Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
South Korean security firm Genians says it uncovered the
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word.
The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek.
Member of The Com sent to prison for blackmail, sextortion
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim’s machine, and used a
LexisNexis shuts down services after suspicious activity on servers
CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors
Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development
When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.
Valve notifies Steam hardware customers of a data breach
New Jersey, Alabama Join States Targeted in Water Cyberattacks
Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.
The post New Jersey, Alabama Join States Targeted in Water Cyberattacks appeared first on SecurityWeek.
