generalnews.media
All World Business Technology Science Health Sports Entertainment Security
67 stories
Exclusive

Agent Framework Flaws in AWS, Google, Vercel Allow Unauthorized Tool Use

Security researchers found vulnerabilities in agent frameworks from AWS, Google, and Vercel. The flaws let attackers trigger agent tools directly without running the underlying AI model, potentially bypassing safety controls. This matters because it exposes a new attack surface in AI-powered applications.

Exclusive

Backdoor in Chinese-Made Zbtlink Routers Allows Unauthenticated Root Access

Security researchers found that certain Zbtlink router models ship with a hardcoded backdoor, allowing remote attackers to gain root shell access without any authentication. The flaw affects devices using a specific firmware version and could be exploited to hijack traffic or launch further attacks. Users are advised to check their router models and apply any available security updates immediately.

Exclusive

Creator of Ransom Cartel Gets 16 Years for Ransomware-as-a-Service

The creator of the Ransom Cartel ransomware operation was sentenced to 16 years in prison for running a ransomware-as-a-service scheme. The conviction highlights the growing legal accountability for cybercriminals who enable large-scale ransomware attacks. This case signals stronger deterrence efforts against the underground economy driving such cybercrime.

Exclusive

ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware

Researchers discovered over 250 ClickFix domains that use browser fingerprinting to evade detection while luring macOS users into downloading malware. This technique tailors malicious content based on the visitor's browser and device, making the attacks harder to block. The campaign underscores how threat actors are increasingly using evasion tactics to target Mac users.

Exclusive

OpenAI Shuts Down Scam Network in Poipet That Used ChatGPT for Fraud

OpenAI has disrupted a cybercrime network operating from Poipet, Cambodia, which used ChatGPT to support multiple fraud schemes. The takedown targeted infrastructure that enabled scams such as phishing and fake investment fraud. It underscores the escalating battle between AI developers and criminals abusing AI tools.

Exclusive

Paperclip AI Flaws Allow Remote Code Execution via Malicious Agent Imports

Security researchers found vulnerabilities in Paperclip AI that let attackers run host commands by importing malicious agents. This could lead to full system compromise for users of the tool, underscoring the risks of untrusted AI agent integrations.

security

Malicious npm Packages Hide C2 IPs in Ethereum Addresses

Researchers found trojanized npm packages that conceal command-and-control server IPs within Ethereum recipient addresses to bypass detection. The packages target software developers, posing a supply-chain risk. Developers are advised to audit dependencies and registry sources.

Exclusive

Car Anti-Theft Device Found to Have Security Flaws

Security researchers have identified vulnerabilities in a car anti-theft device that could allow thieves to bypass its protections. The flaws affect the device's authentication or communication methods. This matters because it undermines vehicle security and could lead to increased thefts for affected owners.

Exclusive

Open VSX Removes 77 Malicious Extensions Stealing Developer Data

Open VSX, a prominent open-source extension registry, removed 77 malicious "evil twin" extensions that imitated legitimate tools to exfiltrate developer data. The campaign targeted developers by tricking them into installing compromised packages, potentially exposing credentials and sensitive information. This incident underscores the ongoing security risks within open-source marketplaces.