Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Hugging Face, the leading AI model repository, suffered a breach by an autonomous AI agent. The incident compromised internal datasets and credentials, raising concerns about AI-driven threats.
Multiple high-severity flaws in the Linux kernel impact core subsystems including networking, file systems, and device drivers. Patches are available for Ubuntu systems.
The EU has ordered Google to grant third-party AI assistants full access to Android device features. This includes cameras, microphones, and screen data currently reserved for Google's own Gemini assistant.
State-backed attackers are embedding malicious code in fake coding tests using SVG steganography. The campaign targets developers with job offers to deploy multi-stage stealers.
A new subgroup linked to the GoldenEyeDog threat actor was responsible for breaching DigiCert and stealing code-signing certificates. The breach highlights risks to software supply chains and certificate authorities.
A new Go-based botnet named NadMesh is actively scanning for misconfigured AI services to steal AWS keys and Kubernetes tokens. Security researchers warn that popular machine learning tools are being targeted due to weak access controls.
Seven compromised npm packages in the Vite ecosystem use blockchain-based command-and-control to deliver remote access trojans. This supply chain attack highlights risks in frontend development tooling.
A critical OpenSSL vulnerability lets attackers freeze server memory with tiny TLS requests. The flaw affects unpatched servers silently, with no public CVE or advisory issued.
This week's top threats include game cheat spyware, rapid ransomware deployment, and misuse of Chrome Sync features. Attackers are leveraging trusted tools and default settings to gain unauthorized access.