Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin

Apple is facing a lawsuit over its handling of cryptocurrency wallet apps on the App Store, with three individuals claiming that approximately $1.8 million in Bitcoin was stolen after they downloaded and used a fake Sparrow Wallet application. The plaintiffs allege that Apple failed to adequately review and monitor applications distributed through the App Store, … Read more

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybercrime Groups Exploit Remote Access Tools to Gain Unfettered Access to Networks A sophisticated cyberattack campaign, dubbed Operation BlueDash, has been uncovered, with hackers leveraging fake Microsoft Teams updates to deploy malicious remote management tools on unsuspecting organizations’ networks. The operation’s goal is to gain unfettered access to sensitive systems, underscoring the increasing threat posed … Read more

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

Cybersecurity researchers have uncovered a critical vulnerability in n8n, an open-source workflow automation platform widely used by businesses and developers. The bug, dubbed “Sandbox Escape,” allows malicious actors to execute system commands as the n8n process, potentially leading to data breaches and other serious security incidents. The vulnerability lies in the way n8n’s sandboxed execution … Read more

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

Cybersecurity experts are sounding the alarm about a new wave of threats that arise from artificial intelligence (AI) models, which can identify and exploit software vulnerabilities at an unprecedented scale. This trend has serious implications for businesses and individuals alike, as it allows attackers to pinpoint weaknesses in systems and launch targeted attacks. The AI-powered … Read more

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

A Critical Public Exploit Has Been Released for a Previously Patched vBulletin Flaw, Putting Thousands of Sites at Risk A severe vulnerability in the popular online community platform vBulletin has resurfaced in the form of a public exploit, putting thousands of websites that still haven’t patched the flaw at significant risk. The exploit allows attackers … Read more

Coca-Cola confirms data theft in Fairlife ransomware attack

Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack, Production Mostly Resumed A ransomware attack on Coca-Cola’s dairy subsidiary, Fairlife, has resulted in the theft of sensitive data, the company confirmed yesterday. The cyberattack, which was first disclosed by the global beverages giant earlier this month, disrupted production operations at Fairlife’s four US facilities, but most … Read more

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity Threats Escalate as Operation BlueDash Exploits Remote Management Tools A sophisticated cyberattack campaign, dubbed Operation BlueDash, has been uncovered, targeting organizations with fake software updates that compromise remote management tools. This malware-driven operation leverages a combination of Level RMM (Remote Monitoring and Management) and ScreenConnect to gain unauthorized access to corporate networks. At its … Read more

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

A critical vulnerability has been discovered in the popular workflow automation tool n8n, allowing unauthorized access to sensitive system resources. The flaw, known as an “out-of-sandbox” escape, allows malicious actors to execute arbitrary operating system commands with elevated privileges, posing a significant risk to organizations that rely on the platform. The issue stems from a … Read more

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

As AI-generated malware continues to evolve and become increasingly sophisticated, security teams are being outsmarted by rogue agents designed to exploit software vulnerabilities. In a disturbing trend, researchers have discovered that these AI models can identify previously unknown flaws in code, making it easier for attackers to breach even the most secure systems. The vulnerability … Read more

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

A freshly disclosed exploit for a pre-authentication code execution vulnerability in vBulletin, a popular online forum software, is wreaking havoc on unsuspecting users. The bug, first patched by vBulletin’s developers several months ago, has been exploited by attackers to inject malicious code and steal sensitive data from compromised websites. The vulnerable software, widely used by … Read more