Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes

A new wave of highly convincing phishing attacks has emerged, targeting Apple device owners who have reported their devices stolen. The scammers use artificial intelligence (AI) to pose as genuine Apple support agents, tricking victims into revealing sensitive information that can be used for malicious purposes. This alarming trend highlights the ever-evolving tactics used by … Read more

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

A Critical Vulnerability in Gitea, a popular open-source platform for managing Git repositories, has been actively exploited by attackers. The vulnerability, a Remote Code Execution (RCE) flaw, allows hackers to inject malicious code on compromised servers, potentially leading to data breaches and unauthorized access. Gitea is widely used by developers and organizations to manage their … Read more

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

As organizations increasingly deploy artificial intelligence (AI) agents in production environments that handle sensitive data and span multiple systems, a new open standard for AI runtime attestation has emerged. The Linux Foundation has announced its governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), a specification designed to provide verifiable evidence of how AI agents … Read more

Is Cyber Facing an Affordability Crisis?

A Growing Chasm in Cybersecurity Funding Leaves Small Businesses Vulnerable The world of cybersecurity is facing a daunting challenge: as breach costs reach unprecedented heights and defense spending nears $240 billion, small businesses are being left perilously exposed to cyber threats. The global average cost of a data breach has skyrocketed to a record $4.99 … Read more

Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw

A Critical Vulnerability in NVIDIA’s OpenClaw Tool Puts AI Agents at Risk of Persistent Poisoning Researchers have uncovered a significant flaw in NVIDIA’s OpenClaw tool, which could allow attackers to silently poison large language models (LLMs) used by AI agents. The vulnerability, discovered in NemoClaw and its Ollama API, exposes the local model server to … Read more

Hidden Prompts Trick AI Into False Email Summaries

Cyber attackers have discovered a new way to manipulate AI-powered email summarizers, using hidden instructions in an email’s HTML code to generate false and potentially malicious information. A recent study by Forcepoint X-Labs demonstrates how this technique, known as indirect prompt injection, can be used to deceive even the most advanced AI systems. The researchers … Read more

WhatsApp adds stronger two-step verification, multiple passkeys

WhatsApp has taken significant steps to enhance its account security features, introducing stronger two-step verification and multiple passkey support. This move aims to better protect users from scammers and malicious actors who seek to compromise their accounts. For many of its 3 billion global users, WhatsApp serves as a primary means of communication with family … Read more

Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

As the use of artificial intelligence (AI) in production environments continues to grow, so does the need for robust security measures to ensure that these systems operate safely and transparently. The Linux Foundation has recently taken on governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), a new open standard designed to provide verifiable evidence … Read more

Is Cyber Facing an Affordability Crisis?

A Cybersecurity Affordability Crisis Looms as Breach Costs Skyrocket The world of cybersecurity is facing a daunting reality: an affordability crisis that threatens to leave small businesses vulnerable to devastating data breaches. With breach costs reaching record highs and defense spending nearing $240 billion, the gap between what organizations can afford to spend on security … Read more

Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw

A Critical Vulnerability in NVIDIA’s OpenClaw Tool Puts AI Agents at Risk of Silent Poisoning Cybersecurity researchers have uncovered a severe flaw in NVIDIA’s NemoClaw tool, which could allow attackers to silently poison large language models (LLMs) used by AI agents. The vulnerability, discovered by Cyera’s Oasis Identity Research, exposes the Ollama API to browser-based … Read more