News

CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Russian-speaking Aurora ransomware group leveraged Cursor AI coding assistant to conduct hands-on exploitation against 10 targets between April and May 2026.
Application Security
Five Critical WordPress Flaws Enable Site Takeover and RCE
Five critical vulnerabilities in WPMU DEV Dashboard, Avada Theme, TranslatePress, Pods, and GiveWP allow authentication bypass, privilege escalation, and RCE.
Application Security
Anthropic Warns Infostealer Malware Hijacking Claude Sessions
Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits fraudulently.
Cybersecurity
Boston Scientific Cyberattack Disrupts Manufacturing and Shipping
August 25 cyberattack hit Boston Scientific's on-premises IT, disrupting manufacturing, order processing, and some cardiac monitor remote activations.
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
FulcrumSec claims theft of 86 gigabytes from Manchester Airports Group, exposing booking data for 8.7 million customers from a third-party database breach.
Application Security
PaperCut Zero-Days Under Active Exploit Despite Two Patches
CVE-2026-81578 and CVE-2026-82078 allow unauthenticated RCE on PaperCut NG/MF versions 24-26; WatchTowr found patch bypasses forcing second emergency patch.
Application Security
McKesson Breach: ShinyHunters Demands $55M for 284M Records
ShinyHunters demands $55 million for 284 million McKesson records containing PHI, prescriptions, and billing data; threatens release by September 1.
Cybersecurity
Slovenian Casino Operator Hit Resumes After Three-Day Shutdown
Hit casino operator reopened six Slovenian and Bosnian casinos after a three-day cyberattack shutdown, with gaming functions and loyalty systems still offline.
Application Security
Hasbro Data Breach Exposed 436+ Employee Records
Hasbro disclosed breach affecting 436+ Massachusetts employees, exposing names, national IDs, and financial data, tied to late March cyberattack.
Cybersecurity
Berlin Refuses Rhysida Ransom as Group Claims 5.7TB Data Theft
Rhysida ransomware group demanded 30 bitcoin for 5.7 terabytes of Berlin state data, but Governing Mayor Kai Wegner flatly refused to negotiate or pay.