Cybersecurity

Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44 

Wiz Uncovers Critical Access Bypass Flaw in AI-Powered Vibe Coding Platform Base44 

Cybersecurity researchers have disclosed a now-patched critical security flaw in a popular vibe coding platform called Base44 that could allow unauthorized access to private applications built by its users.
“The vulnerability we discovered was remarkably simple to exploit — by providing only a non-secret app_id value to undocumented registration and email verification endpoints, an attacker

PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain 

PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain 

The maintainers of the Python Package Index (PyPI) repository have issued a warning about an ongoing phishing attack that’s targeting users in an attempt to redirect them to fake PyPI sites.
The attack involves sending email messages bearing the subject line “[PyPI] Email verification” that are sent from the email address noreply@pypj[.]org (note that the domain is not “pypi[.]org”).
“This is

The AI Fix #61: Replit panics, deletes $1M project; AI gets gold at Math Olympiad 

The AI Fix #61: Replit panics, deletes $1M project; AI gets gold at Math Olympiad 

In episode 61 of The AI Fix, a robot called DeREK goes bananas, OpenAI, Google DeepMind, and Anthropic warn we may lose the ability to see what AI is thinking, a dextrous robot changes its own batteries, the USA unveils its AI action plan, and a human beats AI to win the World Coding Championship.

Also in this week’s episode, Graham reveals why you should never ask a vibe coding app to “clean up” your project, and Mark explains why it was handbags at dawn at the International Mathematical Olympiad.

All this and much more is discussed in the latest edition of “The AI Fix” podcast by Graham Cluley and Mark Stockley.

Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims 

Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims 

A newly emerged ransomware-as-a-service (RaaS) gang called Chaos is likely made up of former members of the BlackSuit crew, as the latter’s dark web infrastructure has been the subject of a law enforcement seizure.
Chaos, which sprang forth in February 2025, is the latest entrant in the ransomware landscape to conduct big-game hunting and double extortion attacks.
“Chaos RaaS actors initiated

How the Browser Became the Main Cyber Battleground 

How the Browser Became the Main Cyber Battleground 

Until recently, the cyber attacker methodology behind the biggest breaches of the last decade or so has been pretty consistent:

Compromise an endpoint via software exploit, or social engineering a user to run malware on their device; 
Find ways to move laterally inside the network and compromise privileged identities;
Repeat as needed until you can execute your desired attack — usually

Cybercriminals Use Fake Apps to Steal Data and Blackmail Users Across Asia’s Mobile Networks 

Cybercriminals Use Fake Apps to Steal Data and Blackmail Users Across Asia’s Mobile Networks 

Cybersecurity researchers have discovered a new, large-scale mobile malware campaign that’s targeting Android and iOS platforms with fake dating, social networking, cloud storage, and car service apps to steal sensitive personal data.
The cross-platform threat has been codenamed SarangTrap by Zimperium zLabs. Users in South Korea appear to be the primary focus.
“This extensive campaign involved

Why React Didn’t Kill XSS: The New JavaScript Injection Playbook 

Why React Didn’t Kill XSS: The New JavaScript Injection Playbook 

React conquered XSS? Think again. That’s the reality facing JavaScript developers in 2025, where attackers have quietly evolved their injection techniques to exploit everything from prototype pollution to AI-generated code, bypassing the very frameworks designed to keep applications secure.
Full 47-page guide with framework-specific defenses (PDF, free).
JavaScript conquered the web, but with

CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation 

CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation 

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security vulnerability impacting PaperCutNG/MF print management software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.
The vulnerability, tracked as CVE-2023-2533 (CVSS score: 8.4), is a cross-site request forgery (CSRF) bug that could

Hackers Breach Toptal GitHub, Publish 10 Malicious npm Packages With 5,000 Downloads 

Hackers Breach Toptal GitHub, Publish 10 Malicious npm Packages With 5,000 Downloads 

In what’s the latest instance of a software supply chain attack, unknown threat actors managed to compromise Toptal’s GitHub organization account and leveraged that access to publish 10 malicious packages to the npm registry.
The packages contained code to exfiltrate GitHub authentication tokens and destroy victim systems, Socket said in a report published last week. In addition, 73 repositories

NEW CUSTOMERS CALL TODAY: 720.221.6804  |  EXISTING CUSTOMERS REQUIRING SUPPORT: 303.617.6442

X