Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
The implant, identified by Rapid7 Labs with medium confidence as originating from North Korean state-sponsored actors, targets entities in South Korea's auto...
The attack occurred between 07:35 UTC and 21:45 UTC on Monday, August 31.
Abliteration.ai aims to enable offensive cyber operations, red-teaming, and agent testing that other models refuse.
The cyberattack, which occurred around June 15, resulted in the theft of patient data including names, dates of birth, medical testing information, laborator...
Invisible Unicode tag characters often used for AI prompt injection have appeared in high-volume phishing attacks.
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153...
The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection. AI data company Micro1 has now offered $12.
Researchers have discovered a public wiki message board that they claim was used by autonomous AI agents, identifying themselves as OpenAI systems, to exchan...
Hunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets.
Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security iss...
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and...
Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion campai...
A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. T...
FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans.
In this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build a...
Threat actors are increasingly converting stolen cloud credentials into access to costly generative AI services, a technique known as LLMjacking.
The suspicious calls, texts, and DMs you got recently aren’t a coincidence, according to Malwarebytes. Scammers have worked out which platform gets them the ...
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credent...
The malware, disguised as a "privacy browser," was distributed via a deceptive sponsored search result after an employee mistyped a URL.