• Researchers Trick Perplexity’s Comet AI Browser Into Phishing Scam in Under Four Minutes

    Researchers Trick Perplexity’s Comet AI Browser Into Phishing Scam in Under Four Minutes

    Agentic web browsers that leverage artificial intelligence (AI) capabilities to autonomously execute actions across multiple websites on behalf of a user could be trained and tricked into falling prey to phishing and scam traps. The attack, at its core, takes advantage of AI browsers’ tendency to reason their actions and use it against the model…

    Read More

  • Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

    Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

    Cybersecurity researchers have disclosed details of two now-patched security flaws in the n8n workflow automation platform, including two critical bugs that could result in arbitrary command execution. The vulnerabilities are listed below – CVE-2026-27577 (CVSS score: 9.4) – Expression sandbox escape leading to remote code execution (RCE) CVE-2026-27493 (CVSS score: 9.5) – Unauthenticated

    Read More

  • Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown

    Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown

    Meta on Wednesday said it disabled over 150,000 accounts associated with scam centers in Southeast Asia as part of a coordinated effort in partnership with authorities from Thailand, the U.S., the U.K., Canada, Korea, Japan, Singapore, the Philippines, Australia, New Zealand, and Indonesia. The effort also led to 21 arrests made by the Royal Thai…

    Read More

  • Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices

    Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices

    SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems. The vulnerabilities in question listed below – CVE-2019-17571 (CVSS score: 9.8) – A code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) CVE-2026-27685 (CVSS score: 9.1) – An insecure deserialization

    Read More

  • Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days

    Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days

    Microsoft on Tuesday released patches for a set of 84 new security vulnerabilities affecting various software components, including two that have been listed as publicly known. Of these, eight are rated Critical, and 76 are rated Important in severity. Forty-six of the patched vulnerabilities relate to privilege escalation, followed by 18 remote code execution, 10…

    Read More

  • UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

    UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

    A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package last year to completely breach a victim’s cloud environment within a span of 72 hours. The attack started with the theft of a developer’s GitHub token, which the threat actor then used to gain unauthorized access…

    Read More

  • Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets

    Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets

    Cybersecurity researchers have discovered five malicious Rust crates that masquerade as time-related utilities to transmit .env file data to the threat actors. The Rust packages, published to crates.io, are listed below – chrono_anchor dnp3times time_calibrator time_calibrators time-sync The crates, per Socket, impersonate timeapi.io and were published between late February and early March

    Read More

  • How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows

    How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows

    Artificial Intelligence (AI) is no longer just a tool we talk to; it is a tool that does things for us. These are called AI Agents. They can send emails, move data, and even manage software on their own. But there is a problem. While these agents make work faster, they also open a new…

    Read More

  • KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet

    KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet

    Cybersecurity researchers have discovered a new malware called KadNap that’s primarily targeting Asus routers to enlist them into a botnet for proxying malicious traffic. The malware, first detected in the wild in August 2025, has expanded to over 14,000 infected devices, with more than 60% of victims located in the U.S., according to the Black…

    Read More

  • New “LeakyLooker” Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries

    New “LeakyLooker” Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries

    Cybersecurity researchers have disclosed nine cross-tenant vulnerabilities in Google Looker Studio that could have permitted attackers to run arbitrary SQL queries on victims’ databases and exfiltrate sensitive data within organizations’ Google Cloud environments. The shortcomings have been collectively named LeakyLooker by Tenable. There is no evidence that the vulnerabilities were exploited in

    Read More