Russia-Aligned Group Tests Prompt Injection to Blind AI Malware Scanners
A Russia-aligned campaign used a malicious script comment designed to trigger an AI model’s safety refusal and interrupt malware analysis. The GuardBreaker technique, found in a MATCHBOIL delivery...
Mantax Otax Android Ransomware Adds Screen Spying, OTP Theft and Covert Photos
New Android malware called Mantax Otax combines file encryption with surveillance, credential theft, screen recording and covert camera access. The campaign relies on sideloaded APKs and appears focused...
Critical CSF Flaw Exposes cPanel Servers to Unauthenticated Command Execution
A critical flaw in ConfigServer Security & Firewall can let remote attackers execute commands through its optional MESSENGER service without logging in. Administrators using CSF 14.00 through 16.29...
CISA Flags CVSS 10 GitLab File-Read Flaw Under Active Attack
CISA says attackers are exploiting a critical GitLab path-traversal vulnerability that can expose arbitrary server files without authentication. Organizations should patch immediately, review access logs, and treat exposed...
Claude Misuse Report Shows AI Agents Automating Exploits, Malware Changes and Intrusions
Anthropic says state-backed groups, cybercriminals and hacktivists misused Claude to automate attack chains, develop exploits and adapt malware. The cases show that AI agents can compress specialist work...
CISA Adds Exploited Citrix NetScaler Authentication Bypass to Urgent Fix List
CISA has added CVE-2026-19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog. Internet-facing ADC and Gateway deployments supporting remote access should apply Citrix updates...
State-Backed Hackers Exploit Cisco Firewall Flaws for Root Access and Malware Deployment
Attackers are actively abusing two Cisco Secure Firewall Management Center vulnerabilities, including a maximum-severity authentication bypass. Cisco says state-sponsored operators and a ransomware affiliate have used the flaws...
Phishing Campaign Builds Fake Login Pages Inside Browsers After Trusted Microsoft Redirects
A phishing campaign chains DocuSign-themed calendar invitations, Microsoft redirects and browser blob URLs to display credential-stealing pages assembled in local memory. The method reduces reliance on a conventional...