Risk & Resilience

New Anthropic Compliance API Enhances Claude Code Security Monitoring

Anthropic has introduced new Compliance API endpoints for Claude Code, providing improved visibility into local AI agent activity while highlighting the need for broader endpoint governance.

Microsoft Warns Of TerminalFix ClickFix Variant Targeting Windows Users

Microsoft has disclosed the TerminalFix campaign, a new ClickFix variant that uses fake Cloudflare CAPTCHA pages to deploy a reverse tunnel backdoor through Windows Terminal and PowerShell.

Google Introduces New Privacy And Network Security Features In Android 17

Google has introduced operating system wide Encrypted Client Hello support, Local Network Protection, Certificate Transparency, and enhanced 2G security in Android 17 to improve user privacy and network protection.

Critical Cosmos EVM Vulnerability Impacts Multiple Blockchain Networks

Cosmos Labs has disclosed details of a critical Cosmos EVM vulnerability that was exploited across six blockchain networks, prompting urgent upgrade recommendations for affected chain operators.

Malicious Chrome And Edge Extensions Target Crypto Wallets And User Credentials

Cybersecurity researchers have identified 19 Chrome and Edge extensions containing wallet stealing and cryptocurrency draining capabilities. The campaign has reportedly been active since February 2024 and uses compromised and newly created browser extensions.

Security Research Reveals Critical Unitree G1 EDU Root RCE Vulnerabilities

Security researcher Olivier Laflamme has disclosed two critical vulnerabilities affecting the Unitree G1 EDU humanoid robot that could allow root remote code execution through network and Bluetooth attack paths.

ServiceNow Releases Fixes For Four AI Platform Security Vulnerabilities

ServiceNow has patched four vulnerabilities affecting its AI Platform, including three critical flaws rated CVSS 10.0 that could allow unauthenticated attackers to execute code or SQL statements.

HOOKEDGE Backdoor Campaign Linked To APT28 Targets European Government Networks

Recorded Future has identified a new HOOKEDGE backdoor linked to APT28, targeting government and diplomatic organizations in Romania, Spain, and Türkiye through malicious Microsoft Word documents.

Researchers Disclose Prompt Injection Vulnerability In Amazon Kiro IDE

Researchers have disclosed a prompt injection vulnerability in Amazon Kiro IDE that could allow sensitive data exfiltration through Kiro Powers. Amazon addressed the issue in version 0.8.140.

Researchers Reveal GPUThor Rowhammer Technique Affecting NVIDIA GDDR6 GPUs

Researchers have disclosed GPUThor, a new Rowhammer attack that bypasses ECC protections on select NVIDIA GDDR6 GPUs, enabling denial of service and host privilege escalation under specific conditions.

GoCaracal Malware Adopts Ethereum Smart Contracts For Command And Control Resilience

Arctic Wolf has identified the new GoCaracal malware framework, linking it with medium confidence to Dark Caracal and revealing its use of Ethereum smart contracts to update command and control infrastructure.

Aikido Security Recreates Claude Opus 4.6 Gym Booking Behavior In Controlled Tests

Aikido Security recreates the Claude Opus 4.6 gym booking incident, highlighting IDOR vulnerabilities, agent behavior, and the importance of secure API design.

Recent articles

spot_img