[tl;dr sec] #339 – Hugging Face’s Incident Report, Context Bombs, AI does Cryptanalysis
Hacker Summer Camp I’m excited about Black Hat and DEF CON next week! It’s always such a delight to catch up with friends and meet…
Hacker Summer Camp I’m excited about Black Hat and DEF CON next week! It’s always such a delight to catch up with friends and meet…
Researchers said dozens of US and Canadian firms have been targeted, however, the motivation appears to be financial rather than espionage. Source link
As the fight with Iran intensifies, the revelation earlier this month, first reported by The Financial Times — that Iran is targeting U.S. military personnel…
“For decades, governance focused on controlling who could access a system,” said Susan Stapleton, GRC expert at Pathlock. “AI agents introduce a different challenge: understanding…
Wiz Research uncovered CosmosEscape, a critical vulnerability in Azure’s flagship database service, Azure Cosmos DB, via its Gremlin API. The vulnerability could have been exploited…
American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. The company detected the incident on…
Analog Devices, Inc., a leading U.S. semiconductor manufacturer specializing in analog, mixed-signal, and digital signal processing technology, has confirmed a cybersecurity incident that led to…
Now more than ever, companies face an onslaught of cyberattacks and potential data breaches. While the core steps of incident response (containment, investigation, remediation, and…
WorkNest Secure has expanded its GuardNest platform with continuous vulnerability scanning, giving organisations ongoing visibility into security weaknesses rather than relying solely on periodic penetration…
The age of rogue AI hacker agents has arrived—but it didn’t have to happen this way. After an OpenAI agent breached the Hugging Face platform…
AtlasRAT is a modular Windows remote access trojan that uses a four-stage, fully in-memory loader chain to quietly establish TLS‑ and ChaCha20‑protected command-and-control, log keystrokes…
The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of Materials…