Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The tech journalists at 404 Media learned that OpenAI is hiring hundreds of contractors to read and review a massive stream of real users' ChatGPT prompts and responses as part of Project Lily, raising significant privacy concerns about how AI training data is handled.
BambooToken is a new cross-platform malware that uses MQTT protocol for command-and-control communication to orchestrate infected Windows and Linux systems. The malware leverages the lightweight IoT messaging protocol to evade detection by blending into legitimate MQTT traffic, making it difficult for traditional network monitoring tools to identify malicious activity.
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems.
AhnLab SEcurity intelligence Center (ASEC) recently identified a case in which ransomware was distributed through a private home trading system (HTS). The HTS program used to distribute the ransomware is called “UBP Asset” and has long been exploited in online investment scams.
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.
📌 **Analyst Note:** CVE-2026-76461: Critical Cisco Secure Email Gateway Zero-Day Enables Root RCE involves CVE-2026-76461, which has confirmed active exploitation in the wild. This represents a critical threat requiring immediate remediation as threat actors have already developed and deployed working exploits.