Software

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. The vulnerability, tracked as CVE-2026-16812, is an unauthenticated OS command injection flaw with severity scores of 10.0, the maximum score that can be given to flaws. VeloCloud Orchestrator, also known as VCO, is a centralized […]

Arista patches VeloCloud Orchestrator zero-day exploited in attacks Read More »

Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S. The malicious activity was observed last week by the agentic security company ThreatBook,

Hackers target US firms in FastJson RCE zero-day attacks Read More »

Jensen Huang’s first-ever post on X is in defense of open access to AI models, alongside Google, OpenAI, and Meta

Nvidia’s CEO Jensen Huang joined X last month, and recently made his first-ever post. As you could probably guess, it’s about AI. He argues, alongside companies like Google, OpenAI, and Meta, that the US should not aim to restrict open models ‘prematurely’, as they’re important for the growth of AI (among other things). Taking a

Jensen Huang’s first-ever post on X is in defense of open access to AI models, alongside Google, OpenAI, and Meta Read More »

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

Three attacks, three names, and one identical flaw: AI coding agents treat a hallucinated identifier as a verified command. By Shane Warden, Principal Architect, ActiveState Ask an AI coding agent to fetch a tool. Occasionally, it returns a name that sounds right, but does not exist. Developers used to ignore this mistake, assuming a compiler

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack Read More »

Chick-fil-A data breach affects more than 13,000 customers

American fast food restaurant chain Chick-fil-A has confirmed that over 13,000 customers had their data stolen in a recent wave of credential stuffing attacks. As BleepingComputer first reported, the company revealed in data breach notification letters filed with multiple attorney general’s offices that it detected attacks targeting its website and mobile app between June 17

Chick-fil-A data breach affects more than 13,000 customers Read More »

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. The campaign has been ongoing since at least June and impacts organizations in various sectors, including financial services, professional services, legal, health care, energy, and retail. Cybersecurity company ReliaQuest identified compromised Wi-Fi

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts Read More »

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended “YOLO” mode to automate post-exploitation activity during an alleged breach of Thailand’s Ministry of Finance. The activity was uncovered by threat intelligence company Hunt.io and security researcher Bob Diachenko after they discovered several exposed web directories containing hundreds of files associated with the operation.

Hermes AI agent used to automate attack on Thai Finance Ministry Read More »

OnTrac notifies customers of data breach after network hack

OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22. Apart from names, it is unclear what type of information

OnTrac notifies customers of data breach after network hack Read More »

ShinyHunters data leaks fuel $2,000 sextortion email scam

Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The emails claim to come from ShinyHunters and tell recipients that hackers compromised their devices after obtaining their email addresses from breached company databases. However, the messages appear to be sent

ShinyHunters data leaks fuel $2,000 sextortion email scam Read More »

Malicious sites use JavaScript to build malware in browser memory

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The operation has been active since late 2024 and is localized to 25 languages in 12 countries, primarily in Asia Pacific and Latin America. A filtering system ensures that only real

Malicious sites use JavaScript to build malware in browser memory Read More »