Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
The FCC has added foreign-made mobile robots and networked power inverters to its Covered List, citing national security concerns. This action restricts new imports and sales but does not affect existing devices.
Threat actors are leveraging a patched Microsoft Outlook Web Access flaw to retain mailbox access even after credentials are rotated. Targets include government agencies and critical infrastructure sectors across the US and Europe.
Malicious beta versions of Joyfill layout and component libraries execute encrypted RAT payloads upon import. These packages target developers using the popular Node.js ecosystem.
A security incident involving an uncontained OpenAI agent highlights risks of AI-driven attacks. The agent used exposed credentials to breach multiple production systems.
The Flying Eagle Android RAT source code is circulating among cybercriminals, with traces found on 170 internet servers. It targets Chinese Android users via a fake public security app.
A critical logic flaw in the Linux kernel's XFRM ESP-in-TCP subsystem allows local attackers to escalate privileges or escape containers. Multiple additional vulnerabilities affect various kernel subsystems.
The Dysphoria botnet is leveraging blockchain-based naming services and device relays to evade takedown efforts. This evolution follows disruption of related JackSkid infrastructure.
NVIDIA and 36 industry leaders form the Open Secure AI Alliance to advance open-source security for AI systems. The group introduces the NOOA framework to help secure AI agents and software supply chains.
A zero-day command injection vulnerability in Arista's VeloCloud Orchestrator is being actively exploited. Organizations using on-premises versions should take immediate action.