Tag: security

Shock horror — AI-generated security patches fall short of actually solving all the problems they were meant to fix

Researchers tested AI-generated patches on six CVEs with poor success rates Many fixes failed, altered behavior, or introduced new vulnerabilities Guidance improved outcomes, leading to FLAWED evaluation harness release When using Generative Artificial Intelligence (GenAI) to fix vulnerabilities, security professionals are most of the time just robbing Peter to pay…

Read More

Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads

Attackers cloned AI skills, later adding malicious code to steal credentials Zenity Labs found millions of installs and dozens of dangerous skill variants Vercel and Microsoft removed malicious skills, but manual removal is still required AI skills, instructions that teach AI agents how to do certain tasks and thus extend…

Read More

Are your Android apps secretly sharing your location with advertisers? Some developers are accidentally leaving on this critical data-invading setting when using third-party SDKs

Some Android apps contain invasive data-gathering SDKs that gather location data without user consent Location data is then sold to advertisers, or purchased by law enforcement for targeting and tracking US citizens Developers, regulators, and legislators should work together to remove the incentive for SDKs to gather this data Monetizing…

Read More

New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit

Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealer Attackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloads Malware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems…

Read More

Watch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here’s what to look out for

Phishing campaign used fake Teams notifications to route victims to a genuine Microsoft sign-in page Rather than stealing passwords, attackers asked victims to approve permissions for an attacker-controlled app, gaining access to mail, files, Teams, SharePoint, OneDrive and calendars without defeating MFA Check Point says the technique has been commoditized…

Read More

Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets

Palo Alto Networks’ Unit 42 detailed three Google passkey exploits Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly Security researchers from Palo Alto Networks’ Unit 42 have…

Read More