Category: Uncategorized
-

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. LangGraph is an open-source framework created by LangChain to build complex, stateful, and multi-agent artificial intelligence (AI) agentic applications. “An SQL injection in LangGraph’s function couldRead More
-
It’s time to update incident response for the AI era
Your latest cybersecurity incident might not be a threat actor, but an internal AI agent doing what it’s authorized to do. Incident response must evolve to accommodate AI.Read More
-

INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator [email protected] (The Hacker News)
An INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday. The effort, codenamed Operation Ramz, took place between October 2025 and February 2026, and saw authorities from 13 countries in the Middle East and North Africa (MENA) region making 201 arrests. Included among them was…
-

Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs [email protected] (The Hacker News)
Authorities in Europe have disrupted AudiA6, a cryptocurrency laundering service used by ransomware gangs and cybercriminal networks. Europol, in a statement issued Thursday, said the dismantling of AudiA6 cut off a “key financial pipeline used to wash hundreds of millions in illicit profits.” The service is estimated to have been used to launder more than…
-

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities [email protected] (The Hacker News)
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google’s Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish…
-

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets [email protected] (The Hacker News)
Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs. Imperva buried instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them. Varonis built…
-

New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files [email protected] (The Hacker News)
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender. “This was an accidental discovery, it took a total of 4 hours to find this,” the researcher said in a post on Blogger. “If you ever attempted to…
-

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm [email protected] (The Hacker News)
A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis). According to a detailed reportRead More
-
How to build AI security guardrails without blocking innovation
To take advantage of opportunities AI might present — without opening the door to a breach — an organization needs to put the right guardrails in the right places.Read More
-
The prosecution gap: Why cybercrimes go unpunished
Are cybersecurity criminals simply acting with impunity? It sometimes feels like it. Learn what defenders need to know and what investigators are doing about it.Read More
