Hackers steal $23.7 million in crypto from Ostium in off-chain attack

A massive cryptocurrency heist has unfolded on the decentralized trading platform Ostium, with attackers making off with a staggering $23.7 million. The incident, which occurred last week, saw the perpetrators exploit vulnerabilities in off-chain infrastructure used to feed prices into the protocol. Ostium has confirmed that an attacker submitted fake price reports and rapidly opened … Read more

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

SonicWall SMA1000 Flaws Exposed as Zero-Days to Install Custom Malware A serious security breach has come to light involving SonicWall’s SMA1000 Secure Mobile Access appliances. Two previously undisclosed vulnerabilities were exploited by threat actors for weeks, allowing them to install custom malware on vulnerable VPN devices. The flaws, tracked as CVE-2026-15409 and CVE-2026-15410, affect SMA1000 … Read more

Estée Lauder discloses data breach via Oracle E-Business flaw

Estée Lauder recently disclosed a data breach that occurred last August, when hackers exploited a vulnerability in the Oracle E-Business Suite system used for human resources operations. The company’s investigation revealed that an unauthorized third party gained access to personal information of certain individuals, including full names, addresses, email addresses, dates of birth, Social Security … Read more

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Four Widely Used AI Coding Agents Hit by Sandbox Escapes, Exposing Developers to Malicious Attacks Security researchers have discovered a critical vulnerability in four popular AI coding agents, allowing attackers to bypass sandbox protections and execute malicious code on developers’ machines. The affected tools include Cursor, OpenAI’s Codex CLI, Google’s Gemini CLI, and Antigravity. This … Read more

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

Cybersecurity experts are still reeling from a brazen attack on the Ostium trading platform, which saw hackers make off with a staggering $23.7 million in cryptocurrency. The assault, which occurred last week, exploited weaknesses in the platform’s off-chain infrastructure to manipulate prices and steal funds from its liquidity provider vault. Ostium is a decentralized trading … Read more

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Zero-Day Attacks Exploit SonicWall SMA1000 Flaws, Push Custom Malware A highly sophisticated threat actor has been exploiting two previously undisclosed vulnerabilities in SonicWall’s SMA1000 Secure Mobile Access appliances for weeks, installing custom malware on vulnerable VPN devices. The attacks took place long before the vulnerabilities were publicly disclosed by SonicWall last week, and experts warn … Read more

Estée Lauder discloses data breach via Oracle E-Business flaw

Estée Lauder’s Data Breach Exposes Sensitive Information of 57,000 Employees and Customers Cosmetics giant Estée Lauder has disclosed a data breach that occurred in August 2025, when hackers exploited a flaw in Oracle E-Business Suite, a software system used by the company for human resources management. The breach exposed sensitive information of certain individuals, including … Read more

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

A massive cyberattack campaign, dubbed “FakeGit,” has been using over 7,600 compromised GitHub repositories to spread malware known as SmartLoader. The attackers have leveraged the trust associated with open-source code hosting platforms like GitHub to distribute their malicious software, putting countless developers and organizations at risk. At its core, FakeGit works by creating fake versions … Read more

CISOs Feel the Heat Over AI Risk

Cybersecurity Executives Feel the Heat as AI Adoption Creates Unprecedented Challenges A recent survey has revealed that a staggering 26% of top cybersecurity executives are considering leaving their jobs due to the pressures brought on by the rapid adoption of artificial intelligence (AI) technologies. This alarming figure highlights the growing concern among security professionals that … Read more

Critical ServiceNow code execution flaw now exploited in attacks

A Critical Vulnerability in ServiceNow’s AI Platform is Being Exploited by Attackers A critical vulnerability in the ServiceNow AI Platform, a popular enterprise-grade platform that helps businesses integrate artificial intelligence into core workflows, has been discovered to be actively exploited by attackers. The vulnerability, known as CVE-2026-6875, allows unauthenticated threat actors to escape the sandbox … Read more