A security researcher claims Kimi K3 discovered a Redis zero-day and produced a proof-of-concept exploit in 27 minutes. Redis has not confirmed the findings.
Discover how the Rogue Agent vulnerability in Google Dialogflow CX enabled persistent AI agent compromise, data exfiltration, ...
Researchers escaped the sandboxes of Cursor, Codex, Gemini CLI and Antigravity without breaking them. Three vendors patched; Google downgraded its two.
A security researcher released a public static config scanner Monday for a critical heap buffer overflow in NGINX that has existed since 2011, and the full proof-of-concept exploit that can deliver ...
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two ...
JadePuffer, a ransomware operation, used an AI agent to carry out much of the intrusion chain from reconnaissance, key theft, ...
A PNG hiding a prompt injection could steal your repo's secrets, researchers demonstrate. The technique, dubbed 'Ghostcommit, ...
Ethereum gossipsub vulnerability CVE-2026-34219 lets any unauthenticated peer crash a validator with a single crafted PRUNE ...
Hackers used a backdoor through a little-known third-party app to steal LastPass customer data.