Australia opens inquiry after OpenAI agent breached health portal

A research agent got past controls on a government statistics portal, prompting a taskforce review and questions about how slowly OpenAI reported it.

The Latest

Breaking News and Alerts

Arista tells customers to patch a VeloCloud orchestrator flaw now

A CVSS 10.0 input validation bug in on-premises VeloCloud Orchestrator is under active exploitation, and fixes cover only two of four release trains.

Spotlight

Cybersecurity Profiles and Stories

Malware hides in a B-tree library now that npm blocks install hooks

A malicious npm package pulled two million weekly downloads while running its payload from ordinary library code instead of an install script.

TASK#STOMP hides a document thief behind Windows’ own tools

A PowerShell backdoor built from native Windows components steals business files, Wi-Fi passwords and clipboard contents while hiding as scheduled system tasks.

A single line break turned a WordPress comment into a server shell

An anonymous commenter could plant a script that ran in an administrator's browser and, from there, uploaded a web shell to the site.

A nested-virtualization bug lets ARM64 guests touch host memory

A skipped cache invalidation leaves a freed page of host memory mapped and writable for a guest virtual machine on ARM64 hosts.

Features

Research and Thought Leadership