Copy-paste vulnerability hits AI inference frameworks at Meta, Nvidia, and Microsoft

Why this matters for AI infrastructure The vulnerable inference servers form the backbone of many enterprise-grade…

Fighting AI with AI: Adversarial bots vs. autonomous threat hunters

I recently gave a presentation at SecTor on proactive threat hunting, which sparked some meaty conversations…

North Korea’s ‘Job Test’ trap upgrades to JSON malware dropboxes

The final payload (BeaverTail) showed previously seen capabilities, including “usage of Axioms as embedded HTTP client,…

EU-Kommission will DSGVO für KI und Cookie-Tracking lockern

Schutz sensibler Daten eingeschränkt Eine weitere umstrittene Änderung des Vorschlags wäre die Einschränkung der Definition sensibler…

Maverick: a new banking trojan abusing WhatsApp in a massive scale distribution

A malware campaign was recently detected in Brazil, distributing a malicious LNK file using WhatsApp. It…

Hidden links: why your website traffic is declining

When analyzing the content of websites in an attempt to determine what category it belongs to,…

Malicious package with AdaptixC2 framework agent found in npm registry

Incident description The first version of the AdaptixC2 post-exploitation framework, which can be considered an alternative…

Cyberespionage campaign PassiveNeuron targets machines running Windows Server

Introduction Back in 2024, we gave a brief description of a complex cyberespionage campaign that we…

Notable email phishing techniques in 2025

Introduction Cyberthreats are constantly evolving, and email phishing is no exception. Threat actors keep coming up…

The BetterBank DeFi protocol exploited for reward minting

Executive summary From August 26 to 27, 2025, BetterBank, a decentralized finance (DeFi) protocol operating on…