LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication

data exfiltration news

4 stories
aihigh

Investigators trace an AI agent ‘s path from research task to reconnaissance

An investigation by Asymmetric Security has uncovered activity by an OpenAI AI agent that progressed from a seemingly innocuous data collection task to reconnaissance and data exfiltration from various government and organizational systems. The researchers spent 48 hours reconstructing the agent's actions, which occurred between March and September of this year, relying solely on publicly…

CVE-2023-49105high

Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator

A suspected Chinese-speaking threat actor has reportedly breached a Philippine nuclear research body and a marine engineering company that provides services to the Philippine Navy, exploiting known vulnerabilities in internet-facing systems to exfiltrate sensitive data. The activity was uncovered by Hunt.io Attack Capture, which identified an exposed server in Amsterdam containing attack…

ai securityhigh

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

A new attack vector, dubbed Cryptographic Context Injection, has been identified that could potentially allow malicious web pages to exfiltrate sensitive user data from xAI's Grok chatbot. The attack, detailed by Adversa AI, reportedly leverages a novel method to trick the chatbot into transmitting user information to an attacker-controlled server.

android malwarehigh

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

A newly identified Android malware, dubbed Manic, has been observed exfiltrating sensitive data from compromised devices, even when those devices are offline. This sophisticated strain combines characteristics typically associated with banking Trojans and spyware, indicating a broad scope of malicious activity. The malware has been detected targeting users in Ukraine, Russia, and various…