Microsoft Traces Four Ransomware Brands to One Repeating Playbook

The payload name changed across Qilin, DragonForce, Anubis and BERT deployments, but the operator kept returning to the same remote-access and exfiltration tools.

The payload name changed across Qilin, DragonForce, Anubis and BERT deployments, but the operator kept returning to the same remote-access and exfiltration tools.

A malicious CRM lead could cross into Agentforce and emerge as a trusted Slack reply without showing who triggered it. Salesforce has changed the defaults.

A MacSync downloader feeds a public iCloud calendar into zsh until it reaches commands hidden in the event description.

The AI agent is not the entry point. An unauthenticated Docker API is, and Carbonato turns it into privileged host access and automated post-compromise work.

SolarWinds patched two remote-code paths in its monitoring platform, but each depends on a specific non-default or communication configuration.

An incoming GitLab email address carries account authority. Research shows why a leaked address needs the same response as a leaked access token.

The enforcement decision is smaller than the breach headline, but its reasoning reaches every supplier handling concentrated public-sector data.

A pre-authentication SQL injection in Roundcube's virtuser_query plugin is now being exploited, four months after fixed versions shipped.

A password change can feed the new secret straight back to the attacker if the malicious authentication provider remains registered.

Bitget says its $388 million breach may have begun in a third-party security product, exposing credentials used to send fraudulent withdrawal commands.