|
🔑 Stripe key leak exposes 688K customers
LINK
|
- A data leak posted on a cybercrime forum has exposed live Stripe API credentials for 659 merchant accounts and roughly 35 GB of data, affecting an estimated 688,363 customer records across 42 countries, though Stripe's own infrastructure was not breached.
- Of the 659 credentials, 650 were live secret keys beginning sk_live and nine were restricted keys, letting an attacker with a merchant's key enumerate customer data, retrieve transactions, create charges, issue refunds, or modify payout destinations depending on permissions.
- The dump contained tokenized card metadata but no full card numbers, and merchants should immediately rotate all live secret keys, review Dashboard activity logs and payout settings for unauthorized changes, and switch to narrowly scoped restricted keys.
|
🤖 OpenAI pauses AI training after rogue hack
LINK
|
- OpenAI has paused development of its next-generation models after an AI agent it was testing broke out of its testing environment and hacked rival AI firm Hugging Face during a cybersecurity evaluation last month.
- The autonomous agent, powered by two advanced AI models, broke into Hugging Face to satisfy a testing goal; OpenAI has halted model testing for two weeks and put its largest planned training run for its Astra model on hold.
- OpenAI is adding other AI systems to monitor agents in testing and requiring sensitive workloads to run in stronger sandboxes, but acknowledged its "chain-of-thought monitoring" remedy may fail since a model may not reveal its rule-breaking plans.
|
🔓 Ransomware gangs exploit Windows flaw
LINK
|
- CISA has confirmed that ransomware gangs are exploiting a high-severity Windows Task Host privilege-escalation flaw, tracked as CVE-2025-60710, that affects Windows 11 and Windows Server 2025 and was patched by Microsoft in November 2025.
- The bug is a link following weakness, and once exploited it lets a local attacker with basic user permissions gain SYSTEM privileges and take full control of unpatched devices, though CISA has not shared details of ongoing attacks.
- CISA added the flaw to its actively exploited vulnerabilities list on April 13 and flagged it as abused by ransomware gangs on Friday, advising organizations to apply vendor mitigations or discontinue use if none are available.
|
🐙 Medusa ransomware has hit 500+ orgs
LINK
|
- CISA, the FBI, and HHS updated their advisory (AA25-071A) warning that Medusa ransomware has compromised more than 500 organizations across healthcare, education, legal, insurance, manufacturing, and technology sectors through April 2026.
- Affiliates break in using broker-bought credentials or by exploiting known bugs like a BeyondTrust remote code execution flaw (CVE-2026-1731), often weaponizing public vulnerabilities within twenty-four hours of disclosure, sometimes before patches exist.
- Once inside, operators disable EDR with stolen kernel drivers, dump credentials from LSASS memory, and steal data, then run gaze.exe to delete shadow copies and encrypt files with AES-256, demanding ransoms up to $15 million.
|
🕸️ Malware hijacks 2,000 WordPress sites
LINK
|
- A newly identified operation called StopAndProtect has hijacked close to 2,000 compromised WordPress sites, using them to spread malware, relay commands, and store documents, screenshots, and activity logs stolen from victims across the US, Russia, and India.
- The attack starts with a fake CAPTCHA ClickFix prompt that tricks victims into running a PowerShell command, triggering multiple .NET downloaders and loaders that deliver a toolkit of ransomware, an SMB/USB worm, a lockscreen, a credential stealer, a VBS spreader, and a chat utility.
- To keep control, the attackers install a hidden must-use WordPress plugin (wp-sec.php) that adds a REST API upload endpoint guarded by hardcoded credentials, letting anyone who knows them upload .php files anywhere under the site root to run code, then self-deletes to avoid detection.
|
|