Fake Bug Report Hijacks AI Coding Agents at Scale
"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent's inability to differentiate between content and instructions.
Aggregated from vendor advisories, security research, and industry publications.
"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent's inability to differentiate between content and instructions.
A new prompt injection attack dubbed "BioShocking" could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore an…
Microsoft announced today that it is accelerating its quantum-safe security roadmap, saying advances in quantum computing are bringing the need to replace today's encryption standa…
A campaign active since last November has been targeting Python developers building Telegram bots with trojanized Pyrogram forks that allow attackers to read arbitrary files on com…
Threat actors don't need any special authentication to reach a target endpoint — they just need to know where it is.
With its next-gen AI accelerators, the SoC vendor aims to fly high above the memory wall
SEMQ promises an abstraction layer for separating semantics from embeddings
Netgear today announced Insight 10.0, the latest version of its cloud-based network management platform, which adds new AI-powered capabilities designed to help small and midsize e…
29% of security pros were open to fully autonomous pentesting last year; now only 9% are
In this "Heard it From a CISO" video, Silverfort CISO John Paul Cunningham explains that AI in cybersecurity workflows is creating opportunities rather than eliminating jobs — and …
Separate but similar campaigns described by Microsoft and Trend Micro use malicious zip files to spread malware via social engineering and obsfucation, including blockchain abuse.
Looks like it’s going to be a long, hot cybersec summer. The latest news roundup covers how Microsoft 365 Copilot got turned into a data exfiltration tool, why the FortiBleed attac…
New Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to make the agent quietly hand over…
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock w…
Ex-employee claims this 'meets the definition of an insider threat'
61% word accuracy is progress, but the system still relies on users typing and can't yet support real-time communication. Implanted BCIs remain well ahead
DB wrangling tech needs to meet demands of AI agents, Cockroach Labs CEO Spencer Kimball tells El Reg
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found t…
A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information. [...]
Cybersecurity researchers have flagged an active browser extension campaign that is designed to steal cryptocurrency by stealthily replacing wallet addresses when unsuspecting user…
“Everybody codes” was an enterprise buzzword. In this era of AI vibe-coding and single-use coding, should everyone code? Should anyone code? John and Johna talk about enterprise st…
Linux container CLI and API for Windows applications
PARTNER CONTENT: The OCI MSA settled the architecture for optical scale-up. How fast bandwidth scales is a manufacturing question, not an architectural one
Even with lots of RAM, GPU, and fast disks, you probably don’t want it
The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New…
Business Email Compromise is more than an email scam. It's a coordinated operation involving compromised accounts, financial research, and cash-out networks. Flare explores how und…
The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware …
Proposals could open cheaper routes for purchases made through third parties
Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in w…
Teams are dealing with a truly dangerous problem — automation that works, but that no one understands.