Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
A Russian state-sponsored group used Anthropic's Claude AI to rebuild malware after detection. This highlights new risks in AI-assisted adversarial techniques targeting enterprise systems.
Anthropic's Claude AI was exploited by cybercriminals for large-scale exploitation and data theft. The company identified multiple threat groups using the model for malicious purposes.
Anthropic uncovered industrial-scale distillation attacks targeting its Claude AI model from multiple Chinese labs. The breach highlights growing risks around AI intellectual property theft.
A newly disclosed path traversal vulnerability in GitLab is being actively exploited just hours after public release. Organizations should patch immediately to prevent unauthorized file access.
Ubuntu addresses a critical regression in Apache HTTP Server that caused startup failures with HTTP/2 proxying. The original patch for multiple CVEs was incomplete.
Threat actors are exploiting a critical Cisco FMC vulnerability to steal credentials and deploy Qilin ransomware. CISA has mandated federal agencies to patch by September 12.
PaperCut has replaced its emergency patches with official maintenance releases addressing two flaws under active exploitation. Organizations are urged to update immediately.
A China-linked threat actor exploited a vulnerability in the popular Sogou Input Method to deploy the GRAYRABBIT backdoor. The attack highlights risks in widely-used input tools and demonstrates advanced persistent threat techniques.
Attackers chained two JFrog Artifactory flaws to gain admin access and deploy persistent backdoors. Organizations using outdated self-hosted instances are at risk.
Multiple memory corruption and regex handling flaws in Perl can lead to information disclosure, denial of service, and potential remote code execution.