Policy & SecurityAutonomous AI Agents Execute Full Ransomware Attack in Under 10 Hours
A human operator leveraged frontier AI agents to breach an enterprise network in under 10 hours, leaving behind an 80-page security audit.
Policy & SecuritySonicWall SMA1000 Zero-Days Under Active Attack
SonicWall urges immediate patching as attackers actively exploit a critical zero-day chain targeting SMA1000 remote access gateways.
Policy & SecurityLenovo Login Flaw Exposes Dropbox Accounts to Attackers
A legacy Lenovo login integration left 5,000 Dropbox accounts exposed to unauthorized access after bad actors exploited a glaring email verification loophole.
Policy & SecurityUK Cyber Bill Shifts Liability Away From AI Vendors
The UK government has decided against bringing AI vendors under its new cybersecurity bill, choosing to focus on enterprise users instead.
Policy & SecurityBGP Hijack Exposes Softaculous and Virtualizor Users to Malware
A 33-hour BGP hijacking attack diverted Softaculous and Virtualizor traffic to malicious servers, triggering urgent credential resets and server inspections.
Policy & SecurityAnthropic AI Security Pledge Sparks Fresh Industry Safety Debate
Anthropic promises tighter AI model controls and calls on ecosystem partners to step up security after Claude models breached real-world systems during fictional tests.
Policy & SecurityFirefox iOS Ad Blocker Launches: Native Tech Meets Monetization
Mozilla just launched native ad blocking for iOS Firefox, navigating Apple's WebKit constraints while keeping sponsored spaces on its own new tab pages.
Policy & SecuritySality Botnet Disrupted After 23 Years by Police and CrowdStrike
International law enforcement and CrowdStrike have disrupted the 23-year-old Sality peer-to-peer botnet, cutting off malware distribution and crypto theft.
Policy & SecurityMETR API Key Theft Highlights Cloud Security Blind Spots
Model Evaluation and Threat Research (METR) reveals a massive API key theft that consumed $600k in credits without triggering early alerts.
Policy & SecurityJFrog Artifactory Flaw Under Active Exploit by Unknown Agents
A critical JFrog Artifactory CVE is under active attack days after patching, raising urgent questions about whether human hackers or AI agents are driving the exploit.
Policy & SecurityAnthropic Fights Stolen Claude Accounts Used for Token Mining
Anthropic is actively cracking down on compromised accounts where attackers use infostealer malware to hijack Claude access for unauthorized AI token mining.
Policy & SecurityTerminalFix Malware Hides in PNGs and Deploys Reverse Tunnels
A dangerous new TerminalFix malware campaign tricks users into running multi-line PowerShell scripts, hiding payloads inside PNG graphics to establish reverse tunnels.
Policy & SecurityOpenClaw 2.0 Lands With Usability Overhaul and Security Debate
OpenClaw 2.0 brings a massive usability overhaul and security tweaks, sparking fresh debate over whether self-hosted AI agent risks are being ignored.
Policy & SecurityHealthcare Cyberattacks Expose Pacemakers and Patient Records
Recent cyberattacks targeting Boston Scientific and McKesson have disrupted remote pacemaker monitoring and compromised millions of patient records.
Policy & SecurityDIA Insider Threat Employee Pleads Guilty to State Secrets Leak
A former Defense Intelligence Agency insider threat specialist has pleaded guilty to leaking top-secret state secrets following an FBI sting operation.