OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards

A significant breakthrough in artificial intelligence (AI) research is sparking both excitement and concern among tech enthusiasts and security professionals alike. OpenAI, a leading developer of advanced language models, has announced a new version of its GPT (Generative Pre-trained Transformer) technology, known as GPT-5.6 Sol. While the company touts this innovation as a major leap … Read more

Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

Ukraine Discovers Sophisticated Phishing Tactic Used by Russian Intelligence to Steal Messaging Credentials A brazen and highly sophisticated phishing operation, allegedly carried out by Russian intelligence services, has been uncovered in Ukraine. The attack relied on a clever ruse, where hackers impersonated Ukrainian citizens and sent fake support texts to targeted individuals, tricking them into … Read more

CISA sets urgent deadline to fix Cisco flaw exploited in attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies to patch two recently discovered vulnerabilities within a tight deadline. The flaws, one of which is already being actively exploited by attackers, put sensitive systems at risk of compromise. A server-side request forgery (SSRF) vulnerability in Cisco’s Unified Communications … Read more

FBI: Russian hackers now target Signal backup recovery keys

Russian Hackers Evolve Tactics to Steal Signal Backup Recovery Keys, Exposing Users’ Historical Messages A phishing campaign targeting Signal users tied to Russian intelligence services has taken a concerning turn. The FBI and CISA have issued an updated public service announcement warning that hackers are now attempting to steal Signal Backup Recovery Keys, granting them … Read more

Clean GitHub repo tricks AI coding agents into running malware

A newly discovered vulnerability in AI-powered coding tools has left security experts sounding the alarm. Researchers at Mozilla’s Zero Day Investigative Network (0DIN) have demonstrated a method by which an attacker can plant malware on a developer’s device without leaving any suspicious code or exploit in the repository. The attack relies on a seemingly innocuous-looking … Read more

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

A Critical Flaw in Amazon Q Developer Platform Exposes Users to Malicious Repositories Amazon Web Services (AWS) has acknowledged a significant vulnerability in its Q developer platform, which could allow malicious users to run code on affected accounts via configuration files. The flaw, discovered by security researchers, affects users who have enabled the Model Customization … Read more

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

A Critical Linux Exploit Has Been Uncovered, Granting Root Access to Attackers A devastating security vulnerability has been discovered in various Linux distributions, allowing attackers to gain root access by manipulating cached binaries. Dubbed a “COW” (Copy-On-Write) exploit, this flaw can be exploited remotely, making it a pressing concern for system administrators and users alike. … Read more

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

A sophisticated Chinese-speaking Advanced Persistent Threat (APT) group has unleashed a new backdoor malware, known as TinyRCT, on unsuspecting organizations in Southeast Asia. This highly targeted campaign has left security teams scrambling to contain the damage and prevent further exploitation. TinyRCT is a type of remote access trojan (RAT) designed to provide its operators with … Read more

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

A new and highly sophisticated malware strain, dubbed SharkLoader, has been identified by cybersecurity researchers. This malware is particularly noteworthy for its ability to deploy Cobalt Strike, a notorious attack framework often used by nation-state actors, in a series of coordinated cyberattacks dubbed “StrikeShark.” The attacks have already compromised several organizations worldwide, leaving many scrambling … Read more

FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys

FBI Warns of Russian Intelligence Hackers Targeting Signal Backup Recovery Keys, Exposing User Data The FBI has issued a warning that Russian intelligence hackers have been actively targeting encrypted messaging service Signal’s backup recovery keys, potentially exposing users’ sensitive information. This brazen attack highlights the evolving tactics used by nation-state actors to compromise even the … Read more