Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
METR, a research non-profit evaluating frontier AI models, disclosed two security incidents where external actors attempted unauthorized access to its systems. While no sensitive information was compromised, attackers stole an API key and consumed AI credits worth approximately $600,000.
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model's (LLM) safety mechanisms and prevent its normal functioning.
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The first vulnerability, CVE-2026-0768 (CVSS score: 9.8), allows unauthenticated attackers to execute arbitrary Python code as root due to improper input validation in Langflow.
Kaspersky researchers detail Mirage Kitten, a threat actor deploying new backdoors called NodeRabbit and PollCat. The actor targets organizations in the Middle East and uses custom malware with sophisticated evasion techniques to maintain long-term access.