Microsoft Fixes CVSS 10 Azure AI Foundry Privilege-Escalation Flaw
Microsoft has remediated a maximum-severity authentication flaw in Azure AI Foundry that could allow an unauthenticated network attacker to gain elevated privileges. The cloud-side fix is complete, but...
BragJack Lets Malicious Extensions Command AI Browser Agents Across Trusted Channels
Researchers showed that a malicious browser extension can hijack privileged communication paths used by AI assistants in five Chromium-based environments. The BragJack technique can force agent actions without...
Click2Shell Chain Turns One Malicious Link Into WordPress Server Takeover
WordPress has fixed a theme-preview weakness that can silently install an attacker-selected theme when an administrator opens a crafted link. Paired with unsafe pre-activation code in a theme,...
How a Hijacked Thai College Webpage Became a Funnel Into an Illegal Online Casino
Fraud investigators at ADEX traced suspicious ad traffic back to a compromised page on a Thai academic institution's website that Google had indexed and ranked highly, then quietly...
CISA’s Latest Advice for Defenders: Lay Traps for Hackers Before They Even Get In
CISA has published new guidance urging organizations to seed their networks with fake credentials, decoy systems and honeytokens so that any attacker who slips past perimeter defenses trips...
OpenAI Caught Its Own Models Stealing API Keys and Faking Data During Training Runs
OpenAI has disclosed six internal incidents in which models under reinforcement-learning training went looking for ways around blocked tasks — one located and used an exposed API key...
How AI Cracked Its Maker: Claude Opus 5 Helped Researchers Breach OpenAI’s Own Forum
Security researchers at Hacktron used Anthropic's newly released Claude Opus 5 to build a working exploit for a memory-corruption bug in the image library behind OpenAI's community forum,...
FBI Seizes NightmareStresser Domains After Hundreds of Thousands of DDoS Attacks
The FBI and Canadian authorities have disrupted NightmareStresser, a DDoS-for-hire service blamed for hundreds of thousands of attacks since 2022. The domain seizures are part of Operation PowerOFF...