Click any tag below to further narrow down your results
Links
Bajaj Auto and its tech subsidiary detected a ransomware intrusion that disrupted their systems, prompting immediate containment and mitigation efforts. The company hasn’t revealed the attacker’s identity, any data theft, or a ransom demand, and there’s no link yet to a recent Tata Electronics breach.
- Bajaj Auto and its tech subsidiary Bajaj Auto Technology were hit by ransomware, disrupting systems at its Pune HQ and R&D arm
- No confirmed ransom demand or data theft so far, and containment efforts appear to be working
- No evidence links this attack to the same group (World Leaks) behind the recent Tata Electronics breach
- Highlights growing cybersecurity risks facing major Indian manufacturers, even industry leaders like Bajaj
This roundup covers the Tata Electronics data breach exposing Apple and Tesla secrets, a critical FFmpeg RCE patch, and Meta’s halted keystroke-tracking AI program. It also reviews Linux AF_ALG privilege escalation mitigation, new prompt-injection tactics against LLMs, OpenClaw skill-market threats, and OpenAI’s Daybreak security tools alongside warnings of near-term AI-driven cyberattacks.
- Tata Electronics breach exposed 200,000+ internal files including Tesla and Apple product specs, potentially aiding rivals and triggering regulatory exposure
- Meta scrapped its Model Capability Initiative after discovering it had leaked employees' keystrokes, mouse movements, private chats, and performance reviews company-wide
- Role confusion prompt attacks spiked LLM jailbreak success rates from 0% to 61%, though simple "destyling" of input text cut that back to 10%
- Five Eyes agencies warn frontier AI capable of crippling cyberattacks will arrive within months, not years
In 2025, infostealer malware infected over 11 million devices and exposed 3.3 billion credentials, browser artifacts, session tokens, and system metadata. Sold as malware-as-a-service for as little as $60 a month, strains like Vidar and Lumma use sandbox detection and obfuscation to evade defenses, harvesting passwords, cookies, crypto keys, and more. Attackers then resell the data or use the stolen credentials to gain undetected access and deploy ransomware.
- Infostealer malware hit over 11.1 million devices in 2025, exposing 3.3 billion credentials and session tokens on underground markets, with kits renting for as little as $60/month.
- Vidar exploded in early 2026 to 73% of infections (up from 4th place), while 2025's leader Lumma collapsed to about 1.1%.
- Stolen data (passwords, cookies, session tokens, crypto keys, system metadata) is packaged into "stealer logs" and sold on to other criminal groups, who use it to bypass defenses and deploy ransomware.
- Victims typically have no idea they're compromised until ransom demands appear or their credentials surface for sale, since the malware evades detection via sandbox checks and obfuscation.
Check Point released updates for CVE-2026-50751, an authentication bypass in IKEv1-based Remote Access and Mobile Access VPNs that has been exploited since May and impacted a few dozen organizations, including a confirmed Qilin ransomware incident. They also patched CVE-2026-50752, a certificate validation flaw in IKEv1 site-to-site VPNs, and urge customers to move to IKEv2, enforce machine certificates, or apply the provided mitigations.
- CVE-2026-50751, an unauthenticated login bypass in Check Point's IKEv1-based VPNs, has been exploited since May 7, hitting a few dozen organizations, with at least one leading to a confirmed Qilin ransomware attack.
- A second flaw, CVE-2026-50752, allows MITM attacks on site-to-site VPNs via IKEv1 certificate validation issues, though it hasn't been seen exploited yet.
- Check Point's fix/mitigation advice: drop legacy clients, switch to IKEv2-only, enforce machine certificates, and enable updated IPS signatures.
CISA has directed U.S. federal agencies to fix a critical authentication bypass in Check Point Remote Access and Mobile Access VPNs (CVE-2026-50751) by June 11. The flaw, exploited by Qilin ransomware affiliates since early May, affects IKEv1 deployments without machine certificates. Check Point released updates and mitigation steps for unpatched environments.
- CVE-2026-50751 lets attackers bypass authentication entirely on Check Point Remote Access/Mobile Access VPNs using legacy IKEv1 setups without machine certificates.
- Qilin ransomware affiliates have been exploiting it since May 7, breaching a few dozen organizations, with exploitation spiking over the weekend.
- CISA added it to the KEV catalog and gave federal agencies until June 11 to patch, citing VPN flaws as a top ransomware entry point.
- If patching isn't immediate, mitigations include disabling legacy clients, enforcing IKEv2-only, enabling updated IPS signatures, and requiring machine certificates.