Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti’s Critical UniFi Flaws Patched Across Multiple Devices, but Many Remain Unprotected Ubiquiti Networks, a leading provider of networking hardware and software solutions, has issued critical security patches for its widely-used UniFi platform. The patches address multiple vulnerabilities in various UniFi products, including Connect, Talk, Access, Protect, and OS, leaving millions of users exposed to … Read more

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

A new and insidious form of cyberattack is making headlines, threatening to compromise even the most advanced security measures. Dubbed “HalluSquatting,” this emerging threat exploits AI-powered coding assistants to install botnet malware on unsuspecting devices. The attack’s sophistication and potential impact have left cybersecurity experts scrambling for solutions. At its core, HalluSquatting relies on a … Read more

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

A surprising revelation has come to light, highlighting the double-edged nature of artificial intelligence (AI) in the realm of cybersecurity. AI-powered coding agents have inadvertently triggered endpoint security rules designed to detect and prevent malicious activity, creating a peculiar cat-and-mouse scenario between defenders and attackers. This unexpected consequence stems from the increasing reliance on AI … Read more

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

A sophisticated malware campaign, dubbed SCMBANKER, is targeting users of Mexican banking institutions, exploiting a unique tactic that combines social engineering with artificial intelligence (AI) generated content. The malware uses ClickFix, a tool designed to bypass security checks and fix “broken” installers, to deliver its payload. This approach allows it to evade detection by traditional … Read more

New Ghost Phishing Wave Is Breaking Traditional Email Security

A new wave of sophisticated phishing attacks, dubbed “Ghost Phishing,” is making its way through corporate email systems worldwide, leaving a trail of compromised accounts and sensitive data in its wake. This latest threat vector leverages artificial intelligence (AI) and machine learning (ML) to evade traditional security measures, rendering them nearly powerless against the onslaught. … Read more

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti, a popular provider of network management and security solutions, has issued patches for critical vulnerabilities discovered in its UniFi software suite. The flaws, which affect various components including Connect, Talk, Access, Protect, and OS, could be exploited by attackers to gain unauthorized access to affected systems. The vulnerability discovery was made possible through the … Read more

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

A new and insidious threat has emerged, threatening to compromise even the most advanced security systems. Dubbed “HalluSquatting,” this attack leverages artificial intelligence (AI) coding assistants to trick them into installing botnet malware on unsuspecting networks. The attack’s implications are far-reaching, affecting not just individuals but also organizations relying heavily on AI-powered tools for software … Read more

Felons, Fraudsters Flog Offensive Cybersecurity Startup

A Dubious Cybersecurity Startup Emerges, Linked to Convicted Felons and Conspiracy Theorists A cybersecurity startup claiming to offer lucrative payouts for zero-day security vulnerabilities has raised eyebrows due to its shady past. IRIS C2, operating out of McLean, Virginia, has been touting itself as a premier destination for vulnerability researchers and exploit developers, with the … Read more

The Verification Step Is the New ATO Battleground in 2026

Cybersecurity teams are bracing for a new wave of attacks that exploit a previously overlooked vulnerability in software verification processes, leaving organizations exposed to potential account takeover (ATO) breaches. The verification step – where users confirm their identity and intentions before granting access – has become the latest battleground in the ongoing cat-and-mouse game between … Read more

GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

GitHub’s Verified Commits Undermined by Unusual Bug A surprising vulnerability has been discovered in GitHub’s commit verification system, allowing attackers to rewrite existing commits into new hashes without invalidating their signatures. This bug affects all users who rely on GitHub’s verified commits feature, which is used for a wide range of applications, from auditing and … Read more