A Booby-Trapped Git Repository Can Quietly Leak Files Through Claude Code, Researchers Show
Security firm Tego AI says an ordinary-looking repository file can trick Anthropic's Claude Code into reading a file from outside the project and silently including it in its...
Cl0p Affiliates Are Breaching PTC Windchill Servers to Steal Product Blueprints Before Extortion
Cl0p-linked attackers are chaining an unauthenticated information disclosure bug with a critical deserialization flaw in PTC Windchill and FlexPLM to steal engineering and product-design data from manufacturers, automakers,...
UNC3753 (Luna Moth) Escalates Campaign Against US Law Firms: Vishing, RMM Tools, and Now Physical Intrusion
Google Cloud Mandiant has documented a sustained UNC3753 (Luna Moth) campaign targeting US law firms from January–May 2026. The group uses vishing calls and RMM tools to exfiltrate...
Malicious npm Package js-logger-pack Turns Hugging Face Into Malware CDN and Data Exfiltration Backend
JFrog Security researchers have uncovered a malicious npm package, js-logger-pack, that uses Hugging Face as both a malware delivery network and an exfiltration backend for stolen data. The...
Akira Ransomware: A Formidable Adversary in the Ever-Changing Cybersecurity Landscape
Cybersecurity Tactics, and the Pivotal Shift Towards Data Exfiltration, Highlighting the Ongoing Challenge in Defending Against Adaptive Threats in the Ever-Changing Digital Battlefield