Latest security news
- AI agents tricked into recommending malicious GitHub repositories
- JadePuffer returns with ransomware built to target AI models and infrastructure
- Cisco’s open-weight Antares models make vulnerability localization cheaper
- A New Ransomware Threat Actor Emerges Every Week, Warns Report
- FBI Warns of Deepfake Videos Impersonating IC3 Leadership
- SonicWall SMA zero-days were exploited weeks before disclosure
- Fake FBI agents target people who already got scammed
- US Hospital Finance Software Provider Craneware Reports Data Theft
- Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros
- AWS wants GuardDuty to automate the first steps of threat investigations
- Estée Lauder discloses data breach tied to Oracle EBS vulnerability
- Cruciferra Crypter Uses Process Ghosting to Evade Detection
- JadePuffer Returns With Ransomware Designed to Wipe AI Models
- Researchers Build WordPress Exploit Using OpenAI's GPT
- New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
- Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders
- Government Agencies Falling Victim to Ransomware Daily, Warns Study
- 23andMe Faces New Security Mandates in $18m Data Breach Settlement
- CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities
- The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat
- Phishing Campaign Hides Lua Loader as TrueType Font File
- Modular macOS Stealer Uses Kill Loops to Force Password Entry
Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island) The fake repositories are tied to about 6,600 accounts, around 1,400 of which were built around AI tools, agents, or workflows, and span individual and enterprise use, ranging from Gmail and WhatsApp integrations to …
(C) Do-Know.com (http://do-know.com/). Do not copy without permission from info at do-know.com.