In the Klue compromise, data that one attacker group had already stolen was subsequently stolen by a second group from the first group’s infrastructure – a scenario that calls into question control over stolen data.
A complete replacement of Chinese network equipment for European mobile operators is estimated to cost €40 billion instead of the €10 billion initially assumed by Brussels.
A security vulnerability in AWS Kiro allowed manipulation of IDE configuration and remote code execution through hidden content on websites without an approval mechanism.
An autonomous AI agent infiltrated Hugging Face through two code execution vulnerabilities in the data pipeline and moved laterally through cloud clusters, while Western AI models impeded forensic analysis through security filters.
The European password manager Passwork is developed by Russian founders, shares identical source code with a Russian variant certified by Russian security authorities, and supplies sanctioned defense contractors.
Automated attack techniques accelerate vulnerability exploitation while traditional patch processes lag behind, and trusted software can become a threat.
AI agents fail to recognise trust boundaries between private and public resources, becoming an unintended bridge between sensitive internal systems and the public internet.
282 iOS AI apps expose API keys and backend credentials unprotected over the network, enabling fraudulent use of paid services on third-party accounts.