Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

Microsoft has formally disclosed that it’s working to release a patch to address a Defender zero-day codenamed RoguePlanet.

The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), with the tech giant describing it … Continue reading Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

Posted in Uncategorized

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.

Ordinary stuff, until one move near the end.

Before his command-and-control server went dark, he installed OpenSSH… Continue reading Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

Posted in Uncategorized

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.

Ordinary stuff, until one move near the end.

Before his command-and-control server went dark, he installed OpenSSH… Continue reading Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

Posted in Uncategorized

Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization

For security teams, the findings never stop, but confidence in knowing which ones matter is becoming harder to maintain.

The problem is no longer visibility. It’s validation. Security teams must decide which findings warrant action while operating und… Continue reading Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization

Posted in Uncategorized

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

Cybersecurity researchers have flagged a “coordinated malware campaign” on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.

“Every plugin poses as an AI … Continue reading Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

Posted in Uncategorized

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim’s project hijack the victim’s machine learning model upload and run code inside Google’s serving infrastructure.

Palo Alto Networks Unit 42, which found and… Continue reading Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

Posted in Uncategorized

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, per independent reports from Morphisec, BlueVoyant, and Huntress, respectively.

Attacks inv… Continue reading ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

Posted in Uncategorized