A critical vulnerability has surfaced in Prompty, Microsoft’s open-source project for building applications on top of large language models. The flaw let a specially prepared .prompty file escape ordinary template processing and run arbitrary...
Artificial intelligence recently breached a crucial internal OpenAI boundary. Basic safeguards against malicious requests simply no longer suffice. The company officially recognized Astra as its first model possessing critical cybersecurity capabilities. During rigorous testing,...
A routine software search recently transformed into a critical entry point for severe malware infections. Microsoft recently exposed a sophisticated counterfeit installer campaign. Participants in this operation meticulously cloned the websites of renowned software...
The United States successfully seized the domains of two prominent hacking platforms. The Department of Justice and the FBI allege the Chinese state-sponsored group QTFY operated these platforms. The group utilized these domains to...
Servers for developing AI applications have become vaults of valuable secrets, accessible through a single unprotected request. Attackers have begun exploiting the critical vulnerability CVE-2026-0768 in Langflow to extract OpenAI and AWS keys, administrator...
Corporate email can fall into an attacker’s hands after the compromise of a single low-privilege account. Nearly 22,000 internet-facing Microsoft Exchange servers have not received the fix for CVE-2026-62911, a flaw that allows every...
Sometimes, threat actors utilize video files not for mere viewing, but for cunning concealment. Censys specialists recently discovered a sophisticated malware campaign. This campaign actively deploys structurally sound, yet entirely unplayable MP4 files. These...
Andrew Tate’s exclusive “War Room” sold far more than basic financial and relationship advice. A massive data leak recently exposed highly secretive internal courses. These materials instructed members on bribing government officials and police...
A South Korean court has sentenced to 20 years in prison one of the leaders of a hacking group that hunted the fortunes of wealthy Koreans and reached the assets of BTS’s Jungkook. The...
A hacked computer has become a commodity whose value an algorithm determines by its banking software, corporate systems, and owner data. Group-IB specialists have discovered a malicious framework named BraZetsu, which supplies an underground...
Israeli authorities recently arrested an information security specialist. Investigators allege this individual spent his free time intentionally infecting the very corporate networks he was trained to protect. Police suspect the Ashkelon resident, a man...
Banking trojans typically target individual retail customers. However, the BREEZE COMET group selected significantly larger targets. The Google Threat Intelligence Group recently exposed this dangerous organization. Since 2024, they successfully penetrated Brazilian banks, fintech...
Compiled code no longer functions as an impenetrable shell protecting JSCeal. Check Point specialists recently developed a fully static deobfuscation method. This innovative technique effectively transforms the hidden malware into readable pseudocode. Crucially, it...
Blocking a malware’s command server is usually insufficient if a new address can be fetched straight from the blockchain. Arctic Wolf specialists have discovered a previously unknown modular malware belonging to the Dark Caracal...
For the first time, the United States has struck with counterterrorism sanctions at the Italian hacktivist collective Autistici/Inventati, which for more than 25 years has provided activists with email, hosting, and tools for anonymous...