A newly discovered Android trojan relies on generative AI to more intelligently navigate and control the infected devices, mobile security company Zimperium reports. Dubbed RatHat, the malware has been distributed through smishing and malvertising, relying on an automated multi-stage infection… Read More "RatHat Android Trojan Uses AI for Automation"
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
The ShinyHunters hacking and extortion gang has claimed a cyber-attack against a fellow cybercriminal outfit, the Clop ransomware group. The incident, which came to light on the evening of 18 September, saw Clop’s dark web data leak site defaced with… Read More "ShinyHunters Claim Hack of Rival Ransomware Gang Clop"
Your First Dark Web Scan Report, Explained
Most people don’t hesitate to run a free security scan because they doubt it’ll find anything. They hesitate because they don’t know what the results will look like. Will it be 40 pages of raw data without context? A sales… Read More "Your First Dark Web Scan Report, Explained"
Outsider Phishing Kit Survives Takedown With 700 New Pages
A phishing-as-a-service (PaaS) operation has continued generating new campaigns despite a coordinated takedown effort, with more than 700 new phishing pages identified within a month of the disruption. Group-IB said its researchers had tracked the Outsider Phishing Kit, operated by… Read More "Outsider Phishing Kit Survives Takedown With 700 New Pages"
Rust Team Members and Popular Crate Owners Targeted via Video Calls
The Rust project warned last week that an ongoing social engineering campaign is targeting Rust-lang team members and the owners of popular crates to hijack developer credentials and deploy malicious packages. The crates.io team and the security response working group… Read More "Rust Team Members and Popular Crate Owners Targeted via Video Calls"
Pegasus Zero-Click Exploit Infects Serbian Student Activist’s iPhone
A member of Serbia’s student protest movement has been infected with NSO Group’s Pegasus spyware through an iMessage zero-click exploit, according to a forensic investigation by the Citizen Lab and the SHARE Foundation. The Citizen Lab said it found high-confidence… Read More "Pegasus Zero-Click Exploit Infects Serbian Student Activist’s iPhone"
OpenAI Agents Hacked Another Website
After reporting last week that the surveillance company Flock Safety is building an AI search tool for law enforcement, WIRED reconstructed Flock’s latest search tool from code that the company sends to a police officer’s browser and uncovered key details… Read More "OpenAI Agents Hacked Another Website"
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
French cybersecurity firm CrowdSec has confirmed that approximately 300 private and public repositories were compromised and source code was stolen from them. The company provides open source, crowdsourced threat intelligence, including a lightweight security engine to detect and block attacks… Read More "CrowdSec Confirms Source Code Stolen in Supply Chain Attack"
G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules
The G7 is urging nations to accelerate the post-quantum cryptography (PQC) transition. As part of France’s 2026 G7 Presidency, the French National Cybersecurity Agency (ANSSI), chairing the G7 Cybersecurity Working Group, has spearheaded a new call to action urging governments… Read More "G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules"
US and China Discuss Alerting Each Other to AI National Security Threats
Talks have begun between US and Chinese officials to propose a mechanism for the two countries to notify each other of artificial intelligence incidents which could threaten national security. The framework, called the US China AI Dialogue, would also see… Read More "US and China Discuss Alerting Each Other to AI National Security Threats"