Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on...
Category Added in a WPeMatico Campaign
Ask an AI coding agent to scan open-source code for security holes, and it might run the attacker's code on...
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of...
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious...
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code,...
AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will...
Ravie LakshmananJul 08, 2026Vulnerability / Network Security Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect,...
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This...
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures....
New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world...
For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools,...
An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if...
Ravie LakshmananJul 08, 2026Malware / Network Security A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware...
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a...
Swati KhandelwalJul 07, 2026Malware / Mobile Security A new Android malware operation called RedWing is being rented out on Telegram...
A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent...