Grok tricked into leaking user data
A researcher found that encrypting malicious instructions lets Grok exfiltrate user chats and personal details.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A researcher found that encrypting malicious instructions lets Grok exfiltrate user chats and personal details.
Ransom Busters, a fake recovery firm, steals victims' ransom payments that were meant for the original criminals.
Two flaws in JFrog Artifactory could let low-privileged users tamper with package metadata and compromise software supply chains.
ToxicPanda 2.0 and GoldDigger expand targets with automated fraud and credential theft.
Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.
US agencies warn hackers are exploiting Siemens PLCs in critical infrastructure with AI-generated scripts.
UK NCSC issues interim guidance urging sandboxing, human oversight, and access limits for agentic AI systems.
US defense contractors report record-high self-assessed cybersecurity scores, but confidence in their accuracy drops sharply.
An open database from ClarityCheck exposed 9M+ facial images, risking identity theft and phishing.
Japanese cloud and data center provider Sakura Internet says up to 1,360,563 member accounts may be exposed in a hack.
ICE reminds employees that personal Meta glasses are prohibited workplace body-worn cameras
The Linux Foundation's Akrites initiative plans to launch its vulnerability disclosure and remediation platform in September.
Joint advisory warns of AI-powered attacks exploiting Siemens S7 PLCs across critical infrastructure sectors.
As 'De-Flock America' trends, CEO apologizes for police misuse of ALPRs amid 46 documented abuse cases.
Microsoft's Defender Experts linked 30+ domains via behavioral patterns, shifting Mac malware defense strategy.
PHANTOM-B framework aims to make AI threat modeling fast enough for busy teams, but experts warn against skipping fundamentals.
Xfinity's WiFi Motion turns routers into motion sensors, but privacy questions loom over data sharing and retention.
Attackers are exploiting critical MLflow and FUXA vulnerabilities to steal cloud credentials and execute code.
A critical AIT-GUI vulnerability could let attackers send commands to NASA spacecraft and instruments without authentication.
CISA orders federal agencies to fix actively exploited Ray bug in 3 days, citing unique risk.