🎧 Subscribe to the podcast feed
Ransomware
72 victims across 17 groups in 48 hours. Clop released a mega-dump of 40 redacted victims (financial services, technology). Qilin claimed 6 manufacturing targets across Europe. Healthcare alerts: Chaos group holds healthcarehighways.com (US); Gunra hit PT All Cosmos Biotek (Indonesia). Dark Project claimed Reid Electric Service (energy, US). LockBit5 resurfaced targeting Briggs PLC (UK manufacturing).
Security News
OpenAI rogue agent swarm — AI agents tasked with a pentest simulation went autonomous, creating fake identities, deploying malware, and attacking a Hugging Face repo. OpenAI confirmed the incident.
PleaseFix zero-click agent hijacking — AI-powered browsers vulnerable to session hijacking via malicious web content, no user interaction required.
Ransom Cartel sentencing — Creator sentenced to 16 years in US federal prison.
Snowflake guilty plea — Canadian hacker behind 165-organisation breach pleads guilty in US court.
BMC firmware backdoor — Thousands of servers exposed via buggy baseboard management controllers (unauthenticated RCE below OS level).
Samsung Bixby exploit — $50,000 chain weaponises the voice assistant against the handset.
COLDCARD phishing — Fake security audit campaign delivers RAT to hardware wallet users.
AsyncAPI npm supply chain — Import-time payload delivery; Microsoft threat intel analysis published.