RC RANDOM CHAOS

The Wire

Curated cybersecurity and tech news — AI-summarized, source attributed.

cybersecurityvulnerability

CISA Expands KEV Catalog With 8 Active Exploits, April-May 2026 Patch Deadlines

CISA has added eight new actively-exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, with federal civilian agencies facing mandatory reme

via The Hacker News ·
cybersecuritymalware

FakeWallet campaign smuggles 26 crypto-draining apps into China's App Store

Kaspersky has tied 26 malicious iOS apps to a campaign it calls FakeWallet, an extension of the SparkKitty operation active since last year. The apps impersonat

via BleepingComputer ·
tech-culturepolicy

Flawed Conference Abstract Spawns Headlines Blaming Produce for Lung Cancer

A non-peer-reviewed conference abstract presented at the American Association for Cancer Research meeting is driving headlines claiming fruits, vegetables, and

via Ars Technica ·
cybersecuritymalware

Gentlemen ransomware bolts SystemBC botnet onto 1,570-host attack toolchain

Check Point researchers traced a Gentlemen ransomware intrusion to a SystemBC command-and-control server running a botnet of more than 1,570 infected hosts, wit

via BleepingComputer ·
aivulnerability

Google Patches Prompt Injection RCE in Antigravity AI IDE

Google has shipped a patch for its Antigravity IDE addressing a prompt injection vulnerability that allowed attackers to achieve arbitrary code execution on dev

via The Hacker News ·
identitycybersecurity

Identity Is the New Perimeter: Attackers Skip Exploits, Log In With Stolen Creds

Credential theft, session hijacking, and MFA fatigue have quietly overtaken traditional exploitation as the dominant intrusion path. Attackers don't need a CVE

via The Hacker News ·
cybersecuritymalware

Insider rot: Ransomware negotiators ran BlackCat attacks against their own clients

Angelo Martino, a former DigitalMint incident responder, pleaded guilty to running BlackCat ransomware operations against U.S. companies between April 2023 and

via BleepingComputer ·
cybersecuritymalware

Lazarus-linked attackers drain $290M from KelpDAO via poisoned RPC nodes

KelpDAO, an Ethereum liquid restaking protocol, lost roughly 116,500 rsETH (about $293 million) on April 18 after attackers subverted the cross-chain verificati

via BleepingComputer ·
aivulnerability

MCP Design Flaw Turns AI Agent Tool Calls Into RCE Vectors

A design-level weakness in Anthropic's Model Context Protocol (MCP) lets attackers achieve remote code execution against systems that wire LLM agents to externa

via The Hacker News ·
privacypolicy

Mexican Surveillance Firm Grupo Seguritech Pushes Into US Market

Grupo Seguritech, a Mexican surveillance vendor behind pervasive monitoring deployments like Plataforma Centinela in Ciudad Juárez, is moving into the United St

via Schneier on Security ·
malwarecybersecurity

NGate Android malware swaps NFCGate for trojanized HandyPay to siphon NFC card data

A fresh NGate variant tracked by ESET is hijacking HandyPay, a legitimate Android NFC payment processor on Google Play since 2021, to capture card data the mome

via BleepingComputer ·
cybersecuritymalware

NGate Malware Trojanizes Brazilian HandyPay App to Relay NFC Data and PINs

A fresh NGate campaign is targeting Brazilian banking customers by distributing a trojanized clone of HandyPay, a legitimate point-of-sale application. Once ins

via The Hacker News ·