Click any tag below to further narrow down your results
Links
This daily digest covers a mass credential harvest via FortiBleed targeting FortiGate firewalls, new backdoors like ModeloRAT and Mistic tied to ransomware brokers, and critical data-exposure flaws in platforms such as Dify AI. It also highlights supply-chain risks in open-source CI/CD workflows, Anthropic’s Mythos model uncovering classified-system weaknesses, and industry moves on AI-driven SecOps and network-layer virtual patching.
This digest covers a range of InfoSec news, from a Salesforce data theft via a compromised Klue integration and a mass phishing campaign impersonating Boots, to the discovery of GlassWASM WebAssembly malware hidden in trojanized Open VSX extensions. It also highlights red-teaming honey pot detection, recent ASUS driver CVEs, a Dropping Elephant loader chain, and Homebrew 6.0’s new security features.
This issue covers fresh attacks on AI agent infrastructure—over 7,000 Langflow servers hit via chained bugs in LangGraph and LangChain—and a new agentjacking risk where exposed Sentry keys let attackers hijack Claude-based workflows. It also details Apple’s Beats Studio Buds wiretap patch, Gizmodo’s ClickFix malware incident, and ongoing FortiBleed fallout, plus guidance on client-side bot detection, post-quantum crypto, and microVM limits.
This roundup covers the Tata Electronics data breach exposing Apple and Tesla secrets, a critical FFmpeg RCE patch, and Meta’s halted keystroke-tracking AI program. It also reviews Linux AF_ALG privilege escalation mitigation, new prompt-injection tactics against LLMs, OpenClaw skill-market threats, and OpenAI’s Daybreak security tools alongside warnings of near-term AI-driven cyberattacks.
This digest covers new exploits in AI and enterprise platforms, including a path traversal flaw in Langflow, a ServiceNow tenant data leak, and critical Ivanti Sentry root bugs. It also highlights Anthropic’s ATT&CK mapping of AI-driven threats and evolving deepfake tactics for bypassing facial recognition.
Mozilla used Anthropic’s Mythos Preview model to scan Firefox 150’s unreleased source code and flagged 271 security vulnerabilities before release. That’s a big jump from the 22 bugs found by Anthropic’s earlier Opus 4.6 model on Firefox 148, cutting out months of manual auditing.
The article discusses a recent supply chain attack involving the popular Axios package, highlighting how an attacker installed malware without altering the original code. It emphasizes the challenges posed by AI in both coding and attacking, as automated systems can easily introduce vulnerabilities faster than traditional security measures can respond.
Vitalik Buterin highlights significant vulnerabilities in decentralized stablecoins, including their reliance on the U.S. dollar, the risks associated with oracle data, and the challenges of staking incentives. He emphasizes that these design flaws could undermine the stability of these assets over time, suggesting that future stablecoins may need to consider broader price indexes instead of being dollar-dependent.