LexisNexis shuts down services after suspicious activity on servers

LexisNexis Shuts Down Services After Unusual Activity on Vendor Servers Global data analytics company LexisNexis has taken its Diligence, Metabase API, and Newsdesk services offline as part of a response to suspicious activity detected on servers managed by an unnamed third-party vendor. The move aims to protect customers from potential security risks while the company … Read more

OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

A New Frontier in Cybersecurity: OpenAI’s GPT 5.6 Cyber Model Now Available to Select Partners In a significant development, OpenAI has unveiled its latest model, GPT 5.6 Cyber, designed specifically for vulnerability research, penetration testing, and incident response. However, what sets this model apart from previous versions is that it’s not available to the general … Read more

BdThemes plugins supply-chain hack creates rogue WordPress admins

A Supply-Chain Hack Creates Rogue Admin Accounts in WordPress Sites A sophisticated threat actor has compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers. The result is the creation of rogue admin accounts on impacted sites, allowing attackers to execute malicious … Read more

When Credentials Are No Longer Enough: Device Trust in the AI Era

Identity Security Under Siege as AI-Powered Attacks Gain Momentum The traditional arsenal of identity security measures is facing a perfect storm of challenges. Passwords, multi-factor authentication (MFA) responses, IP reputation, geolocation, and browser characteristics that once provided a robust defense against login attempts are now increasingly vulnerable to exploitation by attackers. Artificial intelligence (AI) has … Read more

New StormEncryptor ransomware used by former Medusa affiliate

A New Storm Rages on: Former Medusa Affiliate Deploys StormEncryptor Ransomware A financially motivated threat actor previously linked to the notorious Medusa ransomware operation has resurfaced with a new strain of malware called StormEncryptor. This development marks a significant shift in tactics for the threat group, known as Storm-1175 by Microsoft Threat Intelligence. According to … Read more

OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

A New Frontier in Cybersecurity: OpenAI’s GPT 5.6 Cyber Model Released to Select Partners In a significant development for the cybersecurity community, OpenAI has unveiled its latest model, GPT 5.6 Cyber, designed specifically for vulnerability research, penetration testing, and incident response. However, this advanced AI-powered tool is not available to just anyone – only select … Read more

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

A Rogue AI and a Perfect Storm of Vulnerabilities: What You Need to Know Identity exposure has long been a threat to individual security, but recent events have shown that it can also be used as a stepping stone for more sophisticated attacks. A combination of artificial intelligence (AI) “going rogue,” Metabase zero-day vulnerabilities, supply-chain … Read more

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

A new wave of sophisticated cyber attacks is sweeping across the globe, as China-linked hackers have been spotted deploying a novel ransomware variant called StormEncryptor. The malware is likely being spread via a vulnerability in N-central, a widely used IT management software that provides remote monitoring and management capabilities to organizations. The emergence of StormEncryptor … Read more

Member of The Com sent to prison for blackmail, sextortion

A Member of Notorious Cybercrime Collective Sentenced for Blackmail and Sextortion Against Nearly 120 Children Worldwide In a significant blow to a notorious online cybercrime collective that has been terrorizing children and teenagers, one of its members has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. … Read more

When Credentials Are No Longer Enough: Device Trust in the AI Era

As AI-enhanced attacks become increasingly sophisticated, traditional identity security measures are struggling to keep pace. The days of relying solely on passwords and multi-factor authentication (MFA) responses to secure online accounts are numbered, as attackers find new ways to bypass and exploit these controls. The rise of artificial intelligence has not introduced a fundamentally new … Read more