A CISA contractor published internal login credentials that began circulating in November 2025 on GitHub; more than a week later, critical keys remained unrevoked while Congress demands a security review.
The Netherlands dismantled a network of hosting providers linked to the EU-sanctioned Stark Industries and serving as a hub for Russian cyberattacks on European targets.
Attackers have infected a popular npm package (codexui-android, ~27,000 weekly downloads) with malware that steals long-lived OpenAI tokens while successfully evading code audits and Google Play reviews.
Anthropic isolates Claude agents through multi-layered sandboxes (gVisor, Seatbelt, Bubblewrap, VMs) with explicit boundaries for data access, filesystem, and egress control.
The specialized Saiga 2FA phishing kit demonstrates that modern phishing platforms are being deliberately developed to target multi-factor authentication and are evolving from static tools into configurable attack platforms.
Employee data is predominantly compromised through negligent security practices rather than targeted attacks and often remains undetected for extended periods.
A combination of configuration errors in cloud identity and secrets management enables complete system compromise even from individual integration failures.
Two Notepad++ vulnerabilities enable code execution through XML manipulation; they were patched in version 8.9.6.1, but attackers must already have access to the user directory.