** Dec 29, 2026 ** Ravie Lakshmanan Database Security / Vulnerability A recently disclosed security vulnerability in MongoDB has come under active exploitation in the wild, with over 87,000 …
AI Security Roundup
Daily AI security roundup covering malware, vulnerabilities, defensive research, cloud risk, and incident response signals from trusted technical sources.
Are We Ready to Be Governed by Artificial Intelligence? Artificial Intelligence (AI) overlords are a common trope in science-fiction dystopias, but the reality looks much more prosaic. The …
Cybersecurity researchers have disclosed details of what has been described as a “sustained and targeted” spear-phishing campaign that has published over two dozen packages to the npm …
ISC Stormcast For Sunday, December 28th, 2025 https://isc.sans.edu/podcastdetail/9750, (Sun, Dec 28th)
ISC Stormcast For Sunday, December 28th, 2025 https://isc.sans.edu/podcastdetail/9750
** Dec 27, 2025 ** Ravie Lakshmanan Database Security / Vulnerability A high-severity security flaw has been disclosed in MongoDB that could allow unauthenticated users to read uninitialized heap …
** Dec 26, 2025 ** Ravie Lakshmanan Cryptocurrency / Incident Response Trust Wallet is urging users to update its Google Chrome extension to the latest version following what it described as a …
IoT Hack Someone hacked an Italian ferry . It looks like the malware was installed by someone on the ferry, and not remotely. Tags: France , hacking , Internet of Things , malware Posted on December …
Friday Squid Blogging: Squid Camouflage New research : Abstract: Coleoid cephalopods have the most elaborate camouflage system in the animal kingdom. This enables them to hide from or deceive both …
A China-linked advanced persistent threat (APT) group has been attributed to a highly-targeted cyber espionage campaign in which the adversary poisoned Domain Name System (DNS) requests to deliver its …
** Dec 26, 2025 ** Ravie Lakshmanan AI Security / DevSecOps A critical security flaw has been disclosed in LangChain Core that could be exploited by an attacker to steal sensitive secrets and even …
ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories
** Dec 25, 2025 ** Ravie Lakshmanan Cybersecurity / Hacking News It’s getting harder to tell where normal tech ends and malicious intent begins. Attackers are no longer just breaking in — …
** Dec 25, 2025 ** Ravie Lakshmanan Data Breach / Financial Crime The encrypted vault backups stolen from the 2022 LastPass data breach have enabled bad actors to take advantage of weak master …
** Dec 25, 2025 ** Ravie Lakshmanan Vulnerability / Enterprise Security Fortinet on Wednesday said it observed “recent abuse” of a five-year-old security flaw in FortiOS SSL VPN in the …
CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution
** Dec 25, 2025 ** Ravie Lakshmanan Vulnerability / Endpoint Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a security flaw impacting Digiever DS-2105 Pro network …
Urban VPN Proxy Surreptitiously Intercepts AI Chats This is pretty scary : Urban VPN Proxy targets conversations across ten AI platforms: ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity, …
** Dec 24, 2025 ** Ravie Lakshmanan Online Fraud / Artificial Intelligence The fraudulent investment scheme known as Nomani has witnessed an increase by 62%, according to data from ESET, as campaigns …
** Dec 24, 2025 ** Ravie Lakshmanan Malware / Endpoint Security Cybersecurity researchers have discovered a new variant of a macOS information stealer called MacSync that’s delivered by means of …
The U.S. Securities and Exchange Commission (SEC) has filed charges against multiple companies for their alleged involvement in an elaborate cryptocurrency scam that swindled more than $14 million …
** Dec 24, 2025 ** Ravie Lakshmanan Privacy / Antitrust Apple has been fined €98.6 million ($116 million) by Italy’s antitrust authority after finding that the company’s App Tracking …
** Dec 24, 2025 ** The Hacker News Password Management / Access Control Every year, cybercriminals find new ways to steal money and data from businesses. Breaching a business network, extracting …
Cybersecurity researchers have discovered two malicious Google Chrome extensions with the same name and published by the same developer that come with capabilities to intercept traffic and capture …
Denmark Accuses Russia of Conducting Two Cyberattacks News : The Danish Defence Intelligence Service (DDIS) announced on Thursday that Moscow was behind a cyber-attack on a Danish water utility in …
** Dec 23, 2025 ** Ravie Lakshmanan Financial Crime / Law Enforcement The U.S. Justice Department (DoJ) on Monday announced the seizure of a web domain and database that it said was used to further a …
Passwd is designed specifically for organizations operating within Google Workspace. Rather than competing as a general consumer password manager, its purpose is narrow, and business-focused: secure …
A law enforcement operation coordinated by INTERPOL has led to the recovery of $3 million and the arrest of 574 suspects by authorities from 19 countries, amidst a continued crackdown on cybercrime …