The Silent Sabotage: How MemGhost Alters AI Agent Memories
A new automated attack technique can plant persistent, invisible false memories into AI agents through a single, malicious email.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A new automated attack technique can plant persistent, invisible false memories into AI agents through a single, malicious email.
A whistleblower report alleges systemic security failures and regulatory non-compliance, sparking intense scrutiny from federal officials.
Microsoft anticipates a surge in security updates as AI-accelerated vulnerability discovery becomes the new industry standard.
A newly identified macOS infostealer leverages Apple-notarized installers to bypass system security and harvest sensitive user data.
Microsoft's latest record-breaking security cycle highlights the mounting pressures of AI-driven vulnerability discovery and exploitation.
Thousands of Hikvision devices remain vulnerable to a critical command injection flaw, drawing attention from global threat actors.
New research reveals that AI browsers can be tricked into ignoring safety guardrails by forcing them into a state of logical delusion.
New research highlights how generative AI enables low-skilled attackers to craft custom, evasive malware payloads on demand.
A coalition of 12 nations has exposed an FSB-led operation scanning global networks for vulnerable router configurations and legacy exploits.
A risk register identifies what could go wrong with AI, but only an actionable response plan ensures your team knows how to react.
Quishing attacks are weaponizing QR codes to bypass traditional security, creating a sophisticated new pathway for account hijacking.
Varonis Threat Labs launches an interactive capture-the-flag experience to teach security teams how to combat modern identity attacks.
A stealthy new attack technique is bypassing traditional security logs, allowing threat actors to compromise cloud-based infrastructure.
Cybersecurity leaders are mistaking visual dashboards for true operational survivability in an increasingly chaotic, AI-driven era.
A sophisticated China-based actor is leveraging watering hole tactics and keylogging to compromise targets across the maritime sector.
Law enforcement digital infrastructure in Pakistan has become a high-stakes battlefield for dueling foreign intelligence operations.
A single edit permission in Google Cloud's Dialogflow CX could have allowed attackers to hijack agents and steal sensitive data.
Researchers at Tracebit are utilizing context bombing to force AI models to trigger their own safety guardrails during attacks.
Federal agencies face a tight three-day deadline to patch critical remote code execution vulnerabilities in popular Joomla extensions.
A CISA postmortem reveals how a contractor's public repository leak serves as a critical guide for improving organizational security.