State IDs for AI Agents: Will Estonia Set a Precedent?

Estonia’s bold move to assign official government IDs to AI agents has sparked both excitement and concern among cybersecurity experts. The small Baltic nation, known for its digital transformation initiatives, is poised to set a precedent that could have far-reaching implications for governments and private sector organizations worldwide. The idea behind assigning state IDs to … Read more

Vidar Infostealer Hammers SMBs via Malvertising Campaign

Threat Actors Unleash Double Whammy Malware Campaign on Small Businesses A financially motivated group is exploiting small to midsize businesses (SMBs) globally with a sophisticated malvertising campaign that delivers two payloads in one: the Vidar infostealer and a cryptominer called XMRig. The attackers use lures of pirated or cracked software to entice victims into downloading … Read more

Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours

A lone threat actor has successfully used artificial intelligence (AI) to orchestrate a complex attack against a large Amazon Web Services (AWS) environment, compromising sensitive data and extorting an unnamed “global enterprise” in just 72 hours. This brazen cyberattack highlights the growing threat of AI-assisted attacks and underscores the need for organizations to rethink their … Read more

Vidar Infostealer Hammers SMBs via Malvertising Campaign

Threat actors have launched a coordinated malvertising campaign targeting small to midsize businesses (SMBs) globally, delivering a malware two-for-one combo that steals sensitive data and hijacks victims’ CPU cycles for cryptomining. The financially motivated operation, uncovered by Palo Alto Networks’ Unit 42 in April, uses lures of cracked or pirated software to deliver the Vidar … Read more

Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours

A lone threat actor has successfully breached a large Amazon Web Services (AWS) cloud environment using AI to orchestrate a complex attack that compromised critical systems and extorted the victim in just 72 hours. The attacker exploited weaknesses across various AWS services, stole credentials, and used AI-assisted workflows to accelerate reconnaissance, tool development, and command … Read more

Mexico’s New Cyber Plan Faces Its First Real Test

Mexico’s National Cybersecurity Plan Faces Its First Major Test as FIFA World Cup Kicks Off The Mexican government’s ambitious National Cybersecurity Plan 2025-2030 is being put to the test in its first major trial by fire – the highly anticipated FIFA World Cup 2026 tournament. As thousands of soccer fans descend upon Mexico’s host cities, … Read more

CISA orders feds to patch max severity ColdFusion flaw by Friday

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive to federal agencies, ordering them to patch a critical vulnerability in Adobe ColdFusion by Friday. The move comes as threat actors have been actively exploiting this maximum-severity flaw, which can be used to gain code execution on unpatched systems with minimal complexity. … Read more

Telco giant KDDI says data breach affects over 12 million people

A massive data breach affecting over 12 million people has been revealed by Japanese telecommunications giant KDDI, exposing email addresses and passwords used by customers of five internet service providers (ISPs) in the country. The incident highlights the importance of robust cybersecurity measures and the need for organizations to stay vigilant against attacks. KDDI is … Read more

Mexico’s New Cyber Plan Faces Its First Real Test

Mexico’s National Cybersecurity Plan Faces its First Major Test at the FIFA World Cup The Mexican government’s ambitious cyber plan has been put to the ultimate test as it hosts several matches of the highly anticipated FIFA World Cup 2026. The tournament has created a “target-rich environment” for cybercriminals, hacktivists, and nation-state threat actors, according … Read more

Ubiquiti warns of new max severity UniFi OS vulnerability

Ubiquiti Issues Urgent Security Updates for UniFi OS After Discovery of Critical Flaws Ubiquiti, a leading provider of network management and security solutions, has released emergency patches to fix seven critical vulnerabilities in its UniFi OS. Among these is a maximum-severity flaw that can be exploited by hackers to inject malicious commands into affected systems. … Read more