5 critical threats detected in the last 24 hours. Active threat actors: ShinyHunters, Conti, Qilin. Immediate review of affected systems recommended.
Critical
NVD CRITICAL: CVE-2026-106037 — Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in...
How to secure RMM software: 8 controls MSPs should test
Critical Medical Devices Unable to Support PQC Transition
Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers
Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems
Alleged ATM malware creator appears in Nebraska court after arrest
Aguirre was added to the FBI’s “Top 10 Most Wanted Fugitives” list in March, becoming the first cybercriminal added to the list.
South Korean officials believe AI agents were used to hack several banks
The personal data of at least 68,000 people was reportedly exposed in breaches of at least seven financial institutions, with officials saying they believe a Chinese cybersecurity tool was used to hack the banks’ systems.
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
Eduard Kovacs reports: The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees, Reuters reported on Tuesday, citing two people familiar with the matter. The FBI has not publicly named the contractor or the organization involved. However, a senior bureau official told Reuters that its... Source
Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]
ClickFix Attack Hides VBScript Payload in Browser Cache
ClickFix sites stage a VBScript payload in the browser cache to bypass the Run dialog's length limit
UK picks banks as lead managers for digital gilt pilot
The UK government has selected six banks as joint lead managers for the Digital Gilt Instrument (Digit) pilot issuance.
Osaka Metropolitan University cancels classes after suspected ransomware attack
Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.
NVD CRITICAL: CVE-2026-106037 — Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in...
Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put, /api/remove_all and /api/mount to read cached KV data with user prompts, inject or delete objects, and mount attacker-described segments.
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees. The post FBI Blames Contractor’s Missed Patch for ShinyHunters Breach appeared first on SecurityWeek .
Securing Agent-to-Agent Communication: The Next Identity Frontier
As organizations deploy autonomous AI agents, security teams face a significant shift as non-human non-human entities making decisions, invoking tools, and delegating tasks to other agents without human intervention. Security architectures built around human users, static APIs, and distinct endpoints break down when AI agents dynamically collaborate across an environment. As these interactions bec
Gatehouse Bank backs youth homeless charity via new saver account
Gatehouse Bank has today launched a one-year fixed term Community Saver Account in support of the Bank’s charity partner, Depaul UK, a youth homelessness charity.
How to secure RMM software: 8 controls MSPs should test
RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery and tenant isolation. [...]
Nikkei Discloses Two Employee Cloud Account Compromises
Nikkei says two employee cloud accounts were accessed, with one used to send 9,000 phishing emails
Live Activity
Threat Alerts
Real-time alerts for the threats that matter to you. Choose your severity levels and threat categories.