Latest Briefings
Fake Paysafe and Skrill SDKs on npm and PyPI harvest developer credentials
Seventeen malicious packages mimicking legitimate payment SDK APIs silently exfiltrate API keys, cloud tokens, and system metadata to an attacker-controlled AWS server.
Eight Greeks Sue Intellexa for $8.7M Over Predator Spyware Surveillance
Eight Greek nationals targeted by Predator spyware have filed a civil lawsuit against Intellexa and 13 associated individuals, seeking roughly 7.6 million…
Block to Pay $45M Settlement Over Cash App Security Failures
Forty-six state attorneys general have reached a bipartisan settlement with Block, Inc. over allegations that Cash App misled users about fraud protections…
Mount Royal University Hit by Data Theft and Wiping Attack
Calgary's Mount Royal University confirmed hackers stole files from its H drive and wiped a separate departmental drive in a June 17…
Prompt Injection Flaw in GitHub Agentic Workflows Can Expose Private Repos
A vulnerability dubbed GitLost allows unauthenticated attackers to leak private repository contents by hiding malicious instructions inside a public GitHub Issue, requiring…
Google Dialogflow CX Flaw Let Attackers Hijack AI Chatbot Conversations
A vulnerability dubbed Rogue Agent allowed an attacker with edit access to one Dialogflow CX agent to silently compromise all Code Block-enabled…
Accenture Confirms Breach After Hacker Lists 35 GB of Stolen Data
A threat actor known as '888' claims to have exfiltrated 35 GB of source code, credentials, and configuration files from Accenture, and…
CISA Orders Federal Agencies to Patch Actively Exploited Langflow Auth Bypass
CISA has added a Langflow authorization bypass flaw to its KEV catalog and given federal civilian agencies until Friday to apply patches,…
Supreme Court Lets Texas App Age Verification Law Take Effect
The Supreme Court declined to block the Texas App Store Accountability Act, allowing enforcement to proceed while a federal appeals court considers…
RedWing MaaS Brings Android Bank Fraud to Telegram as a Rental Service
A newly discovered Android malware operation called RedWing is being offered on Telegram as a turnkey bank-fraud service, lowering the bar for…
Critical Gitea Auth Bypass Flaw Under Active Exploitation
A critical vulnerability in Gitea's Docker images allows attackers to impersonate any user with a single HTTP header. Exploitation began just 13…
Ohio County Paid $1M Ransom to Kairos Extortion Group After Data Theft
Union County, Ohio reportedly paid $1 million in Bitcoin to prevent the release of 2 terabytes of stolen data, following a May…