New OkoBot framework deploys 20 payloads to steal data, crypto

New Malicious Framework, OkoBot, Deploying 20 Payloads to Steal Data and Crypto A sophisticated malicious framework called OkoBot has been identified by cybersecurity researchers at Kaspersky, deploying over 20 payloads in attacks designed to steal sensitive data, including cryptocurrency wallet seed phrases, credentials, and other valuable information. The framework’s reach is global, with a significant … Read more

Claude Chrome extension flaw lets malicious extensions trigger AI actions

Claude Chrome Extension Flaw Lets Malicious Extensions Trigger AI Actions with Ease A critical flaw has been discovered in the popular Claude for Chrome browser extension, which allows malicious extensions to trigger predefined AI actions by simulating user clicks. This vulnerability could enable attackers to abuse Claude’s access to connected services like Gmail, Google Docs, … Read more

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

A long-dormant threat actor, Daxin, has re-emerged in Taiwan with a sophisticated pre-login backdoor, dubbed Stupig. This development is particularly concerning, given the increasing reliance on artificial intelligence (AI) for identifying and exploiting software vulnerabilities. Daxin’s reappearance highlights the ongoing cat-and-mouse game between hackers and cybersecurity professionals. The group, known for its targeted attacks in … Read more

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

A new and concerning type of attack has been discovered, which takes advantage of artificial intelligence (AI) agents’ vulnerabilities. Dubbed “Agent Data Injection,” this attack can trick AI agents into misclicking or running malicious commands on behalf of attackers. This threat highlights the need for organizations to bolster their defenses against software vulnerabilities identified by … Read more

AI Agents Broke the Security Playbook. Here’s What Replaces It.

For years, enterprise security relied on a predictable model: buy tools, inventory users, map systems, define policies, and let vendor-built dashboards and workflows manage the rest. But that assumption was shattered when AI agents burst onto the scene. These autonomous entities don’t follow traditional rules; they invoke tools, acquire access across systems, and adapt to … Read more

Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide

A Critical Flaw in Shark Vacuum Systems Exposes Thousands to Remote Control and Data Theft Risks In a disturbing revelation, researchers have uncovered an unpatched vulnerability in certain Shark vacuum models that could allow malicious actors to remotely control affected devices and access sensitive user data. The flaw affects thousands of owners across the United … Read more

AI Can Find Bugs, But Human Knowledge Still Proves Them

A newly developed artificial intelligence (AI) system is uncovering critical software vulnerabilities at an unprecedented rate, but experts warn that human knowledge and expertise are still essential to verify and validate these findings. This AI-powered vulnerability discovery process works by feeding vast amounts of code into machine learning algorithms, which then identify patterns indicative of … Read more

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

A Critical Flaw in n8n Token Exchange System Puts Users at Risk of Account Takeover A severe security vulnerability has been discovered in the token exchange system of n8n, an open-source workflow automation platform widely used by developers and organizations. The flaw allows attackers to hijack user accounts from other issuers, compromising sensitive data and … Read more

ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

A new wave of sophisticated threats is sweeping through the online landscape, targeting gamers, consumers, and businesses alike with increasingly cunning tactics. This month’s crop of security breaches highlights the growing importance of staying vigilant against AI-powered attacks, from game cheat spyware to high-stakes 24-hour ransomware demands. At the heart of these developments lies a … Read more