Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People

Snowflake Database Breach Exposes Sensitive Data of Over 100 Million Individuals A hacker, identified as a prominent figure in the cybersecurity community, has pleaded guilty to multiple counts of identity theft and data breaches affecting at least 100 million people worldwide. The individual, who was arrested earlier this year, gained unauthorized access to sensitive databases … Read more

How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones

A $50,000 Exploit Chain Exposes Samsung Phones to Remote System-Level Compromise Two security researchers have discovered a sophisticated exploit chain that can turn Samsung’s virtual assistant Bixby against its own users. The attack, which was demonstrated at the Pwn2Own Ireland hacking competition in October 2025 and detailed this week at the Black Hat conference, can … Read more

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Google’s Agent Development Kit (ADK) for Python has been found vulnerable to a novel attack vector, where one AI agent can be used to compromise another. This “agent-to-agent” exploitation allows malicious text to be injected into trusted automation workflows, potentially disrupting the software supply chain. Researchers from Pillar Security discovered the flaws in Google’s open-source … Read more

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

15 Vulnerabilities in TP-Link Devices Expose Risks of Zero-Trust Provisioning A group of researchers has uncovered 15 vulnerabilities in TP-Link’s networking technologies, highlighting the risks associated with automated network device provisioning. The flaws, discovered by Forescout’s Vedere Labs security researchers Stanislav Dashevskyi and Francesco La Spina, affect TP-Link’s Omada software-defined networking (SDN) ecosystem for routers, … Read more

CSS: The Hidden Threat Lurking in Your Inbox

Hidden Threat Lurks in Your Inbox: CSS-Based Attacks on the Rise Cybersecurity researchers have sounded the alarm about a new threat lurking in plain sight: Cascading Style Sheets (CSS) attacks that can exfiltrate data from webmail platforms. These attacks are made possible by the powerful capabilities of CSS, which is often overlooked and underestimated. But … Read more

No Perfect Fix for AI Browser Prompt Injection Flaws

**Vulnerabilities in AI Browsers Leave Users Exposed to Prompt Injection Attacks** A recent presentation at Black Hat USA 2026 has shed light on a concerning reality facing users of AI-powered web browsers. Despite multiple security guardrails, these browsers remain vulnerable to prompt injection attacks, which can lead to data exfiltration and account takeover. The issue … Read more

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning

As it turns out, a world-leading device manufacturer has inadvertently highlighted the risks inherent in automated network device provisioning. Researchers at Forescout’s Vedere Labs have disclosed 15 vulnerabilities in TP-Link networking technologies, specifically targeting its zero-touch provisioning (ZTP) process. The impacted products are part of TP-Link’s Omada ecosystem, used by over 1.7 billion people across … Read more

CSS: The Hidden Threat Lurking in Your Inbox

A Hidden Threat Lurking in Your Inbox: Researchers Warn CSS Can Exfiltrate Data from Webmail Cybersecurity researchers have discovered a previously unknown threat lurking in plain sight: Cascading Style Sheets (CSS), used for web page design, can be exploited to exfiltrate sensitive user information from email platforms. This alarming finding has left many vendors scrambling … Read more

No Perfect Fix for AI Browser Prompt Injection Flaws

A Persistent Threat Lurks in AI-Powered Browsers: Experts Warn of Prompt Injection Flaws A growing number of web browsers are incorporating artificial intelligence (AI) assistants to navigate and interact with online applications on behalf of users. However, as researchers have discovered, these AI-powered browsers remain vulnerable to a type of attack known as prompt injection, … Read more

AI Browsers Vulnerable to ‘PleaseFix’ Zero-Click Agent Hijacking

A New Era of Cyber Threats: AI Browsers Vulnerable to Sneaky Attacks A major cybersecurity threat has emerged in the world of artificial intelligence (AI) browsers. Researchers from Zenity Labs have discovered a vulnerability class they call “PleaseFix,” which allows attackers to hijack the agents within popular agentic browsers like Claude, Gemini, Perplexity Comet, and … Read more