The Gentlemen is one of the most rapidly escalating ransomware threats observed in 2026. Emerging in mid-2025 from a payment dispute within the Qilin RaaS program, the group has evolved into a full-spectrum, human-operated Ransomware-as-a-Service (RaaS) operation that Microsoft tracks as Storm-2697. Within its first year of independent operation, The Gentlemen has claimed over 500 victims across … [Read more...]
Source-10
You are viewing page 51 of the Source-10 archive. Older tech news, programming trends, and development reports continue below.
VECT and TeamPCP Reverse Ransomware Kill Chain With Supply Chain Credential Theft
A ransomware strain called VECT has formed an unusual supply chain partnership with a threat group known as TeamPCP, quietly exposing thousands of organizations to compromise before any ransom note appears. VECT's operators buy their way in using stolen credentials harvested from tampered open source software rather than scanning networks for weaknesses. Most ransomware groups pick a target, gain … [Read more...]
4,982 Security Issues Identified Across 2,259 Affected in Public MCP Servers
A sweeping security crisis across public Model Context Protocol (MCP) servers, cataloging 4,982 security issues across 2,259 affected servers, exposing serious gaps that directly threaten the emerging agentic AI ecosystem. Model Context Protocol has become the dominant standard for connecting large language models (LLMs) to local and remote data sources, enabling AI applications to evolve into … [Read more...]
The $50K-to-$5M Gap: Why Your SOC SLA Is Stuck in 2019 — Here’s the 2026 AI SLA Vendor Guide
A technical breakdown of why legacy MDR contract language fails in the age of AI-driven security operations — and the measurable standards that should replace it. The Problem: Contracts Written for Human Queues Pull out your current MDR contract and read the SLA section. Most SOC SLAs still in production were drafted for human-only operations: 4-hour MTTR targets, "commercially reasonable … [Read more...]
GitLost Vulnerability Tricks GitHub’s AI Agent into Leaking Private Repos
A newly disclosed vulnerability dubbed "GitLost" shows how attackers can weaponize a single GitHub Issue to trick GitHub's new AI-powered Agentic Workflows into leaking private repository contents to the public internet, with no credentials, coding skills, or system access required. GitHub Agentic Workflows pair GitHub Actions with an AI agent backed by Claude or GitHub Copilot, letting teams … [Read more...]
AnyDesk Phishing Attack Uses Scheduled Task Persistence and Artifact Deletion to Evade Detection
A new phishing campaign is turning a trusted remote access tool into a long term backdoor for espionage. Attackers hide behind fake invoices to slip past email filters, and once inside a network they rely on everyday IT software rather than custom malware, making the intrusion harder to spot. The campaign targets Russian aerospace and aviation organizations using an invoice themed lure. Rather … [Read more...]
Ubiquiti Disclosed 25 Security Vulnerabilities Across the UniFi Ecosystem
Ubiquiti has disclosed 25 security vulnerabilities affecting its UniFi ecosystem in Security Advisory Bulletin 066, including several critical flaws rated 9.9 and 10.0 on the CVSS v3.1 scale that could allow network-based attackers to fully compromise devices. The advisory spans UniFi Connect, Talk, Access, Protect, Network Application, and the core UniFi OS platform running on UDM, UNVR, and UNAS … [Read more...]
STOCKSTAY Backdoor Uses Malicious RDP Files and WinRAR Exploit to Target Ukraine
A newly detailed cyber-espionage campaign is using fake remote desktop files and a recently patched WinRAR flaw to plant a stealthy backdoor called STOCKSTAY on computers in Ukraine. The malware disguises itself as everyday software, including stock market trackers and calculator apps, to avoid raising suspicion while it quietly collects information from infected machines. STOCKSTAY is built in … [Read more...]
Windows Adds Microsoft Execution Containers to Secure AI Agent Workflows
Microsoft has introduced Microsoft Execution Containers (MXC), a new security capability designed to protect AI agent workflows on Windows, marking a significant step toward making Windows more trustworthy for autonomous systems. AI agents are rapidly evolving beyond simple assistants into systems that can read files, execute code, interact with services, and automate multi-step tasks. While this … [Read more...]
U.S. Cyber Defense Agency Reportedly Using Anthropic’s Mythos to Audit Government Code Repositories
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is reportedly deploying Anthropic's advanced AI model, Mythos, to audit federal government code repositories, signaling a growing reliance on artificial intelligence for proactive vulnerability discovery. According to Reuters, the initiative, CISA's Attack Surface Evaluation team is using Mythos to scan internal software systems for … [Read more...]
Critical PHP PDO Driver Bugs Expose Firebird SQL Injection and PostgreSQL DoS Risks
A newly disclosed pair of flaws in PHP's database driver layer shows that even mature code can hide dangerous surprises. The bugs live inside PHP Data Objects (PDO), the abstraction layer web applications use to talk to databases like Firebird and PostgreSQL. Low level quirks in these drivers let attackers slip malicious input past safe defenses. The first issue affects the pdo_firebird driver and … [Read more...]
Microsoft Confirms Windows 11, 26H2 Comes With Change in Backup Policy
Microsoft has confirmed a significant change to its Windows settings backup policy with the upcoming release of Windows 11 version 26H2, marking a shift toward improved system resilience and recovery capabilities. According to Microsoft, the Windows settings backup policy will now be enabled by default on eligible devices starting with version 26H2. Previously, this feature was disabled unless … [Read more...]
Hackers Use Recruiter Phishing Emails and Fake Career Pages to Harvest Gmail Logins
A new phishing campaign is targeting job seekers by posing as recruiters from recognizable brands. The scheme uses fake career pages and worded emails to trick people into handing over Gmail login credentials. What makes this campaign notable is not just its scale but the planning behind each message. The attack begins with an email that looks like it comes from a genuine recruiter offering a … [Read more...]
Hackers Leverage Microsoft Teams Call to Install RMM Tools and Deploy EtherRAT
Threat actors are now weaponizing something as ordinary as a Microsoft Teams call to slip past corporate defenses and plant a stealthy new remote access trojan called EtherRAT. The campaign blends social engineering with legitimate remote support software, making it look like a routine IT interaction rather than an attack in progress. Victims are left unaware that a simple screen sharing session … [Read more...]
OpenAI Codex Desktop App for macOS Vulnerability Allows Attackers to Inject Indirect Prompt
A newly disclosed vulnerability in the OpenAI Codex desktop application for macOS could allow attackers to exploit indirect prompt injection techniques to exfiltrate sensitive data, according to a recent entry in the GitHub Advisory Database. Tracked as CVE-2026-14898, the issue arises from how the Codex app handles Markdown content in model-generated responses. Specifically, the application … [Read more...]
Cavern Manticore Abuses SysAid RMM and WinDirStat DLL Sideloading to Deploy C2 Framework
A new Iranian-linked hacking group has been caught abusing everyday IT tools to slip malware onto Israeli networks. Researchers have named the group Cavern Manticore, and its latest campaign shows how creative attackers have become at hiding in plain sight. Instead of flashy exploits, the group leans on software organizations already trust. At the heart of this campaign is a technique that turns … [Read more...]
Tenda Authentication Backdoor Grants Attackers Full Administrative Access
A newly disclosed vulnerability in Tenda network devices exposes a critical authentication backdoor that allows attackers to gain full administrative access without valid credentials. The flaw affects multiple firmware versions across several Tenda router models, including the FH1201, W15E, AC10, AC5, and AC6 series. The issue, tracked as CVE-2026-11405, was published by the CERT Coordination … [Read more...]
16-Year-Old Linux KVM Vulnerability Allows Malicious Guest to Corrupt Host Kernel Memory
A newly disclosed Linux Kernel-based Virtual Machine (KVM) vulnerability, tracked as CVE-2026-53359 and dubbed "Januscape," exposes a critical flaw that allows a malicious guest to corrupt host kernel memory, breaking the fundamental isolation guarantees of virtualization. The issue, which remained unnoticed for nearly 16 years, affects KVM's x86 shadow memory management logic and impacts both … [Read more...]
Critical BeyondTrust Flaws Let Attackers Bypass Access Controls and Gain Unauthorized Access
BeyondTrust has disclosed multiple critical and high-severity vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) solutions, potentially allowing attackers to bypass access controls and gain unauthorized access to sensitive systems. The issues are tracked under Advisory ID BT26-03 and carry a maximum CVSS v4 score of 9.2, indicating a severe risk to impacted … [Read more...]
Windows Device Identifier Used to Arrest Scattered Spider Hacking Group Member
A persistent Microsoft device identifier was used to unravel the anonymity of an alleged Scattered Spider operator, according to a federal superseding complaint filed in the Northern District of Illinois. Peter Stokes, 19, a dual U.S.–Estonian citizen who allegedly used the handles "Bouquet," "Spencer," and "Jordan," was arrested in Finland on April 10, 2026, while attempting to board a flight to … [Read more...]


















