profile

Cyber Threats Weekly

Critical threats, hacks, and defenses — 3× per week, free.

DeepSeek AI weaponized for autonomous server attacks

Monday Free Edition - August 3, 2026 Threat of the Week: DeepSeek AI Deployed for Autonomous Cyberattacks A Chinese-speaking threat actor has been observed using the DeepSeek AI model paired with the open-source Hermes Agent to conduct autonomous cyberattacks against exposed servers — with minimal human involvement required. According to Bleeping Computer, the attacker leverages DeepSeek's reasoning capabilities to identify, target, and exploit vulnerable systems at a speed and scale that...

ShinyHunters claims E&Y breach via supply-chain attack

Wednesday Free Edition - July 29, 2026 Threat of the Week: ShinyHunters Claims Ernst & Young Breach The ShinyHunters extortion gang has claimed responsibility for a data breach at professional services giant Ernst & Young, alleging it obtained credentials for some of the firm's systems through a supply-chain attack. According to Bleeping Computer, the group says the intrusion was made possible not by directly targeting E&Y's own infrastructure, but by compromising a third-party vendor in its...

Check Point zero-day, msaRAT, and Chick-fil-A breach

Friday Free Edition - July 24, 2026 Threat of the Week Check Point SmartConsole Zero-Day Under Active Exploitation Israeli cybersecurity vendor Check Point Software has patched an actively exploited zero-day vulnerability in its SmartConsole graphical user interface admin panel, according to Bleeping Computer. SmartConsole is the primary management interface used by administrators to configure Check Point security gateways and policies — making a zero-day here particularly high-impact for...

Spirals ransomware, Oracle flaw, and Scattered Spider verdict

Weekend Threat Roundup — Premium Edition - July 18, 2026 Week in Review This week delivered a dense cluster of threat activity spanning ransomware, nation-state intrusion campaigns, legal accountability, and critical enterprise vulnerabilities — a reminder that the threat landscape does not slow in summer. The most operationally alarming development was the emergence of Spirals ransomware, a new actor that compressed an entire corporate compromise — initial access, data exfiltration, and full...

JadePuffer ransomware automates attacks via LLM agent

Monday Free Edition - July 6, 2026 Threat of the Week: JadePuffer Ransomware Runs on Autopilot via AI Agent Researchers have documented what they believe is the first confirmed ransomware operation conducted entirely by a large language model (LLM) agent. The group, tracked as JadePuffer, reportedly used an AI agent to automate the full attack chain — from initial access through encryption and ransom demand — with minimal human intervention. According to Bleeping Computer, this marks a...

AI agents are stealing your data while you sleep, boss

Friday Free Edition - June 26, 2026 🚨 THREAT OF THE WEEK Autonomous AI Agents Weaponized in Multi-Stage Enterprise Credential Harvesting Campaign Security researchers at Mandiant and independent red teams have confirmed what many threat intelligence analysts feared was coming: a sophisticated, state-nexus threat actor tracked as UNC-MOSAIC is actively exploiting enterprise-deployed AI agent frameworks — including auto-GPT-style orchestration layers and LLM-powered RPA bots — to conduct...

When your medical implant gets pwned by script kiddies

Monday Free Edition - June 15, 2026 THREAT OF THE WEEK The nightmare scenario we've all been dreading finally materialized this week as researchers uncovered critical vulnerabilities in Medtronic's latest generation of insulin pumps and pacemakers. The flaws, dubbed "HeartBleed 2.0" by the security community, allow attackers within Bluetooth range to execute arbitrary commands on implanted devices. What makes this particularly terrifying? The affected devices use a shared encryption key...