AI adoption is moving faster than security programs can account for. Roughly 71% of organizations are piloting AI agents across their
Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
Vulnerable WordPress plugin iterations leak API keys, secrets, tokens, server information, and other data.
The post Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data appeared first on SecurityWeek.
North Korean Hackers Blamed for Mastra NPM Supply Chain Attack
A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.
The post North Korean Hackers Blamed for Mastra NPM Supply Chain Attack appeared first on SecurityWeek.
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control.
The annoying part is how little of this feels new. Weak credentials, sketchy downloads, browser extensions with too much access, and WordPress sites are used to push more
What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks
Groups like ShinyHunters are demonstrating that attackers do not necessarily need malware or zero-day exploits to cause massive damage.
The post What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks appeared first on SecurityWeek.
New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones
The vulnerability exploited by the Usbliter8 exploit cannot be patched and a PoC exploit has been released by researchers.
The post New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones appeared first on SecurityWeek.
Fortinet Responds to FortiBleed Campaign
A database of over 86,000 confirmed working credentials was created during the credential-harvesting campaign.
The post Fortinet Responds to FortiBleed Campaign appeared first on SecurityWeek.
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
The Federal Court released a public version of the ruling on June 15. It is the first time the Canadian Security Intelligence Service has used its threat reduction warrant powers this way.
The warrant let CSIS alter,
More Cybersecurity Firms Disclose Impact From Klue Hack
HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium are among the affected Klue customers.
The post More Cybersecurity Firms Disclose Impact From Klue Hack appeared first on SecurityWeek.
AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
The distinction matters. AryStinger exists for the stage of an attack that comes before the break-in. Infected
