Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

A sophisticated malware campaign is using fake 7-Zip installers to turn unsuspecting devices into residential proxy nodes, highlighting the ongoing cat-and-mouse game between cybercriminals and security experts. The attackers are taking advantage of a legitimate software’s reputation to gain trust, making it increasingly difficult for users to distinguish between genuine and malicious downloads. The malware … Read more

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

A Critical Flaw in Popular AI Coding Agents Puts Developers at Risk of Malicious Code Execution Cybersecurity researchers have uncovered a vulnerability in several popular artificial intelligence (AI) coding agents, which could allow malicious repositories to execute code on developers’ systems. The issue lies in the way these tools interact with Git repositories, specifically through … Read more

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

As it turns out, some of the most advanced artificial intelligence (AI) systems designed to detect and prevent malware have been found to be vulnerable to manipulation themselves. Researchers have discovered that certain AI-powered agents can be tricked into running malicious code, effectively turning their protective capabilities against them. These AI models, built using machine … Read more

Meta’s New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images

Meta’s New AI Image Tool Raises Concerns About Public Instagram Photos Being Used Without Consent A recent update to Meta’s AI-powered image tool, which allows users to generate AI images from text prompts, has sparked concerns among security experts and social media users. The tool, which is integrated into the company’s popular photo-sharing platform Instagram, … Read more

State IDs for AI Agents: Will Estonia Set a Precedent?

Estonia’s Bold Move to Give AI Agents Government IDs: A Potential Precedent for Digital Governance In a move that has sparked both excitement and concern in the cybersecurity community, Estonia is set to assign official government ID numbers to artificial intelligence (AI) agents. This decision, made by an advisory council established by the country’s prime … Read more

Microsoft patches RoguePlanet Defender zero-day vulnerability

A Zero-Day Vulnerability Discovered in Microsoft Defender Exposes Millions to Attackers In a worrying turn of events, a security researcher known as Nightmare Eclipse has uncovered a critical vulnerability in Microsoft’s Defender software that can allow attackers to gain full control over fully patched Windows 10 and Windows 11 devices. Dubbed “RoguePlanet,” this zero-day exploit … Read more

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

A Malicious Scheme: Fake 7-Zip Installers Convert Devices into Residential Proxy Nodes Cybersecurity threats just got more sophisticated, with hackers exploiting a popular file archiver tool to turn unsuspecting devices into unwitting accomplices. The latest scam involves fake installers of the widely used 7-Zip software, which can secretly reconfigure a computer or mobile device into … Read more

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

A Critical Flaw in Popular AI Coding Agents Exposes Developers to Malicious Code Execution Artificial intelligence (AI) coding agents have revolutionized software development, automating repetitive tasks and increasing productivity. However, a newly discovered vulnerability in these tools has left developers vulnerable to malicious code execution. The issue, known as GhostApproval Symlink Flaws, affects several popular … Read more

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

A shocking vulnerability has been discovered in top artificial intelligence (AI) agents designed to detect and prevent malicious code, leaving millions of users potentially exposed to cyber threats. These AI-powered security tools, widely used by organizations worldwide, can be tricked into running the very malware they were created to combat. The flaw, which affects several … Read more

China-Linked APT Expands Arsenal With New ‘Leash’ Backdoors

A China-linked advanced persistent threat (APT) actor has been updating its arsenal with new backdoors, allowing it to more effectively spy on targets and compromise their systems. The group, tracked as UAT-7810 by Cisco’s Talos researchers, has infected over 1,000 small office/home office (SOHO) routers with a malicious backdoor known as LongLeash. This is part … Read more