News Archive
1926 stories · page 44 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

AI Genie in the Wild
When I give talks about AI genies, I use this sort of example as a hypothetical. It’s happened. The story is from Australia. Someone named Andrew tasked OpenClaw to book gym classes for him. And…. Minutes later, his AI agent reported it had discovered a way to book Andrew into classes several weeks in advance, far beyond what was supposed to be possible. Andrew, who was sitting fourth on a waitlis

The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It
Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. The post The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It appeared first on SecurityWeek.

Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages queried an Ethereum wallet to locate C2 infrastructure

Cursor Security Bug Allowed Repositories to Execute Commands Before Trust Verification
Cursor fixed a pre-trust code execution path in three days then closed the report as informative

Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]

Vague Task, Total Access: When AI Delegation Becomes a Security Risk
AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. [...]

Arctera enhances Unified Platform for evidence-driven compliance workflows
Arctera has announced new capabilities to the Arctera Unified Platform enabling organizations to manage complex governance requirements by connecting signals, controls and response workflows across the compliance lifecycle. These capabilities help organizations create a more complete and defensible record of compliance activity. Compliance teams are expected to do more than identify potential issu

Water sector example added to the NCSC’s Secure connectivity principles
New guidance is the first content authored by the Industrial Control System COI to appear on ncsc.gov.uk.

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Audit logs found no unexpected visitors, but release verification still needs an update

OpenAI Launches Two-Tier Security Access Program Alongside GPT 5.6 Cyber
Daybreak Blue removes some OpenAI-made guardrails while Daybreak Red grants the use of cyber-focused frontier AI models

AI for Military Support
Interesting empirical research: “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI.” Abstract: How is AI transforming decision-making in modern conflict? This study provides a unique empirical window into that question by deploying a high-fidelity replica of an AI decision-support system (DSS) used in military targeting. After reconstructing the interface and function

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB redirection is enabled; Microsoft says that

Logistics Giant Ceva Suffers Data Breach Impacting European Clients
Supply chain attack and data breach at Ceva Logistics appears to have a large blast radius

Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request into fragments that each look routine, place them in channels the assistant already uses, and let

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.

Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
Marcus Hutchins doesn’t personally consider himself a hacker – but he accepts the epithet because it’s a widely used term for what he once did. The post Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption appeared first on SecurityWeek.

US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]

OpenAI Pauses Some Development of Astra Model on Security Concerns
OpenAI is tightening restrictions on testing of its upcoming Astra model due to security concerns

Fake popular sites offer a free app, instead take over PCs
Fake branded download pages are tricking Windows users into installing legitimate remote-access software that's being abused by attackers.

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat

GPT-5.6-Cyber refuses security researchers’ requests far less often
GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. Model is available only through Daybreak Red, the higher tier of OpenAI’s vetted access program for cybersecurity professionals. “The GPT‑5.6‑Cyber model is trained to improve performance on certain cybersecurity workflows i

Mozilla Issues New Firefox GPG Key Following Exposure
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers. The most serious one lets an attacker take over a subscriber’s data session, so the network delivers that subscriber’s traff

Previously unseen entry vector used to breach Polish energy plant
The December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, according to CERT Polska. The private APN is a dedicated mobile network that a Distribution System Operator (DSO), the company running the local electricity grid, sets up with a mobile carrier. Illustrative use of a private APN