The Register - Security
Researchers say they identified a supply-chain attack technique in the GitHub repository for Google’s Agent Development Kit (ADK) for Python, in which a lower-privileged AI agent could be manipulated...
3 Aug 20262 min read
Read article →The Hacker News
Security researchers have identified 18 malicious npm packages involved in a targeted software supply-chain campaign against developers using Alibaba-related tools. The packages deliver a cross-platfo...
3 Aug 20262 min read
Read article →Dark Reading
Attackers are exploiting a newly identified authentication-bypass weakness affecting N-able remote monitoring and management (RMM) servers, according to the vendor’s latest disclosure.Tracked as CVE-2...
3 Aug 20261 min read
Read article →BleepingComputer
OpenAI has provided an early look at Astra, an unreleased model family intended to handle complex problems that require sustained effort over extended periods. The company says an internal version of...
2 Aug 20262 min read
Read article →SecurityWeek
Cybersecurity investment management company Balance Theory has raised $19 million in a Series A financing round aimed at expanding its platform for enterprise security leaders. SYN Ventures led the ro...
2 Aug 20261 min read
Read article →The Register - Security
Anthropic has disclosed that several AI models reached and interacted with external systems during a cybersecurity evaluation after an environment intended to be offline was mistakenly connected to th...
2 Aug 20262 min read
Read article →The Hacker News
A firmware vulnerability in certain Coldcard hardware wallets has been linked to the theft of 1,082.65 bitcoin, worth approximately $70.2 million when the incident occurred. Galaxy Research said an at...
1 Aug 20262 min read
Read article →Dark Reading
The Cybersecurity and Infrastructure Security Agency has issued updated guidance for software bills of materials (SBOMs), adding roughly two dozen changes intended to make the information they contain...
1 Aug 20262 min read
Read article →BleepingComputer
Ruby on Rails maintainers have released patches for a critical Active Storage vulnerability that can let unauthenticated attackers retrieve arbitrary files from affected servers and potentially achiev...
1 Aug 20262 min read
Read article →SecurityWeek
A range of cybersecurity developments this week involved data exposure, software vulnerabilities, credential attacks and emerging research into artificial intelligence-assisted security testing.Incide...
31 Jul 20262 min read
Read article →The Register - Security
Brinks Home, a major provider of residential and commercial security services, says it has detected unauthorized access to part of its information technology environment. The disclosure follows a clai...
31 Jul 20262 min read
Read article →The Hacker News
A previously unattributed threat actor believed to be Chinese-speaking has targeted government organizations and related institutions across Central Asia since January 2025, according to an analysis b...
31 Jul 20262 min read
Read article →