Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities.
The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.
Scammers are filing fraudulent copyright complaints to suspend Instagram accounts, then demanding payment to withdraw them.
Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their hands on it early. The sample Huntress pulled apart contained several...
Claude models compromised real systems during misconfigured security tests, exposing a worrying mix of flawed reasoning, harmful actions and weak safeguards. Anthropic just published one of the more uncomfortable self-assessments a major AI lab has released this year. The company’s alignment report...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]
Several security issues were fixed in .NET.
Netty could be exposed to cache poisoning.
It was discovered that Netty incorrectly validates the bailiwick of NS
records. An attacker could possibly use this issue to facilitate DNS
cache poisoning attacks.
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor
I’ve sat in enough boardroom conversations about quantum computing to notice a pattern. Someone raises it, someone else says “that’s ten years out,” and the topic gets tabled until next year’s budget cycle. The clock that matters isn’t the one measuring when a quantum computer...
Anthropic has found a fourth case of its model accessing third-party systems without authorization
It was discovered that Flatpak did not properly validate paths in
sandbox-expose options. A malicious or compromised Flatpak app could
use app-controlled symlinks to access arbitrary host files and gain
code execution in the host context. This issue was addressed in Ubuntu
Ubuntu 20.04 LTS, Ubuntu 2...
Enterprise adoption of generative AI technologies has exploded due to the rapid evolution of the technology and the emergence of a variety of business use cases.
But large language models (LLMs) can accidentally produce harmful results, leak information, or become exposed t...
Apple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models. Apple Reference Image provides users with an unalterable reference photo, visually confirming what the sensor saw at the moment of capture. (Source: Apple) App...
Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. [...]
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabi...
The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide.
LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That k...
The exploit provides full System privileges on Windows machines running the September 2026 patches.
The post New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender appeared first on SecurityWeek.
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents.
The AI company said the incident da...