A $25 template helped scammers build hundreds of phantom bank domains

A phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the bran… Continue reading A $25 template helped scammers build hundreds of phantom bank domains

Fake Gemini installer delivers Vidar infostealer via Google Colab lure

A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was n… Continue reading Fake Gemini installer delivers Vidar infostealer via Google Colab lure

US agencies warn of AI-powered attacks on Siemens industrial controllers

Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs) used across water, energy, manufacturing, and other critical infrastructure sectors, according to US federal agencies… Continue reading US agencies warn of AI-powered attacks on Siemens industrial controllers

US charges 17 Iranian hackers over 31-terabyte academic data theft

The U.S. has charged 17 alleged members of Mabna Institute, an Iranian hacking-for-hire company accused of running a years-long campaign that stole data from American universities, companies, and government agencies.
The post US charges 17 Iranian hack… Continue reading US charges 17 Iranian hackers over 31-terabyte academic data theft

Researchers find a loophole that lets expired credit cards make unauthorized payments

A team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and presented the findings a… Continue reading Researchers find a loophole that lets expired credit cards make unauthorized payments

Medusa ransomware gang has hit over 500 organizations, CISA warns

Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory first issued in Ma… Continue reading Medusa ransomware gang has hit over 500 organizations, CISA warns

Google’s AI security agents found 100+ critical software vulnerabilities in just two days

Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into st… Continue reading Google’s AI security agents found 100+ critical software vulnerabilities in just two days

ChatGPT’s new feature could give infostealers a map of your Mac activity

OpenAI’s new Computer History feature turns recent Mac computer activity into memories ChatGPT and Codex can use, and it’s raising questions about privacy and security along the way. Computer History (Source: OpenAI) What Computer History d… Continue reading ChatGPT’s new feature could give infostealers a map of your Mac activity

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2… Continue reading Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)