Grok exfiltrates user data when malicious instructions are encrypted
Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.
Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.
Secret parameter allowed hackers to steal passwords when a target clicked on a link.
Screen-sharing bug lets remote hackers log in without a password.
Trump memo is first time gov’t has authorized private sector to perform cyberattacks.
The data was scraped and exfiltrated from 2,500 users of a compromised AI package.
A public AI tool found the dangerous Zoom flaw in under 20 prompts.
FBI Atlanta confirms it’s looking into the incident, no arrests made.
Device-bound session credentials thwart an increasingly common form of account takeover.
Phone and Bluetooth signals could turn roadside cameras into far richer tracking tools.
Why passkey apps treat Windows differently than other operating systems.
Companies treat some email domains as digital trash cans, despite the risks.
Baseboard management controllers from the world’s biggest manufacturers are a security mess.
Anthropic and OpenAI models’ unprompted actions forced halt to UK cyber tests.
A removable chip lets hackers inspect their badge—and keep using it after Defcon.
Had the hacks used conventional methods, someone would likely go to prison.
The AI chatbot was more effective at creating “exploitable trust” than the humans.
Exploits can give persistent server access that survives credential rotation and disk re-imaging.
HAWK withstood years of testing that had yet to uncover a fatal weakness found through Mythos.
Microsoft is on a mad dash behind the scenes to patch exploits before hackers find them.
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
Microsoft says tools cost less than competing ones and outperform them, too.
The government says destroying his own data during an airport interrogation was illegal.
“This is day one for cybersecurity in the age of agents,” Hugging Face CEO says.
More than one-eighth of apps analyzed contained foreign code.
Governments look at banning ransom payments in face of increasingly sophisticated threats.
The social-engineering technique has primarily been a tool of financially motivated criminals.
HiveLegacy is a “powerful primitive” that’s likely capable of other nefarious actions.
Old and forgotten “shims” Microsoft failed to revoke have made Secure Boot bypasses simple.
With residential proxies all the rage, CISA urges router users to be vigilant.
“Context bombing” tricks hacking agents into shutting down before they can do harm.
The feud between NightmareEclipse and Microsoft shows no signs of resolving soon.
Both vulnerabilities allow untrusted users to gain root privileges.
“HalluSquatting” weaponizes LLMs’ inability to say “I don’t know.”
The discovery underscores the increased effort being poured into Mac infostealers.
Starliner’s certification may be delayed to 2027, 10 years later than Boeing’s original schedule.
Telling an LLM that 2 + 2 = 5 is enough to make it follow forbidden instructions.