A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion […]
Category: Security
Shock horror — AI-generated security patches fall short of actually solving all the problems they were meant to fix
(Image credit: Getty Images) Researchers tested AI-generated patches on six CVEs with poor success rates Many fixes failed, altered behavior, […]
Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads
(Image credit: Shutterstock) Attackers cloned AI skills, later adding malicious code to steal credentials Zenity Labs found millions of installs […]
Top US hedge funds targeted by major vishing campaign — Blackstone, KKR and CME among those under fire
Image Credit: Pixabay (Image credit: Pixabay) Google’s Threat Intelligence team links BlackFile (now Redact) to phishing and extortion attacks on […]
This ‘classic’ decades-old SQL injection flaw could let hackers take over entire Windows servers, thanks to a nifty database trick
Image Credit: Shutterstock (Image credit: Pixabay) Huntress saw Oracle SQLi used to deploy rare khunt toolkit Khunt enabled OS commands, […]
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the […]
Growing Up The Hard Way
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave […]
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
Swati KhandelwalAug 07, 2026Linux / Vulnerability A use-after-free bug in Linux’s SCTP networking code can be turned into full root […]
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Swati KhandelwalAug 07, 2026Network Security / Vulnerability Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network […]
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control […]
