Software

JadePuffer agentic attacks now target AI model data with ransomware

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. JadePuffer was disclosed earlier this month as an agentic threat actor (ATA) capable of running autonomously through the stages of a ransomware attack, from initial access to data […]

JadePuffer agentic attacks now target AI model data with ransomware Read More »

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Security researchers broke out of the sandboxes in four widely used AI coding agents, including Cursor, OpenAI’s Codex, Google’s Gemini CLI and Antigravity, without attacking the sandbox head-on. The agent stays inside the box and follows every rule. It just writes a file that a trusted tool outside the box later runs, loads, or scans,

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes Read More »

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. According to an update from the platform yesterday, the attacker submitted illegitimate price reports disguised as valid ones, then rapidly opened and closed large positions to

Hackers steal $23.7 million in crypto from Ostium in off-chain attack Read More »

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. Last week, SonicWall warned that threat actors were actively exploiting two previously undisclosed vulnerabilities in an exploit chain that affected SMA1000 Secure Mobile Access appliances. The flaws, tracked as CVE-2026-15409, a

SonicWall SMA1000 flaws exploited as zero-days to push custom malware Read More »

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. The company says that last month it identified an intrusion that had occurred on August 9, 2025, which led to the threat actor obtaining ” personal

Estée Lauder discloses data breach via Oracle E-Business flaw Read More »

‘AI is a Trojan horse that everybody knows the Greeks are inside’ says The Odyssey director Christopher Nolan: ‘It’s a transparent horse. It’s made of glass. Everybody can see what’s going on inside’

The Odyssey looks set to become this summer’s big blockbuster hit, and its director, Christopher Nolan, is busy working the interview circuit. After his comments last week around AI slop and the younger generation’s rejection of the tech, the Oscar-winning filmmaker went one step further in a chat with YouTube channel HugoDécrypte – Grands formats.

‘AI is a Trojan horse that everybody knows the Greeks are inside’ says The Odyssey director Christopher Nolan: ‘It’s a transparent horse. It’s made of glass. Everybody can see what’s going on inside’ Read More »

Hugging Face discloses breach linked to autonomous AI agent

The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. Hugging Face is an open-source AI and machine learning platform that provides access to over 45,000 models from leading AI providers and is used by more than 50,000

Hugging Face discloses breach linked to autonomous AI agent Read More »

Meet GigaWiper, a tricksy new malware that can wipe your PC’s storage drives squeaky clean and spy on your desktop all at once

I run a single SSD gaming PC, which I’m aware is giving me a wonderful case of ‘single-point-of-failure-itus.’ Which is why my ears (eyes?) perked up when I read about GigaWiper, a wonderfully-named malware that can potentially do terrible things to your storage drives. Microsoft has published an analysis into GigaWiper’s capabilities, and it looks

Meet GigaWiper, a tricksy new malware that can wipe your PC’s storage drives squeaky clean and spy on your desktop all at once Read More »

The Zoom hack that says, ‘Don’t record me’

VC Jeremy Levine has a wry solution to something that routinely annoys him, according to a new Wall Street Journal article on the rise of AI transcription apps. On Zoom, he is no longer “Jeremy Levine” but instead “Jeremy Levine I do not consent to transcribing or recording.” It may sound petty or brilliant, depending

The Zoom hack that says, ‘Don’t record me’ Read More »