WordPress Template Flaw Enters KEV as Attacks Reach File Writes
CISA lists the exploited WordPress template flaw. Learn why theme and PHP…
Kiteworks Calls for a Nine-Hour Pause After Threat Warning
Kiteworks requested a nine-hour shutdown without reporting a breach. Who handles the…
AWS Quarantined a Leaked Key in 10 Seconds. The Response Wasn’t Over.
Unit 42 measured AWS quarantining a public GitHub key leak in 10…
AgentCore Harness Test Exposes a Service Token Through Memory
Unit 42 demonstrated AgentCore credential theft through a support ticket. See why…
LeakySensey Rents Out Hacked Routers as a Proxy Network
LeakySensey turned weak VPN logins into rented proxies. What the exposed server…
Settra Ransomware Leaves a Defender Log Intact After a Typo
Huntress found that Settra misspelled a Defender event-log name. What survived, how…
AI Access Thief Sends 43 KB of Agent Context to a Honeypot
An attacker’s coding agent exposed instructions, keys and history to a research…
Claude Code Auto Mode: Check What an Approved Command Can Reach
A controlled Opus 5 test turned a website summary into code execution.…
AI-Assisted Intrusion: Stolen Cloud Keys Outlive a Blocked Change
Unit 42 corrected its account to an intrusion. Review stolen credentials and…
ASCII Smuggling Phishing: What to Do With a Funding Email
Invisible characters can hide financial lure words from simple filters. Verify the…
ReliaQuest Phishing: MFA Approved, Application Access Blocked
ReliaQuest says device trust blocked applications after a password and MFA approval…
MikroTrick RouterOS Attacks: Patch and Check Your Router
MikroTrick attacks chain two RouterOS flaws against routers with public SSH. Check…
