Healthcare software breach at Unlimited Technology Systems exposes 3.8 million patient records10h ago
Elastic Security Labs documents Claude Code and Cursor enabling reverse tunnels and persistence on macOS14h ago
Phishing attack on US defense supplier exposes engineering and export-controlled files via Microsoft 36518h ago
Storm-2755 AiTM phishing campaign targets Microsoft 365 accounts across healthcare and government30h ago
Google GTIG links hedge fund cyberattacks to UNC6671 extortion group using vishing and MitM phishing33h ago
LightSpy spyware expands to 13 countries including US with new router and device-wipe capabilities34h ago
AWS cryptographer claims polynomial-time quantum algorithm that could threaten post-quantum standards35h ago
Canadian hacker pleads guilty to breaching 165 Snowflake customers and stealing billions of records36h ago
Black Hat 2026: undocumented Windows Defender kernel driver and 12 AI framework CVEs disclosed36h ago
Suno adds audio watermarking and copyright detection amid RIAA lawsuits and data breach fallout40h ago
Anthropic launches inference hooks letting enterprises intercept Claude prompts via DLP servers59h ago
Researchers propose first efficient unclonable encryption scheme using quantum no-cloning theorem63h ago
Researcher finds SQL injection extraction technique via Snowflake compile-time constant folding70h ago
WebKit DNS prefetch, WebAuthn and WebTransport leak real IPs past proxy and iCloud Private Relay3d ago
Greatness PhaaS platform adds AiTM attacks to steal Microsoft 365 tokens via RingCentral spoofing3d ago
AI-generated security article incorrectly labels Elixir RCE vector as safe and ranks first on Google4d ago
Keyv and related npm packages compromised in supply chain attack affecting hundreds of millions of downloads4d ago
Researchers disclose Pass-ta-key attacks that extract Google-synced passkeys from Chrome memory4d ago
Researchers find exploitable trust gaps in AI harness frameworks from Anthropic, Google and OpenAI4d ago
N-able N-central authentication bypass under active exploitation with emergency hotfix released5d ago
Red team research shows compromised LiteLLM admin credential enables API key theft and tool-call injection5d ago
James Kettle to present AI security research and new HTTP desync findings at DEF CON and Black HatJul 30
Active credential stuffing campaign compromises accounts across 30 organisations via SonicWall devicesJul 29
Class action lawsuit challenges Ring Familiar Faces facial recognition on non-consenting bystandersJul 29
JFrog confirms AI models chained 8 Artifactory zero-days to escape sandbox and breach Hugging FaceJul 28
Study finds AI coding agents leave prompt injection payloads armed in memory files after refusing themJul 26
Security research details RCE chain via VS Code Copilot memory poisoning and apply_patch TOCTOU flawJul 24
mrmustard 0.7.4 PyPI package ships credential-stealing malware via compromised maintainer accountJul 24
Researchers find millions of California cars vulnerable to Bluetooth hijacking via shared hardcoded keyJul 23
Python Software Foundation launches Python Packaging Council with first election opening July 28Jul 23
JRuby 10.1.1.0 ships targeting Ruby 4.0 compatibility with security fixes and performance gainsJul 22
International law enforcement seizes 200 servers and arrests Kratos phishing-as-a-service operatorJul 21
Ghost Core patches critical inflation bug that let attackers mint 2 billion tokens beyond supply capJul 17
DPRK campaign hides four-stage malware in SVG files to target developers via fake coding challengesJul 17
Unpatched Shark vacuum flaw exposes cameras, Wi-Fi passwords and floor maps across 1.5M devicesJul 17
Google details Wiz acquisition integration with Gemini AI and Mandiant into agentic security platformJul 17
CISA orders federal agencies to patch actively exploited Fortinet FortiSandbox RCE flaws by July 19Jul 17
LAPD drops Flock Safety cameras after audit finds 32% false alert rate and unauthorized data sharingJul 16
FortiGuard tracks large-scale phishing campaign deploying Agent Tesla and Remcos via Lua loadersJul 16
Oracle leads bid to build Japan's air-gapped government cloud over Amazon, Microsoft and GoogleJul 16
Elastic Security Labs details TELEPUZ modular MaaS malware spreading via ClickFix and VIDAR chainsJul 15
Kaspersky exposes OkoBot multi-stage malware framework targeting crypto users across 25 countriesJul 15
White House launches Gold Eagle AI clearinghouse to coordinate critical infrastructure vulnerability fixesJul 15
Researchers find Claude Tag Slack integration can be triggered by bots to execute unauthorized actionsJul 14
Cursor IDE auto-executes malicious code when opening poisoned repos after seven months unpatchedJul 14
EU Digital Identity Wallet contributors push back on Google Play Integrity and Apple attestation requirementsJul 14
Canada's banking regulator warns banks that Claude Mythos threatens traditional patching cyclesJul 14
Ghostcommit attack hides prompt injection in PR images to steal secrets via AI code review toolsJul 14
US and allies warn Russian FSB hackers exploiting weak router security to hit critical infrastructureJul 13
Microsoft identifies GigaWiper backdoor bundling multiple wipers and ransomware into one packageJul 10
Threat actors use AI-generated PowerShell scripts for Active Directory recon to evade signature detectionJul 09
Symlink flaw lets malicious repos hijack AI coding agents across Claude Code, Cursor and four othersJul 09
Researchers find workflow-level jailbreak bypasses GitHub Copilot safety on all 816 harmful promptsJul 09
Vidar stealer campaign uses Go loaders, rogue code-signing certs, and 491 MB file inflation to evade detectionJul 09
GNU Guix patches four vulnerabilities including remote privilege escalation via substitute serversJul 09