Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Infostealer malware operators are expanding beyond browser passwords and crypto wallets to target AI agent authentication tokens stored locally. Researchers at Gen Digital found that infostealers now capture API keys, OAuth tokens, and session data used by AI coding assistants and agent frameworks, potentially giving attackers access to corporate AI systems.
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Highway Safety and Motor Vehicles, stealing a database containing millions of driver records. The group is demanding a ransom payment and has leaked samples of the stolen data on their Telegram channel.
OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays. The outage affects users attempting to generate images through the DALL-E integration within ChatGPT. OpenAI has not provided a timeline for resolution and recommends users check the status page for updates.
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider .
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems. The bug causes application crashes and system instability on affected servers.
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security update, including a maximum-severity kernel vulnerability that could allow unauthenticated remote code execution. The critical flaw, rated CVSS 10.0, affects the SAP kernel component and requires immediate patching.