Iran-Linked Hackers Knocked a UK Power Plant Offline for Four Days in a First-of-Its-Kind Attack
A small UK energy generator was forced completely offline for four days last month in what officials describe as the first successful cyberattack to shut down a British...
Fake Adobe Reader Site Powers a New Malware-as-a-Service Platform Targeting Windows Users
Researchers have uncovered a live malware-as-a-service operation hiding behind a convincing fake Adobe Acrobat Reader site, using a WebDAV trick and a disguised batch file to install information-stealing...
This Week in Cyber: An AI Coding Assistant Helped Run a Ransomware Attack, and Azure Logins for 9 Major Firms Hit the Dark Web
Two stories from this week show how enterprise security is being reshaped from both ends: a ransomware affiliate reportedly used an AI coding assistant to breach VPNs and...
Microsoft’s New Windows Tool Quietly Resets Chrome, Firefox, and Brave to Bing
A newly spotted Microsoft installer called MicrosoftSettings.exe pushes a browser extension that switches Chrome, Firefox, and Brave over to Bing search and the MSN homepage. Security researchers note...
Grok AI Chatbot Tricked Into Leaking Private Chats Through Encrypted Prompt Injection
Security researchers at Adversa AI found a zero-click flaw in xAI's Grok that hides malicious instructions inside encrypted text to steal names, locations, and chat history. The attack...
Unauthenticated File Upload Flaw in Elementor Pro Opens Door to Remote Code Execution
A critical vulnerability tracked as CVE-2026-32475 lets unauthenticated attackers upload malicious PHP files through the Elementor Pro Forms widget, potentially leading to full remote code execution on affected...
Chinese Threat Group Automates Web Server Attacks at Scale Using AI Agents, Cisco Talos Warns
Cisco Talos has tracked a Chinese-speaking group known as UAT-10147 using AI-generated scripts and playbooks to automate reconnaissance and exploitation across roughly 170,000 URLs. The campaign hit government,...
New Espionage Campaign ‘SilkParasite’ Hits Central Asian Governments With Five Undocumented Malware Tools
Researchers have uncovered SilkParasite, a cyberespionage operation using spear-phishing and five previously unseen malware families to target government bodies across Central Asia. The campaign favors cloud-based command channels...