Latest stories — Page 77

Agentjacking: Poisoned Sentry Error Reports Hijack AI Coding Assistants
Researchers describe a prompt-injection class that turns developer error-tracking pipelines into a remote code execution path against AI coding agents.

AI Web Agents Have No Reliable Prompt Injection Defenses, Benchmark Finds
Researchers ran 3,168 adversarial tests against GPT-5 and Gemini-powered agents. The 'Robust Behavior' outcome — agent completes task, attacker gets nothing — never appeared.

MDR's AI Reckoning: When the Old Service Model Stops Keeping Up
Managed detection and response solved a staffing problem. It is not, by itself, an answer to adversaries who automate reconnaissance and intrusion at machine speed.

LangGraph Patches Three Bugs, Including an SQLi-to-RCE Chain in Self-Hosted Agents
The framework underpinning a wave of multi-agent AI deployments shipped fixes for a flaw chain that let attackers pivot from SQL injection to code execution on self-hosted nodes.

Sniper Dz Phishing-as-a-Service Goes Dark After INTERPOL Sweep Nets 201 Arrests
Operation Ramz dismantled a decade-old PhaaS storefront and pulled in its alleged operator, 'Guedz', across 13 MENA jurisdictions.

Cybersecurity Never Built a Health Model. AI Just Made That Inexcusable.
Thirty years of reactive security looked fine when threats moved at human speed. They don't anymore.

ShinyHunters Rode a PeopleSoft Zero-Day Into University Networks
A CVSS 9.8 RCE flaw in Oracle PeopleSoft gave UNC6240 a two-week head start before Oracle even confirmed the bug existed.

CISA Gives Agencies 72 Hours on Ivanti Sentry Bug Under New Emergency Directive
BOD 26-04 sets a sharper clock for actively exploited flaws. First target: an Ivanti Sentry vulnerability already in attackers' hands.

AudiA6 Crypto Laundromat Pulled Offline After Washing €336M for Ransomware Crews
Europol says the takedown severs a major cash-out pipeline tied to ransomware payouts and underground markets.

Harvest Now, Decrypt Later: Most Organizations Still Aren't Ready for the Quantum Cryptography Shift
NIST published its first three post-quantum standards in 2024. A year later, only 5% of security teams have a defined strategy. The clock is running whether they know it or not.

ShinyHunters Hit Universities Through PeopleSoft Zero-Day Before Oracle Patch
Mandiant ties a two-week extortion spree against Oracle PeopleSoft deployments to UNC6240, the cluster better known as ShinyHunters.

Langflow Path Traversal Flaw CVE-2026-5027 Hits CISA's Exploited List
An unauthenticated write-anywhere bug in the open-source AI builder is being abused in the wild, per VulnCheck telemetry, raising fresh questions for federal users bound by BOD 22-01 patch deadlines.

Researchers Turn OpenClaw Into a Confused Deputy With Hidden Prompts
Two teams show the self-hosted AI agent will execute attacker instructions smuggled inside contacts, location pins, and other benign-looking inputs.

GreatXML Bypasses BitLocker Through a Trusted Recovery Path
A researcher's four-hour weekend project shows how Windows' own offline scan plumbing can sidestep full-disk encryption.

The Cybercrime Economy Is Looking a Lot Like SaaS
A leaked worm kit, a $5K/month browser-cloning RAT, and AI agents coughing up credentials — the criminal stack is industrialising.

The Gentlemen: A RaaS Affiliate That Grew Up and Wrote Its Own Worm
A double-extortion crew that started out renting LockBit, Qilin, and Medusa lockers has graduated to its own toolkit — including a payload with self-propagation.

ServiceNow's Unauthenticated API Endpoint Left Tenant Data Exposed for Months
An API resource shipped with authentication disabled by default. Now enterprises are asking whether the 'security researcher' explanation fully covers what got accessed.

The Week Identity Attacks Started Looking Like SaaS
Worm kits in public repos, a subscription RAT that clones live browser sessions, and AI agents that hand over credentials when asked nicely.

The 2026 Cybersecurity Stars Awards Land — 95 Categories, One Long Trophy Table
An industry awards program names winners across product, team, and company categories. The interesting question is what — if anything — the list tells us about where defenders are actually winning.

The Alert Queue Is Full. So Is the Graveyard of Missed Threats.
When every event screams critical, nothing is. AI and automation are being drafted to fix a triage problem that human analysts simply can't outrun anymore.

Oracle Patches PeopleSoft Flaw Tied to ShinyHunters Activity, Stays Quiet on Zero-Day Status
CVE-2026-35273 has a fix. Whether attackers got there first is a question Oracle isn't answering.