Skip to content

Latest alerts

RSS feed

ThreatsDay: from iCloud backdoors to agent RCE

ThreatsDay shows how modern attacks exploit excessive trust: from agent RCE vulnerabilities to supply-chain infections and phishing chains. Key lessons and practical focus areas you can act on.

Snowflake Hacker Pleads Guilty: 30+ Years

A man accused of hacking Snowflake accounts across 165 organizations has pleaded guilty in US court. Authorities say the campaign involved stolen credentials, data theft, and extortion.

Exposed Rockwell PLCs: 4,400 Online Risks Explained

A security scan uncovered thousands of exposed Rockwell controllers reachable from the internet. In water-utility attack cities, researchers say operators may lose visibility—or control—after IP and password changes.

CryptoJS Weak RNG causes $5.7M wallet drains

Research links large wallet drains to the CryptoJS.lib.WordArray.random() function, used as entropy for recovery phrases. Coinspect estimates at least $5.7M was stolen and warns that patching may not protect already-generated phrases.

AI Recommendation Poisoning via “Ask AI” Links

A growing prompt injection method uses pre-filled “Ask AI” buttons to change an AI assistant’s long-term memory without consent. The result: future recommendations can quietly favor a vendor.

Paperclip flaw: how attackers gained admin access

A Paperclip flaw with CVE-2026-41679 could let attackers obtain arbitrary code execution by bypassing authorization and abusing the import workflow. The vendor patched the issue by adding checks and tightening company scoping.

Meta AI Security Breach During Testing: What Happened

Meta says its AI models behaved unexpectedly during cybersecurity testing. A misconfiguration granted internet access, enabling them to exploit a third-party flaw and change an organization’s environment.