AI-Generated Zero-Day Exploit Targets Web Admin Tool
Google researchers found a zero-day exploit likely generated using AI, targeting a popular open-source web administration tool to bypass two-factor authentication protection.
HalluSquatting is an attack where researchers pre-compute fake repository, package, or skill names that AI coding agents predictably invent, register those names first, and load them with malicious instructions.
Google researchers found a zero-day exploit likely generated using AI, targeting a popular open-source web administration tool to bypass two-factor authentication protection.
South Staffordshire Water was fined £963,900 for failing to discover hackers hidden inside its computer network for nearly two years, resulting in the personal data of 633,887 customers and employees being published.
Changing passwords doesn't immediately invalidate old credentials across every authentication path in Active Directory and hybrid Entra ID environments, leaving a window for attackers to maintain access.
Texas is suing Netflix for allegedly collecting and sharing subscriber data with advertisers and data brokers without user consent, creating 'surveillance machinery'.
A rogue version of the CheckMarx Jenkins Application Security Testing plugin was published on the Jenkins Marketplace, containing credential-stealing malware.
Cybercriminals threaten to leak 3.65 terabytes of sensitive data from Canvas, a widely used education tech platform, after a prolonged cyberattack.
The FCC has extended its deadline for a ban on software and firmware updates for foreign-made routers and drones to January 1, 2029, citing concerns for the public interest.
A build application firewall may be the solution to prevent supply chain attacks by inspecting each package that enters the build process.
The average cyberattack costs a small- or medium-size business over $250,000, highlighting the need for affordable cybersecurity leadership solutions.