Security researchers found vulnerabilities in agent frameworks from AWS, Google, and Vercel. The flaws let attackers trigger agent tools directly without running the underlying AI model, potentially bypassing safety controls. This matters because it exposes a new attack surface in AI-powered applications.
Security researchers found that certain Zbtlink router models ship with a hardcoded backdoor, allowing remote attackers to gain root shell access without any authentication. The flaw affects devices using a specific firmware version and could be exploited to hijack traffic or launch further attacks. Users are advised to check their router models and apply any available security updates immediately.
The creator of the Ransom Cartel ransomware operation was sentenced to 16 years in prison for running a ransomware-as-a-service scheme. The conviction highlights the growing legal accountability for cybercriminals who enable large-scale ransomware attacks. This case signals stronger deterrence efforts against the underground economy driving such cybercrime.
Researchers discovered over 250 ClickFix domains that use browser fingerprinting to evade detection while luring macOS users into downloading malware. This technique tailors malicious content based on the visitor's browser and device, making the attacks harder to block. The campaign underscores how threat actors are increasingly using evasion tactics to target Mac users.
OpenAI has disrupted a cybercrime network operating from Poipet, Cambodia, which used ChatGPT to support multiple fraud schemes. The takedown targeted infrastructure that enabled scams such as phishing and fake investment fraud. It underscores the escalating battle between AI developers and criminals abusing AI tools.
Security researchers found vulnerabilities in Paperclip AI that let attackers run host commands by importing malicious agents. This could lead to full system compromise for users of the tool, underscoring the risks of untrusted AI agent integrations.
Researchers found trojanized npm packages that conceal command-and-control server IPs within Ethereum recipient addresses to bypass detection. The packages target software developers, posing a supply-chain risk. Developers are advised to audit dependencies and registry sources.
Security researchers have identified vulnerabilities in a car anti-theft device that could allow thieves to bypass its protections. The flaws affect the device's authentication or communication methods. This matters because it undermines vehicle security and could lead to increased thefts for affected owners.
Open VSX, a prominent open-source extension registry, removed 77 malicious "evil twin" extensions that imitated legitimate tools to exfiltrate developer data. The campaign targeted developers by tricking them into installing compromised packages, potentially exposing credentials and sensitive information. This incident underscores the ongoing security risks within open-source marketplaces.