The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software.
The post DARPA Selects Xint to Use AI in Securing Military Messaging Apps appeared first on SecurityWeek.
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft.
The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors.
The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR).
"The key insight is that, while modern CPUs
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown.
"During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
Apple has released security updates for supported iPhones, iPads and Macs after reports that a file-processing flaw may have been used against selected iPhone users. Malwarebytes Labs says installing the latest update offered through Software Upda…
The malware framework uses a modular architecture and a custom executable file format for long-term persistence.
The post Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft appeared first on SecurityWeek.
Hackers stole patient data from Qbusoft, a Polish medical software maker, weeks after a breach at another provider exposed records of nearly 19 million people in the country. The data comes from Medyc, a platform the company sells to medical offices and clinics to manage patient registration, records and prescriptions. In August, attackers stole data on nearly 19 million people from MyDr, a Warsaw-based company whose software is used by about 12,000 healthcare facilities. The … More →
The post Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider appeared first on Help Net Security.
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]
Cloudflare released EmDash 1.0, a free, open source content management system that locks each sandboxed plugin in its own isolated runtime. A plugin starts with access to its own private storage. It cannot reach the site’s content, media, users, secrets, environment, filesystem, or network until it declares what it needs and a site administrator approves the request. The people this protects are site owners who run code they did not write. Cloudflare pitches EmDash as … More →
The post Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first appeared first on Help Net Security.
GitHub Security Lab researcher Kevin Stubbings built custom AI-driven audit workflows, called taskflows, on top of the lab’s open source Taskflow Agent, and used them to find and report more than 20 vulnerabilities in Android apps. Two of the disclosed bugs show what’s at stake. In OsmAnd, a navigation app with over 10 million downloads on the Play Store, an exported activity called MapActivity accepted intent extras that should have stayed restricted to an internal … More →
The post GitHub’s AI agent found 24 Android app vulnerabilities appeared first on Help Net Security.
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions.
"An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions:
Application Security Researcher Novee Security | Israel | Hybrid – View job details As an Application Security Researcher, you will test web applications and APIs to verify vulnerabilities found by Novee’s AI platform and document how they can be exploited. You will help customers reproduce and fix findings, investigate missed or inaccurate results, and work with research and engineering teams to improve detection. You will also develop new testing methods and support complex customer deployments. … More →
The post Cybersecurity jobs available right now: September 29, 2026 appeared first on Help Net Security.
The vendor’s products are a common, recurring target for attackers, yet the official warning for some Citrix NetScaler customers was too late.
The post Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings appeared first on CyberScoop.
The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.