A five-step attack chain that silently redirects Claude Code’s Model Context Protocol (MCP) traffic through attacker-controlled infrastructure, intercepting OAuth bearer tokens that grant persistent, broadly scoped access to connected SaaS platforms like Jira, Confluence, and GitHub with no patch incoming from Anthropic. Researchers at Mitiga Labs have demonstrated the attack, with the entry point being...Read More
Anthropic, the maker of the Claude artificial intelligence (AI) models, made a new version of its technology available to the general public on Tuesday while restricting its use in sensitive areas. Dubbed Fable 5, the model is the first to be made widely available from the company’s new Mythos class – its most advanced lineup...Read More
Project Consulting Services Project Consulting Services Inc., a U.S.-based engineering and consulting firm serving the oil and energy industry, disclosed a data breach. The breach was disclosed to the Vermont Attorney General on June 9, 2026. The total number of individuals affected across the United States has not been publicly reported at this time. The...Read More
On 4 and 5 June 2026, a training course entitled “Cybercrime in Information Technologies: From Detection to Judicial Decision” was held in Bukhara. The event was organized by the OSCE Project Co-ordinator in Uzbekistan in partnership with the Law Enforcement Academy of the Republic of Uzbekistan. Twenty judges and chairpersons of district and city criminal...Read More
Just over a week ago, Meta’s AI-powered chat assistant unwittingly gave hackers access to thousands of Instagram accounts, including high-profile ones such as makeup retailer Sephora and the top noncommissioned officer of the US Space Force, as well as Barack Obama’s White House account. The exact number was later revealed in a regulatory filing with the...Read More
The federal vulnerability management conversation has been stuck in a loop for years. Everyone agrees that patching happens too slowly, and the diagnosis generally blames budget, headcount or tooling. That diagnosis is wrong. The real friction is structural, and it lives in the processes and policies that govern how we assess compliance and risk, and...Read More
Google, in its latest Fraud & Scams Advisory, separately highlighted the evolution of traditional phishing into Adversary-in-the-Middle (AITM) and QR-code phishing attacks while documenting growing abuse of trusted cloud services, AI-driven investment scams, and impersonation campaigns. While Microsoft’s advisory focuses on AI-branded lures and Google’s examines broader fraud trends, both point to attackers evolving established...Read More
A previously undocumented cyber espionage group has been attempting to compromise the smartphones, computers and Telegram accounts of Russian military personnel by posing as women seeking romantic relationships, researchers have found. The group, dubbed SiribClone by Russian cybersecurity firm F6, has been active since at least the summer of 2025 and has primarily targeted members...Read More
AI healthcare concepts. getty Healthcare exists at the confluence of significant trust and heightened cyber vulnerability. Patient records, medical equipment, diagnostic systems, and associated networks contain very sensitive personal information; unfortunately, advanced hackers are targeting them. The sector’s digital development has outpaced its security measures. The integration of AI, IoT medical devices, cloud migration, and...Read More
A widespread vulnerability in government security tools opened an attack window for a tracked ransomware gang. Federal agencies have received an immediate directive to fix affected products by Wednesday. A ransomware group is actively exploiting an unpatched vulnerability in security tool suites used across the U.S. federal government, prompting CISA to order all civilian agencies...Read More