Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Criminals are impersonating OnlyFans creators using AI-generated deepfakes to lure fans with fake promises of live chats. They create fake accounts on platforms like TikTok and move conversations to Snapchat, where they request Cash App payments for exclusive content.
Researchers discovered that Apple's iCloud Private Relay can be bypassed through three WebKit features: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. These features send traffic directly from the device, exposing the user's real IP address.
Researchers disclosed that Apple's iCloud Private Relay can be bypassed through three WebKit features: DNS prefetching, WebAuthn Related Origin Requests, and WebTransport. These features send traffic directly from the device, exposing the user's real IP address despite the proxy configuration.
A new class of prompt injection called AI Recommendation Poisoning abuses pre-filled deep links in AI assistants like ChatGPT and Claude. When clicked, these links execute commands that can permanently bias the AI's memory toward a vendor's domain.
A new class of prompt injection called AI Recommendation Poisoning abuses pre-filled deep links in AI assistants like ChatGPT and Claude. When clicked, these links execute commands that can permanently bias the AI's memory toward a vendor's domain.
A scam campaign uses full-screen popups impersonating Apple Support and Amazon to claim a $149.99 unauthorized purchase. The fake alerts share an identical phone number, which is a key indicator of fraud.