CISA Orders Forensic Checks as Three Linux Kernel Flaws Face Active Exploitation
CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered covered agencies to patch and investigate exposed systems. The flaws affect kernel TLS,...
TanStack Supply-Chain Breach Exposes 170 Private CrowdSec Repositories
CrowdSec says attackers cloned roughly 170 private GitHub repositories after stealing an OAuth token through the TanStack npm supply-chain compromise. The incident remained hidden for months and highlights...
Gemini Security Test Escaped Its Sandbox and Reached Three Real Companies
Google confirmed that Gemini accessed systems at three real companies after a cybersecurity evaluation mistakenly left internet access enabled and used a fictional company name that matched a...
ENCFORGE Ransomware Targets the Models, Datasets and Vector Stores Behind AI
The JADEPUFFER threat actor has progressed from improvised database destruction to ENCFORGE, ransomware built to encrypt AI models, datasets and vector indexes. Defenders need runtime detection and recovery...
BIND Security Update Fixes 14 Flaws Across DNSSEC, DoH and Resolver Caches
ISC has issued BIND 9 updates for 14 vulnerabilities affecting cache integrity, DNSSEC validation, DNS-over-HTTPS and service availability. Operators of recursive and internet-facing resolvers should upgrade promptly and...
HEAVYGRAM Backdoor Uses Telegram to Spy on Journalists and Iranian Dissidents
Researchers have expanded the known scope of HEAVYGRAM, a Windows surveillance backdoor that uses Telegram bots and groups for command and control. The campaign targets journalists and Iranian...
FBI Seizes NightmareStresser Domains After Hundreds of Thousands of DDoS Attacks
The FBI and Canadian authorities have disrupted NightmareStresser, a DDoS-for-hire service blamed for hundreds of thousands of attacks since 2022. The domain seizures are part of Operation PowerOFF...
How AI Cracked Its Maker: Claude Opus 5 Helped Researchers Breach OpenAI’s Own Forum
Security researchers at Hacktron used Anthropic's newly released Claude Opus 5 to build a working exploit for a memory-corruption bug in the image library behind OpenAI's community forum,...