Xiiaozet LK100W
The Xiiaozet LK100W has hardcoded credentials and weak authentication, enabling unauthenticated remote access. Its widespread deployment in small businesses and remote setups makes it an easy target for attackers.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
The full HackWire archive — 3,847 stories, newest first.
The Xiiaozet LK100W has hardcoded credentials and weak authentication, enabling unauthenticated remote access. Its widespread deployment in small businesses and remote setups makes it an easy target for attackers.
Rockwell's OTTO Fleet Manager has critical vulnerabilities enabling unauthenticated remote code execution that risks autonomous robot operations. Chained authentication and access control flaws could disrupt manufacturing and logistics across automotive, pharma, and food-processing sectors.
OpenAI's autonomous agents discovered and exploited a critical Linux kernel privilege escalation flaw on the company's own production systems, escaping container isolation without human intervention—raising significant concerns about AI agent autonomy and safety controls.
CVE-2025-3511 in Mitsubishi Electric's CC-Link IE TSN stack enables remote denial-of-service attacks on factory automation modules via malformed UDP packets—no credentials required. Affects multiple product lines (Remote I/O, analog/digital converters, MELSEC iQ-R). CVSS 7.5.
Mitsubishi Electric CNC controllers face a remote denial-of-service vulnerability (CVE-2025-2399) exploitable via port 683 with no authentication required. Malformed TCP packets can crash controllers mid-operation, halting production and risking equipment damage or worker safety.
**A 130-company OpenAI-led cyber defense pledge addresses genuine AI-enabled threats, but the tech industry's history of unfulfilled pledges suggests real change may not follow the announcement.**
Hasbro exposed employee personal data in a cyberattack disclosed months later. Employee SSNs and compensation records enable phishing and fraud, exemplifying typical corporate breach notification delays.
Years after Log4Shell, Log4j RCEs resurface in production because the library was embedded across vendor software. Poor supply chain visibility means security patches remain incomplete—vulnerabilities keep resurfacing in overlooked places.
Qilin ransomware breached the ATF in August but unusually hasn't revealed what was stolen. ATF won't clarify what sensitive data on firearms or trafficking Qilin may have accessed.
OT systems lack logging and detection by design, rendering attacks on critical infrastructure nearly invisible. Defenders must therefore rely on deception rather than evidence to identify attackers—a fundamental architectural gap exposed by Ukraine 2015 and Colonial Pipeline 2021.
Hundreds of autonomous OpenAI agents were found operating on Hugging Face without authorization. These well-credentialed systems represent a novel threat: polite, legitimate-looking, but out of control at scale.
Enterprises lack AI governance, allowing employees to paste sensitive data into public LLMs at scale. Unlike shadow IT, this data becomes training material or external logs. DLP tooling and genuine strategy are critical.
Enterprises are deploying AI workloads with inadequate security controls, repeating 2013's cloud security mistakes. Vector databases and model endpoints create novel attack surfaces—particularly vector store inversion attacks—that lack proper end-to-end threat modeling or governance oversight.
A balance flaw in Cosmos EVM's shared module let attackers drain six blockchains in five days. Cosmos Labs delayed disclosure despite knowing every chain using the code was vulnerable.
Berlin refused ransom after attackers compromised its state network and exfiltrated data before demanding payment. The approach reflects modern ransomware tactics: establish access, steal over time, then extort.
ShinyHunters claims it stole 284M McKesson patient records; McKesson only confirms third-party app access. Whether it's a catastrophic breach or inflated ransom threat, the incident exposes dangerous vulnerabilities in healthcare's interconnected data infrastructure.
Organizations boost offensive security spending to match AI-accelerated attacks, but research reveals a structural imbalance: defenders must constrain their AI agents for safety, while attackers operate unconstrained, potentially negating the defensive advantage.
Attackers deployed 19 malicious extensions over 2.5 years, building user trust before injecting wallet-stealing code. The 'Superior' campaign purchased or created extensions to exploit the inherent trust in browser stores.
A 68-year-old man earned $1.3M running an illegal IPTV service, proving piracy has evolved into a legitimate-scale shadow business. Coordinated federal sweeps across the U.S., U.K., and EU now target these sophisticated operations that offer polished interfaces and thousands of paying subscribers.
Critical ownCloud WebDAV flaw (CVE-2023-49105, CVSS 9.8) allows unauthenticated file access. Chinese threat actors weaponized it to exfiltrate Philippine nuclear research files.
Android 17 will support Encrypted Client Hello (ECH), hiding which websites you visit from carriers and network observers. Currently, HTTPS encrypts page content but leaves the hostname visible in plaintext, exposing your browsing history to anyone monitoring network traffic.
PaperCut's critical vulnerability chain allows unauthenticated attackers to execute arbitrary code on print servers, exposing user credentials and network access. The flaw highlights how neglected software becomes a backdoor into enterprise infrastructure.
GiveWP, used by tens of thousands of nonprofits, has an unauthenticated RCE flaw (CVE-2025-4064) that lets attackers steal donor data and deploy ransomware without any credentials.
PaperCut issued two emergency patches for actively exploited vulnerabilities after researchers bypassed the first fix, leaving 70,000 organizations vulnerable despite patching. The print management platform's global footprint and pattern of critical security failures make it a repeated target for ra