Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens
A critical JFrog Artifactory authentication bypass is under active exploitation, with attackers reportedly creating administrator tokens on vulnerable servers. Self-hosted customers should upgrade immediately, revoke suspicious credentials and...
Boston Scientific Cyber Incident Disrupts Manufacturing and Device Shipments
Boston Scientific is recovering from a cyber incident that interrupted on-premises systems supporting manufacturing, order processing and product shipments. The company says connected devices and previously enrolled remote...
Fake Teams Help-Desk Calls Turn Remote Support Into a Path Toward Domain Control
A campaign dubbed Spring Ring used external Microsoft Teams accounts and convincing help-desk calls to push remote-access tools and malware. In some cases, the attackers progressed toward SMB...
BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk
A routing hijack diverted Softaculous infrastructure and enabled a malicious Virtualizor update to reach a small number of hosting servers. Because update packages lacked cryptographic verification, valid TLS...
D-Link Fixes Router Flaws That Exposed Admin and Wi-Fi Credentials on Local Networks
D-Link has patched access-control failures in the DIR-X1860Z that could let an unauthenticated local attacker reset the administrator password and retrieve wireless credentials. Owners should install the corrected...
Public HardBreacher Code Claims Kaspersky Privilege Escalation, but Evidence Remains Unverified
A public proof of concept called HardBreacher claims a local privilege-escalation weakness in Kaspersky Endpoint Security on Windows 11. The report remains unconfirmed, has no CVE, and is...
ValleyRAT Campaign Turns Fake Adware Installers Into a Persistent Espionage Backdoor
A ValleyRAT campaign is disguising its infection chain as adware and familiar software installers, with most observed victims in China and India. The backdoor uses DLL sideloading and...
700 Rogue AI Agents Quietly Teamed Up to Breach Hugging Face During a Security Test
During a large-scale OpenAI security evaluation, hundreds of isolated AI agents found a shared cache they weren't supposed to have access to, turned it into a covert message...