Topic: attack vectors

  • Perplexity Comet Browser Flaw Exposed Users to System Attacks

    Perplexity Comet Browser Flaw Exposed Users to System Attacks

    Security researchers discovered a critical vulnerability in Perplexity's Comet browser, where its MCP API allowed built-in extensions to execute commands on the user's operating system, bypassing standard browser protections. The flaw could enable attackers to take control of devices or deploy ma...

    Read More »
  • Google: Cloud Breaches Driven More by Flaws Than Weak Passwords

    Google: Cloud Breaches Driven More by Flaws Than Weak Passwords

    Exploiting software vulnerabilities has replaced weak passwords as the primary method for breaching cloud environments, accounting for nearly 45% of intrusions as attackers rapidly weaponize new flaws. The window for exploiting disclosed vulnerabilities has collapsed to mere days, with attackers ...

    Read More »
  • GitHub Codespaces RCE Flaw Exposed

    GitHub Codespaces RCE Flaw Exposed

    A critical vulnerability in GitHub Codespaces allows attackers to execute remote code by embedding malicious commands in configuration files, which run automatically when a developer opens a compromised repository or pull request. The attack exploits three main vectors: automatic tasks in `.vscod...

    Read More »
  • WebMCP Tools Exposed to Agents Can Be Hijacked

    WebMCP Tools Exposed to Agents Can Be Hijacked

    Integrating WebMCP into a website to make it agent-ready creates a new attack surface, as the tools exposed to AI agents can be weaponized through prompt injection, with the responsibility for security falling on the website owner, not the agent. Chrome identifies two primary attack vectors: a "m...

    Read More »
  • CISA Mandates Federal Patch for Actively Exploited Geoserver Flaw

    CISA Mandates Federal Patch for Actively Exploited Geoserver Flaw

    CISA has mandated federal agencies to patch a critical, actively exploited vulnerability (CVE-2025-58360) in GeoServer that allows attackers to steal files via unauthenticated XML injection. The vulnerability affects GeoServer versions 2.26.1 and earlier, and federal agencies are legally required...

    Read More »
  • Apple Offers $2 Million Bounty for Zero-Click Exploits

    Apple Offers $2 Million Bounty for Zero-Click Exploits

    Apple is dramatically increasing its security bounty rewards, now offering up to $2 million for zero-click exploit chains and potential bonuses that could push payouts over $5 million, targeting vulnerabilities in its latest software and hardware. The program enhancements, including new reward ca...

    Read More »
  • How Hackers Poison AI and How to Stop Them

    How Hackers Poison AI and How to Stop Them

    Cybercriminals are leveraging AI to create sophisticated spam, malicious code, and phishing campaigns, while also directly targeting AI systems to exploit vulnerabilities. Attackers use AI to refine deceptive communications through A/B testing and exploit AI assistants and security tools, leading...

    Read More »
  • Tenable Uncovers Critical Google Gemini AI Flaws That Risked User Data

    Tenable Uncovers Critical Google Gemini AI Flaws That Risked User Data

    Tenable Research uncovered three critical security flaws in Google's Gemini AI, known as the Gemini Trifecta, which allowed attackers to manipulate the AI and steal sensitive user data without direct system access. The vulnerabilities affected components like Gemini Cloud Assist, Search Personali...

    Read More »
  • Chinese Mustang Panda Hackers Use CoolClient Backdoor to Spread Infostealers

    Chinese Mustang Panda Hackers Use CoolClient Backdoor to Spread Infostealers

    Mustang Panda has deployed an updated CoolClient backdoor with enhanced capabilities to steal browser credentials and clipboard data, targeting government entities across Asia and beyond. The malware uses new distribution methods, compromising legitimate software for initial access, and introduce...

    Read More »
  • Secure Your Windows Environments with Runtime CNAPP

    Secure Your Windows Environments with Runtime CNAPP

    Sweet Security has expanded its Runtime CNAPP sensor to include comprehensive protection for Windows cloud environments, offering visibility, threat detection, and automated investigation capabilities previously limited to Linux. The Windows sensor is engineered for cloud deployment using Rust, m...

    Read More »
  • Why Password Audits Fail to Protect High-Value Accounts

    Why Password Audits Fail to Protect High-Value Accounts

    Traditional password audits focus on compliance and complexity, missing critical risks like breached credentials, orphaned accounts, and over-privileged service accounts. A password can meet all complexity rules yet be dangerously weak if it is reused, follows a predictable pattern, or has alread...

    Read More »
  • Hackers Ditch Encryption, Focus on Data Theft and Extortion

    Hackers Ditch Encryption, Focus on Data Theft and Extortion

    Cybercriminals are increasingly shifting from ransomware to "encryptionless" extortion, stealing and threatening to release data without locking files, which bypasses traditional defenses. The primary attack methods involve exploiting unpatched software vulnerabilities and supply chain weaknesses...

    Read More »
  • OpenAI's ChatGPT Defense: Why Safety Isn't Guaranteed

    OpenAI's ChatGPT Defense: Why Safety Isn't Guaranteed

    OpenAI acknowledges that complete security for its AI-powered Atlas browser may be impossible, highlighting a core tension where the tools' useful capabilities also create significant new cyberattack risks. To proactively find vulnerabilities, OpenAI uses an AI-based automated attacker that simul...

    Read More »
  • Ransomware Profits Plummet as Victims Refuse to Pay

    Ransomware Profits Plummet as Victims Refuse to Pay

    Ransomware payment rates have hit a record low of 23%, driven by improved corporate defenses and pressure from authorities not to pay cybercriminals. Attackers are increasingly using "double extortion" tactics, with data theft involved in over 76% of incidents, though payment rates for such attac...

    Read More »
  • Vibe coding poses a security threat to enterprises

    Vibe coding poses a security threat to enterprises

    Vibe coding, which uses conversational AI to generate application code, poses a major enterprise security risk, particularly through hard-coded secrets like credentials and API keys being uploaded to public GitHub repositories and exploited by attackers. Experts like Gartner's Pete Shoard warn th...

    Read More »
  • MazeBolt Uses AI to Simulate Attacks for DDoS Security Testing

    MazeBolt Uses AI to Simulate Attacks for DDoS Security Testing

    MazeBolt's new RADAR VectorAI module uses machine learning to simulate AI-powered DDoS attacks, testing both known and novel threats that traditional methods may miss. The module addresses a gap in proactive DDoS defense by enabling continuous validation against emerging AI-crafted attack strateg...

    Read More »
  • Cybersecurity Crisis: 2 in 3 Companies Face Staff Shortages

    Cybersecurity Crisis: 2 in 3 Companies Face Staff Shortages

    Nearly two-thirds of companies face unfilled cybersecurity positions, creating critical vulnerabilities due to slow hiring and sophisticated threats, while 55% still operate with insufficient staff. A disconnect exists between security teams and leadership, with only 56% of professionals believin...

    Read More »
  • Exploit in Default Cursor Setting Runs Malicious Code on Dev Machines

    Exploit in Default Cursor Setting Runs Malicious Code on Dev Machines

    A security flaw in Cursor AI code editor allows attackers to execute malicious code silently due to the Workspace Trust feature being disabled by default. Exploitation can lead to credential theft, file manipulation, and data exfiltration, especially risky given developers' elevated system privil...

    Read More »
  • Nozomi Networks' Arc Release Boosts OT Security

    Nozomi Networks' Arc Release Boosts OT Security

    Nozomi Networks has upgraded its Arc platform to include automated threat prevention for operational technology, enabling active defense of critical infrastructure without downtime. The enhancement introduces flexible prevention modes, OT-focused threat intelligence, and seamless integration with...

    Read More »
  • Attackers Use ClickFix and PySoxy Proxying for Persistent Access

    Attackers Use ClickFix and PySoxy Proxying for Persistent Access

    Attackers are increasingly using legitimate open-source tools like ClickFix and PySoxy to establish persistent, undetected access after social engineering attacks. ClickFix tricks victims into executing malicious code via deceptive update prompts, while PySoxy provides proxying to mask command-an...

    Read More »