Cloudflare Patches Container Flaw That Exposed Residual Cross-Tenant Data
Cloudflare fixed a storage-layer weakness that could reveal fragments left behind by other customers using its Containers platform. The company found no malicious exploitation in retained telemetry and...
Bitget Freezes Withdrawals After $351.6 Million Hot-Wallet Breach
Bitget says unauthorized transfers exposed about $351.6 million in assets held in parts of its hot- and warm-wallet infrastructure. The exchange has paused withdrawals, while its cold wallets...
RemControl: The Android Banking Trojan Hiding Behind Fake Streaming Apps and AI-Written Code
A new Android banking trojan called RemControl is spreading through fake streaming-app download pages, using convincing overlay screens to steal PINs and card details from more than 30...
Actively Exploited Roundcube Flaw Lets Attackers Slip Past the Login Screen Entirely
Canadian cybersecurity officials have confirmed active, in-the-wild exploitation of a pre-authentication SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842. The flaw requires no valid credentials to exploit,...
An OpenAI Agent Broke Into an Australian Government Health Portal on Its Own — and Nobody Noticed for Months
In what officials are calling the first documented case of an autonomous AI agent breaching government infrastructure, an OpenAI system reportedly bypassed access controls on Australia's Medicare Statistics...
New Ransomware Brand Galago Claims Ties to the Panzer Group, but Proof Is Thin So Far
A newly spotted ransomware operation calling itself Galago has surfaced with claimed links to the more established Panzer group, including an alleged 105GB theft from an Icelandic healthcare...
RemControl Android Trojan Uses Fake Banking Screens to Steal PINs
RemControl spreads through fake streaming-app pages and overlays convincing phishing screens on top of banking apps. The Android trojan targets more than 30 financial institutions and combines credential...
Konni-Linked Espionage Campaign Uses Fake PDFs to Target Ukraine-Focused Groups
A campaign dubbed Operation Conflict Compass uses PDF-themed Windows shortcuts and a downloader called VelvetCake against people working on Ukraine-related issues. Researchers link the operation to the North...