Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
In July 2025, someone registered a domain that used to belong to a content delivery network that had been wound down years earlier, and the domain was allowed to expire. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath the domain.
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version. Security firm Air Security found that the agents fetch a snapshot by commit hash but never check that the code they end up with actually matches it.
Cybersecurity researchers have discovered a cluster of 13 npm packages that deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and OtterCookie. WeaselBiscuit is smaller, lighter, and stripped down, harvesting Chrome extension storage across Windows, macOS, and Linux.
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.