Elastic documents REVSTEALER-linked modules that disable Windows defenses
Elastic Security Labs documented four previously unreported programs associated with the REVSTEALER Windows information stealer. One module, LockAppHost, can add Microsoft Defender exclusions, disable Windows Update services and t...
PaperCut flaws exploited in credential-theft attacks on schools
Attackers are exploiting two newly disclosed PaperCut flaws in attacks on vulnerable education-sector servers in the U.S. and Europe, according to Arctic Wolf. The security firm described the flaws as an authentication-bypass and ...
Microsoft reports ASCII-smuggling use in email spam
Microsoft said email spammers are adopting ASCII smuggling, a technique used to conceal malicious instructions in AI-agent prompt-injection attacks, to evade email-platform filters. The reported shift applies the obfuscation techn...
Liquid sidechain pauses after reported 4,000 BTC withdrawal
Liquid says purported white-hat hackers withdrew about 4,000 BTC, valued in its statement at roughly $320 million, from the Liquid Federation wallet. The company says the funds left through the SideSwap Peg-out Authorization Key, ...
Report describes AI-assisted ransomware intrusion completed in under 10 hours
The Tech Edvocate, citing Palo Alto Networks' Unit 42, reports that a human ransomware operator used AI models and agentic frameworks in an intrusion that compromised an enterprise network in under 10 hours. The report says the ag...
Berlin reviews ransomware data release after rejecting ransom
Berlin's state government said it is reviewing a 5.79TB trove of stolen data published by the Rhysida ransomware group after the state refused to pay a ransom. Reuters reported that the released files reportedly include national-d...
