AI Infrastructure Needs Automatic Containment as Attacks Accelerate Beyond Human Response
AI-connected environments can let autonomous attacks progress faster than analyst-led response processes can contain them. Security leaders should redesign controls around isolation, short-lived identities, behavioral sequences and tested...
Crafted PNGs and RTSP Playlists Expose VLC Users to Memory Corruption and Data Leaks
Two VLC Media Player flaws can trigger heap corruption through a malicious PNG or leak process memory through a hostile RTSP server. Versions 3.0.0 through 3.0.23 are affected,...
Plesk Backup Restore Race Opens a Path From Customer Access to Linux Root
A race condition in Plesk Obsidian’s Backup Manager can let a low-privileged hosting customer cross tenant boundaries and ultimately obtain root access on Linux servers. Administrators should install...
Cloud and SaaS Resilience Starts With Identity, Dependency Mapping and Tested Recovery
Cloud and SaaS adoption has replaced a clear network perimeter with overlapping identity and supplier dependencies. Organizations can limit cascading failures by mapping concentration risk, prioritizing exposed systems,...
Russia-Aligned Group Tests Prompt Injection to Blind AI Malware Scanners
A Russia-aligned campaign used a malicious script comment designed to trigger an AI model’s safety refusal and interrupt malware analysis. The GuardBreaker technique, found in a MATCHBOIL delivery...
Mantax Otax Android Ransomware Adds Screen Spying, OTP Theft and Covert Photos
New Android malware called Mantax Otax combines file encryption with surveillance, credential theft, screen recording and covert camera access. The campaign relies on sideloaded APKs and appears focused...
Critical CSF Flaw Exposes cPanel Servers to Unauthenticated Command Execution
A critical flaw in ConfigServer Security & Firewall can let remote attackers execute commands through its optional MESSENGER service without logging in. Administrators using CSF 14.00 through 16.29...
CISA Flags CVSS 10 GitLab File-Read Flaw Under Active Attack
CISA says attackers are exploiting a critical GitLab path-traversal vulnerability that can expose arbitrary server files without authentication. Organizations should patch immediately, review access logs, and treat exposed...