News
Bedrock flaw exposes deeper cloud AI risks
2+ week, 4+ day ago (560+ words) Security researchers have uncovered a vulnerability in Amazon Web Services Bedrock's code interpreter environment, raising concerns over the robustness of isolation safeguards in generative AI systems and prompting renewed scrutiny of cloud-based development tools used by enterprises. The flaw, identified…...
CanisterWorm exploits npm accounts at scale
1+ week, 6+ day ago (644+ words) A coordinated supply chain attack targeting the Node Package Manager ecosystem has exposed a new level of automation and persistence, with threat actors hijacking trusted publisher accounts to distribute malicious code across widely used software libraries. Security researchers tracking the…...
PixRevolution malware targets Brazil’s instant payment system
3+ week, 1+ day ago (304+ words) A sophisticated strain of Android malware capable of diverting real-time payments has emerged as a major cybersecurity concern in Brazil, exploiting the country's widely used PIX instant payment platform and highlighting the risks attached to rapidly expanding digital payment ecosystems....
GlassWorm malware quietly infiltrates developer toolchains
3+ week, 12+ hour ago (248+ words) This technique exploits two common configuration features used in extension manifests, typically called extension packs and dependency links. These functions allow developers to bundle related tools or automatically install required add-ons. By manipulating these mechanisms, attackers can cause code editors…...
Researchers expose Cortex XDR detection evasion flaw
2+ week, 4+ day ago (377+ words) Cybersecurity analysts have uncovered a method that enables attackers to bypass behavioural protections in Palo Alto Networks" Cortex XDR platform, raising fresh concerns over the resilience of endpoint detection systems widely used by enterprises. According to the technical analysis, reverse…...
Firefox patch fixes critical heap overflow flaw
1+ mon, 2+ week ago (588+ words) Mozilla has issued an emergency update to its Firefox browser to address a critical heap buffer overflow vulnerability in the libvpx video codec library, urging users and organisations to apply the patch without delay. The fix, delivered through version 147.0.4 of…...
Stealit Campaign Harnesses Experimental Node.js Feature for Windows Infiltration — Arabian Post
5+ mon, 3+ week ago (434+ words) Arabian Post is a Dubai-based online news publication that provides English-language coverage of a wide array of topics, with a particular emphasis on the Middle East. Established in 2013, the platform is owned and managed by Hyphen Digital Network and caters…...
Hackbots Accelerate Cyber Risk — And How to Beat Them
9+ mon, 3+ week ago (699+ words) Security teams globally face mounting pressure as artificial'intelligence'driven "hackbots" emerge as a new front in cyber warfare. These autonomous agents, powered by advanced large language models and automation frameworks, are increasingly capable of probing systems, identifying exploits, and in some…...
Kali GPT Delivers AI Co‑Pilot for Penetration Testing
9+ mon, 3+ week ago (299+ words) Core to Kali'GPT's offering is its real'time assistance: users receive immediate diagnostics for errors encountered in tools like Nmap, along with actionable remedies. It can also generate tailored Linux commands'such as identifying files larger than 100'MB'customised to the user's needs,…...