Cybersecurity

OpenClaw AI Assistant Patched for Critical 1-Click RCE Flaw

A critical flaw in the popular AI assistant OpenClaw allows attackers to execute remote code via a single malicious link.The vulnerability, patched on January...

GlassWorm Malware Hits Open VSX via Developer Hack

Threat actors compromised a legitimate developer's account on the Open VSX Registry to publish malicious versions of four extensions.The poisoned extensions delivered the GlassWorm...

ShinyHunters Expand Saas Attacks with Vishing Campaign

Google's Mandiant reported a surge in advanced voice phishing attacks by the ShinyHunters group, targeting SaaS applications for data theft and extortion on January...

Ex-Google Engineer Found Guilty of AI Trade Theft

Former Google engineer Linwei Ding convicted on multiple counts of economic espionage and theft of trade secrets.He stole over 2,000 confidential documents related to...

Unsecured AI Ollama Hosts Found Exposed Online

Security researchers identified approximately 175,000 publicly accessible Ollama AI hosts across 130 countries, most with high-risk capabilities.Nearly half of these exposed systems support tool-calling,...

Critical SolarWinds Web Help Desk Vulnerabilities Patched

SolarWinds released security updates for its Web Help Desk software to address six severe vulnerabilities, four of which are critical with CVSS scores of...

Cybercriminals Use Grok AI to Bypass X’s Malvertising Protections

Cybercriminals are using a new strategy to get around ad protections on X (formerly Twitter) by leveraging its AI assistant, Grok. The method,...

AI-Powered “FraudOnTok” Scam Targets TikTok Shop Users Worldwide

The scam, called "FraudOnTok," uses fake TikTok Shop sites and AI-generated videos to steal credentials and distribute malware. Researchers found over 15,000 lookalike...

Latest news

Kelp DAO Attacker Starts Laundering Stolen $175M in Ether

The attacker behind the $290 million Kelp DAO exploit has begun moving stolen funds, transferring ~$175M in ETH to...

CISA Adds Eight Exploited Vulnerabilities to KEV Catalog

The U.S. cybersecurity agency has flagged eight new software flaws being actively exploited by attackers.Three of the vulnerabilities impact...

Arbitrum Freezes $71 Million from Kelp DAO Hack

The Arbitrum Security Council froze $71 million in stolen funds from the Kelp DAO hack.The move is controversial as...