Topic: Security
182 stories
- Three JFrog Artifactory bugs remain under active attack despite patches
- OpenAI agents ran an undisclosed RubyGems attack, report says
- Google reroutes search result links to curb scraping
- Google Project Zero releases MAccConc to test Linux kernel race conditions
- Bengio warns AI training process makes agents deceptive
- Anthropic details Claude misuse for weapons, mass surveillance, and Chinese distillation
- WebGPU bug freezes M-series Macs: Apple calls it not a security issue
- Proof of Capture: an open source counterpart to Apple Reference Image, using steganography
- EvoSafeHarness cuts DecodingTrust-Agent attack success from 45.6% to 10.0%
- Anthropic finds a fourth Claude incident involving unauthorized access to real systems
- Anthropic disrupts Claude-automated Russian espionage campaign
- Guardrail-stripped GLM-5.3 hacked a Wired reporter's home network
- Four hacking groups share BlueMoon exploit kit chaining Chrome and Windows bugs
- Cognition's Devin factors RSA-260, sets new factoring record
- Calif Research demos WeWorm, a zero-click WeChat worm built with AI
- Apple details how the Secure Exclave keeps Watch audio private
- Split-LLM privacy checks pass even as the gradient leaks which rows are real
- Microsoft patches a record 972 vulnerabilities, 112 critical
- LG TVs shown scanning home networks for other devices
- Hackers steal Claude tokens from paid subscribers using infostealer malware
- NixOS backdoored by trusting-trust attack on GNU strip
- GLM 5.3-flash makes autonomous AI hacking cheap, essay warns
- GamersNexus's LG TV eavesdropping claims rely on a rooted device
- Oxide publishes design for its rack-level key hierarchy
- OpenAI agents hijacked a German website, new research finds
- Interisle report finds one in five new gTLD domains are scams
- Header-based bot detection cut a blog's 'browser' traffic by 74.5%
- GrapheneOS rewrites its Messaging app interface in Android Compose
- Google DeepMind launches Fairwind Program for cyber defense
- go-tpm-tls signs TLS handshakes inside a TPM, not a key file
- Anubis ships WebAssembly proof-of-work after a year-long build
- Congress presses Pentagon on troop tracking via data brokers
- Chrome again exempts google.com from site data deletion
- Rails ActiveStorage CVE hit a state government site 8 hours after patch
- Chrome fixes actively exploited V8 sandbox bug
- OpenAI commits $1 billion in Daybreak access to protect essential services
- Abliteration.ai turns guardrail removal into a paid service
- OpenAI's Astra draws safety warnings over hidden reasoning
- Mistral explains how to opt out of Vibe and API data training
- Amazon's Alexa for Shopping now checks if a message is really from Amazon
- OpenAI's Astra becomes its first model rated Critical for cybersecurity
- OpenAI omits culture from its Hugging Face hack postmortem
- OpenAgentFlow blocks 95.3% of attacks on AI agent actions
- Hundreds of AI agents reportedly hacked OpenAI, Hugging Face
- FBI investigates Nexus, dark web seller of 153 million+ driver's licenses
- CrowdStrike and police disrupt 23-year-old Sality botnet
- Anthropic ties zero data retention on Fable 5.1 to new abuse monitoring
- Mystery freezer failures hit 14+ US military commissaries, hacking unproven
- Boston Scientific, McKesson hit by separate healthcare cyberattacks
- Valve's Steam2 leak exposes 12TB of unreleased game prototypes
- Qubes OS patches dom0 code execution flaw in qvm-copy-to-vm
- OpenAI, Anthropic and 100+ firms warn of AI cyberattacks within months
- AI agents now find security exploits within minutes of a bug rumour
- SLEEPWALKER backdoor hides inside ESET's management agent
- cohttp security patch drew exploit probes within 10 minutes
- Cara scraper turned collaborator builds Lantern, an anti-AI-scraping tool
- OpenAI rallies 100+ companies to warn of imminent AI cyberattacks on infrastructure
- Germ, a tiny new Scheme interpreter, aims to shrink Guix's bootstrap chain
- Georgia officer misused Flock cameras to track ex and a colleague
- EDB argues AI agent governance must live in the data layer
- CRPx0 gang claims victim count more than quintupled
- Claude Code's Auto Mode blocks its own malware cleanup, researcher finds
- SecOPD cuts Qwen3.6-27B prompt injection success rate from 94% to 9%
- OpenAI's unreleased model coordinated 1,000+ agents to breach Hugging Face
- FBI seizes hacking platforms it says China used against NASA, Senate
- CyberFactory turns CVEs into training data, lifts Qwen 3.5 by 22.8 points
- Python's str.lower() breaks IDNA domain encoding, CVE-2026-17084
- OpenAI bans ChatGPT accounts behind a Russian influence campaign
- C2PA camera authentication broken on Android, researcher shows
- Sleepwalker backdoor hides in Windows by posing as ESET's own agent
- OX Alpha on OpenRouter is Z.ai's GLM, analysis finds
- vLLM's eval() bug shows how a malicious LLM could control its host
- Microsoft Paint invisibly watermarks AI images with a server GUID
- Iran-linked cyberattack shut down a UK power plant
- Instinct's AI assistant raises privacy and security concerns
- Blackstone-owned Beam Living exposed applicant SSN digits
- Anthropic's Mythos 5 agent fakes apology to hide malware in UK safety test
- Sebastian Raschka explains how Claude watermarks AI text
- OpenAI slows Astra scaling after cybersecurity risk finding
- Armadin's AI swarm claims record live cyberattack test
- Researcher hijacks abandoned e164.arpa zone, logs 209,000 ENUM queries to military bases
- OpenAI previews Private Safety Processing for Zero Data Retention
- Felony Bench ranks AI labs by an 'illegal activity' score
- Claude Opus 4.6 generates explicit content in all 10 tests
- Anthropic runs Claude Security scanner on Claude Mythos 5
- Z.ai releases GLM 5.3, an open-weight model for cybersecurity and coding
- Fake LinkedIn recruiter's coding test hides a RAT and wallet stealer
- arrayref Rust crate compromised, smuggles in build-time malware
- AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint switching
- OpenAI previews Private Safety Processing for Zero Data Retention customers
- Flock built an AI tool that identifies and tracks drivers, contradicting its own claims
- Feds warn attackers use AI-generated code to hack Siemens S7 PLCs
- DiSCO cuts NSFW attack success rate by up to 37.7% in text-to-image models
- Researchers revive expired Visa cards to make payments
- Aegis stops all risky AI agent actions in sandbox test
- OpenAI details four-pillar defense plan after Hugging Face incident
- How Bluesky makes its logo appear only in screenshots
- GitHub Copilot Autofix PR opens flaw, Wiz's AI agent breaches Snowflake's Jira
- Zhipu says GLM-5.3 beats Anthropic, OpenAI at finding bugs
- OpenAI dissolves its Preparedness safety team
- OpenAI, Anthropic agents escaped sandboxes and hacked outside companies
- Microsoft blames AI bug backlog for delayed Exchange SE update
- jit moves developer secrets into a Touch ID vault on macOS
- ChainDrop worm infects 444 npm packages, evades standard defenses
- Anthropic's bio-weapons filter was down for nearly a year, exposing 133 million chats
- ShinyHunters leaks 1.6M RingCentral email addresses
- macOS screen-sharing flaw CVE-2026-65400 exploited to plant Monero miners
- Google releases HEIR, an open source compiler for private AI
- Flock tightens license plate database rules after stalking backlash
- Connecticut court flags first US case of hidden AI prompt injection in filings
- Boeing 737 can be hacked with a coin-sized $100 device
- Anthropic's Mythos and rivals could end law enforcement hacking
- Amp passes SOC 2 without pull requests
- Z.ai releases GLM-5.3, a coding model with emergent exploit skills
- Ruby 4.0 deserialization chain turns Marshal.load into RCE
- OpenAI faces safety reckoning after AI agents breached Hugging Face
- One bit-flip unlocks protected DRAM on AMD Family 16h chips
- Intel details a phased roadmap for post-quantum cryptography
- ShieldFont turns webpages into gibberish for AI scrapers
- OpenAI expands Daybreak Cyber Partner Program to security firms
- LiteLLM supply-chain attack exposes credentials from 2,500+ orgs
- IIT Bombay and Adobe researchers reconstruct LLM prompts from output text
- Dawn Song says rogue AI agents aren't evil, just eager to please
- Attackers spoof ClaudeBot and other AI bots to scan for credentials
- OpenAI brings Daybreak cybersecurity models to AWS Bedrock
- OpenAI, Anthropic, Google models leak hidden reasoning via API flaw
- DEF CON crowd suspected in fake Wi-Fi attack on Delta flight
- AI bug hunters find Zoom flaw letting anyone hijack devices on a call
- OpenAI launches GPT-5.6-Cyber for authorized vulnerability research
- Mozilla rotates GPG signing key for Firefox and Thunderbird after leak
- DEF CON's Franklin project adds MSSPs and AI digital twins to defend water utilities
- A pathologically long CPU instruction can break x86 SMM's security guarantee
- tl;dv exposed 181,874 meeting recordings for six months
- Spectre I aims to jam AI wearables that now defeat noise jammers
- HackerOne shifted from hackers to sales, a longtime bug hunter writes
- AI agent on Anthropic's Claude hacks gym site to jump the waitlist
- Zscaler: ransomware gangs now target middle managers, not the CEO
- GrammaTech's DDisasm disassembles binaries into reassemblable code
- Claude Code makes auto mode default, cites 89% attack block rate
- Claude Code, Cursor draw security, privacy complaints in new study
- Rosenbridge reveals hardware backdoor in VIA C3 x86 CPUs
- OpenAI pauses Astra over possible Critical cybersecurity risk
- OpenAI agents accidentally breached Hugging Face
- Researchers hack a kids' GPS smartwatch to spy on a WIRED reporter
- Kimi K3 escapes its sandbox during a cybersecurity test
- Hugging Face turned to China's GLM 5.2 after AI guardrails blocked its defense
- Have I Been Pwned adds Nepal as its 47th government partner
- explosive drone found near Ukrainian cargo planes at German airport
- 40,000-run study: humans miss 1 in 3 AI agent command threats
- OpenAI's Atlas browser could be hijacked to spam WhatsApp contacts, Zenity finds
- HD Moore finds new BMC bugs; some 2013 flaws remain active
- Atlassian Rovo flaws let prompt injection exfiltrate Jira and Confluence data
- Anthropic's Claude Mythos won't break symmetric crypto, blog argues
- AI can't devise new hacking methods alone, but excels with a human, researcher finds
- WebKit leaks real IP and DNS around proxy browsers, iCloud Private Relay
- OpenAI, Anthropic agents took unsanctioned action 19 times
- Mistral releases Shieldstral, a 3B open-weights safety classifier
- GLM-5.2 nears frontier AI but refuses no cyber or bio tasks
- Bugtraq relaunches at securityfocus.com under new ownership
- Researchers build a self-replicating AI worm that hijacks GPUs
- OpenAI models hacked into Hugging Face to find test answers
- Interpol: AI drove 55% of Africa's cybercrime in 2025
- IBM: 92% of AI security breaches trace back to weak access controls
- Cloudflare triages bug bounty reports with Claude Sonnet for $58 a month
- TP-Link TL-841N teardown finds hardcoded credentials that survive a reset
- OpenAI's Altman calls to 'pace' AI development after Hugging Face hack
- Apple's bug bounty inbox buried a real $200K macOS flaw under AI slop
- Lean patches kernel bug that let an AI "disprove" the Collatz conjecture
- IETF deprecates RSA and Diffie-Hellman key exchange in TLS 1.2
- IBM i's QSYRUPWD password API traced to an AES cipher
- Google pulls Nano Banana image generator from Google Earth after misuse
- Coldcard's weak-entropy bug traced to a commit message reading 'runs'
- Microsoft Copilot for Word hijacked by a self-spreading worm, unfixed after 144 days
- Google pulls Google Earth AI image editor one day after launch
- FBI: Iran-linked hackers hit water utilities in seven US states
- The Download: an LLM security flaw, a revived geothermal plant, and Project ASGARD
- OpenAI models hack OpenAI and HuggingFace to cheat an internal test
- Anthropic's Mythos AI model finds flaw that sinks NIST candidate HAWK
- Anthropic finds Claude mistook real systems for sandbox, uploaded malware to PyPI
- Hugging Face details 4.5-day breach by an OpenAI-driven agent
- FAR.AI finds Grok and Gemini easy to jailbreak, Claude resists
- Anthropic's Claude Mythos halves HAWK's security, dents AES modestly