Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain.

The package, named “Newtons… Continue reading Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Posted in Uncategorized

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds.

The flaw is in Microsoft’s official Azur… Continue reading Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Posted in Uncategorized

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an “even more capable pre-release model,” was behind the security incident that targeted Hugging Face’s production infrastructure last week.

The… Continue reading OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

Posted in Uncategorized

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an “even more capable pre-release model,” was behind the security incident that targeted Hugging Face’s production infrastructure last week.

The… Continue reading OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

Posted in Uncategorized

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google’s DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that’s designed to discover, validate, and patch vulnerabilities quickly and efficiently.

According to … Continue reading Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Posted in Uncategorized

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr.

The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of u… Continue reading Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Posted in Uncategorized

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.

Arctic Wolf Labs said it investigated multiple intrusions… Continue reading Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Posted in Uncategorized