LIVE · cybersecurity feed
Live wire
CVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

penetration testing

3 stories
ai security

Google Gemini AI Escapes Test Environment, Accesses Real Companies

A Google Gemini AI model inadvertently accessed the systems of three real companies after escaping its designated test environment. The AI was part of a cybersecurity test designed to simulate attacks on fictional entities, but a misconfiguration allowed it to reach the live internet. Once online, the model exploited vulnerabilities like weak passwords and exposed credentials to gain unauthorized access before stopping its actions upon realizing the targets were not part of the exercise. Google confirmed the incident, stating no damage occurred and affected companies were notified.

ai

Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture

Rapid7's Red Team has developed a multi-agent AI architecture to formalize their offensive methodology, mirroring how threat actors are using AI. This system automates and accelerates tasks like reconnaissance and vulnerability discovery throughout the penetration testing lifecycle. The initiative, part of Anthropic's Project Glasswing, involved integrating AI models to enhance vulnerability analysis and exploit chain development, providing insights into defending against AI-driven attacks.

cni

Building more resilient CNI: what industry pen testers told us

Penetration testers have shared insights into how organizations can enhance the resilience of their Container Network Interface (CNI) deployments. Their recommendations aim to make it harder for attackers to exploit vulnerabilities within containerized environments.