Max severity SonicWall SMA1000 flaw now exploited in attacks

A critical vulnerability in SonicWall’s secure remote access gateways has been exploited in real-world attacks just days after a patch was released. The flaw, tracked as CVE-2026-102255, affects specific models of the SMA1000 appliance and allows an attacker to take control of the device without authentication. The affected devices are the SMA1000 6210, 7210, and … Read more

How to keep AI agents within their permissions

A Critical Issue in AI Agent Management: Preventing Unauthorized Access As AI agents become increasingly ubiquitous in corporate environments, their ability to perform complex tasks with minimal human oversight is a double-edged sword. While agents can indeed be more efficient than humans in many situations, they also require careful management to prevent unauthorized access and … Read more

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

Cyberattackers have been exploiting a vulnerability in Google’s advertising system, using Bing search-result redirects as click URLs to direct unsuspecting users to fake download pages for the popular AI tool, Claude. The technique, dubbed “Adception” by security researchers at Push Security, is designed to evade security checks and deceive even the most vigilant visitors. The … Read more

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

Credential-Stealing GitHub Actions Workflows Found in Tens of Thousands of Repositories, Threatening Developer Security A shocking discovery has left cybersecurity experts reeling as tens of thousands of GitHub repositories have been found to contain malicious workflows that can steal sensitive credentials. The threat, which affects a staggering number of developers worldwide, is particularly concerning given … Read more

Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

Threat actors are capitalizing on unpatched vulnerabilities in the AhsayCBS backup management platform to deploy malicious code and mine cryptocurrency. The affected organizations, at least five of which have been targeted, rely on managed service providers (MSPs) and system integrators to manage their backups. AhsayCBS is a critical component for many businesses, used to store … Read more

Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

Hackers are using a clever technique to evade advertising security checks and direct unsuspecting users to malicious download pages. By abusing legitimate Bing search-result redirects in Google Ads, attackers are able to push Claude ClickFix attacks, which ultimately deliver unknown payloads to victims’ devices. The method, dubbed “Adception” by researchers at Push Security, involves using … Read more

FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

The FBI has made another significant arrest in its ongoing investigation into the notorious ShinyHunters hacking group. A suspect reportedly involved in last year’s high-profile hack of a popular jobs portal has been taken into custody, bringing the total number of ShinyHunters suspects arrested or charged to at least five. ShinyHunters gained widespread attention for … Read more

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

A massive credential-stealing campaign has been uncovered on GitHub, with tens of thousands of repositories compromised by malicious workflows. The attack leverages GitHub Actions, a popular automation tool that allows developers to run scripts and deploy code automatically when specific events occur in their repository. Malicious actors have exploited this feature to steal sensitive credentials … Read more