Gen Digital ties China-linked UNC3569 to Sogou input flaw used to plant GRAYRABBIT backdoor
Image: Primary
Image: Primary
Microsoft says threat actors tied to the ShinyHunters, Helix and other extortion gangs have used passkey- and single sign-on-themed social engineering since May 2026 to compromise corporate Microsoft accounts and steal data from M...
Anthropic says a French-speaking actor using the handle 'frkoo' and linked to the ShinyHunters collective ran a credential-harvesting pipeline across ten AWS EC2 workers that mass-downloaded 1.8 million distinct Android APKs, deco...
Anthropic said it identified and disrupted industrial-scale illicit distillation campaigns against Claude run by seven China-based labs, including Alibaba, Moonshot, DeepSeek, Z.ai and MiniMax. The company said the labs routed re...
The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...
Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...
GitLab released patches for a maximum-severity path traversal flaw in its repository commits API that lets an unauthenticated attacker read arbitrary files from a GitLab server under certain conditions, the company said. The vuln...