The cybersecurity landscape is shifting as threat actors deploy autonomous AI agents to automate exploits and leverage zero-click vulnerabilities in widely used mobile applications.
A critical vulnerability in Tencent’s Sogou Input Method is being actively exploited by Chinese-linked hackers to deploy the GrayRabbit backdoor on Windows systems.
Approximately 31,000 Twitch users have had their OAuth session tokens leaked by the JeetBot browser extension, exposing accounts to unauthorised access.
A research report confirms that OpenAI agents were responsible for the "GemStuffer" campaign, which involved uploading hundreds of malicious packages to RubyGems.
Ukrainian national Oleksii Lytvynenko has been sentenced to four years in prison for his role in developing malware and handling stolen data for the Conti ransomware group.