New EvilTokens Attack Exposes Browser Visibility Gap in Enterprise SOCs
EvilTokens phishing hides takeover clues until browser execution leaving SOC teams needing deeper visibility to validate threats faster and reduce account risk.
EvilTokens phishing hides takeover clues until browser execution leaving SOC teams needing deeper visibility to validate threats faster and reduce account risk.
A adoção de chatbots e assistentes com inteligência artificial nas empresas acelerou nos últimos meses. Equipes de atendimento, suporte interno, jurídico e financeiro passaram a contar com interfaces conversacionais alimentadas por LLMs para automatizar tarefas e responder pergun…
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnera…
A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. [...]
Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction. The cryptocurrency clipper activity has been codenamed Silent Swap by McA…
A fake FIFA World Cup 2026 T-shirt giveaway scam is spreading Voidrift malware through personalized emails using company logos and trusted websites to bypass security filters.
Business Email Compromise is more than an email scam. It's a coordinated operation involving compromised accounts, financial research, and cash-out networks. Flare explores how underground forums reveal how BEC attacks are planned and executed. [...]
Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend s…
Cibercriminosos estão explorando ativamente uma vulnerabilidade crítica no Oracle E-Business Suite, sistema usado por empresas para processos financeiros, pagamentos e operações corporativas. A falha foi identificada como CVE-2026-46817 e recebeu pontuação CVSS 9.8. O problema af…
Uma vulnerabilidade de execução remota de código no Microsoft 365 Apps pode permitir que invasores comprometam computadores por meio de um arquivo Excel malicioso. A falha foi identificada como CVE-2025-60727 e afeta diferentes versões do Microsoft Office. O problema está na form…
The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-planned, months out, across three sectors and at least ten langu…
An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0…
Uma vulnerabilidade crítica no Gemini CLI, ferramenta de linha de comando do Google voltada a desenvolvedores, pode permitir que invasores executem comandos em ambientes automatizados de desenvolvimento, especialmente em fluxos do GitHub Actions. A falha foi identificada como CVE…
Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. [...]
The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. [...]
Two researchers have found six security flaws in AirDrop and Quick Share, the wireless features that beam files between nearby devices with no cables or shared network. An attacker within wireless range, with just a laptop and no prior connection, can crash the sharing service o…
CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. [...]
Washington Dept. Health & Social Services Insider Breach Affects 8,600 Individuals The HIPAA Journal
The Washington Department of Social and Health Services (DSHS) has identified an insider data breach involving unauthorized access to the protected […] The post Washington Dept. Health & Social Services Insider Breach Affects 8,600 Individuals appeared first on The HIPAA Journal.
Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user's credentials and sending them to an attacker. …