Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article reports on a zero-click vulnerability dubbed 'PleaseFix' that allows attackers to hijack AI browser agents by embedding malicious instructions in content the browser processes. The attack requires no user interaction, and researchers note that there is no straightforward fix available to mitigate the threat.
This article reports on a zero-click vulnerability dubbed 'PleaseFix' that allows attackers to hijack AI browser agents by embedding malicious instructions in content the browser processes. The attack requires no user interaction, and researchers note that there is no straightforward fix available to mitigate the threat.
This article covers the sentencing of Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, to 16 years in prison. Silnikau was held accountable for orchestrating ransomware attacks against at least 18 companies across the globe, highlighting the severe legal repercussions for such cybercrimes.
This article discusses new research showing that AI browsers from leading vendors are still vulnerable to prompt injection attacks, even after deploying various security measures. The findings indicate that no perfect fix exists, leaving users exposed to potential manipulation of AI agents through crafted prompts.
This article discusses new research showing that AI browsers from leading vendors are still vulnerable to prompt injection attacks, even after deploying various security measures. The findings indicate that no perfect fix exists, leaving users exposed to potential manipulation of AI agents through crafted prompts.
A Canadian man pleaded guilty to participating in a scheme to access company accounts at cloud storage provider Snowflake and steal data from at least 165 organizations. The attack was designed to extort millions of dollars from victims.