Tag: threat
-
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim’s Copilot session.The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that…
-
University of Texas forced to take systems offline in San Antonio after cyberattack
The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, including phones, offline in response. First seen on therecord.media Jump to article: therecord.media/university-of-texas-forced-to-take-systems-offline-cyberattack-san-antonio
-
Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss
Apple sent a new wave of mercenary spyware threat notifications to targeted users in 110 countries, while making the warnings more visible on iPhones. The alerts signal suspected targeting, not confirmed compromise, and Apple is urging affected users to verify the warning, consider Lockdown Mode, and seek expert help. The post Apple Warns Users in…
-
Hacker Claims Millions of Records Stolen From Azure Tenants
A threat actor is claiming to have stolen millions of employee records from the Microsoft Azure environments of several major companies, raising concerns that the information could be used to launch targeted phishing, impersonation, and privilege escalation attacks. The threat actor, known as >>TheHatman,<< has reportedly posted internal employee directories belonging to companies including McDonald's,…
-
Courts Face New Threat as Litigant Uses Hidden AI Prompt Injection in Filings
In what is believed to be the first decision of its kind in the U.S., a Connecticut state court judge has sanctioned a self-represented litigant for attempting to covertly influence artificial intelligence (AI) systems through hidden text embedded in court documents. In an Aug. 6 ruling in Elliott v. New York Bariatric Group, Superior Court..…
-
10 Integrated Risk Management Strategies with Continuum GRC in 2026
Tags: business, ciso, compliance, control, cybersecurity, governance, grc, risk, risk-management, strategy, threatIn 2026, organizations face an increasingly complex threat landscape where siloed risk management approaches fail to address the interoperability demands of modern regulatory frameworks. Integrated Risk Management has emerged as the essential discipline for CISOs and compliance officers seeking to unify cybersecurity controls, audit processes, and business objectives under a single governance model. Continuum GRC”¦…
-
Silent ‘TwinLoot’ Cyber Threat Operates Entirely From Microsoft’s Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials and achieves persistence. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud
-
Adam Shostack Talks Hugging Face Breach & PHANTOM-B
The security expert talks with the Dark Reading News Desk about why he blown away by OpenAI’s revelations regarding the Hugging Face attack, and also discussed his new threat model for LLMs. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/adam-shostack-talks-hugging-face-phantom-b
-
Law Firms Increasingly Targeted By Ransomware/Vishing Attacks
Law firms face growing ransomware and data-theft threats as attackers target privileged client information, exposing firms to cybersecurity, ethical and legal risks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/law-firms-increasingly-targeted-by-ransomware-vishing-attacks/
-
Projextor Abuses Cross-Platform Electron Framework to Conceal Malware Activity
Threat actors behind the Projextor campaign are abusing Electron-based productivity applications to conceal malware-like capabilities behind fully functioning document converters, meal planners, recipe tools, and PDF utilities. The applications deliver their advertised features, but their shared codebase also enables runtime JavaScript execution and access to desktop-capture functionality creating a serious surveillance and post-compromise risk. Search-optimized…
-
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below – ubnuler ubnlder ri18nr reaker rakier orakw joxn First seen…
-
How the Mass-Adoption of AI is Redefining the Shift to Continuous Threat Exposure Management
AI adoption is expanding the enterprise attack surface faster than security teams can respond. Exposure management helps organizations discover shadow AI, protect sensitive data and prioritize exploitable risk. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-the-mass-adoption-of-ai-is-redefining-the-shift-to-continuous-threat-exposure-management/
-
Hacker claims millions of records stolen from corporate Azure tenants
A threat actor known as >>TheHatman<< claims to have obtained millions of employee records from the Azure environments of several Fortune 500 companies, including … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/azure-data-leak-fortune-500-companies/
-
C2Looper v2 Uses GitHub Repositories as Full CommandControl Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver tasks, receive results, maintain beacon records, and host payloads. ThreatLabz identified the malware in July 2026 and assesses, with low-to-medium confidence, that it is delivered through…
-
Hackers Turn Claude Code and Codex Into AI-Powered Tools for Credential Theft and Cloud Attacks
Threat actors are increasingly using coding assistants as operational tools. Detailed research from Gambit Security highlights three campaigns where Claude Code, OpenAI Codex, and large language models facilitated activities ranging from ransomware preparation to the harvesting of secrets on a large scale and exploiting cloud accounts. These cases demonstrate how AI can speed up attackers’…

