← Latest brief

Security news.

·Morning Brief

Today's security landscape is heavily influenced by AI, with both defenders and attackers leveraging its capabilities. Critical vulnerabilities in widely used software are also under active exploitation, highlighting the ongoing need for diligent patching and robust defensive strategies.

SECURITYWEEKVULN
Aug 31READ

Critical Ruby on Rails Vulnerability Under Attack

A critical arbitrary file read flaw, named KindaRails2Shell, in Ruby on Rails allows attackers to extract secrets and execute arbitrary code remotely.

THNBREACH
Aug 31READ

China-Linked Fire Ant Hijacks Cisco Routers

The China-nexus cyber espionage group Fire Ant is expanding its campaign to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts, in addition to VMware hypervisors, to steal credentials and blind security logs.

SECURITYWEEKMALWARE
Aug 31READ

Anthropic Warns Claude Users of Infostealer Malware

AI company Anthropic is warning some Claude users that infostealer malware is hijacking active Claude login sessions, allowing attackers to access accounts and consume usage.

THNRANSOMWARE
Aug 31READ

Aurora Ransomware Uses Cursor AI for Attacks

Operators of the Aurora (aka Aur0ra) ransomware have been observed leveraging SpaceX's AI-powered coding assistant, Cursor, to breach target networks in at least 10 attacks.

THNMALWARE
Aug 31READ

ValleyRAT Backdoor Hides in Signed Adware

The Silver Fox threat actor is distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, QN Wallpaper, running the malware under a trusted process after users add it to antivirus exclusions.

SECURITYWEEKBREACH
Aug 31READ

Extortion Group Claims Manchester Airports Group Data Breach

The FulcrumSec extortion group claims to have stolen over 80 GB of data, including customer, booking, and travel information, from Manchester Airports Group and threatens to leak it online.

SECURITYWEEK
Aug 31READ

Boston Scientific Still Recovering From Cyberattack

Boston Scientific is still recovering from a cyberattack that caused global network disruption, with CrowdStrike and other firms investigating the incident.

UNIT 42PHISHING
Aug 31READ

Spring Ring Voice Phishing Campaigns Target Microsoft Teams

The Spring Ring campaign is actively abusing Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers for credential theft and further compromise.

Generated twice daily from public security RSS feeds. Informational only.