News

Cybersecurity
Anthropic Disputes Jailbreak Claim Against Claude Fable 5
Anthropic disputed a researcher jailbreak claim against Claude Fable 5, arguing the technique does not constitute a bypass of the model's safety classifiers.
Application Security
Six Proto6 Flaws in protobuf.js Enable Node.js RCE
Six Proto6 vulnerabilities in protobuf.js enable remote code execution and denial-of-service against Node.js apps via malicious schemas or crafted payloads.
Application Security
npm v12 Disables Auto-Run Scripts to Cut Supply Chain Risk
npm v12 will disable install scripts by default, requiring an explicit allowlist and closing the primary vector used by Miasma and Shai-Hulud attackers.
Cybersecurity
Anthropic Releases Guardrail-Free Mythos 5 to Security Researchers
Anthropic released Claude Mythos 5 with safety guardrails intentionally removed to vetted security researchers alongside the public Claude Fable 5 launch.
Cybersecurity
Novo Nordisk Discloses Breach of Clinical Trials Patient Data
Novo Nordisk disclosed a breach of clinical trials patient data, triggering GDPR, GCP, and clinical research regulatory obligations across global operations.
Cybersecurity
Europol Dismantles AudiA6 Crypto Laundering Service
Europol dismantled AudiA6, a cryptocurrency laundering service that processed over $380 million in ransomware extortion proceeds for criminal networks.
Application Security
Three LangGraph Flaws Chain to Remote Code Execution
Three patched LangGraph vulnerabilities chain from SQL injection to remote code execution on self-hosted AI agent framework deployments, researchers disclosed.
Cybersecurity
OnyxC2 Stealer Targets 200+ Apps for $250 Per Month
OnyxC2, a new MaaS information stealer priced at $250 per month, targets 200-plus applications using DLL sideloading and encryption to evade detection.
Cybersecurity
Maine AG Portal Abused to Post Fabricated Breach Notices
Threat actors filed fraudulent breach notices through Maine's AG portal, publishing false disclosures on a government site; VRChat denied the fabricated claim.
Application Security
Fortinet FortiSandbox CVE-2026-25089 Allows Unauthenticated RCE
Fortinet patched CVE-2026-25089, a CVSS 9.1 OS command injection in FortiSandbox's Web UI exploitable by unauthenticated attackers via crafted HTTP requests.