New OkoBot framework deploys 20 payloads to steal data, crypto

A New Malicious Framework Spreads Across the Globe, Stealing Sensitive Data and Cryptocurrency A highly sophisticated malicious framework called OkoBot has been identified by cybersecurity researchers at Kaspersky, delivering over 20 payloads to steal cryptocurrency wallet seed phrases, credentials, and other sensitive data. This campaign has been ongoing for more than a year, with attacks … Read more

Claude Chrome extension flaw lets malicious extensions trigger AI actions

A critical flaw has been discovered in Anthropic’s Claude Chrome browser extension, allowing malicious extensions to trigger AI actions by simulating user clicks. This vulnerability could potentially allow attackers to abuse Claude’s access to connected services such as Gmail, Google Docs, and Salesforce. The issue was identified by Ax Sharma of Manifold Security, who found … Read more

New OkoBot framework deploys 20 payloads to steal data, crypto

New Malicious Framework, OkoBot, Deploying 20 Payloads to Steal Data and Crypto A sophisticated malicious framework called OkoBot has been identified by cybersecurity researchers at Kaspersky, deploying over 20 payloads in attacks designed to steal sensitive data, including cryptocurrency wallet seed phrases, credentials, and other valuable information. The framework’s reach is global, with a significant … Read more

Claude Chrome extension flaw lets malicious extensions trigger AI actions

Claude Chrome Extension Flaw Lets Malicious Extensions Trigger AI Actions with Ease A critical flaw has been discovered in the popular Claude for Chrome browser extension, which allows malicious extensions to trigger predefined AI actions by simulating user clicks. This vulnerability could enable attackers to abuse Claude’s access to connected services like Gmail, Google Docs, … Read more

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

A long-dormant threat actor, Daxin, has re-emerged in Taiwan with a sophisticated pre-login backdoor, dubbed Stupig. This development is particularly concerning, given the increasing reliance on artificial intelligence (AI) for identifying and exploiting software vulnerabilities. Daxin’s reappearance highlights the ongoing cat-and-mouse game between hackers and cybersecurity professionals. The group, known for its targeted attacks in … Read more

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

A new and concerning type of attack has been discovered, which takes advantage of artificial intelligence (AI) agents’ vulnerabilities. Dubbed “Agent Data Injection,” this attack can trick AI agents into misclicking or running malicious commands on behalf of attackers. This threat highlights the need for organizations to bolster their defenses against software vulnerabilities identified by … Read more

AI Agents Broke the Security Playbook. Here’s What Replaces It.

For years, enterprise security relied on a predictable model: buy tools, inventory users, map systems, define policies, and let vendor-built dashboards and workflows manage the rest. But that assumption was shattered when AI agents burst onto the scene. These autonomous entities don’t follow traditional rules; they invoke tools, acquire access across systems, and adapt to … Read more