Cyber Security News
Fake Bug Report Hijacks AI Coding Agents at Scale
"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent’s inability to differentiate between content and instructio… Read more
Attackers Hijack Exposed AI Endpoints to Power Offensive Ops
Attackers don’t need any special authentication to reach a target endpoint, they just need to know where it is. Read more
Vulnerabilities Expose Private Data in Indian Government Systems
One critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal. Read more
In Less Than 24 Hours Attackers Weaponize Cisco CUCM Flaw
The flaw enables server-side request forgery (SSRF) and escalates privileges to root, impacting Cisco Unified CM and Unified CM SME deployments. Read more
Best Practices
Malicious Chromium extension spoofs Perplexity AI to hijack browser searches
Google has removed a malicious browser extension masquerading as Perplexity AI after Microsoft researchers found it was intercepting user… Read more
Proposed US law would make AI risk reporting a legal obligation
US lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incide… Read more
Attackers exploit Cisco Unified CM flaw weeks after patch release
A critical Cisco Unified CM vulnerability is now under active exploitation, weeks after the company issued patches warning it could allow… Read more
How a malicious AI agent skill passed security checks and reached 26000 users
A fake AI agent skill that passed security checks reached over 26,000 users through Instagram, highlighting new risks as enterprises rely… Read more
New Threats and Vulnerabilities
Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider
Summary The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this advisory in response to ransomware actors leveraging unpatched instances o… Read more
Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations
Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to dissemina… Read more
Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider
Summary The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this advisory in response to ransomware actors leveraging unpatched instances o… Read more
Patch Management
Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26000 Agents
Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 a… Read more
Attackers Exploit Three Fortinet FortiSandbox Flaws One Patched Last Week
Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on … Read more
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many … Read more
Apple Patches 30+ iOS macOS Safari Flaws Including AI-Discovered WebKit Bugs
Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit… Read more
AI and Security
Changing AI math could reduce the hardware burden researchers show
Sophisticated AI models tend to require a lot of memory and take up a lot of storage space. One of the ways to reduce that footprint involves a process called … Read more
AI agents: Cause of database sprawl And also the proposed solution
Database management work will soon be mostly automated by AI agents, just like coding, according to the CEO of Cockroach Labs, the company behind the distribut… Read more