Hackers Target US Companies in FastJson RCE Zero-Day Exploits
Cybercriminals are currently taking advantage of a flaw in the FastJson open-source Java library, which enables remote code execution without the need for user interaction or elevated permissions. This security vulnerability impacts FastJson versions 1.2.68 to 1.2.83 and is being utilized in attacks against various entities in the United States. The malicious activities were detected…
Attackers Take Advantage of Command Injection Vulnerability in Arista VeloCloud Orchestrator
A critical security vulnerability affecting on-premises versions of Arista VeloCloud Orchestrator (VCO) is currently being exploited in the wild. This vulnerability, identified as CVE-2026-16812 (with a CVSS score of 10.0), involves operating system command injection that could enable arbitrary code execution. According to an advisory released by Arista on Monday, “VeloCloud Orchestrator (VCO) on-prem has…
FakeGit Campaign Exploits 7,600 GitHub Repositories to Distribute SmartLoader Malware
Cybersecurity experts have identified close to 7,600 harmful GitHub repositories, with over 800 masquerading as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to disseminate a malware variant known as SmartLoader, as part of an ongoing initiative referred to as FakeGit. According to Oleg Zaytsev, the lead security researcher at Island, in a…
JadePuffer Agentic Attacks Now Target AI Model Data with Ransomware
The autonomous AI agent known as JadePuffer has been enhanced with a custom malware named EncForge, which is designed to encrypt AI-related assets, including training datasets, vector databases, and model checkpoints. Earlier this month, JadePuffer was identified as an agentic threat actor (ATA) capable of autonomously executing all phases of a ransomware attack, from gaining…
Exploitation of SonicWall SMA1000 Vulnerabilities as Zero-Days to Deploy Custom Malware
Recently, two vulnerabilities in the SonicWall SMA1000 were revealed to have been exploited in zero-day attacks for several weeks, enabling threat actors to install tailored malware on affected VPN devices. Last week, SonicWall issued a warning regarding the active exploitation of two previously unknown vulnerabilities in an exploit chain impacting SMA1000 Secure Mobile Access appliances….
We created a vulnerability vending machine: AI tokens in, zero-days out
Artificial intelligence is transforming the landscape of vulnerability research, yet much of the discussion remains theoretical, focusing on the potential capabilities of models rather than their current practical applications. Our goal was to address a more pragmatic inquiry: with the models we currently have access to, how effectively can AI assist in identifying genuine, exploitable…
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
A malware framework known as OkoBot has been operational on Windows systems since April 2025, with one of its components designed to deceive hardware wallet users into revealing their recovery phrases. On a compromised computer, the request originates from the wallet’s own desktop application. At times, it waits until the device is connected. The page…
AsyncAPI npm Packages Compromised by Credential-Stealing Malware
Five harmful versions of AsyncAPI packages were uploaded to the Node Package Manager (npm) as part of a supply-chain attack that introduced a remote access trojan capable of stealing information. The attacker took advantage of a poorly configured GitHub Actions workflow, releasing trojanized packages within the @asyncapi namespace, which collectively garnered over 2.25 million downloads…
Announcing Gas City 1.0! – Marquee de Sells: Chris’s insight outlet
Announcing Gas City 1.0! You may have heard from Steve Yegge, the creator of Beads and Gas Town, that we’ve released Gas City 1.0! As the CEO of the newly minted Gas City, Inc., I thought I’d provide some additional details on Steve’s excellent blog post. It’s hard to look back on the release of…
China’s DeepSeek trims the price of its flagship AI model by 75%, and it could be a huge shift
Chinese AI startup DeepSeek just made one of the boldest pricing moves in the artificial intelligence race so far. The company announced it is permanently slashing the cost of its flagship V4-Pro AI model by 75%, bringing prices down to just a fraction of what developers were paying only weeks ago. AI companies worldwide have…
