Google Warns on AI Coding Tool Threats
Google Threat Intelligence Group warns AI coding tools are prime targets for supply chain attacks.
30 results for “threat actors”
Google Threat Intelligence Group warns AI coding tools are prime targets for supply chain attacks.
Threat actors are hijacking the trusted Node.js runtime to deliver malware, evading detection in targeted attacks since early 2026.
Threat actors compromised over 270 Zimbra instances in ongoing RCE attacks, prompting CISA to order urgent patching.
Threat actors are exploiting a critical SharePoint authentication bypass after Rapid7 released a PoC exploit.
Threat actors are bypassing standard enterprise security by using vishing attacks to compromise personal mobile devices.
A new report identifies a strategic shift among threat actors, moving away from simple malware toward identity and trust-based exploits.
Threat actors are breaking malicious projects into small, fragmented tasks to circumvent AI safety guardrails, according to research.
Threat actors are actively chaining two critical SonicWall vulnerabilities to deploy ransomware and escalate privileges to root.
Threat actors are hijacking hotel network gateways to push fraudulent software updates and capture user credentials via deceptive portals.
Threat actors are exploiting technical support discussions on Steam to trick gamers into executing malicious PowerShell cryptominers.
North Korean threat actors are leveraging AI-driven lures and Telegram account hijacks to target cryptocurrency and finance professionals.
Threat actors are repurposing publicly leaked data to launch targeted sextortion campaigns demanding Bitcoin payments from breach victims.
Threat actors are increasingly leveraging vulnerabilities in VPNs and firewalls to gain direct access to corporate networks.
New research details how threat actors are ditching delayed credential harvesting for live, session-based account hijacking.
Threat actors are exploiting a severe vulnerability in PTC Windchill and FlexPLM to exfiltrate sensitive enterprise product data.
A newly uncovered intrusion suggests threat actors are leveraging autonomous AI tools to streamline lateral movement and enumeration.
A rivalry between major threat actors is escalating, with data showing a surge in attacks targeting small businesses and large enterprises.
Threat actors are weaponizing legitimate security software updates to infiltrate high-value government and private sector networks.
North Korean threat actors are using fake coding tests and steganography to compromise developer systems and steal sensitive data.
Threat actors are weaponizing fake TrueType Font files to slip low-detection malware past traditional Windows endpoint defenses.
Threat actors are weaponizing OAuth client ID spoofing to validate stolen credentials while remaining invisible to standard telemetry.
Microsoft details how threat actors bypassed traditional defenses to compromise Salesforce environments via OAuth and guest access.
Joint sanctions targeting military intelligence and private threat actors aim to disrupt an expansive Russian ecosystem of digital aggression.
Threat actors are weaponizing reservation-themed emails with container files to bypass modern Microsoft Office security protections.
Threat actors are weaponizing years-old accounts to map organizational structures and probe sensitive repositories via the GitHub API.
Thousands of Hikvision devices remain vulnerable to a critical command injection flaw, drawing attention from global threat actors.
After a brief period of decline, ransomware activity has spiked as the dissolution of the Conti group fuels a new wave of attacks.
A stealthy new attack technique is bypassing traditional security logs, allowing threat actors to compromise cloud-based infrastructure.
A single exposed directory reveals how multiple threat actors leverage AiTM tools and OAuth abuse to compromise corporate accounts.
Threat actors are leveraging AI to refine and accelerate traditional attack chains, lowering the barrier to entry for complex operations.