An AI agent found 21 zero-days in FFmpeg for $1,000. Chrome just patched a record 429 bugs.
An AI agent found 21 zero-days in FFmpeg for $1,000. Chrome just patched a record 429 bugs.

A security startup’s autonomous AI agent found 21 previously unknown vulnerabilities in FFmpeg, the open-source media library embedded in almost everything that touches video. The startup, depthfirst, says the run cost roughly $1,000 in compute. Some o…

Former IBM cybersecurity exec accuses company of covering up years of Chinese hacking
Former IBM cybersecurity exec accuses company of covering up years of Chinese hacking

A former IBM cybersecurity executive has accused the company of concealing multiple data breaches by Chinese state-linked hackers. William Barlow served as IBM’s vice president of threat intelligence until August 2019. In a whistleblower lawsuit unseal…

FIFA World Cup 2026 is a cybercriminal’s dream, and the scams are already live
FIFA World Cup 2026 is a cybercriminal’s dream, and the scams are already live

The most oversubscribed sporting event in history is also the most phished. With more than 150 million ticket requests in the first 15 days and just six million seats across 16 cities in the US, Canada, and Mexico, the 2026 FIFA World Cup has created e…

While tech week talks AI, Scytale is talking about what’s actually killing deals
While tech week talks AI, Scytale is talking about what’s actually killing deals

The conversation at this year’s NY Tech Week is about AI. The panels, the pitch decks, the happy hours: agents that code, agents that sell, infrastructure for the agents. Then a screen mounted to a truck shows a man sitting on a toilet, staring at his …

Publishing professionals are becoming prime targets for impersonation
Publishing professionals are becoming prime targets for impersonation

An aspiring author receives an email from a “literary agent” expressing enthusiasm about their manuscript. The message is polished, personalized, and professional. The sender references recent bestsellers, adaptation potential, and submission strategy….

A single GitHub issue could have hijacked Anthropic’s own Claude Code action and poisoned every project that uses it
A single GitHub issue could have hijacked Anthropic’s own Claude Code action and poisoned every project that uses it

The attack starts with a GitHub issue. Not a sophisticated one. Just an issue opened by a bot account with a carefully worded body that looks like an error message. When Claude Code’s GitHub Action picks it up for triage, it follows the instructions hi…

A popular OpenAI Codex tool with 29,000 weekly downloads has been quietly stealing developer tokens for a month
A popular OpenAI Codex tool with 29,000 weekly downloads has been quietly stealing developer tokens for a month

The npm package looked legitimate. It had an active GitHub repository, steady development history, and roughly 29,000 weekly downloads. For developers using OpenAI Codex, it offered exactly what it advertised: a remote web UI for the AI coding tool. Bu…

One click on GitHub.dev is all it takes to hand over your private repositories
One click on GitHub.dev is all it takes to hand over your private repositories

Every developer who has ever pressed the period key on a GitHub repository, launching the convenient browser-based VS Code editor known as GitHub.dev, has unknowingly accepted a bargain. In exchange for a lightweight coding environment, GitHub silently…

Hackers brute-forced Dashlane’s two-factor authentication and downloaded encrypted password vaults
Hackers brute-forced Dashlane’s two-factor authentication and downloaded encrypted password vaults

Dashlane disclosed on Sunday that an external attacker launched a brute-force attack against its two-factor authentication system, successfully bypassing 2FA protections on fewer than 20 personal plan user accounts and downloading copies of their encry…

Hackers hijacked Instagram accounts by asking Meta’s own AI chatbot to reset the password
Hackers hijacked Instagram accounts by asking Meta’s own AI chatbot to reset the password

Hackers hijacked Instagram accounts over the weekend by tricking Meta’s own AI-powered support chatbot into granting them access. The attack required no access to the victim’s email, no phishing link, and no malware. The hacker simply asked the chatbot…