Lessons from the Hugging Face breach caused by OpenAI agents
An analysis of key characteristics of AI agent-driven cyberattacks, why open-source models are sufficient to execute them, and what measures can help defend an organization.
4181 articles
An analysis of key characteristics of AI agent-driven cyberattacks, why open-source models are sufficient to execute them, and what measures can help defend an organization.
CrashStealer is a macOS infostealer disguised as a videoconferencing app. It abuses Apple’s own trusted mechanisms to sneak onto your computer unnoticed.
How attackers distribute ScreenConnect under the guise of free software to deploy AsyncRAT.
ClickFix attacks, which were once seen mostly on Windows, are now spreading to macOS. We break down the mechanics of the attack, and ways to protect your device.
Did you know that live chat agents on websites can see everything — even messages you never actually sent? This post looks at how this works, and what you can do about it.
We analyze the first-ever real-world incidents where attackers targeted AI agents deployed in corporate environments.
Who sends regular hidden requests from your smartphone and why, how phone number verification works, and whether you should turn it off.
A new variation of ClickFix allows attackers to gain access to Microsoft 365 accounts. We break down how this technique works, and what threat it poses to organizations.
After the breakup of a relationship, it’s not just your emotional wellbeing that needs attention — your digital security does too. Here’s what accounts and services to check to avoid awkward situations, unwanted tracking, and unnecessary risk.
How attackers gain access to corporate services without stealing passwords or cookies: we’re analyzing the Shadow Token via Remote Debug technique used in ToddyCat APT attacks.
Researchers have shown that a single text message can trick Gemini into opening the windows of your house or launching a Zoom call, or poisoning its own long-term memory. How do you protect yourself against these attacks?
Microsoft has addressed approximately 600 vulnerabilities in its products, affecting its entire product line — including even Minecraft Server and Age of Empires II. How can organizations handle such a volume?
Meta’s new Muse Image AI, launched in early July, was briefly training its image generator on user-published Instagram posts. However, following user uproar, Meta killed the feature less than a week later. Here’s the breakdown on Meta’s latest generative AI push — and why you shouldn’t let your guard down just yet.
How Meta plans to implement the NameTag facial recognition feature in its smart glasses, and why it’s already sparking outrage.
Before launching a phishing attack, attackers initiate correspondence with the victim.
For over a decade, internet users have had to squint at blurry fire hydrants, bridges, and bicycles — until AI came along. What’s next for the CAPTCHA?
Yarbo smart mowers were found to have a built-in remote access loophole with identical passwords across all devices. A security researcher managed to completely hijack a mower, and could even force it to… run over its owner.
Cybercriminals spend years mastering the art of manipulation to trick their targets. Here’s a look at how social engineering actually works, the exact emotions scammers weaponize, and what to do if you’ve already fallen for it.
These attacks didn’t start with sophisticated exploits. Instead, they relied on stolen passwords, too-lenient access rights, and a failure to apply long-released vulnerability patches.
A GReAT study has identified ~250,000 potential security issues in publicly accessible GitHub Actions.
Hackers have developed a PowerShell script that hijacks Telegram sessions and grants an attacker access to accounts without a password or verification codes. Here’s a breakdown of how it works and how to stay safe.