Organizations must transition from signature-based, reactive controls to an architectural foundation that combats AI with AI, leveraging autonomous agents and real-time behavioral analysis.
A zero-day vulnerability in Zimbra enabled Russian attackers to exfiltrate 90 days of email history, directories, stored passwords, and 2FA recovery codes by simply opening a message.
A prompt injection vulnerability in AWS Kiro enabled manipulation of the mcp.json configuration file and code execution — AWS has implemented protection measures for sensitive file paths.
A seven-year-old undetected race condition in XFS allows unprivileged processes to overwrite arbitrary files and gain root access, but can only be fixed through a kernel update.
The msaRAT implant used by Chaos ransomware evades network detection by routing C2 traffic through locally controlled browser processes instead of direct outbound connections.
An unsecured AWS storage bucket belonging to car rental aggregator Carla exposed hundreds of new booking documents daily, containing complete driver identities, travel dates, and vehicle details to potential attackers.
Cybercriminals in Germany increasingly use social engineering and impersonation of legitimate processes instead of pure malware techniques, as the Gen Report shows with increases of 134 percent in fake shop fraud and 160 percent in dropper malware.