ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it's personal. The gang wants the Feds to correct the record on how it operates. "This is NOT financially motivated," a Shiny spokesperson told The Register. "We want the FBI to correct or retract their statements they made, which included substantial false allegations." The FBI did not immediately respond to The Register's request for comment. READ MORE...
Microsoft said Tuesday that it led an industry-wide disruption of a subscription-based scam platform that used an AI chatbot to compromise 12,000 Microsoft accounts over a few-month span. Named EvilTokens, the platform was introduced over a Telegram channel in February and charged an initial $1,500 fee and a recurring $500 charge each month after that. EvilTokens provided a single service for streamlining most steps required to compromise email accounts in large numbers. READ MORE...
An attacker stole about 170 private GitHub repositories from the French security firm CrowdSec, after compromising a former employee's computer with the Shai-Hulud worm, and stole an OAuth token for his GitHub account. CrowdSec acknowledged the breach, which happened in May, last week in a blog post outlining the attack and how it happened. Attackers stole a GitHub API token from the former employee's machine that retained permission to read CrowdSec's private repositories. READ MORE...
A vast network of intermediary servers is enabling users in China to access frontier AI models in the US without revealing their identities and location, likely to circumvent potential access restrictions and monitoring. The volume of activity flowing through the network suggests systematic attempts to use outputs from frontier AI models to create less capable versions at substantially lower cost than developing them independently. READ MORE...
Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don't have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude's paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure. READ MORE...
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. BIG-IP APM (short for Access Policy Manager) is the company's centralized access management proxy solution that helps admins secure access to their organizations' networks, applications, cloud, and application programming interfaces (APIs). Tracked as CVE-2026-94127, the flaw affects instances configured as an OAuth Authorization Server. READ MORE...
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. VCO is a cloud-based centralized management platform that helps admins configure, monitor, and manage VeloCloud SD-WANs (Software-Defined Wide Area Networks) and associated edge devices. Tracked as CVE-2026-93952, this maximum-severity flaw stems from an improper input validation weakness. READ MORE...
Check Point on Tuesday announced urgent patches for a critical-severity vulnerability in Management Server that has been exploited in the wild as a zero-day. Tracked as CVE-2026-93616 (CVSS score of 9.8), the security defect is described as a directory traversal and file upload issue that could allow unauthenticated attackers to upload and execute arbitrary scripts on the Management Server. READ MORE...
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users' credentials and cryptocurrency wallets. Once deployed, the malware does not require continued commands from a human operator, according to Cisco Talos, which describes it as the first publicly documented Windows implant to use this approach for command-and-control (C2). READ MORE...
As the cyber insurance industry has worked to regain momentum against a rising wave of cyber risk, the rapid emergence of AI has put increased pressure on determining whether the sector could afford to cover potentially billions in losses from a catastrophic event. After months of uncertainty, Beazley, a leading specialist in the cyber sector, on Thursday confirmed it would provide "AI-afffirmative cover," meaning it would cover losses stemming from an [AI-related] incident. READ MORE...