We built a vulnerability vending machine: AI tokens in, zero-days out

Cybersecurity researchers at Intruder have developed a cutting-edge system that leverages artificial intelligence (AI) to automatically discover and exploit previously unknown security vulnerabilities in production software. Dubbed a “vulnerability vending machine,” this AI-powered pipeline has successfully identified a zero-day SQL injection vulnerability in a popular WordPress plugin used by over 300,000 users. The Intruder team’s … Read more

​ ​AsyncAPI npm packages infected with credential-stealing malware

A Supply-Chain Attack Unfolds: AsyncAPI Packages Compromised with Credential-Stealing Malware In a brazen supply-chain attack, five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in just four hours and seven minutes. The compromised packages, part of the @asyncapi namespace, had a staggering cumulative weekly download count of over 2.25 million. … Read more

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

Major Browser and Software Updates Patch Critical Flaws Exposed by AI-Powered Threats A critical wave of security updates has swept across the tech landscape, with multiple high-profile companies releasing fixes for devastating vulnerabilities exposed by cutting-edge AI-powered threat detection. Firefox, Chrome, Adobe, and VMware have all issued patches to address a range of serious flaws … Read more

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

A sophisticated malware framework known as OkoBot has been discovered to be targeting Ledger and Trezor cryptocurrency wallet users through a clever phishing tactic. The attack, which leverages a combination of social engineering and technical expertise, has left many in the crypto community on high alert. The OkoBot malware framework is designed to phish seed … Read more

​ ​AsyncAPI npm packages infected with credential-stealing malware

A massive supply-chain attack has compromised five versions of AsyncAPI packages on the Node Package Manager (npm), delivering a remote access trojan with info-stealing capabilities to over 2.25 million users. The threat actor exploited a misconfigured GitHub Actions workflow, injecting malware into project files and publishing trojanized packages in the @asyncapi namespace. The malicious packages, … Read more

New Webinar: Closing the Approval Gap in AI-Era Ad Tech

As AI-powered cyber threats become increasingly sophisticated, a new webinar promises to reveal strategies for securing against software vulnerabilities discovered by artificial intelligence models. The five-step plan outlined in “Closing the Approval Gap in AI-Era Ad Tech” is aimed at helping organizations protect themselves from advanced attacks that exploit previously unknown vulnerabilities. The webinar highlights … Read more

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

A new Windows zero-day vulnerability was disclosed just hours after Microsoft’s scheduled Patch Tuesday update, leaving users vulnerable to exploitation. The proof-of-concept (PoC) exploit code, released by security researcher Ian Alden Potter, targets a previously unknown flaw in Windows’ Remote Desktop Protocol (RDP). The zero-day vulnerability affects multiple versions of the Windows operating system, including … Read more

SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.

A recently disclosed vulnerability in Security Service Edge (SASE) platforms has exposed a significant blind spot in AI-powered security solutions. SASE, which converges network security functions with cloud-native technology, relies heavily on artificial intelligence to inspect packets and detect potential threats. However, researchers have discovered that sophisticated attacks can evade these systems by exploiting the … Read more

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws

**Critical Security Updates Released for Firefox, Chrome, Adobe, and VMware** Multiple high-profile companies have just released critical security updates to patch vulnerabilities that could allow hackers to remotely access users’ systems, steal sensitive data, or even take control of entire networks. The affected software includes popular web browsers like Mozilla’s Firefox and Google’s Chrome, as … Read more

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

A Critical Security Threat Emerges from npm Packages, Compromising Thousands of Developers and Businesses Worldwide A significant security breach has been discovered involving compromised AsyncAPI npm packages, which have been used to deliver multi-stage botnet malware to unsuspecting users. The attack, which was revealed on July 15th, has far-reaching implications for developers, businesses, and individuals … Read more