Security news.
Today's security landscape is heavily influenced by AI, with both defenders and attackers leveraging its capabilities. Critical vulnerabilities in widely used software are also under active exploitation, highlighting the ongoing need for diligent patching and robust defensive strategies.
Critical Ruby on Rails Vulnerability Under Attack
A critical arbitrary file read flaw, named KindaRails2Shell, in Ruby on Rails allows attackers to extract secrets and execute arbitrary code remotely.
China-Linked Fire Ant Hijacks Cisco Routers
The China-nexus cyber espionage group Fire Ant is expanding its campaign to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts, in addition to VMware hypervisors, to steal credentials and blind security logs.
Anthropic Warns Claude Users of Infostealer Malware
AI company Anthropic is warning some Claude users that infostealer malware is hijacking active Claude login sessions, allowing attackers to access accounts and consume usage.
Aurora Ransomware Uses Cursor AI for Attacks
Operators of the Aurora (aka Aur0ra) ransomware have been observed leveraging SpaceX's AI-powered coding assistant, Cursor, to breach target networks in at least 10 attacks.
ValleyRAT Backdoor Hides in Signed Adware
The Silver Fox threat actor is distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, QN Wallpaper, running the malware under a trusted process after users add it to antivirus exclusions.
Extortion Group Claims Manchester Airports Group Data Breach
The FulcrumSec extortion group claims to have stolen over 80 GB of data, including customer, booking, and travel information, from Manchester Airports Group and threatens to leak it online.
Boston Scientific Still Recovering From Cyberattack
Boston Scientific is still recovering from a cyberattack that caused global network disruption, with CrowdStrike and other firms investigating the incident.
Spring Ring Voice Phishing Campaigns Target Microsoft Teams
The Spring Ring campaign is actively abusing Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers for credential theft and further compromise.