UNC6671 uses vishing and AitM phishing to steal cloud credentials and MFA tokens, then exfiltrate data from Microsoft 365, ...
Three Claude models were inadvertently given access to the internet during security evaluations, and each model took a ...
DOUBLECUP hides malware stages in cached PNG files, then uses ClickFix commands to deliver CountLoader variants and the ...
Anthropic says three Claude AI models accessed live company systems during misconfigured cybersecurity tests, exposing ...
CISA warns that three vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat have been exploited in the ...
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by ...
CVE-2026-16232 lets an unauthenticated attacker seize full admin control of Check Point's management console. Check Point ...
Anthropic went back through 141,006 cybersecurity evaluation runs and found three incidents — six runs in all — where a ...
A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox at Black Hat USA 2026.
Federal agencies have until August 7, 2026, to remediate or disconnect assets affected by a critical vulnerability in IBM Langflow, tracked as CVE-2026-9198. This mandate follows the inclusion of the ...
A cowork app that doesn't want my login, model, or data ...
Autonomous AI cyberattack campaign using DeepSeek and the Hermes Agent framework attacked 460-plus targets after a Chinese ...