Veradigm has disclosed a data breach involving patient personal details and Social Security numbers after a threat actor gained access to a vendor's API credentials.
Threat actors are using infostealer malware like Lumma and Vidar to harvest session tokens, enabling them to bypass MFA and hijack premium AI services.
Researchers have identified a new attack vector called "workflow identity hijacking" that allows threat actors to exploit authorisation flaws in enterprise AI pipelines.
A new zero-click worm, developed using AI, can hijack Android and iOS devices through WeChat calls without any user interaction.
A new AI-built tool called WeWorm allows attackers to hijack WeChat accounts on Android and iOS devices through a zero-click VoIP exploit.