The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved the
Mount Royal University confirms breach as hackers claim attack
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
Hackers exploit Roundcube flaw to spy on academic researchers
AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers
The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack.
Decrypting browser credentials, listing what sits in Windows’ credential store,
Entra passkey enrollment vishing targets Microsoft 365 users
Accenture Confirms Data Breach After Hacker Claims Source Code Theft
The professional services giant says it contained the incident, remediated its source, and experienced no operational or service delivery impact.
The post Accenture Confirms Data Breach After Hacker Claims Source Code Theft appeared first on SecurityWeek.
China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors
Cisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors.
The post China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors appeared first on SecurityWeek.
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reliably invents, register them first, and wait for the assistant to fetch your trap on a user’s
Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS
The list of vulnerabilities is as follows –
CVE-2026-50746 (CVSS score: 10.0) – An improper access control vulnerability in UniFi Connect Application that an attacker
