Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.
The post Exclusive: How One Line of Code Put Billions of Microsoft Android App … Continue reading Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks

Researchers warn GreyVibe’s extensive use of ChatGPT, Gemini, and other AI tools offers a glimpse into how future cybercriminal and state-aligned groups will operate.
The post Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks appear… Continue reading Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks

New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails

France-based startup Edamame says its runtime verification platform uses host telemetry and AI analysis to detect coding-agent “intent drift,” secret theft and supply-chain attacks in real time.
The post New Edamame Platform Aims to Catch AI Coding Age… Continue reading New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails

The Credential Crisis: How Stolen Credentials Defeat Modern Security

As AI accelerates phishing, session hijacking, and credential abuse, security teams are racing to close the gap between attacker speed and defensive response.
The post The Credential Crisis: How Stolen Credentials Defeat Modern Security appeared first … Continue reading The Credential Crisis: How Stolen Credentials Defeat Modern Security

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems

Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipelines, and deploying malicious code.
The post ‘SymJack’ Attack Turns AI C… Continue reading ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems

AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security

Marlin AI automatically analyzes SaaS misconfigurations, investigates related activity across enterprise environments, and recommends remediation steps — while stopping short of fully autonomous corrective action.
The post AppOmni’s Marlin AI Brings Au… Continue reading AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security

Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images

DockSec, an OWASP incubator project, correlates findings from multiple container security scanners and uses AI to generate plain-English remediation guidance and exact Dockerfile fixes.
The post Open Source DockSec Uses AI to Cut Through Vulnerability … Continue reading Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images

Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility

New vulnerabilities are being discovered too fast, the time-to-exploitation is too short, and our visibility into them is largely lacking.
The post Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility appeared first on Security… Continue reading Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility

AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop

Digital.ai’s latest threat report warns that agentic AI has erased the distinction between emerging and primary targets, enabling attackers to strike mobile apps within hours of release across every industry.
The post AI-Powered App Attacks Are Faster,… Continue reading AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop

AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop

Digital.ai’s latest threat report warns that agentic AI has erased the distinction between emerging and primary targets, enabling attackers to strike mobile apps within hours of release across every industry.
The post AI-Powered App Attacks Are Faster,… Continue reading AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop