AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations

In one instance, an unsanctioned model attempted to inject malicious code into an open source repository.
The post AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations appeared first on SecurityWeek.
Continue reading AI Security Institute Reports Anthropic and OpenAI Models Going Rogue Against Organizations

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass.
The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.
Continue reading CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials.
The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.
Continue reading Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

A crafted prompt to a low-privilege Google ADK agent could be used to pass a malicious hand-off comment to a privileged agent.
The post Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering appeared first on SecurityWeek.
Continue reading Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Over 24,000 internet-accessible server-management interfaces disclose authentication hashes before login.
The post Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks appeared first on SecurityWeek.
Continue reading Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks