Cyber Security News
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study. Read more
GhostJacking Exposes Identity Governance Gaps in AI Agents
New research shows how attackers can use security alerts and blocked events to manipulate and hijack AI agents. Read more
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America. Read more
China-Linked Hacker Shows AI Capabilities in APAC Attack
In the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise go… Read more
Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS
The botnet adds exploitation modules, credential theft, and reverse SOCKS relays to turn compromised devices into persistent attacker infrastructure. Read more
Best Practices
Security validation should begin where attackers begin
Modern attacks increasingly begin with the web application. Customer portals, partner platforms, APIs, external business applications,… Read more
Researcher bypasses Microsoft Defender security patch seizing control
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that p… Read more
The AI harness is the new attack surface
Ask a security researcher what makes an AI agent dangerous, and the instinct is to talk about the model, what it will and won’t refuse, … Read more
Metabase SQLi exploit grants attackers total access
Business intelligence (BI) platform provider Metabase has disclosed a zero-day SQL Injection vulnerability, warning that customers’ sensi… Read more
New Threats and Vulnerabilities
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and … Read more
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies Check If You Have One
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to int… Read more
Adobe Patches Three CVSS 100 ColdFusion and Campaign Classic Flaws
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully explo… Read more
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker’s choosing. On the cellular modules built into electric-vehicle chargers, i… Read more
Patch Management
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber … Read more
Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a statement shared … Read more
AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that’s capable of hijacking Chrom… Read more
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronizatio… Read more
AI and Security
Devs to Anthropic OpenAI Cursor and friends: Make security and privacy the default
Despite the popularity of Claude Code, Cursor, GitHub Copilot, and OpenAI Codex, developers have plenty of complaints about AI coding tools. So researchers aff… Read more
UK puts Google AI on the flight path to fewer contrails
Britain is putting Google AI in the flight-planning loop to see whether airliners can dodge the patches of sky where their vapor trails are most likely to stic… Read more
Nvidias latest solution to soaring enterprise AI costs isa router?
Soaring AI infrastructure costs and model pricing, combined with uncertain returns on investment, threaten to stall enterprise adoption. To make enterprise AI … Read more