Researchers Expose Flying Eagle Criminal Ecosystem Behind Fake Chinese Police App

Researchers linked the Flying Eagle Android RAT to fake police apps, uncovering 170 servers in a growing cybercrime ecosystem. Hunt.io researchers and independent journalist NetAskari started with a fraudulent... Read more »

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write access to databases across customer... Read more »

Why brand impersonation is becoming an initial access vector

Brand impersonation now drives initial access, using fake sites and apps to deliver malware, making rapid takedowns essential to disrupt attacks. Attackers recently poisoned more than 700 websites, including... Read more »

Google Plans Global Rollout of Privacy-Focused Age Signals API

Google plans to expand its Play Age Signals API globally, helping Android developers tailor app experiences without collecting exact birth dates. The post Google Plans Global Rollout of Privacy-Focused... Read more »

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264... Read more »

Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents

Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders. Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike,... Read more »

GitHub Automatically Holds Suspicious Actions Runs, but Repository Owners Must Approve Them

GitHub’s new Actions safeguard pauses potentially malicious workflow runs before execution, leaving repository owners to decide who can approve them and what checks must come first. The post GitHub... Read more »

Hugging Face Deepfake Tests Raise New Risks for AI Procurement

Researchers found that seven of nine tested Hugging Face image-editing tools produced sexualized alterations, highlighting gaps in model oversight, provenance, and enterprise vendor controls. The post Hugging Face Deepfake... Read more »

Analog Devices Discloses Data Breach After Unauthorized System Access

Chipmaker Analog Devices disclosed a data breach after detecting unauthorized access to systems on June 23. The investigation is ongoing. Semiconductor giant Analog Devices (ADI) disclosed a data breach... Read more »

Amazon pins multiple open source compromises on North Korea

Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 incident affecting the axios NPN library. Read more »
Subscribe to our Newsletter