OpenAI has paused internal work on its unreleased Astra AI model after tests showed agentic coding and cyber capabilities near its highest risk tier, prompting new safeguards.
New research shows CSS-only payloads in HTML email can break webmail isolation in Outlook, Gmail and others to steal passwords, tokens and hijack UI flows.
A new npm supply-chain campaign planted nearly 800 AI-generated packages that install a cross-platform RAT and infostealer on Windows, macOS and Linux systems.
Researcher Malcolm Stagg unveils NatJack, a NAT flaw that lets adjacent attackers hijack TCP sessions, spoof DNS and exhaust NAT tables on major platforms.
ICE is accessing credit card application data through commercial data brokers and Thomson Reuters CLEAR, bypassing warrants and raising privacy alarms.
Commercial sites are hiding prompt injection payloads in Ask AI buttons, quietly poisoning LLM memory to skew recommendations and challenge security teams.