A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial […]
Category: Security
World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
Ravie LakshmananJul 20, 2026AI Security / Vulnerability In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that […]
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems […]
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow […]
‘The bypass is still six lines of JavaScript’: Security experts warn that Claude for Chrome browser extension could be hijacked, despite it alerting Anthropic several times that something was wrong
Anthropic’s Claude extension flaws allow fake clicks to launch sensitive AI workflows Researchers found vulnerable handlers unchanged across eight extension […]
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Ravie LakshmananJul 19, 2026Malware / Cyber Warfare Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to […]
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 […]
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Swati KhandelwalJul 17, 2026Vulnerability / Web Security An anonymous HTTP request can run code on a WordPress site. The bug […]
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that […]
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Ravie LakshmananJul 17, 2026Software Supply Chain / Malware Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting […]
