ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.

This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough.

So the threat landscape is not getting cleaner. It is just getting more places to make the same mistake. Here’s what showed up this week.

The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

The lesson this week is not that attackers suddenly got smarter. It is that useful things keep becoming attack surfaces faster than teams learn to treat them that way.

So check what is exposed. Check what holds tokens, prompts, configs, and keys. Kill weak defaults. Patch the boring old stuff too. New tech does not cancel old mistakes; it just gives them more places to hide.

That is the useful part of weeks like this. Not panic. Better instincts. Fewer easy wins left on the table.

source: TheHackerNews