This tutorial explains how to catch a dangerous agent skill before an agent ever runs it: review it automatically, block it in CI if it fails, and only…
Category: EN
Zoom Patches Zero-Click Code Execution Vulnerability
Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.
Two wars and a World Cup lead to epic DDoS attacks on publishers
Ukraine, Iran, and football inspire geopolitically motivated DDoS attacks, while 1 Tbps traffic jams up 519 percent
AI Genie in the Wild
When I give talks about AI genies , I use this sort of example as a hypothetical. It’s happened . The story is from Australia. Someone named Andrew tasked…
Delta investigating after someone set up fake Wi-Fi network mid-flight
The Delta flight crew switched off the aircraft’s legitimate Wi-Fi network for around 30 minutes due to the incident, according to a spokesperson.
Former BlackFile affiliates linked to extortion campaign targeting private equity
Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.
Secure development can help turn the tables as AI alters cyber landscape
A top Microsoft executive says a shift toward memory safety and other preventative measures can limit the ability to exploit flawed software.
Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages queried an Ethereum wallet to locate C2 infrastructure
AI Helps Researchers Uncover Zoom Zero-Click RCE in Less Than a Day
Researchers used public AI models to uncover ZOOMSDAY, a critical Zoom zero-click RCE exploit chain, in less than 24 hours.
The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
Organizations are rushing to implement AI without fully grasping where its legal protections begin and end.
CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’
The vulnerability-coordination project has had a rocky few years, but a key leader says it will “flourish and improve.”
Alert Fatigue Is Hitting US SOCs Hard: How to Cut Through the Noise
US SOC teams are dealing with a growing volume of alerts, while analyst time and security budgets remain limited. Too much of that time is spent checking…
78 arrests in bust of major Western Mediterranean smuggling network in Spain
The operation, conducted under a newly established Europol Taskforce within Europol’s European Centre Against Migrant Smuggling, brought together officers…
Hackers Can Turn Off Refrigeration While the Temperature Display Still Looks Normal
Claroty Team82 has uncovered 23 vulnerabilities in Copeland’s XWEB Pro supervisory controllers, widely used to manage commercial refrigeration in…
Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
Cursor fixed a pre-trust code execution path in three days then closed the report as informative
Plug and Pwn Attack Abuses Windows PnP Drivers to Gain SYSTEM With Zero Clicks
Plug and Pwn attack details that the Windows Plug and Play driver installation can lead to execution as NT AUTHORITY\SYSTEM. The technique, published by…
Enriched URL Reports: VirusTotal URL Scanning 2.0
Introduction In today’s fast-moving cybersecurity landscape, threat analysts must move beyond basic, binary reputation scores to successfully defend…
Mozilla Revokes Firefox Signing Key After Unencrypted Subkey Was Committed to GitHub
Mozilla has rotated a GPG signing subkey used for selected Firefox and Thunderbird release artifacts after an unencrypted copy of the previous subkey was…
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs.
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
