Fulcrumsec Claims 2nd Data Dump Exposes Firm's Hugging Face Models, Drug R&D Data Extortion gang Fulcrumsec has leaked on its dark web site a second large cache of data it allegedly stole in a June at…
cyberintel.kalymoon.com · 11164 articles · updated every 4 hours · grows forever
Fulcrumsec Claims 2nd Data Dump Exposes Firm's Hugging Face Models, Drug R&D Data Extortion gang Fulcrumsec has leaked on its dark web site a second large cache of data it allegedly stole in a June at…
Also, LiteLLM Attack Exposed 430,000 Pipelines, Ukrainian IT Workers Targeted This week: An evil twin attack on a Delta flight, the LiteLLM attack exposed 430,000 pipelines, Russian hackers targeted U…
Resilience Data Shows Social Engineering Dominates Over AI-Native Losses AI is amplifying familiar attacks rather than creating new categories of loss. Resilience's Jud Dressler explains why social en…
CEO: Funding Will Expand Exploit Blocking Across Cloud-Native and Agentic Apps Startup Oligo raised $60 million to expand runtime exploit blocking to agentic AI, tracing activity from prompts and tool…
Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing g…
Exploitation against CVE-2026–59310 began earlier this month, and patching the vulnerability may not be enough to fully mitigate the threat.
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts. [...]
Also: CTFC-led $48M Fraud Case, NFT Founder Charged in $10M Scam This week, Harmony and BTCPay hacked, violent crypto thefts surged, the U.S. CFTC filed a $48 million fraud case, an NFT founder charge…
A newly identified macOS infostealer called AmnesiaStealer is spreading via a convincing fake GitHub download page, tricking Mac users into pasting a malicious Terminal command that silently installs …
Beacon, the customer relationship management (CRM) platform relied on by over a thousand UK charities and non-profit organizations, has confirmed that a threat actor made a complete copy of and exfilt…
Fortinet has rolled out fixes for a batch of authentication-related vulnerabilities across its FortiWeb, FortiManager, and FortiClient product lines, urging administrators to patch quickly given the s…
A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...…
Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasio…
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]
White House Program Will Tap Private Sector for Surveillance and Cyber Operations The White House, in a major expansion of how it works with the private sector, has launched a program to engage privat…
Thousands of internet-exposed building controllers may be putting the physical backbone of U.S. data centers at risk. They manage cooling, electrical distribution, and environmental conditions. If an …