Claude Misuse Report Shows AI Agents Automating Exploits, Malware Changes and Intrusions
Anthropic says state-backed groups, cybercriminals and hacktivists misused Claude to automate attack chains, develop exploits and adapt malware. The cases show that AI agents can compress specialist work...
CISA Adds Exploited Citrix NetScaler Authentication Bypass to Urgent Fix List
CISA has added CVE-2026-19490, a critical Citrix NetScaler authentication bypass, to its Known Exploited Vulnerabilities catalog. Internet-facing ADC and Gateway deployments supporting remote access should apply Citrix updates...
State-Backed Hackers Exploit Cisco Firewall Flaws for Root Access and Malware Deployment
Attackers are actively abusing two Cisco Secure Firewall Management Center vulnerabilities, including a maximum-severity authentication bypass. Cisco says state-sponsored operators and a ransomware affiliate have used the flaws...
Phishing Campaign Builds Fake Login Pages Inside Browsers After Trusted Microsoft Redirects
A phishing campaign chains DocuSign-themed calendar invitations, Microsoft redirects and browser blob URLs to display credential-stealing pages assembled in local memory. The method reduces reliance on a conventional...
ClearFake CAPTCHA Campaign Disables EDR to Deploy Crypto Stealer
ClearFake has expanded its fake CAPTCHA operation with a vulnerable-driver technique that terminates endpoint defenses before deploying a cryptocurrency stealer. The campaign combines compromised sites, blockchain-hosted instructions, WebDAV...
AI Agent Swarm Exploits PaperCut Flaws Across 440 Servers Worldwide
A Russian-speaking operator used hundreds of autonomous AI agents to compromise 440 PaperCut servers across 48 countries. Although only a fraction reached domain administrator, the campaign shows how...
BlueMoon Exploit Kit Chains Chrome and Windows Zero-Days in Espionage Attacks
Multiple espionage groups are using the BlueMoon exploit kit to chain Chrome and Windows flaws against government, defense and commercial targets. The campaign highlights the danger of patch-gap...
Fake Job Interviews Deliver NodeRabbit and PollCat Malware to Software Developers
An Iran-linked group tracked as Mirage Kitten (UNC1549) is posing as recruiters on LinkedIn to trick developers into running malicious take-home coding tests. The booby-trapped projects deploy two...