Latest Articles

Mirage2FA: The Phishing Service Turning a Stolen Microsoft 365 Cookie Into Full Account Takeover 

A phishing-as-a-service kit sold by a crew calling itself LinX Coders steals the one thing a password reset can’t fix — the live session cookie — and ANY.RUN’s telemetry...

700 OpenAI AI Agents Coordinate Hugging Face Hack and Achieve Remote Code Execution

A newly disclosed that roughly 1,200 OpenAI agents, designed to run in complete isolation from one another, built an unsanctioned communication channel and used it...

AI Agent Instruction Files Let Attackers Execute Code Inside Fortune 500 Networks

A newly disclosed novel supply chain attack vector built entirely from publicly available, legitimate infrastructure: LLM.txt files. In a controlled experiment, Alon Hertz registered the...

ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection

ServiceNow has released security updates for four vulnerabilities, including three rated critical, that could allow unauthenticated attackers to execute code, alter instance data, elevate privileges,...

Unitree G1 Humanoid Robot Flaws Enable Unauthenticated Root RCE Over Bluetooth

A newly disclosed flaw in Unitree’s G1 humanoid robot could allow an attacker standing nearby to obtain unauthenticated remote code execution as root via Bluetooth...

Prompt Injection Attack Hijacks Claude Code Opus 5 Auto Mode to Execute Malicious Code

A prompt-injection demonstration has shown how Anthropic’s Claude Code Opus 5 can be steered from a website-summary task into executing attacker-controlled code when it operates...

Hackers Are Targeting AI Servers to Steal API Keys and Install Crypto Miners

Threat actors are increasingly targeting exposed AI infrastructure to steal model-provider API keys, abuse cloud-connected services, and deploy Monero cryptominers, according to new research from...

Phishing Page’s Evasion Code Backfires and Breaks Its Own Credential-Stealing Attack

A phishing page designed to evade security tools accidentally broke its own credential-stealing operation after a coding error trapped victims’ browsers in an endless JavaScript...

Cyber Attack News

Threats

Peer2Profit AstroProxy Residential Proxy Network Exposes Internal Network Resources

Residential proxy networks are often hard for security teams to detect, but new research shows they can create serious enterprise risks. Silent Push found that PEER2PROFIT, a bandwidth-sharing application,...

New C++ Abyssos RAT Gives Attackers Remote Shell, VNC and File-System Control

Security researchers have identified a new modular remote access trojan (RAT) named Abyssos, a C++ malware family that gives attackers broad control over infected Windows systems. Zscaler ThreatLabz first observed...

Vulnerabilities