Cyber Security News
Remediating Vulnerabilities With LLMs: Inside Ivantis Automation Push
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open question… Read more
Claude Flaw Automatically Sends Malicious Prompts to AI Agents
When combined with another exploit, the "PromptFiction" vulnerability, which has been fixed, could have enabled an end-to-end attack on a targeted sys… Read more
2-Click Cursor Exploit Enables Dev Environment Takeover
Simple age-old bugs give bad actors access to developers’ secrets and source code-rich environments. Read more
Ukraine warns fake CAPTCHAs are being used to make you hack yourself
Ukraine’s computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised … Read more
Best Practices
Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk
A cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that conc… Read more
GitHub’s public APIs are becoming an enterprise reconnaissance tool
GitHub continues to be a scintillating target for attackers because it sits in the middle of the software supply chain and gives threat a… Read more
GitHub AI agent leaks private repositories via prompt injection attack
A prompt injection attack can trick GitHub’s preview Agentic Workflows into retrieving content from private repositories and publishing i… Read more
Cybercriminals exploit India’s tax filing season with a dual-malware campaign
Cybercriminals are exploiting India’s tax filing season with a new malware campaign that refuses to put all its eggs in one basket. Re… Read more
New Threats and Vulnerabilities
Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents
A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no … Read more
Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs
Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining the fea… Read more
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vu… Read more
20+ Hijacked Government Websites Became?an Attack Channel
More than 20 Brazilian government websites were hijacked and turned into malware delivery channels in an active PhantomEnigma campaign uncovered by ANY.RUN, a l… Read more
Patch Management
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HT… Read more
Firefox Chrome Adobe and VMware Updates Fix Multiple Critical Security Flaws
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed … Read more
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its com… Read more
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that’s capable of harvesting sensitive data from compromised systems…. Read more
AI and Security
OpenAI hides Codex agent instructions behind encryption leaving developers in the dark
OpenAI has never been as open as its name suggests and is becoming even less so. The free-spending AI giant recently revised the multi-agent orchestration in i… Read more
IBMs mainframe sales get mugged by AI hardware panic stock sheds more than a quarter of its value
IBM says customers spooked by soaring demand for AI infrastructure raided their mainframe budgets to stockpile servers, storage, and memory instead, knocking B… Read more
AI spam filters are getting suckered by old-school text salting
Notice more spam getting through that corporate email filter lately? Attackers are using a technique known as "text salting," which hides benign-looking words … Read more