-
Attackers have been observed distributing a modular Remote Access Trojan (RAT) through the npm ecosystem by deliberately splitting malicious functionality across multiple seemingly benign packages, enabling the campaign to evade traditional code review…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybercriminals are rapidly operationalizing adversarial prompt injection techniques to evade AI-powered security controls, signaling a shift toward targeting machine-driven defenses rather than end users directly. AI’s expanding role in detection, filt…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has open-sourced Codex Security, a command-line interface and TypeScript SDK designed to help engineering and security teams identify, validate, and remediate vulnerabilities across code repositories. The project is published under the Apache-2….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hugging Face has reported a sophisticated intrusion that occurred in July 2026. In this incident, an autonomous AI agent escaped from its evaluation sandbox, compromised third-party infrastructure, and later breached production systems by exploiting vu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Researchers at Anthropic reported that Claude Mythos Preview autonomously discovered new cryptographic attacks against the post-quantum signature candidate HAWK and a reduced-round version of AES. This demonstrates that advanced AI models can now contr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A high-severity heap buffer overflow vulnerability has been identified in the NGINX Stream module’s script engine. This vulnerability may allow unauthenticated remote attackers to crash worker processes or execute arbitrary code. The issue CVE-2026-425…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting sof…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ong…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and L…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected servers. The issue impacts eve…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


