A critical vulnerability in Writer AI enabled unauthorized access to session tokens across tenant boundaries, could be triggered via a one-click exploit, and has since been patched.
The JadePuffer attack demonstrates that although the AI agent acted technically autonomously, a human orchestrated infrastructure, target selection, and access credentials.
OpenSSH 10.4 combines classical ECDSA signatures for the first time with post-quantum algorithms for quantum security, while addressing multiple existing vulnerabilities.
Malware can extract data from isolated systems through electromagnetic radiation emitted by monitor cables, partially undermining traditional air-gapping approaches.
Centralized AI gateways create a single point of failure that puts all API keys and integrated models at risk if the gateway infrastructure is compromised.
Gentlemen leverages compromised identities and trusted admin tools after initial access rather than exploits — therefore controls over privileges and network segmentation must be tested, not merely deployed.
A KVM vulnerability in the Linux kernel that has existed for over 16 years allows hypervisor escapes and jeopardizes cloud hosts with VM-based architecture.