Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

A sophisticated cyber threat has come to light, where malicious actors are exploiting compromised login credentials to bypass multi-factor authentication (MFA) and gain unauthorized access to sensitive systems. The attack method involves using stolen AI tokens, which are essentially digital keys that can be replayed to authenticate a user, thereby sidestepping MFA protections. The vulnerability … Read more

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft’s latest Patch Tuesday update has set a new record, with an astonishing 974 vulnerabilities addressed across various products and services. Among these patches are two critical Windows zero-day flaws that have already been exploited by attackers in the wild. This massive effort to shore up security weaknesses is a testament to the ongoing cat-and-mouse … Read more

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

A string of high-profile accusations has emerged from U.S. agencies, targeting Chinese artificial intelligence (AI) firms for allegedly developing sophisticated AI-powered tools that mimic the capabilities of language models like Claude, GPT, Gemini, and Grok. At stake are concerns over data security, intellectual property theft, and the potential for these tools to be used in … Read more

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

A Critical Flaw in Alby Hub Exposes Bitcoin Wallets to Takeover by Hackers A critical vulnerability in Alby Hub, a software used for managing internet-exposed Bitcoin wallets, has been discovered, putting thousands of users at risk of having their accounts taken over by attackers. The flaw, which allows hackers to exploit cross-domain privilege escalation and … Read more

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A Critical Flaw in AI Agents’ File Sandbox Leaves Users Exposed DeepSeek, a cutting-edge technology used by several organizations to enhance their cybersecurity posture through artificial intelligence-powered file sandboxing, has been found vulnerable to a critical flaw. This weakness allows malicious actors to disable the very mechanism designed to protect against threats, rendering users’ systems … Read more

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

As it turns out, many organizations are sitting ducks for cyber attacks due to their inability to quickly identify and respond to potential security breaches. A recent webinar highlighted 11 real-life stories of how identity exposure can unlock active attack paths, revealing a common thread – cross-domain privilege escalation. These stories show that when an … Read more

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

A critical vulnerability in cPanel, a popular web hosting control panel, has been disclosed that allows an attacker with mail privileges to execute arbitrary code as root. The flaw affects thousands of websites worldwide and underscores the importance of robust security practices for managed hosting services. The vulnerability, tracked as CVE-2026-1234, was discovered by researchers … Read more

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

A Critical Zero-Day Vulnerability in Chrome’s V8 Engine Exploited in the Wild, Threatening Sandbox Security Google Chrome users are facing a new threat as hackers have begun exploiting a zero-day vulnerability in the browser’s V8 JavaScript engine. This exploit allows attackers to execute malicious code within the sandbox environment, potentially leading to full system compromise. … Read more

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

A massive wave of cyber espionage has been rocking US government agencies, with top security officials accusing Chinese AI firms of exploiting vulnerabilities in cutting-edge language models. At the heart of this scandal are four notorious AI tools: Claude, GPT, Gemini, and Grok – all capable of generating convincing text, manipulating public opinion, and carrying … Read more