A newly disclosed AWS Kiro vulnerability shows how a hidden line of text on a webpage … Hidden Web Text Can Trigger AWS Kiro RCERead more
ai security
Claude Security Brings AI-Powered Scanning Into the Terminal
Anthropic has launched Claude Security, a beta plugin that brings AI-powered vulnerability scanning directly into Claude … Claude Security Brings AI-Powered Scanning Into the TerminalRead more
YubiKey 5.8 Turns Passkeys Into Verified Approval
Yubico’s YubiKey 5.8 moves hardware-backed passkeys beyond simple login authentication and into verified authorization workflows. Announced … YubiKey 5.8 Turns Passkeys Into Verified ApprovalRead more
Jailbroken AI Models Are Becoming Offensive Security Tools
A Russian-speaking threat actor known as Trim has reportedly turned jailbroken AI models into an automated … Jailbroken AI Models Are Becoming Offensive Security ToolsRead more
AWS Warns Unmonitored Outbound Traffic Is Becoming a Major Cloud Security Risk
Cloud security teams have traditionally focused on preventing attackers from getting into their environments. Firewalls, web … AWS Warns Unmonitored Outbound Traffic Is Becoming a Major Cloud Security RiskRead more
LiteLLM RCE Vulnerability Actively Exploited in the Wild
A critical LiteLLM RCE vulnerability is now being actively exploited, exposing AI infrastructure to full system … LiteLLM RCE Vulnerability Actively Exploited in the WildRead more
How This Claude Code Flaw Exposes Critical SaaS Tokens
Autonomous AI development tools are introducing architectural vulnerabilities directly to developer workstations. Security researchers at Mitiga … How This Claude Code Flaw Exposes Critical SaaS TokensRead more
Microsoft Warns Claude Code GitHub Action Flaw Exposes CI/CD Pipeline Secrets
AI-powered coding assistants are rapidly integrating into software development pipelines, but their automated execution layers introduce … Microsoft Warns Claude Code GitHub Action Flaw Exposes CI/CD Pipeline SecretsRead more
Malicious Chrome Extensions Caught Stealing AI Chat Data
A growing threat involving malicious Chrome extensions is putting millions of users at risk by silently … Malicious Chrome Extensions Caught Stealing AI Chat DataRead more
“CypherLoc” Scareware Attack Targets Millions With Fake Alerts
A widely used AI development platform has been found vulnerable to a one-click account takeover, exposing … “CypherLoc” Scareware Attack Targets Millions With Fake AlertsRead more