attacks
32 stories and discussions about attacks, aggregated from every source we track.
Such strikes aim to disrupt "people's ability to stay connected, study, work", says Ukraine's president.
SHA-256 is the most widely used hash function today. It has resisted all known practical cryptanalytic attacks, benefits from hardware acceleration, is ...
We built a multi-tenant team task board with no backend. The browser loads static files, signs in...
Lithuania says Russia could try to broaden its pressure on Nato countries through attacks on critical infrastructure including ports or airports
🛡️ Regex catches 0%, Meta's Prompt Guard 2 catches 1% of 629 realistic AgentDojo injection attacks when they're buried in tool output. Reproducible benchmark. - rudratoshs/buried-injections
TEMPEST attacks are often the most effective way to break air-gapped security: rather than directly accessing a computer, the attacker records the system’s unintended radio emissions and uses them …
CISA gives federal agencies just 3 days to patch
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the…
I built a checker for AI-drafted answers to retirement questions (retirement-answer-check). Before a...
Mistakes at Israeli startup Irregular sent Anthropic, OpenAI, Meta, and Google agents after real-world targets.
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks.
A sophisticated attacker with a quantum computer can exploit a protocol design flaw to downgrade post-quantum IPsec tunnels to classical crypto. We helped the IETF develop a transcript authentication extension to…
Two questions remain: who is abusing the CVEs? And why did Citrix take so long to disclose?
A sophisticated attacker with a quantum computer can exploit a protocol design flaw to downgrade post-quantum IPsec tunnels to classical crypto. We helped the IETF develop a transcript authentication extension to…
I reran my Denial of Spend test on GPT-6 Astra, Sol and Luna and Claude Fable 5.1, Opus 5.5, Sonnet 5 and Haiku 4.5. None were fooled by lookalike letters, and all of them still paid to read them: up to 5.7x the tokens…
Side-Channel Leakage from the File-Notification System on Linux, Android, Windows, and macOS. Accepted at The ACM Conference on Computer and Communications Security (CCS), November 15-19, 2026 — The Hague, Netherlands…
Side-Channel Leakage from the File-Notification System on Linux, Android, Windows, and macOS. Accepted at The ACM Conference on Computer and Communications Security (CCS), November 15-19, 2026 — The Hague, Netherlands…
The images were sent to CBS News by active service members under condition of anonymity.
Sudheendra Raghav Neela, a member of a group of researchers from Graz University of Technology, [...]
The Trump administration has made an extraordinary public intervention into Australia's debate about its proposed digital duty of care.
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt…
In July, OpenAI revealed that its AI agents had attacked Hugging Face without permission , sparking widespread concerns about AI safety. Since then, a string of similar incidents involving agents from Meta, Anthropic, Google, and other companies has fueled further fears about rogue AI . As disclosures implicating numerous AI models trickled out over the past few months, these seemed like separate incidents. But many share a common source: one specific company tasked with testing the agents. Irregular , an Israeli startup that stress-tests AI models in "high-fidelity research platforms that simulate and monitor real-world AI security scenarios … Read the full story at The Verge.