Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an...
Ericsson security advisory (AV26-743)
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's...
AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI...
IntroductionThe modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely...
Dear readers, The upcoming 25th anniversary of the 9/11 terrorist attacks is a time for somber remembrance and reflecting upon how the landscape has evolved with new challenges and adversaries...
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance,...
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping...
[Control Systems] Moxa security advisory (AV26-742)
Senior fellow Gary Miller spoke with Cape Cellular about the exploitation of mobile network vulnerabilities to track US personnel during the Iran war. The post How Iran Uses Cellular...
The Department of Defense’s leasing of land to private companies for artificial intelligence server farms is drawing bipartisan scrutiny from lawmakers worried about the impact on military...
Google Chrome security advisory (AV26-741)
A China-linked espionage operation compromised a Vietnamese public hospital’s X-ray and MRI imaging system, tunneled through Malaysia’s Ministry of Foreign Affairs network, and sent malware to...
Not all languages are treated equally when it comes to AI model function and safety, and European organizations face a particular risk when it comes to this reality. The modern large language...
Universities have found themselves in the firing line of cybercriminals, as ransomware attacks against higher education institutions have increased, analysis of recent incidents has revealed....
Policy targets online scammers, sextortionists, and potentially their immediate families
Let’s not start picking out uniforms just yet. The chorus calling for a Cyber Force continues to grow by the day, but the debate has its priorities backward. In June, an amendment from Sen....
Microsoft Edge security advisory (AV26-740)
A group of Russian state-supported cyber actors has been targeting and compromisingvarious Western government and commercial organizations using the ZimbraCollaboration Suite (ZCS) software since...
Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize...
The Trump administration is wrestling with how to respond to the possibility that leading Chinese tech firm Moonshot AI stole American intellectual property to create its latest artificial...
Two members of Congress have introduced bipartisan legislation that would require developers of the most advanced artificial-intelligence systems to maintain the ability to slow down, suspend or...
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a...
Authorities arrest Kratos's developer, HollowGraph hides C2 in 2050 calendar events, and OpenAI's models breach Hugging Face to steal benchmark answers.
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams...
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows...
Improper certificate validation vulnerability (CVE-2026-15243) has been found in Apereo CAS Client software.
This essay was written with Barath Raghavan, and originally appeared in The Guardian. Major benchmarks measure what AI can do. None measure whether it does what you mean: the distance between what...
Pro-Iran hackers who claimed to have disrupted Microsoft 365 in the early days of the war said Thursday that they came back for another round of “targeting systems managed by the West that are...
How a childhood of endless questions led Dominic Djannesari to a career connecting people, ideas, and security signals