Hidden risk in Notion 3.0 AI agents: Web search tool abuse for data exfiltration
(news.ycombinator.com)
211.
212.
CISA exposes malware kits deployed in Ivanti EPMM attacks
(bleepingcomputer.com)
213.
Tinycolor supply chain attack post-mortem
(news.ycombinator.com)
214.
Microsoft adds malicious link warnings to Teams private chats
(bleepingcomputer.com)
215.
Cursor AI editor lets repos “autorun” malicious code on devices
(bleepingcomputer.com)
216.
Hackers left empty-handed after massive NPM supply-chain attack
(bleepingcomputer.com)
217.
Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack
(bleepingcomputer.com)
218.
6 browser-based attacks all security teams should be ready for in 2025
(bleepingcomputer.com)
219.
Threat actors abuse X’s Grok AI to spread malicious links
(bleepingcomputer.com)
221.
Malicious versions of Nx and some supporting plugins were published
(news.ycombinator.com)
222.
How RubyGems.org protects OSS infrastructure
(news.ycombinator.com)
223.
Malicious Android apps with 19M installs removed from Google Play
(bleepingcomputer.com)
224.
Ghrc.io appears to be malicious
(news.ycombinator.com)
225.
AI website builder Lovable increasingly abused for malicious activity
(bleepingcomputer.com)
226.
LLMs and coding agents are a security nightmare
(news.ycombinator.com)
227.
LLMs and Coding Agents = Security Nightmare
(news.ycombinator.com)
228.
Microsoft Teams to protect against malicious URLs, dangerous file types
(bleepingcomputer.com)
229.
DoubleAgents: Fine-Tuning LLMs for Covert Malicious Tool Calls
(news.ycombinator.com)
230.
60 malicious Ruby gems downloaded 275,000 times steal credentials
(bleepingcomputer.com)
231.
Fake WhatsApp developer libraries hide destructive data-wiping code
(bleepingcomputer.com)
232.
Wave of 150 crypto-draining extensions hits Firefox add-on store
(bleepingcomputer.com)
234.
CTM360 spots Malicious ‘FraudOnTok’ Campaign Targeting TikTok Shop users
(bleepingcomputer.com)
235.
CTM360 spots Malicious ‘ClickTok’ Campaign Targeting TikTok Shop users
(bleepingcomputer.com)
236.
Attackers exploit link-wrapping services to steal Microsoft 365 logins
(bleepingcomputer.com)
237.
Spikes in malicious activity precede new security flaws in 80% of cases
(bleepingcomputer.com)
238.
Spikes in malicious activity precede new CVEs in 80% of cases
(bleepingcomputer.com)
239.
Inside a Real Clickfix Attack: How This Social Engineering Hack Unfolds
(bleepingcomputer.com)
240.
Flaw in Gemini CLI AI coding assistant allowed stealthy code execution
(bleepingcomputer.com)