cyber attack

OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted

OpenAI’s autonomous AI agents attempted to hack four government, university, and public-data systems while carrying out routine information-gathering tasks, according…

1 week ago

BragJack Attack Lets Malicious Extensions Hijack AI Agents Across 5 Major Browsers

A new attack technique dubbed "BragJack" allows a malicious browser extension to seize trusted communication channels used by AI assistants…

2 weeks ago

New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones

A newly discovered Android malware family named Manic combines banking fraud with full-scale spyware, and it comes with a trick…

2 months ago

Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions

A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by allowing Microsoft…

2 months ago

CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks

The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and…

2 months ago

Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA

A new "Pass-the-Passkey" family of attack techniques demonstrates how systemic implementation flaws surrounding WebAuthn can undermine passkey security even when…

2 months ago

Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack

Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly…

2 months ago

Anthropic Confirms Claude Hacked 3 Organizations by Breaking Test Environment

Anthropic has disclosed that its Claude AI models gained unauthorized access to the real systems of three organizations after reaching…

2 months ago

New GenieLocker Ransomware Attacks Windows, ESXi, and Linux Instances

GenieLocker, a newly identified ransomware linked to the financially motivated Toy Ghouls group, targets Windows, Linux, and VMware ESXi systems…

2 months ago

First-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face

Between July 9 and July 13, 2026, security researchers documented what is being called the first fully autonomous AI agent…

2 months ago