The FBI received over 1 million complaints of malicious activity in 2025, with investment, BEC, and tech support scams causing the highest losses.
Hi, what are you looking for?
The FBI received over 1 million complaints of malicious activity in 2025, with investment, BEC, and tech support scams causing the highest losses.
Focused on persistence, the botnet does not engage in widespread infection and avoids blacklisted IPs and critical infrastructure entities.
The vulnerability allows hackers to upload arbitrary files to a site’s server and achieve remote code execution.
The startup has created a layered security solution aiming to secure AI agents throughout their entire lifecycle.
The improper validation of user-supplied JavaScript code allows attackers to execute arbitrary code and access the file system.
By targeting Grafana’s AI components, attackers can point to external resources and inject indirect prompts to bypass safeguards.
The group is using zero-days, quickly weaponizes fresh bugs, and exfiltrates and encrypts data within days of initial access.
Shchukin is accused of extorting more than $2 million as the head of the GandCrab and REvil ransomware operations.
A vulnerability named ‘AI Agent Traps’ allows attackers to manipulate, deceive, and exploit visiting agents via malicious web content.
Hackers published 36 NPM packages posing as Strapi plugins to execute shells, escape containers, and harvest credentials.
The threat actor behind the Axios supply chain attack has been aiming at other maintainers in its social engineering campaign.
The improper access control bug in FortiClient EMS allows unauthenticated attackers to execute arbitrary code remotely.
Hackers stole over 300GB of data from the Commission’s AWS environment, including personal information.
A Chinese threat actor exploited the video conferencing platform to perform reconnaissance, escalate privileges, and execute additional payloads.
The vulnerabilities can be chained together to bypass authentication and upload arbitrary files to the server.
Using automated scanning and the Nexus Listener collection framework, the hackers compromised over 750 systems.
The attackers prepared infrastructure and multiple nonce-based transactions, took over an admin key, and drained five vaults.
The bugs could lead to authentication bypass, remote code execution, information disclosure, and privilege escalation.
In January 2026, a threat actor hacked the hospital’s internal network and stole personal and health information.
The AI recruiting firm is investigating the incident as Lapsus$ claimed the theft of 4TB of Mercor data.