ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

02/07/2026 0 Comments 0 tags

This week’s security news is mostly about weak spots. Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everything looks normal until someone

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

02/07/2026 0 Comments 0 tags

The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that’s designed to gain surreptitious access to a victim’s email correspondence via the Google API.

Identity Lifecycle Management Wasn’t Built for AI Agents 

02/07/2026 0 Comments 0 tags

Identity lifecycle management was architected around a person with an employment record, a manager, and a departure date. AI agents have none of those. As autonomous principals proliferate across enterprise

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

02/07/2026 0 Comments 0 tags

Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

02/07/2026 0 Comments 0 tags

The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions. “An operator tied to

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

02/07/2026 0 Comments 0 tags

Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

02/07/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

01/07/2026 0 Comments 0 tags

Argo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

01/07/2026 0 Comments 0 tags

A teenager accused of belonging to the hacking group Scattered Spider has been extradited from Finland to face U.S. charges of conspiracy, computer intrusion, and fraud, the U.S. Department of

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

01/07/2026 0 Comments 0 tags

Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT. Kaspersky said the activity is part of a “massive, multi-domain, multi-language” campaign