Leaked AWS Administrator Key Fuels Costly LLMjacking Through Bedrock and Marketplace
A leaked AWS IAM key with administrator privileges allowed an attacker to create a new identity, activate premium AI models and bill inference usage to the victim. The...
Rogue ScreenConnect Clients Turn Remote Support Sessions Into a Worm-Like Infection Chain
Attackers are abusing unauthorized ScreenConnect installations to push staged malware into newly connected Windows systems. The campaign begins with social engineering, then uses trusted remote-support functions for persistence,...
Inside ‘The Gentlemen’: The Ransomware Operation That Can Take Down a Network Before Lunch
A ransomware-as-a-service operation dubbed 'The Gentlemen' by researchers is compromising networks and detonating encryption in as little as 24 hours, methodically disabling backups and security tooling before attackers...
Attackers Are Already Probing a Critical Flaw in Sangoma’s Switchvox VoIP Platform
A critical, unauthenticated SQL injection flaw in Sangoma Switchvox is being actively probed in the wild just weeks after a patch became available. With thousands of phone systems...
QR-Code Phishing Reaches Record Levels as Attackers Shift Credential Theft to Phones
ESET says QR-code phishing accounted for about 11% of detected phishing email in the first half of 2026, with roughly 100,000 detections per month. By moving victims from...
Phantom Deal Fraud Uses Fake M&A Secrecy to Push a €626,000 Wire Transfer
The Phantom Deal campaign impersonates executives and advisers, then uses a polished NDA to isolate employees from normal approval channels. One documented attempt sought a €626,735.45 transfer and...
Critical VMware Workstation and Fusion Bugs Let Attackers Break Out of the Virtual Machine
Broadcom has patched two vulnerabilities in VMware Workstation and Fusion that allow an attacker with access to a guest virtual machine to execute code on the underlying host,...
A Popular WordPress Backup Plugin’s Flaw Puts 5 Million Sites One Restore Away From Takeover
A high-severity SQL injection flaw in the All-in-One WP Migration and Backup plugin, installed on more than five million WordPress sites, can be triggered through the platform's own...