News Archive
1920 stories · page 74 of 80Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
This week’s security news is mostly about weak spots. Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everything looks normal until someone tests a small gap and finds a way through. This

Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture
Rapid7's Red Team has developed a multi-agent AI architecture to formalize their offensive methodology, mirroring how threat actors are using AI. This system automates and accelerates tasks like reconnaissance and vulnerability discovery throughout the penetration testing lifecycle. The initiative, part of Anthropic's Project Glasswing, involved integrating AI models to enhance vulnerability analysis and exploit chain development, providing insights into defending against AI-driven attacks.

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspondence via the Google API. "In this campaign, the attackers focused their attenti

Context Engineering | Compaction & Agent Memory for Automated Malware Analysis
SentinelLABS has evaluated OpenAI's native context compaction feature for automated malware analysis, finding it significantly reduces token usage and costs without impacting overall task quality. Compaction compresses past context into a denser working state, which is crucial for long-running agent tasks where context can accumulate rapidly and degrade performance. While effective, the analysis noted a slight decrease in the model's ability to recover higher-level structural reasoning, underscoring the need to store critical artifacts in durable storage rather than relying solely on compacted context.

Anthropic's AI Finds Bugs. IBM Bets $5B It Can Fix Them.
IBM and Red Hat assign 20,000 engineers to the new Project Lightwell service as Anthropic's Mythos findings ignite debate over how to secure the open source software supply chain.

Identity Lifecycle Management Wasn't Built for AI Agents
Identity lifecycle management was architected around a person with an employment record, a manager, and a departure date. AI agents have none of those. As autonomous principals proliferate across enterprise environments, the governance mode

Cybersecurity Mission Creep in the US
Interesting paper: “Cybersecurity Mission Creep.” Abstract: Cybersecurity is experiencing mission creep. Policymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinform

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: br

Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects
Kaspersky's 2025 compromise assessments revealed that many organizations struggle with undetected threats, with a significant portion of high-severity incidents remaining hidden for months or even years. A substantial percentage of these missed threats were only identified through proactive assessments, highlighting gaps in existing security tools' alerting capabilities. The analysis also noted that attackers frequently utilize remote management tools and living-off-the-land binaries, and that malicious files can persist even in backups.

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. "An operator tied to Forti

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new

Inside Elastic InfoSec's agentic SOC: cutting alert triage from 30 minutes to under 3
Elastic's InfoSec team has developed an automated security operations center (SOC) that significantly reduces alert triage time. By using deterministic queries and specialized AI agents, the system handles most alert investigations before human analysts are involved, cutting down a 30-minute process to under three minutes. This approach leverages Elastic's own technology stack and focuses on efficient, cost-effective automation to manage increasing alert volumes.

Smashing Security podcast #474: Polymarket can predict the future. So how did it miss this hack?
Polymarket has built an entire business on predicting the future. So how did it manage to spectacularly fail to predict its own hack? Plus, the Google engineer with a million-dollar secret, and the curious case of the airport hairdryer. Mea

Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS
Attackers fingerprint victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability.

And the Winner in Dominant Malware Delivery? ClickFix
Researchers say the highly effective social engineering technique is no longer the exception for malware attacks — it's now the rule.

Microsoft named a leader in the Frost Radar for cloud and application runtime security
A new report from Frost & Sullivan identifies Microsoft as a leader in cloud and application runtime security. The report highlights a market shift towards contextual risk reduction, focusing on how exposures combine across infrastructure and applications to create exploitable attack paths. Microsoft's position is attributed to its extensive ecosystem, the capabilities of Microsoft Defender for Cloud integrated with Defender XDR, and its large customer base.

When Too Much Security Data Becomes the Risk
Rapid growth turned routine firewall logs into a security and budget liability. One CISO used artificial intelligence to filter what data truly belongs in the SIEM.

5 Myths About AI in the SOC Security Teams Need to Rethink
Security operations teams are increasingly adopting AI, but common assumptions about its role need reevaluation. Experts suggest AI should augment, not replace, human analysts by handling repetitive tasks and data processing. While automation is beneficial for enrichment and triage, critical actions still require human oversight. Transparency and explainability are crucial for building trust and ensuring analysts can confidently use AI outputs.

'Phantom Squatting': An Emerging AI-Driven Supply Chain Threat
LLMs consistently hallucinate Web domains for legitimate brands that attackers can register for malicious activity in a difficult-to-detect attack vector.

Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula
Cybersecurity researchers have identified a new campaign by the banking Trojan Ousaban, primarily targeting users in Spain and Portugal. The malware, previously active in Brazil, is distributed via a sophisticated phishing PDF that leads victims to a malicious webpage. This page employs environmental and geo-fencing checks to ensure only intended targets download the payload, which includes a VBS script and the Ousaban executable. The Trojan then establishes persistence, decrypts banking-related strings using a custom algorithm, and communicates with command-and-control servers through dynamically generated hostnames.

Safe Events Start With Threat Intel & Digital Security
Proactive cybersecurity measures are essential for ensuring the smooth operation of events. By anticipating potential digital threats, organizers can prevent disruptions and maintain a secure environment.

Building more resilient CNI: what industry pen testers told us
Penetration testers have shared insights into how organizations can enhance the resilience of their Container Network Interface (CNI) deployments. Their recommendations aim to make it harder for attackers to exploit vulnerabilities within containerized environments.

Texas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches
Several organizations experienced significant security incidents this week. The Texas Parks and Wildlife Department suffered a data breach affecting over 3 million customers due to a vendor compromise, exposing personal information but not financial or social security data. Additionally, a supply chain attack on WordPress plugin vendor ShapedPlugin delivered malicious updates, leading to credential theft and website modifications. AI-powered threats are also on the rise, with a new phishing service called EvilTokens exploiting device-code authentication to steal Microsoft 365 tokens.

Papa Johns Surveillance-Based Advertising
Papa Johns is spying on people’s buying activities to predict when they are low on food: The pizza chain recently tapped NBCUniversal, Instacart and the dentsu-owned media agency Carat for help reaching consumers when they’re low on groceri