Anthropic, OpenAI models go rogue during testing by UK’s AISI, attempt to poison open-source project on GitHub
Tag: EN
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the…
AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations
In one instance, an unsanctioned model attempted to inject malicious code into an open source repository.
Brazil Health Surveillance Database Exposed 79GB of Sensitive Records
Brazil’s SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password…
15 TP-Link Omada Flaws Exploit Zero-Touch Provisioning to Hijack Devices and Infiltrate Networks
Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack…
Remote Scheduled Tasks Spread EtherRAT Across Compromised Windows Domain
EtherRAT has surfaced in a Windows domain intrusion tied to an affiliate of the Gentlemen ransomware operation. The campaign shows how a single foothold…
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
Vulnerabilities in Car Anti-Theft Device
This is disturbing: …a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System,…
Samsung Debuts Next-Gen Vertical AI Memory
Samsung Electronics says V10 Bonding V-NAND tech could help increase density and improve performance for AI workloads
ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates
ScreenConnect is being systematically weaponized in the SMOKE#SCREEN campaign, where attackers hide execution windows, delete installers, and disguise…
TP-Link Zero-Touch Provisioning Flaws Could Expose Enterprise Networks, Warns Forescout
Forescout Vedere Labs research has uncovered 15 previously unknown vulnerabilities affecting TP-Link’s Omada Zero-Touch Provisioning (ZTP) ecosystem,…
15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic
TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a…
Junk Cleaner clears the clutter from your Android
The easiest way to reclaim storage on your phone. Free up space without hunting through folders or risking your important files.
ChainDrop Worm Hits 400+ npm Packages with Two Billion Monthly Installs
A new npm worm has compromised packages with over two billion monthly installs
Perplexity Overturns Amazon Bot Injunction On Appeal
Appeals panel rejects Amazon’s request for court order blocking Perplexity AI agents from accessing its service
Fake Open VSX Extensions Hijack AMD, Azure, Salesforce and Government Namespaces
Fake Open VSX extensions have hijacked high‑trust namespaces like AMD, Azure, Salesforce, Hyperledger, and a U.S. government agency on the Open VSX…
Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software…
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Execute Code Remotely
Veeam has issued security updates to address multiple vulnerabilities in Veeam ONE, including a critical flaw that could enable an unauthenticated remote…
Ukrainian Drones Strike More Wildberries Warehouses
Drones have burned down 13 Wildberries e-commerce logistics facilities over past 18 days, Ukraine officials say