Anthropic has introduced new Compliance API endpoints for Claude Code, providing improved visibility into local AI agent activity while highlighting the need for broader endpoint governance.
Microsoft has disclosed the TerminalFix campaign, a new ClickFix variant that uses fake Cloudflare CAPTCHA pages to deploy a reverse tunnel backdoor through Windows Terminal and PowerShell.
Google has introduced operating system wide Encrypted Client Hello support, Local Network Protection, Certificate Transparency, and enhanced 2G security in Android 17 to improve user privacy and network protection.
Cosmos Labs has disclosed details of a critical Cosmos EVM vulnerability that was exploited across six blockchain networks, prompting urgent upgrade recommendations for affected chain operators.
Cybersecurity researchers have identified 19 Chrome and Edge extensions containing wallet stealing and cryptocurrency draining capabilities. The campaign has reportedly been active since February 2024 and uses compromised and newly created browser extensions.
Security researcher Olivier Laflamme has disclosed two critical vulnerabilities affecting the Unitree G1 EDU humanoid robot that could allow root remote code execution through network and Bluetooth attack paths.
ServiceNow has patched four vulnerabilities affecting its AI Platform, including three critical flaws rated CVSS 10.0 that could allow unauthenticated attackers to execute code or SQL statements.
Recorded Future has identified a new HOOKEDGE backdoor linked to APT28, targeting government and diplomatic organizations in Romania, Spain, and Türkiye through malicious Microsoft Word documents.
Researchers have disclosed a prompt injection vulnerability in Amazon Kiro IDE that could allow sensitive data exfiltration through Kiro Powers. Amazon addressed the issue in version 0.8.140.
Researchers have disclosed GPUThor, a new Rowhammer attack that bypasses ECC protections on select NVIDIA GDDR6 GPUs, enabling denial of service and host privilege escalation under specific conditions.
Arctic Wolf has identified the new GoCaracal malware framework, linking it with medium confidence to Dark Caracal and revealing its use of Ethereum smart contracts to update command and control infrastructure.
Aikido Security recreates the Claude Opus 4.6 gym booking incident, highlighting IDOR vulnerabilities, agent behavior, and the importance of secure API design.