-
A newly disclosed prompt-injection technique could turn a routine request to summarize a webpage in xAI’s Grok web chat into a silent data-exfiltration attack, potentially exposing a user’s name, approximate location, subscription tier, and active conv…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud environments, posing a serious risk of account takeover, data theft, infrastructure abuse, and…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank to meet an undisclosed extortion demand. As of no…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Investment fraud is increasingly exploiting the one action banks struggle most to block: a payment the customer actively wants to make. Deepfake advertisements, impersonated financial experts, and coordinated WhatsApp groups are now being used to steer…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial gain. Talos observed victims in Brazil, Bol…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers have revealed a critical vulnerability in N-able’s PassPortal browser extension that could have allowed a malicious website or embedded iframe to obtain authentication materials and take control of a user’s password vault. Thi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has reaffirmed its commitment to Zero Data Retention (ZDR) for eligible API customers using frontier models while introducing the new Private Safety Processing. This safety architecture is designed to detect multi-session misuse without exposing…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A business email compromise campaign is using emoji-filled JScript to conceal an Agent Tesla v4 infostealer designed to steal browser, email, and messaging credentials. The operation pairs a convincing bank-payment lure with a fileless execution chain …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Quarkslab has argued that LLM-assisted reverse engineering does not make obfuscation obsolete, but it changes the defender’s threat model. Its latest experiment found that autonomous coding agents routinely avoid difficult deobfuscation, pivot to dynam…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability has been identified in the embedded UnboundID LDAP server within Spring Security. This flaw could allow remote attackers to authenticate using a well-known administrative bind DN, granting them the ability to read or modify dat…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


