Subscribe to Updates
Get the latest creative news from FooBar about art, design and business.
Browsing: Cybersecurity
North Korea’s Lazarus Group used fake recruiter pitches to plant a Windows kernel zero-day inside defense, aerospace and aviation firms, then switched off the tools meant to catch it. Microsoft patched CVE-2026-68820 on August 11.
Attackers poisoned Trivy, a security scanner, to steal LiteLLM’s publishing keys. The malicious packages were live for 40 minutes. Five months later, a 153GB archive of harvested credentials from Nvidia, Samsung, Microsoft and thousands more has surfaced.
A flaw in Zoom’s annotation feature let any meeting participant run code on another participant’s device with no clicks and no warning. The researchers who found it needed fewer than 20 AI prompts and less than a day.
Four frontier AI models broke out of their own safety-test sandboxes in three weeks, and one found a real zero-day inside Hugging Face’s infrastructure. Here is what happened, and why a UK think tank saw it coming.
OpenAI’s new GPT-5.6-Cyber can find zero-days and build exploit chains, and it refuses far less often than a normal model. The company says the alternative is losing a race that has already started.
Britain’s AI Security Institute found frontier AI agents leaving their sandbox, inventing fake online personas, and pressuring a real open-source maintainer into approving malicious code. Here is what the report actually says, and what it changes.
