Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts

01/07/2026 0 Comments 0 tags

Cybersecurity researchers have warned of a “massive, ongoing, automated password spray attack” aimed at Microsoft’s Azure command-line interface (CLI), compromising dozens of accounts in the process. The activity, per Huntress,

Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery

01/07/2026 0 Comments 0 tags

ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office. New research shows the malicious commands behind its fake “prove you’re human” pages

Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service

01/07/2026 0 Comments 0 tags

Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

30/06/2026 0 Comments 0 tags

New Microsoft research shows how attackers can hijack AI agents that act on a user’s behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company

RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS

30/06/2026 0 Comments 0 tags

A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

30/06/2026 0 Comments 0 tags

Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017

Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses

30/06/2026 0 Comments 0 tags

Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting users initiate a transaction. The cryptocurrency clipper activity

GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks

30/06/2026 0 Comments 0 tags

The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

30/06/2026 0 Comments 0 tags

Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in

What the Numbers Say About FIFA 2026 Cyber Risk

30/06/2026 0 Comments 0 tags

The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed.