The Perilous Hallucinations of AI Coding Agents: A New Era of Exploitation Emerges

The rapid integration of Artificial Intelligence into software development workflows has ushered in an era of unprecedented productivity gains. AI coding agents, designed to streamline tasks from code generation to…

Chick-fil-A Suffers Credential Stuffing Attack, Exposing Data of Over 13,000 Customers

The fast-food giant Chick-fil-A has confirmed a significant data breach, revealing that the personal information of 13,322 customers was compromised due to a wave of credential stuffing attacks targeting its…

GitHub and PyPI Introduce Time-Based Defenses Against Software Supply Chain Attacks

In a significant move to bolster the security of the open-source software ecosystem, GitHub and the Python Package Index (PyPI) have jointly implemented new time-based security measures designed to combat…

Microsoft’s Automated Network Maintenance System Triggered Massive July 23rd Outage Affecting Azure and Microsoft 365 Services

A critical bug within Microsoft’s automated network maintenance request system was identified as the root cause of a widespread service disruption on Thursday, July 23rd, impacting millions of users across…

Escalating Sextortion Scams Exploit Data Breach Information, Targeting Victims with Fabricated Threats

Threat actors are leveraging email addresses previously exposed in data breaches orchestrated by the notorious ShinyHunters extortion group to perpetrate a wave of sophisticated sextortion scams. These emails, demanding $2,000…

Steam Discussion Forums Targeted by Sophisticated "ClickFix" Attackers, Deploying Cryptominers Under the Guise of Game and System Fixes

Steam, the ubiquitous digital storefront and gaming platform, has become the latest battleground for cybercriminals employing a deceptive social engineering tactic known as "ClickFix." Threat actors are reportedly exploiting the…

Malicious Advertising Campaigns Exploit Browser Memory for In-Browser Malware Assembly

A sophisticated and widespread malvertising campaign, dubbed "SourTrade" by security researchers, is employing an innovative and concerning tactic: leveraging the web browser’s own memory as a clandestine assembly line for…

ChatGPT Experiences Widespread Outage Affecting Users Globally, Including OpenAI API and Codex

A significant and widespread outage is currently impacting OpenAI’s popular artificial intelligence chatbot, ChatGPT, rendering it inaccessible for users across the globe. The disruption, which began around 5:00 AM Eastern…

Hermes AI Agent Automates Post-Exploitation in Alleged Thailand Ministry of Finance Breach

A sophisticated cyberattack, potentially leveraging the open-source Hermes AI agent in an automated "YOLO" mode, has been uncovered targeting Thailand’s Ministry of Finance. Threat intelligence firm Hunt.io, in conjunction with…

OnTrac Notifies Customers of Data Breach After Network Hack

OnTrac, a prominent American parcel delivery company specializing in last-mile e-commerce logistics, has alerted its customers to a significant data breach that occurred on its corporate network. The incident, detected…