Latest stories — Page 67

Threat Intelligence

Silent Swap: Unsigned Installers Drop Fake Chromium Extensions That Hijack Crypto Transactions

McAfee Labs documents a clipper campaign using .NET and Golang loaders to sideload a malicious browser extension that rewrites wallet addresses at send time.

3 min read
AI Security

GuardFall: A 1970s Shell Trick Walks Past AI Coding Agent Safety Checks

Adversa AI says ten of eleven open-source coding agents fall to a command-substitution bypass that any sysadmin would recognize on sight.

3 min read
AI Security

Two-Thirds of iPhone AI Chatbot Apps Are Bleeding API Keys

A study of 444 iOS chatbot apps found 282 exposing paid model access in plaintext network traffic — sometimes with no authentication at all.

3 min read
Threat Intelligence

BEC Isn't an Email Problem. It's a Supply Chain.

Underground forums show Business Email Compromise as a multi-stage operation — account access, target research, and mules — not a clever phishing lure.

2 min read
AI Security

Bash Shell Tricks From the '90s Are Breaking AI Coding Agents Wide Open

Old-school shell injection techniques can bypass safeguards in most open-source AI coding agents — and a poisoned repo is all it takes to start the chain.

2 min read
Threat Intelligence

FIFA 2026 Fraud Infrastructure Was Pre-Staged Months Before Kickoff, Researchers Say

A Check Point exposure report documents pre-positioned phishing kits, lookalike domains and multilingual scam pages built well ahead of the June 11 opening match.

2 min read
AI Security

Malicious Extension Spoofs AI Platform to Intercept Searches

A fake browser extension impersonating Perplexity AI intercepted search queries, highlighting governance gaps in enterprise security.

2 min read
Threat Intelligence

From Modded Game Controllers to IBM X-Force Red: The Chris Thompson Arc

A teenage hardware tinkerer grows up to run one of the most recognizable offensive-security brands in enterprise tech — then leaves to build something new.

2 min read
Policy & Regulation

Supreme Court Extends Fourth Amendment Shield to Cell-Site Location Data

A geofence warrant case gives the Court a vehicle to rule that historical location records tied to a phone are constitutionally protected — full stop.

2 min read
Vulnerabilities

SimpleHelp OIDC Bypass Gets Weaponized: TaskWeaver and Djinn Stealer Land on Unpatched Servers

An unauthenticated auth bypass scoring a perfect 10.0 is dropping two new malware families on remote-support boxes that nobody remembered were internet-facing.

2 min read
Vulnerabilities

Six Bugs in AirDrop and Quick Share Let Anyone Within Range Knock Out File Sharing

Researchers chained wireless-range flaws to crash receiving devices and bypass Quick Share permission checks — no taps, no pairing, no prompts.

3 min read
AI Security

The Hidden Cost of Agentic AI in Security: Token Budgets Are Now a Defense Problem

Cybersecurity platforms are racing to embed agentic AI, but the economics of token consumption, AI credits, and deployment architecture may undercut the value before defenders see a return.

2 min read
AI Security

BioShocking: Prompt-Game Trick Pries Credentials From AI Browsers

Researchers at LayerX got six AI browsers and assistants — including ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude extension — to exfiltrate user logins by framing the attack as a game.

3 min read
Vulnerabilities

Pre-Auth Root RCE in Progress Kemp LoadMaster: Patch the API Now

CVE-2026-8037 lets an unauthenticated attacker run commands as root via a crafted API request. CVSS 9.8. The vendor has shipped a fix.

3 min read
Vulnerabilities

Apple Ships Three Dozen Fixes, Including WebKit Bugs Surfaced by LLM-Assisted Review

Four of the patched WebKit flaws were found with help from Claude and Codex — a quiet data point on how vendors are folding AI into vulnerability discovery.

2 min read
Vulnerabilities

Oracle E-Business Suite Payments Bug Hits CVSS 9.8, Already Being Hit

CVE-2026-46817 lets unauthenticated attackers take over Oracle Payments. Exploitation is happening now.

2 min read
Vulnerabilities

CISA Flags Three Daktronics Controller Flaws That Could Let Attackers Hijack Highway Signs

A researcher found the vulnerabilities in controllers widely used to drive digital billboards and roadway message signs. Exploitation could mean someone else controls what drivers read.

2 min read
Breaches

NAIC Says ShinyHunters Walked Out With Public Data and Stale Logs After PeopleSoft Zero-Day Hit

The regulator-of-regulators confirms an Oracle PeopleSoft zero-day was the entry point, but disputes the extortion crew's claims about what was taken.

3 min read
Threat Intelligence

Fake Perplexity Extension Siphoned Every Chrome Address Bar Keystroke

Microsoft researchers flagged a counterfeit Perplexity Chrome extension that piped queries and omnibox input to an attacker server before completing the search.

3 min read
Identity & Access

WhatsApp Starts Username Reservations, Finally Decoupling Identity From Phone Numbers

The optional handle system lets users be reachable without exposing an E.164 number — a meaningful identifier change for a 3-billion-user directory.

3 min read
Threat Intelligence

Mustang Panda Turns Zoho WorkDrive Into C2 in Twin Campaigns Against Indian Government

The China-aligned crew is running parallel operations against New Delhi ministries and hydropower operators, abusing a legitimate cloud collaboration service to move commands past network defenses.

3 min read
© 2026 Threat Vectr