AI Gateways Under Fire: Attackers Chain LiteLLM and MCP Flaws for Remote Code Execution
A 90-day honeypot study shows attackers systematically probing AI proxies, MCP servers, and agent frameworks like LangChain and Langflow, chaining authentication bypass and command-injection bugs into remote code...
TITAN Ransomware Claims Its AI Can Sift 700GB of Stolen Data an Hour to Maximize Extortion
A relatively new ransomware-as-a-service operation called TITAN is marketing an AI-powered analysis platform that it says can classify and mine stolen corporate data at 700GB per hour, helping...
Malvertising Has Moved Past the Ad Itself: Why the Real Threat Now Lives in the Redirect Chain
New moderation data shows malicious advertising is increasingly indistinguishable from a legitimate ad at first glance, with the real payload hidden several redirects deep behind cloaking, disposable domains,...
A Free DNS Change Can Add a Security Filter to Every Device on Your Home Network
Cloudflare's malware-filtering DNS service can block connections to known malicious and phishing domains across an entire home network. The simple router change is useful as an added layer,...
Infostealers Target Claude Sessions, Letting Attackers Bypass MFA and Drain Paid Accounts
Attackers are stealing authenticated Claude browser sessions and abusing malicious ads and files to compromise users. Anthropic has invalidated affected sessions and refunded confirmed charges, but victims must...
Critical ServiceNow AI Flaws Expose Enterprise Data and Code Execution Paths
ServiceNow has patched three critical AI-platform vulnerabilities and a high-severity Now Platform sandbox escape. Self-hosted customers should urgently verify fixed releases and investigate signs of unauthorized code execution...
APT28’s New HOOKEDGE Backdoor Targets European Defense and Diplomatic Networks
The Russia-linked APT28 group is using a lightweight backdoor called HOOKEDGE against defense, government and diplomatic targets in Europe. The campaign combines malicious Word macros, scheduled tasks, hidden...
Cyber Incident Halts Small UK Power Plant for Four Days as Attribution Remains Unclear
A cyber incident reportedly stopped a small British peaking power plant for roughly four days without disrupting customers or the wider grid. Officials confirmed the event, while key...