-
The UK AI Security Institute (AISI) has reported a serious incident involving autonomous AI agents that were conducting cybersecurity evaluations. These agents crossed their intended test boundaries and performed unauthorized actions on the live intern…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft Defender’s new automatic device isolation capability has emerged as a decisive control against modern ransomware intrusions that abuse legitimate Windows binaries, as demonstrated in a recent incident at QNET where a multi-stage attack was st…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Botnet operators are systematically probing router diagnostic interfaces for OS command injection flaws, chaining default credentials, legacy CGI endpoints, and weak command execution patterns to gain full remote control and deploy Mirai‑like payloads….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A serious one-click remote code execution (RCE) vulnerability that affects Cursor, Microsoft Visual Studio Code, and Google Antigravity, an AI-assisted coding environment. This flaw could enable attackers to hide malicious commands within links embedde…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A controlled proof-of-concept by Barracuda’s Red Team has demonstrated how a compromised Microsoft 365 account with Copilot access can serve as a powerful launchpad for business email compromise (BEC). This scenario ultimately enables attackers to impe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Six newly disclosed vulnerabilities in Flowise, a popular open‑source platform for building AI agents and LLM workflows, allow unauthenticated and low‑privileged attackers to achieve remote code execution (RCE) on self‑hosted and cloud AI workflow serv…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
DarkSword’s leaked iOS exploit chain is now powering a fast‑moving server cluster that marries one‑click Safari exploitation with a convincing fake Apple ID login page, putting millions of iPhone users at risk of seamless device compromise and credenti…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT) disguised as an “undetected” version of the popular Xeno script executor. Security researchers wa…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has shut down a coordinated network of ChatGPT accounts that powered a Cambodia-based scam factory running multi-vector fraud and trafficking-linked operations, and has shared indicators with industry peers and authorities to make the network…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers have compromised the GitHub account of a Keyv maintainer, a widely used JavaScript key-value storage library, to distribute credential-stealing malware via npm packages. This ongoing supply chain attack, known as the Shai-Hulud campaign, has …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


