AI Platforms Under Siege as Critical Flaws Exploited
Attackers exploit critical Langflow and Rails flaws for credential probing and C2 activity.
30 results for “aws”
Attackers exploit critical Langflow and Rails flaws for credential probing and C2 activity.
Patches cover three critical code injection bugs and a sandbox escape in the Now Platform.
Weekly roundup covers Log4j RCE scare, Minimus shutdown, Iranian hacker sanctions, and more.
OpenAI-led open letter urges global cyber defense surge as AI-enabled attacks grow more capable.
CISA adds six exploited flaws to KEV, including NetScaler, Linux, and SQL Server bugs.
Adobe and Nvidia address dozens of vulnerabilities, including critical flaws in AI infrastructure and GPU attack mitigations.
Chubb's 2026 Cyber Claims Report finds fewer claims but soaring average costs, driven by litigation and business interruption.
Aikido Security finds Claude Opus 4.6 repeatedly bypassed a gym's booking restrictions and altered other users' reservations in a synthetic test.
Critical MiniOrange SAML SSO flaws exploited in wild; silent patch raises risk for WordPress sites.
Broadcom patches 91 Spring vulnerabilities, with one critical flaw exposing LDAP servers to attack.
Two flaws in JFrog Artifactory could let low-privileged users tamper with package metadata and compromise software supply chains.
Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.
A Ninth Circuit decision forces platforms to fight costly early lawsuits before Section 230 immunity can apply.
CISA adds four actively exploited vulnerabilities affecting macOS, SharePoint, vCenter, and Windows IKE to its KEV catalog.
Xpander, founded by ex-AWS engineers, secures seed funding to help enterprises manage AI agents securely.
Apple ships 28-security-fix updates for macOS and iOS, covering two dozen WebKit bugs.
A weekly summary of key cybersecurity events, from a Boeing 737 hack demo to refrigeration flaws and Rapid7 layoffs.
A new Mirai-based Linux botnet uses encrypted C2, SOCKS proxies, and exploits in routers to hijack edge devices.
XM Cyber researchers chain four SCCM flaws into SYSTEM access for $58, with partial fixes leaving a path open.
Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.
Road to Battlefield competition draws record applications, 84% AI startups, and new investment prizes.
Intel and AMD release combined patches for more than 80 vulnerabilities, including high-severity issues in processors and software.
Ivanti releases updates for Endpoint Manager and Neurons for MDM addressing remotely exploitable vulnerabilities.
Passengers on Delta 591 reportedly spoofed onboard Wi-Fi after DEF CON, prompting an FBI inquiry.
August's Patch Tuesday addresses 398 vulnerabilities, including an actively exploited zero-day, as AI-driven discovery swells update volumes.
Microsoft's August Patch Tuesday fixes 421 CVEs, including one exploited zero-day and two publicly disclosed flaws.
Researchers chain AI-found flaws to gain admin on SharePoint servers, bypassing authentication entirely.
SAP's August 2026 patch batch addresses 28 flaws, including a 10/10 severity bug in Commerce Cloud that could allow attackers to bypass authentication and execute code.
Appeals court denies platforms' Section 230 bid, allowing thousands of addiction lawsuits to proceed.