Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload d… Continue reading Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

Posted in Uncategorized

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as … Continue reading Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Posted in Uncategorized

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.

Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, expos… Continue reading ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

Posted in Uncategorized

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

The U.S. government on Wednesday warned of an “active threat” targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts.

The activity is targeting Siemens S7 SeriesProgrammable Logic Co… Continue reading AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

Posted in Uncategorized

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI has disclosed an attack technique that it says can cause xAI’s Grok chatbot to send a user’s name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it… Continue reading New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Posted in Uncategorized

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.

According to the cloud computing and virtualization technology comp… Continue reading Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Posted in Uncategorized