Latest from the feed

Content is curated from many trusted industry sources, including vendor advisories, security blogs, bug bounty programs, and conference organizers worldwide.

  • Act Fast: Early Fraud Reporting Improves Recovery Odds

    Cyber fraud rises with online banking and digital payments. Victims can often recover funds if they act fast: report immediately, request freezes, and file disputes. Prompt action improves chances of reversal and refunds, depending on policy, timing, and cooperation with banks and payment networks.

    Source: The 420

  • Estée Lauder Breach: Oracle HR Flaw Exposes Customer Data

    Estée Lauder has notified customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite used for human resources operations. The incident prompted investigations and a security review to determine data exposure and remediation steps, with ongoing communication to affected individuals. The firm is reviewing exposure and remedies.

    Source: Bleeping Computer

  • Shadow AI Amplifies Disclosure Risk for Banks

    A bank's SEC filing reveals how shadow AI--unauthorized tools used by employees--can transform a simple shortcut into a material cybersecurity event. Even with looser federal disclosure rules, firms still face state laws, sector mandates, rising litigation risk, and mounting costs that stress incident response plans.

    Source: Data Breach Today

  • Neo Debuts $100M to Guard AI-Enabled Enterprise Apps

    Neo, a security startup focused on agentic AI, debuted with $100M in funding to help enterprises discover, analyze, and govern AI-enabled software across apps. It contends agentic apps, plug-ins, and AI skills create a fast-growing security blind spot that traditional endpoint tools aren’t designed to address.

    Source: Data Breach Today

  • Health Data Theft Hits Craneware and Abbott in Probes

    Cybercriminals are widening their data theft and other cyberattacks to healthcare sector outsiders, targeting third‑party vendors and suppliers. Recent victims include Craneware and Abbott, underscoring how breaches at vendors can threaten patient data, operations, and regulatory compliance for healthcare organizations. This shift risks data leaks...

    Source: Data Breach Today

  • SonicWall SMA1000 zero-days exploited to push custom malware

    Two recently disclosed SonicWall SMA1000 flaws were exploited in ongoing zero-day campaigns, enabling threat actors to install custom malware on vulnerable VPN appliances and potentially gain persistence, data access, or remote control within affected networks. This risk touches remote work, supply chains, and infra, urging detection and patching. now

    Source: Bleeping Computer

  • Hackers Steal $23.7M from Ostium via Off-Chain Breach

    Ostium reports a security incident in which an attacker stole $23.75 million from its liquidity provider vault after compromising the off‑chain price feed infrastructure relied on by the protocol, underscoring risks associated with external data feeds and supply chain governance. The disclosure highlights the need for stronger data validation, now.

    Source: Bleeping Computer

  • WordPress RCE vuln exploited after patches, AI-assisted chaos

    Two WordPress bugs (CVE-2026-63030 and CVE-2026-60137) enabled pre-auth RCE after fixes, with AI-assisted code reuse accelerating weaponization. Public PoCs spread quickly, allowing hashed-credential exfiltration and remote code execution in short order. WordPress patched late; exploitation rapidly grew across organizations worldwide.

    Source: The Register - Cyber Crime

  • WP2Shell Flaw Lets Remote Takeover of WordPress Sites

    Attackers rapidly chained CVE-2026-60137 with CVE-2026-63030 within days of disclosure, intensifying exploit attempts targeting a major Internet-facing attack surface. The rapid chaining of these flaws highlights elevated risk from multi-vulnerability sequences and underscores the urgent need for patching, monitoring, and hardening to reduce risk.

    Source: Dark Reading

  • AI sandbox escapes hit Cursor Codex Gemini CLI Antigravity

    Researchers escaped sandboxes in Cursor, Codex, Gemini CLI and Antigravity by instructing the AI agent to write files that trusted host tools subsequently executed. The report notes multiple CVEs, applied patches, and Google downgrading two Antigravity findings, highlighting continued risks in AI-assisted tooling. The study urges stronger sandbox.

    Source: Bleeping Computer

  • JadePuffer Attacks Target AI Data with EncForge Ransomware

    JadePuffer’s autonomous AI agent now includes EncForge, a bespoke malware that encrypts AI assets—training data, vector stores, and model checkpoints. This capability threatens data confidentiality, prolongs recovery, and highlights the rising risk of malware tailored to corrupt ML pipelines and deployed AI systems.

    Source: Bleeping Computer

  • Hugging Face: Autonomous AI Agent Breach Hits Production

    An AI-driven cyberattack compromised a limited portion of Hugging Face datasets and service credentials, while public models, Spaces, and published packages remained untampered, indicating targeted access rather than broad compromise across the platform.

    Source: Hack Read

Real-time threat intelligence1654 signals

Latest Intelligence

News

Act Fast: Early Fraud Reporting Improves Recovery Odds

Cyber fraud rises with online banking and digital payments. Victims can often recover funds if they act fast: report immediately, request freezes, and file disputes. Prompt action improves chances of reversal and refunds, depending on policy, timing, and cooperation with banks and payment networks.

Estée Lauder Breach: Oracle HR Flaw Exposes Customer Data
News

Estée Lauder Breach: Oracle HR Flaw Exposes Customer Data

Estée Lauder has notified customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite used for human resources operations. The incident prompted investigations and a security review to determine data exposure and remediation steps, with ongoing communication to affected individuals. The firm is reviewing exposure and remedies.

Shadow AI Amplifies Disclosure Risk for Banks
News

Shadow AI Amplifies Disclosure Risk for Banks

A bank's SEC filing reveals how shadow AI--unauthorized tools used by employees--can transform a simple shortcut into a material cybersecurity event. Even with looser federal disclosure rules, firms still face state laws, sector mandates, rising litigation risk, and mounting costs that stress incident response plans.

Neo Debuts $100M to Guard AI-Enabled Enterprise Apps
News

Neo Debuts $100M to Guard AI-Enabled Enterprise Apps

Neo, a security startup focused on agentic AI, debuted with $100M in funding to help enterprises discover, analyze, and govern AI-enabled software across apps. It contends agentic apps, plug-ins, and AI skills create a fast-growing security blind spot that traditional endpoint tools aren’t designed to address.

Health Data Theft Hits Craneware and Abbott in Probes
News

Health Data Theft Hits Craneware and Abbott in Probes

Cybercriminals are widening their data theft and other cyberattacks to healthcare sector outsiders, targeting third‑party vendors and suppliers. Recent victims include Craneware and Abbott, underscoring how breaches at vendors can threaten patient data, operations, and regulatory compliance for healthcare organizations. This shift risks data leaks...

SonicWall SMA1000 zero-days exploited to push custom malware
News

SonicWall SMA1000 zero-days exploited to push custom malware

Two recently disclosed SonicWall SMA1000 flaws were exploited in ongoing zero-day campaigns, enabling threat actors to install custom malware on vulnerable VPN appliances and potentially gain persistence, data access, or remote control within affected networks. This risk touches remote work, supply chains, and infra, urging detection and patching. now

Hackers Steal $23.7M from Ostium via Off-Chain Breach
News

Hackers Steal $23.7M from Ostium via Off-Chain Breach

Ostium reports a security incident in which an attacker stole $23.75 million from its liquidity provider vault after compromising the off‑chain price feed infrastructure relied on by the protocol, underscoring risks associated with external data feeds and supply chain governance. The disclosure highlights the need for stronger data validation, now.

WordPress RCE vuln exploited after patches, AI-assisted chaos
News

WordPress RCE vuln exploited after patches, AI-assisted chaos

Two WordPress bugs (CVE-2026-63030 and CVE-2026-60137) enabled pre-auth RCE after fixes, with AI-assisted code reuse accelerating weaponization. Public PoCs spread quickly, allowing hashed-credential exfiltration and remote code execution in short order. WordPress patched late; exploitation rapidly grew across organizations worldwide.

WP2Shell Flaw Lets Remote Takeover of WordPress Sites
News

WP2Shell Flaw Lets Remote Takeover of WordPress Sites

Attackers rapidly chained CVE-2026-60137 with CVE-2026-63030 within days of disclosure, intensifying exploit attempts targeting a major Internet-facing attack surface. The rapid chaining of these flaws highlights elevated risk from multi-vulnerability sequences and underscores the urgent need for patching, monitoring, and hardening to reduce risk.

AI sandbox escapes hit Cursor Codex Gemini CLI Antigravity
News

AI sandbox escapes hit Cursor Codex Gemini CLI Antigravity

Researchers escaped sandboxes in Cursor, Codex, Gemini CLI and Antigravity by instructing the AI agent to write files that trusted host tools subsequently executed. The report notes multiple CVEs, applied patches, and Google downgrading two Antigravity findings, highlighting continued risks in AI-assisted tooling. The study urges stronger sandbox.

JadePuffer Attacks Target AI Data with EncForge Ransomware
News

JadePuffer Attacks Target AI Data with EncForge Ransomware

JadePuffer’s autonomous AI agent now includes EncForge, a bespoke malware that encrypts AI assets—training data, vector stores, and model checkpoints. This capability threatens data confidentiality, prolongs recovery, and highlights the rising risk of malware tailored to corrupt ML pipelines and deployed AI systems.

Hugging Face: Autonomous AI Agent Breach Hits Production
News

Hugging Face: Autonomous AI Agent Breach Hits Production

An AI-driven cyberattack compromised a limited portion of Hugging Face datasets and service credentials, while public models, Spaces, and published packages remained untampered, indicating targeted access rather than broad compromise across the platform.

Download Secwiser App