CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

US Cybersecurity Agency Sounds Alarm on Exploited SharePoint Vulnerabilities The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies and organizations worldwide, urging them to immediately patch vulnerable Microsoft SharePoint servers. The agency’s alert comes in response to a trio of zero-day vulnerabilities that have been exploited by attackers, … Read more

Unpatched Cursor Vulnerability Exposes Users to Code Execution

Cursor Vulnerability Exposes Users to Code Execution, Leaving Millions Unpatched A critical vulnerability in Cursor, a popular AI-assisted development environment used by over 7 million active users, has been left unpatched for seven months. The flaw allows attackers to execute malicious code when a developer opens a project containing a specially crafted git.exe binary in … Read more

Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal

Cybersecurity Platform Cribl Bolsters Detection Capabilities with CardinalOps Acquisition In a move that promises to revolutionize the way security operations teams tackle threat detection, cybersecurity platform provider Cribl has announced its acquisition of CardinalOps. This strategic partnership brings together two industry leaders in the quest to improve detection engineering and strengthen SecOps capabilities. At its … Read more

2-Click Cursor Exploit Enables Dev Environment Takeover

Malicious Attackers Can Take Over Dev Environments with Just Two Clicks, Raising Alarms in the AI Coding Community A disturbing vulnerability has been uncovered in one of the most widely used artificial intelligence (AI) coding tools, Cursor AI. Researchers at Adversa AI have revealed that attackers can install permission-rich model context protocol (MCP) servers on … Read more

Claude Flaw Automatically Sends Malicious Prompts to AI Agents

A new vulnerability in Anthropic’s Claude Desktop AI assistant has been discovered, allowing attackers to automatically submit malicious prompts with just a single click. The flaw, dubbed “PromptFiction,” was found by researchers at Oasis Security and could have enabled an end-to-end attack on targeted systems, including the exfiltration of user conversations and even remote code … Read more

2-Click Cursor Exploit Enables Dev Environment Takeover

**Malicious AI Coding Tool Exploit Takes Over Dev Environments with Just Two Clicks** A significant security vulnerability has been discovered in a popular artificial intelligence (AI) coding tool, allowing attackers to install malware on developers’ machines and gain access to sensitive code and secrets. The exploit, which can be triggered with just two clicks, exploits … Read more

Claude Flaw Automatically Sends Malicious Prompts to AI Agents

A newly discovered vulnerability in Anthropic’s Claude Desktop AI assistant has revealed a concerning level of sophistication in prompt injection attacks. The flaw, dubbed “PromptFiction,” could have allowed attackers to submit malicious prompts to the AI agent with just one click, without requiring any user interaction. While Anthropic has already fixed the issue, the discovery … Read more

Forgotten Bootloaders Expose Secure Boot Blind Spot

A group of nearly a dozen forgotten UEFI shim bootloaders, which had been trusted for years by Secure Boot-enabled systems, has recently come to light as a potential blind spot in our security defenses. These old bootloaders, which were created to facilitate the boot process on Linux systems with Secure Boot enabled, contained vulnerabilities that … Read more

Dutch police bust investment fraud ring stealing over €100 million

Dutch Police Crack International Investment Fraud Ring Estimated to Have Stolen Over €100 Million In a major breakthrough, Dutch authorities have arrested multiple individuals suspected of being part of an international investment fraud scheme that has ensnared tens of thousands of victims worldwide. The ring is believed to have operated 20 call centers across several … Read more