Phishing attacks leverage TikTok, Instagram Reels
RL has discovered two social engineering attack techniques targeting users via short-form videos. Here’s how they work.

4276 articles
4276 ARTICLES
RL has discovered two social engineering attack techniques targeting users via short-form videos. Here’s how they work.


TL;DR: Frontier AI models are discovering zero day vulnerabilities and weaponizing them in hours. Boards, regulators and underwriters have noticed, and they are asking a question most CISOs cannot answer: “What does our exposure cost in dollars?” Reporting in CVE counts and CVSS scores made sense when the threat timeline gave security teams room to

In our post about Project Glasswing, we made the argument that the architecture around a vulnerability matters more than the speed of the patch. Here we walk through what that architecture looks like, the threats it defends against, and how we run it ourselves as Cloudflare’s customer zero.

Agentic AI changes the red teaming conversation. Traditional generative AI testing often focuses on whether a model will produce harmful text. Agentic AI raises the question of what happens when an AI system can plan, reason, and interact with tools, workflows, and downstream systems. That is where agentic AI red teaming becomes essential. In CSA’s recent research publication, Evaluating PyRIT for Agentic AI Red Teaming, Microsoft’s Python Risk Identification Toolkit is evaluated as a wa…

For years, application security programs have focused on a single goal: finding vulnerabilities earlier in the software lifecycle. We’ve invested heavily in shift-left security, app security testing, CI/CD scanning, and dev-focused remediation workflows. But according to CSA and Miggo Security’s new survey report, security teams are still losing the production battle. The problem is no longer visibility alone. Security teams are overwhelmed with threat intelligence findings, alerts, a…

EXECUTIVE SUMMARY Enterprise artificial intelligence has transitioned from isolated, static Large Language Model (LLM) prompts to dynamic, multi-agent systems (MAS) operating at high levels of operational autonomy. While these systems dramatically accelerate software development, supply chain orchestration, and threat response, they introduce unprecedented security blind spots that render legacy identity, data protection, and boundary defense mechanisms obsolete. This bl…

In cybersecurity, the most damaging attacks are not always the most sophisticated. Sometimes, they begin with something as mundane as a forgotten DNS record. That reality came into sharp focus when researchers uncovered a large-scale campaign involving hijacked university subdomains across institutions including UC Berkeley, Columbia University, and Washington University in St. Louis. Attackers exploited abandoned CNAME records to take control of trusted .edu subdomains and use them to h…

Gremlin is an autonomous engineering agent for small, well-scoped tasks. It uses Mastra for orchestration and OpenCode in a sandbox to turn Sentry issues, Linear tasks, and Slack instructions into reviewable pull requests.

Chainguard’s new scanner blocks malware and ‘greyware’ before it reaches developers, protecting 100,000+ packages daily across open source ecosystems.

Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered AI security, network protection, identity management, compliance frameworks, and supply chain security. Read

As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog.

For the latest discoveries in cyber research for the week of 8th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES DentaQuest, a U.S. dental benefits administrator owned by Sun Life, has suffered a data breach after threat group ShinyHunters leaked exfiltrated data. Analysts assessed that 2.6 million accounts were exposed, including names, emails, […] The post 8th June – Threat Intelligence Report appeared first on Check Point Research.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy