Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

19/08/2026 0 Comments 0 tags

A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

19/08/2026 0 Comments 0 tags

Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

18/08/2026 0 Comments 0 tags

A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups’ servers in exchange for a

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

18/08/2026 0 Comments 0 tags

Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

18/08/2026 0 Comments 0 tags

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

18/08/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT. “TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted

AI “Mind Viruses” Can Spread Between Agents Through Persistent Prompt Files

18/08/2026 0 Comments 0 tags

Security researchers at Anthropic and Switzerland’s EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

18/08/2026 0 Comments 0 tags

A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

18/08/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

18/08/2026 0 Comments 0 tags

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers. The hardware wallet