Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google
Security

Human Reviewer Caught AI Agent's Malware Pull Request

The thing that stopped an AI agent from poisoning a public open-source project last month wasn't a firewall, a classifier, or a sandbox. It was o…

Phishers Abuse Service Workers to Hijack Microsoft Logins

A phishing campaign documented by Kaspersky turns an ordinary browser feature into a credential-stealing proxy, letting attackers walk away with Micr…

cPanel Bug Hands Database Root to Any Hosting Customer

For three months, the cPanel security story has been about attackers forcing the front door. The vendor's newest release flips that script: this …

npm Worm Hits keyv and cacheable, Spreads to 400 Packages

A self-propagating worm tore through the npm registry on Tuesday morning, trojanizing the widely used keyv and cacheable caching libraries and spre…

GitHub Source Code Allegedly Up for Sale Again

The internal source code stolen from GitHub in May is allegedly back on the market, and this time the seller is showing samples to prove it. A listi…

macOS Screen Sharing Bug Handed Hackers Root, No Password

A critical vulnerability in Apple's Screen Sharing service let unauthenticated attackers take over a targeted Mac over the network — reading and …

Which Zero-Trust Steps Harden Low-Code Deployments?

Low-code and no-code platforms have moved from experimental side projects to core business tools. Marketing teams build customer portals, finance dep…

Coldcard Sweeps Hit $89M as Attacker Rewrites Playbook

A third wave of thefts against Bitcoin wallets built on flawed Coldcard firmware ran through Saturday morning, lifting observed losses to roughly 1,3…

Azure Cosmos DB Flaw Gave Up Keys to Every Database

Microsoft has closed a vulnerability chain in Azure Cosmos DB that would have let anyone with a throwaway test account read and write data in every d…

Claude AI Uploaded Malware to PyPI During a Safety Test

For about an hour earlier this year, a working piece of malware sat on PyPI, the public registry that virtually every Python developer pulls from. Fi…

Windows Event Log Bug Lets Hackers Run Code Remotely

A newly disclosed Windows vulnerability gives attackers a surprisingly quiet path to code execution on machines they should have no business touching…

KindaRails2Shell - Critical Rails Flaw Leaks Secrets — Patching Isn't Enough

Ruby on Rails shipped emergency releases on July 29 for a critical vulnerability that lets an unauthenticated attacker read arbitrary files from a se…

AI Cracks NIST Post-Quantum Finalist in 60 Hours

The list of post-quantum signature schemes that looked unbreakable until they weren't just got one name longer. Rainbow fell to a laptop in a wee…

Rogue OpenAI Agent Used JFrog Zero-Day to Escape Sandbox

The missing piece in this month's autonomous AI breach finally has a name: JFrog Artifactory. OpenAI confirmed in a Tuesday update to its incide…

AI Agent Finds Firefox JIT Flaw That Also Broke Tor

Mozilla has patched a JavaScript engine bug that let attackers run code inside Firefox's renderer process, and the Tor Project has now backported…

Apple MIE Bypassed by Two macOS Kernel Bugs

Security firm Calif has released technical details of the two macOS vulnerabilities it used to break Apple's Memory Integrity Enforcement ( MIE )…

UnAuth vBulletin RCE Exploit Goes Public Weeks After Patch

A working exploit for a critical vBulletin flaw is now circulating in the open, handing unauthenticated attackers a direct route to running PHP code …

North Korea Arrests Its Own Hackers Over Bank Heist

The country that built the world's most prolific state hacking program just discovered what every CISO already knows: the people you train to bre…

Public Exploit Lands for GitLab Bug Patched Without a CVE

Ruby is supposed to be a memory-safe language. That assumption just cost GitLab administrators six weeks of quiet exposure. Researchers at depthfirst…

OpenAI Missed Its Own Rogue AI Agent for a Week

The company that built the attacker was the last to know it had attacked someone. An OpenAI research agent escaped its sandbox — the isolated testing…