topic · 81 stories

Security

Breaches, vulnerabilities, and the defenses that matter.

+follow topic ← all stories
Abstract geometric representation of software supply chain dependencies in green and gray tones Security US military-targeted apps contain Chinese and Russian code More than one-eighth of apps targeting US troops include third-party code from adversarial nations, creating potential supply chain vulnerabilities in military mobile infrastructure. 21 Jul 26 3 min Abstract geometric patterns representing security vulnerability documentation in forest green tones Security Linux kernel publishes over 400 CVEs in 24 hours A sudden surge in Linux kernel vulnerability disclosures highlights shifting security practices or accumulated technical debt in foundational infrastructure. 21 Jul 26 3 min Abstract illustration of data streams and musical waveforms in muted green tones Security Suno AI music platform breach exposes 55 million user accounts A major breach of an AI-driven consumer platform demonstrates that AI companies handling user data face the same security challenges as traditional services. 21 Jul 26 2 min Abstract illustration representing compromised VPN network security Security Palo Alto GlobalProtect VPN vulnerability exploited in Qilin ransomware attacks A critical authentication bypass flaw in widely deployed enterprise VPN infrastructure is now being weaponized by a known ransomware operation. 21 Jul 26 3 min Abstract illustration of layered geometric shapes suggesting system privilege levels Security Windows LegacyHive zero-day receives unofficial patches from third-party security researchers Windows systems remain vulnerable to privilege escalation attacks until Microsoft ships official patches, leaving admins to evaluate third-party remediation. 21 Jul 26 3 min Abstract illustration of web infrastructure network with threat indicators Security WordPress critical vulnerability under active exploitation with public proof-of-concepts A critical flaw affecting the world's most popular content management system is being actively exploited with dozens of public attack tools available. 20 Jul 26 3 min Abstract illustration of connected enterprise systems with vulnerability Security Estée Lauder data breach traced to Oracle E-Business Suite vulnerability A flaw in widely deployed enterprise resource planning software exposed HR data at a Fortune 500 company, highlighting third-party platform risk. 20 Jul 26 3 min Abstract illustration of network security layers with breach points Security SonicWall SMA1000 zero-day vulnerabilities exploited for weeks before disclosure Two unpatched flaws in widely deployed enterprise VPN appliances allowed attackers to install custom malware before vendors became aware. 20 Jul 26 3 min Abstract illustration of data structures being obscured, suggesting encryption of AI infrastructure Security JadePuffer autonomous AI agent deploys ransomware targeting AI training data and model checkpoints Attackers now use autonomous AI agents to encrypt AI infrastructure assets including training datasets and vector databases, escalating threats to organizations deploying machine learning. 20 Jul 26 2 min Abstract illustration of fragmented containers with organic elements suggesting security boundary escape Security Cursor, Codex, Gemini CLI, and Antigravity AI coding tools vulnerable to sandbox escape attacks Popular AI coding assistants allow attackers to escape security sandboxes by writing files that host tools later execute, potentially compromising developer workstations. 20 Jul 26 2 min Abstract illustration showing calendar grids with hidden data pathways Security HollowGraph malware uses Microsoft 365 calendars as command-and-control channel Attackers now exploit legitimate calendar features in compromised Microsoft 365 accounts to hide malicious communications within everyday business activity. 20 Jul 26 3 min Abstract illustration showing nested geometric forms representing hidden data within calendar infrastructure Security Microsoft 365 calendars exploited as command-and-control infrastructure in espionage campaign Attackers are weaponizing trusted Microsoft cloud services to evade detection, hiding espionage commands in calendar appointments scheduled decades into the future. 20 Jul 26 3 min Abstract illustration of code execution security boundaries and isolation layers Security OpenCode raises security concerns about VSCode extension execution Developer tools that execute code from remote repositories without clear isolation boundaries introduce supply chain risks to local development environments. 20 Jul 26 3 min Abstract illustration of fragmented database architecture representing data loss Security Romania's entire land registry database wiped by hacker A successful attack on a national land registry threatens property rights and legal certainty for an entire country's real estate system. 20 Jul 26 3 min Abstract representation of scattered financial data and compromised user records Security Paidwork user database with 23 million records leaked online A database containing bank account numbers, payout histories, and personal details for 23 million users of a gig economy platform is now publicly accessible. 20 Jul 26 3 min Abstract representation of autonomous AI systems navigating infrastructure networks Security Hugging Face breached via autonomous AI agent system An autonomous AI agent breached a major AI repository, exposing internal datasets and credentials — a new attack vector combining AI capabilities with traditional intrusion methods. 20 Jul 26 3 min Abstract visualization of AI-assisted security vulnerability research process Security WordPress remote code execution vulnerability discovered using AI-assisted research A security researcher used AI tools to discover a WordPress vulnerability valued at $500,000 by exploit brokers, demonstrating AI's growing role in vulnerability research. 20 Jul 26 3 min Abstract network visualization showing security vulnerability in enterprise platform Security ServiceNow AI Platform critical vulnerability now under active exploitation A critical code execution flaw in ServiceNow's enterprise AI platform is being actively exploited, threatening organizations using the widely deployed IT service management system. 20 Jul 26 3 min Abstract illustration of compromised network infrastructure Security ViPNet Update Mechanism Exploited to Target Russian Government Agencies Supply chain attacks targeting secure networking software demonstrate how trusted update mechanisms become high-value vectors for government espionage. 19 Jul 26 3 min Abstract representation of hidden mechanisms and discovery Security XZ Backdoor Documented in New Book 'Half a Second' The 2024 XZ Utils supply chain attack—one of the closest calls in open-source security—now has a comprehensive written account examining how it was discovered and stopped. 19 Jul 26 3 min