GitHub Copilot ‘CamoLeak’ Vulnerability Exposes Private Code Through Hidden AI Prompts

A new security discovery called CamoLeak revealed a major flaw in GitHub Copilot Chat that could expose private code and sensitive data. The issue was discovered by researchers from Legit Security, who demonstrated how hidden prompts could manipulate Copilot into leaking information from private repositories. The proof-of-concept attack showed how AI assistants could unintentionally become … Continued

Ukraine Faces AI-Driven Cyber Attacks as Russia Unleashes Smart Malware

Russian hackers are reportedly turning to artificial intelligence as their newest weapon in the cyber war against Ukraine. In recent months, Ukraine’s cyber agencies have noticed a sharp rise in AI-powered attacks that go beyond traditional phishing or malware. These operations are faster, more targeted, and far more deceptive than before. Ukraine’s State Service for … Continued

Hackers Reportedly Leak Data of 5.5 Million Discord Users After Major Breach

Hackers have claimed that they breached a system used by Discord and accessed data of around 5.5 million users. They said they stole about 1.6 terabytes of data, including support tickets, attachments, and partial billing details. The attack reportedly took place in late September 2025 and lasted nearly 58 hours. Discord, however, said its main … Continued

Ransomware Attack on Asahi Sparks Beer Shortage Across Japan

A major cyberattack has disrupted one of Japan’s largest beverage companies, Asahi Group, causing a noticeable shortage of its popular beers in stores and restaurants across the country. The ransomware attack last week hit the company’s computer systems, making it difficult for Asahi to take new orders or deliver its products on time. The issue … Continued

New Cyber Threat: Storm-1175 Exploits GoAnywhere Vulnerability for Medusa Ransomware Campaign

Microsoft has reported that a threat actor it calls Storm-1175 is exploiting a critical vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) product. The attacks use a serious deserialization flaw in the GoAnywhere license servlet and have been tied to follow-up activity that included delivering Medusa ransomware. The technical problem is an unauthenticated deserialization bug … Continued

Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files

A newly discovered zero-day flaw in Zimbra Collaboration has been used in real cyberattacks against military organizations in Brazil. Hackers exploited this vulnerability by sending specially crafted calendar files, known as ICS files, which contained malicious code designed to compromise systems. The attack was especially dangerous because it targeted a zero-day vulnerability one that was … Continued

CVE-2025-61882: Oracle Battles Cl0p’s Data Theft Campaign With Emergency Patch

Oracle has quickly released an emergency security patch after the Cl0p ransomware group reportedly exploited a serious zero-day vulnerability, tracked as CVE-2025-61882. The company confirmed that some customers using Oracle E-Business Suite received extortion emails claiming their data had been stolen through this flaw. The vulnerability affects the Concurrent Processing component of Oracle E-Business Suite … Continued

Newsletter line