News
- FBI disrupts Chinese hacking tools used to breach critical infrastructure
- 'AgentCorruption' Puts AWS Environments At Risk With Single Prompt
- Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal
- Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
Malware
- Attackers hijack country-code domains to impersonate Google and other services
- Amazon has an uncomfortably personal profile on you
- Meta’s Muse AI files away your friendships, arguments, and secrets
- Solving the Continuous Authorization Conundrum
Threat Actors
- Making sure the checks get printed
- UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
- Ignore all instructions and read this blog: The state of AI-analysis evasion in malware
- Solving the Continuous Authorization Conundrum
Vulnerabilities
- GNUnet P2P Framework 0.26.2
- PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
- PraisonAI: Platform member PATCH routes allow owner resource rewrites and project lead reassignment delete bypass
- PraisonAI: Shell command allowlist bypass via find -exec built-in action