Welcome to Indigodefense!

The best hacker and cyber security news. Contact us on LinkedIn for cyber security services.

Latest posts

Sep 20, 2026

Google Had an Undercover Analyst Inside TeamPCP as Hackers Breached a Thousand Companies

Headline image

A Mandiant persona sat in TeamPCP’s roughly 12-person CanisterWorm chat from about March 2026, WIRED reported. Australian police later arrested two alleged principal participants. The AFP said the haul included more than 500,000 users’ credentials.

Source: cyberpresso.com

Sep 19, 2026

Guest to host: escaping Docker's hypervisor

Headline image

Docker has patched a sandbox escape we reported in its hypervisor for Mac: a container can get complete read and write access to the host filesystem by running three lines of bash. Docker Desktop and Docker Sandboxes are both affected. Docker Desktop is only affected if Docker VMM is turned on in Settings. It’s a good thing we found it now, because Docker VMM is scheduled to become the default for Docker Desktop at the end of October 2026.

Sep 19, 2026

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

Headline image

An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. The installer inside the archives is a copy of the legitimate Microsoft Visual Studio CoreCLR Debugger, ‘vsdbg.exe,’  renamed and configured to sideload a malicious DLL (vsdbg.dll). The installer deploys the Rapuncel infostealer as well as the Alinubx.sys kernel driver, which is used to kill antivirus software.

Sep 18, 2026

Hacking OpenAI

Headline image

A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories On July 25, 2026, we chained two critical vulnerabilities to compromise multiple OpenAI employees’ ChatGPT accounts. With these accounts, we could then access internal OpenAI repositories, and potentially many other connectors.

Source: hacktron.ai

Sep 17, 2026

The AI hacking apocalypse is not inevitable

Headline image

While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices. By Derek B. Johnson September 17, 2026 Listen to this article 0:00 Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment. In recent conversations, cybersecurity and national security professionals  raised questions about both the technical solutions OpenAI and Anthropic use to contain their models, as well as the glaring absence of federal oversight from federal regulators or truly independent third-party review. (Image via Getty)

Sep 17, 2026

New KREMLIN Malware Bypasses Chrome and Edge Integrity Checks to Silently Install Malicious Extensions

Headline image

New KREMLIN Malware Bypasses Chrome and Edge Integrity Checks to Silently Install Malicious Extensions. Security researchers have uncovered a banking malware operation, tracked under the toolkit name “KREMLIN,” that is able to force malicious extensions into the Chrome and Edge browsers without any action or approval from the user.

Source: pbxscience.com

Sep 17, 2026

Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People

Headline image

While people around the U.S. are tearing down Flock cameras, one group of hackers went a step further: extracting the camera’s software too. Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety’s cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain the software, in the hopes that other people may copy them.

Sep 16, 2026

Enclave: DeepSeek V4.1 Flash is Now Our Best Hacking Model

Headline image

DeepSeek’s 11/11 result showed why advanced agent benchmarks need to check both the outcome and the attack path: our audit confirmed six planned exploits and found five unexpected routes. Across the full benchmark, the model used 2,349 Bash commands and almost two hours and 38 minutes of active model time. The median successful run took four minutes and 38 seconds. The provider reported 268.3 million input tokens and about two million output tokens.

Sep 16, 2026

America's Driver's License Breach Is a National Security Disaster

Headline image

In the mid-2010s, Chinese cyber espionage actors stole complementary data from a variety of sources that, together, would be useful for analyzing the U.S. intelligence apparatus. Various Chinese APT groups stole information from the health insurance company Anthem, credit reporting company Equifax, Marriott hotels, United Airlines, and, perhaps most significantly, security clearance information from the Office of Personnel Management.

Source: lawfaremedia.org

Sep 15, 2026

ConnectWise Patches ScreenConnect Vulnerability Exploited

Headline image

ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks. Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue. The bug creates “a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances,” ConnectWise explains in its advisory.