Tag: security
Shock horror — AI-generated security patches fall short of actually solving all the problems they were meant to fix
Researchers tested AI-generated patches on six CVEs with poor success rates Many fixes failed, altered behavior, or introduced new vulnerabilities Guidance improved outcomes, leading to FLAWED evaluation harness release When using Generative Artificial Intelligence (GenAI) to fix vulnerabilities, security professionals are most of the time just robbing Peter to pay…
Read MoreExperts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads
Attackers cloned AI skills, later adding malicious code to steal credentials Zenity Labs found millions of installs and dozens of dangerous skill variants Vercel and Microsoft removed malicious skills, but manual removal is still required AI skills, instructions that teach AI agents how to do certain tasks and thus extend…
Read MoreAre your Android apps secretly sharing your location with advertisers? Some developers are accidentally leaving on this critical data-invading setting when using third-party SDKs
Some Android apps contain invasive data-gathering SDKs that gather location data without user consent Location data is then sold to advertisers, or purchased by law enforcement for targeting and tracking US citizens Developers, regulators, and legislators should work together to remove the incentive for SDKs to gather this data Monetizing…
Read MoreNew ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit
Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealer Attackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloads Malware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems…
Read MoreWatch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here’s what to look out for
Phishing campaign used fake Teams notifications to route victims to a genuine Microsoft sign-in page Rather than stealing passwords, attackers asked victims to approve permissions for an attacker-controlled app, gaining access to mail, files, Teams, SharePoint, OneDrive and calendars without defeating MFA Check Point says the technique has been commoditized…
Read MoreExperts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets
Palo Alto Networks’ Unit 42 detailed three Google passkey exploits Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly Security researchers from Palo Alto Networks’ Unit 42 have…
Read MoreRecent Posts
- The Trump phone just got a $250 price hike
- Playground Games says Fable’s story will last between ’15-20 hours’ or double that with other open-world content, and the life systems are ‘limitless’
- Our Favorite GoPro 360 Camera Is Now 40 Percent Off
- Xbox swoops in to publish Hideo Kojima’s ‘Physint’ after Sony dropped out
- Volvo XC40 PHEV is back with a new look, better sensors, and Gemini AI
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023