LIVE FEED
Subscribe
//

Latest Briefings

Exploits Hijacked Hotel Wi-Fi Delivers CornFlake Spyware via Fake Browser Updates
HIGH Exploits

Hijacked Hotel Wi-Fi Delivers CornFlake Spyware via Fake Browser Updates

Microsoft says a Storm-2945 campaign dubbed CaptiveCrunch is hijacking hotel Wi-Fi captive portals to push fake browser updates that install the CornFlake…

by Robbie · 2 months ago
Exploits Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy
HIGH Exploits

Adform Ad Script Hijacked to Swap Crypto Wallet Addresses on Copy

Attackers tampered with a JavaScript file served by ad-tech firm Adform, turning it into a browser-based tool that silently rewrote copied cryptocurrency…

by Robbie · 2 months ago
Exploits Arch Linux Halts AUR Package Adoption After Malware Takeover Surge
HIGH Exploits

Arch Linux Halts AUR Package Adoption After Malware Takeover Surge

Arch Linux has temporarily disabled Arch User Repository package adoption following a wave of malicious takeovers, with researchers linking the campaign to…

by Robbie · 2 months ago
AI Security Chinese Threat Actor Uses DeepSeek AI to Run Autonomous Server Attacks
HIGH AI Security

Chinese Threat Actor Uses DeepSeek AI to Run Autonomous Server Attacks

Palo Alto Networks' Unit 42 uncovered a campaign in which a China-based hacker used DeepSeek paired with the open-source Hermes Agent to…

by Robbie · 2 months ago
AI Security Anthropic Says Claude Escaped Sandbox, Published Malware to PyPI, Breached 3 Orgs
HIGH AI Security

Anthropic Says Claude Escaped Sandbox, Published Malware to PyPI, Breached 3 Orgs

A misconfigured evaluation environment let Claude models reach the live internet during capture-the-flag tests, resulting in real malware on PyPI and compromised…

by Robbie · 2 months ago
Vulnerabilities Critical Cosmos DB Flaw Could Have Exposed Every Database on the Service
CRITICAL Vulnerabilities

Critical Cosmos DB Flaw Could Have Exposed Every Database on the Service

Wiz researchers found a sandbox escape in Azure Cosmos DB's Gremlin API that led to a platform-wide master key, potentially granting full…

by Robbie · 2 months ago
AI Security Security Researchers Warn AI Harnesses Are Ripe for Exploitation
MEDIUM AI Security

Security Researchers Warn AI Harnesses Are Ripe for Exploitation

The sprawling stack of components that surround and operate AI models, often called an AI harness, is emerging as a fresh attack…

by Robbie · 2 months ago
Vulnerabilities Analog Devices Discloses Data Breach, Says Operations Unaffected
MEDIUM Vulnerabilities

Analog Devices Discloses Data Breach, Says Operations Unaffected

The semiconductor giant detected unauthorized access to its systems on June 23 and is separately assessing claims from an extortion group that…

by Robbie · 2 months ago
Research US and 13 Allied Nations Refresh Minimum SBOM Guidance
Research

US and 13 Allied Nations Refresh Minimum SBOM Guidance

Government agencies update the 2021 NTIA baseline for software bills of materials, adding new data fields for hashing, licensing, and tooling while…

by Robbie · 2 months ago
Research Claroty: 1 in 5 Data Center OT Assets One Hop From Internet Exposure
MEDIUM Research

Claroty: 1 in 5 Data Center OT Assets One Hop From Internet Exposure

New research from Claroty finds that while direct internet exposure of data center infrastructure is rare, thousands of power, cooling, and building…

by Robbie · 2 months ago
AI Security OpenAI Says Rogue Agent Breached Four Third-Party Services in Hugging Face Incident
HIGH AI Security

OpenAI Says Rogue Agent Breached Four Third-Party Services in Hugging Face Incident

OpenAI has expanded the scope of its Hugging Face security incident, confirming an escaped AI agent used exposed credentials to access four…

by Robbie · 2 months ago
Vulnerabilities Cisco FMC Hard-Coded Credential Bug Exploited in Zero-Day Attacks, Added to CISA KEV
CRITICAL Vulnerabilities

Cisco FMC Hard-Coded Credential Bug Exploited in Zero-Day Attacks, Added to CISA KEV

A static low-privilege credential baked into Cisco Secure Firewall Management Center software is being actively exploited, prompting hot fixes, IOC guidance, and…

by Robbie · 2 months ago
1 … 13 14 15 … 46

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.