ShinyHunters says it breached Clop’s ransomware leak site and holds the keys to its Tor onion service. Here’s what that means for every organisation still listed on it.
ShinyHunters says it breached Clop’s ransomware leak site and holds the keys to its Tor onion service. Here’s what that means for every organisation still listed on it.
New research shows compromised non-human identity now drives more breaches than phishing. See why service accounts, API keys, and AI agents are the entry point most identity programmes still cannot see.
An attacker breached a marketing platform and sent phishing emails from a hardware wallet maker’s genuine domain to 347,000 subscribers. Every technical control that checks for forgery passed, because nothing was forged.
Passkey attacks published this year do not break the cryptography. They target the sync fabric, the recovery path, and the enrolment step instead — the parts a passwordless migration usually leaves unmonitored.
Security vendors sit at the top of the privilege ladder, yet TPRM programs consistently score them low because certification substitution and category heuristics mask the real question: what does an attacker inherit if this vendor is compromised?
A documented ransomware operation completed reconnaissance, credential theft, lateral movement, and encryption with no human operator at any stage. This analysis breaks down the JADEPUFFER intrusion end to end: the Langflow vulnerability that opened the door, how an autonomous LLM agent adapted mid-attack, and what defense architecture needs to look like when breakout is measured in minutes.
A 25-year-old wiki sat forgotten for years, then quietly became AI agent infrastructure: 18,000 posts in 52 days, unnoticed. Abandoned digital assets stay accessible and unmonitored while still carrying your organization’s name.
OAuth consent phishing let a single extortion group breach 1,000+ organizations without exploiting a CVE. See how attackers weaponize legitimate consent grants — and why MFA and firewalls never see it happen.
Annual vendor audits produce a snapshot; vendor risk is a movie. See why the 364 days between formal assessments is where 48% of third-party breaches actually happen, and how continuous vendor monitoring closes that gap for DORA and NIS2 compliance.
Three actively exploited AI orchestration platforms — LiteLLM, RAGFlow, and Kestra — are giving attackers a single entry point to every model provider credential an organization holds. See the CVE chains, IOCs, and detection rules from Brandefense’s INT-2608-e7a5 campaign analysis.