OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries

Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. Continue reading OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries→

Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests

Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations. Continue reading Anthropic Says Claude Models Hacked 3 Organizations During Cyber Tests→

Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover

Cybersecurity researchers at Wiz found CosmosEscape in Azure’s Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found. Continue reading Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover→

LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach

LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people. Continue reading LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach→

22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking

Researchers found 24,650 public BMC interfaces leaking IPMI password hashes, exposing servers to offline password cracking through a decades-old protocol flaw. Continue reading 22-Year-Old IPMI Flaw Exposes 24,000 Servers to Offline Password Cracking→