OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes

05/08/2026 0 Comments 0 tags

OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

05/08/2026 0 Comments 0 tags

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

05/08/2026 0 Comments 0 tags

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer’s computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI)

Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt

05/08/2026 0 Comments 0 tags

Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude, claims

Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses

05/08/2026 0 Comments 0 tags

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

05/08/2026 0 Comments 0 tags

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam’s

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

05/08/2026 0 Comments 0 tags

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft’s real authentication

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

05/08/2026 0 Comments 0 tags

A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

05/08/2026 0 Comments 0 tags

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

05/08/2026 0 Comments 0 tags

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without