Bajaj Auto Confirms Ransomware Attack — Both Parent Company and Tech Subsidiary Affected
Bajaj Auto disclosed a ransomware attack on June 23, 2026, affecting systems at the company and its subsidiary BATL. The firm has notified CERT-In and is working to...
DifyTap: Critical Flaws in AI Platform Dify Allow Silent Wiretapping of AI Conversations Across 1M+ Apps
Researchers at Zafran disclosed four vulnerabilities in Dify — including two critical CVSS 9+ flaws — that let attackers silently intercept AI conversations across tenants, access private files,...
Squidbleed: 29-Year-Old Squid Proxy Vulnerability Leaks Passwords and API Keys from Other Users
A critical heap overread vulnerability in Squid Proxy, dubbed Squidbleed, has gone undetected since 1997. Discovered with the help of AI, the flaw allows an attacker controlling an...
AryStinger Botnet Hijacks 4,300+ Routers to Build Global Covert Attack Proxy Network
Researchers have uncovered AryStinger, a stealthy botnet that has hijacked over 4,300 legacy Linksys and D-Link routers by exploiting decade-old vulnerabilities. Unlike DDoS botnets, AryStinger is purpose-built for...
Prinz Eugen Ransomware Uses RemotePC RMM and PowerShell Stagers to Evade Detection
A new ransomware group is deploying the Go-based Prinz Eugen ransomware by abusing legitimate remote management software (RemotePC) and PowerShell stagers. The campaign has already hit major financial...
Klue Supply Chain Hack Exposes Salesforce Data at Nine Cybersecurity Companies
A supply chain attack on market intelligence platform Klue has compromised Salesforce CRM data across at least nine organizations, including HackerOne, Huntress, and Recorded Future. The Icarus extortion...
SiderAI and MaxAI Chrome Extensions Expose 10 Million Users to Full Browser Compromise
Critical vulnerabilities dubbed Spyder and MaXSS have been discovered in the SiderAI and MaxAI Chrome extensions, which together are installed on over 10 million devices. The flaws allow...
HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic
Qualys researchers have exposed HazyBeacon, a stealthy APT campaign targeting Southeast Asian governments that uses AWS Lambda Function URLs as covert command-and-control relays. By routing malicious traffic through...