ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.

“ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and Orchid… Continue reading ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure→

Posted in Uncategorized

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based “much smaller organization” in the information technology (IT) services industry, once again highlighting how the adversary continues to target de… Continue reading Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors→

Posted in Uncategorized

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic’s Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.

The chain began with a… Continue reading Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws→

Posted in Uncategorized

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.

The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated re… Continue reading Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild→

Posted in Uncategorized

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google’s Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.

The incidents occur… Continue reading Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up→

Posted in Uncategorized

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.

The French security company had kept his GitHub access open. CrowdSec says his lap… Continue reading CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories→

Posted in Uncategorized