Uncategorized

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents 2026-07-22 at 09:44 By A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The […]

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents Read More »

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark 2026-07-22 at 09:44 By OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an “even more capable pre-release model,” was behind the security incident that targeted Hugging Face’s production infrastructure last week. The AI company

OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Read More »

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library 2026-07-22 at 09:00 By Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Json library and is a trojanized

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library Read More »

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs 2026-07-22 at 01:07 By Apple has moved to address a security flaw in its Hide My Email service that enabled users’ real email addresses to be unmasked, effectively undermining the feature’s privacy guarantees. 404 Media reported Tuesday that a fix for the

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Read More »

ChatGPT encouraged Alabama mom’s suicide, lawsuit alleges: ‘You are not delusional. You are prophetic’

ChatGPT encouraged Alabama mom’s suicide, lawsuit alleges: ‘You are not delusional. You are prophetic’ 2026-07-21 at 23:02 By Ariel Zilber Christian Faith Madison, 29, died last year after she was hit by an oncoming vehicle on an Alabama highway. This article is an excerpt from Latest Technology News | New York Post View Original Source

ChatGPT encouraged Alabama mom’s suicide, lawsuit alleges: ‘You are not delusional. You are prophetic’ Read More »

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities 2026-07-21 at 20:30 By Google’s DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that’s designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant,

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities Read More »

Chinese AI firms that rip off US models could face sanctions, Treasury Secretary Scott Bessent warns

Chinese AI firms that rip off US models could face sanctions, Treasury Secretary Scott Bessent warns 2026-07-21 at 20:16 By Thomas Barrabi As The Post has reported, AI giants like Anthropic, OpenAI and Google have each raised alarms about China-based labs using unauthorized distillation – a technique where a more advanced model is used to

Chinese AI firms that rip off US models could face sanctions, Treasury Secretary Scott Bessent warns Read More »

China-based Moonshot AI seeks $50B valuation — and could go public this year: report

China-based Moonshot AI seeks $50B valuation — and could go public this year: report 2026-07-21 at 19:44 By Thomas Barrabi The company – founded in 2023 by Carnegie Mellon-trained AI researcher Yang Zhilin – drew global attention with the launch of Kimi K3. The large-language model was trained on 2.8 trillion parameters, making it the

China-based Moonshot AI seeks $50B valuation — and could go public this year: report Read More »

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC 2026-07-21 at 17:57 By A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Read More »

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities 2026-07-21 at 17:47 By Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities Read More »

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access 2026-07-21 at 17:04 By Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access Read More »

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit 2026-07-21 at 16:30 By A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Read More »

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs 2026-07-21 at 14:58 By An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Read More »

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner 2026-07-21 at 12:00 By This year Security Magazine partnered with The National Center for Spectator Sports Safety and Security (NCS4) to present the Golden Eagle Award to SkySafe as the 2026 Golden Eagle Award winner for its case study submission, “University of Illinois Sets

Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winner Read More »

Scroll to Top