A Russian-speaking threat actor pointed a swarm of AI agents at one PaperCut vulnerability — and beat human defenders to the finish line.
patch management
+6
Researchers turned Microsoft Copilot into a full reconnaissance tool using nothing but polite, innocent-sounding questions — and any AI assistant with broad access could do the same.
meta-hacking
+9
The signature that proves a Firefox update is real got exposed — and there's no way to know who saw it
Software Updates
Stolen and resold AI accounts are turning shared logins into a surveillance channel nobody notices
Account Takeover
A hidden instruction in one Word file just proved AI assistants will infect every document they touch next.
Microsoft Copilot
+7
A hidden comment in a pull request is all it takes to hijack the AI gatekeeper your team trusts to ship safe code
Zero Trust
One email is all it takes to plant a permanent lie in your AI assistant's memory — and there's no patch coming, because it isn't a bug.
identity-security
Symlink attacks, hallucinated packages, and prompt injection are turning your AI pair programmer into an attacker's easiest way in
NHI
The forensics always leads back to the same place — an account that shouldn't have existed, with access it shouldn't have had. Here's what to fix before the 2 AM alert.
Convention files, prompt injection, and why the line between productivity tool and data pipeline just disappeared
You clicked "Add to Chrome" because it promised to make you faster. You actually installed a wiretap.
chrome-extensions
The Vercel breach wasn't a credential failure. It was a token problem — and your IAM program probably can't see it.
Oauth Security
Five vendors. Six weeks. The same architectural failure. Here's why agents keep shipping with godmode permissions — and what good actually looks like.
Least Privilege
+4