Hugging Face Breached by Autonomous AI Agent in First-of-Its-Kind Attack
Hugging Face, the world's largest open-source AI model repository, disclosed a security breach perpetrated by an autonomous AI agent system. The attack…
Hugging Face, the world's largest open-source AI model repository, disclosed a security breach perpetrated by an autonomous AI agent system. The attack…
Hugging Face suffered a multi-day hack by AI agents that exploited zero-days in HDF5 and RefJinja to extract credentials and gain broad…
A previously undocumented threat actor, tracked as UTA0533 by Volexity, exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series…
Cybersecurity researchers at Checkmarx have uncovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…
North Korean threat actors linked to the Contagious Interview campaign have been observed using steganography in SVG image files to conceal malicious…
ACR Stealer, an infostealer active since 2024, is targeting enterprise networks by stealing saved browser passwords, live session tokens, PDFs, Microsoft 365…
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN,…
PhantomEnigma is an active malware campaign that evolved from a browser-extension banker into a modular Inno/Node.js backdoor. It uses compromised Brazilian government…
The macOS Keychain, which stores passwords and credentials, is exfiltrated by ClickLock Stealer after the victim enters their login password.