Adobe patches seven max severity ColdFusion, Campaign flaws

Adobe has just released patches for seven critical vulnerabilities in its ColdFusion web app development platform and Campaign Classic marketing automation platform. These vulnerabilities, six of which affect ColdFusion and one affecting Campaign Classic, can be exploited remotely without user interaction to gain code execution or arbitrary code execution on unpatched systems. This is a … Read more

Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service

Cybersecurity giant Citrix has issued patches for six critical vulnerabilities affecting its NetScaler platform, which allows attackers to read sensitive files and launch crippling denial-of-service (DoS) attacks on organizations worldwide. The severity of these flaws is underscored by the fact that they were discovered using artificial intelligence (AI) models, highlighting the growing importance of AI … Read more

Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery

Cybersecurity researchers have uncovered a sophisticated malware delivery mechanism, leveraging APIs to evade detection and compromise systems worldwide. A recent analysis of 3,000 live ClickFix payloads revealed a complex web of API-driven malware distribution, compromising networks and disrupting operations across various industries. At its core, the attack relies on AI-powered models that identify vulnerabilities in … Read more

Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts

At least 78 Microsoft accounts have been compromised in a massive password spray attack that leveraged the Azure Command-Line Interface (CLI), a tool used for managing and configuring Azure services. The attack, which was launched against an estimated 81 million attempted login credentials, serves as a stark reminder of the ongoing threat posed by password-based … Read more

Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls

A highly publicized exploit of artificial intelligence (AI) technology has been resolved, but not before it brought attention to a growing concern for businesses and individuals alike: the use of AI models to discover previously unknown software vulnerabilities. Anthropic, a leading AI research firm, recently restored access to its powerful language model, Claude, after the … Read more

Fake Bug Report Hijacks AI Coding Agents at Scale

**AI Coding Agents Hijacked at Scale: A New Threat Vector for Attackers** In a disturbing demonstration of how easily attackers can exploit AI coding agents, researchers have shown that these tools can be hijacked to run arbitrary code on a developer’s machine by planting a single fake-error report in a public bug tracking service. This … Read more

China-Linked Group Targets Southeast Asia Critical Systems

China-Linked Cyberthreat Group Targets Southeast Asia Critical Systems, Compromising at Least 10 Regional Organizations A China-linked cyberthreat group has been making waves in Southeast Asia, compromising critical systems of multiple organizations across the region. The group, identified as CL-STA-1062 by cybersecurity firm Palo Alto Networks, has successfully targeted electricity and water providers in several countries, … Read more

CISA: Windows BlueHammer flaw now exploited by ransomware gangs

A high-severity vulnerability in Microsoft Defender has given ransomware gangs a potent tool for taking control of Windows systems. The flaw, known as BlueHammer, allows attackers with authorized access to escalate their privileges and potentially gain complete control over the targeted system. The issue was first identified by security researcher Nightmare Eclipse, who leaked proof-of-concept … Read more

Blackfield ransomware asks Nidec Corporation for $2 million ransom

Nidec Corporation, a Japanese electronics giant with global operations, is facing a significant cybersecurity crisis as Blackfield ransomware gang demands $2 million to restore access to its Taiwanese subsidiary’s server. The attack has raised concerns about data security and the potential impact on production and shipping. Nidec is one of the world’s leading manufacturers of … Read more

Anthropic to restore Claude Fable access on Wednesday

A major development in the world of artificial intelligence (AI) has unfolded, with Anthropic announcing that it will restore access to its high-powered language model, Fable 5, on Wednesday. The company’s move comes after the Department of Commerce lifted export controls on Fable 5 and its sister model, Mythos 5. The news is significant because … Read more