13 million tool calls: auditing every AI coding agent action with Elastic Agent
Cursor hooks and Elastic Agent capture every tool call, shell command, file read and MCP request as structured events you can hunt with ES|QL.
Cursor hooks and Elastic Agent capture every tool call, shell command, file read and MCP request as structured events you can hunt with ES|QL.
Companies are sending sensitive data, including injury reports, pizza orders, and test credentials, to domains like @noreply.us and @noreply.
The misconfiguration on Klaviyo's sign-up page allowed any third-party trackers present on the site to potentially access and share sensitive customer data.
The vulnerabilities were found in Samsung's proprietary system apps, which cannot be uninstalled by users and operate outside the protection of Google Play P...
Researchers identified that FirewallFalcon Manager secretly redirects traffic, weakens server security, and in older versions, installs a universal SSH backd...
The company rolled out “Red” and “Blue” programs for defenders, introduced a new model and announced partnerships with 16 major cybersecurity vendors. The po...
We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) f...
The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland...
Two Polish security researchers, Robert Kruczek and Kamil Szczurowski, discovered over 10,000 affected public entities with 250,000 websites exhibiting secur...
The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure. The ...
The breach occurred when an employee fell victim to a phishing scam, impersonating a business contact and presenting a fake Microsoft sharing link.
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputat...
Gartner predicts that by 2029, most privacy incidents will arise from AI-generated inferences rather than direct exposure of personal information.
Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a z...
Researchers at Zenity Labs discovered a campaign on skills.sh, a Vercel-hosted registry for AI skills.
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe.
Malicious “Solidity Pro” extensions are abusing the trust developers place in VS Code and Open VSX tooling, evolving from delayed payload droppers into broad...
Interlock ransomware incident that shows how unprotected endpoints can give attackers enough time to steal credentials, establish persistence, and reach a do...
Anthropic’s Claude Opus 5 has significantly reduced the likelihood of a successful indirect prompt injection (IPI) attack, bringing it down to 2% over 15 att...
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observe...