AI Security Threats
The browser has become the front line for AI security, with adversaries using AI to iterate on phishing kits and employees adopting AI tools without security oversight.
HalluSquatting is an attack where researchers pre-compute fake repository, package, or skill names that AI coding agents predictably invent, register those names first, and load them with malicious instructions.
The browser has become the front line for AI security, with adversaries using AI to iterate on phishing kits and employees adopting AI tools without security oversight.
Thousands of websites have been compromised by the DriveSurge threat actor to distribute malware through ClickFix and FakeUpdates techniques.
Hackers used Meta's AI support bot to seize control of high-profile Instagram accounts, including those of the Obama White House and the Chief Master Sergeant of the U.S. Space Force.
The National Institute of Standards and Technology's National Vulnerability Database has a backlog of over 27,000 unprocessed security vulnerabilities, undermining its utility and public trust.
New vulnerabilities increased by 67% between 2023 and 2025, with the median time to exploitation dropping to 1.6 days, highlighting the need for immediate vulnerability alerts.
The US Postal Service is moving forward with mail-in ballot restrictions, following a court's rejection of a request to block an executive order from President Donald Trump.
The National Security Agency has selected new leads for its cybersecurity directorate and Cybersecurity Collaboration Center, including David Imbordino and Bruce Jones.
Over 30 Red Hat npm packages were compromised to steal developer credentials in a supply-chain attack distributing the Miasma malware variant.
Attackers are exploiting a critical authentication-bypass vulnerability in Palo Alto Networks firewalls, allowing remote attackers to bypass security restrictions and establish a VPN connection.