The Oasis researchers document a vulnerability chain that can be initiated from any website the AI agent (or its user) visits, without users needing to interact in any way or being at all aware that they are being compromised. The attack targets the OpenClaw "gateway" that essentially acts as the AI agent's nerve center.
Alarms raised about embedded TikTok browser capable of tracking keystrokes. Company says that the ability exists within the code, but that it is not active and only used internally for debugging and testing purposes.
Security researchers discovered 9,000 unsecured internet-facing VNC servers that threat actors could use to access internal networks, including critical infrastructure organizations.
New research from security firm Dragos finds that Volt Typhoon, one of the primary groups of state-sponsored Chinese hackers menacing the US as of late, was able to dwell in the Massachusetts electric grid for more than 300 days beginning in early 2023.
Security researchers at SafeBreach discovered a method to collect millions of stolen user credentials through Google's malware analysis platform, VirusTotal without compromising any organizations.
A ChatGPT vulnerability documented in a new report causes training data, some containing personal information, to randomly appear when one tells the chatbot to repeat a particular word.
XIoT devices are laden with security risks. 68% have a known vulnerability with a CVSS score of at least 8 and 18% are carrying a vulnerability of at least 9. And the average organization has three to five XIoT devices per employee.
Check Point discovered another security vulnerability in Qualcomm chips affecting 40% of smartphones, allowing hackers to inject code in Android phones, including Google, Samsung, LG, Xiaomi, and One Plus brands.
New security-by-design and security-by-default guidelines from a collection of federal agencies provide the first guidance of its type issued to urge manufacturers to ship devices with adequate security for the modern threat landscape.
Malwarebytes detected a credit card skimmer belonging to a potent Magecart attack threat actor on Segway's online store embedded within a favicon.ico image file.









