Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Massive supply-chain attack compromises 440 packages under four hours
1+ hour, 7+ min ago (491+ words) In less than four hours early Tuesday, an attacker compromised a GitHub maintainer account and unleashed a self-replicating piece of malware which injected malicious code into more than 440 distinct npm packages, according to multiple security firms. The worm, built on…...
How companies could share cyber risks without exposing their secrets
13+ hour, 16+ min ago (400+ words) Zero-knowledge proofs could let infrastructure operators answer key security questions without handing over the sensitive data behind their answers. The data that would help the most is what companies are least willing to share. A vulnerability scan can show which…...
CrowdStrike: AI is now both the weapon and the target in cyberattacks
1+ day, 16+ hour ago (518+ words) While AI is supposed to help defenders, it’s now creating more than twice as much noise as human-triggered incidents CrowdStrike detects as potentially malicious. The company’s threat hunting team and systems triaged an average of 14 million detection leads daily, resulting…...
What the Hugging Face breach reveals about defense in the age of agentic AI
4+ day, 13+ hour ago (728+ words) We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days…...
Okta’s deal for Permiso aims to close gaps in identity threat detection
5+ day, 2+ hour ago (426+ words) Ely Kahn, Okta's chief product officer, told CyberScoop the deal enriches the company's current threat detection tools and gives it deeper visibility into AI agent activity across enterprise systems. The post Okta’s deal for Permiso aims to close gaps in…...
Google's solution to hacker name confusion? Yet another naming system
1+ week, 1+ day ago (543+ words) Google’s solution to hacker name confusion? Yet another naming system CyberScoop If you are a CISO, here is a new problem for the pile: Do I worry more about Sandworm Relic or Strawberry Tempest? The company said in a blog…...
Despite multiple takedowns, botnets continue to grow
1+ week, 4+ day ago (396+ words) Botnets powered by residential proxy networks are proliferating, enabling cybercriminals of all types to evade detection by blending in with seemingly legitimate traffic, Lumen Technology’s Black Lotus Labs said in a report Friday. Super-sized botnets are also gaining momentum, according…...
Malware is targeting AI tools in software development environments
1+ week, 6+ day ago (523+ words) Malware targeting AI coding assistants and software developers’ automated workflows is spreading into more environments with more capabilities, placing defenders at a growing disadvantage. A malware strain dubbed Sandworm_Mode, first discovered by Socket in February, represents a growing threat to software…...
White House accuses Chinese company of distilling Anthropic’s Fable
1+ week, 6+ day ago (580+ words) A top White House technology official is accusing a Chinese company of distilling Anthropic’s models to create their own AI product. Michael Kratsios, who leads the White House Office of Science and Technology Policy, claimed that Moonshot AI, a Beijing,…...
AI models keep getting caught cheating
2+ week, 3+ hour ago (574+ words) Frontier AI companies often refer to their models as “helpful assistants” or try to compare them to entry-level employees. But new research from the UK’s AI Security Institute reinforces how large language models suffer from a common flaw that would…...