News
-
ClickFix Mac stealer targets credentials and crypto
Huntress has documented a ClickFix-delivered macOS stealer that harvests identity data and contains code capable of draining a configurable portion of cryptocurrency balances.
-
Help-desk impersonation targets financial identities
A large social-engineering campaign has targeted financial and corporate organisations using phone calls, fake support processes, and real-time theft of authentication credentials.
-
Claude browser research demonstrates account takeover chains
Zenity researchers used indirect prompt injection against Claude in Chrome to demonstrate cross-service account takeover paths through authenticated browser sessions.
-
Oracle database becomes attacker execution layer
Huntress found attackers using SQL injection to place a post-exploitation toolkit inside an Oracle database and reach operating-system command execution on the underlying Windows server.
-
AI alliance proposes shared incident exchange
The Open Secure AI Alliance has proposed a confidential framework for sharing AI security incidents and near misses, extending industry collaboration into operational failure data.
-
Atlas research exposes cross-session agent risk
Zenity researchers manipulated ChatGPT Atlas through hostile web content, demonstrating unauthorised actions across authenticated services before the browser’s scheduled retirement on 9 August.
-
Critical Jenkins flaw crosses agent-controller boundary
A critical Jenkins vulnerability can allow a compromised agent or suitably privileged user to bypass a deserialisation safeguard and potentially execute code on the higher-trust controller.
-
Snowflake hacking case reaches guilty plea
Connor Moucka has pleaded guilty over a campaign that compromised more than 165 organisations, giving the Snowflake customer-account attacks a new accountability chapter.
-
N-able orders second N-central hotfix
N-able has issued a second mandatory N-central hotfix as it responds to evolving attacker techniques after exploitation reached systems inside managed customer environments.
-
ICO orders Met to improve data governance
The ICO has ordered the Metropolitan Police to improve training, monitoring, and governance after sensitive disclosures exposed weaknesses in both human handling and technical safeguards.





