What if a host component outside the sandbox reads AI coding agents’ output? And what if that output is manipulated?
There’s a new twist to the old code injection attack, and this one comes with AI seasoning.
Abbott suffers two attacks in the same week, and at least one is demanding a ransom payment.
The Ecopetrol attackers demanded a ransom payment but did not deploy an encryptor.
Qilin and The Gentlemen are going at it, at the expense of SMBs facing more attacks than ever.
Someone pulled sensitive customer data from EY’s servers, but the data is yet to surface anywhere.

Researchers found Claude’s Chrome extension still contains vulnerabilities allowing fake clicks and permission bypasses despite Anthropic releasing multiple updates.
ClickLock bores its victims into complying and then steals all sorts of data.
The malware has been hiding in plain sight for half a decade, stealing all sorts of valuable secrets.
1Password partnership will mean Claude will never see the secrets or load them into its own memory.