Systematic GitHub API queries are increasingly used for corporate reconnaissance prior to attacks, as threat actors abuse public APIs and leverage dormant ghost accounts to mimic legitimate usage patterns.
A single attacker demonstrates the danger of credential theft combined with automated AI workflows: penetration of an AWS environment was achieved in under three days.
A gap in Dialogflow CX made it possible to gain access to other chatbots within the same project through a compromised agent setup and exfiltrate user data or inject phishing messages.
Stolen access credentials from British authorities and infrastructure providers are being marketed on the dark web, including NHS accounts, energy suppliers, and pharmaceutical vendors.
Attackers create fraudulent OpenAI organizations under real company names and send invitations from OpenAI’s infrastructure to trick authorized employees into using them and intercept sensitive data they enter.
Vulnerability in Amazon Q for VS Code allows credential theft through manipulated repositories and reveals systemic risks in AI-powered developer tools.
Vulnerability in Amazon Q for VS Code allows credential theft through manipulated repositories and reveals systemic risks in AI-assisted developer tools.