Risk
-
Researchers flag Java-based QuimaRAT malware sold as a cross-platform MaaS tool
Researchers have identified QuimaRAT, a Java-based cross-platform remote access trojan sold as malware-as-a-service for Windows, Linux and macOS. The modular toolset includes a builder, loader and dropper, with subscriptions starting at $150 a month.
-
Study says AI coding agent skill scanners can be evaded with simple cloaking tricks
Researchers say scanners for malicious AI coding agent skills can be bypassed with simple cloaking tricks, with one method evading every scanner tested more than 90% of the time. A runtime checker caught most hidden threats in tests.
-
U.S. county linked to $1 million payment in data theft extortion case
A case study linked a $1 million payment to a U.S. government entity after stolen files were threatened with release. The report pointed to Union County, Ohio, and described a data theft extortion scheme with no evidence of encryption.
-
Sysdig says AI agent ran ransomware attack through patched Langflow flaw
Sysdig says an AI agent carried out a ransomware attack from start to finish after exploiting a patched Langflow flaw, stealing credentials and encrypting a production database. The report says the case shows how exposed software and weak defaults can be chained automatically.
-
MeetingTV sues Palo Alto Networks over Koi Security report that linked startup to espionage campaign
MeetingTV has sued Palo Alto Networks and Koi Security over a threat-intelligence blog that linked the startup to Chinese espionage. The company says the report was AI-driven, inaccurate and led to blocks on its domains.
-
Malicious browser extension campaign steals crypto by swapping wallet addresses
McAfee Labs said a June campaign called Silent Swap uses malicious browser extensions to swap cryptocurrency wallet addresses in the clipboard, while a separate Socket disclosure found fake VPN extensions stealing sensitive data.
-
Japan military used infected USB drives linked to China-based hacking in nearly year-long breach
Japan’s Ground Self-Defense Force used counterfeit USB drives infected with malware on sensitive networks for nearly a year after they entered service during earthquake relief work, according to a Nikkei Asia investigation and leaked internal documents.
-
DHS revives critical infrastructure cyber information sharing with new ANCHOR-CI program
DHS is restoring a cyber information sharing forum for critical infrastructure with ANCHOR-CI, a CISA-run council that replaces CIPAC and will be exempt from federal advisory transparency rules.
-
Fake Perplexity Chrome extension tracked searches on Chrome Web Store
A malicious Chrome Web Store extension posing as Perplexity AI intercepted search traffic and collected browsing data, Microsoft said in a technical analysis. The company found no credential theft, but warned the permissions could enable broader abuse.
-
Exploitation attempts target Oracle Payments flaw patched in May
Exploitation attempts have surfaced against CVE-2026-46817 in Oracle Payments, part of Oracle E-Business Suite. The flaw was patched in May, but defenders are being told to check logs and restrict unpatched systems.






