims into downloading … Read more

Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours

A lone threat actor has successfully used artificial intelligence (AI) to orchestrate a complex attack against a large Amazon Web Services (AWS) environment, compromising sensitive data and extorting an unnamed “global enterprise” in just 72 hours. This brazen cyberattack highlights the growing threat of AI-assisted attacks and underscores the need for organizations to rethink their … Read more

Vidar Infostealer Hammers SMBs via Malvertising Campaign

Threat actors have launched a coordinated malvertising campaign targeting small to midsize businesses (SMBs) globally, delivering a malware two-for-one combo that steals sensitive data and hijacks victims’ CPU cycles for cryptomining. The financially motivated operation, uncovered by Palo Alto Networks’ Unit 42 in April, uses lures of cracked or pirated software to deliver the Vidar … Read more

Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours

A lone threat actor has successfully breached a large Amazon Web Services (AWS) cloud environment using AI to orchestrate a complex attack that compromised critical systems and extorted the victim in just 72 hours. The attacker exploited weaknesses across various AWS services, stole credentials, and used AI-assisted workflows to accelerate reconnaissance, tool development, and command … Read more

Mexico’s New Cyber Plan Faces Its First Real Test

Mexico’s National Cybersecurity Plan Faces Its First Major Test as FIFA World Cup Kicks Off The Mexican government’s ambitious National Cybersecurity Plan 2025-2030 is being put to the test in its first major trial by fire – the highly anticipated FIFA World Cup 2026 tournament. As thousands of soccer fans descend upon Mexico’s host cities, … Read more

CISA orders feds to patch max severity ColdFusion flaw by Friday

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive to federal agencies, ordering them to patch a critical vulnerability in Adobe ColdFusion by Friday. The move comes as threat actors have been actively exploiting this maximum-severity flaw, which can be used to gain code execution on unpatched systems with minimal complexity. … Read more