ποΈ Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A macOS ClickFix operation spanning more than 250 frontend domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks. The serverside gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
OpenAI said it disrupted a Cambodiabased scam operation that used its generative artificial intelligence AI chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have discovered more than halfadozen services advertisements for illegal access to artificial intelligence AI models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims to offer access to Anthropic's large language models LLMs, including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. "Advertisements for Poison Claude.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an opensource control plane for teams of artificial intelligence AI agents, and both paths rely on importing a malicious agent and starting it. A third flaw could expose sensitive data and controlplane details through application programming interface API routes.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A crosstenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchainbased commandandcontrol C2 technique that conceals the C2 server IP address inside a madeup destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianiraui" and "fluidtypeui," has been codenamed NullReceiver by.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of defaultconfigured distributions, and a public exploit ships with prebuilt records for roughly 800 kernel builds. The vulnerability, tracked as CVE202664531 CVSS score 7.8 and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attackercontrolled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources, creating a direct path to data exposure, financial fraud,.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
β€1
ποΈ Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
An unauthenticated attacker can read any file the service account can access on Gitea, the selfhosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Orgmode markup are enough. The flaw is fixed in Gitea 1.27.1. The fileread flaw is tracked as CVE202659774, rated Critical with a CVSS score of 9.8, and received its.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Leaked n8n API Tokens Exposed Live Instances to Credential Theft ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
β€1
π 10 Best AI SOC Vendors without Lock-In Contracts : Data Portability Clauses, Log Ownership, and Exit Rights Compared Across 6 Platforms π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Which AI SOC vendors let you own your logs and leave freely? Discover data portability, sovereignty, and exit clauses compared across 6 platforms. The post 10 Best AI SOC Vendors without LockIn Contracts Data Portability Clauses, Log Ownership, and Exit Rights Compared Across 6 Platforms appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
10 Best AI SOC Vendors without Lock-In Contracts : Data Portability Clauses, Log Ownership, and Exit Rights Compared Across 6 Platforms
Which AI SOC vendors let you own your logs and leave freely? Discover data portability, sovereignty, and exit clauses compared across 6 platforms.
ποΈ OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence AI model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it's implementing security controls for highercapability models and associated activities, such as isolated.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
ποΈ Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code VS Code extension named Solidity Pro "soliditypro" that has been observed delivering a browser wallet and credential stealer. The names of the extensions are below helperbeeps.soliditypro web3devtoolsx.soliditypro Although neither of the extensions is now available on Open VSX, the GitHub repository.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
π US Sanctions Iranian $6bn Crypto βExchangeβ Shelbit π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
US Sanctions Iranian $6bn Crypto βExchangeβ Shelbit
TRM Labs explains that sanctioned Iranian firm Shelbit was a fake crypto exchange
π’ Swiss authorities urge calm amid fears over SharePoint credential leak π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The Federal Office for Information Technology and Telecommunication said that while accounts have been compromised, no sensitive data has been accessed.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Swiss authorities urge calm amid fears over SharePoint credential leak
The Federal Office for Information Technology and Telecommunication said that while accounts have been compromised, no sensitive data has been accessed
π’ Swiss authorities urge calm amid fears over SharePoint credential leak π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
The Federal Office for Information Technology and Telecommunication said that while accounts have been compromised, no sensitive data has been accessed.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Swiss authorities urge calm amid fears over SharePoint credential leak
The Federal Office for Information Technology and Telecommunication said that while accounts have been compromised, no sensitive data has been accessed
π βGhostjackingβ Exploits AI Agentsβ Trusted Access to Evade Firewall Controls π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
βGhostjackingβ Exploits AI Agentsβ Trusted Access to Evade Firewall Co
Tenet reported that half of Fortune 500 companies are vulnerable to the Ghostjacking technique, which involves tricking AI agents with fake reports
π Go-Based macOS Malware Steals Crypto and Secrets π
π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
A macOS malware variant has been detected stealing crypto, passwords and more.π Read more.
π Via "Infosecurity Magazine"
----------
ποΈ Seen on @cibsecurity
Infosecurity Magazine
Go-Based macOS Malware Steals Crypto and Secrets
A macOS malware variant has been detected stealing crypto, passwords and more
π 11 Most Affordable AI SOC Platforms in 2026: What Each Pricing Tier Actually Covers for Small and Mid-Market Teams π
π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
Explore affordable AI SOC platforms with 247 coverage. See real costs, tier gaps, and compliance support for CTOs and security leads. The post 11 Most Affordable AI SOC Platforms in 2026 What Each Pricing Tier Actually Covers for Small and MidMarket Teams appeared first on UnderDefense.π Read more.
π Via "UnderDefense"
----------
ποΈ Seen on @cibsecurity
UnderDefense
11 Most Affordable AI SOC Platforms in 2026: What Each Pricing Tier Actually Covers for Small and Mid-Market Teams
Explore affordable AI SOC platforms with 24/7 coverage. See real costs, tier gaps, and compliance support for CTOs and security leads.
π’ Trust your AI agents? New research shows βmemory poisoningβ can dupe them into βrememberingβ fake information β and itβs a huge security risk π’
π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
Memory poisoning allows hidden text on a webpage to be treated as fact and used to make harmful decisions.π Read more.
π Via "ITPro"
----------
ποΈ Seen on @cibsecurity
IT Pro
Trust your AI agents? New research shows βmemory poisoningβ can dupe them into βrememberingβ fake information β and itβs a hugeβ¦
Memory poisoning allows hidden text on a webpage to be treated as fact and used to make harmful decisions
ποΈ New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA ποΈ
π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloudsynced passkey system from malware already on the victim's machine, and used a .π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity