cybersecurity

Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
Dem senators criticize Trump administration decisionmaking on AI security risks [cyberscoop.com] Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens [thehackernews.com] Prolific ransomware group behind SonicWall zero-day attacks [cyberscoop.com] Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming [cyberscoop.com] Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks [thehackernews.com]
Senate set to debate package of bills on privacy, AI and kids safety  [cyberscoop.com] Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access [thehackernews.com] AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls [www.darkreading.com] When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted [thehackernews.com] Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent [thehackernews.com]
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root [thehackernews.com] How companies could share cyber risks without exposing their secrets [cyberscoop.com] DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT [thehackernews.com] CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises [thehackernews.com] Device Code Phishing Up 1,500% in 2026; Vishing Doubles [www.darkreading.com]