Researchers find ‘agent-to-agent’ privilege escalation in Google’s ADK for Python repo
A low-privileged agent triggered by a PR or issue could be led to manipulate a high-privileged agent.
20 articles
A low-privileged agent triggered by a PR or issue could be led to manipulate a high-privileged agent.
A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent. The post Gemini Agent-to-Agent...
Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at ...
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cP...
Indusface has announced SwyftComply AI, an autonomous vulnerability remediation solution that virtually patches vulnerabilities surfaced by AI-assisted pente...
And it’s personal information (alternate link): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meeting...
ESET is expanding its AI capabilities across threat detection, investigations, threat protection, and security operations, delivering added value to customer...
Interpol claims AI is driving a surge in cybercrime in Africa, with related losses doubling
A cryptographic technique could let companies prove they're vulnerable to critical flaws without revealing the sensitive data that attackers could exploit. T...
Joinable Labs launched Joinable Security, the first domain on the Joinable platform, with two products: Joinable Threat Map, a free utility that lets the sec...
Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login. The post Decades-Old BMC Vulnerability Exposes Thou...
Securonix has announced expanded cybersecurity cost reduction, expanded Threat Analytics for Microsoft Sentinel, and new Governed AI Agent Detection and Resp...
A critical vulnerability in Gitea has been identified, potentially allowing unauthenticated remote attackers to read arbitrary files on vulnerable servers an...
A recently disclosed privilege-related vulnerability in the Common UNIX Printing System (CUPS) on macOS could allow an unprivileged local user to create atta...
Uptime Kuma checks whether a website, a Docker container, a DNS record, or a Steam game server is still answering, and pushes a message to Telegram, Slack, o...
Legit Security has unveiled VibeGuard 2.0, bringing a new endpoint security capability that seamlessly discovers and integrates with coding agents, secures t...
Adobe has released an urgent security update for Adobe Campaign Classic, addressing multiple critical vulnerabilities that could allow remote attackers to ex...
Tanium has announced a series of new autonomous security capabilities across the Tanium Autonomous IT Platform. Spanning agentic AI, exposure management and ...
A large-scale malware campaign targeting developers and AI users has been uncovered ,revealing how attackers are weaponizing fake AI tools and cloned GitHub ...
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cac...