pawsylifesadmin

New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldCrash” right after Microsoft rolled out its September 2026 Patch Tuesday security updates. ShieldCrash is described as a bypass for the ShieldBreak Defender privilege escalation flaw patched on Thursday, which itself bypassed RoguePlanet, another Defender flaw disclosed in […]

New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access Read More »

Man gets 15 years for extorting women with AI-generated porn videos

An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims via phone calls, voicemails, text messages, and online posts. When he was arrested on federal charges on June 23, 2025, 37-year-old James Strahler II was also charged with anonymous telecommunications harassment and child pornography production

Man gets 15 years for extorting women with AI-generated porn videos Read More »

Over 36,000 exposed Plex servers vulnerable to recent flaws

Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking. While the company didn’t provide additional details on Tuesday when it issued the warning,

Over 36,000 exposed Plex servers vulnerable to recent flaws Read More »

MFA’s Weakest Link: Account Recovery Is the New Attack Path

For years, security teams have been making account takeover harder. Multi-factor authentication (MFA) added crucial protection to password-only authentication, while conditional access and device trust add further checks before users can reach sensitive systems. However, these controls give attackers a reason to look for another route. Some attacks that are becoming increasingly common target the

MFA’s Weakest Link: Account Recovery Is the New Attack Path Read More »

US says Chinese firms extracted billions of tokens from frontier AI models

U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. A joint advisory from CISA, NSA, and the FBI states that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens through millions of requests from frontier AI

US says Chinese firms extracted billions of tokens from frontier AI models Read More »

Veradigm warns of patient data breach after ransomware gang claims attack

Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients’ personal data. The company says the incident did not cause operational disruptions but affected a small number of customers. Formerly known as Allscripts Healthcare Solutions, Veradigm is a Chicago-based healthcare technology company that supplies medical

Veradigm warns of patient data breach after ransomware gang claims attack Read More »

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. Devices running firmware version 1.0.0.28 are affected by a high-severity vulnerability tracked as CVE-2025-20701 in the Airoha Bluetooth Audio SDK, which the Skullcandy Dime 3 (model S2DCW)

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking Read More »

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. The company provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products. AdaptHealth first disclosed the incident in

AdaptHealth confirms 4.1 million people exposed in July cyberattack Read More »

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. “In August

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks Read More »

Hackers build AI frameworks for widescale credential theft

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. Drawing on telemetry from Mandiant’s incident response engagements, threat actor tracking, and live platform defenses, the Google Threat Intelligence Group (GTIG) observed AI agents coordinating multiple attack tasks, troubleshooting failures, and adapting their actions with minimal

Hackers build AI frameworks for widescale credential theft Read More »