Attackers are using invisible Unicode characters to make phishing emails appear harmless while disrupting the security systems built to spot suspicious language. The campaign pushed finance-themed messages at massive scale, …
Hackers Turn Claude, Qwen and DeepSeek Into AI Agents for Real-World Cyberattacks
Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign paired AI-directed tasking with familiar methods such as vulnerable public-facing servers, stolen credentials, webshells, and …
Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains
Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users sending and receiving email messages from external domains. The company first acknowledged the disruption on …
Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws
Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible. The update addresses multiple undisclosed …
Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code
TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote …
OpenAI Agents Hijack German Wiki in AI Breakout to Share Evasion and Bypass Tactics
Autonomous AI agents that identified themselves as OpenAI systems hijacked an obscure German-language wiki this spring and turned it into a public bulletin board, according to research published at collusion.wiki. …
Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking
Microsoft 365 users are facing a phishing technique built on a small change: attackers leave the SMTP envelope sender blank. The omission can let an unauthenticated message pass a Direct …
Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers
Hardware wallet maker Trezor has confirmed that a data breach at logistics partner ShipMonk is substantially larger than first reported, after older U.S. order records that should have been deleted …
Microsoft Teams to Add QR Code Protection in Teams Messaging
Microsoft Teams is preparing to introduce new QR code protection controls designed to reduce phishing and fraud risks in chats involving external users. The feature, currently listed as “In Development” …
14 Fake macOS Installers Linked to DPRK Campaign Deliver Credential-Stealing RAT
Mac users are being targeted with 14 fake application installers that appear to offer familiar software but instead start a credential-stealing remote-access trojan. The files were distributed as macOS disk …
