Researchers Find Matching RCE Flaws in Claude Code, Gemini CLI and Codex Coding Agents
Security researcher Elad Meged has uncovered a strikingly similar vulnerability pattern across AI coding agents from Anthropic, Google, and OpenAI, all traceable to how each vendor's surrounding 'harness'...
New Vanta Stealer Malware Raids Browsers, Crypto Wallets and Gaming Accounts in a Single Sweep
A newly documented information stealer called Vanta Stealer goes well beyond saved browser passwords, harvesting cookies, payment data, Discord tokens, gaming accounts and cryptocurrency wallet files in one...
Thousands of Exposed Rockwell PLCs Leave US Water Utilities Open After Multi-State Attack Wave
A wave of attacks against U.S. water and wastewater utilities has renewed scrutiny of how many industrial controllers sit exposed to the open internet. Forescout researchers count over...
SilverFox Malware Deploys New Kernel Drivers to Blind Antivirus Before Installing ValleyRAT
Researchers at CATO Networks have caught the SilverFox threat group hiding behind trusted PDF software while quietly loading vulnerable, signed kernel drivers to knock out endpoint protection. The...
Greatness Phishing Service Lets Attackers Slide Past MFA Into Microsoft 365 Inboxes
A phishing-as-a-service platform called Greatness is stealing live authentication tokens rather than passwords, letting attackers walk past multi-factor authentication and into Microsoft 365 mailboxes. A recent campaign hid...
Cisco Rushes Fixes for Near-Maximum-Severity Flaws in Catalyst SD-WAN
Cisco has patched five vulnerabilities in Catalyst SD-WAN Software, three of them scoring 9.9 out of 10 on the CVSS scale. There is no evidence of active exploitation...
Fake VS Code Extensions Quietly Siphoned Git and CI Secrets From Developers
Seventy-seven counterfeit Open VSX extensions impersonated legitimate developer tools and quietly phoned home to a single attacker-controlled domain. Nineteen of them went further, harvesting Git repository details and...
How Attackers Spent July Turning Microsoft, Zoom, and Government Sites Against Their Own Users
Threat intelligence from ANY.RUN shows attackers spent July 2026 weaponizing the everyday trust built into Microsoft logins, Zoom event pages, and government portals across the US, Europe, and...