** Ravie Lakshmanan ** Jan 22, 2026 Vulnerability / Zero-Day Cisco has released fresh patches to address what it described as a “critical” security vulnerability impacting multiple Unified …
AI Security Roundup
Daily AI security roundup covering malware, vulnerabilities, defensive research, cloud risk, and incident response signals from trusted technical sources.
ISC Stormcast For Thursday, January 22nd, 2026 https://isc.sans.edu/podcastdetail/9776, (Thu, Jan 22nd)
ISC Stormcast For Thursday, January 22nd, 2026 https://isc.sans.edu/podcastdetail/9776
As many as 3,136 individual IP addresses linked to likely targets of the Contagious Interview activity have been identified, with the campaign claiming 20 potential victim organizations spanning …
** Ravie Lakshmanan ** Jan 21, 2026 Vulnerability / Network Security Zoom and GitLab have released security updates to resolve a number of security vulnerabilities that could result in …
** The Hacker News ** Jan 21, 2026 Artificial Intelligence / Automation Every managed security provider is chasing the same problem in 2026 — too many alerts, too few analysts, and clients demanding …
Internet Voting is Too Insecure for Use in Elections No matter how many times we say it, the idea comes back again and again. Hopefully, this letter will hold back the tide for at least a while …
Gartner® doesn’t create new categories lightly. Generally speaking, a new acronym only emerges when the industry’s collective “to-do list” has become mathematically impossible …
VoidLink Linux Malware Framework Built with AI Assistance Reaches 88,000 Lines of Code
The recently discovered sophisticated Linux malware framework known as VoidLink is assessed to have been developed by a single person with assistance from an artificial intelligence (AI) model. …
Visual Studio Code is a popular open-source code editor[ 1 ]. But it’s much more than a simple editor, it’s a complete development platform that supports many languages and it is available on multiple …
** Ravie Lakshmanan ** Jan 21, 2026 Vulnerability / Artificial Intelligence Security vulnerabilities were uncovered in the popular open-source artificial intelligence (AI) framework Chainlit that …
** Ravie Lakshmanan ** Jan 21, 2026 Email Security / Malware LastPass is alerting users to a new active phishing campaign that’s impersonating the password management service, which aims to …
** Ravie Lakshmanan ** Jan 21, 2026 Open Source / Vulnerability A security vulnerability has been disclosed in the popular binary-parser npm library that, if successfully exploited, could result in …
ISC Stormcast For Wednesday, January 21st, 2026 https://isc.sans.edu/podcastdetail/9774, (Wed, Jan 21st)
ISC Stormcast For Wednesday, January 21st, 2026 https://isc.sans.edu/podcastdetail/9774
The North Korean threat actors associated with the long-running Contagious Interview campaign have been observed using malicious Microsoft Visual Studio Code (VS Code) projects as lures to deliver a …
** Ravie Lakshmanan ** Jan 20, 2026 Vulnerability / Artificial Intelligence A set of three security vulnerabilities has been disclosed in mcp-server-git , the official Git Model Context Protocol ( MCP …
** Ravie Lakshmanan ** Jan 20, 2026 Malware / Threat Intelligence Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious …
** The Hacker News ** Jan 20, 2026 Enterprise Security / AI Security The Problem: The Identities Left Behind As organizations grow and evolve, employees, contractors, services, and systems come and go …
Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto
** Ravie Lakshmanan ** Jan 20, 2026 Cloud Security / Developer Security Cybersecurity researchers have disclosed details of a malware campaign that’s targeting software developers with a new …
Leaked API keys are no longer unusual, nor are the breaches that follow. So why are sensitive tokens still being so easily exposed? To find out, Intruder’s research team looked at what …
Could ChatGPT Convince You to Buy Something? Eighteen months ago, it was plausible that artificial intelligence might take a different path than social media. Back then, AI’s development hadn’t …
** Ravie Lakshmanan ** Jan 20, 2026 Web Security / Vulnerability Cloudflare has addressed a security vulnerability impacting its Automatic Certificate Management Environment ( ACME ) validation logic …
IDNs or “International Domain Names” have been with us for a while now (see RFC3490[ 1 ]). They are (ab)used in many attack scenarios because.. it works! Who can immediately spot the difference …
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion
** Ravie Lakshmanan ** Jan 20, 2026 Cryptocurrency / Artificial Intelligence A Telegram-based guarantee marketplace known for advertising a broad range of illicit services appears to be winding down …
ISC Stormcast For Tuesday, January 20th, 2026 https://isc.sans.edu/podcastdetail/9772, (Tue, Jan 20th)
ISC Stormcast For Tuesday, January 20th, 2026 https://isc.sans.edu/podcastdetail/9772
Google Gemini Prompt Injection Flaw Exposed Private Calendar Data via Malicious Invites
Cybersecurity researchers have disclosed details of a security flaw that leverages indirect prompt injection targeting Google Gemini as a way to bypass authorization guardrails and use Google Calendar …