
OnePlus OxygenOS root exploit disclosed
Researcher Rasmus Moorats chained two unpatched OnePlus software flaws to gain root access on an Android phone via a malicious app.
Defence on Zero Day Room: Patch management, Multi-factor authentication and phishing resistance, Backup and recovery that survives ransomware, Network segmentation, Endpoint detection and response and Logging and detection engineering.

Researcher Rasmus Moorats chained two unpatched OnePlus software flaws to gain root access on an Android phone via a malicious app.

Japan, the US, Australia, and Germany detail a North Korean hiring scheme that stole over $10 million and infected 30,000 devices.

A North Korean hacking group compromised 30,000 devices worldwide over eight months, stealing over $10.7 million in cryptocurrency.

A new ransomware variant called Settra is attacking retail and manufacturing firms. According to Huntress, the malware uses RMM tools for persistence and disables victim recovery options.

Researchers at KTH Royal Institute of Technology have developed an autonomous intrusion response agent for industrial control systems.

The Gigabud Android banking trojan now uses a weaponized app cloner called Vwork to isolate fraudulent transactions in a separate work profile.

Threat actors are using stolen session tokens and API keys from infostealer logs to bypass multi-factor authentication and hijack AI service accounts.

Mars Security has launched a real-time detection capability that automatically converts threat advisories from sources like CISA and Mandiant into tested detection rules.

Hackers negotiated publicly with the Liquid Network cryptocurrency platform, returning $266.5 million of a $320 million exploit but keeping $47 million as a reward.

Doppler's secrets management platform centralizes credentials for developers, CI/CD pipelines, and AI agents.

Teleport's Chris Webber argues traditional zero trust principles are insufficient for AI agents.

A global phishing campaign using fake documents to deploy legitimate remote monitoring and management software has made the United States its primary target.

Elastic Security Labs has identified four new programs linked to the REVSTEALER infostealer that persist after the main malware deletes itself.

Attackers are exploiting MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication.

AIR Security has emerged from stealth with $50 million in funding and a new firewall product designed to secure AI agents and their add-ons.

A breach of Thomson Reuters' C-Track court management platform exposed sealed records and personal data from courts in at least 12 U.S. States, the U.S.