We hear this a lot: "We've got hundreds of service accounts and AI agents running in the background. We didn't create most of them. We don't kno...
Category: Attack
A critical token validation failure in Microsoft Entra ID (previously Azure Active Directory) could have allowed attackers to impersonate any us...
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed leveraging ClickFix-style lure...
î ‚Sep 20, 2025î „Ravie LakshmananSoftware Security / Malware LastPass is warning of an ongoing, widespread information stealer campaign targeting A...
Cybersecurity researchers have discovered what they say is the earliest example known to date of a malware with that bakes in Large Language Mod...
î ‚Sep 20, 2025î „Ravie LakshmananArtificial Intelligence / Cloud Security Cybersecurity researchers have disclosed a zero-click flaw in OpenAI Chat...
î ‚Sep 19, 2025î „Ravie LakshmananVulnerability / Threat Intelligence Fortra has disclosed details of a critical security flaw in GoAnywhere Managed...
An Iran-nexus cyber espionage group known as UNC1549 has been attributed to a new campaign targeting European telecommunications companies, succ...
î ‚Sep 19, 2025î „Ravie LakshmananBotnet / Network Security A proxy network known as REM Proxy is powered by malware known as SystemBC, offering abo...
The phishing-as-a-service (PhaaS) offering known as Lighthouse and Lucid has been linked to more than 17,500 phishing domains targeting 316 bran...
