Autonomous AI agents are driving an ongoing campaign against hundreds of online retailers, compromising at least 27 firms and stealing 600k+ card records.
Attackers began targeting critical WordPress core flaw CVE-2026-87902 within hours of disclosure, enabling unauthenticated local file inclusion and possible RCE on vulnerable sites worldwide.
Extortion gang ShinyHunters claims it hacked the FBI's jobs portal, stole data on thousands of agents and applicants, and demands a cyber warning be retracted.
Microsoft and UK police dismantled the EvilTokens device-code phishing service, seizing infrastructure and arresting suspects after thousands of Microsoft 365 accounts were hijacked.
CTF.ae’s XRanges for AI scores autonomous security agents against realistic apps using live telemetry, answering what the agent actually did, not just claimed.
New Forescout research finds OT, IoMT and IP cameras rarely live on isolated segments, expanding lateral movement paths and breach blast radius for enterprises.
OpenAI’s GPT-6 Astra autonomously decrypts a once-unsolved 1941 Wehrmacht Enigma radio message, highlighting emerging AI capabilities in cryptanalysis.
Unit 42's Continuous Frontier AI Defense offers AI-driven offensive security to continuously test enterprise environments, validate exposures and speed remediation.
Extortion gang ShinyHunters hijacks rival Clop’s Tor leak site via a Grav CMS file upload flaw, exposing how shared web app bugs can destabilize cybercrime.