❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 24 July 2026Hacking and InfoSec

The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk

24 July 2026 at 16:00

The recent developments surrounding vulnerabilities in major AI repositories like Hugging Face serve as a critical wake-up call for the cybersecurity community. As we accelerate toward an agentic future, the platforms we rely on for innovation are increasingly becoming the primary vectors for systemic risk.

Before yesterdayHacking and InfoSec

Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation

23 July 2026 at 17:00

Security operations teams face a constant balancing act: stopping sophisticated email threats, maintaining visibility across their attack surface and keeping administrative workflows running smoothly. When security tools operate in silos or rely on rigid, manual processes, friction builds up quickly. This friction consumes valuable time that analysts could spend on higher-priority initiatives.

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

23 July 2026 at 12:00

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called β€œJalisco,” is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.

New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims

23 July 2026 at 06:32

A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the theft and triage of high-value corporate targets. Unlike commodity stealers that focus mainly on browser passwords, Dolphin X is positioned as an enterprise-adjacent data vacuum with a built-in AI-powered victim scoring […]

The post New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation

By: Divya
23 July 2026 at 03:37

Google has unveiled CodeMender, a managed AI security agent designed to identify, validate, and remediate software vulnerabilities at machine speed. Announced in preview on July 22, 2023, the tool is available through the Gemini Enterprise Agent Platform and can also function as a core component of Google’s AI Threat Defense offering. This launch comes as […]

The post Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit

By: Divya
23 July 2026 at 01:12

Anthropic has launched the Claude Security plugin for Claude Code in beta, enhancing its AI-assisted development platform with security scanning capabilities designed to identify vulnerabilities earlier in the software development lifecycle. The company stated that developers can scan code changes before committing them or initiate comprehensive security reviews across an entire codebase directly from the […]

The post Anthropic Launches Claude Security Plugin to Scan Codebases for Vulnerabilities Before Commit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Attackers Exploit AI Hallucinations to Send Users to Phishing Sites

22 July 2026 at 16:00

Threat actors are using a new technique called β€œphantom squatting” to trick AI tools into directing users to phishing sites, according to researchers at Palo Alto Networks’ Unit 42.

Since AI models frequently hallucinate phony information, they sometimes point users to websites that don’t exist. Threat actors are now registering these AI-hallucinated domains and using them to host phishing sites.

Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows

By: Divya
22 July 2026 at 02:19

Yubico has released the YubiKey firmware version 5.8, expanding its hardware security key platform beyond phishing-resistant authentication. This update introduces verifiable, hardware-backed authorization for digital signatures, identity wallets, payment confirmations, and AI agent approval workflows. Announced on July 21, 2026, this firmware update aims to help enterprises verify not only who accesses an application but […]

The post Yubico Launches YubiKey 5.8 With Hardware-Backed Authorization for AI Agent Workflows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers

By: Divya
22 July 2026 at 00:46

OpenAI has revealed that during an internal evaluation of advanced cyber capabilities, AI agents exploited a zero-day vulnerability, escaped a constrained research environment, and compromised parts of Hugging Face’s production infrastructure. While Hugging Face detected and contained the activity, OpenAI’s internal security team also identified unusual behavior during the assessment. OpenAI Compromise Hugging Face Servers […]

The post OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Trust Nothing: Tips to Secure AI Tools and Agents

21 July 2026 at 16:00

So, you have some AI tools or are thinking about deploying them and want to know a bit about securing them.

You are not alone, but there are significant challenges due to the rapidly growing capabilities of AI, and the issues around new types of vulnerabilities we may not be used to thinking of. This is a very challenging area to attempt to secure, but I hope to point you in the right direction and set you up with some resources.

JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data

21 July 2026 at 06:57

JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high‑value AI and ML artifacts across an entire stack. A missing‑authentication bug in the /api/v1/validate/code endpoint that enables unauthenticated arbitrary Python execution on the host. That initial operation chained reconnaissance, credential […]

The post JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials

21 July 2026 at 04:40

Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft that significantly complicate detection and response. APT42, also tracked as TA453 in some reporting, is […]

The post Iran-Linked APT42 Uses AI-Assisted Phishing and TAMECAT Backdoor to Target Defense Officials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware

21 July 2026 at 03:34

AgentBaiting is the clearest sign yet that AI agents and their capability ecosystems have become a first‑class malware delivery surface, with FakeGit’s 7,600‑repo operation pushing SmartLoader and StealC directly into AI Skills and MCP workflows. By turning agent‑readable READMEs, public AI registries, and GitHub trust signals into a weaponized β€œAI capability supply chain,” attackers now […]

The post AgentBaiting Uses Fake AI Skills and MCP Servers to Deliver SmartLoader and StealC Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids

21 July 2026 at 01:48

Bit2Watt is a newly disclosed cyber‑physical attack class that weaponizes AI and GPU workloads in modern data centers to destabilize nearby power grids, turning compute infrastructure itself into a grid‑scale threat surface. Measurements on NVIDIA accelerators show sub‑millisecond power ramps where a single Volta V100 or RTX‑series GPU swings from low-load phases to near‑TDP draw, […]

The post Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hugging Face Says Autonomous AI Agent System Breached Production Infrastructure

By: Waqas
20 July 2026 at 17:06
An AI-led cyberattack breached limited Hugging Face datasets and service credentials, while public models, Spaces and published packages showed no signs of tampering.

The AI Pentesting Platform Checklist for Regulated Enterprises

20 July 2026 at 15:00

Regulated enterprises evaluating AI pentesting platforms should assess eight capabilities: FedRAMP Moderate authorization or higher, multi-framework compliance support, human-in-the-loop with agentic AI, verified zero-false-positive findings, bidirectional workflow integrations, self-service launch, auditable coverage visibility, and full offensive security platform capabilities. Vendors who can't clearly distinguish their AI from an automated scanner are likely selling exactly that.

The post The AI Pentesting Platform Checklist for Regulated Enterprises appeared first on Synack.

❌
❌