❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 23 July 2026Hacking and InfoSec

Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit

By: Divya
23 July 2026 at 01:12

Anthropic has launched the Claude Security plugin for Claude Code in beta, enhancing its AI-assisted development platform with security scanning capabilities designed to identify vulnerabilities earlier in the software development lifecycle. The company stated that developers can scan code changes before committing them or initiate comprehensive security reviews across an entire codebase directly from the […]

The post Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Yesterday β€” 22 July 2026Hacking and InfoSec

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

22 July 2026 at 16:00

Threat actors are using a new technique called β€œphantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42.

Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.

Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows

By: Divya
22 July 2026 at 02:19

Yubico has released the YubiKey firmware version 5.8, expanding its hardware security key platform beyond phishing-resistant authentication. This update introduces verifiable, hardware-backed authorization for digital signatures, identity wallets, payment confirmations, and AI agent approval workflows. Announced on July 21, 2026, this firmware update aims to help enterprises verify not only who accesses an application but […]

The post Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers

By: Divya
22 July 2026 at 00:46

OpenAI has revealed that during an internal evaluation of advanced cyber capabilities, AI agents exploited a zero-day vulnerability, escaped a constrained research environment, and compromised parts of Hugging Face’s production infrastructure. While Hugging Face detected and contained the activity, OpenAI’s internal security team also identified unusual behavior during the assessment. OpenAI Compromise Hugging Face Servers […]

The post OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Before yesterdayHacking and InfoSec

Trust Nothing: Tips to Secure AI Tools and Agents

21 July 2026 at 16:00

So, you have some AI tools or are thinking about deploying them and want to know a bit about securing them.

You are not alone, but there are significant challenges due to the rapidly growing capabilities of AI, and the issues around new types of vulnerabilities we may not be used to thinking of. This is a very challenging area to attempt to secure, but I hope to point you in the right direction and set you up with some resources.

JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data

21 July 2026 at 06:57

JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high‑value AI and ML artifacts across an entire stack. A missing‑authentication bug in the /api/v1/validate/code endpoint that enables unauthenticated arbitrary Python execution on the host. That initial operation chained reconnaissance, credential […]

The post JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials

21 July 2026 at 04:40

Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft that significantly complicate detection and response. APT42, also tracked as TA453 in some reporting, is […]

The post Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware

21 July 2026 at 03:34

AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first‑class malware delivery surface, with FakeGit’s 7,600‑repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By turning agent‑readable READMEs, public AI registries, and GitHub trust signals into a weaponized β€œAI capability supply chain,” attackers now […]

The post AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids

21 July 2026 at 01:48

Bit2Watt is a newly disclosed cyber‑physical attack class that weaponizes AI and GPU workloads in modern data centers to destabilize nearby power grids, turning compute infrastructure itself into a grid‑scale threat surface. Measurements on NVIDIA accelerators show sub‑millisecond power ramps where a single Volta V100 or RTX‑series GPU swings from low-load phases to near‑TDP draw, […]

The post Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hugging Face Says Autonomous AI Agent System Breached Production Infrastructure

By: Waqas
20 July 2026 at 17:06
An AI-led cyberattack breached limited Hugging Face datasets and service credentials, while public models, Spaces and published packages showed no signs of tampering.

The AI Pentesting Platform Checklist for Regulated Enterprises

20 July 2026 at 15:00

Regulated enterprises evaluating AI pentesting platforms should assess eight capabilities: FedRAMP Moderate authorization or higher, multi-framework compliance support, human-in-the-loop with agentic AI, verified zero-false-positive findings, bidirectional workflow integrations, self-service launch, auditable coverage visibility, and full offensive security platform capabilities. Vendors who can't clearly distinguish their AI from an automated scanner are likely selling exactly that.

The post The AI Pentesting Platform Checklist for Regulated Enterprises appeared first on Synack.

New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure

17 July 2026 at 06:55

NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed‑loop platform. In early July 2026, researchers identified NadMesh as a high‑volume Go-written botnet that was aggressively deploying bot agents across internet‑facing […]

The post New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

The Hidden Costs of Building an AI Pentesting Solution

16 July 2026 at 12:11

Most security teams underestimate what it costs to build an AI pentesting solution in house. People, AI token costs, infrastructure, and compliance gaps add up faster than the initial business case accounts for, and the hidden bill usually arrives in year two. I’ve been hearing the same question from security leaders lately. They’re all asking […]

The post The Hidden Costs of Building an AI Pentesting Solution appeared first on Synack.

New Framework Redefines AI Penetration Testing Around Prompt Injection and Behavioral Objective Violations

16 July 2026 at 08:38

A newly proposed framework argues that AI penetration testing must move beyond conventional infrastructure compromise and assess whether an adversary can make an AI-enabled system act against its intended operational purpose. Traditional penetration testing typically measures compromise through outcomes such as unauthorized access, privilege escalation, data theft, service disruption, or persistence. Those outcomes remain critical […]

The post New Framework Redefines AI Penetration Testing Around Prompt Injection and Behavioral Objective Violations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌