Google has released Chrome 152.0.7977.75/.76 for Windows and macOS and Chrome 152.0.7977.75 for Linux, addressing 26 security vulnerabilities across the browser. The update includes two critical use-after-free flaws affecting Shared …
Hugging Face Flaw Lets Malicious AI Models Plant Python Code on User Systems
A newly disclosed vulnerability in Hugging Face Transformers could allow malicious AI model repositories to place attacker-controlled Python files on a user’s system before the user approves remote code execution. …
OpenAI’s New Astra AI Can Discover Zero-Day Security Flaws and Build Exploits
OpenAI says its upcoming Astra model has reached the company’s Critical cybersecurity capability threshold, meaning it can independently discover unknown vulnerabilities and develop working exploits against hardened systems when given …
Anthropic Launches Claude Fable and Mythos 5.1 for Advanced Coding and Research
Anthropic has rolled out two new frontier AI models, Claude Fable 5.1 and Claude Mythos 5.1, positioning them as the most capable systems yet for software development, enterprise knowledge work, …
OWASP Launches OASIS AI Initiative to Fix Open Source Vulnerabilities at Scale
OWASP has launched the Open Automated Security Initiative for Software (OASIS), a global community effort designed to close the gap between finding vulnerabilities in open source code and actually fixing …
FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and …
Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations
Cybercriminals are increasingly weaponizing trusted cloud platforms such as Microsoft Azure, Google Firebase, Google Cloud Storage, Amazon Web Services, and Cloudflare to host phishing infrastructure aimed squarely at the financial …
Five Hackers Plead Guilty to ATM Jackpotting Attacks Using Malware to Dispense Cash
Five Venezuelan nationals have pleaded guilty in a U.S. federal case involving attempted ATM jackpotting attacks. This criminal technique uses malware to force cash machines to dispense money without legitimate …
Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability
Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, …
Hackers Pose as Recruiters and Send Fake Coding Tests to Infect Software Developers
Cybercriminals are posing as recruiters to turn routine job interviews into malware traps for software developers. Their latest campaign delivers two cross-platform remote access tools, NodeRabbit and PollCat, through coding …

