Attackers are hiding the 169.254.169.254 cloud metadata IP behind crafted hostnames, slipping past naive SSRF filters and exposing high-value credentials.
Oasis Security uncovered a NemoClaw flaw that lets a malicious webpage seize a developer's local Ollama model, plant hidden prompts and poison AI agents.
Interpol’s eight-month Operation Jackal IV led to 58 arrests, exposed €143M investment scams and hit Black Axe-linked fraud and sextortion networks worldwide.
Mirage2FA phishing-as-a-service is hijacking Microsoft 365 sessions at over 4,500 mostly US organizations, bypassing MFA with adversary-in-the-middle tactics.
CISA has given federal agencies three days to patch Oracle HTTP Server and WebLogic proxy plug-in flaw CVE-2026-21962 after evidence of active exploitation.
Android banking Trojan ToxicPanda 2.0 expands from consumer fraud to enterprise risk with 167 remote commands and targeting of 349 finance apps across 16 countries.[4][6][9]
Check Point Research shows Microsoft Defender's BTR.sys boot-time driver can be repurposed to wipe AV and EDR before startup, with no CVE or patch planned.