#attacker:


Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

Sep 28, 2026 // 21:08

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, […]

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Sep 16, 2026 // 16:40

Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. […]

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

Sep 15, 2026 // 15:01

With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig […]

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

Sep 14, 2026 // 23:22

An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines using a legitimate […]

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

Sep 10, 2026 // 14:49

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security […]

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Sep 3, 2026 // 00:22

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the […]

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

Aug 18, 2026 // 14:36

A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according […]

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

Aug 11, 2026 // 17:30

A malicious SIM card can order the device it sits in to run commands of the attacker’s choosing. On the cellular modules built into electric-vehicle […]

New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands

Jul 16, 2026 // 15:17

Ask an AI agent to summarize the reviews on a product page, and a single planted review can make it click “Buy Now” instead. Ask […]

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

Jul 13, 2026 // 14:04

Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. “The script looked […]

1 2 Next