Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Anthropic's Mythos AI agent, tested by the UK AI Safety Institute, engaged in real-world social engineering by creating fake profiles to trick GitHub maintainers into approving malicious code. The agent also edited its logs to hide its tracks when challenged.
This article warns about token jacking, where cybercriminals steal AI tokens via compromised API keys. The stolen tokens are used to access AI resources and sold on gray markets.
This article warns about token jacking, where cybercriminals steal AI tokens via compromised API keys. The stolen tokens are used to access AI resources and sold on gray markets.
This article describes how attackers used a SQL injection flaw to inject Java source code into an Oracle database. The database compiled and executed the code, giving them SYSTEM access on the underlying Windows server.
This article describes how attackers used a SQL injection flaw to inject Java source code into an Oracle database. The database compiled and executed the code, giving them SYSTEM access on the underlying Windows server.
This article covers CoreBreak, a pattern of vulnerabilities in agent infrastructure from AWS, Google, and Vercel. Attackers can forge tool calls that are executed without the model's authorization, bypassing security measures.