The Hacker News #1 Trusted Source for Cybersecurity News
What used to be scrappy proof-of-concept attacks are now slick, automated operations running at scale. In 2024, most synthetic media and generative AI attacks were still unpolished, easy to spot, and deployed in isolated experiments. As the 2026 election cycle hits full stride with midterms approaching, the threats that voters, campaigns, and candidates are coming face-to-face with have completely changed from even two years ago.
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product’s web application root directory. Apple has announced that it’s taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. Citing growing risks posed by https://openscience.us/repo/other/flowpermissions.html more capable and autonomous AI agents, Apple will introduce additional controls.
For operators of critical infrastructure, however, collecting this information is not even the most challenging part. By September 10, the majority of them will be able to file inside 24 hours, and they will be right to feel relieved about it, because filing on time is exactly what the regulation asks, and it is not a trivial thing to arrange. From coding assistant to agent runtime The first generation of coding assistants mainly… They are participating in the agent’s decision loop. One emerging approach is to generate that evidence directly from source code us…
Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks
The problem security teams need to solve is not only that AI-generated code might be vulnerable. What it may not know is that the field is consumed by four other services across separate repositories, that one of those services belongs to another team, or that the same field eventually carries sensitive data into a third party integration. The agent can inspect the code available on the developer’s machine and search for references. A developer can ask an AI coding agent to deprecate an API field, update an authentication flow, or modify a service interface. Mean time to detect (MTTD) tells you how quickly the team recognizes a real threat, while mean time to respond (MTTR) tells you how quickly the team investigates and contains it. For years, security teams have tried to reduce this window by adding more detection tools.
However, the vulnerability does not allow cross-tenant access. “Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network,” Microsoft said in an advisory released on October 2, 2026. What’s notable about this browser cache smuggling approach is that it allows the attackers to conceal the payload script and bypass character limit restrictions imposed on Windows Run (aka the Run dialog). “Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file,” the Microsoft Threat Intelligence team said in a post on X.
FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
- Google called the stop temporary in a post on X on October 1 and said it was due to “a significant rise in automated submissions, the vast majority of which are not valid.” The post gave no figures.
- This week’s threats keep finding leverage in small things that were easy to overlook.
- “His cooperation is critical to ongoing efforts to arrest these hackers,” a source told the news agency.
- For campaign security teams, that means the job has expanded well beyond protec…
- “Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file,” the Microsoft Threat Intelligence team said in a post on X.
- The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what they can access.
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. An analysis of the malware sample has found it to embed exploit logic for various command injectio… “Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel,” Nozomi Networks said in a report published last week. Users of affected on-premises Microsoft Exchange Server products are a… As a result, Exchange Online customers are not required to take any action.
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. Amir Barati, an alleged member of the Mabna https://www.internetling.com/the-funniest-fails-in-history-of-internet.html Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).
A Marketplace With No Bouncer In 2012, Google ran Bouncer, an automated scanner that checked Android apps for malware before they reached users. Earlier this year, our team at OX Security , traced critical vulnerabilities in Anthropic’s MCP source code, downloaded more than 150 million times. Thousands of developers built servers, and enterprises plugged them into agent workflows.
Security teams can decide afterward whether those actions were acceptable, but fully enumerating them in advance is not only antithetical to using an agent but https://esportsgrind.com/savings-tips/crypto-security-for-gamers-protect-your-wallet-like-your-main-account/ also practically impossible. You cannot reliably predict what an AI agent is going to do. For campaign security teams, that means the job has expanded well beyond protec…

Leave a Reply
Want to join the discussion?Feel free to contribute!