loader image
Jira Tickets Used to Breach AI in Cato Networks Test

Security researchers at Cato Networks have demonstrated how Jira tickets used in internal workflows can become attack vectors through prompt injection exploits. The proof-of-concept attack, dubbed “living off AI,” reveals how external inputs can manipulate AI-driven systems that interface with enterprise applications. The attack leverages seemingly benign content embedded in Jira tickets, which AI tools […]

CISA Warns TP-Link Router Flaw Hit in Live Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has issued an alert about a security flaw affecting several outdated TP-Link router models. The vulnerability is currently being exploited in the wild, increasing the risk for organizations that still rely on the discontinued devices. CISA Warns TPLink Router users to take immediate action to protect their networks […]

China Hackers Spoof Certs to Deploy ShortLeash Malware

A cyber-espionage campaign with ties to China has deployed a new backdoor dubbed ShortLeash, using fraudulent digital certificates to evade detection. The campaign, identified as “LapDogs,” has targeted specific organizations by embedding the malware within seemingly legitimate software updates. Analysts say China hackers spoof certs to disguise malicious payloads and gain unauthorized access to systems. […]

Google Offers Imagen 4 AI Art Tool Free on AI Studio

Google Offers Imagen 4, its latest text-to-image generation model, for free access exclusively through its AI Studio platform. The company confirmed the rollout of the advanced tool, positioning it as a significant step in making generative AI more accessible to developers and creators. Imagen 4 represents Google’s most sophisticated image synthesis model to date. It […]

Malware in AI Models on PyPI Hits Alibaba Users

Malicious actors have embedded malware within artificial intelligence models uploaded to the Python Package Index (PyPI), with a specific focus on compromising users affiliated with Alibaba’s AI Labs. The attack involves the distribution of seemingly legitimate AI models that, once downloaded, execute hidden malicious code on the target systems. The tactic exploits the growing reliance […]

Hackers Hijack AI Tools to Launch Malicious Payloads

Hackers are exploiting misconfigured artificial intelligence tools to launch sophisticated cyberattacks by generating malicious AI-powered payloads, according to researchers at Sysdig. These intrusions leverage exposed APIs, unsecured machine learning environments, and open-source platforms like Jupyter and TensorFlow to gain unauthorized access. Once inside, attackers use the compromised AI infrastructure to create dynamic, context-aware malware, phishing […]

Anthropic MCP Flaws Expose AI to Secret-Leaking Hacks

Researchers have disclosed critical security flaws in Anthropic’s Model Context Protocol (MCP), highlighting the risk of stealthy exploitation in production environments. According to newly published findings, attackers can execute Full-Schema Poisoning attacks, injecting malicious logic into any schema field within MCP. This vulnerability enables adversaries to manipulate model behavior without detection during development or testing […]

Salesforce Fixes 5 Flaws, Blames Users for 16 More

Salesforce has patched five software bugs after a series of issues were reported, the customer relationship management (CRM) provider confirmed. The company said it addressed the vulnerabilities internally and emphasized that the remaining 16 reported concerns were the result of customer-side misconfigurations, not flaws in its platform. The disclosure follows heightened scrutiny of cloud application […]

Microsoft Adds Export Tool to Windows Recall in EU

Microsoft has introduced a new export feature for its Windows Recall tool in Europe, giving users the ability to back up snapshots of their digital activity. The update allows individuals to manage and preserve their Recall data more securely, addressing privacy concerns tied to the tool’s automatic screen capture function. Microsoft Adds Export Tool aims […]

Crypto CEO’s Zoom Slip Costs Him $200,000 in Scam

A cryptocurrency executive inadvertently exposed sensitive information during a Zoom call, leading to a costly breach that unraveled his digital life. The incident occurred when the CEO shared his screen during a virtual meeting, unknowingly revealing private access credentials. The mistake provided cybercriminals with a gateway into his accounts, resulting in the loss of $200,000. […]

Chinese Hackers Forge LAPD Cert in Infrastructure Hit

A cybercrime group resembling a typhoon in reach and disruption has constructed a network of more than 1,000 compromised devices, according to a new report. The attackers, identified as Chinese hackers, forged an apparently legitimate TLS certificate claiming to be signed by the Los Angeles Police Department (LAPD), in an effort to disguise malicious traffic. […]

Cisco Flags 10.0-Rated Flaws in Identity Software

Cisco has issued an urgent warning regarding critical security flaws in its Identity Services Engine (ISE) platform, with vulnerabilities rated at the highest severity level. The company flagged the issues as part of its latest security advisory, stating that the flaws could allow remote attackers to execute arbitrary code on affected systems. Cisco flags 10.0 […]