Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]
Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.
A malicious application delivers four-stage Android spyware via phony Google Play sites, exploiting civilian fear during Iranian missile strikes.
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-893…
A agência de cibersegurança dos Estados Unidos, CISA, ordenou ontem que órgãos do governo federal priorizem a correção de uma vulnerabilidade crítica no Langflow, framework visual para construção de agentes de IA. A falha, registrada como CVE-2026-0770 (CVSS de 9.8), permite que …
OpenAI models escaped from a controlled cyber test, exploited zero-day flaws and breached Hugging Face while searching its production database for test answers.
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]
"This is day one for cybersecurity in the age of agents," Hugging Face CEO says.
Advanced LLMs escaped their sandboxes while attempting to achieve a non-malicious benchmark test objective.
Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data. The shortcoming has been codenamed Hermet…
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_lo…
Clover Health Assessing Impact of Social Engineering Incident The HIPAA Journal
Clover Health Investments has notified the U.S. Securities and Exchange Commission (SEC) about a cybersecurity incident first identified on July […] The post Clover Health Assessing Impact of Social Engineering Incident appeared first on The HIPAA Journal.
Operadores ligados ao ransomware Qilin exploraram uma falha no PAN-OS para invadir redes corporativas e criptografar sistemas. Os ataques observados em junho de 2026 começaram pelo serviço de VPN GlobalProtect, instalado em firewalls da Palo Alto Networks. Identificada como CVE-2…
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]
Uma vulnerabilidade crítica no Microsoft SharePoint Server foi explorada em ataques para executar código remotamente sem autenticação. Registrada como CVE-2025-53770, a falha recebeu pontuação CVSS de 9,8 e afeta instalações locais da plataforma. O problema envolve a desserializa…
A vulnerability in snap-confine lets an unprivileged user gain root access on affected Ubuntu Desktop systems. Install the latest snapd update to fix the issue.
Uma campanha chamada AgentBaiting está usando falsas extensões de inteligência artificial para induzir agentes e desenvolvedores a instalar malware. A operação FakeGit reúne cerca de 7.600 repositórios maliciosos no GitHub, dos quais mais de 800 se apresentam como Skills ou servi…
American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. [...]
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on…