AI Coding Assistant Now a Ransomware Weapon
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
30 results for “search”
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
A single website visit can hijack NemoClaw's local Ollama model server via DNS rebinding, according to new research.
OpenAI dismantled a Russia-linked ChatGPT campaign fronting as a think tank with stolen research.
Former Yandex chief builds web-scale index for AI, backed by Accel's $26M seed.
Researcher discovers AliExpress using obsolete WebAudio fingerprinting; Firefox fix likely neutralizes it.
Cybercriminals are using fake IT helpdesk messages on Microsoft Teams to deliver a new backdoor malware, researchers warn.
Threat actor Doubloon Dredger exploits Notion and device codes to steal authentication tokens, researchers say.
Researchers show how Windows' own BTR.sys can delete security software at boot, evading blocks.
Researchers uncover 14 malicious npm packages delivering RedC2 4.0, an AI-assisted Linux backdoor, via stealthy loader.
A researcher found that encrypting malicious instructions lets Grok exfiltrate user chats and personal details.
Researchers found 40 malicious Firefox extensions impersonating Web3 products to steal wallet secrets.
Researchers find Kriminal AI service routes requests through Grok, Claude, and others via jailbreaks for as little as $12.99 a month.
Microsoft is fixing a deployment issue causing search failures in Outlook, SharePoint, and OneDrive.
Researchers say a suspected China-nexus APT used a VMware flaw to deploy ransomware as a smoke screen.
New macOS infostealer AmnesiaStealer combines credential theft with silent remote browser control, researchers report.
Researchers say ‘City-Forum’ campaign targets Salesforce and ServiceNow, possibly tied to ShinyHunters.
Fortra researchers verified ExfilSquad's access to sensitive data from 13 organizations, likely via misconfigured Power Pages portals.
Researchers have uncovered a new macOS infostealer that uses ClickFix social engineering and has stealthy remote browser control capabilities.
XM Cyber researchers chain four SCCM flaws into SYSTEM access for $58, with partial fixes leaving a path open.
A developer's habit of storing passwords in a shared Google Doc led to a search-indexed exposure of staging credentials.
A researcher's PoC bypasses Microsoft's Defender patch, granting system-level access to attackers with initial foothold.
Researchers show fake USB devices can trigger Windows to install vulnerable vendor software, granting SYSTEM privileges.
Researchers uncover 'City-Forum' campaign using a custom toolset to exploit unauthenticated guest access in Salesforce and ServiceNow.
Microsoft's August 2026 Patch Tuesday brings mandatory updates for Windows 11, adding security fixes and new features like Voice Isolation.
Researchers chain AI-found flaws to gain admin on SharePoint servers, bypassing authentication entirely.
Malicious SIM cards can force phones to leak files, drop to 2G, or crash—by abusing standard SIM commands.
Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.
Recent research shows passkey protections can be bypassed without breaking the underlying cryptography.
PortSwigger's HTTP Terminator, guided by a human, finds novel vulnerability classes and hundreds of live targets.
New research reveals how the NatJack attack class exploits fundamental design flaws in NAT, bypassing standard network protections.