Latest news as of 9/1/2026, 4:15:10 AM
The Register
McKesson admits breach as ShinyHunters demands $55.2M
Dark Reading
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Bleeping Computer
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]
Dark Reading
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
The Register
Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness
Bleeping Computer
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
The Register
Next-level ClickFix wave sets off multi-stage attack chain
The Hacker News
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme,
Dark Reading
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
Bleeping Computer
Microsoft is investigating a widespread service issue causing authentication issues and email delays and failures for Exchange Online customers. [...]