• ClickFix Attack Delivers macOS Crypto Drainer That Steals Wallet Funds

    A new ClickFix campaign targets macOS users with malware that steals cryptocurrency, browser passwords, Apple Keychain data and cached credentials. Huntress discovered the threat while responding to a ClickFix incident. Researchers say the Go-based malware can intercept cryptocurrency transfers and redirect funds before victims approve their transactions. Unlike many wallet-draining tools, this macOS crypto drainer…

  • UNC6671 Linked to Vishing Attacks on Hedge Funds and Private Equity Firms

    A wave of cyberattacks targeting hedge funds, private-equity companies and other financial organisations has been linked to the UNC6671 extortion group. Recent reports said attackers targeted Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel and several private-equity firms. The campaigns reportedly relied on voice phishing, or vishing, to trick employees into giving attackers access…

  • Swiss Government SharePoint Breach Compromises Around 200 Accounts

    Switzerland’s federal IT office says attackers breached its Microsoft SharePoint servers and compromised approximately 200 user accounts. The Federal Office for Information Technology and Telecommunication, known as BIT, detected unusual activity on its SharePoint environment on July 28. After confirming the incident, the agency cut off external internet access, patched suspected vulnerabilities and reset passwords…

  • Meta Says Its AI Model Reached a Third-Party System During Testing

    Meta says one of its advanced AI systems accessed a third-party service during a cybersecurity evaluation, adding to growing concerns about how AI labs test and contain powerful agents. A setup error reportedly gave Muse Spark 1.1 internet access. According to Meta, the model then exploited a security weakness in a third-party service. Irregular, an…

  • New Orleans Will Use AI to Help Triage 911 Calls

    New Orleans will soon use artificial intelligence to help answer and sort 911 calls, as emergency services look for ways to reduce pressure on human operators. The Orleans Parish Communication District plans to introduce an AI-powered emergency call triage system from Carbyne. The technology will assess incoming calls, provide updates on known incidents and direct…

  • Kimi K3 Reportedly Escapes AI Testing Sandbox to Search the Web

    Kimi K3 reportedly escaped a cybersecurity testing sandbox and accessed the internet during an evaluation, raising fresh concerns about the controls used to contain AI agents. The China-based model, developed by Moonshot AI, allegedly found a way out of its restricted environment because of a setup error. Rather than attacking systems, the agent reportedly searched…

  • Germany Urges Website Operators to Publish security.txt Files

    Germany’s federal cybersecurity agency is calling on businesses, public bodies and website administrators to publish a security.txt file on their websites. The Bundesamt für Sicherheit in der Informationstechnik, better known as BSI, says the simple measure can make responsible vulnerability reporting much faster. It also gives organisations less time to react before attackers discover and…

  • ByteDance Reportedly Trains 10 Trillion-Parameter AI Model

    ByteDance is reportedly pre-training a huge new artificial intelligence system with as many as 10 trillion parameters. The project could put the ByteDance AI model among the largest systems developed by a Chinese technology company so far. The Financial Times reported that the company has already started pre-training, citing people familiar with the matter. ByteDance…

  • WebKit IP Leaks Can Expose iOS and macOS Users Behind Private Relay and Tor

    Security researchers have found WebKit IP leaks that can reveal the real network addresses of iOS and macOS users, even when they use browser-level proxies, iCloud Private Relay, or some Tor-based browsers. The findings come from Mysk, a privacy-focused development team that investigated reports of DNS leaks in its Psylo browser. According to the researchers,…

  • Ryde Data Breach Affects 4.5 Million Scooter App Accounts

    Electric scooter company Ryde has confirmed that a data breach has affected all of its customer accounts, or roughly 4.5 million people across Norway and other European markets. The company said an unauthorised party accessed its systems on August 2 and copied customer information before Ryde blocked the intrusion. Ryde operates in Norway, Sweden, Finland,…