AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit.
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit.
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines.
The Open Secure AI Alliance has announced plans for the Shared AI Findings Exchange (SAFE)
Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access to...
Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm cred...
Elastic Security Labs identified the return of Shai-Hulud. Attackers compromised the keyv maintainer and deployed CHAINDROP, a worm that uses stolen npm cred...
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated.
We're honored to announce that Cloudflare is the only vendor that has been recognized as a Visionary in both the 2026 Gartner® Magic Quadrant™ for SASE Platf...
Modern attacks increasingly begin with the web application. Customer portals, partner platforms, APIs, external business applications, and AI-powered service...
Seventy-seven malicious extensions impersonating legitimate developer tools were discovered on the Open VSX marketplace, transmitting system and development ...
Fifteen new vulnerabilities were discovered in the zero-touch provisioning (ZTP) systems used by TP-Link’s Omada networking ecosystem, with researchers warni...
CAF Bank restored its online banking service after a prolonged outage lasting more than 10 days, which the bank attributed to attempted fraud and a subsequen...
Apple restored Telegram to its App Store after a brief removal due to reported child sexual abuse material.
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE ...
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on undergr...
Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sit...
Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services.
A long‑running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposi...
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security expla...
A recently disclosed Linux local privilege-escalation vulnerability, tracked as CVE-2026-64531 and referred to as OVSwrap, affects the kernel’s Open vSwitch ...