Beacon CRM says a compromised AWS access key allowed attackers to copy database backups for around 1,500 UK charities, exposing donor and service user records.
A new Trump directive lets vetted US firms support government-led offensive cyber operations against transnational crime, sparking legal and escalation concerns.
New Android malware chain WindRelay plus SpyNote turns NFC phones into live card relays, letting fraudsters take out loans and transactions in real time.
Researchers warn the City-Forum campaign is abusing guest portals in Salesforce and ServiceNow to quietly siphon customer data, with no patchable CVE in play.
Suspected China-linked hackers used open-source AI agents in a four-day near-autonomous campaign breaching Taiwan government and energy infrastructure.
CloudSEK analysis of data stolen via malicious LiteLLM PyPI releases tied to a Trivy supply-chain attack suggests 2,500+ orgs risk credential exposure.
OpenAI has unveiled GPT-5.6-Cyber, a highly permissive model for vetted defenders that accelerates exploit discovery while reigniting AI safety concerns.
Malicious MCP servers quietly hijack AI coding agents by splitting instructions into benign steps, enabling stealthy exfiltration of SSH keys, code and cloud secrets.
Gunra ransomware is exploiting Fortinet FortiOS/FortiProxy and Schneider Electric PowerLogic P5 flaws to breach global critical infrastructure and extort data.
Attackers used a misconfigured private cellular APN to reach a Polish CHP plantβs OT network, shutting a turbine without cutting heat, CERT Polska reveals.