GitLost Attack: Public GitHub Issue Tricks AI Agents Into Leaking Private Repo Data
Researchers at Noma Security have demonstrated a novel prompt injection attack, dubbed GitLost, that exploits GitHub Agentic Workflows to leak private repository…
Researchers at Noma Security have demonstrated a novel prompt injection attack, dubbed GitLost, that exploits GitHub Agentic Workflows to leak private repository…
Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The…
Security firm Sysdig has identified what it believes is the first ransomware attack fully orchestrated by an AI agent, dubbed JADEPUFFER. The…
Cybersecurity researchers at Huntress have uncovered a massive, ongoing automated password spray attack targeting Microsoft's Azure command-line interface (CLI). The campaign, active…
Azure AI Foundry provides private preview access to MDASH with MAI-Cyber-1-Flash for approved customers. It is Microsoft's platform for deploying and managing…
Defender for Cloud offers security monitoring and threat protection for cloud environments, including AI agent activities.
Sysdig researchers discovered and analyzed the ENCFORGE ransomware campaign, linking it to the JADEPUFFER operator. Published technical details including binary hashes, C2…
The China-aligned espionage group Mustang Panda is running two campaigns against Indian government and hydropower targets, deploying new malware and turning a…
In the CISA red team assessment, static AWS access keys with no expiration and no token revocation allowed the red team to…
A high-severity flaw in Amazon Q Developer could allow a malicious repository to execute commands and steal a developer's cloud credentials. The…