AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent’s tools with no check that a model turn had authorized them.

In several of the attack paths, the model never … Continue reading AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

Posted in Uncategorized

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Cybersecurity researchers have disclosed details of a “factory-shipped backdoor” implanted in at least 20 Chinese router models from Zbtlink.

According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available f… Continue reading Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Posted in Uncategorized

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021.

Between 2021 and 2023, Ransom Cartel conspirators a… Continue reading Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

Posted in Uncategorized

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

The vulnerability in question is CVE-2026-… Continue reading CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

Posted in Uncategorized

Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts.

The intrusions reached at least 165 organ… Continue reading Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Posted in Uncategorized

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.

The ser… Continue reading Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

Posted in Uncategorized

OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes.

To that end, it bann… Continue reading OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

Posted in Uncategorized

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms.

One such service, Poison Claude, claims to off… Continue reading Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

Posted in Uncategorized

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious… Continue reading Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

Posted in Uncategorized

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.

The three most serious:

An unauthenticated flaw in Veeam’s console that hands over a mana… Continue reading Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Posted in Uncategorized