Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Researchers Buy 'No Reply' Domains and Get Company Data
1+ hour, 2+ min ago (221+ words) Cory Solovewicz, a security researcher and consultant, laid out the problem at the Defcon security conference this week. He registered noreply.us in 2020, intending to use it as a personal catch-all (an inbox that accepts mail sent to any address…...
Metabase Zero-Day Exposes Framework, Tally Customer Data
1+ hour, 15+ min ago (235+ words) Two companies told customers this week that their personal data had been stolen. Neither was breached directly. The attacker walked in through the analytics dashboard, which was both wired to their production databases. Laptop maker Framework and form builder Tally…...
Public Exploit Lands for WordPress XSS2Shell Core Flaw
1+ hour, 40+ min ago (217+ words) A working proof-of-concept exploit for "XSS2Shell" is now circulating publicly, raising the stakes on a WordPress Core flaw that turns a single failed login into attacker-controlled JavaScript — and, against an administrator, full server takeover. A Python-based exploit tool that walks through…...
Meta AI Breach Turns Spotlight on Testing Firm Irregular
1+ day, 23+ hour ago (381+ words) Meta confirmed on Wednesday that one of its AI models reached the open internet and hacked a third-party service during a security evaluation. It is the third such admission from a major AI lab in weeks — and the second traced…...
The New Attack Surface: How Cybercriminals Are Using AI to Target Developers
2+ day, 1+ hour ago (645+ words) Cybercriminals are increasingly targeting developers in attacks. One of the major factors behind the trend is access. Developers often work on a wide range of internal and external projects. Compromising a developer's system can give a cybercriminal a way into…...
Researchers Chain WordPress RCE to Fileless Linux Root
2+ day, 22+ hour ago (186+ words) cyberkendra.com Security researchers have shown that the critical wp2shell WordPress flaw doesn't have to stop at a web shell — it can be chained all the way to full Linux root, without writing a single file to disk. More striking, they…...
Mac Malware Checks Your GPU Before Showing Its Lure
2+ day, 22+ hour ago (169+ words) The crews behind a long-running macOS scam have started doing something defenders usually do: vetting who is on the other end of a connection before committing to an attack. Microsoft Threat Intelligence says a ClickFix operation pushing the MacSync and…...
Human Reviewer Caught AI Agent's Malware Pull Request
3+ day, 16+ hour ago (386+ words) The thing that stopped an AI agent from poisoning a public open-source project last month wasn't a firewall, a classifier, or a sandbox. It was one suspicious developer who decided to detonate a strange script in a throwaway container before…...
Cloudflare Gives AI Agents a Wallet and a Spending Cap
4+ day, 1+ hour ago (400+ words) Cloudflare has started handing out wallet handles to its customers, and the pitch sounds like a convenience feature: let your AI agent buy the API it needs without pinging you for a credit card. Read the fine print, though, and…...
npm Worm Hits keyv and cacheable, Spreads to 400 Packages
4+ day, 2+ hour ago (701+ words) A self-propagating worm tore through the npm registry on Tuesday morning, trojanizing the widely used keyv and cacheable caching libraries and spreading to more than 400 packages within hours. Wiz Research, Socket, and Microsoft Threat Intelligence are all tracking the campaign,…...