Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
Microsoft published a list of everything wrong with its own defaults.
Claude Code Opus 5’s Auto Mode can be tricked into running malicious code via a simple website-summary request, succeeding in ...
A prompt-injection demonstration has shown how Anthropic’s Claude Code Opus 5 can be steered from a website-summary task into ...
SPECTRE backdoor, deployed by Chinese-speaking hacker group UAT-10147, blinds CrowdStrike Falcon, SentinelOne, and Microsoft ...
Anthropic has just published the results of a protein design campaign. Fifteen targets, a written brief and an instruction to ...
A toolkit shaped by decades of Unix history makes technical work second nature on Linux.
A supply-chain worm has compromised multiple releases of @7nohe/openapi-react-query-codegen, an npm package that generates ...
Hackers target exposed AI gateways and agent tools to steal credentials, execute commands, and deploy cryptominers through AI ...
Code autonomy is the level of AI control where software agents stop suggesting edits and start doing the whole job: reading a ...
OpenAI agents hacked Hugging Face in a 700-strong swarm after 1,200 agents exchanged 70,000 messages. ETIH’s edtech news report explains how.
LLM security testing for pentesters: map attacks to the OWASP LLM Top 10, break a vulnerable MCP server locally, and turn ...