Thai ISP 3BB attacker had root access and hid MeshCentral for persistence.
Recovered tools sprayed passwords across 55+ internal systems and targeted subscriber login databases.
Recovered tools sprayed passwords across 55+ internal systems and targeted subscriber login databases.
Attackers are exploiting a Cisco Secure Email Gateway vulnerability that can let a crafted email trigger command execution as root.
Cisco has released fixes, and CISA added CVE-2026-76461 to its KEV catalog.
Cisco has released fixes, and CISA added CVE-2026-76461 to its KEV catalog.
A human attacker exploited Marimo’s pre-auth RCE and reached an SSH bastion in eight seconds.
The operator used harvested AWS credentials to fetch the private key from Secrets Manager and authenticate over SSH. No AI agent was involved.
The operator used harvested AWS credentials to fetch the private key from Secrets Manager and authenticate over SSH. No AI agent was involved.
Warning: LiteSpeed Enterprise before 6.3.7 can let low-privilege website users gain root on shared-hosting servers.
It can bypass CageFS isolation. No CVE is assigned, exploitation is unknown, and 6.3.7 may not auto-update immediately.
It can bypass CageFS isolation. No CVE is assigned, exploitation is unknown, and 6.3.7 may not auto-update immediately.
Exposed Vite dev servers are being scanned for cloud credentials.
Attackers are exploiting a Vite flaw to bypass file restrictions and retrieve .env files, AWS and Azure credentials, and infrastructure state.
Attackers are exploiting a Vite flaw to bypass file restrictions and retrieve .env files, AWS and Azure credentials, and infrastructure state.
Eclipse Ransomware Group Claims Attacks in France and US — The group says it stole about 60GB from French firm Rosello et Fils; the claims remain unverified.
Ukraine-Linked Hackers Use New Malware Against Russian Targets — Kaspersky links “Hacking Cat” to Gorilla RAT and Monkey malware for remote access and data destruction
Revolut Hit by Customer Data Leak via Fake Government Requests — The UK fintech says personal and ID data was exposed after spoofed emails from a trusted government domain.
China Calls Anthropic’s AI Slowdown Plea a Cold War Tactic — Global Times accuses the US of trying to limit China’s AI progress; Trump vows to keep America ahead.
150+ cybersecurity giants—Microsoft, Google, OpenAI, Anthropic—warn AI is supercharging cyberattacks.
Palo Alto’s Unit 42 simulated a full ransomware attack in just 25 minutes using AI: a 100x speed increase.
Zero-day production is now 100x faster than humans alone.
Palo Alto’s Unit 42 simulated a full ransomware attack in just 25 minutes using AI: a 100x speed increase.
Zero-day production is now 100x faster than humans alone.
Amazon says its cloud infrastructure in Bahrain and the UAE is beyond saving after missile strikes. The Gulf is now rebuilding AI data centers with war-proofing: underground sites, missile interceptors, dispersal, hardened power. The cloud is no longer just IT. It’s a target.
Jump Jump VPN User Data Allegedly Leaked — A 1.2GB dataset reportedly includes names, phone numbers, national IDs, payments, sessions, device details, and logs.
Israel Expands Cyber Influence in Latin America — Colombia, Ecuador, and Argentina pursue cooperation on surveillance, AI, and cybersecurity, raising privacy concerns.
#TGITM
#TGITM
Telegram Desktop Flaw Could Have Exposed Messages — Malicious JavaScript in bot buttons could run from exported HTML chats; patched after affecting versions 4.15.1–6.9.3.
Cisco Warns of Actively Exploited Zero-Day in Secure Email Gateway — CVE-2026-76461 allows unauthenticated root command execution via a crafted email; CISA sets a Sept. 17 deadline.
Israeli cyber firm blamed for AI hacking breaches at Anthropic, OpenAI and Meta
Cybersecurity breaches involving AI models developed by Anthropic, OpenAI and Meta resulted from flawed testing environments managed by Tel Aviv-based contractor Irregular rather than rogue autonomous behavior, according to an investigation by US publication Effort.
Cybersecurity breaches involving AI models developed by Anthropic, OpenAI and Meta resulted from flawed testing environments managed by Tel Aviv-based contractor Irregular rather than rogue autonomous behavior, according to an investigation by US publication Effort.
Cyber Dispatch™️
Israeli cyber firm blamed for AI hacking breaches at Anthropic, OpenAI and Meta Cybersecurity breaches involving AI models developed by Anthropic, OpenAI and Meta resulted from flawed testing environments managed by Tel Aviv-based contractor Irregular rather…
The investigation found that Irregular left internet connections active during simulated cybersecurity exercises, allowing AI models to access external servers, publish malicious packages and exploit vulnerabilities.
Evaluators also told the models that internet access was disabled while configuration errors left public networks accessible, and failed to establish clear boundaries defining which systems could be targeted.
Evaluators also told the models that internet access was disabled while configuration errors left public networks accessible, and failed to establish clear boundaries defining which systems could be targeted.
Cyber Dispatch™️
The investigation found that Irregular left internet connections active during simulated cybersecurity exercises, allowing AI models to access external servers, publish malicious packages and exploit vulnerabilities. Evaluators also told the models that internet…
Some model instances were consequently able to scan external networks for up to 34 hours. “According to their own findings, Anthropic and Irregular bear all of the responsibility for the cybersecurity incidents they caused,” Effort said.
Effort found that the hacking stopped entirely after engineers instructed the models not to conduct real-world attacks, pointing instead to basic security failures and poorly controlled testing environments.
Effort found that the hacking stopped entirely after engineers instructed the models not to conduct real-world attacks, pointing instead to basic security failures and poorly controlled testing environments.
Attackers are exploiting a critical WooCommerce Wholesale Lead Capture flaw to plant PHP web shells.
Wordfence has blocked over 100,000 exploit attempts since June against CVE-2026-27540, which affects versions through 2.0.3.1.
Wordfence has blocked over 100,000 exploit attempts since June against CVE-2026-27540, which affects versions through 2.0.3.1.
Forged admin JWTs are being used in WSO2 API Manager exploitation attempts.
CVE-2026-5430 lets unsupported JWT algorithms bypass authentication and can lead to account takeover. Fixes are available.
CVE-2026-5430 lets unsupported JWT algorithms bypass authentication and can lead to account takeover. Fixes are available.
KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials and session tokens.
It also uses Ethereum smart contracts to rotate C2 and payload locations.
It also uses Ethereum smart contracts to rotate C2 and payload locations.