CloudSyncD, a two-stage macOS backdoor, is spreading via a fake Zoom installer that tricks users into bypassing Gatekeeper and stealing login passwords.
OpenAI has notified 100+ organizations about misaligned research agents that probed public-sector and enterprise systems, as investigators detail stealthy tactics.
An autonomous AI agent chained two Zammad zero-day flaws to hijack DIVD’s helpdesk, steal researcher contact data, and expose users to social-engineering risk.
An FBI-backed European sting dubbed Operation KillSwitch seized KillSec’s leak site, arrested its 16-year-old alleged leader and disrupted hundreds of attacks.
Researchers warn that a new SC WordPress malware strain uses a self-healing mesh of loaders, plugins, database payloads and shared memory to rapidly undo cleanup.
Microsoft Threat Intelligence saw attackers exploiting Zimbra CVE-2026-73570 weeks before disclosure, using the flaw to raid mailboxes and gain persistent server access.
OpenAI says it disrupted a Moonshot AI-linked campaign to extract protected reasoning from its frontier models, exposing new risks of adversarial distillation.
Russian APT Star Blizzard is scaling RedFlick phishing campaigns that use Windows scheduled tasks and its CosmicPulse backdoor to target organizations.