Huntress reports attackers abusing trusted AI platform features to deliver malware
Huntress's Security Operations Center says attackers are increasingly abusing trusted AI platform features rather than attacking the models themselves. Over nine months, it tracked campaigns weaponizing shareable AI content, publ...
Florida confirms DMV driver database breach via stolen police credentials
The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...
Microsoft links passkey-themed phishing to ShinyHunters and Helix extortion crews
Microsoft says threat actors tied to the ShinyHunters, Helix and other extortion gangs have used passkey- and single sign-on-themed social engineering since May 2026 to compromise corporate Microsoft accounts and steal data from M...
Wiz reports Artifactory flaw chain exploited to plant Rust backdoor
Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...
GitLab patches maximum-severity file-read flaw as probes hit exposed servers
GitLab released patches for a maximum-severity path traversal flaw in its repository commits API that lets an unauthenticated attacker read arbitrary files from a GitLab server under certain conditions, the company said. The vuln...
Figma launches Japan data residency for enterprise file hosting
Figma introduced data residency in Japan, letting enterprise customers store Figma Design, FigJam, Figma Slides, and Figma Make file data in the country. The company said the option responds to customer demand for domestic storag...
