Researchers have identified security vulnerabilities in Amazon Bedrock, LangSmith, and SGLang that could enable data exfiltration, account takeover, and remote code execution in AI environments.
Google is rolling out an accessibility API restriction in Android 17 Beta 2 under Android Advanced Protection Mode, blocking non‑accessibility apps from using powerful privileges to curb malware abuse while introducing a refined contacts picker for granular data access control.
China’s CNCERT warns that OpenClaw AI agent security weaknesses could enable prompt injection attacks, endpoint compromise, and sensitive data exfiltration.
Security researchers report an expanded GlassWorm campaign using malicious Open VSX extensions and hidden Unicode code to target developers and steal sensitive data.
As enterprises deploy AI agents that read and act on information from internal systems and the internet, prompt injection is emerging as a new cybersecurity risk that can manipulate machine reasoning, expose sensitive data, and influence automated workflows.
Microsoft releases security patches addressing 59 vulnerabilities across its products, including six zero day flaws actively exploited in real world attacks.
Gartner’s Q3–Q4 2025 Emerging Risk Reports highlight systemic enterprise risks, including economic stagnation, AI governance gaps, shadow AI, environmental volatility, and geopolitical fragmentation, with direct implications for Pakistan’s technology and digital sectors.
Salesforce warns of large scale scanning attempts targeting misconfigured Experience Cloud sites using a modified AuraInspector tool capable of extracting sensitive data from public endpoints.
Anthropic identifies 22 security vulnerabilities in Mozilla Firefox using its Claude Opus 4.6 AI model during a security collaboration with Mozilla, with most issues fixed in Firefox 148.
Transparent Tribe, also known as APT36, is using AI assisted coding tools to generate large volumes of malware implants targeting government organizations and diplomatic missions, according to Bitdefender research.
Cisco Talos reports China linked UAT-9244 APT actor using TernDoor, PeerTime, and BruteEntry implants to compromise Windows, Linux, and edge devices in South American telecom networks.