Attackers abused a misconfigured METR agent dashboard to steal an API key, running up about $600K in AI model credits before the nonprofit cut off access.
A federal whistleblower warns USPS’s rushed ballot mail IT systems under Trump’s new rule could reject valid mail-in ballots and trigger legal fights in 2026.
A new ClickFix campaign chains fake fixes with EtherHiding C2 on the Polygon blockchain, evading takedowns while quietly infecting unwitting organizations.
White House and Texas leaders launched Project Watershed 250, a six-month pilot delivering free cyber defense to under-resourced water utilities statewide.
Anthropic is warning Claude users that commodity infostealer malware is hijacking authenticated browser sessions, burning paid usage and bypassing MFA controls.
Kaspersky has pushed a database update after researcher Nightmare Eclipse released HardBreacher, a proof-of-concept exploit targeting Endpoint Security.
Anthropic is forcibly logging Claude users out, wiping stored payment methods and flagging infostealer-driven account abuse that hijacks live AI sessions.