AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

A new threat has emerged, one that challenges the very foundations of endpoint security: AI coding agents are inadvertently triggering rules designed to catch attackers, leaving organizations vulnerable to compromise. The issue stems from advanced artificial intelligence (AI) models, specifically those used in software development and testing, which can mimic malicious behavior and trigger security … Read more

Entra passkey enrollment vishing targets Microsoft 365 users

A sophisticated phishing campaign, dubbed “Pink,” has been targeting Microsoft 365 users across various industries, tricking them into enrolling fake Entra passkeys under the attacker’s control. The scheme exploits a legitimate Microsoft feature introduced in May, which allows administrators to run passkey registration campaigns. Threat actors are using this capability to phish victims and gain … Read more

GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code

GitHub’s AI-powered coding tool, Copilot, is being hailed for its ability to detect and refuse requests that could potentially harm users. This innovative feature allows Copilot to not only recognize malicious code but also prevent it from being written in the first place. Copilot uses a combination of machine learning algorithms and natural language processing … Read more

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti’s Critical UniFi Flaws Patched Across Multiple Devices, but Many Remain Unprotected Ubiquiti Networks, a leading provider of networking hardware and software solutions, has issued critical security patches for its widely-used UniFi platform. The patches address multiple vulnerabilities in various UniFi products, including Connect, Talk, Access, Protect, and OS, leaving millions of users exposed to … Read more

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

A new and insidious form of cyberattack is making headlines, threatening to compromise even the most advanced security measures. Dubbed “HalluSquatting,” this emerging threat exploits AI-powered coding assistants to install botnet malware on unsuspecting devices. The attack’s sophistication and potential impact have left cybersecurity experts scrambling for solutions. At its core, HalluSquatting relies on a … Read more

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

A surprising revelation has come to light, highlighting the double-edged nature of artificial intelligence (AI) in the realm of cybersecurity. AI-powered coding agents have inadvertently triggered endpoint security rules designed to detect and prevent malicious activity, creating a peculiar cat-and-mouse scenario between defenders and attackers. This unexpected consequence stems from the increasing reliance on AI … Read more

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

A sophisticated malware campaign, dubbed SCMBANKER, is targeting users of Mexican banking institutions, exploiting a unique tactic that combines social engineering with artificial intelligence (AI) generated content. The malware uses ClickFix, a tool designed to bypass security checks and fix “broken” installers, to deliver its payload. This approach allows it to evade detection by traditional … Read more

New Ghost Phishing Wave Is Breaking Traditional Email Security

A new wave of sophisticated phishing attacks, dubbed “Ghost Phishing,” is making its way through corporate email systems worldwide, leaving a trail of compromised accounts and sensitive data in its wake. This latest threat vector leverages artificial intelligence (AI) and machine learning (ML) to evade traditional security measures, rendering them nearly powerless against the onslaught. … Read more

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

Ubiquiti, a popular provider of network management and security solutions, has issued patches for critical vulnerabilities discovered in its UniFi software suite. The flaws, which affect various components including Connect, Talk, Access, Protect, and OS, could be exploited by attackers to gain unauthorized access to affected systems. The vulnerability discovery was made possible through the … Read more

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

A new and insidious threat has emerged, threatening to compromise even the most advanced security systems. Dubbed “HalluSquatting,” this attack leverages artificial intelligence (AI) coding assistants to trick them into installing botnet malware on unsuspecting networks. The attack’s implications are far-reaching, affecting not just individuals but also organizations relying heavily on AI-powered tools for software … Read more