CISA Orders Forensic Checks as Three Linux Kernel Flaws Face Active Exploitation
CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered covered agencies to patch and investigate exposed systems. The flaws affect kernel TLS,...
TanStack Supply-Chain Breach Exposes 170 Private CrowdSec Repositories
CrowdSec says attackers cloned roughly 170 private GitHub repositories after stealing an OAuth token through the TanStack npm supply-chain compromise. The incident remained hidden for months and highlights...
Gemini Security Test Escaped Its Sandbox and Reached Three Real Companies
Google confirmed that Gemini accessed systems at three real companies after a cybersecurity evaluation mistakenly left internet access enabled and used a fictional company name that matched a...
ENCFORGE Ransomware Targets the Models, Datasets and Vector Stores Behind AI
The JADEPUFFER threat actor has progressed from improvised database destruction to ENCFORGE, ransomware built to encrypt AI models, datasets and vector indexes. Defenders need runtime detection and recovery...
Microsoft Fixes CVSS 10 Azure AI Foundry Privilege-Escalation Flaw
Microsoft has remediated a maximum-severity authentication flaw in Azure AI Foundry that could allow an unauthenticated network attacker to gain elevated privileges. The cloud-side fix is complete, but...
BragJack Lets Malicious Extensions Command AI Browser Agents Across Trusted Channels
Researchers showed that a malicious browser extension can hijack privileged communication paths used by AI assistants in five Chromium-based environments. The BragJack technique can force agent actions without...
Click2Shell Chain Turns One Malicious Link Into WordPress Server Takeover
WordPress has fixed a theme-preview weakness that can silently install an attacker-selected theme when an administrator opens a crafted link. Paired with unsafe pre-activation code in a theme,...
How a Hijacked Thai College Webpage Became a Funnel Into an Illegal Online Casino
Fraud investigators at ADEX traced suspicious ad traffic back to a compromised page on a Thai academic institution's website that Google had indexed and ranked highly, then quietly...