RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

supply-chaincybersecurity

Bomgar RMM Exploitation Surge Exposes Downstream Supply Chain Blast Radius

Attackers are escalating exploitation of BeyondTrust's Bomgar remote monitoring and management platform, turning a trusted administrative tool into a privileged

via Dark Reading ·
vulnerabilitycybersecurity

BRIDGE:BREAK: 22 Flaws Expose 20,000+ Serial-to-IP Converters to Takeover

Researchers disclosed 22 vulnerabilities, collectively dubbed BRIDGE:BREAK, affecting serial-to-IP converters manufactured by Lantronix and Silex. These devices

via The Hacker News ·
supply-chaincybersecurity

Checkmarx Supply Chain Hit: Poisoned KICS Docker Images and VS Code Extensions

Attackers published malicious artifacts masquerading as Checkmarx's KICS infrastructure-as-code scanner, seeding both Docker registries and the VS Code Marketpl

via The Hacker News ·
aivulnerability

Cohere Terrarium sandbox flaw lets AI-generated code escape the container as root

A vulnerability in Cohere's Terrarium, the sandboxed Python execution environment used to run code produced by AI agents, allowed attackers to break out of the

via The Hacker News ·
cybersecurityidentity

Cross-App Permission Stacking Creates Hidden Privilege Escalation Paths

Modern SaaS environments rarely fail because of a single over-permissioned integration. They fail because individually reasonable grants — a calendar read here,

via The Hacker News ·
cybersecurityprivacy

France's ANTS document agency breached, 19M records allegedly up for sale

The Agence nationale des titres sécurisés (ANTS), the French Interior Ministry body that issues passports, national IDs, driver's licenses, and immigration pape

via BleepingComputer ·
malwarecybersecurity

GoGra Linux backdoor abuses Microsoft Graph API and Outlook for C2

Symantec has identified a Linux build of the GoGra backdoor attributed to Harvester, a state-aligned espionage group active since 2021 against telecom, governme

via BleepingComputer ·
aivulnerability

Google Patches Critical RCE in Antigravity AI Development Tool

Google has shipped a fix for a critical remote code execution vulnerability in Antigravity, its AI-powered development platform. The flaw allowed attackers to e

via Dark Reading ·
cloudidentity

Graph API code change exposes race condition in Universal Print share creation

Microsoft has attributed an ongoing Universal Print outage (UP1287359) to a recent Microsoft Graph API code change that increased Entra ID directory replication

via BleepingComputer ·
cybersecuritymalware

Harvester APT Port GoGra Backdoor to Linux, Abuses Microsoft Graph API for C2

The Harvester threat group has expanded its Linux tooling with a port of the GoGra backdoor, previously seen only on Windows, and is using it against targets in

via The Hacker News ·
privacypolicy

ICE Confirms Use of Graphite Spyware in Domestic Operations

U.S. Immigration and Customs Enforcement has acknowledged deploying Graphite, a zero-click spyware product from Israeli vendor Paragon Solutions. The agency fra

via Schneier on Security ·
cybersecuritymalware

Kyber ransomware ships dual ESXi/Windows payloads, fakes post-quantum crypto on Linux

Rapid7 analyzed two Kyber ransomware variants deployed in tandem during a March 2026 incident, with one targeting VMware ESXi and a Rust-built sibling hitting W

via BleepingComputer ·