Five Venezuelans plead guilty to ATM jackpotting attacks in US

Five Venezuelans Plead Guilty in High-Profile ATM Jackpotting Case A group of five Venezuelan nationals has pleaded guilty to attempting to drain millions from automated teller machines (ATMs) across the United States. The defendants, who targeted vulnerable ATMs using malware, have been charged with conspiracy to commit bank larceny and are facing significant prison sentences. … Read more

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

A wave of targeted attacks is sweeping through various sectors, exploiting critical vulnerabilities in programming languages and frameworks. The hackers are using these weaknesses to probe for sensitive credentials and establish command-and-control (C2) channels, ultimately leading to devastating breaches. This alarming trend affects organizations worldwide, including those in finance, healthcare, and government. At the heart … Read more

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Russian-Aligned Malware Exploits AI Vulnerabilities, Disrupts Analysis A sophisticated malware strain linked to Russian-aligned threat actors has been discovered to inject a nuclear weapon prompt into AI-driven systems, deliberately disrupting their analysis capabilities. This clever tactic is designed to hinder cybersecurity analysts’ efforts in identifying and mitigating the threat, allowing malicious actors to maintain control … Read more

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

Attackers Steal METR API Key, Drain AI Credits Worth Over $600,000 in Sophisticated Heist A brazen cyber attack has left a prominent artificial intelligence (AI) platform reeling after thieves made off with an API key and drained credits worth over $600,000. The heist highlights the ongoing threat of identity exposure, where attackers exploit compromised credentials … Read more

Boston Scientific Still Recovering From Cyberattack

Boston Scientific Still Struggling to Recover from Devastating Cyberattack US medical technology giant Boston Scientific is facing a daunting task as it struggles to recover from a highly disruptive cyberattack that has brought its global operations to a near-halt. The attack, which was first detected on August 25, has disrupted critical functions such as product … Read more

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Critical Ruby on Rails Vulnerability Exploited in the Wild, Putting Thousands at Risk A severe vulnerability in the popular web framework Ruby on Rails is being actively exploited by hackers, putting thousands of websites and applications at risk. The flaw, tracked as CVE-2026-66066 (CVSS score 9.5), allows attackers to execute arbitrary code on affected servers, … Read more

PaperCut Exploitation Escalates to Active Intrusions

A growing number of organizations are falling victim to a sophisticated cyber attack campaign that exploits two vulnerabilities in PaperCut’s print management solutions, NG and MF. Threat actors have shifted from reconnaissance to hands-on-keyboard activity, compromising vulnerable systems and deploying remote access tools. PaperCut first issued warnings about an actively exploited zero-day vulnerability on August … Read more

Recently patched PaperCut zero-days used in data theft attacks

A devastating new wave of cyberattacks has emerged, exploiting two recently patched vulnerabilities in the PaperCut print management software used by millions worldwide. The security flaws, tracked as CVE-2026-81578 and CVE-2026-82078, can be chained to bypass authentication and grant attackers remote code execution on vulnerable servers. This has led to a surge in data theft … Read more

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Critical Vulnerabilities Exposed in Langflow and Rails, Leaving Thousands of Websites Open to Credential-Probing and C2 Activity A devastating combination of vulnerabilities in Langflow and Rails has left thousands of websites vulnerable to credential-probing and command-and-control (C2) activity. Attackers have been exploiting these critical flaws to gain unauthorized access to sensitive data and disrupt business … Read more

Judge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’

A Federal Judge Slams the Pentagon’s Actions Against AI Firm Anthropic, Ruling Them “Illegal and Baseless” In a scathing rebuke, US District Judge Rita Lin has ruled that the Pentagon acted unlawfully in labeling artificial intelligence company Anthropic as a supply chain risk earlier this year. The government had designated the firm as a threat … Read more