A new open-source project called Cybermes has entered the crowded field of AI-powered offensive security tooling, positioning itself as an enterprise-grade autonomous agent capable of running full penetration tests with …
New Malware-as-a-service Leveraging Adobe-themed Domain to Attack Windows Users Using .bat File
A criminal service is hiding behind a website that appears to offer Adobe Acrobat Reader. The site, acrobatreaderonline.com, is not a document service. Instead, it appears to expose an operator …
Iran-Linked Hackers Force UK Power Plant Offline in Unprecedented Four-Day Cyberattack
A cyberattack attributed to hackers linked to Iran forced a British power plant offline for four consecutive days last month, marking what officials describe as the first successful attack of …
Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 Stories
This week’s bulletin captures a cybersecurity landscape increasingly shaped by artificial intelligence, both as a weapon and a shield. A ransomware affiliate weaponized Claude Code to autonomously steal LDAP credentials, …
Microsoft Windows 11 App Pushes Bing as Default Search in Chrome, Firefox and Brave
Microsoft has built a dedicated Windows 11 app that exists to put Bing in front of users who already chose another search engine. The utility, Microsoft Recommended Search Settings, arrives …
What specifically allowed the agent to reach a real company’s systems during testing?
Wayne Anderson, Managing Director, Cybersecurity and Digital Innovation, BDO USA. First and foremost, the technical “walls” were reduced during the testing experience. One of the questions that many organizations have …
What 45 Million wp2shell Exploit Attempts Reveal About the New Vulnerability Response Window
The latest wp2shell vulnerability was one of the biggest WordPress security events in history. The critical vulnerability chain combined two flaws that allowed unauthenticated attackers to exploit vulnerable sites and ultimately execute …
Grok Zero-Click Attack Steals Chat Data Using Encrypted Prompt Injection
A newly disclosed attack can turn a routine “summarize this page” request in xAI’s Grok web chat into a silent theft of the user’s name, coarse location, subscription tier, and …
Claude Mythos 5 Now Available in Claude Security for Vulnerability Scanning
Anthropic has expanded access to its frontier AI cyber-defense capabilities by making Claude Mythos 5 available in Claude Security, enabling enterprise customers to scan codebases for vulnerabilities and receive AI-generated …
Microsoft Expands Mailbox Storage From 50 GB to 100 GB for Users
Microsoft has started expanding primary mailbox storage for Microsoft 365 Business Basic, Business Standard, and Business Premium users. Eligible users can now receive up to 100 GB of Exchange Online …
