Anthropic’s Claude Mythos model promises unprecedented automated vulnerability discovery, but leaks, restricted access and mixed evidence leave security teams weighing real-world risk.
A newly disclosed Microsoft Copilot for Word weakness lets hidden prompts in documents alter business content and persist into new files, with no CVE yet issued.
Dutch investigators seized 800 servers tied to Russian bulletproof host THE.Hosting, but key IP ranges remain online and continue to probe EU networks.
A new vendor report on 2,000 exposed AI-built apps shows how 'shadow AI' is outpacing security controls as employees ship vibe-coded tools into production.
India's CERT-In has issued new guidance urging organizations to patch critical internet-facing vulnerabilities within 12 hours amid rising AI-driven attacks.
Iran-linked group Screening Serpens is using new MiniJunk V2 and related RATs in tailored spear-phishing against aerospace, defense and telecom targets.