AgentForger: The New Corporate Mole
A now-patched flaw in OpenAI's platform allowed attackers to deploy autonomous, malicious agents via a single malicious link.
Data breaches, ransomware payouts, and phishing operations rarely make the news until the damage is already done. This is where Xploitwire tracks the attackers — who they are, how they got in, and what it means for the organizations and people caught in the blast radius.
A now-patched flaw in OpenAI's platform allowed attackers to deploy autonomous, malicious agents via a single malicious link.
A red teamer exploited human behavior to gain unauthorized access to a hospital records room, highlighting significant security gaps.
A critical vulnerability in Oracle E-Business Suite led to the exposure of personal data at the global cosmetics firm.
Researchers uncovered an exposed server revealing how attackers use AI to industrialize the creation of malware delivery campaigns.
A sophisticated crypter service is leveraging process ghosting and kernel-driver abuse to cloak various commodity malware strains.
A cyberattack on the billing software provider has resulted in the theft of employee, customer, and partner records.
An autonomous AI agent framework successfully breached internal Hugging Face infrastructure, marking a shift in attacker tactics.
Intelligence agencies report that Russian actors are hijacking IP cameras to monitor military movements across Europe and Ukraine.
A third-party platform compromise has led to the unauthorized access of client tax documents at Ernst & Young.
A rivalry between major threat actors is escalating, with data showing a surge in attacks targeting small businesses and large enterprises.
A newly identified malware sample, HollowGraph, is utilizing Microsoft 365 calendar events as a covert command and control channel.
A third-party IT management tool used by Ernst & Young was compromised, leading to the unauthorized exfiltration of tax documents.
A threat actor used Google Gemini CLI to automate botnet management and infrastructure migration, bypassing traditional defenses.
Law enforcement officials are advocating for Cybercrime Risk Orders following the sentencing of two Scattered Spider hackers.
Third-party AI integrations evolve too quickly for traditional security models, exposing enterprise data to unforeseen downstream risks.
Time is running out for victims of the 2024 Fidelity data breach to claim their share of a $2.5 million settlement fund.
A sophisticated malware-as-a-service campaign is leveraging social engineering and WebDAV to compromise enterprise environments.
The city of San Francisco has issued a demand for Apple and Google to remove AI-powered apps capable of generating non-consensual deepfake imagery.
Abbott is currently evaluating the security impact of two distinct unauthorized access claims within its diagnostic and lab portal divisions.
A Chinese sub-group's infiltration of DigiCert reveals how stolen code-signing certificates are weaponized against the industry.