-
A security researcher has revealed a critical design flaw in HP ThinPro versions 8 and 9, which allows attackers with physical access to a thin client’s storage drive to extract TPM-sealed LUKS disk-encryption keys. This vulnerability arises from…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
RovoBlast is a recently disclosed vulnerability affecting Atlassian’s Rovo AI assistant that allows attackers to expose sensitive enterprise data through a single malicious link. According to Varonis Threat Labs, the vulnerability exploits Rovo&#…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A supply chain compromise affecting multiple BdThemes WordPress plugins has allowed attackers to hijack administrator sessions, create unauthorized admin accounts, and deploy persistent web shells, without modifying the plugin source code or requiring …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Interlock ransomware incident that shows how unprotected endpoints can give attackers enough time to steal credentials, establish persistence, and reach a domain controller before defenders intervene. During a March 2026 response engagement, Sophos Eme…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a privileged network attacker to write attacker-controlled files as root during node boot. This f…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware operations are increasingly targeting the people behind critical business processes, not just privileged IT administrators. Over a one-month observation period, ThreatLabz identified 351 victims across 334 organizations connected to a single…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic’s Claude Opus 5 has significantly reduced the likelihood of a successful indirect prompt injection (IPI) attack, bringing it down to 2% over 15 attempts in the Gray Swan IPI benchmark. This marks an improvement from a 5.5% success rate …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
North Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with local large language models. Retrieval-augmented generation, AI agents, and speech-to-text tooling …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An Australian AI agent powered by Anthropic’s Claude reportedly exploited an authorization flaw in a gym booking platform, allowing it to book classes outside of permitted time frames and cancel another user’s waitlist reservation without explici…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph to identify employees handling payroll, finance, HR, benefits, invoices, and banking workflows. The…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


