A Chinese-linked cyber espionage group known as Fire Ant has compromised Cisco routers and authentication infrastructure to steal credentials and…
Category: EN
Hasbro Data Breach Impacts Employee Personal Information
The Hasbro Company has notified its employees that their personal information could have been exposed as a result of a data breach involving one of their…
ServiceNow Patches 3 Critical Code Injection Vulnerabilities
Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.
How We Find Critical Vulnerabilities with GLM 5.3 and Red Clippy
Over the last few months our red team exercises for BFSI customers have been run with an AI coding agent sitting in the loop. The findings that came out…
ShinyHunters claims 284M patient records from McKesson
McKesson, a major U.S.
Secure AI Systems: Defending Enterprise Applications Against Agent-Era Threats
The rise of autonomous AI agents within business software demands a fresh approach to security. Unlike earlier chatbot tools, modern agents act with real…
Debian votes to allow AI-assisted coding
The Debian Linux distribution community has formally adopted a policy allowing the use of generative AI tools in software development, following a vote…
McKesson Confirms Data Breach as Attacker Deadline Looms
The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems.
Anthropic Warns Claude Users of Infostealer Infections
Anthropic has begun forcibly logging users out of Claude AI accounts and removing stored payment data after detecting widespread infostealer malware…
HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This…
Hugging Face Incident: AI Agent Access Lessons
A recent security incident at Hugging Face, a major AI platform and model repository, has prompted security leaders to reconsider how they manage access…
Security Hardening Assessment: Prepare for AI Transformation Without Increasing Risk
As organizations accelerate AI adoption, AI introduces new security considerations, but it can also amplify existing weaknesses such as excessive…
Judge Rules Pentagon’s Anthropic Measures Illegal
A federal judge has determined that the Pentagon acted illegally when it designated artificial intelligence company Anthropic as a supply chain security…
Chrome and Edge Extensions Strip CSP and Inject JavaScript to Drain EVM, Solana and Tron Wallets
Research identified 19 malicious browser extensions 18 for Google Chrome and 1 for Microsoft Edge that use a modular malware framework to strip website…
China-linked Fire Ant Hides Inside Trusted Infrastructure
Fire Ant hijacked Cisco routers, stole credentials and altered logs to hide its tracks, using trusted infrastructure to reach high-value networks.…
AWS Console Private Access can block sign-ins to personal accounts
The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28…
Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut…
What the Hugging Face Incident Teaches Security Leaders About AI Agent Access
Security teams must treat autonomous agents as highly privileged identities.
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the…
OpenClaw 2.0 Released With Enhanced AI Agent Security and Credential Protection
OpenClaw has launched version 2.0, offering a major overhaul of its AI-agent platform. This update emphasizes streamlined deployment, a rebuilt browser…
