Endpoint
Vulnerability in Anthropic’s Claude Code Shows Up in Cowork
Jeffrey Burt | | Agentic AI, AI agents, AI models, AI Security, Anthropic AI, Anthropic Cowork, Claude risks, MCP server, prompt injection attacks, PromptArmor
PromptArmor threat researchers uncovered a vulnerability in Anthropic's new Cowork that already was detected in the AI company's Claude Code developer tool, and which allows a threat actor to trick the agent ...
Security Boulevard
Cyber Fraud, Not Ransomware, is Now Businesses’ Top Security Concern
Jeffrey Burt | | AI vulnerabilities, china, cyber fraud, generative AI, geopolitics, Phishing, Ransomware, Russia, World Economic Forum cyber report
In a report a week before its Davos conference, the World Economic Foundation said 64% world business leaders are most worried about cyber fraud, replacing ransomware at their top concern. AI vulnerabilities ...
Security Boulevard
Microsoft, Law Enforcement Disrupt RedVDS Global Cybercrime Service
Jeffrey Burt | | Account Takeover Fraud, BEC attacks, bitsight, cybercrime as a service, Microsoft Threat Intelligence, phishing threats, Ransomware-as-a-Service (RaaS), RedVDS
Microsoft and law enforcement agencies in Europe disrupted the operations of RedVDS, a global cybercrime service that sold cheap and disposable dedicated virtual servers to threat actors that used them to run ...
Security Boulevard
Service Providers Help Pig Butchering Scammers Scale Operations: Infoblox
Jeffrey Burt | | cyberscam compounds, Infoblox, Investment Scams, Malware-as-a-Service (MaaS), Pig Butchering Scams, pig butchering-as-a-service (PBaaS), romance scams, Southeast Asian crime syndicates
Service providers are delivering infrastructure, tools, and expertise and giving rise to pig-butchering-as-a-service models that are enabling the Asian crime syndicates running massive investment and romance scams to through industrial-scale compounds around ...
Security Boulevard
Use of XMRig Cryptominer by Threat Actors Expanding: Expel
Jeffrey Burt | | Amazon Web Services (AWS), cryptominers, Expel, G Data, Kaspersky Labs, Kubernetes, MDR (Managed Detection and Response), Monero, React2Shell Vulnerability, Wiz, XMRig miner
Security researchers last year wrote about a surge in the use by threat actors of the legitimate XMRig cryptominer, and cybersecurity firm Expel is now outlining the widening number of malicious ways ...
Security Boulevard
Owner of Stalkerware Maker pcTattletale Pleads Guilty to Hacking
Jeffrey Burt | | Hacker Guilty Plea, ICE, Kaspersky Labs, MalwareBytes, NSO Group, Paragon Graphite spyware, pcTattletale, Pegasus Spyware, Smartphone Hacking, spyware, Stalkerware
Bryan Fleming, who founded the stalkerware business pcTattletale, pleaded guilty in federal court to hacking and conspiracy charges. Investigators said he crossed the line when he started marketing the software to people ...
Security Boulevard
Quantum Computing Stats, Trends & Future 2026: Crucial Year for Quantum Security
Janki Mehta | | Consulting Services, encryption, Future of Quantum Computing, HTTPS Encryption, Quantum Computing Market, Quantum Computing Stats, Quantum Computing Trends
The encryption protecting billions of dollars, which experts once called unbreakable, no longer works. Hackers don’t need passwords. They don’t brute-force keys. They simply walk through digital vaults that were supposed to ...
Widely Used Malicious Extensions Steal ChatGPT, DeepSeek Conversations
Jeffrey Burt | | AI Models Risk, AI sidebar, Anthropic AI, ChatGPT, Chrome extension malware, DeepSeek AI, google, malicious extensions, Microsoft Copilot, OX Security
Threat actors used two malicious Chrome extensions that have 900,000 users to steal their chats with AI models like ChatGPT and DeepSeek and browser history. The incident is the latest in a ...
Security Boulevard
Surge of OAuth Device Code Phishing Attacks Targets M365 Accounts
Jeffrey Burt | | Account Takeover Attacks, China-linked Hackers, data exfiltration, device authorization, device code phishing, financially motivated groups, Microsoft, Nation-State Bad Actors, russia hacker
Financially motivated and nation-state threat groups are behind a surge in the use of device code phishing attacks that abuse Microsoft's legitimate OAuth 2.0 device authorization grant flow to trick users into ...
Security Boulevard
Google Finds Five China-Nexus Groups Exploiting React2Shell Flaw
Jeffrey Burt | | Backdoor Exploit, china espionage, downloader, Google Threat Intelligence, Iran Hacker Groups, Malware, North Korean Threat Actors, Palo Alto Networks Unit 42, RCE (Remote Code Execution), React2Shell Vulnerability, software flaw, Sysdig
Researchers with Google Threat Intelligence Group have detected five China-nexus threat groups exploiting the maximum-security React2Shell security flaw to drop a number of malicious payloads, from backdoors to downloaders to tunnelers ...
Security Boulevard

