A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions ...
New TELEPUZ malware spreads through ClickFix, then steals browser cookies, logs keystrokes, runs commands, and installs itself as a Windows service.
Adblock for YouTube has over 11 million installations. However, it can inject script code into any page uncontrollably.
Unpatched Claude extension flaws could allow hijacking of Gmail and Google Docs workflows ...
A Chrome ad blocker with more than 10 million installs has reopened an old browser security debate. The tool may work as promised, but researchers say its design leaves room for a much riskier outcome ...
Discover the AI Agent Safety Directory that evaluates AI agents before deployment with trusted safety ratings, risk insights, and performance benchmarks.
AWS Kiro prompt injection flaw let hidden web page text rewrite the IDE’s MCP configuration file and silently execute ...
AWS fixed a Kiro prompt injection chain that rewrote mcp.json and launched attacker-controlled code with developer privileges ...
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress ...
Awareness of all the ways prompt injection can be effected will help security teams spot a new generation of attacks.
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This ...
Stolen and leaked credentials lead to Node.js packages from AsyncAPI and Jscrambler Code Integrity being poisoned with ...