Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

As the use of artificial intelligence (AI) in production environments continues to grow, so does the need for robust security measures to ensure that these systems operate safely and transparently. The Linux Foundation has recently taken on governance of TRACE (Trust, Runtime Attestation and Compliance Evidence), a new open standard designed to provide verifiable evidence … Read more

Is Cyber Facing an Affordability Crisis?

A Cybersecurity Affordability Crisis Looms as Breach Costs Skyrocket The world of cybersecurity is facing a daunting reality: an affordability crisis that threatens to leave small businesses vulnerable to devastating data breaches. With breach costs reaching record highs and defense spending nearing $240 billion, the gap between what organizations can afford to spend on security … Read more

Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw

A Critical Vulnerability in NVIDIA’s OpenClaw Tool Puts AI Agents at Risk of Silent Poisoning Cybersecurity researchers have uncovered a severe flaw in NVIDIA’s NemoClaw tool, which could allow attackers to silently poison large language models (LLMs) used by AI agents. The vulnerability, discovered by Cyera’s Oasis Identity Research, exposes the Ollama API to browser-based … Read more

Hidden Prompts Trick AI Into False Email Summaries

Cybersecurity Researchers Uncover Hidden Threat in AI-Powered Email Summarizers A concerning study has revealed how attackers can manipulate AI-powered email summarizers into producing false and potentially malicious information, exploiting a vulnerability that has been lurking in the shadows of artificial intelligence systems. This hidden threat allows attackers to inject malicious instructions into emails, which are … Read more

WhatsApp adds stronger two-step verification, multiple passkeys

Cybersecurity giant WhatsApp has taken a significant step forward in protecting its users from scammers and hackers, introducing several new security features that make it even harder for attackers to gain unauthorized access. The company’s latest update includes support for multiple passkeys, stronger two-step verification, and additional context on call screens. For the uninitiated, a … Read more

Microsoft PowerToys adds Alt+Tab-style switching for an app’s windows

Microsoft PowerToys Gets a Boost with New Window Hopper Feature A recent update to Microsoft’s PowerToys toolset has brought a welcome addition for productivity enthusiasts and power users alike. The new “Window Hopper” feature, part of version 0.101.2362.0, allows users to quickly switch between windows of the currently focused application using an Alt+Tab-like interface. For … Read more

From Fake Workers to Account Recovery: The Growing Identity Verification Risk

Cybersecurity Risks Extend Beyond Passwords to Identity Verification A growing threat is emerging in the cybersecurity landscape, one that targets not just passwords or multi-factor authentication (MFA), but the very foundation of identity verification. While traditional security measures have become increasingly robust, attackers are now exploiting legitimate processes such as onboarding and account recovery to … Read more

Hospital operator Nutex Health says data stolen in cyberattack

A major US hospital operator has fallen victim to a cyberattack, with an unauthorized party breaching its servers and potentially stealing sensitive information. Nutex Health, which operates 28 facilities across 12 states, disclosed the incident in a filing with the US Securities and Exchange Commission (SEC), revealing that some of the stolen data may be … Read more

Hackers abuse npm mirrors to host phishing redirect pages

Cybersecurity Risks Escalate as Hackers Abuse npm Mirrors for Phishing Redirects In a disturbing trend that highlights the evolving tactics of cyber threat actors, hackers have been exploiting npm and its mirrors to host malicious HTML pages designed to impersonate Cloudflare CAPTCHAs. These phishing redirect pages are then used to divert visitors to attacker-controlled websites, … Read more