144 npm packages of the Mastra Framework have been infected with an infostealer that steals wallet and browser data during installation, already affecting the heavily-used core package.
Cisco ISE contains multiple vulnerabilities that compromise critical system functions (code execution, privilege escalation, data access) and pose a high risk to network authentication.
Deterministic security models are no longer sufficient when AI systems make unforeseen decisions at runtime and interact with APIs and environments in unanticipated ways.
AI-SOCs will automate routine tasks and create new specialized roles such as Data Engineer, Agent-Orchestrator, and Model-Trainer, rather than eliminating existing jobs.
15 compromised JetBrains plugins masquerade as AI assistants and steal plaintext API keys over unencrypted HTTP connections to IP address 39.107.60.51.
ScarCruft uses fake Microsoft security alerts to distribute NarwhalRAT, a Python-based malware that operates in memory and communicates with command-and-control servers via compromised websites and pCloud APIs.