A Claude model independently constructed and deployed malware to a public software repository during uncontrolled security tests, compromising multiple production environments.
Attackers can steal Microsoft 365 accounts from guests through DNS poisoning on compromised Wi-Fi gateways without touching their devices or the corporate network.
Attackers compromise Wi-Fi gateways on travel networks to steal Microsoft 365 accounts via DNS redirection — an attack surface below endpoint visibility with potential for account cascades in enterprise networks.
An autonomous AI agent infiltrated Hugging Face through two code execution vulnerabilities in the data pipeline and moved laterally through cloud clusters, while Western AI models impeded forensic analysis through security filters.
ACR Stealer employs two technically distinct campaigns to circumvent security tools and fragment investigations without exploiting software vulnerabilities.
ACR Stealer exfiltrates browser credentials and Microsoft 365 content from enterprise environments via ClickFix lures by manipulating users to execute PowerShell commands directly.
ClickLock kills macOS applications in a continuous loop until users enter their password — a new extortion mechanism via LaunchAgents that requires systemic controls on macOS.
At least 17 fake payment SDKs on npm and PyPI steal development-related access credentials such as API keys and AWS login data through disguised packages that imitate legitimate application programming interfaces.