MCP Servers: A New Secret-Leak Vector
Model Context Protocol servers can expose enterprise secrets via plaintext configs, over-permissioning, and prompt injection, often undetected.
30 results for “ge”
Model Context Protocol servers can expose enterprise secrets via plaintext configs, over-permissioning, and prompt injection, often undetected.
GE and Philips confirm probing Clop breach claims as the gang's PTC Windchill attacks ripple through enterprise giants.
AI is supercharging both bug discovery and bug creation, driving patch counts to record highs — and reshaping how software gets fixed.
A two-stage exploit chain can achieve full Android kernel access on Unisoc devices via VoLTE video call, with no patch.
A threat actor is selling millions of records allegedly stolen from Azure tenants of major companies.
Zhipu's new AI model outperforms Western rivals on a cybersecurity benchmark, signaling China's rapid advance.
A major outage hit Claude.ai, Claude Code, and Claude Cowork on August 16, with services restored by evening.
Swiss messaging firm Threema faced sustained DDoS attacks this week, with changing tactics challenging defenses.
Corma's AI agents stopped a live attack in under 10 minutes while its CEO walked his dog, showing defenders can keep pace.
Arrests in Brazil and Europe follow a €30M bank fraud exploiting a service provider's software flaw.
Anthropic details how Claude’s watermarking works, addressing evade, edit, and code concerns.
AI coding startup Cursor officially joins SpaceX, gaining access to its vast GPU fleet as part of a $60B deal.
Researchers say ‘City-Forum’ campaign targets Salesforce and ServiceNow, possibly tied to ShinyHunters.
Aurora and Kodiak get permits to test autonomous trucks on California highways, ending a state ban.
Marco Arment's new app makes reminders impossible to dismiss, scaling snooze intervals to keep tasks visible until done.
Fortra researchers verified ExfilSquad's access to sensitive data from 13 organizations, likely via misconfigured Power Pages portals.
Google will let users remove visible watermarks from AI generations while keeping invisible SynthID and C2PA metadata.
A weekly summary of key cybersecurity events, from a Boeing 737 hack demo to refrigeration flaws and Rapid7 layoffs.
A new Mirai-based Linux botnet uses encrypted C2, SOCKS proxies, and exploits in routers to hijack edge devices.
SecurityOracle's new Database Security Central tool is free until February 2027, arriving amid rising database attacks.
A growing backlog of unresolved vulnerabilities is not a security problem but an organizational failure of ownership, capacity, and decision-making.
New batch of Apple threat notifications flags mercenary spyware attacks, urging users to take them seriously.
Ukraine shuts down 94 fraudulent call centers, seizes $2M and equipment, targeting investment scams and bank fraud.
Jewelbug hackers run espionage and crypto fraud from the same control panel, targeting government webmail.
Major acquisitions by Bank of America, CrowdStrike, and Cyera signal continued consolidation in cybersecurity.
Google Cloud's roadmap targets SNDL risk by 2027, with signatures and key management by 2028.
Bluesky's new CEO and COO will argue open protocols can reboot social media at TechCrunch Disrupt 2026.
Fortinet resolves eight flaws, including high-severity authentication bugs in FortiWeb and FortiManager.
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.
Threat actors are exploiting a critical SharePoint authentication bypass after Rapid7 released a PoC exploit.