Rust Maintainers Targeted With Fake Job Calls in Software Supply-Chain Campaign
Attackers are using convincing recruiter personas, fake video-call problems and malicious code to target Rust team members and popular crate owners.
Cybersecurity, AI, etc.
Attackers are using convincing recruiter personas, fake video-call problems and malicious code to target Rust team members and popular crate owners.
Researchers chained code execution in OpenAI’s community forum with an over-privileged OpenAI sign-in token, reaching an employee account connected to internal repositories before the flaws were fixed.
A Gemini model unintentionally accessed systems belonging to three real companies after an AI security evaluation was given internet access and confused real organizations with a fictional test target.
Researchers disclosed two patched OpenAI Codex sandbox escapes, including a flaw that could let a malicious repository trigger commands on a developer’s host from the strictest sandbox mode.
OpenAI introduced a framework and six reports covering observed unexpected or concerning model behavior.
Mandiant describes a compromised AI coding session that led to a supply-chain worm spreading across repositories.
A hard-coded JWT key in Issabel Framework can enable unauthenticated remote command execution.
Cisco urges immediate updates for an actively exploited ISE and ISE-PIC authentication-bypass vulnerability.
UK, U.S., and Dutch agencies detailed Iranian spyware targeting dissidents, activists, and journalists.
CenterPoint Energy confirmed an unauthorized party obtained some customer personal information through an external-facing system.