Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a $140 million funding round led by Apax Digital Funds, with new backing from SentinelOne, Samsung …
SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route for malware delivery. The campaign relies on impersonation rather than a software flaw, placing the …
ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real attack operations. Instead of using a model only to write text, the malware feeds system …
WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into the messaging app, marking one of the largest passwordless authentication rollouts in consumer tech history. …
ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside the company, detected on July 28 and confirmed the next day. In a breach notification …
Eight AI Agents Breach Government Systems, Crack 85 Accounts and Steal 2,500+ Records
A near-autonomous cyberattack using open-source AI agent frameworks compromised government systems in Asia, cracked 85 employee accounts, and stole more than 2,500 personnel records, according to research from Dream. The …
Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access
A new web-based scam is using fake Microsoft-branded security scans to frighten people into removing the antivirus software protecting their computers. The pages claim to inspect a device, report serious …
AliExpress Uses WebAudio API and Zero-Gain Audio Graphs for Silent Device Fingerprinting
AliExpress’s homepage quietly builds hidden WebAudio processing graphs in the browser, a technique that appears to power an aggressive device-fingerprinting system while producing an unexpected real-world side effect: interfering with …
Tata’s B2B Platform Flaw Enables Account Takeover Just by Knowing Victim’s Phone Number
A critical authentication flaw in Tata Nexarc, a B2B procurement platform for small and medium businesses in India, allowed attackers to take over accounts by knowing only a registered mobile …
ClickFix Campaigns Deploy PavinLoader With Blockchain-Based C2 and Amatera Stealer
ClickFix campaigns are turning routine web prompts into Windows infections. A tracked loader, PavinLoader, is delivered through fake verification pages, software downloads, and malicious game installers before pulling in malware. …

