AI Coding Assistant Now a Ransomware Weapon
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
Data breaches, ransomware payouts, and phishing operations rarely make the news until the damage is already done. This is where Xploitwire tracks the attackers — who they are, how they got in, and what it means for the organizations and people caught in the blast radius.
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
Alleged masterminds of TeamPCP, tied to Shai-Hulud worm, arrested in Perth with FBI help.
CRPx0's victim count rose from under 10 to 48 organizations since June, but experts urge caution over unverified claims.
MAG says customer data was stolen from its systems, warning of phishing risks ahead of peak travel.
A single website visit can hijack NemoClaw's local Ollama model server via DNS rebinding, according to new research.
Iran-linked Tortoiseshell adds reverse SSH tunneling and a C++ backdoor, with new infrastructure hinting at wider targeting.
AnonyMousKIT uses AI calls to trick iPhone owners into giving up passcodes.
Treasury targets Iran-linked hackers behind critical infrastructure breaches in 'Operation Economic Outcast'.
Attackers abuse npm mirrors to host HTML phishing pages, bypassing security filters by serving from legitimate domains.
Mirage2FA campaign hit 4,532 companies, bypassing MFA and stealing sessions.
Operation Jackal IV arrests 58, targets Black Axe syndicate across 22 countries over eight months.
Cato Networks found a campaign abusing Google Sites to spread macOS malware through ClickFix tactics.
Cybercriminals are using fake IT helpdesk messages on Microsoft Teams to deliver a new backdoor malware, researchers warn.
Threat actor Doubloon Dredger exploits Notion and device codes to steal authentication tokens, researchers say.
Juan Manuel Gouveia-Aguilera sentenced to 96 months for ATM jackpotting, with DOJ citing $3.5 million in losses.
New Agent Tesla v4 infostealer uses emoji obfuscation to evade detection and target finance departments.
Wiz links a crates.io compromise to Sapphire Sleet, warning of broad developer exposure.
Researchers found 40 malicious Firefox extensions impersonating Web3 products to steal wallet secrets.
New Android malware Manic can exfiltrate data through nearby infected devices using Wi-Fi Direct or Bluetooth.
Researchers find Kriminal AI service routes requests through Grok, Claude, and others via jailbreaks for as little as $12.99 a month.