Researchers found trojanized npm packages that conceal command-and-control server IPs within Ethereum recipient addresses to bypass detection. The packages target software developers, posing a supply-chain risk. Developers are advised to audit dependencies and registry sources.
Security researchers have identified vulnerabilities in a car anti-theft device that could allow thieves to bypass its protections. The flaws affect the device's authentication or communication methods. This matters because it undermines vehicle security and could lead to increased thefts for affected owners.
Open VSX, a prominent open-source extension registry, removed 77 malicious "evil twin" extensions that imitated legitimate tools to exfiltrate developer data. The campaign targeted developers by tricking them into installing compromised packages, potentially exposing credentials and sensitive information. This incident underscores the ongoing security risks within open-source marketplaces.
A vulnerability in Apple's WebKit engine can expose users' real IP addresses and DNS queries, bypassing proxy protections in browsers and iCloud Private Relay. This undermines privacy tools meant to hide user location and activity. Users should apply security updates to mitigate the leak.
The Greatness phishing-as-a-service platform has added a device code phishing technique that bypasses multi-factor authentication and steals access tokens. This method tricks users into submitting codes on attacker-controlled devices, allowing session hijacking even with MFA enabled. Organizations should update training and monitoring to address this evolving threat.
Cybercriminals are tricking users with fake Adobe and Zoom update prompts that install ScreenConnect, a legitimate remote access tool, granting persistent control of infected systems. This enables attackers to maintain long-term access and potentially steal data or deploy further malware. Users should only download updates from official sources to avoid this threat.
Cybercriminals are exploiting "vibe hacking"—a casual, conversational approach to programming AI—to quickly generate effective attack code. This trend lowers the technical barrier for adversaries, making AI a more accessible and dangerous weapon for launching cyberattacks.
Google removed three Agent Development Kit (ADK) workflows after discovering a malicious GitHub issue could potentially trigger a privileged agent. The flaw could have allowed unauthorized actions in the AI agent environment. The takedown highlights security concerns in AI-powered workflow automation.
Security researchers have found that some conversations from Anthropic's Claude AI chatbot are appearing in Google search results. These chats were likely shared via public links and indexed, raising privacy and data exposure concerns.