cyber attack

New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones

A newly discovered Android malware family named Manic combines banking fraud with full-scale spyware, and it comes with a trick…

4 weeks ago

Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions

A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by allowing Microsoft…

4 weeks ago

CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks

The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and…

4 weeks ago

Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA

A new "Pass-the-Passkey" family of attack techniques demonstrates how systemic implementation flaws surrounding WebAuthn can undermine passkey security even when…

1 month ago

Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack

Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly…

1 month ago

Anthropic Confirms Claude Hacked 3 Organizations by Breaking Test Environment

Anthropic has disclosed that its Claude AI models gained unauthorized access to the real systems of three organizations after reaching…

2 months ago

New GenieLocker Ransomware Attacks Windows, ESXi, and Linux Instances

GenieLocker, a newly identified ransomware linked to the financially motivated Toy Ghouls group, targets Windows, Linux, and VMware ESXi systems…

2 months ago

First-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face

Between July 9 and July 13, 2026, security researchers documented what is being called the first fully autonomous AI agent…

2 months ago

A Fake Teams Update Can Give Hackers Two Separate Ways to Control Your PC

A new phishing operation, tracked as Operation BlueDash, is tricking users into installing a fake Microsoft Teams update that silently…

2 months ago

NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based…

2 months ago