Latest news
-
AI Security via Sonar
The refactor you could never afford
For twenty years, the case against refactoring a legacy system was an economic one, and it was hard to argue with. A system needs to improve precisely because its…
-
AI Security via Sonar
OpenAI GPT-6 Astra: An evaluation
GPT-6 Astra writes less code and quality code than GPT-5.6 Sol, and it concentrates what it still gets wrong into the tier that matters. A stronger model does not pay…
-
Threat Intel via Bishop Fox
From Fork to Framework: What Modifying Apollo Taught Us About Agent Invasion
Forking an existing C2 agent sounds faster than building from scratch. Bishop Fox learned otherwise. This post documents what happened when they forked Apollo, built a…
-
via Wired
Meta’s Copyright System Is Being Weaponized Against Albanian Protesters
After three months of daily anti-government protests—dubbed the Flamingo Revolution—the sudden mass suspension of Instagram accounts has led to fears of brigading…
-
Vulnerabilities via The Hacker News
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is…
-
Breaches via DataBreaches.net
Raon data leak: Insider leak of 1,894 cases went undetected for 4 years
Choi Won-woo reports: Internal data amounting to 1,894 cases from the Korean-type heavy ion accelerator ‘Raon,’ built with a state budget of 1.5 trillion Korean won [USD…
-
Breaches via DataBreaches.net
International Meteor Organization says cyberattack dealt ‘critical blow’ to website
Jonathan Greig reports: A cyberattack has shut down the website of the premier international organization responsible for tracking meteors. The International Meteor…
-
AI Security via SecurityWeek
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.
-
Vulnerabilities via BleepingComputer
Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates.
-
Vulnerabilities via CISA
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39964 Linux Kernel Race…
-
Vulnerabilities via CISA
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39682 Linux Kernel Improper…
-
Breaches via SecurityWeek
23 Million User Records Compromised in Gyazo Data Breach
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.
-
AI Security via Schneier on Security
Are AIs Still Struggling with CAPTCHAs?
Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful…
-
via The Hacker News
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets…
-
AI Security via The Hacker News
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the…
-
AI Security via Trail of Bits
Auditing in the age of (good enough) AI
Security firms have published numerous blog posts describing how they pointed their agent harness at a codebase and found dozens of bugs (we’re one of them). However…
-
Vulnerabilities via SecurityWeek
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
-
Threat Intel via The Hacker News
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed…
-
Vulnerabilities via Ubuntu Security
USN-8782-1: Rclone vulnerability
It was discovered that Rclone incorrectly handled unauthenticated requests to the remote control API. An attacker could possibly use this issue to execute arbitrary…
-
AI Security via Help Net Security
Bots with good manners are better at fooling people on social media
Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed…
