C compilers silently remove security checks, creating TOCTOU vulnerabilities in production binaries4d ago
Leaked materials reveal Russian university pipeline funneling graduates into Sandworm and GRU cyber units7d ago
Security roundup: AI coding agents weaponized in ransomware attacks and supply chain poisoning in August 20267d ago
Mirage Kitten APT targets software engineers with trojanized npm packages via fake job challenges7d ago
ContextLeak attack tricks AI agents into leaking runtime context via malicious tool descriptions7d ago
Researchers train Opus-sized model that generalizes reward hacking into cyberattacks and safety evasionSep 01
Apple court filing alleges ex-engineer used confidential chip schematics with AI agent at OpenAIAug 31
Russian-linked malware campaign hides in 52 fake GitHub repos impersonating AI and security toolsAug 29
Cursor quietly removes transparency language about code indexing and metadata storage from termsAug 29
Huntress documents five North Korean operatives hired into healthcare and financial services rolesAug 26
Joint Tenable and SentinelOne analysis finds 79% overlap in edge vendors exploited by state actors and ransomware groupsAug 26
Ray CVE-2025-62593 allows RCE on developer laptops via DNS rebinding, CISA flags active exploitationAug 25
ReliaQuest confirms ShinyHunters breach was blocked at view-only access by device-trust controlsAug 24
Certighost CVE-2026-54121 lets low-privileged users compromise Active Directory domains via AD CSAug 24
JFrog Boost flaw let a single Always Allow click grant blanket shell access in Cursor and Claude CodeAug 23
Malicious PR injected wipe command into Amazon Q Developer, reached nearly 1 million VS Code usersAug 23
Apollo Global confirms data breach exposing SSNs in social engineering campaign targeting financial firmsAug 21
Percona PMM patches unauthenticated SQL execution and AWS metadata chain in Grafana ClickHouse sourceAug 20
Check Point finds Windows Defender boot driver weaponizable as kernel primitive across Windows 7 to 11Aug 20
Citrix patches critical NetScaler authentication bypass CVE-2026-19490 with 22,000 instances exposedAug 20
Guardrail-free AI platform Kriminal stitches together Grok, Claude and Llama for cybercrime servicesAug 19
Cloudflare researchers demonstrate cross-tenant memory leak in Workers via remote Spectre attackAug 19
Cloudflare finds two Tier-1 networks stripping BGP OTC attribute, undermining route leak protectionAug 18
Apple patches image-processing vulnerability exploitable for spyware across iPhones, Macs and Vision ProAug 18
Microsoft Copilot flaw let researchers extract hidden parameters and exfiltrate data via one-click linkAug 18
AI safety labs report multiple cases of models escaping test sandboxes and causing real-world harmAug 17
Black Hat USA 2026 highlights AI agent governance and attack path analysis as top security prioritiesAug 11
GitHub Copilot MitM analysis finds secrets leaking via .env files and unencrypted local chat storeAug 11
Researchers extract chain-of-thought reasoning from Anthropic, OpenAI and Google models via cross-model replayAug 11
Researchers release open-source GitHub Threat Detector with 22 detection rules for supply chain attacksAug 11
Russian hackers attack Polish heat plant via misconfigured cellular APN in first documented OT pivotAug 10
Researcher buys noreply.net and receives 700 sensitive emails per day from misconfigured systemsAug 10