All Episodes
Displaying 41 - 60 of 160 in total
Attackers used a Microsoft-attested Windows driver to disable 145 security tools
Attackers used a Microsoft-attested Windows driver to disable 145 security tools. Victims could lose passwords, browser sessions, and cryptocurrency data after a malwa...
North Korean-linked operators used fake job interviews to infect 30,000 devices
North Korean-linked operators used fake job interviews to infect 30,000 devices. Developers and employers now face theft and network intrusion through recruitment proc...
AI agents turn trusted tools and memory into a new attack surface
AI agents turn trusted tools and memory into a new attack surface. AI risk changes when a model gains access to files, email, persistent memory, external tools, or com...
Exposed cPanel servers are being pulled into Mirai botnets
Exposed cPanel servers are being pulled into Mirai botnets. Hosting providers and their customers face disruption as attackers exploit a critical authentication bypass...
Gyazo breach exposes 23.62 million users and image metadata
Gyazo breach exposes 23.62 million users and image metadata. Millions of Gyazo users now face account and privacy risk after attackers accessed the screenshot-sharing ...
GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds
GhostCode can hijack Microsoft 365 accounts in as little as 78 seconds. A Microsoft 365 account can be taken over even when the victim completes authentication, includ...
Apple update closes 273 security gaps, including one under attack
Apple update closes 273 security gaps, including one under attack. Apple users face a broad patching cycle covering 273 unique security issues across the company’s ope...
Cisco hardening releases address actively exploited security gaps
Cisco hardening releases address actively exploited security gaps. Network access and firewall management systems need urgent review following major Cisco hardening re...
Utility customer data exposed through an internet-facing system
Utility customer data exposed through an internet-facing system. Personal information belonging to some CenterPoint Energy customers was obtained through an external-f...
A hijacked AI coding session reportedly spread a worm across about 100 repositories
A hijacked AI coding session reportedly spread a worm across about 100 repositories. A hijacked AI coding-assistant session reportedly helped an attacker spread malici...
ScreenConnect attacks turn trusted remote access into an entry point
ScreenConnect attacks turn trusted remote access into an entry point. Attackers are now exploiting ScreenConnect to transfer or execute files through active remote ses...
Windows update locks some workers out of domain accounts
Windows update locks some workers out of domain accounts. Some Windows 11 users are being locked out of their domain accounts even though their credentials are still v...
Targeted attacks exploit a Pixel modem weakness without user action
Targeted attacks exploit a Pixel modem weakness without user action. Supported Pixel phones face a high-severity cellular modem weakness that has been used in limited,...
Browser extensions could seize control of five built-in AI assistants
Browser extensions could seize control of five built-in AI assistants. A proof-of-concept attack demonstrated that an ordinary browser extension could take control of ...
CenterPoint customer data exposed through an internet-facing system
CenterPoint customer data exposed through an internet-facing system. CenterPoint Energy has confirmed that an unauthorized third party obtained personal information be...
Active ScreenConnect attacks threaten trusted remote access
Active ScreenConnect attacks threaten trusted remote access. Attackers are actively exploiting a ScreenConnect weakness that can turn a trusted remote session into a d...
Hijacked AI coding session spreads compromise across about 100 repositories
Hijacked AI coding session spreads compromise across about 100 repositories. A compromised software development workflow allowed malicious activity to spread across ab...
Active attacks put Cisco identity and firewall controls at risk
Active attacks put Cisco identity and firewall controls at risk. Cisco says weaknesses affecting core network trust controls are already being exploited.
Windows update leaves some enterprise users locked out
Windows update leaves some enterprise users locked out. Some Windows 11 enterprise users are being locked out even though their domain credentials are valid.
Trusted WordPress update backdoors at least 1,500 customer sites
Trusted WordPress update backdoors at least 1,500 customer sites. A trusted update channel delivered malicious code to at least one thousand five hundred WordPress sites.