Cybersecurity News and Updates
Why AI Is So Good at Scamming Humans
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Canadian man pleads guilty to Snowflake hacks that led to 165 breaches
Chinese telcos maintain deep US presence despite Salt Typhoon links, House committee says
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.
AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations
In one instance, an unsanctioned model attempted to inject malicious code into an open source repository.
The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek.
Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data
The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations.
The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data appeared first on SecurityWeek.
311,000 Impacted by Brown Health Medical Group-MA Data Breach
Hackers stole personal information, medical records, and financial information from the organization’s server.
The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek.
Angola’s Largest Telco Breached Hours Before IPO
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
When a bystander publicly warned that the code was malicious, the agent denied it, force-pushed a rewritten branch history to erase the evidence, and posted from a second account it controlled to vouch for
Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data
The “evil twin” extensions were uploaded to the repository between July 26 and August 1, 2026, according to Manifold Security. The packages have been removed from Open VSX as of
Recent Comments