Attackers exploit the legitimate Microsoft authentication flow as an attack vector, bypassing traditional anti-phishing controls through social engineering lures.
Critical wireless vulnerabilities in hundreds of thousands of Hoymiles inverters enable remote shutdown and destruction of PV systems without authentication.
Agent-driven GitHub workflows can be manipulated through crafted public issues to unauthorisedly disclose private repositories of the enterprise when the agent has organisation-wide read access.
Standard CI security scanners fail to detect attack scenarios in GitHub Actions through their structural distribution across multiple workflows and external actions, necessitating complementary governance measures.
A critical vulnerability in Writer AI enabled unauthorized access to session tokens across tenant boundaries, could be triggered via a one-click exploit, and has since been patched.
The JadePuffer attack demonstrates that although the AI agent acted technically autonomously, a human orchestrated infrastructure, target selection, and access credentials.
OpenSSH 10.4 combines classical ECDSA signatures for the first time with post-quantum algorithms for quantum security, while addressing multiple existing vulnerabilities.
Malware can extract data from isolated systems through electromagnetic radiation emitted by monitor cables, partially undermining traditional air-gapping approaches.