Software

Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated

Can autonomous AI agents be sued or prosecuted for hacking? It’s no longer a question for sci-fi movies. It’s a question human lawyers and judges may soon have to grapple with. Under current U.S. hacking laws, a human can face criminal charges for breaking into someone else’s computer without permission. But when an AI agent […]

Who’s legally to blame for Anthropic and OpenAI’s autonomous AI hacks? It’s complicated Read More »

Inside the Underground Business of the Android BTMOB RAT malware

The Android RAT’s official operation is surrounded by cheaper resellers, alleged source-code vendors, independent server owners, and possible impersonators. BTMOB has been covered by several cybersecurity publications, primarily through technical analyses of the malware and its capabilities, but much less has been reported about the ecosystem that has developed around it. Activity observed by Flare

Inside the Underground Business of the Android BTMOB RAT malware Read More »

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

A cyberattack on the U.K.’s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals. The intrusion was detected on Sunday, July 26, and was later claimed by the ExfilSquad data extortion group, which alleges it stole 135,000 contact records. PNLD is an online legal

ExfilSquad hackers leak info of over 100,000 UK police officers, staff Read More »

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. The company on Sunday released hotfix 2026.3.1.7 to address the security issue, which affects all versions of N-central before 2026.3. On August 1st, the vendor disclosed that it detected active exploitation and launched an investigation

N-able warns of N-central auth bypass flaw exploited in attacks Read More »

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. Xeno Executor is a popular Roblox utility for running scripts that players can use to automate actions or run custom code on the platform, including cheats. The tool isn’t an official part of the game, so

Fake Roblox Xeno script launcher pushes infostealer, RAT malware Read More »

New DOUBLECUP ClickFix service hides malware in browser cache images

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. SOCRadar’s Threat Research Unit says DOUBLECUP has operated since early June 2026, providing customers with licenses

New DOUBLECUP ClickFix service hides malware in browser cache images Read More »

New Pass-ta-key attacks let malware hijack Google-synced passkeys

Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. Passkeys are a passwordless authentication method that uses cryptographic keys stored on a user’s device to sign in to online accounts. They are

New Pass-ta-key attacks let malware hijack Google-synced passkeys Read More »

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. The activity was previously disclosed in a report from cybersecurity company ReliaQuest, which detailed how the attacker changed DNS settings on Wi-Fi devices to steal Microsoft 365 accounts. Besides attributing the campaign to Russian

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts Read More »

Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate

Cybersecurity startup Horizon3 has raised a $250 million Series E at a $2 billion valuation, more than tripling its valuation in 14 months. The San Francisco-based firm drew backing from returning investors NightDragon and NEA. The funding arrives as two major AI research labs disclosed last week that their models had breached systems outside their

Horizon3 hits $2 billion valuation with $250M Series E as AI threats escalate Read More »

Samsung bans smart TV apps that share users’ internet connections with strangers

Several popular Samsung smart TV apps contain code that share the owner’s internet connection with strangers, potentially putting millions of Samsung smart TVs at risk of hijacking, according to new security research published on Monday. Some of these apps claim to have been installed on hundreds of millions of smart TVs in people’s homes, per

Samsung bans smart TV apps that share users’ internet connections with strangers Read More »