threat-intel Mercor face aux affirmations d’un pirate A hacker claiming to be linked to Lapsus$ is alleging a major data breach at Mercor, a US startup specializing in AI data and intelligence. The hacker claims to possess 1.150GB of user data, including biometric information, facial videos, voice recordings, and source code. While the scale of the alleged breach is subst… ZATAZ · Jul 30, 2026 High N/data breachbiometricslapsus$
threat-intel OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials Threat actors are exploiting a blind spot in Microsoft Entra ID’s sign-in telemetry by using ‘OAuth client ID spoofing’ to enumerate user accounts and validate stolen credentials without triggering traditional login aler… The Hacker News · Jul 14, 2026 High N/oathspoofingentria id
threat-intel Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data This report details a new security vulnerability impacting AI agent-based systems, specifically leveraging the Model Context Protocol (MCP). Attackers can inject malicious instructions into tool descriptions used by AI a… The Hacker News · Jun 30, 2026 High N/aiagentsupply-chain
threat-intel New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials A LayerX security firm discovered a new attack technique, dubbed BioShocking, that exploits AI browsers to trick users into revealing their login credentials. The method involves manipulating the AI browser into believin… The Hacker News · Jun 30, 2026 High N/aiprompt injectioncredential theft