A critical vulnerability in the Vault Secrets Operator for Kubernetes, tracked as CVE-2026-8715, allows authenticated users to exfiltrate cluster-wide secrets to external endpoints. This alarming discovery highlights the ongoing fragility of cloud-native infrastructure as organizations continue to
Data exfiltration in this campaign is handled via the FtpWebRequest protocol, with stolen credentials and contact lists sent to a C2 infrastructure hosted at ftp.melrz.com. This specific operational detail highlights the brazen nature of a new wave of Business Email Compromise (BEC) attacks
The rapid transition of artificial intelligence from an experimental curiosity to the foundational architecture of the modern enterprise has created a profound structural mismatch with existing security frameworks. As organizations integrate large language models and autonomous agents into the very
By abusing built-in utilities such as osascript, curl, and Base64, MacSync Stealer effectively blends into standard system activity to avoid detection by traditional signature-based security software. This sophisticated infostealer has evolved significantly by the current year, 2026, marking a
The formation of the Shared AI Findings Exchange aims to establish a unified system for tracking unauthorized system access and sandbox escapes by frontier models. This initiative arrives at a critical juncture following a sophisticated security incident at OpenAI that compromised sensitive
The National Commission on Informatics and Liberty is investigating how stolen administrative credentials led to the mass exposure of sensitive family quotient figures. This significant security incident has sent ripples through the French administrative landscape, specifically targeting the Caisse