AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android

A new and sophisticated form of browser ransomware, known as “ChromaRansom,” has been spotted in the wild, leveraging AI-generated code to exploit vulnerabilities in Chromium-based browsers on both Windows and Android platforms. This malware is particularly worrying due to its ability to bypass traditional security measures, making it a significant threat to individuals and organizations … Read more

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

A Critical Flaw in Kemp LoadMaster Appliances is Being Actively Exploited, Putting Thousands of Organizations at Risk A severe pre-authentication remote code execution (RCE) vulnerability in Kemp LoadMaster appliances has been discovered and is currently being exploited by attackers. The flaw, which affects versions 7.2.x and earlier, allows unauthenticated hackers to execute arbitrary code on … Read more

Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

Critical Cursor Flaws Expose Systems to Unchecked Malicious Activity A shocking revelation has shaken the cybersecurity community, with the discovery of critical cursor flaws that could allow attackers to bypass sandbox protections and execute malicious commands on compromised systems. The vulnerabilities, discovered by researchers using AI-powered tools, have left many organizations scrambling to assess their … Read more

Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

Adobe’s July Patch Tuesday brings critical fixes for 7 vulnerabilities, with 4 of them holding a maximum CVSS score of 10.0. The affected software includes ColdFusion and Adobe Campaign Classic, both widely used in enterprise environments. These high-severity flaws can be exploited remotely, making them a significant concern for organizations relying on these tools. The … Read more

Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures

Cybersecurity researchers have uncovered a sophisticated banking Trojan called Ousaban, which is specifically designed to target users of Iberian banks, including Spanish and Portuguese financial institutions. This malware uses a clever tactic to trick victims into downloading the malicious software, exploiting a common vulnerability in human behavior rather than technical security weaknesses. Ousaban works by … Read more

Attackers Hijack Exposed AI Endpoints to Power Offensive Ops

Cybersecurity Threats Leverage Exposed AI Endpoints with Alarming Ease A growing number of attackers are exploiting exposed artificial intelligence (AI) endpoints, turning them into powerful tools for complex cyber operations. This alarming trend has come to light in recent months as researchers at Zenity have observed three distinct campaigns leveraging organization-owned AI agents for malicious … Read more

Adobe patches seven max severity ColdFusion, Campaign flaws

Adobe has released critical security patches for seven maximum-severity vulnerabilities affecting its ColdFusion web application development platform and Campaign Classic marketing automation platform. These flaws, which can be exploited by attackers without requiring user interaction, pose a high risk of being targeted in low-complexity attacks. The affected platforms include ColdFusion versions 2025.9 and earlier, as … Read more

Amazon fined $2.25M for withholding evidence from fraud victims

Amazon has been fined $2.25 million by the U.S. Federal Trade Commission (FTC) for withholding evidence from identity theft victims, a move that’s sparking concerns about corporate accountability in cases of online fraud. The FTC alleges that Amazon failed to provide transaction records to those who had fallen victim to identity theft, as required by … Read more

Microsoft fixes GIF functionality in the Windows Emoji Panel

A critical GIF functionality has stopped working in the Windows Emoji Panel for some users, leaving them without access to their favorite animated images. The issue was caused by the retirement of Google’s Tenor GIF search engine application programming interface (API), which was used to power the feature. However, Microsoft has swiftly acted to resolve … Read more

Microsoft Accelerates Post-Quantum Cryptography Shift to 2029

Microsoft Accelerates Post-Quantum Cryptography Shift, But What Does it Mean for You? In a significant move that will have far-reaching implications for the global tech industry, Microsoft has announced plans to accelerate its transition to post-quantum cryptography by 2029. This development comes as a response to growing concerns over the vulnerability of current encryption methods … Read more