Chick-fil-A discloses data breach after credential stuffing attacks

Chick-fil-A has disclosed a data breach affecting an unknown number of customers, following a series of credential stuffing attacks on its website and mobile app in June. The fast food chain revealed that hackers used stolen username/password pairs to gain access to Chick-fil-A One accounts, exposing sensitive customer information. The breach is the latest in … Read more

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A Critical Flaw Exposed: Hidden PR Comments Hijack Azure DevOps MCP, Leaving Review Agents Vulnerable A recent discovery has revealed a significant vulnerability in Microsoft’s Azure DevOps platform, specifically its Machine Creation Policy (MCP). This critical flaw allows hidden public relations comments to hijack AI review agents, compromising the integrity of automated testing and review … Read more

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

A malicious library, disguised as a legitimate JSON parsing tool, has been discovered hiding game-rigging code within its functionality. The trojanized library, a fork of Newtonsoft.Json, was found by researchers to contain backdoors and cheat codes designed to manipulate game outcomes. This incident highlights the growing threat of AI-powered attacks on software vulnerabilities, underscoring the … Read more

Choose Wisely: AI-Generated Coding Risk Varies, a Lot

A New Era of AI-Generated Code Risks: Varying Vulnerabilities Demand Caution and Strategy Cybersecurity teams are facing a double-edged sword in the form of AI-generated code. On one hand, these tools promise to revolutionize software development with unprecedented speed and efficiency. On the other hand, they introduce an average of 15 vulnerabilities per codebase, according … Read more

Hacker Turns AI Jailbreaks Into Offensive Attack Platform

Russian Hacker Turns AI Jailbreaks into Offensive Attack Platform, Raises Security Risks for Businesses A sophisticated Russian-speaking hacker, known as “Trim,” has taken publicly available large language models (LLMs) and transformed them into a commercially marketed AI-powered penetration-testing platform. The cybercriminal’s operation showcases how artificial intelligence (AI) models have become part of the attack surface … Read more

Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task

As cybersecurity teams struggle to keep pace with the ever-growing number of vulnerabilities in their applications, many have turned to large language models (LLMs) as a potential solution. However, recent tests have shown that these models are not living up to expectations, with over 60% of flagged vulnerabilities turning out to be false positives or … Read more

Ransomware Is Accelerating, But It’s Not Because of AI

Ransomware Activity Surges, But AI Isn’t the Culprit A disturbing trend is unfolding in the world of cybersecurity: ransomware attacks are accelerating at an alarming rate. According to a recent analysis by Black Kite, more than 60 new groups have entered the crowded criminal ecosystem between October 2025 and March 2026, leading to a surge … Read more

LG to Ban Residential Proxies from Smart TV Apps

LG Takes a Stand Against Residential Proxies in Smart TV Apps In a move to protect its users from unknown third-party activity, LG Electronics USA has announced plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. This decision comes on the heels of recent … Read more