A trojanized NuGet typosquat targets Digitain's FG-Crash backend, rigs live game results, and later versions exfiltrate them ...
TripGain MCP Server launches at GBTA Convention 2026, extending agentic AI beyond flight booking to handle employee expense ...
AWS fixed a Kiro prompt injection chain that rewrote mcp.json and launched attacker-controlled code with developer privileges, bypassing approval.
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals ...
AWS Kiro prompt injection flaw let hidden web page text rewrite the IDE's MCP configuration file and silently execute ...
Dependency confusion is a supply chain issue that affects how package managers choose where to download a dependency from. If your build or developer tooling can see both a private package registry ...
An active worm in the npm JavaScript repository is spreading across more than 2,000 versions of 444 unique packages after a ...
In what they call the first-ever real-world agent-to-agent exploitation method, Pillar Security researchers say they ...
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but ...
Fastjson Zero-Day Exposes Java Servers To Remote Attacks Arabian Post. clearfix>Attackers are exploiting a critical vulnerability in Alibaba's Fastjson library that can allow unauthenticated remote ...
Wiz researchers say some AI coding assistants displayed misleading approval prompts, allowing symbolic links to redirect approved edits to sensitive system files.
AI agent protocols IETF standard review begins at IETF 126 Vienna this week, where the agentproto Birds-of-a-Feather session Thursday could charter a working group to produce the first formal RFC for ...