Latest IntelligencePage 11
Search by keyword →
Claude Cowork’s Sandbox Vulnerability Allows Attackers to Run Arbitrary Commands as Root
A vulnerability chain in Anthropic’s Claude Cowork allows an attacker with local code execution to escalate privileges and run arbitrary commands as root ...

Google loses final appeal against €4.1 billion Android antitrust fine
The European Union's highest court has upheld a €4.125 billion ($4.8 billion) antitrust fine against Google, bringing to an end the company's appeal over allega...

Scattered Spider member extradited to the U.S. facing cybercrime charges
The U.S. Department of Justice has announced the arrest and extradition of an alleged member of the notorious cybercrime group Scattered Spider. According to th...

CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure
A newly disclosed CitrixBleed-class vulnerability in Citrix NetScaler appliances came under active exploitation less than a day after public disclosure, with de...

DHS Confirms Breach of Information-Sharing Network Platform HSIN
The Department of Homeland Security has confirmed that hackers breached the Homeland Security Information Network (HSIN), a sensitive but unclassified platform ...

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
This week’s security news is mostly about weak spots. Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Every...

ChatGPT File Download Flow Vulnerability Could Be Abused to Access System Files
A proof-of-concept vulnerability chain in ChatGPT that combined a guardrail bypass with a path traversal flaw, potentially allowing attackers to access restrict...

Google loses final appeal to overturn €4.1 billion EU fine
Court of Justice of the European Union (CJEU) has dismissed Google's final appeal against a €4.1 billion ($4.7 billion) antitrust fine over the company's use of...

New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure
Hackers are targeting NetScaler appliances using public PoC code to retrieve arbitrary memory content in the HTTP response. The post New CitrixBleed Vulnerabili...

900+ Oracle E-Business instances Exposed Online Amid Active Vulnerability Exploitation
More than 900 Oracle E‑Business Suite instances have been found exposed on the public internet. At the same time, attackers actively exploit a critical vulnerab...

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to def...
.webp)
Hackers Use Legitimate VLC Executable and Malicious libvlc.dll to Deploy ValleyRAT
Cybercriminals have found a clever way to slip past security defenses by hiding malware inside a program most people trust without a second thought. Researchers...

Hackers Use Fake VLC Executable and Malicious libvlc.dll to Deploy ValleyRAT
Cybercriminals have found a clever way to slip past security defenses by hiding malware inside a program most people trust without a second thought. Researchers...

Opera Blocks Clipboard Attacks, Including ClickFix, With New Paste Protect Feature
Opera has introduced a new built-in security feature called Paste Protect, designed to defend users against clipboard-based cyberattacks, including the increasi...

Microsoft Outlook Bug Removes Copilot Button For Windows Users
A software defect in classic Outlook for Windows caused Copilot Chat and Copilot entry points to vanish for affected users, with Microsoft confirming the issue ...

Agentic Ransomware JADEPUFFER Uses Base64 Python Payloads to Harvest Cloud and API Keys
Ransomware has always needed a human at the keyboard or writing the script behind it. That assumption no longer holds. Researchers have documented what appears ...

Cisco Catalyst Center Vulnerability Allows Remote Attackers to Read Arbitrary Files
Cisco has disclosed a high-severity vulnerability in its Catalyst Center platform that could allow unauthenticated remote attackers to read arbitrary files from...

Hackers Use Mapbox Dead-Drop C2 and Python RAT to Target Vulnerability Researchers
Security researchers have uncovered a long-running campaign that turns trusted proof-of-concept exploits into weapons against the very people who study vulnerab...

How to Conduct a Successful Audit of AI-Driven Software Development
As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks befo...

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspon...