Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.

The first ca… Continue reading Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data→

Posted in Uncategorized

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of acti… Continue reading CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV→

Posted in Uncategorized

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.

On May 12, Maciej Mensfeld, senior product m… Continue reading OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers→

Posted in Uncategorized

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.

Knowledge distillation by itself … Continue reading Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks→

Posted in Uncategorized

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.

The operation has been attributed to a cyber espion… Continue reading Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection→

Posted in Uncategorized

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report.

Wiz saw the atta… Continue reading Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors→

Posted in Uncategorized