Research
-
Microsoft details AutoJack flaw that could let a web page trigger code on AI agent hosts
Microsoft said a flaw in AutoGen Studio could let a single web page trigger code execution on the host running an AI browsing agent. The issue affects two pre-release PyPI builds, while the stable release is not exposed.
-
Apple patches Beats Studio Buds flaw that could let nearby attackers eavesdrop
Apple has patched a high-severity Beats Studio Buds Bluetooth flaw that could let nearby attackers eavesdrop through the microphone. The advisory says the fix is in Beats Firmware Update 1B211 and requires no user interaction.
-
USB worm spreads crypto-stealing malware through Windows shortcut files
A USB worm has been spreading clipboard-stealing malware that targets cryptocurrency wallets through Windows shortcut files, with activity tracked since at least February and communications hidden over Tor.
-
INC ransomware claims 830 victims since 2023, researchers say
INC ransomware has emerged as one of 2026’s most active cybercrime groups, with researchers linking it to 830 victims since 2023 and more than 120 incidents in the first quarter of this year.
-
DragonForce hackers used Microsoft Teams relay to hide command traffic, researchers say
DragonForce-linked attackers used a custom backdoor to hide command traffic inside Microsoft Teams relay infrastructure during a months-long intrusion at a major U.S. services firm, researchers said.
-
Fake reputation campaign pushes crypto clipper through GitHub, YouTube and news sites
A campaign used fake reputation signals across GitHub, SourceForge, YouTube and news sites to promote a crypto clipboard hijacker, according to a technical analysis from Check Point Research. The malware replaced copied wallet addresses with attacker-controlled ones.
-
Researchers say attacker used Tailscale and SSH to keep access after C2 outage
A technical analysis by Cato Networks says an attacker kept access to a French automotive business after a C2 outage by installing OpenSSH and Tailscale on a victim machine and using a separate access path.
-
144 Mastra npm packages hit by supply chain attack
A supply chain attack compromised 144 npm packages in the Mastra namespace in June 2026, with a malicious dependency used to drop payloads that could steal wallet data, browser information and credentials.
-
Malicious JetBrains plugins stole AI provider keys, researchers say
Researchers say 15 JetBrains Marketplace plugins posed as AI assistants while stealing user API keys for services such as OpenAI and DeepSeek. The campaign has run since October 2025 and included two plugins with more than 25,000 downloads each.
-
Google Vertex AI SDK flaw let attackers hijack model uploads and run code
A flaw in Google’s Vertex AI SDK for Python let attackers hijack model uploads through a predictable bucket name and run code in Google’s serving environment. Google patched the issue, and researchers said they saw no exploitation in the wild.










