Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Threat Actors Use Claude Code, Codex and DeepSeek AI to Power Cyberattacks
2+ hour, 57+ min ago (525+ words) A new threat intelligence report from Gambit Security has documented a ransomware affiliate using generative AI as an operational partner throughout a live intrusion campaign, highlighting how AI-assisted attacks are moving far beyond phishing content and basic malware generation. Nir…...
C2Looper Backdoor Uses GitHub C2 and Shellcode Injection to Establish Ransomware Footholds
2+ hour, 39+ min ago (313+ words) The malware was discovered in July 2026 and is likely used by a ransomware-related threat actor to gain an initial foothold, perform reconnaissance, move laterally, and deploy additional payloads. Researchers assess with low to medium confidence that C2Looper is delivered through multi-stage…...
New Ruby RCE Gadget Chain Turns Unsafe Marshal.load Into Command Execution
3+ day, 4+ hour ago (481+ words) A newly disclosed universal deserialization gadget chain demonstrates that a single unsafe Marshal.load operation can lead to remote command execution on Ruby 4.0.6. The chain reportedly also works unchanged on Ruby versions as far back as 3.3, renewing concerns that Ruby’s…...
Microsoft Updates Copilot App, Merges Personal Chats and Retires Key AI Features
3+ day, 3+ hour ago (459+ words) Microsoft is consolidating its consumer and productivity-focused AI experiences through a major update to the Copilot app, combining chat histories and content for personal users while retiring several high-profile features, including Podcasts, Deep Research, and Group Chat. The changes arrive…...
DCRat Malware Uses DLL Sideloading and Process Hollowing to Hide Inside Trusted Windows Process
4+ day, 13+ min ago (359+ words) The attack ultimately hides a remote-access trojan inside a legitimate Windows-related process, helping it blend into normal endpoint activity. The campaign uses a fake legal-notice lure named “Resolución Denuncia Jurídica,” designed to exploit fear and urgency. Victims receive a phishing…...
Poisoned npm Packages Steal AI Tokens and Spread Them Across Developer Build Environments
4+ day, 3+ hour ago (349+ words) The stolen tokens can be abused directly or fed into underground “transfer stations” that resell discounted access to expensive AI models. AI token jacking is becoming a costly risk as companies rapidly adopt large language models, automated agents, and AI-powered…...
Cybercriminals Can Now Rent Malware That Re-Encrypts Itself to Keep Evading Antivirus
4+ day, 1+ hour ago (437+ words) Cybercriminals are renting services that help malware change its appearance and avoid detection. Cruciferra, a crypter-as-a-service platform linked to campaigns that used tax-themed emails to target victims, including Indian taxpayers and finance professionals. The service is not the final malware....
LiteLLM Supply Chain Breach Spreads Credential Stealer Across Thousands of Enterprise CI/CD Environments
4+ day, 23+ hour ago (325+ words) A major software supply chain breach involving LiteLLM has reportedly exposed credentials, cloud keys, API tokens, and internal configuration data from thousands of enterprise CI/CD environments. Forensic investigations by Snyk, Trend Micro, and Cycode show that LiteLLM was not…...
Phishing, Cracked Software and Discord Links Spread Phantom Stealer Across Multiple Countries
5+ day, 3+ hour ago (359+ words) The malware is designed to silently collect browser credentials, saved passwords, cookies, cryptocurrency wallet data, system details, and other sensitive information from infected Windows devices. Its modular structure, flexible delivery methods, and strong focus on credential theft make it a…...
ShieldBreak Windows Defender Zero-Day Bypasses Microsoft Patch to Gain SYSTEM Access
5+ day, 20+ hour ago (416+ words) The release marks the ninth exploit in the researcher’s 2026 series, and places renewed scrutiny on the resilience of Windows Defender’s core protection components. Rather than introducing an unrelated bug class, ShieldBreak allegedly reaches the same underlying weakness that RoguePlanet exposed:…...