OpenAI Models Hide Errors and Hunt API Keys OpenAI disclosed six misalignment incidents found during model training and evaluation. Cases included GPT-5.6 Sol instances instructing future instances to hide errors, another model using an exposed API key without permission before fabricating requested data, and agents uploading files or communicating through repositories. The cases were individual …
Cybersecurity
BragJack Turns Browser AI Into an Insider Threat Researchers demonstrated BragJack, a proof-of-concept attack that let one ordinary extension compromise AI-enabled environments in Chrome, Comet, Edge, Opera Neon, and Claude in Chrome. Depending on the product, it could steal files, screenshots, and browsing data, command agents on authenticated sites, or activate Chrome’s camera and microphone. …
Claude Helps Hackers Hunt 1.8M Apps for Secrets One mislaid key can now invite an industrial-scale treasure hunt. A massive credential-harvesting scheme orchestrated by a suspected ShinyHunters affiliate relied heavily on Claude, according to Anthropic’s latest threat report. The French-speaking hacker utilized 10 AWS EC2 instances to pull 1.8 million Android APKs from various marketplaces, …
Rhysida Leaks 1.4 Million Berlin Government Files Berlin refused Rhysida’s ransom demand, prompting the group to publish nearly 1.4 million stolen government files. This leaked data reportedly includes employee records, identity documents, and potentially sensitive emergency-planning material. Not paying the ransom often gets the most attention, but security teams also need a plan for stolen …
GitHub will revoke three password-protected code-signing certificates for its Desktop and Atom applications on Thursday of this week. GitHub detected unauthorized access to repositories in early December 2022. The revocation will invalidate certain versions of Desktop and Atom as of February 2. Mac users are urged to update to the latest version of Desktop (2.3.1.5 …
The biggest story, by far, even if it didn’t get any media coverage, was Slack’s secret data breach disclosure published just ahead of New Year’s Eve. The company said a threat actor stole “Slack employee tokens” and gained access to its GitHub source code repositories. This happened on December 27, according to Slack, and the …
Mantax Otax Turns Android Phones Against You Mantax Otax is a new Android threat linked to Indonesian operators that merges extortion, espionage, and straight-up harassment after victims sideload malicious APKs. It can swipe lock-screen PINs, OTPs, texts, web histories, locations, and secretly snap photos. Android 9 and older devices face another problem: It can encrypt …
AI Agents Compromise 440 PaperCut Instances A suspected Russian-speaking attacker unleashed a swarm of AI agents to exploit two PaperCut NG/MF flaws, breaching roughly 440 instances at 395 organizations globally. Nearly half of the victims were in education. Powered by a Codex harness and DeepSeek model, the automated blitz hit 11 organizations in 26 seconds. …
Google Fixes Chrome Zero-Day Used in Attacks Google has patched another Chrome zero-day after confirming attackers are already exploiting the vulnerability in the wild. The out-of-bounds write flaw can be triggered through a crafted webpage, potentially allowing arbitrary code execution within Chrome’s sandbox. AI is accelerating vulnerability discovery and adding to an already overwhelming volume …
How Do You Implement Zero Trust Security Without Destroying Network Performance? Zero trust goes beyond basic VPNs. Learn how microsegmentation firewalls impact latency and why ABAC requires refactoring application code. Key Takeaways What: Zero Trust replaces static perimeter defenses with continuous, context-aware request verification. Why: Cloud migration and remote work make internal networks inherently hostile. …