Triaging the Week 106

AI in the crosshairs: State-sponsored espionage, cloud worms, and supply chain attacks dominate in triaging the week 106.

AI in the crosshairs: State-sponsored espionage, cloud worms, and supply chain attacks dominate in triaging the week 106.

Supply chain attacks, AI-centric vulnerabilities, abused kernel drivers, and AI assistant marketplaces hit hard in triaging the week 105.

Destructive nation-state attacks, new AI-weaponized malware, critical zero-day vulnerabilities, supply-chain attacks affecting NPM and PyPI, and 175K exposed Ollama AI servers in triaging the week 104.

AI-coded malware, weaponized extensions, social engineering the help desk, and exploiting zero-days across critical infrastructure. All in this week's edition of triaging the week.

Quishing and Browser-in-the-Browser attacks steal credentials, exploitation of LLM services and automation platforms, a massive leak of BreachForums accounts, and urgent patches for Cisco and Fortinet in triaging the week 102.

State-sponsored espionage, active exploitation of critical vulnerabilities in legacy hardware and popular software, and new malware campaigns targeting cloud services and user credentials in triaging the week 101.

State-sponsored espionage using Windows Group Policy, new malware (SantaStealer, PyStoreRAT, DocSwap) distributed through phishing, fake GitHub repos, and compromised app stores in triaging the week 100.

Active exploitation of the critical "React2Shell" vulnerability, malicious VSCode extensions target developers, and urgent security warnings for Fortinet, Ivanti, and Docker Hub users in triaging the week 099.

Critical supply chain vulnerabilities, compromised browser extensions, maximum-severity RCE flaws in React frameworks, and the rise of malicious AI models in triaging the week 098.

WhatsApp metadata exposure affecting 3.5 billion accounts, a critical Grafana admin takeover vulnerability, a foiled insider threat at CrowdStrike, and a third-party breach impacting OpenAI in triaging the week 097.

Automated AI cyberattacks, law enforcement actions against bulletproof hosting services, evolving threats from North Korean hackers, and new supply chain vulnerabilities in triaging the week 096.

Glassworm malware returns, critical container escape flaws in runC, a side-channel attack on encrypted AI chats called 'WhisperLeak', and malicious NuGet packages with "time bomb" payloads in triaging the week 095.

AI-powered malware and autonomous code-fixing agents, state-sponsored attacks, critical vulnerabilities, and sophisticated fraud networks in triaging the week 094.

Sophisticated phishing and ransomware campaigns, critical vulnerabilities in widely used software, and attacks on critical infrastructure make the headlines in triaging the week 093.

Cybercrime makes staggering income, ClickFix attacks and malicious extensions remain prevalent, and AI browsers targeted in traiging the week 092.