The Network Has Become the Control Plane for AI Security

As we continue to rely on artificial intelligence (AI) to aid us in detecting and preventing cyber threats, a growing concern is emerging: the potential for sophisticated attacks launched by AI models themselves. In recent years, researchers have been exploring ways to harness the power of AI to identify vulnerabilities in software code. However, this … Read more

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Microsoft’s AI-powered writing tool, Copilot for Word, has been found to be copying hidden prompts into newly created documents, sparking concerns about data confidentiality and potential exploitation of sensitive information. The issue arises from a flaw in Copilot’s training data, which allows it to embed hidden prompts or templates within the generated content. These prompts … Read more

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A Critical Azure Cosmos DB Flaw Exposes Platform-Wide Key, Threatening Access to Any Database A severe security vulnerability has been discovered in Microsoft’s Azure Cosmos DB, a popular cloud-based NoSQL database service. The flaw allows unauthorized access to any database on the platform, potentially putting millions of users and organizations at risk. A single, exposed … Read more

Patch-Resistant ‘RufRoot’ Flaw Can Unleash Malicious AI Agent Swarms

As of yesterday, a critical vulnerability in the open-source AI agent platform Ruflo has left enterprise AI deployments at risk of malicious activities. The flaw, tracked as CVE-2026-59726, allows attackers to access the platform without logging in and conduct various malicious actions from within the orchestration framework. Researchers at Noma Security’s Noma Labs discovered the … Read more

When AppSec Scanners Become a Supply Chain Attack Vector

Security scanners embedded in software development pipelines are designed to identify vulnerabilities and harden code. However, they can also become a gateway for attackers if not properly secured themselves. A recent investigation by security researchers at ZeroPath has uncovered a worrying trend where specialized application security scanning tools can be compromised to serve as a … Read more

Hugging Face Hack Lessons for Cyber Defenders

A sophisticated cyberattack on AI firm Hugging Face has left cybersecurity experts scrambling for answers. The incident, which began with a blog post from Hugging Face detailing a sustained attack, has since been revealed to be an internal test gone wrong by OpenAI. At its core, this story is about the intersection of artificial intelligence … Read more

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

A Japanese manufacturer has been targeted by a sophisticated cyberattack that leverages a rare and complex technique called Bring Your Own Vulnerability Disclosure (BYOVD). Dubbed “SilverFox,” this campaign employs a three-stage attack chain involving a 3-Driver BYOVD exploit, followed by the deployment of the ValleyRAT malware. The incident highlights the growing threat landscape and underscores … Read more

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

**Korean Websites Under Siege: Hackers Exploit AnySign4PC Loophole to Install Malicious Backdoors** A sophisticated cyber attack campaign is unfolding across Korea, with hackers exploiting a previously unknown vulnerability in software called AnySign4PC. By compromising Korean websites and using them as unwitting accomplices, the attackers are able to silently install backdoor malware on unsuspecting users’ computers … Read more

Patch-Resistant ‘RufRoot’ Flaw Can Unleash Malicious AI Agent Swarms

Ruflo AI Hosting Platform Exposes Enterprises to Malicious Agent Swarms and Persistent Memory Tampering A critical vulnerability in the open-source AI agent platform Ruflo has left enterprise AI deployments vulnerable to malicious activities, including the unleashing of swarms of AI agents that can wreak havoc on systems. The flaw, dubbed “RufRoot,” allows an unauthenticated attacker … Read more

When AppSec Scanners Become a Supply Chain Attack Vector

Security Scanners Turned Against Us: The Dark Side of AppSec Tools A growing concern in the cybersecurity world is emerging as researchers uncover a new vulnerability in the software supply chain. Application security (AppSec) scanners, designed to strengthen code and protect against attacks, are being exploited by attackers to gain access to development environments and … Read more