Aurora Used Cursor to Turn Ransomware Into a Repeatable Playbook

Recovered Cursor logs show an Aurora ransomware affiliate using Claude against live victim networks while a skilled human controlled the intrusion.
Vulnerabilities, defensive security, architecture and operational security.

Recovered Cursor logs show an Aurora ransomware affiliate using Claude against live victim networks while a skilled human controlled the intrusion.

CISA has added a seven-year-old Microsoft SQL Server vulnerability to its exploited list, turning forgotten database instances into an urgent incident-response problem.

A Lenovo email-verification flaw opened about 5,000 Dropbox accounts through passwordless sign-in. The incident exposes the risk of weak identity binding.

Separate social-engineering breaches at Quinn Emanuel and McDermott show how one compromised identity can expose exceptionally sensitive legal records.

Attackers diverted Coder's trusted Terraform registry to malicious modules that searched provisioners for cloud keys, tokens, SSH credentials and secrets.

Firefox 155 is not a routine browser refresh. Mozilla’s security bulletin lists 29 CVEs, including two high-impact use-after-free vulnerabilities that it explicitly describes as sandbox escapes. The release also fixes several privilege-escalation paths, multiple additional use-after-free bugs, an Android extension…

Two VMware Workstation and Fusion flaws can let an administrator inside a virtual machine execute code on the host. Versions 25H2 and 26H1 need 26H1u1.

A passwordless Proxmox VE authentication bypass was fixed in 2023 but disclosed three years later, leaving exposed end-of-life control planes at urgent risk.

CISA says attackers are exploiting a Switchvox SQL injection that turns one unauthenticated web request into operating-system command execution.

Jenkins shipped fixes for 33 CVEs, including paths to the Script Console, controller code execution, credential abuse and arbitrary file access.