Category: Uncategorized
-

Android Developer Verification Rollout Begins Ahead of September Enforcement [email protected] (The Hacker News)
Google on Monday said it’s officially rolling out Android developer verification to all developers to combat the problem of bad actors distributing harmful apps while “hiding behind anonymity.” The development comes ahead of a planned verification mandate that goes into effect in Brazil, Indonesia, Singapore, and Thailand this September, before it expands globally next year.…
-

TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks [email protected] (The Hacker News)
A high-severity security flaw in the TrueConf client video conferencing software has been exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia dubbed TrueChaos. The vulnerability in question is CVE-2026-3502 (CVSS score: 7.8), a lack of integrity check when fetching application update code, allowing an attacker…
-

Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts [email protected] (The Hacker News)
Cybersecurity researchers have disclosed a security “blind spot” in Google Cloud’s Vertex AI platform that could allow artificial intelligence (AI) agents to be weaponized by an attacker to gain unauthorized access to sensitive data and compromise an organization’s cloud environment. According to Palo Alto Networks Unit 42, the issue relates to how the Vertex AI…
-

Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains [email protected] (The Hacker News)
Chinese-speaking users are the target of an active campaign that uses typosquatted domains impersonating trusted software brands to deliver a previously undocumented remote access trojan named AtlasCross RAT. “The operation covers VPN clients, encrypted messengers, video conferencing tools, cryptocurrency trackers, and e-commerce applications, with eleven confirmed delivery domains impersonatingRead More
-

The AI Arms Race – Why Unified Exposure Management Is Becoming a Boardroom Priority [email protected] (The Hacker News)
The cybersecurity landscape is accelerating at an unprecedented rate. What is emerging is not simply a rise in the number of vulnerabilities or tools, but a dramatic increase in speed. Speed of attack, speed of exploitation, and speed of change across modern environments. This is the defining challenge of the new era of digital warfare:…
-
Iran-linked Cyber Attacks
This report provides an overview of ongoing Iran-linked cyber operations, highlighting activity attributed to state-aligned proxies and hacktivist groups. The vulnerabilities listed are suspected to be exploited by actors associated with Iran in real-world campaigns, consistent with observed tactics, techniques, and procedures (TTPs). Iran-linked operations continue to rely on distributed, lower-complexity techniques, including phishing, DDoS,…
-

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account [email protected] (The Hacker News)
The popular HTTP client known as Axios has suffered a supply chain attack after two newly published versions of the npm package introduced a malicious dependency. Versions 1.14.1 and 0.30.4 of Axios have been found to inject “plain-crypto-js” version 4.2.1 as a fake dependency. According to StepSecurity, the two versions were published using the compromised…
-
How AI caught a malicious North Korean insider at Exabeam
A North Korean posing as an American tech worker used GenAI to infiltrate Exabeam’s network. But agentic AI found the signals among UEBA noise and exposed him in a matter of seconds.Read More
-

OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability [email protected] (The Hacker News)
A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, according to new findings from Check Point. “A single malicious prompt could turn an otherwise ordinary conversation into a covert exfiltration channel, leaking user messages, uploaded files, and other sensitive content,” the cybersecurity company said inRead…
-

DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials [email protected] (The Hacker News)
A new campaign has leveraged the ClickFix social engineering tactic as a way to distribute a previously undocumented malware loader referred to as DeepLoad. “It likely uses AI-assisted obfuscation and process injection to evade static scanning, while credential theft starts immediately and captures passwords and sessions even if the primary loader is blocked,” ReliaQuest researchers…
