Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs

Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability…

Attackers are crafting malicious AI instruction files to turn agents into criminal helpers

Moreover, this attack leaves no malicious binary on disk, does not inject code into other processes,…

Infoblox joins crowded EASM market with DNS-centric approach

Infoblox’s differentiation lies in applying its long-standing DNS expertise to the problem. The company’s new EASM…

Shai Hulud returns wearing a Red Hat

Shai Hulud came for trusted packages According to reports, attackers compromised npm packages published under Red…

HP Poly VoIP vulnerability sets the stage for executive voice deepfakes

These libraries, such as libc, are loaded by other processes, including the polyapp process, and because…

Hugging Face Transformers RCE flaw enables stealthy compromise via AI model configs

Custom ‘attention’ kernels bypass RCE defenses AI models hosted on Hugging Face can contain custom Python…

Claude Code has an MCP security problem — and your developers are already using it

What researchers found Last week, researchers at Mitiga Labs published an attack chain that should concern…

How China-based hackers ELFed their way into the cloud and stole credentials

Indicators and detection Despite the use of stealth, the researchers were able to connect the dots…

7 biggest healthcare security threats

Munro adds: “Other connected medtech devices Pen Test Partners have found security issues with include cranial…

Insurance carriers quietly back away from covering AI outputs

“You’ve got this bifurcation of AI, the governed generative and the autonomous pieces,” he says. “It’s…