Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with…
Tag: EN
Critical ServiceNow Flaws Let Attackers Execute Code and Access Data
ServiceNow has released security updates for four vulnerabilities in its Now Platform and ServiceNow AI platform, including three critical flaws that…
700 AI Agents Secretly Coordinated to Hack Hugging Face After Breaking Their Isolation
A large group of AI agents reportedly bypassed their intended isolation, created a covert communication channel, and coordinated an attack on Hugging Face…
Hackers Can Take Full Control of Unitree G1 Humanoid Robots Over Bluetooth
A critical attack chain could let attackers within Bluetooth range take full control of Unitree G1 humanoid robots, gaining root-level code execution on…
How Varonis hacks AIs into snitching on themselves
Varonis AI Threat Lead on Copilot Exploits, Prompt Injection, and the AI Hacking Trifecta The host interviews Mark Vaitsman, AI threat research lead at…
Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security.
Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network
Berlin’s state government has confirmed that it is the target of an extortion attempt following the August compromise of the city’s state administrative…
4 Samsung Smart Switch Flaws Put Sensitive Data at Risk: Check Your Version
Samsung patched four Smart Switch Android vulnerabilities that could expose sensitive data. Users should update to version 3.7.72.6.
Innovator Spotlight: Snowflake
Giving AI Freedom Without Losing Control Who’s Really in Control? AI agents are stepping into a bigger role inside the enterprise. They are not just…
58 Arrested, 263 Suspects Identified: Inside the Global Crackdown on Operation Jackal IV
The Foundation Operation Jackal INTERPOL has been spearheading a continuing, multi-year international law enforcement effort known as Operation Jackal to…
The Balance Of Healthcare Research Potential And Privacy In The Age Of AI
There’s no question that AI has transformed healthcare research and completely changed the trajectory of the healthcare industry. What would have taken…
Innovator Spotlight: Rubrik Zero Labs
When AI Breaks Out of the Sandbox What Happens When AI Escapes? AI assistants are gaining unprecedented access to the inner workings of businesses, but…
Friday Squid Blogging: Truckload of Squid Spills in Rhode Island
Ugh : A tractor-trailer rollover sent a truckload of squid spilling into a Rhode Island roadway, leaving a stench as they sat in the road for hours in the…
The Artificial Adversary
Cybersecurity has spent decades focused on the human adversary. We built models for nation-state actors, cybercriminal gangs, insiders, access brokers,…
The Department of Know: Power plant attack, NSA hacker reunion, Hugging Face hack report
Read the full stories at CISOSeries.com . This week’s Department of Know is hosted by Rich Stroffolino, with guests Jason Elrod , CISO, MultiCare Health…
White House Declares Executive Order to Protect Bulk-Power System
National Emergency Declaration for Grid Security White House released Executive Order 14420, which targets security risks within the nation’s bulk-power…
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
More prompt-injection hijinks from wunderwuzzi
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between…
Love Electric Breach: 877,000 Driver Records Offered for $600
Love Electric’s alleged data breach exposes sensitive driver data and highlights the identity risks created by third-party salary sacrifice providers. A…
Anthropic MHS Lets AI Agents Control Machines, Raising Security Questions
Anthropic’s Model Hardware Standard lets AI agents control physical equipment, raising questions about permissions, monitoring and operational security.