With one AI firm disclosing agent risk to investors and another facing a hacking suit, liability for runaway models is up for grabs.
OX Security says 101 packages abuse a WhatsApp library to sign victims' bot sessions up for groups they never chose.
Google and Mozilla pushed new builds fixing 32 Chrome flaws and roughly 76 Firefox bugs in a single day of…
A resend-timer mistake in OpenSSL's UDP handshake can hand leftover heap bytes to the other side of a DTLS session.
Glow Security traced thousands of internal images to AI coding agents that routed private screenshots through public repos.
Researchers show a practical Spectre v2 variant that harvests stale branch predictions left behind by just-in-time compilers.
A Kremlin-tied crew tied to the FSB is trading hand-aimed spear-phishing for bulk runs that plant its CosmicPulse backdoor.
Attackers pulled Polish national ID numbers from a clinic platform through a SQL injection flaw.
The Defense Manpower Data Center left unencrypted records open to intruders for nine months.
A malicious MCP server can redirect a client's OAuth handshake and pocket the secrets.
The toolkit let intruders hold ground inside telecom, university and government networks.
An out-of-bounds write in Apple's drawing engine was aimed at a targeted few.
A frontier model failed its own safety audits and will not ship in October as planned.
Dutch detectives are holding a 24-year-old Amsterdam man over the ShinyHunters extortion crew.
Ninety active accounts produced most of Exploit.in's traffic, and the habits they built still shape today's ransomware crews.
UNSW researchers fine-tuned five language models on 57,000 drunk texts and watched their guardrails dissolve.
Prosecutors say Oxygen Forensics kept Russian shareholders off the paperwork while selling hacking tools to US agencies.
Microsoft says Storm-2570 swaps ransomware payloads but never swaps its tools, handing defenders a stable set of behaviors to hunt.
Two public reports on the DC health finance agency's website carried personal data in fields no visitor was meant to…
Nvidia's Open Agent Safety Platform pairs a sandbox runtime with a separate hardware monitor that can stop a stray AI…
Ardit Kutleshi admitted in a US court to running the Rydox cybercrime marketplace for a decade.
Asus says an intruder reached part of its eShop and may have taken customer contact details and order records.
Proofpoint linked 28 Microsoft 365 tenant intrusions to unrotated service accounts still holding default passwords.
Aikido Security found GitLab's per-user issue email doubles as a non-expiring token that can commit code as the account owner.