Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.

The attacker exploited the flaw to obtain high-level in… Continue reading Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M→

Posted in Uncategorized

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.

Elsewhere, … Continue reading ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats→

Posted in Uncategorized

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI

AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users.

According to Okta’s G… Continue reading Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI→

Posted in Uncategorized

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that’s targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent.

“The implant installs the fram… Continue reading Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent→

Posted in Uncategorized

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals.

Microsoft, which is tracking the activity under the name Storm-3168, has called it an e… Continue reading JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources→

Posted in Uncategorized

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.

The vulnerabilities ar… Continue reading CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally→

Posted in Uncategorized

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26.

Citrix has not confirmed the f… Continue reading Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation→

Posted in Uncategorized

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex.

The new findings come from Ontinue, which describe… Continue reading Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials→

Posted in Uncategorized

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.

The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score:… Continue reading Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells→

Posted in Uncategorized