BREEZE COMET Hackers Use AI-Written Tools to Speed-Run Brazilian Bank Fraud
Google Cloud researchers detail how the financially motivated BREEZE COMET group has spent two years infiltrating Brazilian banks and retailers, combining social engineering and rogue hardware with generative-AI-assisted...
High-Severity Cleo Harmony Bug Lets Attackers Forge Their Way to Admin Access
A high-severity flaw in Cleo Harmony's JWT refresh-token handling, tracked as CVE-2026-84115, lets remote attackers escalate privileges to admin level with a working exploit already public. Cleo has...
New WhatsApp Video Call Trick Bypasses Android Lock Screens to Expose Your Photos
A newly disclosed WhatsApp flaw lets anyone answer a video call on a locked Android phone and, through the in-call background editor, browse the device's entire photo gallery...
Fake Teams Help-Desk Calls Turn Remote Support Into a Path Toward Domain Control
A campaign dubbed Spring Ring used external Microsoft Teams accounts and convincing help-desk calls to push remote-access tools and malware. In some cases, the attackers progressed toward SMB...
Boston Scientific Cyber Incident Disrupts Manufacturing and Device Shipments
Boston Scientific is recovering from a cyber incident that interrupted on-premises systems supporting manufacturing, order processing and product shipments. The company says connected devices and previously enrolled remote...
Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens
A critical JFrog Artifactory authentication bypass is under active exploitation, with attackers reportedly creating administrator tokens on vulnerable servers. Self-hosted customers should upgrade immediately, revoke suspicious credentials and...
Attackers Exploit Critical Langflow and Rails Flaws to Hunt Cloud Secrets
Attackers are actively exploiting critical flaws in Langflow and Ruby on Rails, with observed activity focused on credentials, application secrets and paths to remote code execution. Defenders should...
D-Link Fixes Router Flaws That Exposed Admin and Wi-Fi Credentials on Local Networks
D-Link has patched access-control failures in the DIR-X1860Z that could let an unauthenticated local attacker reset the administrator password and retrieve wireless credentials. Owners should install the corrected...