ThreatVectr — cybersecurity news: breaches, vulnerabilities, ransomware and AI security

Ten governments name a Shanghai contractor as the engine behind China's data-theft campaigns
A joint advisory led by CISA and the FBI pins years of intrusions on Integrity Technology Group and lists eight old, unpatched flaws the operators keep riding into critical infrastructure.

Japan's data leak surge points at mobile app APIs and unpatched Metabase
JPCERT/CC says attackers are hitting mobile app back ends and known software flaws. A fresh Metabase advisory names the kind of bug being abused.

AWS Says Its AI Agent Handing Over Passwords Is Working as Designed
Palo Alto Networks researchers found that Amazon's AI agent platform exposes plaintext credentials by default. AWS closed the report as 'informative'. Security teams carry the risk.

Florida Ransomware 'Expert' Charged With Secretly Paying the Hackers He Promised to Beat
Zohar Pinhasi, owner of MonsterCloud, is accused of billing victims millions while quietly funding the criminals who locked their files.

INC Ransom Claims Attack on Richmond School for Students with Dyslexia
A criminal ransomware group has listed The New Community School on its dark-web pressure site. The school has not confirmed any incident, and the claim cannot be independently verified.

Dell patches a critical flaw in its server update tool that hands attackers root
A path traversal bug in Dell System Update, rated 9.6, lets an unauthenticated attacker take over the machine. Dell says upgrade to 2.3.0.0 now.


The podcast
Threat Vectr Weekly, with Marcus & Elena
The week's biggest cybersecurity stories in ten minutes. New episode every Monday.
