ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

Cybersecurity experts have recently sounded the alarm about a new and insidious threat, one that could potentially compromise even the most secure systems. It starts with artificial intelligence (AI) models being used to detect software vulnerabilities, but with a twist: these AI models are also being exploited by malicious actors to hijack compute resources. The … Read more

Google loses final appeal to overturn €4.1 billion EU fine

The European Union has reaffirmed its stance on Google’s business practices, dismissing the company’s final appeal against a €4.1 billion antitrust fine. This decision is a significant blow to Google, as it confirms that the tech giant abused its dominant market position by promoting its Chrome browser and search service through Android agreements. At the … Read more

Identity Lifecycle Management Wasn’t Built for AI Agents

Cybersecurity Teams Scramble to Contain Breaches as AI-Powered Attackers Exploit Identity Management Weaknesses A growing threat is emerging in the world of cybercrime, where sophisticated attackers are using artificial intelligence (AI) agents to exploit vulnerabilities in identity lifecycle management systems. These attacks have left many organizations scrambling to contain breaches and wondering how such a … Read more

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

A sophisticated malware campaign linked to the ToddyCat threat actor has been uncovered, exploiting a vulnerability in Google’s OAuth 2.0 authentication system to gain unauthorized access to Gmail accounts via the Google API. The attack leverages the API’s legitimate functionality to quietly collect sensitive user data, raising significant concerns about the security of online services … Read more

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

A Wave of Attacks Exploits AI-Powered Vulnerability Discovery, Leaving Organizations Scrambling for Defense In a disturbing trend that highlights the dark side of artificial intelligence (AI) adoption, attackers are increasingly leveraging AI-powered tools to discover and exploit software vulnerabilities. This development has left many organizations scrambling to bolster their defenses against an evolving threat landscape. … Read more

Opera rolls out Paste Protect feature to fight ClickFix attacks

Opera has taken a significant step in bolstering user protection against sophisticated cyber threats with the introduction of its new Paste Protect feature. This innovative security mechanism is specifically designed to counter ClickFix-style attacks, which have become increasingly popular among threat actors. ClickFix is a cunning technique used by attackers to trick users into executing … Read more

CISA: Microsoft SharePoint RCE flaw now actively exploited

Microsoft SharePoint Servers Under Attack: CISA Warns of Actively Exploited Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning to organizations using Microsoft SharePoint servers, indicating that attackers have begun exploiting a high-severity vulnerability in the platform. Tracked as CVE-2026-45659, this remote code execution flaw allows low-privileged attackers to execute … Read more

Cisco finally confirms attackers exploiting Unified CM flaw

A Critical Vulnerability in Cisco’s Unified Communications Manager is Being Actively Exploited by Attackers A major cybersecurity vulnerability has been confirmed to be actively exploited by attackers, putting thousands of businesses and organizations at risk. Cisco Systems, a leading provider of networking equipment and software, has finally acknowledged that its Unified Communications Manager (Unified CM) … Read more

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

**AI-Powered Attackers Leverage FortiBleed Flaw to Steal Sensitive Data** A highly sophisticated cyberattack has been linked to two notorious ransomware operations, exploiting a previously unknown vulnerability in a popular software package. The attack, dubbed “FortiBleed,” uses artificial intelligence (AI) to scan for and exploit vulnerabilities in network devices, highlighting the growing threat of AI-powered attacks. … Read more

Opera rolls out Paste Protect feature to fight ClickFix attacks

Opera has rolled out a new security feature called Paste Protect, designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering. This technique, known as ClickFix, involves deceiving victims into copying and pasting potentially destructive code or commands into their command-line interface, where they execute with the user’s privileges, bypassing … Read more