Cline Kanban Flaw Lets Websites Hijack AI Coding Agents
Oasis Security finds critical Cline kanban WebSocket flaw exposing AI coding agents to hijack
20 articles
Oasis Security finds critical Cline kanban WebSocket flaw exposing AI coding agents to hijack
Commercial AI models were used to help plan and conduct cyber-attack against operational technology of a water and drainage facility, say researchers
Sophos finds fake Claude site spreading DonutLoader and a new Beagle backdoor via DLL sideloading
A China-linked threat actor backdoored a version of Daemon Tools to infect thousands
Traditional network security tools are undermining data protection, with Forrester and Capital One Software research warning AI adoption is impossible withou...
Cofense has warned of a “significant” increase in phishing campaigns abusing Vercel platform
Cisco Talos uncovers CloudZ RAT and Pheno plugin abusing Microsoft Phone Link to intercept SMS OTPs
CISA’s CI Fortify initiative aim for critical infrastructure operators to build isolation & recovery
Rapid7 reveals an Iranian false flag operation masquerading as a Chaos ransomware attack
Cifas says that 13% of employees admit selling company credentials to a former colleague
Microsoft researchers warn of a large-scale phishing campaign using fake compliance emails to steal credentials, targeting 35,000 users across 13,000 organiz...
ESET warns that North Korean hackers compromised a Yanbian gaming site in a supply‑chain attack, trojanizing Windows and Android software to spy on users
Venomous#Helper attackers impersonate the US Social Security Administration to deploy signed RMM software and maintain persistent access across US networks
ISACA report warns that while AI has become the norm, many organizations are yet to formally apply safety or security policies around its use
The UK's National Cyber Security Centre is urging organizations to prepare for glut of new software updates
Security vendor Trellix has suffered a breach involving unauthorized access
Team Cymru’s Stephen Campbell warned that small US defense contractors are not well prepared to face cyber intrusions through edge devices
OpenAI announced its intention to expand the Trusted Access for Cyber program for cyber defenders at the federal, state and local government levels
Claude Security enters public beta, giving enterprises AI driven code scanning with no API integration or custom agents required
The cybersecurity workers used their knowledge and skills to conduct ransomware attacks for notorious gang, rather than protect victims against them