A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured…
INTERPOL flags AI as the new engine of African cybercrime
Africa’s growing digital economy is exposing governments, businesses and internet users to a rising wave of cybercrime. The continent recorded more than…
AI Agents Targeted Real People and Projects During Cybersecurity Tests
AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects.
AI agent deception moves from theory to reality in UK cyber tests
“During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK’s AI Security Institute…
Decades-Old BMC Vulnerability Exposes Data Centers
A critical security flaw affecting baseboard management controller (BMC) systems has left over 24,000 server management interfaces exposed to potential…
Tuskira expands exposure management with Agentic Control Plane
Tuskira has launched its Agentic Control Plane for Exposure Management, a new capability within the Tuskira platform that governs AI-discovered…
Prompt Injection Remains Biggest LLM Risk, Despite Limited Incidents
Prompt injection remains the most dangerous security threat to LLMs, according to OWASP’s latest Top 10 LLM Applications list
Code review used to be the only way to catch these bugs
An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one…
311,000 Impacted by Brown Health Medical Group-MA Data Breach
Hackers stole personal information, medical records, and financial information from the organization’s server.
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them…
UK charities count the cost of Beacon CRM cyberattack
Database backups likely stolen, potentially exposing donor, supporter, and service user details
Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks
Over time, passkeys are supposed to replace passwords. But what happens when malware steals the master key?
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No…
Anthropic, OpenAI Models Involved In More Hacking Incidents
Anthropic, OpenAI models go rogue during testing by UK’s AISI, attempt to poison open-source project on GitHub
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the…
AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations
In one instance, an unsanctioned model attempted to inject malicious code into an open source repository.
Brazil Health Surveillance Database Exposed 79GB of Sensitive Records
Brazil’s SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password…
15 TP-Link Omada Flaws Exploit Zero-Touch Provisioning to Hijack Devices and Infiltrate Networks
Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack…
Remote Scheduled Tasks Spread EtherRAT Across Compromised Windows Domain
EtherRAT has surfaced in a Windows domain intrusion tied to an affiliate of the Gentlemen ransomware operation. The campaign shows how a single foothold…
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
Vulnerabilities in Car Anti-Theft Device
This is disturbing: …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System,…
Samsung Debuts Next-Gen Vertical AI Memory
Samsung Electronics says V10 Bonding V-NAND tech could help increase density and improve performance for AI workloads
ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates
ScreenConnect is being systematically weaponized in the SMOKE#SCREEN campaign, where attackers hide execution windows, delete installers, and disguise…