News

Application Security
Chrome 150 Patches Two Critical Use-After-Free Flaws in Ozone, Views
Google released Chrome 150.0.7871.114/.115 patching 27 vulnerabilities including two critical use-after-free bugs in Ozone and Views.
Application Security
CMU Research: Copilot’s Safety Refusals Fail 100% in Workflow Mode
Carnegie Mellon researchers found GitHub Copilot refuses harmful prompts 99% of the time in chat but produced harmful code in all 816 workflow-mode tests across ...
Application Security
Friendly Fire PoC Turns Claude Code and Codex Into Malware Launchers
AI Now Institute's Friendly Fire PoC shows Claude Code and Codex in security-audit mode will execute disguised malware when seeded with strings from a legitimate ...
Cybersecurity
DigitalMint Employee Sentenced for BlackCat Ransomware Conspiracy
A former DigitalMint employee received 70 months in prison for conspiring with BlackCat ransomware operators while posing as a trusted victim recovery advisor.
Application Security
Ill Bloom Flaw Drained $3.1M by Breaking Wallet Seed Randomness
Coinspect disclosed Ill Bloom, a weak entropy flaw in cryptocurrency wallet seed phrase generation that let attackers drain $3.1 million from affected wallets.
Cybersecurity
Threat Actors Use Aged GitHub Accounts to Map Corporate Orgs
Datadog Security Labs found threat actors using aged GitHub accounts to map corporate organization members and repositories before launching targeted attacks.
Cybersecurity
Microsoft Discloses GigaWiper: Disk Wiper Hidden Behind Fake Ransom
Microsoft disclosed GigaWiper, a Windows backdoor combining a real disk wiper, fake ransomware encryption, and multi-pass file overwriting in a single payload.
Cybersecurity
GodDamn Ransomware Uses PoisonX Driver to Kill EDR Before Encrypting
Symantec identified GodDamn ransomware using a kernel driver named PoisonX via the BYOVD technique to kill security software before file encryption begins.
Application Security
Injective Labs’ npm SDK Poisoned to Steal Crypto Wallet Credentials
Attackers compromised Injective Labs' repository and injected credential-stealing code into the authentic npm SDK packages used by DeFi blockchain developers.
Cybersecurity
Helix Group Uses Vishing and Device Code Flow to Steal SharePoint Data
New threat group Helix chains vishing with Microsoft's OAuth Device Code Flow to harvest M365 tokens and exfiltrate SharePoint data for corporate extortion.