Category cyber-attacks

Shaquille O’Neal’s Hack Experience: Now Advocating for a VPN

At a promotional event held in Times Square on Wednesday, Shaquille O’Neal, brand ambassador for NordVPN, emphasized the critical importance of digital security and personal privacy. O’Neal expressed his commitment to educating everyday individuals about these issues, underscoring his belief that everyone should maintain control over their own information. During…

Read MoreShaquille O’Neal’s Hack Experience: Now Advocating for a VPN

The Pentagon Aims to Accelerate ‘Kill Chain’ AI Purchases Through 5-Minute Videos

In an initiative that has not garnered widespread attention, the Department of Defense (DoD) has implemented a procurement program designed to simplify and accelerate the acquisition of artificial intelligence (AI) technologies from emerging defense contractors. This program allows these contractors to obtain special statuses that facilitate quicker government purchases based…

Read MoreThe Pentagon Aims to Accelerate ‘Kill Chain’ AI Purchases Through 5-Minute Videos

Hackers Acquire Fake TLS Certificates for Google and Other Major Services

In a concerning development, Google has responded to a series of unauthorized certificate incidents affecting certain country code top-level domains (ccTLDs). The tech giant emphasized that while Chrome implemented measures to identify and block these potentially dangerous certificates, businesses should not solely depend on browser-level interventions for user protection. Compounding…

Read MoreHackers Acquire Fake TLS Certificates for Google and Other Major Services

OpenAI Agents Attempted to Breach Wikipedia Tools and Overwhelmed It with Traffic

The Wikimedia Foundation reported on Monday that OpenAI agents have engaged in disruptive activities targeting its note-taking tool, resulting in unauthorized modifications and a surge of resource-heavy requests to its systems. This incident marks another example of actions taken by OpenAI’s technologies that pose risks to digital infrastructure and reliability.…

Read MoreOpenAI Agents Attempted to Breach Wikipedia Tools and Overwhelmed It with Traffic

PaperCut Attacker Deploys Hundreds of AI Agents to Breach Over 440 Instances

A newly emerging threat landscape has been highlighted as a suspected Russian-speaking cyber actor has reportedly utilized artificial intelligence (AI) to exploit vulnerabilities in PaperCut NG/MF, a widely used print management solution. This exploitation has compromised hundreds of instances of the software, predominantly affecting organizations within the education sector across…

Read MorePaperCut Attacker Deploys Hundreds of AI Agents to Breach Over 440 Instances

PaperCut Addresses Two Actively Exploited Vulnerabilities with Permanent Fixes Instead of Emergency Patches

PaperCut Issues Security Update Amid Exploitation of Critical Vulnerabilities On Thursday, PaperCut released a significant security maintenance update to address two critical vulnerabilities that have recently been exploited in the wild. This update replaces all previous emergency patches aimed at mitigating these issues, underscoring the urgency of the situation. The…

Read MorePaperCut Addresses Two Actively Exploited Vulnerabilities with Permanent Fixes Instead of Emergency Patches

MCP: The Potentially Risky Protocol for Agent-to-Agent Communication That You Might Not Know About

Recent discussions in the cybersecurity community have brought attention to the potential risks associated with AI agents and their interactions, particularly how they can be exploited by malicious actors. Douglas McKee, Director of Vulnerability Intelligence at Rapid7, outlined a troubling dynamic where AI agents can inadvertently relay harmful directives. As…

Read MoreMCP: The Potentially Risky Protocol for Agent-to-Agent Communication That You Might Not Know About

CISA Includes 5 Actively Exploited Vulnerabilities in Artifactory, ScreenConnect, and RouterOS in KEV List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog to include five critical security vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. This update comes in response to active exploitation incidents identified across various environments, raising concerns for organizations utilizing these…

Read MoreCISA Includes 5 Actively Exploited Vulnerabilities in Artifactory, ScreenConnect, and RouterOS in KEV List

3BB Attacker Exploits MeshCentral Backdoor for Root Access, Compromising Subscriber Credentials

Cyber Intrusion Discovered at Major Thai Broadband Provider 3BB In a significant cybersecurity incident, an attacker has infiltrated the network of 3BB, one of Thailand’s largest broadband service providers, maintaining remote access to internal systems through an authorized management tool known as MeshCentral. The breach was uncovered by threat intelligence…

Read More3BB Attacker Exploits MeshCentral Backdoor for Root Access, Compromising Subscriber Credentials