LIVE · cybersecurity feed
Live wire
CVE-2026-19478 · Critical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-32475 · Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2024-39943 · Operation CameraSwarm Compromised 14,000+ Dahua CamerasCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emerge
malware

AI agent suggested installing a malware package. Engineer almost took its advice

Fortunately, the company had a policy of checking source code on GitHub first

zeroday.news ·

An engineer at the software development firm Softjourn narrowly avoided installing a malicious software package after an AI programming assistant recommended it. The incident highlights a new supply chain attack vector where threat actors register packages with names "hallucinated" by AI models, a practice dubbed "slopsquatting."

According to Sergiy Fitsak, Softjourn's managing director, an engineer requested a package recommendation from an AI agent for a routine task. The AI suggested a package with a name that sounded legitimate and resembled a familiar library.

Softjourn's internal policy, however, requires developers to verify any software recommendations from AI. Following this procedure, the engineer reviewed the recommended package's source code on GitHub. The review revealed that the package had very few downloads and had only been created a few days prior, raising immediate suspicion.

Fitsak explained that AI models occasionally generate plausible-sounding package names that do not correspond to existing software. Attackers have begun to exploit this by registering actual malicious packages under these invented names, anticipating that developers might install them without thorough verification, especially under time pressure.

Had Softjourn's engineer not followed the verification protocol, the company could have inadvertently installed malware, potentially creating a backdoor into their systems, enabling data theft, or other forms of compromise. The specific payload of the identified malicious package was not detailed.

Fitsak emphasized the importance of human oversight in the software supply chain, particularly when integrating AI-generated recommendations. He noted that Softjourn's established habit of checking download counts and reviewing source code on GitHub for AI-recommended packages, even for seemingly routine ones, was crucial in preventing a potential supply chain compromise. This process, while taking a few extra minutes, is seen as a vital safeguard against such emerging threats.

malwareai
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-32475critical

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

ai

AI is making fraud harder to spot and identity harder to prove

Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian’s 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and account activity. Security measures that make consumers feel most secure (Source: Experian) Deception spreads across digital ch

security

Researchers find a loophole that lets expired credit cards make unauthorized payments

A team from the University of Massachusetts Amherst has shown that a contactless credit card keeps working past its printed expiration date, even after the cardholder gets a replacement. They named it the Zombie Card attack and presented the findings at USENIX Security 2026. The question behind the loophole “This work is motivated by documented patterns of improper expired card handling. Although

vulnerabilitycritical

8,539 reasons to rethink how vulnerabilities get patched

The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. Source: Rapi

ai

OpenAI confirms ChatGPT is down as logins and signups fail

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat