Screenshot service Gyazo has disclosed a breach affecting about 23.6M user records and 490M image metadata entries after an attacker exploited its upload server.
Researchers used Anthropic’s Claude to chain a forum exploit with an OpenAI SSO flaw, taking over employee accounts and reaching internal code before a rapid bug-bounty fix.
Microsoft has patched 18 vulnerabilities in Azure and Copilot AI services, mostly elevation-of-privilege bugs, with server-side fixes and no known exploitation.
Huntress details two Settra ransomware intrusions against retail and manufacturing firms, highlighting MeshAgent abuse, BYOVD tactics and defender takeaways.
US and Canadian authorities have seized NightmareStresser's domains, disrupting a long-running DDoS-for-hire platform tied to hundreds of thousands of attacks.
U.S. and Canadian authorities seized NightmareStresser DDoS-for-hire domains in an Operation PowerOFF push, disrupting attacks on schools, agencies and gamers.
CISA has released detailed cyber decoy guidance to help critical infrastructure detect post-compromise activity, generate high-fidelity alerts and boost defenses.
US, UK and Dutch agencies warn Iran's Chosen Brick Windows spyware, controlled via Telegram bots, is spying on dissidents, journalists, activists worldwide.